This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Solved] Unknown Infection - second attempt

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Unable to respond earlier due to family illness, all ok now - am repeating original thread (now closed due to inactivity), oldman's response and the follow-up action I took following his advice. Thanks oldman for the help, I hope this is the correct way to reactivate a thread?

ORIGINAL LOG POST

did have mcafee on but couldnt disable it so got rid with revo before running dds and downloaded avast for now

over to you guys, grateful for any help…


dds.txt


DS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 23:49:32.71 on 06/04/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.109 [GMT 1:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\AOL\1254164638\ee\AOLSoftware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\PROGRA~1\COMMON~1\MICROS~1\MODI\12.0\MSPOCRDC.EXE
D:\Revo Uninstaller\revouninstaller.exe
C:\Documents and Settings\Jez\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.co.uk/
uSearch Page = hxxp://search.live.com
mStart Page = hxxp://www.myaolbroadband.co.uk
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
mSearchAssistant = hxxp://search.live.com/sphome.aspx
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\spybot - search & destroy\spybot - search & destroy\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol broadband toolbar 5.0\aoltb.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AOL Broadband Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol broadband toolbar 5.0\aoltb.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [cdoosoft] c:\docume~1\jez\locals~1\temp\herss.exe
uRun: [SpybotSD TeaTimer] d:\spybot - search & destroy\spybot - search & destroy\TeaTimer.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HostManager] c:\program files\common files\aol\1254164638\ee\AOLSoftware.exe
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-gb\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\spybot - search & destroy\spybot - search & destroy\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.pitchero.com/profile/ImageUploader5.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

============= SERVICES / DRIVERS ===============

R1 mferkdk;VSCore mferkdk;\??\c:\program files\mcafee\virusscan enterprise\mferkdk.sys –> c:\program files\mcafee\virusscan enterprise\mferkdk.sys [?]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-9-28 54752]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys –> c:\windows\system32\drivers\mfehidk.sys [?]
S2 McShield;McAfee McShield;"c:\program files\mcafee\virusscan enterprise\mcshield.exe" –> c:\program files\mcafee\virusscan enterprise\Mcshield.exe [?]
S2 McTaskManager;McAfee Task Manager;"c:\program files\mcafee\virusscan enterprise\vstskmgr.exe" –> c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [?]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys –> c:\windows\system32\drivers\mfeavfk.sys [?]
S3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys –> c:\windows\system32\drivers\mfebopk.sys [?]

=============== Created Last 30 ================

2010-04-06 19:59 –d—– c:\docume~1\alluse~1\applic~1\SSScanAppDataDir
2010-04-06 19:58 –d—– c:\docume~1\alluse~1\applic~1\MSScanAppDataDir
2010-03-29 16:57 293,376 ——– c:\windows\system32\browserchoice.exe
2010-03-25 18:32 –d—– c:\docume~1\jez\applic~1\Office Genuine Advantage
2010-03-24 20:14 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-21 20:54 121,344 —shr– C:\ji83j.exe
2010-03-21 20:53 115,200 —shr– C:\fk.exe
2010-03-21 20:53 59 —shr– C:\autorun.inf
2010-03-21 19:14 –d—– c:\docume~1\jez\applic~1\Malwarebytes
2010-03-21 19:14 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-21 19:14 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-21 19:14 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-21 19:09 –d—– c:\docume~1\alluse~1\applic~1\ReviverSoft

==================== Find3M ====================

2010-02-26 07:12 662,016 a——- c:\windows\system32\wininet.dll
2010-02-26 07:12 81,920 a——- c:\windows\system32\ieencode.dll
2010-02-08 19:28 91,648 —shr– C:\ws.exe
2010-01-26 16:07 100,864 —shr– C:\df.exe
2010-01-22 16:01 96,768 —shr– C:\qkm.exe
2010-01-16 18:40 118,784 —shr– C:\mh.exe
2010-01-16 05:28 120,320 —shr– C:\kmj.exe
2010-01-08 14:22 121,344 —shr– C:\f2kmj.exe

============= FINISH: 23:50:10.32 ===============


Gmer.txt;

MER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-07 23:10:54
Windows 5.1.2600 Service Pack 2
Running: i91vxye6.exe; Driver: C:\DOCUME~1\Jez\LOCALS~1\Temp\kfqiyaod.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF3AC7C56]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF3AC7B12]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xF3AC80C6]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF3AC7FF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF3AC76E8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF3AC7BEC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF3AC7628]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF3AC768C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF3AC7D0C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xF3AC8194]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF3AC7CCC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF3AC7E4C]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF3AD44FE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF3AD4322]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF3AD445C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-

OLDMAN'S RESPONSE
Hi bluespoons61, welcome to the forum.

To make cleaning this machine easier
Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs.
Please do not run any scans other than those requested
Please follow all instructions in the order posted
All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
Do not attach any logs/reports, etc.. unless specifically requested to do so.
If you have problems with or do not understand the instructions, Please ask before continuing.
Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.



Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2 (if you need to use this link, please right click it and click Save Target As")

* IMPORTANT !!! Save ComboFix.exe to your Desktop


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.





Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Reduced: 93% of original size [ 550 x 158 ] - Click to view full image

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



Next

Please open windows explorer (right click your start button and click explore)
navigate to this folder C:\qoobox
in the tight hand panel locate Add-Remove programs.txt
please post it's contents



Please psot back with
combofix log
Add-Remove Programs.txt


Thanks


COMBOFIX LOG

ComboFix 10-04-21.01 - Jez 22/04/2010 20:56:22.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.54 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\docume~1\Jez\LOCALS~1\Temp\cvasds0.dll
c:\docume~1\Jez\LOCALS~1\Temp\cvasds1.dll
D:\0fkk02x.exe
D:\0fpdq2dw.exe
D:\0qw6vege.exe
D:\1a1dndah.exe
D:\1hqup.exe
D:\2id9.exe
D:\3exi.exe
D:\3n8awsyg.exe
D:\8xcrbho6.exe
D:\9b9w3.exe
D:\9d6tpg.exe
D:\9fo3ar0j.exe
D:\9g86.exe
D:\9jyhdim8.exe
D:\9qqigqwf.exe
D:\9xf8.exe
D:\anoataly.exe
D:\autorun.inf
D:\b00ijwpu.exe
D:\c2e.exe
D:\ctu8r.exe
D:\curqp.exe
D:\df.exe
D:\e9naq.exe
D:\eexyv.exe
D:\f2kmj.exe
D:\fk.exe
D:\g12g.exe
D:\gcq6.exe
D:\h0.exe
D:\hjvjte.exe
D:\ji83j.exe
D:\k8jc.exe
D:\kmj.exe
D:\l61yyp.exe
D:\lphfa.exe
D:\mbdm.exe
D:\mbvd.exe
D:\mh.exe
D:\mje12tni.exe
D:\mranjm.exe
D:\mvmdh.exe
D:\mwfubaob.exe
D:\nds0q.exe
D:\nqdymj.exe
D:\nx.exe
D:\nymdik.exe
D:\opdux.exe
D:\p3vwxx.exe
D:\pbudsara.exe
D:\q3kku.exe
D:\q93fi6kf.exe
D:\qbr2q.exe
D:\qkm.exe
D:\r2g20.exe
D:\s1.exe
D:\s3ek.exe
D:\se12ydam.exe
D:\sp1jensi.exe
D:\srgo.exe
D:\sywyrl0q.exe
D:\t2hjo0.exe
D:\t8g.exe
D:\tgt.exe
D:\u16sqrqn.exe
D:\uqgvf.exe
D:\v1cbvsmq.exe
D:\vk0w.exe
D:\vlvtdflx.exe
D:\wcgswa.exe
D:\wfx062.exe
D:\ws.exe
D:\wu1n.exe
D:\xmor.exe
D:\yu3.exe
E:\0fkk02x.exe
E:\0fpdq2dw.exe
E:\0qw6vege.exe
E:\1a1dndah.exe
E:\1hqup.exe
E:\2id9.exe
E:\3exi.exe
E:\3n8awsyg.exe
E:\8xcrbho6.exe
E:\9b9w3.exe
E:\9d6tpg.exe
E:\9fo3ar0j.exe
E:\9g86.exe
E:\9jyhdim8.exe
E:\9qqigqwf.exe
E:\9xf8.exe
E:\anoataly.exe
E:\Autorun.inf
E:\b00ijwpu.exe
E:\c2e.exe
E:\ctu8r.exe
E:\curqp.exe
E:\df.exe
E:\e9naq.exe
E:\eexyv.exe
E:\f2kmj.exe
E:\fk.exe
E:\g12g.exe
E:\gcq6.exe
E:\h0.exe
E:\hjvjte.exe
E:\ji83j.exe
E:\k8jc.exe
E:\kmj.exe
E:\l61yyp.exe
E:\lphfa.exe
E:\mbdm.exe
E:\mbvd.exe
E:\mh.exe
E:\mje12tni.exe
E:\mranjm.exe
E:\mvmdh.exe
E:\mwfubaob.exe
E:\nds0q.exe
E:\nqdymj.exe
E:\nx.exe
E:\nymdik.exe
E:\opdux.exe
E:\p3vwxx.exe
E:\pbudsara.exe
E:\q3kku.exe
E:\q93fi6kf.exe
E:\qbr2q.exe
E:\qkm.exe
E:\r2g20.exe
E:\s1.exe
E:\s3ek.exe
E:\se12ydam.exe
E:\sp1jensi.exe
E:\srgo.exe
E:\sywyrl0q.exe
E:\t2hjo0.exe
E:\t8g.exe
E:\tgt.exe
E:\u16sqrqn.exe
E:\uqgvf.exe
E:\v1cbvsmq.exe
E:\vk0w.exe
E:\vlvtdflx.exe
E:\wcgswa.exe
E:\wfx062.exe
E:\ws.exe
E:\wu1n.exe
E:\xmor.exe
E:\yu3.exe
F:\0fkk02x.exe
F:\0fpdq2dw.exe
F:\0qw6vege.exe
F:\1a1dndah.exe
F:\1hqup.exe
F:\2id9.exe
F:\3exi.exe
F:\3n8awsyg.exe
F:\8xcrbho6.exe
F:\9b9w3.exe
F:\9d6tpg.exe
F:\9fo3ar0j.exe
F:\9g86.exe
F:\9jyhdim8.exe
F:\9qqigqwf.exe
F:\9xf8.exe
F:\anoataly.exe
F:\Autorun.inf
F:\b00ijwpu.exe
F:\c2e.exe
F:\ctu8r.exe
F:\curqp.exe
F:\df.exe
F:\e9naq.exe
F:\eexyv.exe
F:\f2kmj.exe
F:\fk.exe
F:\g12g.exe
F:\gcq6.exe
F:\h0.exe
F:\hjvjte.exe
F:\ji83j.exe
F:\k8jc.exe
F:\kmj.exe
F:\l61yyp.exe
F:\lphfa.exe
F:\mbdm.exe
F:\mbvd.exe
F:\mh.exe
F:\mje12tni.exe
F:\mranjm.exe
F:\mvmdh.exe
F:\mwfubaob.exe
F:\nds0q.exe
F:\nqdymj.exe
F:\nx.exe
F:\nymdik.exe
F:\opdux.exe
F:\p3vwxx.exe
F:\pbudsara.exe
F:\q3kku.exe
F:\q93fi6kf.exe
F:\qbr2q.exe
F:\qkm.exe
F:\r2g20.exe
F:\s1.exe
F:\s3ek.exe
F:\se12ydam.exe
F:\sp1jensi.exe
F:\srgo.exe
F:\sywyrl0q.exe
F:\t2hjo0.exe
F:\t8g.exe
F:\tgt.exe
F:\u16sqrqn.exe
F:\uqgvf.exe
F:\v1cbvsmq.exe
F:\vk0w.exe
F:\vlvtdflx.exe
F:\wcgswa.exe
F:\wfx062.exe
F:\ws.exe
F:\wu1n.exe
F:\xmor.exe
F:\yu3.exe

.
((((((((((((((((((((((((( Files Created from 2010-03-22 to 2010-04-22 )))))))))))))))))))))))))))))))
.

2010-04-22 19:21 . 2010-04-22 19:21 ——– d—–w- c:\windows\LastGood
2010-04-07 20:58 . 2010-03-09 10:08 19024 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-04-07 20:58 . 2010-03-09 10:12 162640 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-04-07 20:58 . 2010-03-09 10:09 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-04-07 20:57 . 2010-03-09 10:12 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-04-07 20:57 . 2010-03-09 10:08 100432 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-04-07 20:57 . 2010-03-09 10:08 94800 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-04-07 20:57 . 2010-03-09 10:08 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-04-07 20:54 . 2010-03-09 10:24 38848 —-a-w- c:\windows\system32\avastSS.scr
2010-04-07 20:54 . 2010-03-09 10:24 153184 —-a-w- c:\windows\system32\aswBoot.exe
2010-04-07 20:53 . 2010-04-07 20:53 ——– d—–w- c:\program files\Alwil Software
2010-04-07 20:53 . 2010-04-07 20:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-04-06 18:59 . 2010-04-06 18:59 ——– d—–w- c:\documents and settings\Jez\Application Data\Canon
2010-04-06 18:59 . 2010-04-06 19:00 ——– d—–w- c:\documents and settings\All Users\Application Data\SSScanAppDataDir
2010-04-06 18:58 . 2010-04-06 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2010-03-29 15:57 . 2010-02-12 10:03 293376 ——w- c:\windows\system32\browserchoice.exe
2010-03-25 17:32 . 2010-03-25 17:32 ——– d—–w- c:\documents and settings\Jez\Application Data\Office Genuine Advantage
2010-03-24 19:14 . 2010-03-24 20:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-24 16:56 . 2010-03-24 16:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-21 18:14 . 2010-03-21 18:14 ——– d—–w- c:\documents and settings\Jez\Application Data\Malwarebytes
2010-03-21 18:14 . 2010-03-21 18:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-21 18:09 . 2010-03-21 18:09 ——– d—–w- c:\documents and settings\All Users\Application Data\ReviverSoft
2010-03-14 14:27 . 2009-09-29 16:13 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-14 14:26 . 2009-09-29 16:13 ——– d—–w- c:\program files\Common Files\Logitech
2010-03-14 14:26 . 2009-10-01 12:50 ——– d—–w- c:\documents and settings\All Users\Application Data\LogiShrd
2010-03-14 14:26 . 2009-10-01 11:41 ——– d—–w- c:\program files\Common Files\logishrd
2010-03-14 14:25 . 2010-03-14 14:25 ——– d—–w- c:\documents and settings\Jez\Application Data\Leadertech
2010-03-10 22:09 . 2009-09-27 15:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-26 06:12 . 2004-08-04 12:00 662016 —-a-w- c:\windows\system32\wininet.dll
2010-02-26 06:12 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
.

——- Sigcheck ——-

[-] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[-] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\drivers\atapi.sys

[-] 2008-04-13 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\asyncmac.sys
[-] 2004-08-04 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\asyncmac.sys
[-] 2004-08-04 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\drivers\asyncmac.sys

[-] 2004-08-04 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
[-] 2004-08-04 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys

[-] 2008-04-13 . 463C1EC80CD17420A542B7F36A36F128 . 24576 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\kbdclass.sys
[-] 2004-08-04 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0000\DriverFiles\i386\kbdclass.sys
[-] 2004-08-03 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\kbdclass.sys
[-] 2004-08-03 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\drivers\kbdclass.sys

[-] 2008-04-13 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ndis.sys
[-] 2004-08-04 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ndis.sys
[-] 2004-08-04 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ndis.sys

[-] 2008-04-13 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ntfs.sys
[-] 2004-08-04 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ntfs.sys
[-] 2004-08-04 . B78BE402C3F63DD55521F73876951CDD . 574592 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ntfs.sys

[-] 2004-08-04 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys
[-] 2004-08-04 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys

[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\drivers\tcpip.sys
[-] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\tcpip.sys
[-] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\2ad1413c5dc0d16e6d56d3e6ca94ed48\backup\sp2gdr\tcpip.sys
[-] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\2ad1413c5dc0d16e6d56d3e6ca94ed48\backup\sp2qfe\tcpip.sys
[-] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\2ad1413c5dc0d16e6d56d3e6ca94ed48\backup\sp3gdr\tcpip.sys
[-] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\2ad1413c5dc0d16e6d56d3e6ca94ed48\backup\sp3qfe\tcpip.sys

[-] 2008-04-14 . A06CE3399D16DB864F55FAEB1F1927A9 . 77824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\browser.dll
[-] 2004-08-04 . E3CFCCDDA4EDD1D0DC9168B2E18F27B8 . 77312 . . [5.1.2600.2180] . . c:\windows\system32\browser.dll
[-] 2004-08-04 . E3CFCCDDA4EDD1D0DC9168B2E18F27B8 . 77312 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\browser.dll

[-] 2008-04-14 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\lsass.exe
[-] 2004-08-04 . 84885F9B82F4D55C6146EBF6065D75D2 . 13312 . . [5.1.2600.2180] . . c:\windows\system32\lsass.exe
[-] 2004-08-04 . 84885F9B82F4D55C6146EBF6065D75D2 . 13312 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\lsass.exe

[-] 2008-04-14 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netman.dll
[-] 2004-08-04 . DAB9E6C7105D2EF49876FE92C524F565 . 198144 . . [5.1.2600.2180] . . c:\windows\system32\netman.dll
[-] 2004-08-04 . DAB9E6C7105D2EF49876FE92C524F565 . 198144 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\netman.dll

[-] 2008-04-14 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\qmgr.dll
[-] 2004-08-04 . 2C69EC7E5A311334D10DD95F338FCCEA . 382464 . . [6.6.2600.2180] . . c:\windows\system32\qmgr.dll
[-] 2004-08-04 . 2C69EC7E5A311334D10DD95F338FCCEA . 382464 . . [6.6.2600.2180] . . c:\windows\system32\dllcache\qmgr.dll

[-] 2009-02-09 . 6B27A5C03DFB94B4245739065431322C . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\rpcss.dll
[-] 2009-02-09 . 9222562D44021B988B9F9F62207FB6F2 . 401408 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[-] 2009-02-09 . 01095FEBF33BEEA00C2A0730B9B3EC28 . 399360 . . [5.1.2600.3520] . . c:\windows\system32\rpcss.dll
[-] 2009-02-09 . 01095FEBF33BEEA00C2A0730B9B3EC28 . 399360 . . [5.1.2600.3520] . . c:\windows\system32\dllcache\rpcss.dll
[-] 2009-02-09 . 24B5D53B9ACCC1E2EDCF0A878D6659D4 . 401408 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\rpcss.dll
[-] 2008-04-14 . 2589FE6015A316C0F5D5112B4DA7B509 . 399360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\rpcss.dll
[-] 2004-08-04 . 5C83A4408604F737717AB96371201680 . 395776 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB956572$\rpcss.dll

[-] 2009-02-06 . 37561F8D4160D62DA86D24AE41FAE8DE . 110592 . . [5.1.2600.3520] . . c:\windows\system32\services.exe
[-] 2009-02-06 . 37561F8D4160D62DA86D24AE41FAE8DE . 110592 . . [5.1.2600.3520] . . c:\windows\system32\dllcache\services.exe
[-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\services.exe
[-] 2009-02-06 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2009-02-06 . 4712531AB7A01B7EE059853CA17D39BD . 110592 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\services.exe
[-] 2008-04-14 . 0E776ED5F7CC9F94299E70461B7B8185 . 108544 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\services.exe
[-] 2004-08-04 . C6CE6EEC82F187615D1002BB3BB50ED4 . 108032 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB956572$\services.exe

[-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\spoolsv.exe
[-] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\system32\spoolsv.exe
[-] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\spoolsv.exe

[-] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe
[-] 2004-08-04 . 01C3346C241652F43AED8E2149881BFE . 502272 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe
[-] 2004-08-04 . 01C3346C241652F43AED8E2149881BFE . 502272 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\winlogon.exe

[-] 2008-04-14 . BD38D1EBE24A46BD3EDA059560AFBA12 . 1054208 . . [6.0] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\asms\60\msft\windows\common\controls\comctl32.dll
[-] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\comctl32.dll
[-] 2004-08-04 . A77DFB85FAEE49D66C74DA6024EBC69B . 611328 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2004-08-04 . A77DFB85FAEE49D66C74DA6024EBC69B . 611328 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll

[-] 2008-04-14 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\cryptsvc.dll
[-] 2004-08-04 . 10654F9DDCEA9C46CFB77554231BE73B . 60416 . . [5.1.2600.2180] . . c:\windows\system32\cryptsvc.dll
[-] 2004-08-04 . 10654F9DDCEA9C46CFB77554231BE73B . 60416 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\cryptsvc.dll

[-] 2008-07-07 20:32 . 60D1A6342238378BFB7545C81EE3606C . 253952 . . [2001.12.4414.320] . . c:\windows\system32\es.dll
[-] 2008-07-07 20:32 . 60D1A6342238378BFB7545C81EE3606C . 253952 . . [2001.12.4414.320] . . c:\windows\system32\dllcache\es.dll
[-] 2008-07-07 20:26 . D4991D98F2DB73C60D042F1AEF79EFAE . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3GDR\es.dll
[-] 2008-07-07 20:23 . F17F6226BDC0CD5F0BEF0DAF84D29BEC . 253952 . . [2001.12.4414.706] . . c:\windows\$hf_mig$\KB950974\SP3QFE\es.dll
[-] 2008-07-07 20:06 . A4AB3DCA4A383F0DF4988ABDEB84F9A4 . 253952 . . [2001.12.4414.320] . . c:\windows\$hf_mig$\KB950974\SP2QFE\es.dll
[-] 2008-04-14 00:11 . 19A799805B24990867B00C120D300C3A . 246272 . . [2001.12.4414.701] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\es.dll
[-] 2004-08-04 12:00 . ACD36A2DD7D1E9D8A060AA651DC07E63 . 243200 . . [2001.12.4414.258] . . c:\windows\$NtUninstallKB950974$\es.dll
[-] 2004-08-04 12:00 . ACD36A2DD7D1E9D8A060AA651DC07E63 . 243200 . . [2001.12.4414.258] . . c:\windows\SoftwareDistribution\Download\74a19a19cc31989be4bb0df6ac36d839\backup\sp2gdr\es.dll
[-] 2004-08-04 12:00 . ACD36A2DD7D1E9D8A060AA651DC07E63 . 243200 . . [2001.12.4414.258] . . c:\windows\SoftwareDistribution\Download\74a19a19cc31989be4bb0df6ac36d839\backup\sp2qfe\es.dll
[-] 2004-08-04 12:00 . ACD36A2DD7D1E9D8A060AA651DC07E63 . 243200 . . [2001.12.4414.258] . . c:\windows\SoftwareDistribution\Download\74a19a19cc31989be4bb0df6ac36d839\backup\sp3gdr\es.dll
[-] 2004-08-04 12:00 . ACD36A2DD7D1E9D8A060AA651DC07E63 . 243200 . . [2001.12.4414.258] . . c:\windows\SoftwareDistribution\Download\74a19a19cc31989be4bb0df6ac36d839\backup\sp3qfe\es.dll

[-] 2008-04-14 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\imm32.dll
[-] 2004-08-04 . 87CA7CE6469577F059297B9D6556D66D . 110080 . . [5.1.2600.2180] . . c:\windows\system32\imm32.dll
[-] 2004-08-04 . 87CA7CE6469577F059297B9D6556D66D . 110080 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\imm32.dll

[-] 2009-03-21 . B6ACAED7588295129791E0E6A2B0FADE . 986112 . . [5.1.2600.3541] . . c:\windows\system32\kernel32.dll
[-] 2009-03-21 . B6ACAED7588295129791E0E6A2B0FADE . 986112 . . [5.1.2600.3541] . . c:\windows\system32\dllcache\kernel32.dll
[-] 2009-03-21 . B921FB870C9AC0D509B2CCABBBBE95F3 . 989696 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3GDR\kernel32.dll
[-] 2009-03-21 . DA11D9D6ECBDF0F93436A4B7C13F7BEC . 991744 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2009-03-21 . 80202858D245FF07DAA1739C57A3E19B . 989184 . . [5.1.2600.3541] . . c:\windows\$hf_mig$\KB959426\SP2QFE\kernel32.dll
[-] 2008-04-14 . C24B983D211C34DA8FCC1AC38477971D . 989696 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\kernel32.dll
[-] 2004-08-04 . 888190E31455FAD793312F8D087146EB . 983552 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB959426$\kernel32.dll

[-] 2008-04-14 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\linkinfo.dll
[-] 2004-08-04 . C2BBD044C741EA4292016C36F718D2E4 . 18944 . . [5.1.2600.2180] . . c:\windows\system32\linkinfo.dll
[-] 2004-08-04 . C2BBD044C741EA4292016C36F718D2E4 . 18944 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\linkinfo.dll

[-] 2008-04-14 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\lpk.dll
[-] 2004-08-04 . 74D66B3DE265E8789153414E75175F26 . 22016 . . [5.1.2600.2180] . . c:\windows\system32\lpk.dll
[-] 2004-08-04 . 74D66B3DE265E8789153414E75175F26 . 22016 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\lpk.dll

[-] 2010-02-26 . FC9771E54B65828AA8E032329CD61A79 . 3073024 . . [6.00.2900.3676] . . c:\windows\$hf_mig$\KB980182\SP2QFE\mshtml.dll
[-] 2010-02-26 . 9577B285B95EF8F750B2D1A7C3E05285 . 3065344 . . [6.00.2900.3676] . . c:\windows\system32\mshtml.dll
[-] 2010-02-26 . 9577B285B95EF8F750B2D1A7C3E05285 . 3065344 . . [6.00.2900.3676] . . c:\windows\system32\dllcache\mshtml.dll
[-] 2010-02-26 . 063D664850A16932F60E7F8830BDF2E1 . 3073024 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3GDR\mshtml.dll
[-] 2010-02-26 . EE6B9880933172AE78A1146BE15D6D21 . 3073536 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3QFE\mshtml.dll
[-] 2009-12-22 . BD1365D9400C3DB84D76AE77318E1A8D . 3063808 . . [6.00.2900.3660] . . c:\windows\$NtUninstallKB980182$\mshtml.dll
[-] 2009-12-22 . 5747867041C33E26DA5CC893C9532DB8 . 3071488 . . [6.00.2900.3660] . . c:\windows\$hf_mig$\KB978207\SP2QFE\mshtml.dll
[-] 2009-12-22 . A758F0891A87EE005848A0BC740A5B96 . 3071488 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3GDR\mshtml.dll
[-] 2009-12-22 . AD17006339C1934D86449F335C241FF1 . 3073536 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\mshtml.dll
[-] 2009-10-29 . D1CF72C34BAF70C52797D1CB78D6EE92 . 3070976 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3GDR\mshtml.dll
[-] 2009-10-29 . 6CAFAA3E8C37CDD0D7441AF82807F70C . 3063296 . . [6.00.2900.3640] . . c:\windows\$NtUninstallKB978207$\mshtml.dll
[-] 2009-10-29 . DA551BFEC150760A38A9AD0C95A8A71C . 3073024 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\mshtml.dll
[-] 2009-10-29 . F3A9E882DF2F155C9395979FF9D7B0A7 . 3070976 . . [6.00.2900.3640] . . c:\windows\$hf_mig$\KB976325\SP2QFE\mshtml.dll
[-] 2009-10-20 . 4FDC6E7E9B2683EA263CDC9A6203D898 . 3063296 . . [6.00.2900.3636] . . c:\windows\$NtUninstallKB976325$\mshtml.dll
[-] 2009-10-20 . 57B9895B3720587DE96B70FD0F15270A . 3070976 . . [6.00.2900.3636] . . c:\windows\$hf_mig$\KB976749\SP2QFE\mshtml.dll
[-] 2009-10-19 . 4D1EAA7E0B845D1B2E8D711AE754D0F2 . 3070976 . . [6.00.2900.5890] . . c:\windows\$hf_mig$\KB976749\SP3GDR\mshtml.dll
[-] 2009-10-19 . 6C1B3294BCD1A38FDE6D965A96612756 . 3072512 . . [6.00.2900.5890] . . c:\windows\$hf_mig$\KB976749\SP3QFE\mshtml.dll
[-] 2009-09-25 . 299423DFB7E8D8E179F685371C88A6A8 . 3063296 . . [6.00.2900.3627] . . c:\windows\$NtUninstallKB976749$\mshtml.dll
[-] 2009-09-25 . 431D4C38E47AE0CAC1A52A185395A5F5 . 3070976 . . [6.00.2900.3627] . . c:\windows\$hf_mig$\KB974455\SP2QFE\mshtml.dll
[-] 2009-09-25 . 601E18A9A8F0D0ED39692B593212378F . 3070976 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3GDR\mshtml.dll
[-] 2009-09-25 . 37F578776552FA076EA6085F0365209C . 3072512 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\mshtml.dll
[-] 2009-07-18 . 108F212B0E1B4439B014497EEC407981 . 3062272 . . [6.00.2900.3603] . . c:\windows\$NtUninstallKB974455$\mshtml.dll
[-] 2009-07-18 . 7467941BE64DFC5F8E9F3DC1DE920806 . 3069440 . . [6.00.2900.5848] . . c:\windows\$hf_mig$\KB972260\SP3GDR\mshtml.dll
[-] 2009-07-18 . 9A878C4D12BE5598B598B27BFEA1B3C2 . 3069440 . . [6.00.2900.3603] . . c:\windows\$hf_mig$\KB972260\SP2QFE\mshtml.dll
[-] 2009-07-18 . F3EE47F296295D08A97CB50EF57244D9 . 3069952 . . [6.00.2900.5848] . . c:\windows\$hf_mig$\KB972260\SP3QFE\mshtml.dll
[-] 2008-04-14 . A706E122B398FE1AB85CB9B75D044223 . 3066880 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\mshtml.dll
[-] 2004-08-04 . 376E0843B2356CA91CEC8D9837A56FF7 . 3003392 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB972260$\mshtml.dll
[-] 2004-08-04 . 376E0843B2356CA91CEC8D9837A56FF7 . 3003392 . . [6.00.2900.2180] . . c:\windows\SoftwareDistribution\Download\ec0cabbd82acaeb42e692fe1035bccdb\backup\sp2gdr\mshtml.dll
[-] 2004-08-04 . 376E0843B2356CA91CEC8D9837A56FF7 . 3003392 . . [6.00.2900.2180] . . c:\windows\SoftwareDistribution\Download\ec0cabbd82acaeb42e692fe1035bccdb\backup\sp2qfe\mshtml.dll
[-] 2004-08-04 . 376E0843B2356CA91CEC8D9837A56FF7 . 3003392 . . [6.00.2900.2180] . . c:\windows\SoftwareDistribution\Download\ec0cabbd82acaeb42e692fe1035bccdb\backup\sp3gdr\mshtml.dll
[-] 2004-08-04 . 376E0843B2356CA91CEC8D9837A56FF7 . 3003392 . . [6.00.2900.2180] . . c:\windows\SoftwareDistribution\Download\ec0cabbd82acaeb42e692fe1035bccdb\backup\sp3qfe\mshtml.dll

[-] 2008-04-14 . D7075E95AA599EE77B7A89D39296BD3D . 343040 . . [7.0.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\asms\70\msft\windows\mswincrt\msvcrt.dll
[-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\msvcrt.dll
[-] 2004-08-04 . B0FEFA816D61EC66AA765DDF534EAB5E . 343040 . . [7.0.2600.2180] . . c:\windows\system32\msvcrt.dll
[-] 2004-08-04 . B0FEFA816D61EC66AA765DDF534EAB5E . 343040 . . [7.0.2600.2180] . . c:\windows\system32\dllcache\msvcrt.dll

[-] 2008-06-20 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\mswsock.dll
[-] 2008-06-20 . FCEE5FCB99F7C724593365C706D28388 . 245248 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\mswsock.dll
[-] 2008-06-20 . 097722F235A1FB698BF9234E01B52637 . 245248 . . [5.1.2600.3394] . . c:\windows\system32\mswsock.dll
[-] 2008-06-20 . 097722F235A1FB698BF9234E01B52637 . 245248 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\mswsock.dll
[-] 2008-06-20 . 1DFCA7713EA5A70D5D93B436AEA0317A . 245248 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\mswsock.dll
[-] 2008-04-14 . B4138E99236F0F57D4CF49BAE98A0746 . 245248 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\mswsock.dll
[-] 2004-08-04 . 4E74AF063C3271FBEA20DD940CFD1184 . 245248 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748$\mswsock.dll
[-] 2004-08-04 . 4E74AF063C3271FBEA20DD940CFD1184 . 245248 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\2ad1413c5dc0d16e6d56d3e6ca94ed48\backup\sp2gdr\mswsock.dll
[-] 2004-08-04 . 4E74AF063C3271FBEA20DD940CFD1184 . 245248 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\2ad1413c5dc0d16e6d56d3e6ca94ed48\backup\sp2qfe\mswsock.dll
[-] 2004-08-04 . 4E74AF063C3271FBEA20DD940CFD1184 . 245248 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\2ad1413c5dc0d16e6d56d3e6ca94ed48\backup\sp3gdr\mswsock.dll
[-] 2004-08-04 . 4E74AF063C3271FBEA20DD940CFD1184 . 245248 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\2ad1413c5dc0d16e6d56d3e6ca94ed48\backup\sp3qfe\mswsock.dll

[-] 2009-02-06 . 6C476D33D82F1054849790181E8F7772 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[-] 2009-02-06 . 6C476D33D82F1054849790181E8F7772 . 408064 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[-] 2008-04-14 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[-] 2004-08-04 . 96353FCECBA774BB8DA74A1C6507015A . 407040 . . [5.1.2600.2180] . . c:\windows\system32\netlogon.dll
[-] 2004-08-04 . 96353FCECBA774BB8DA74A1C6507015A . 407040 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\netlogon.dll

[-] 2010-02-17 . D41C3CBAD0E1C0728D1CDFD541F60CFA . 2189952 . . [5.1.2600.5938] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\SP3GDR\ntoskrnl.exe
[-] 2010-02-16 . 97E2BF68857818A4D142B872404DC41B . 2186880 . . [5.1.2600.3670] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\SP2QFE\ntoskrnl.exe
[-] 2010-02-16 . EBB75B113E74E90074382347B74D652B . 2181376 . . [5.1.2600.3670] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\SP2GDR\ntoskrnl.exe
[-] 2010-02-16 . E1F653A542449D54FA2D27463D99B6B6 . 2190080 . . [5.1.2600.5938] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\SP3QFE\ntoskrnl.exe
[-] 2009-12-08 . 05BE3D9A71972223AFF6A3C823BA51B1 . 2189312 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe
[-] 2009-12-08 . 78EC47F9B9A3A1D539262D8834C896CE . 2189184 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3GDR\ntoskrnl.exe
[-] 2009-12-08 . 5648297DBF1C631164F779863DF9D5BF . 2180352 . . [5.1.2600.3654] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2009-12-08 . 5648297DBF1C631164F779863DF9D5BF . 2180352 . . [5.1.2600.3654] . . c:\windows\system32\ntoskrnl.exe
[-] 2009-12-08 . 5648297DBF1C631164F779863DF9D5BF . 2180352 . . [5.1.2600.3654] . . c:\windows\system32\dllcache\ntoskrnl.exe
[-] 2009-12-08 . 128D88B3176E70B2E3088ECEB842B673 . 2185984 . . [5.1.2600.3654] . . c:\windows\$hf_mig$\KB977165\SP2QFE\ntoskrnl.exe
[-] 2009-08-04 . 8415D9C7C050E7022AED8ABF281BE4A6 . 2189184 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3GDR\ntoskrnl.exe
[-] 2009-08-04 . D6B537A639D623ED85B73AF3E3BE4B94 . 2180352 . . [5.1.2600.3610] . . c:\windows\$NtUninstallKB977165$\ntoskrnl.exe
[-] 2009-08-04 . FDE779EA1A564EBFE16F4E0F82B61BAD . 2189312 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe
[-] 2009-08-04 . 8DF112C341425F29DB4566B8D2A96A7F . 2185984 . . [5.1.2600.3610] . . c:\windows\$hf_mig$\KB971486\SP2QFE\ntoskrnl.exe
[-] 2009-02-07 . EFE8EACE83EAAD5849A7A548FB75B584 . 2189184 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2009-02-06 . FACEBB0CA3154F77009CDFEE78A00BBB . 2180480 . . [5.1.2600.3520] . . c:\windows\$NtUninstallKB971486$\ntoskrnl.exe
[-] 2009-02-06 . 7A95B10A73737EBF24139AAA63F5212B . 2189056 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntoskrnl.exe
[-] 2009-02-06 . 6A936E9D7BADAF3CAAEED1E1966EC1B0 . 2186112 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntoskrnl.exe
[-] 2008-04-13 . 0C89243C7C3EE199B96FCC16990E0679 . 2188928 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ntoskrnl.exe
[-] 2004-08-04 . CE218BC7088681FAA06633E218596CA7 . 2180992 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB956572$\ntoskrnl.exe

[-] 2008-04-14 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\powrprof.dll
[-] 2004-08-04 . 1B5F6923ABB450692E9FE0672C897AED . 17408 . . [6.00.2900.2180] . . c:\windows\system32\powrprof.dll
[-] 2004-08-04 . 1B5F6923ABB450692E9FE0672C897AED . 17408 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\powrprof.dll

[-] 2008-04-14 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
[-] 2004-08-04 . 0F78E27F563F2AAF74B91A49E2ABF19A . 180224 . . [5.1.2600.2180] . . c:\windows\system32\scecli.dll
[-] 2004-08-04 . 0F78E27F563F2AAF74B91A49E2ABF19A . 180224 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\scecli.dll

[-] 2008-04-14 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sfc.dll
[-] 2004-08-04 . E8A12A12EA9088B4327D49EDCA3ADD3E . 5120 . . [5.1.2600.2180] . . c:\windows\system32\sfc.dll
[-] 2004-08-04 . E8A12A12EA9088B4327D49EDCA3ADD3E . 5120 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\sfc.dll

[-] 2008-04-14 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\svchost.exe
[-] 2004-08-04 . 8F078AE4ED187AAABC0A305146DE6716 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\svchost.exe
[-] 2004-08-04 . 8F078AE4ED187AAABC0A305146DE6716 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\svchost.exe

[-] 2008-04-14 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\tapisrv.dll
[-] 2004-08-04 . EB4A4187D74A8EFDCBEA3EA2CB1BDFBD . 246272 . . [5.1.2600.2180] . . c:\windows\system32\tapisrv.dll
[-] 2004-08-04 . EB4A4187D74A8EFDCBEA3EA2CB1BDFBD . 246272 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\tapisrv.dll

[-] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\user32.dll
[-] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\system32\user32.dll
[-] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\user32.dll

[-] 2008-04-14 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\userinit.exe
[-] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\system32\userinit.exe
[-] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\userinit.exe

[-] 2010-02-26 . 728AB52393206408EFAD838F797F435D . 662016 . . [6.00.2900.3676] . . c:\windows\system32\wininet.dll
[-] 2010-02-26 . 728AB52393206408EFAD838F797F435D . 662016 . . [6.00.2900.3676] . . c:\windows\system32\dllcache\wininet.dll
[-] 2010-02-26 . B42B5BCCDB9853F480FDBB80E5604C30 . 668672 . . [6.00.2900.3676] . . c:\windows\$hf_mig$\KB980182\SP2QFE\wininet.dll
[-] 2010-02-26 . 6F0C67BA6837D82E2366AEAD046FAF4C . 667136 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3GDR\wininet.dll
[-] 2010-02-26 . AEB15B107E1C6543F99D9104BE0DD800 . 668672 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3QFE\wininet.dll
[-] 2009-12-22 . A59054653A2DA13132BE377A650971C9 . 662016 . . [6.00.2900.3660] . . c:\windows\$NtUninstallKB980182$\wininet.dll
[-] 2009-12-22 . 3E617A36A895363FBBE6D1D0405D7E12 . 668672 . . [6.00.2900.3660] . . c:\windows\$hf_mig$\KB978207\SP2QFE\wininet.dll
[-] 2009-12-22 . 814C265012ED921443C515A591D5BFE1 . 667136 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3GDR\wininet.dll
[-] 2009-12-22 . BD27AF5C72D2FBFE491D3A3A8429B974 . 668672 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\wininet.dll
[-] 2009-10-29 . 228ECFDD44D2D9234BDC6E3FA749AE99 . 662016 . . [6.00.2900.3640] . . c:\windows\$NtUninstallKB978207$\wininet.dll
[-] 2009-10-29 . 3839BD07F2C693EFE995F96BAAB7F4BF . 667136 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3GDR\wininet.dll
[-] 2009-10-29 . 6AC4AA42CC9AAEFAB1D5E4E2AF2E3D2B . 668672 . . [6.00.2900.5897] . . c:\windows\$hf_mig$\KB976325\SP3QFE\wininet.dll
[-] 2009-10-29 . DF1F2953B7983F9630CD658899826344 . 668672 . . [6.00.2900.3640] . . c:\windows\$hf_mig$\KB976325\SP2QFE\wininet.dll
[-] 2009-09-25 . C48F75D1733A4725C0F90430D44F56E2 . 662016 . . [6.00.2900.3627] . . c:\windows\$NtUninstallKB976325$\wininet.dll
[-] 2009-09-25 . AE710BE3F4A9F9B0948C3183D49717A0 . 668672 . . [6.00.2900.3627] . . c:\windows\$hf_mig$\KB974455\SP2QFE\wininet.dll
[-] 2009-09-25 . 178CF0F58C9907633AAB633860B68973 . 667136 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3GDR\wininet.dll
[-] 2009-09-25 . 406D33F9B30FFC0EEFC7C55562839931 . 668672 . . [6.00.2900.5880] . . c:\windows\$hf_mig$\KB974455\SP3QFE\wininet.dll
[-] 2009-06-26 . 70FFEA4793D7139A447B169CB0E500BC . 666624 . . [6.00.2900.5835] . . c:\windows\$hf_mig$\KB972260\SP3GDR\wininet.dll
[-] 2009-06-26 . 8553E6D4EC1563277323E6B2D6FBB954 . 668160 . . [6.00.2900.5835] . . c:\windows\$hf_mig$\KB972260\SP3QFE\wininet.dll
[-] 2009-06-26 . ED97493090DA8871F4EB76E1FF3F6A78 . 659456 . . [6.00.2900.3592] . . c:\windows\$NtUninstallKB974455$\wininet.dll
[-] 2009-06-26 . CF0B7B2738BEF0EB87673393CB7EA06E . 668160 . . [6.00.2900.3592] . . c:\windows\$hf_mig$\KB972260\SP2QFE\wininet.dll
[-] 2008-04-14 . 7A4F775ABB2F1C97DEF3E73AFA2FAEDD . 666112 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\wininet.dll
[-] 2004-08-04 . C0823FC5469663BA63E7DB88F9919D70 . 656384 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB972260$\wininet.dll
[-] 2004-08-04 . C0823FC5469663BA63E7DB88F9919D70 . 656384 . . [6.00.2900.2180] . . c:\windows\SoftwareDistribution\Download\ec0cabbd82acaeb42e692fe1035bccdb\backup\sp2gdr\wininet.dll
[-] 2004-08-04 . C0823FC5469663BA63E7DB88F9919D70 . 656384 . . [6.00.2900.2180] . . c:\windows\SoftwareDistribution\Download\ec0cabbd82acaeb42e692fe1035bccdb\backup\sp2qfe\wininet.dll
[-] 2004-08-04 . C0823FC5469663BA63E7DB88F9919D70 . 656384 . . [6.00.2900.2180] . . c:\windows\SoftwareDistribution\Download\ec0cabbd82acaeb42e692fe1035bccdb\backup\sp3gdr\wininet.dll
[-] 2004-08-04 . C0823FC5469663BA63E7DB88F9919D70 . 656384 . . [6.00.2900.2180] . . c:\windows\SoftwareDistribution\Download\ec0cabbd82acaeb42e692fe1035bccdb\backup\sp3qfe\wininet.dll

[-] 2008-04-14 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ws2_32.dll
[-] 2004-08-04 . 2ED0B7F12A60F90092081C50FA0EC2B2 . 82944 . . [5.1.2600.2180] . . c:\windows\system32\ws2_32.dll
[-] 2004-08-04 . 2ED0B7F12A60F90092081C50FA0EC2B2 . 82944 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ws2_32.dll

[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
[-] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\explorer.exe
[-] 2004-08-04 . A0732187050030AE399B241436565E64 . 1032192 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\explorer.exe

[-] 2008-04-14 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\srsvc.dll
[-] 2004-08-04 . 92BDF74F12D6CBEC43C94D4B7F804838 . 170496 . . [5.1.2600.2180] . . c:\windows\system32\srsvc.dll
[-] 2004-08-04 . 92BDF74F12D6CBEC43C94D4B7F804838 . 170496 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\srsvc.dll

[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\wscntfy.exe
[-] 2004-08-04 . 49911DD39E023BB6C45E4E436CFBD297 . 13824 . . [5.1.2600.2180] . . c:\windows\system32\wscntfy.exe
[-] 2004-08-04 . 49911DD39E023BB6C45E4E436CFBD297 . 13824 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\wscntfy.exe

[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\xmlprov.dll
[-] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\system32\xmlprov.dll
[-] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\xmlprov.dll

[-] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[-] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\system32\eventlog.dll
[-] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\eventlog.dll

[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sfcfiles.dll
[-] 2004-08-04 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
[-] 2004-08-04 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\sfcfiles.dll

[-] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ctfmon.exe
[-] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe
[-] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ctfmon.exe

[-] 2008-04-14 . 1926899BF9FFE2602B63074971700412 . 135168 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\shsvcs.dll
[-] 2004-08-04 . E7518DC542D3EBDCB80EDD98462C7821 . 134656 . . [6.00.2900.2180] . . c:\windows\system32\shsvcs.dll
[-] 2004-08-04 . E7518DC542D3EBDCB80EDD98462C7821 . 134656 . . [6.00.2900.2180] . . c:\windows\system32\dllcache\shsvcs.dll

[-] 2008-04-14 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\regsvc.dll
[-] 2004-08-04 . 3151427DB7D87107D1C5BE58FAC53960 . 59904 . . [5.1.2600.2180] . . c:\windows\system32\regsvc.dll
[-] 2004-08-04 . 3151427DB7D87107D1C5BE58FAC53960 . 59904 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\regsvc.dll

[-] 2008-04-14 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\schedsvc.dll
[-] 2004-08-04 . 92360854316611F6CC471612213C3D92 . 190976 . . [5.1.2600.2180] . . c:\windows\system32\schedsvc.dll
[-] 2004-08-04 . 92360854316611F6CC471612213C3D92 . 190976 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\schedsvc.dll

[-] 2008-04-14 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ssdpsrv.dll
[-] 2004-08-04 . 4B8D61792F7175BED48859CC18CE4E38 . 71680 . . [5.1.2600.2180] . . c:\windows\system32\ssdpsrv.dll
[-] 2004-08-04 . 4B8D61792F7175BED48859CC18CE4E38 . 71680 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ssdpsrv.dll

[-] 2008-04-14 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\termsrv.dll
[-] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\system32\termsrv.dll
[-] 2004-08-04 . B60C877D16D9C880B952FDA04ADF16E6 . 295424 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\termsrv.dll

[-] 2008-04-14 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\appmgmts.dll
[-] 2004-08-04 . 9C3C12975C97119412802B181FBEEFFE . 167936 . . [5.1.2600.2180] . . c:\windows\system32\appmgmts.dll
[-] 2004-08-04 . 9C3C12975C97119412802B181FBEEFFE . 167936 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\appmgmts.dll

[-] 2004-08-04 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys

[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\aec.sys
[-] 2004-08-03 22:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\system32\drivers\aec.sys

[-] 2008-04-13 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[-] 2004-08-03 . 2C428FA0C3E3A01ED93C9B2A27D8D4BB . 42368 . . [5.1.2600.2180] . . c:\windows\system32\drivers\AGP440.SYS

[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ip6fw.sys
[-] 2004-08-04 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\ip6fw.sys
[-] 2004-08-04 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ip6fw.sys

[-] 2008-04-14 00:11 . CDDD4416B2B4C7295FE3FDB6DDE57E4E . 927504 . . [4.1.0.61] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\mfc40u.dll
[-] 2004-08-04 12:00 . DDF8D47ACF8FC3FE5F7F2B95C4D4D136 . 924432 . . [4.1.6140] . . c:\windows\system32\mfc40u.dll
[-] 2004-08-04 12:00 . DDF8D47ACF8FC3FE5F7F2B95C4D4D136 . 924432 . . [4.1.6140] . . c:\windows\system32\dllcache\mfc40u.dll

[-] 2008-04-14 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\msgsvc.dll
[-] 2004-08-04 . 95FD808E4AC22ABA025A7B3EAC0375D2 . 33792 . . [5.1.2600.2180] . . c:\windows\system32\msgsvc.dll
[-] 2004-08-04 . 95FD808E4AC22ABA025A7B3EAC0375D2 . 33792 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\msgsvc.dll

[-] 2008-04-14 00:12 . C7E39EA41233E9F5B86C8DA3A9F1E4A8 . 52224 . . [9.0.1.56] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\mspmsnsv.dll
[-] 2004-08-04 12:00 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\system32\mspmsnsv.dll
[-] 2004-08-04 12:00 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\system32\dllcache\mspmsnsv.dll

[-] 2010-02-17 . 1811AFC2FADB60B88947E3D08E250860 . 2063744 . . [5.1.2600.3670] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\SP2QFE\ntkrnlpa.exe
[-] 2010-02-16 . A046C627EC20456E2959B7BD628E1FD0 . 2066816 . . [5.1.2600.5938] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\SP3GDR\ntkrnlpa.exe
[-] 2010-02-16 . 1EE6B94ACA7BE115A1813BBCA65099A8 . 2058368 . . [5.1.2600.3670] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\SP2GDR\ntkrnlpa.exe
[-] 2010-02-16 . DED8B5A89B085284634502E9D75AC78C . 2066944 . . [5.1.2600.5938] . . c:\windows\SoftwareDistribution\Download\9d21500a4aa475547c4a2420fee1c623\SP3QFE\ntkrnlpa.exe
[-] 2009-12-08 . FFDCE1EEA79C678C40237D4E031E5B51 . 2066176 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe
[-] 2009-12-08 . A6683E23468776F75EB2D8C6A02AAD3B . 2066048 . . [5.1.2600.5913] . . c:\windows\$hf_mig$\KB977165\SP3GDR\ntkrnlpa.exe
[-] 2009-12-08 . 384B15FBDCE2A54089A922886DED4EA0 . 2057728 . . [5.1.2600.3654] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2009-12-08 . 384B15FBDCE2A54089A922886DED4EA0 . 2057728 . . [5.1.2600.3654] . . c:\windows\system32\ntkrnlpa.exe
[-] 2009-12-08 . 384B15FBDCE2A54089A922886DED4EA0 . 2057728 . . [5.1.2600.3654] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2009-12-08 . BC123D9238A0C9BB3D853E407EE77254 . 2063104 . . [5.1.2600.3654] . . c:\windows\$hf_mig$\KB977165\SP2QFE\ntkrnlpa.exe
[-] 2009-08-04 . 363B2BBEE0AEDC9E5433616D0AD0236A . 2066176 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe
[-] 2009-08-04 . 7437BA6F538E89381A2E3643AED296C7 . 2066048 . . [5.1.2600.5857] . . c:\windows\$hf_mig$\KB971486\SP3GDR\ntkrnlpa.exe
[-] 2009-08-04 . B0BD27AA04C1B8E857C1DADEF4EF2159 . 2057728 . . [5.1.2600.3610] . . c:\windows\$NtUninstallKB977165$\ntkrnlpa.exe
[-] 2009-08-04 . 97E912E94CCED4064F5DEEE5C25A9278 . 2062976 . . [5.1.2600.3610] . . c:\windows\$hf_mig$\KB971486\SP2QFE\ntkrnlpa.exe
[-] 2009-02-07 . 5BA7F2141BC6DB06100D0E5A732C617A . 2066048 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3GDR\ntkrnlpa.exe
[-] 2009-02-06 . 3006410E24772CC6953F0B5C01BEB35F . 2057728 . . [5.1.2600.3520] . . c:\windows\$NtUninstallKB971486$\ntkrnlpa.exe
[-] 2009-02-06 . 607352B9CB3D708C67F6039097801B5A . 2066176 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2009-02-06 . 9D832AF3FD1917DB0E1E8B2F000A2E3A . 2062976 . . [5.1.2600.3520] . . c:\windows\$hf_mig$\KB956572\SP2QFE\ntkrnlpa.exe
[-] 2008-04-13 . 109F8E3E3C82E337BB71B6BC9B895D61 . 2065792 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ntkrnlpa.exe
[-] 2004-08-04 . 947FB1D86D14AFCFFDB54BF837EC25D0 . 2056832 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe

[-] 2008-04-14 00:12 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ntmssvc.dll
[-] 2004-08-04 12:00 . B62F29C00AC55A761B2E45877D85EA0F . 435200 . . [5.1.2400.2180] . . c:\windows\system32\ntmssvc.dll
[-] 2004-08-04 12:00 . B62F29C00AC55A761B2E45877D85EA0F . 435200 . . [5.1.2400.2180] . . c:\windows\system32\dllcache\ntmssvc.dll

[-] 2008-04-14 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\upnphost.dll
[-] 2004-08-04 . 0546477BDE979E33294FE97F6B3DE84A . 185344 . . [5.1.2600.2180] . . c:\windows\system32\upnphost.dll
[-] 2004-08-04 . 0546477BDE979E33294FE97F6B3DE84A . 185344 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\upnphost.dll

[-] 2008-04-14 . 4D83ED8BDDEC431FC8AD907B47CFB6E3 . 367616 . . [5.3.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\dsound.dll
[-] 2004-08-04 . 55E148C01296696588EAFA425782C3E8 . 367616 . . [5.3.2600.2180] . . c:\windows\system32\dsound.dll
[-] 2004-08-04 . 55E148C01296696588EAFA425782C3E8 . 367616 . . [5.3.2600.2180] . . c:\windows\system32\dllcache\dsound.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
"SpybotSD TeaTimer"="d:\spybot - search & destroy\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 577536]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"HostManager"="c:\program files\Common Files\AOL\1254164638\ee\AOLSoftware.exe" [2008-06-24 41824]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 101136]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\Karen\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

c:\documents and settings\Luke\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1254164638\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1254164638\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [07/04/2010 21:58 162640]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07/04/2010 21:58 19024]
.
Contents of the 'Scheduled Tasks' folder

2010-04-22 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 15:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://www.myaolbroadband.co.uk
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-22 21:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(552)
c:\windows\system32\sirenacm.dll
.
Completion time: 2010-04-22 21:11:54
ComboFix-quarantined-files.txt 2010-04-22 20:11

Pre-Run: 230,989,824 bytes free
Post-Run: 1,694,875,648 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - B725116ED4611F95E26946C2C4838951


ADD-REMOVE PROGRAMS.txt


Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.1
Adobe Shockwave Player 11.5
AOL Broadband Toolbar 5.0
AOL Registration
AOL Uninstaller (Choose which Products to Remove)
Argente - Registry Cleaner 1.5.5.2
avast! Free Antivirus
CDDRV_Installer
ERUNT 1.1j
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Java™ 6 Update 16
Junk Mail filter update
KhalSetup
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MSVCRT
Nero 7 Premium
OGA Notifier 2.0.0048.0
Realtek AC'97 Audio
Revo Uninstaller 1.85
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB960003)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB959997)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office Word 2007 (KB956358)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
Segoe UI
Spybot - Search & Destroy
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Office 2007 (KB934391)
Update for Outlook 2007 Junk Email Filter (kb979895)
Update for Windows XP (KB898461)
Update for Windows XP (KB925720)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
Viewpoint Media Player
WebFldrs XP
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows XP Hotfix - KB885295


Back to you guys, thanks again.
Hi Bluespoons61,

Looks like we removed a fair bit. Some questions before we continue.

What are drives D:\, E:\, amd F:\ ?

Did you attempt to install Windows XP Service Pack 3?

How is the computer?

Thanks
oldman 960 thanks for getting back to me on this. this computer came with a partitioned hard drive, split into c, d, e and f. not exactly sure why. I'm fairly certain something nasty lurks in one of them from last time a computer literate friend attempted to assist me with this. I have no recollection of installing service pack 3, however my sons mainly use this computer as I have my own lap top and they may have done so. Windows is currently telling me this is an unauthorised copy, although it was installed from a licensed disc. performance wise I have 600mb of free space, before it was always about 150-200 mb and constantly asking me to free up space but I havent used this pc frequently enough to give you a more accurate assessment. avast was recently installed but is now telling me it has not downloaded properly. Hope this helps Thanks again
Hi bluespoons61,

Each one of those drives were infected. 600mb free is not very much. How big is C:\?

We need to disable a program while we are cleaning this computer.

SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done and reboot your computer.
(When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]



Let's make sure all Mcafee is removed.

-Download and run MCPR.exe
-Download the removal tool from: http://download.mcafee.com/products/licens…atches/MCPR.exe

-Click Save and save the file to your desktop.

-Double-click MCPR.exe to run the removal tool.

-Restart your computer after receiving the message CleanUp Successful.
Your McAfee product will not be fully removed until the system is restarted.



Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • Make sure all drives are selected
  • Click Start Scan
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Go here to download a new copy of Avast free and save it to your desktop.

Also download the avast uninstaller from HERE just in case you can not uninstall it via add/remove programs. Please review the instructions found there.


Disconnect completely from the internet (pull the plug if you need to) and uninstall Avast. Reboot your computer and install the new version by double clicking the installation file you previously downloaded.

Please post back with the MBAM log. Is avast now working properly?

Thanks
Oldman, Hi Have followed all your suggested steps up to and including running Malwarebytes, here's the log Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 4036 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 26/04/2010 00:37:10 mbam-log-2010-04-26 (00-37-10).txt Scan type: Full scan (C:\|D:\|E:\|F:\|) Objects scanned: 252368 Time elapsed: 47 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 171 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Qoobox\Quarantine\D\0fkk02x.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\0fpdq2dw.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\1a1dndah.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\1hqup.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\2id9.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\3n8awsyg.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\9b9w3.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\9d6tpg.exe.vir (Trojan.PWS) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\9fo3ar0j.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\9g86.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\9jyhdim8.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\anoataly.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\b00ijwpu.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\c2e.exe.vir (Spyware.OnLineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\ctu8r.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\curqp.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\eexyv.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\fk.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\hjvjte.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\k8jc.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\l61yyp.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\lphfa.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\mbdm.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\mbvd.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\mranjm.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\mvmdh.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\mwfubaob.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\nds0q.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\nqdymj.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\nx.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\p3vwxx.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\pbudsara.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\qbr2q.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\r2g20.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\g12g.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\s1.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\s3ek.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\se12ydam.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\srgo.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\sywyrl0q.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\t2hjo0.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\tgt.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\uqgvf.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\vk0w.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\wcgswa.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\wfx062.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\wu1n.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\xmor.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\D\yu3.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\0fkk02x.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\0fpdq2dw.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\1a1dndah.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\1hqup.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\2id9.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\3n8awsyg.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\9b9w3.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\9d6tpg.exe.vir (Trojan.PWS) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\9fo3ar0j.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\9g86.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\9jyhdim8.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\anoataly.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\b00ijwpu.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\c2e.exe.vir (Spyware.OnLineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\ctu8r.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\curqp.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\eexyv.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\fk.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\hjvjte.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\k8jc.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\l61yyp.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\lphfa.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\mbdm.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\mbvd.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\mranjm.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\mvmdh.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\mwfubaob.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\nds0q.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\nqdymj.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\nx.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\p3vwxx.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\pbudsara.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\qbr2q.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\r2g20.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\g12g.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\s1.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\s3ek.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\se12ydam.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\srgo.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\sywyrl0q.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\t2hjo0.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\tgt.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\uqgvf.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\vk0w.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\wcgswa.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\wfx062.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\wu1n.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\xmor.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\E\yu3.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\0fkk02x.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\0fpdq2dw.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\1a1dndah.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\1hqup.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\2id9.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\3n8awsyg.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\9b9w3.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\9d6tpg.exe.vir (Trojan.PWS) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\9fo3ar0j.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\9g86.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\9jyhdim8.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\anoataly.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\b00ijwpu.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\c2e.exe.vir (Spyware.OnLineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\ctu8r.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\curqp.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\eexyv.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\fk.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\hjvjte.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\k8jc.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\l61yyp.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\lphfa.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\mbdm.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\mbvd.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\mranjm.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\mvmdh.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\mwfubaob.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\nds0q.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\nqdymj.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\nx.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\p3vwxx.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\pbudsara.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\qbr2q.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\r2g20.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\g12g.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\s1.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\s3ek.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\se12ydam.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\srgo.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\sywyrl0q.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\t2hjo0.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\tgt.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\uqgvf.exe.vir (Worm.Taterf) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\vk0w.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\wcgswa.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\wfx062.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\wu1n.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\xmor.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\F\yu3.exe.vir (Spyware.OnlineGames) -> Quarantined and deleted successfully. D:\1di1w.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. D:\2sm66r.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. D:\31lyx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. D:\6ruaqx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. D:\vb0hsoay.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. D:\rg9g9bgq.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. D:\f9o8o.exe (Worm.Taterf) -> Quarantined and deleted successfully. E:\rg9g9bgq.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. E:\f9o8o.exe (Worm.Taterf) -> Quarantined and deleted successfully. E:\1di1w.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. E:\ycvvj.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. E:\2sm66r.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. E:\vb0hsoay.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. E:\6ruaqx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. E:\31lyx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. F:\rg9g9bgq.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. F:\f9o8o.exe (Worm.Taterf) -> Quarantined and deleted successfully. F:\1di1w.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. F:\ycvvj.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. F:\2sm66r.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. F:\vb0hsoay.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. F:\6ruaqx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. F:\31lyx.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully. F:\Luke\My Documents\My Music\MyFunCardsSetup2.3.50.26.ZUman000.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. Will re-load Avast at earliest opportunity, well past midnight here now though. FYI, hard drive partitioned into chunks of around 9.5gb as follows c; 9.58 d; 9.49 e; 9.48 f; 9.75 have struggled to clean the c drive properly since infection, just 'filled up' every useage, sometimes two or three times per useage. Thanks for your continued support.
Hi bluespoons61,

Looks like MBAM got some more on the other drives. The detections on C:\ were files we have all ready quarantined.

Because of the type of infection found I suggest you change all of your passwords to any forums or online accounts you have including gaming forums. Use a known clean computer to do this.

This was an autorun infection so we can a little something to prevent it from happening again.

Even though it says flashhdrives, this next tool will do the same for hard drives and all partitions on the hard drive.

Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

FYI, hard drive partitioned into chunks of around 9.5gb as follows
c; 9.58
d; 9.49
e; 9.48
f; 9.75

have struggled to clean the c drive properly since infection, just 'filled up' every useage, sometimes two or three times per useage.

Is C:\ still filling up?. Windows defragmentor needs about 1.6GB to defrag a drive the size of C:\.

Let me kow how you make out with Avast.

Thanks
Oldman, you're a gent - C; appears to have stabilised, PC is running faster, the internet has stopped falling off for no reason and Avast is up and running again. I also now have access to hidden folders, which were previously being denied by something that you appear to got rid of. Am going away on business for three days, will review on my return and start cleaning up the C drive of unnecessary items. (I have followed all your suggestions up to and including Flash Disinfector.) Of all the clean-up tools I have downloaded onto my computer from your tutorial are there anything you feel I should keep for longer term use? I presume the contents of qoobox can now be deleted? Can't thank you enough, so grateful for your assistance. :D
Hi bluespoons81,

Glad to hear things are running smoother.


Of all the clean-up tools I have downloaded onto my computer from your tutorial are there anything you feel I should keep for longer term use? I presume the contents of qoobox can now be deleted?

Try out the computer for a couple of days. Qoobox will be removed when we remove the tools in the proper manner. I will make some suggestions at that time also.

Please post back when you return and if all is well we will clean up the tools.
Back home now; will try and get some serious housekeeping done over the holiday weekend and post again with an update on performance and reliability. Thanks again for all your help so far.
error message on shutting down End program - servicehost.defaultGrp is not responding Something or nothing do you think? Thanks
Hi bluespoons61,

That's usually a sign that something doesn't want to shut down quietly. Norton, McAfee and AOL are in the list of usual suspects.

When did this start happening?

Since you uninstalled McAfee we can run the removal tool to make sure there aren't any remnants.

Download the removal tool from: http://download.mcafee.com/products/licens…atches/MCPR.exe

-Click Save and save the file to your desktop.
-Double-click MCPR.exe to run the removal tool.

Restart your computer after receiving the message CleanUp Successful.
Your McAfee product will not be fully removed until the system is restarted.
Regular users of this pc tell me it has been happening for a while, but not all the time… certainly started before you began helping us, so the two probably aren't linked - more likely (based off what you said in a previous post) it is because AOL are our ISP. Do you still recommend another attempt to rid the system of McAfee based on this additonal information or another course of action?
Hi bluespoons81,

Do you still recommend another attempt to rid the system of McAfee based on this additonal information or another course of action?

Did you run the McAfee uninstaller? If not run it now.

Let's clean up the tools and I'll see if I can find any more info on that error. If not I'll refer you one of our Tech forums for further assistance.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • MCPR.exe (if you haven't used it yet, please do so before deleting)
  • GMER.exe (i91vxye6.exe)
  • DDS.scr

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall

I suggest you keep MBAM, keep it updated and use it regularly.

You can also keep FDD. Use it when you add a new USB storage device to your collection.

Updates and upgrades

Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader Adobe Reader 8.1.1 first. Be sure to move any PDF documents to another folder first though.

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware,IMO)

Or you may find another to your liking in the link to some addional information that I have posted further down.


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.

- Keep your antivirus program updated, as well as any other security programs you have.

-Check this site out to check for out of date programs
Secunia Personal Software Inspector (PSI) 1.0

-More tips and programs can be found HERE

- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

I'll see what I can find for the error.
OK sir, more help needed - started with the MCPR.exe tool but got the message 'Incomplete cleanup'. Log here MCAFEE CLEANUP April 25, 2010 23:31:57 INFO Cleanup will be scheduled and run. INFO Product mpfpcu to be removed from system. INFO Product mpfp to be removed from system. INFO Product mps to be removed from system. INFO Product shred to be removed from system. INFO Product mpscu to be removed from system. INFO Product mskcu to be removed from system. INFO Product msk to be removed from system. INFO Product emproxy to be removed from system. INFO Product mas to be removed from system. INFO Product fwdriver to be removed from system. INFO Product hw to be removed from system. INFO Product mbk to be removed from system. INFO Product mcproxy to be removed from system. INFO Product mhn to be removed from system. INFO Product mqccu to be removed from system. INFO Product mqc to be removed from system. INFO Product shrd to be removed from system. INFO Product nmc to be removed from system. INFO Product redir to be removed from system. INFO Product mna to be removed from system. INFO Product mwl to be removed from system. INFO Product msad to be removed from system. INFO Product mobk to be removed from system. INFO Product vs to be removed from system. INFO Product msc to be removed from system. INFO Product mcpr to be removed from system. INFO Product mcsvchost to be removed from system. ERROR Internal Error INFO Task Scheduler service started.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI