This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Still getting popup sites while on internet

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Okay… So I had Security Suite Virus on my computer. After a lengthy removal process it is gone. But there is still an issue coming from it that I can't find for the life of me. In both IE8 and Firefox I am still getting websites popping up at random times. These websites usually don't exist in the eye of google when I search for them after closing out the window. Also Spybot, MalwareBytes, and AVG haven't come up with anything since getting rid of the initial infection.

This is my HijackThis log file:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:23:51 PM, on 8/14/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Ralink\Common\RaRegistry.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Ralink\Common\RaUI.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.toshiba.com/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/toshibadirect.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\DLACTRLW.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKUS\S-1-5-18\..\Run: [ZE18MW23GY] C:\WINDOWS\TEMP\Ylq.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ZE18MW23GY] C:\WINDOWS\TEMP\Ylq.exe (User 'Default user')
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\Ralink\Common\RaUI.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F0496EB-DA6E-4F6C-9A75-B64F3264BC96}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C2B5551-66B8-47A0-81EA-8BF5DFB5B319}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5296D1C-0456-4F13-8298-0CF334ACB00C}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{0F0496EB-DA6E-4F6C-9A75-B64F3264BC96}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\..\{0F0496EB-DA6E-4F6C-9A75-B64F3264BC96}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files\Ralink\Common\RaRegistry.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: StumbleUponUpdateService - stumbleupon.com - C:\Program Files\StumbleUpon\StumbleUponUpdateService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe

–
End of file - 11868 bytes

Any help would be greatly appreciated. I am on a Toshiba Satellite Laptop if that helps at all.
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Here is the MBR

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000001c

Kernel Drivers (total 162):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EE000 \WINDOWS\system32\hal.dll
0xF7C3E000 \WINDOWS\system32\KDCOM.DLL
0xF7B4E000 \WINDOWS\system32\BOOTVID.dll
0xF762A000 sphn.sys
0xF7C40000 \WINDOWS\System32\Drivers\WMILIB.SYS
0xF7612000 \WINDOWS\System32\Drivers\SCSIPORT.SYS
0xF75E4000 ACPI.sys
0xF75D3000 pci.sys
0xF773E000 ohci1394.sys
0xF774E000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xF775E000 isapnp.sys
0xF750D000 krpoicn.sys
0xF7B52000 compbatt.sys
0xF7B56000 \WINDOWS\system32\DRIVERS\BATTC.SYS
0xF7D06000 pciide.sys
0xF79BE000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF74EF000 pcmcia.sys
0xF776E000 MountMgr.sys
0xF74D0000 ftdisk.sys
0xF7C42000 dmload.sys
0xF74AA000 dmio.sys
0xF7B5A000 ACPIEC.sys
0xF7D07000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
0xF79C6000 PartMgr.sys
0xF777E000 VolSnap.sys
0xF7492000 atapi.sys
0xF7460000 KR10N.sys
0xF778E000 disk.sys
0xF779E000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7440000 fltmgr.sys
0xF742E000 sr.sys
0xF7418000 DRVMCDB.SYS
0xF79CE000 PxHelp20.sys
0xF7401000 KSecDD.sys
0xF73EE000 WudfPf.sys
0xF7361000 Ntfs.sys
0xF7334000 NDIS.sys
0xF731A000 Mup.sys
0xF77BE000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xF6A1D000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF7C2E000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0xF6882000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
0xF686E000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF6846000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF66E9000 \SystemRoot\system32\DRIVERS\w39n51.sys
0xF7AB6000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF66C5000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF7ABE000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF669D000 \SystemRoot\system32\drivers\tifm21.sys
0xF6689000 \SystemRoot\system32\DRIVERS\sdbus.sys
0xF6661000 \SystemRoot\system32\DRIVERS\e100b325.sys
0xF6A0D000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF7AC6000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF6632000 \SystemRoot\system32\DRIVERS\SynTP.sys
0xF7C64000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF7ACE000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF69FD000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF7AD6000 \SystemRoot\system32\drivers\iviaspi.sys
0xF7C32000 \SystemRoot\system32\drivers\pfc.sys
0xF7C66000 \SystemRoot\System32\Drivers\DLACDBHM.SYS
0xF69ED000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF69DD000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF660F000 \SystemRoot\system32\DRIVERS\ks.sys
0xF65D6000 \SystemRoot\System32\Drivers\a2fbbdh6.SYS
0xF7D7D000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF790E000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF72C5000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF65BF000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF791E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF792E000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF7A5E000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF65AE000 \SystemRoot\system32\DRIVERS\psched.sys
0xF793E000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7A6E000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF7A7E000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF657E000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF798E000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7C7A000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF6520000 \SystemRoot\system32\DRIVERS\update.sys
0xF72AD000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF72A9000 \SystemRoot\system32\DRIVERS\tbiosdrv.sys
0xF7C7C000 \SystemRoot\system32\DRIVERS\NBSMI.sys
0xF799E000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xAA3B3000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xAA38F000 \SystemRoot\system32\drivers\portcls.sys
0xF77DE000 \SystemRoot\system32\drivers\drmk.sys
0xF77EE000 \SystemRoot\system32\DRIVERS\Tvs.sys
0xF7AAE000 \SystemRoot\system32\DRIVERS\tsxt_kern_i386.sys
0xF7AE6000 \SystemRoot\system32\DRIVERS\wowhd_kern_i386.sys
0xF77FE000 \SystemRoot\system32\DRIVERS\csiidecoder_kern_i386.sys
0xAA27C000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0xF7AEE000 \SystemRoot\System32\Drivers\Modem.SYS
0xF782E000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7CCE000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7E3A000 \SystemRoot\System32\Drivers\Null.SYS
0xF7CD0000 \SystemRoot\System32\Drivers\Beep.SYS
0xF7B26000 \SystemRoot\System32\Drivers\DLARTL_N.SYS
0xF7B2E000 \SystemRoot\System32\drivers\vga.sys
0xF7CD2000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7CD4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xAA21B000 \SystemRoot\System32\Drivers\meiudf.sys
0xAA20A000 \SystemRoot\System32\Drivers\Udfs.SYS
0xF7B36000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF7B3E000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF6508000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xAA1F7000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xAA19E000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xAA164000 \SystemRoot\System32\Drivers\avgtdix.sys
0xAA13E000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF785E000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF786E000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xAA0EE000 \SystemRoot\system32\DRIVERS\netbt.sys
0xAA0CC000 \SystemRoot\System32\drivers\afd.sys
0xF6A5D000 \SystemRoot\system32\DRIVERS\netbios.sys
0xAA001000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xA9F91000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF6A4D000 \SystemRoot\System32\Drivers\Fips.SYS
0xF7A46000 \SystemRoot\System32\Drivers\avgmfx86.sys
0xA9F5D000 \SystemRoot\System32\Drivers\avgldx86.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xF72E1000 \SystemRoot\System32\drivers\Dxapi.sys
0xF7AFE000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7D6D000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF020000 \SystemRoot\System32\ialmdnt5.dll
0xBF012000 \SystemRoot\System32\ialmrnt5.dll
0xBF042000 \SystemRoot\System32\ialmdev5.DLL
0xBF077000 \SystemRoot\System32\ialmdd5.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xF78BE000 \SystemRoot\System32\Drivers\DRVNDDM.SYS
0xF7E1A000 \SystemRoot\System32\DLA\DLADResN.SYS
0xA9DDF000 \SystemRoot\System32\DLA\DLAIFS_M.SYS
0xA9E69000 \SystemRoot\System32\DLA\DLAOPIOM.SYS
0xF7C94000 \SystemRoot\System32\DLA\DLAPoolM.SYS
0xF7A36000 \SystemRoot\System32\DLA\DLABOIOM.SYS
0xA9DC7000 \SystemRoot\System32\DLA\DLAUDFAM.SYS
0xA9DB1000 \SystemRoot\System32\DLA\DLAUDF_M.SYS
0xF7B46000 \SystemRoot\system32\DRIVERS\AegisP.sys
0xA9D5D000 \SystemRoot\system32\DRIVERS\s24trans.sys
0xF7A66000 \SystemRoot\System32\Drivers\Scutum50.sys
0xA9B06000 \SystemRoot\system32\DRIVERS\RT61.sys
0xA9BD9000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA9BD1000 \SystemRoot\system32\DRIVERS\netdevio.sys
0xA98F9000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF7CC8000 \SystemRoot\System32\Drivers\ASCTRM.SYS
0xA9700000 \SystemRoot\System32\Drivers\HTTP.sys
0xF7A9E000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xA94C5000 \SystemRoot\system32\DRIVERS\srv.sys
0xA9398000 \SystemRoot\system32\drivers\wdmaud.sys
0xA93FD000 \SystemRoot\system32\drivers\sysaudio.sys
0xF787E000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xA8794000 \SystemRoot\system32\DRIVERS\DKRtWrt.sys
0xA833B000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xA7AD1000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xA8D6C000 \SystemRoot\system32\DRIVERS\NuidFltr.sys
0xA7F18000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
0xA7497000 \SystemRoot\system32\DRIVERS\Wdf01000.sys
0xA98E9000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xA65B4000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
0x10000000 \Program Files\DAEMON Tools Lite\Engine.dll

Processes (total 73):
0 System Idle Process
4 System
808 C:\WINDOWS\system32\smss.exe
880 csrss.exe
904 C:\WINDOWS\system32\winlogon.exe
952 C:\WINDOWS\system32\services.exe
964 C:\WINDOWS\system32\lsass.exe
1160 C:\WINDOWS\system32\svchost.exe
1228 svchost.exe
1272 C:\WINDOWS\system32\svchost.exe
1324 C:\WINDOWS\system32\svchost.exe
1380 C:\Program Files\AVG\AVG9\avgchsvx.exe
1392 C:\Program Files\AVG\AVG9\avgrsx.exe
1492 C:\Program Files\AVG\AVG9\avgcsrvx.exe
1588 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
1840 C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
220 svchost.exe
236 svchost.exe
644 C:\WINDOWS\system32\spoolsv.exe
724 svchost.exe
764 C:\Program Files\AVG\AVG9\avgwdsvc.exe
800 C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
1180 C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
1320 C:\WINDOWS\system32\DVDRAMSV.exe
1388 C:\WINDOWS\ehome\ehrecvr.exe
2004 C:\WINDOWS\ehome\ehSched.exe
516 C:\Program Files\AVG\AVG9\avgnsx.exe
524 C:\Program Files\Java\jre6\bin\jqs.exe
2208 C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
2612 C:\WINDOWS\system32\PnkBstrA.exe
2792 C:\WINDOWS\explorer.exe
2960 C:\WINDOWS\system32\PSIService.exe
3116 C:\Program Files\Ralink\Common\RaRegistry.exe
3156 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
3232 svchost.exe
3256 C:\WINDOWS\system32\svchost.exe
3436 C:\TOSHIBA\IVP\swupdate\swupdtmr.exe
3496 C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
3656 mcrdsvc.exe
1456 C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
3200 C:\WINDOWS\system32\TDispVol.exe
3340 C:\WINDOWS\system32\igfxtray.exe
3388 C:\WINDOWS\system32\hkcmd.exe
3492 C:\WINDOWS\system32\igfxpers.exe
3616 C:\WINDOWS\ehome\ehtray.exe
3636 C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe
3036 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
3692 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3700 C:\Program Files\ltmoh\ltmoh.exe
3708 C:\WINDOWS\agrsmmsg.exe
3948 C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
3964 C:\WINDOWS\system32\DLA\DLACTRLW.EXE
3976 C:\Program Files\Synaptics\SynTP\Toshiba.exe
4008 C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
360 C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
584 C:\PROGRA~1\AVG\AVG9\avgtray.exe
1376 C:\Program Files\QuickTime\qttask.exe
1952 C:\WINDOWS\system32\TPSBattM.exe
1968 C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
1980 C:\WINDOWS\system32\ctfmon.exe
296 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
2348 C:\Program Files\Ralink\Common\RaUI.exe
2396 C:\WINDOWS\system32\RAMASST.exe
2744 C:\WINDOWS\system32\dllhost.exe
2120 C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
468 wmiprvse.exe
2648 alg.exe
5028 C:\WINDOWS\ehome\ehmsas.exe
3512 C:\WINDOWS\system32\svchost.exe
5264 C:\TOSHIBA\IVP\ISM\Ivpsvmgr.exe
5412 C:\Program Files\Mozilla Firefox\firefox.exe
5232 C:\WINDOWS\system32\wscntfy.exe
5924 C:\Documents and Settings\Aboluna\Desktop\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive0 Model Number: HTS541010G9SA00, Rev: MBZOC60R

Size Device Name MBR Status
——————————————–
93 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: 31D100779DE502702C374F7C15687B56FCFD5528


Done!



Here is the DDS

DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 11:47:24.54 on Sun 08/15/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.124 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Ralink\Common\RaRegistry.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\DLACTRLW.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Ralink\Common\RaUI.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Aboluna\Desktop\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://partnerpage.google.com/toshibadirect.com
uSearch Bar = hxxp://www.toshiba.com/search
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: StumbleUpon Launcher: {145b29f4-a56b-4b90-bbac-45784ebebbb7} - c:\program files\stumbleupon\StumbleUponIEBar.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: StumbleUpon Toolbar: {5093eb4c-3e93-40ab-9266-b607ba87bdc8} - c:\program files\stumbleupon\StumbleUponIEBar.dll
TB: Search Toolbar: {0c8413c1-fad1-446c-8584-be50576f863e} - c:\program files\search toolbar\tbcore3.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [RegistryBooster] "c:\program files\uniblue\registrybooster\launcher.exe" delay 20000
mRun: [TFncKy] TFncKy.exe
mRun: [TDispVol] TDispVol.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe
mRun: [TPSMain] TPSMain.exe
mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [dla] c:\windows\system32\dla\DLACTRLW.exe
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [ZE18MW23GY] c:\windows\temp\Ylq.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 208.67.220.220,208.67.222.222
TCP: {0F0496EB-DA6E-4F6C-9A75-B64F3264BC96} = 208.67.220.220,208.67.222.222
TCP: {3C2B5551-66B8-47A0-81EA-8BF5DFB5B319} = 208.67.220.220,208.67.222.222
TCP: {F5296D1C-0456-4F13-8298-0CF334ACB00C} = 208.67.220.220,208.67.222.222
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Notification Packages = scecli tolokovu.dll vapewezu.dll wikavoso.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\aboluna\applic~1\mozilla\firefox\profiles\3lmyblkw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.demonoid.com/
FF - prefs.js: keyword.URL - hxxp://search.search-go.net/?sid=10101049100&s=
FF - component: c:\documents and settings\aboluna\application data\mozilla\firefox\profiles\3lmyblkw.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\documents and settings\aboluna\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\aboluna\application data\mozilla\firefox\profiles\3lmyblkw.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\all users\application data\id software\quakelive\npquakezero.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.order.1 - Google
FF - user.js: keyword.URL - hxxp://search.search-go.net/?sid=10101049100&s=c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-11-23 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-11-23 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-11-23 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-14 308136]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\ralink\common\RaRegistry.exe [2009-11-23 185632]
R2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\drivers\Scutum50.sys [2009-11-23 19072]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [2010-5-9 41504]
S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\stumbleupon\StumbleUponUpdateService.exe [2010-4-7 120232]

=============== Created Last 30 ================

2010-08-15 15:52:19 0 –sha-w- C:\DkHyperbootSync
2010-08-15 01:45:44 0 d—–w- c:\program files\EA GAMES
2010-08-14 23:56:28 0 d—–w- c:\program files\Trend Micro
2010-08-14 23:29:38 0 d—–w- c:\docume~1\aboluna\applic~1\Uniblue
2010-08-14 05:05:28 0 d—–w- c:\program files\Wedding Dash 4 Ever
2010-08-13 03:39:29 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-13 03:39:26 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-13 03:39:26 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-13 03:20:37 0 d—–w- c:\program files\CCleaner
2010-08-12 03:01:47 783872 —-a-w- c:\windows\system32\drivers\krpoicn.sys
2010-08-12 03:01:07 0 d—–w- c:\docume~1\alluse~1\applic~1\Update
2010-08-11 23:02:56 54156 —ha-w- c:\windows\QTFont.qfn
2010-08-11 23:02:56 1409 —-a-w- c:\windows\QTFont.for
2010-08-08 03:05:21 0 d—–w- c:\docume~1\aboluna\applic~1\Jumb-O-Fun Games
2010-08-06 18:28:17 0 d—–w- c:\windows\Help32
2010-08-06 18:28:10 0 d—–w- c:\windows\system32\weber
2010-08-05 17:28:46 0 d—–w- c:\docume~1\alluse~1\applic~1\Toolbar4
2010-07-30 23:20:27 286720 ——w- c:\windows\Setup1.exe
2010-07-30 23:20:23 73216 —-a-w- c:\windows\ST6UNST.EXE
2010-07-29 05:21:10 5504 -c–a-w- c:\windows\system32\dllcache\mstee.sys
2010-07-29 05:21:10 5504 —-a-w- c:\windows\system32\drivers\MSTEE.sys
2010-07-29 05:21:05 10880 -c–a-w- c:\windows\system32\dllcache\ndisip.sys
2010-07-29 05:21:05 10880 —-a-w- c:\windows\system32\drivers\NdisIP.sys
2010-07-29 05:21:02 15232 -c–a-w- c:\windows\system32\dllcache\streamip.sys
2010-07-29 05:21:02 15232 —-a-w- c:\windows\system32\drivers\StreamIP.sys
2010-07-29 05:21:01 16384 -c–a-w- c:\windows\system32\dllcache\ipsink.ax
2010-07-29 05:21:01 16384 —-a-w- c:\windows\system32\ipsink.ax
2010-07-29 05:20:58 11136 -c–a-w- c:\windows\system32\dllcache\slip.sys
2010-07-29 05:20:58 11136 —-a-w- c:\windows\system32\drivers\SLIP.sys
2010-07-29 05:20:53 19200 -c–a-w- c:\windows\system32\dllcache\wstcodec.sys
2010-07-29 05:20:53 19200 —-a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2010-07-29 05:20:49 85248 -c–a-w- c:\windows\system32\dllcache\nabtsfec.sys
2010-07-29 05:20:49 85248 —-a-w- c:\windows\system32\drivers\NABTSFEC.sys
2010-07-29 05:20:46 17024 -c–a-w- c:\windows\system32\dllcache\ccdecode.sys
2010-07-29 05:20:46 17024 —-a-w- c:\windows\system32\drivers\CCDECODE.sys
2010-07-29 05:20:35 60032 -c–a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-07-29 05:20:35 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-07-29 05:20:01 0 d—–w- c:\windows\OvtCam
2010-07-29 05:19:59 91136 -c–a-w- c:\windows\system32\dllcache\kswdmcap.ax
2010-07-29 05:19:59 91136 —-a-w- c:\windows\system32\kswdmcap.ax
2010-07-29 05:19:59 61952 -c–a-w- c:\windows\system32\dllcache\kstvtune.ax
2010-07-29 05:19:59 61952 —-a-w- c:\windows\system32\kstvtune.ax
2010-07-29 05:19:59 53760 -c–a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-07-29 05:19:59 53760 —-a-w- c:\windows\system32\vfwwdm32.dll
2010-07-29 05:19:59 43008 -c–a-w- c:\windows\system32\dllcache\ksxbar.ax
2010-07-29 05:19:59 43008 —-a-w- c:\windows\system32\ksxbar.ax
2010-07-29 05:19:51 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-07-29 05:19:51 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2010-07-29 05:17:00 61440 —-a-w- c:\windows\ov519dib.dll
2010-07-29 05:17:00 40960 —-a-w- c:\windows\system32\ov519ext.dll
2010-07-29 05:17:00 25211 —-a-w- c:\windows\system32\drivers\ov519cmd.sys
2010-07-29 05:17:00 25099 —-a-w- c:\windows\system32\ov519ext.ax
2010-07-29 05:17:00 200704 —-a-w- c:\windows\sel3110.exe
2010-07-29 05:17:00 174530 —-a-w- c:\windows\system32\drivers\ov519vid.sys
2010-07-29 05:17:00 16426 —-a-w- c:\windows\system32\ov519usd.dll
2010-07-29 05:17:00 135168 —-a-w- c:\windows\ov519cap.exe
2010-07-29 05:16:58 40960 —-a-w- c:\windows\CleanDev.exe
2010-07-29 05:16:58 32528 —-a-w- c:\windows\amcap.exe
2010-07-29 05:16:58 307200 —-a-w- c:\windows\vidcap32.exe
2010-07-29 05:16:58 0 d—–w- c:\program files\GE
2010-07-26 02:27:36 8704 -c–a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-07-26 02:27:36 8704 —-a-w- c:\windows\system32\kbdjpn.dll
2010-07-26 02:27:36 8192 -c–a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-07-26 02:27:36 8192 —-a-w- c:\windows\system32\kbdkor.dll
2010-07-26 02:27:36 6144 -c–a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-07-26 02:27:36 6144 —-a-w- c:\windows\system32\kbd101c.dll
2010-07-26 02:27:36 5632 -c–a-w- c:\windows\system32\dllcache\kbd103.dll
2010-07-26 02:27:36 5632 —-a-w- c:\windows\system32\kbd103.dll
2010-07-26 02:27:25 6144 -c–a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-07-26 02:27:25 6144 —-a-w- c:\windows\system32\kbd101b.dll
2010-07-26 02:27:23 6144 -c–a-w- c:\windows\system32\dllcache\kbd106.dll
2010-07-26 02:27:23 6144 —-a-w- c:\windows\system32\kbd106.dll
2010-07-25 23:06:50 73728 —-a-w- c:\windows\system32\javacpl.cpl
2010-07-25 23:06:50 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-25 05:58:06 0 d—–w- c:\docume~1\aboluna\applic~1\StumbleUpon
2010-07-25 05:57:59 0 d—–w- c:\program files\StumbleUpon
2010-07-22 03:12:00 389120 –sh–w- c:\windows\Launcher.exe
2010-07-17 01:05:09 0 d—–w- C:\Westwood
2010-07-17 00:58:40 0 d—–w- c:\program files\DAEMON Tools Lite

==================== Find3M ====================

2010-08-11 23:02:40 2880 –sha-w- c:\windows\system32\KGyGaAvL.sys
2010-08-07 22:18:33 86016 —-a-w- c:\windows\system32\OpenAL32.dll
2010-08-07 22:18:33 262144 —-a-w- c:\windows\system32\wrap_oal.dll
2010-07-14 14:03:57 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-14 14:03:54 12536 —-a-w- c:\windows\system32\avgrsstx.dll
2010-07-14 14:02:34 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-12 17:42:02 2580 —-a-w- c:\docume~1\aboluna\applic~1\wklnhst.dat
2010-06-30 12:31:35 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-26 19:16:35 139336 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-06-26 19:16:14 214720 —-a-w- c:\windows\system32\PnkBstrB.exe
2010-06-25 20:12:44 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2010-06-25 20:12:44 2373712 —-a-w- c:\windows\system32\pbsvc.exe
2010-06-24 12:22:03 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44:04 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27:11 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03:00 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 —-a-w- c:\windows\system32\msxml3.dll
2010-06-08 01:04:14 4096 —-a-w- c:\windows\d3dx.dat
2009-12-07 18:39:05 88 –sh–r- c:\windows\system32\3457F750C5.sys
2009-11-28 06:55:16 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009112720091128\index.dat

============= FINISH: 11:49:38.97 ===============

Attached you will find the MBR Attach and the Dmer log.
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi

Please do the following;

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=113977

Collect::
c:\windows\system32\drivers\krpoicn.sys

Folder::
c:\documents and settings\NetworkService\Local Settings\Application Data\voafokrds

DirLook::
c:\windows\Help32
c:\windows\system32\weber
c:\documents and settings\Aboluna\Local Settings\Application Data\.#

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\krpoicn]

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


submit a file to virustotal for analysis
  • Use the browse button on that page to navigate to the location of the file to be scanned.
  • In the right hand panel,
  • click on the file c:\windows\Setup1.exe
  • then click the open button.
  • The file will now be displayed in the submit box.
  • Scroll down a bit and click "send file", wait for the results
  • If you get a message saying File has already been analyzed: click Reanalyze file now
  • Once scanned, copy and paste the link to the results page in your next reply.
Here is the ComboFix log

ComboFix 10-08-15.01 - Aboluna 08/15/2010 21:00:39.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.444 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Aboluna\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\windows\system32\drivers\krpoicn.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\NetworkService\Local Settings\Application Data\voafokrds
c:\windows\system32\drivers\krpoicn.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_krpoicn
——-\Service_krpoicn


((((((((((((((((((((((((( Files Created from 2010-07-16 to 2010-08-16 )))))))))))))))))))))))))))))))
.

2010-08-15 01:45 . 2010-08-15 01:45 ——– d—–w- c:\program files\EA GAMES
2010-08-14 23:56 . 2010-08-14 23:56 ——– d—–w- c:\program files\Trend Micro
2010-08-14 23:29 . 2010-08-14 23:29 ——– d—–w- c:\documents and settings\Aboluna\Application Data\Uniblue
2010-08-14 05:05 . 2010-08-14 05:05 ——– d—–w- c:\program files\Wedding Dash 4 Ever
2010-08-13 03:39 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-13 03:39 . 2010-08-13 03:39 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-13 03:39 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-13 03:26 . 2010-08-13 03:26 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-08-13 03:20 . 2010-08-13 03:20 ——– d—–w- c:\program files\CCleaner
2010-08-13 03:15 . 2010-08-13 03:15 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2010-08-13 03:15 . 2010-08-13 03:15 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-08-12 04:35 . 2010-08-12 04:35 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2010-08-12 04:35 . 2010-08-12 05:05 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\StumbleUpon
2010-08-12 04:34 . 2010-08-12 04:34 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-08-12 03:01 . 2010-08-13 05:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Update
2010-08-08 03:05 . 2010-08-08 03:05 ——– d—–w- c:\documents and settings\Aboluna\Application Data\Jumb-O-Fun Games
2010-08-06 18:28 . 2010-08-06 21:03 ——– d—–w- c:\windows\Help32
2010-08-06 18:28 . 2010-08-06 18:28 ——– d—–w- c:\windows\system32\weber
2010-07-30 23:20 . 2010-07-30 23:20 286720 ——w- c:\windows\Setup1.exe
2010-07-30 23:20 . 2010-07-30 23:20 73216 —-a-w- c:\windows\ST6UNST.EXE
2010-07-29 05:21 . 2008-04-13 15:39 5504 -c–a-w- c:\windows\system32\dllcache\mstee.sys
2010-07-29 05:21 . 2008-04-13 15:39 5504 —-a-w- c:\windows\system32\drivers\MSTEE.sys
2010-07-29 05:21 . 2008-04-13 15:46 10880 -c–a-w- c:\windows\system32\dllcache\ndisip.sys
2010-07-29 05:21 . 2008-04-13 15:46 10880 —-a-w- c:\windows\system32\drivers\NdisIP.sys
2010-07-29 05:21 . 2008-04-13 15:46 15232 -c–a-w- c:\windows\system32\dllcache\streamip.sys
2010-07-29 05:21 . 2008-04-13 15:46 15232 —-a-w- c:\windows\system32\drivers\StreamIP.sys
2010-07-29 05:20 . 2008-04-13 15:46 11136 -c–a-w- c:\windows\system32\dllcache\slip.sys
2010-07-29 05:20 . 2008-04-13 15:46 11136 —-a-w- c:\windows\system32\drivers\SLIP.sys
2010-07-29 05:20 . 2008-04-13 15:46 19200 -c–a-w- c:\windows\system32\dllcache\wstcodec.sys
2010-07-29 05:20 . 2008-04-13 15:46 19200 —-a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2010-07-29 05:20 . 2008-04-13 15:46 85248 -c–a-w- c:\windows\system32\dllcache\nabtsfec.sys
2010-07-29 05:20 . 2008-04-13 15:46 85248 —-a-w- c:\windows\system32\drivers\NABTSFEC.sys
2010-07-29 05:20 . 2008-04-13 15:46 17024 -c–a-w- c:\windows\system32\dllcache\ccdecode.sys
2010-07-29 05:20 . 2008-04-13 15:46 17024 —-a-w- c:\windows\system32\drivers\CCDECODE.sys
2010-07-29 05:20 . 2008-04-13 15:45 60032 -c–a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-07-29 05:20 . 2008-04-13 15:45 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-07-29 05:20 . 2010-07-29 05:20 ——– d—–w- c:\windows\OvtCam
2010-07-29 05:19 . 2008-04-13 21:12 53760 -c–a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-07-29 05:19 . 2008-04-13 21:12 53760 —-a-w- c:\windows\system32\vfwwdm32.dll
2010-07-29 05:19 . 2008-04-13 15:45 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-07-29 05:19 . 2008-04-13 15:45 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2010-07-29 05:17 . 2003-10-14 10:13 200704 —-a-w- c:\windows\sel3110.exe
2010-07-29 05:17 . 2003-09-25 07:00 61440 —-a-w- c:\windows\ov519dib.dll
2010-07-29 05:17 . 2003-09-25 07:00 40960 —-a-w- c:\windows\system32\ov519ext.dll
2010-07-29 05:17 . 2003-09-25 07:00 25211 —-a-w- c:\windows\system32\drivers\ov519cmd.sys
2010-07-29 05:17 . 2003-09-25 07:00 174530 —-a-w- c:\windows\system32\drivers\ov519vid.sys
2010-07-29 05:17 . 2003-09-25 07:00 16426 —-a-w- c:\windows\system32\ov519usd.dll
2010-07-29 05:17 . 2003-09-25 07:00 135168 —-a-w- c:\windows\ov519cap.exe
2010-07-29 05:16 . 2010-07-29 05:16 ——– d—–w- c:\program files\GE
2010-07-29 05:16 . 2003-09-25 07:00 307200 —-a-w- c:\windows\vidcap32.exe
2010-07-29 05:16 . 2003-06-02 13:35 40960 —-a-w- c:\windows\CleanDev.exe
2010-07-29 05:16 . 2002-07-07 20:15 32528 —-a-w- c:\windows\amcap.exe
2010-07-26 02:27 . 2001-08-18 03:36 8704 -c–a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-07-26 02:27 . 2001-08-18 03:36 8704 —-a-w- c:\windows\system32\kbdjpn.dll
2010-07-26 02:27 . 2001-08-18 03:36 8192 -c–a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-07-26 02:27 . 2001-08-18 03:36 8192 —-a-w- c:\windows\system32\kbdkor.dll
2010-07-26 02:27 . 2001-08-17 19:55 6144 -c–a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-07-26 02:27 . 2001-08-17 19:55 6144 —-a-w- c:\windows\system32\kbd101c.dll
2010-07-26 02:27 . 2001-08-17 19:55 5632 -c–a-w- c:\windows\system32\dllcache\kbd103.dll
2010-07-26 02:27 . 2001-08-17 19:55 5632 —-a-w- c:\windows\system32\kbd103.dll
2010-07-26 02:27 . 2001-08-17 19:55 6144 -c–a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-07-26 02:27 . 2001-08-17 19:55 6144 —-a-w- c:\windows\system32\kbd101b.dll
2010-07-26 02:27 . 2008-04-13 21:09 6144 -c–a-w- c:\windows\system32\dllcache\kbd106.dll
2010-07-26 02:27 . 2008-04-13 21:09 6144 —-a-w- c:\windows\system32\kbd106.dll
2010-07-25 23:06 . 2010-07-25 23:06 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-25 05:58 . 2010-08-15 15:06 ——– d—–w- c:\documents and settings\Aboluna\Application Data\StumbleUpon
2010-07-25 05:57 . 2010-07-25 05:58 ——– d—–w- c:\program files\StumbleUpon
2010-07-22 09:20 . 2010-07-22 09:38 ——– d-sh–w- c:\documents and settings\Aboluna\Local Settings\Application Data\.#
2010-07-22 03:12 . 2010-07-22 03:12 389120 –sh–w- c:\windows\Launcher.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 01:56 . 2009-11-24 00:20 ——– d—–w- c:\documents and settings\Aboluna\Application Data\uTorrent
2010-08-16 00:06 . 2010-04-19 07:11 ——– d—–w- c:\documents and settings\Aboluna\Application Data\vlc
2010-08-15 20:01 . 2009-11-27 18:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Soulseek
2010-08-15 04:23 . 2009-12-22 16:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-15 01:46 . 2006-02-15 16:20 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-14 23:56 . 2010-08-14 23:56 388096 —-a-r- c:\documents and settings\Aboluna\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-13 02:35 . 2006-02-25 07:02 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-11 23:02 . 2009-12-07 18:39 2880 –sha-w- c:\windows\system32\KGyGaAvL.sys
2010-08-08 21:58 . 2010-05-12 22:22 ——– d—–w- c:\program files\Steam
2010-08-07 22:18 . 2010-06-09 21:42 86016 —-a-w- c:\windows\system32\OpenAL32.dll
2010-08-07 22:18 . 2010-06-09 21:42 262144 —-a-w- c:\windows\system32\wrap_oal.dll
2010-08-06 18:28 . 2006-02-16 16:59 53432 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-05 18:15 . 2006-02-18 15:03 ——– d—–w- c:\program files\RGB
2010-07-25 23:08 . 2010-07-25 23:08 503808 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5b6fb651-n\msvcp71.dll
2010-07-25 23:08 . 2010-07-25 23:08 499712 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5b6fb651-n\jmc.dll
2010-07-25 23:08 . 2010-07-25 23:08 348160 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5b6fb651-n\msvcr71.dll
2010-07-25 23:07 . 2010-07-25 23:07 12800 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2e93519c-n\decora-d3d.dll
2010-07-25 23:07 . 2010-07-25 23:07 61440 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2e93519c-n\decora-sse.dll
2010-07-25 23:07 . 2006-02-16 09:28 ——– d—–w- c:\program files\Common Files\Java
2010-07-25 23:06 . 2006-02-16 09:28 ——– d—–w- c:\program files\Java
2010-07-17 00:58 . 2010-07-17 00:58 ——– d—–w- c:\program files\DAEMON Tools Lite
2010-07-14 14:03 . 2009-11-23 23:08 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-14 14:03 . 2010-07-14 14:03 12536 —-a-w- c:\windows\system32\avgrsstx.dll
2010-07-14 14:02 . 2009-11-23 23:08 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-13 02:39 . 2010-07-13 02:39 ——– d—–w- c:\documents and settings\Aboluna\Application Data\IBAGroup
2010-07-12 17:42 . 2009-12-01 23:24 2580 —-a-w- c:\documents and settings\Aboluna\Application Data\wklnhst.dat
2010-07-11 02:10 . 2010-07-11 02:10 ——– d—–w- c:\documents and settings\Aboluna\Application Data\NCH Swift Sound
2010-07-11 02:10 . 2010-07-11 02:10 ——– d—–w- c:\program files\NCH Swift Sound
2010-07-08 16:05 . 2010-07-08 16:05 129160 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-07-04 19:50 . 2010-07-04 19:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Gamers Digital
2010-07-04 19:50 . 2010-07-04 19:50 ——– d—–w- c:\documents and settings\Aboluna\Application Data\Gamers Digital
2010-07-02 17:28 . 2010-07-01 02:04 ——– d—–w- c:\documents and settings\Aboluna\Application Data\Be a King 2
2010-06-30 12:31 . 2006-02-15 14:03 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-26 19:16 . 2010-06-25 20:32 139336 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-06-26 19:16 . 2010-06-25 20:03 371776 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\baseq3\cgamex86.dll
2010-06-26 19:16 . 2010-06-25 20:03 187456 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\baseq3\uix86.dll
2010-06-26 19:16 . 2010-06-25 19:39 214720 —-a-w- c:\windows\system32\PnkBstrB.exe
2010-06-26 19:16 . 2010-06-25 20:03 887448 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\pb\pbcl.dll
2010-06-26 19:16 . 2010-06-25 20:03 57344 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\pb\pbag.dll
2010-06-26 19:16 . 2010-06-25 20:03 2436160 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\baseq3\quakelive.dll
2010-06-25 20:17 . 2010-06-25 20:03 465984 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\baseq3\qagamex86.dll
2010-06-25 20:12 . 2010-06-25 19:39 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2010-06-25 20:12 . 2010-06-25 19:39 2373712 —-a-w- c:\windows\system32\pbsvc.exe
2010-06-25 19:39 . 2010-06-25 19:39 ——– d—–w- c:\documents and settings\Aboluna\Application Data\id Software
2010-06-25 19:39 . 2010-06-25 19:39 ——– d—–w- c:\documents and settings\All Users\Application Data\id Software
2010-06-25 16:02 . 2009-12-15 22:03 ——– d—–w- c:\documents and settings\All Users\Application Data\PlayFirst
2010-06-25 16:02 . 2009-12-15 22:03 ——– d—–w- c:\documents and settings\Aboluna\Application Data\PlayFirst
2010-06-24 18:42 . 2010-06-24 18:42 ——– d—–w- c:\documents and settings\Aboluna\Application Data\YoudaGames
2010-06-24 12:22 . 2006-02-15 14:04 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2006-02-15 14:04 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-23 01:10 . 2010-06-23 01:10 ——– d—–w- c:\program files\NCH Software
2010-06-23 01:02 . 2010-06-23 01:02 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2010-06-23 00:42 . 2010-06-23 00:42 200 —-a-w- c:\windows\QCPC80UI.dat
2010-06-22 03:17 . 2010-06-22 03:17 5694 —-a-r- c:\documents and settings\Aboluna\Application Data\Microsoft\Installer\{CA8056BC-05E8-41FB-82C2-4750568CD379}\_86C6042DE7694DB98B69E7.exe
2010-06-22 03:17 . 2010-06-22 03:17 5694 —-a-r- c:\documents and settings\Aboluna\Application Data\Microsoft\Installer\{CA8056BC-05E8-41FB-82C2-4750568CD379}\_3DB404C70A7AFA578074FD.exe
2010-06-22 03:17 . 2010-06-22 03:17 ——– d—–w- c:\program files\MiniTheatre
2010-06-21 15:27 . 2006-02-15 14:04 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 14:58 . 2010-06-18 14:58 ——– d—–w- c:\documents and settings\All Users\Application Data\MythPeople
2010-06-17 14:33 . 2010-06-17 14:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Cateia Games
2010-06-17 14:03 . 2006-02-15 14:02 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 17:08 . 2010-06-21 16:18 545280 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\PicLensHelper.exe
2010-06-14 17:08 . 2010-06-21 16:18 4687360 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\cooliris192.dll
2010-06-14 17:08 . 2010-06-21 16:18 103424 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\pixomatic.dll
2010-06-14 17:08 . 2010-06-21 16:18 425984 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\LaunchCooliris.exe
2010-06-14 17:08 . 2010-06-21 16:18 152064 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2010-06-14 17:08 . 2010-06-21 16:18 4687872 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\cooliris190.dll
2010-06-14 17:08 . 2010-06-21 16:18 57856 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\components\coolirisstub.dll
2010-06-14 14:31 . 2006-02-15 15:36 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2006-02-15 14:03 1172480 —-a-w- c:\windows\system32\msxml3.dll
2010-06-09 22:07 . 2010-06-09 22:07 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-06-08 01:04 . 2010-06-08 01:04 4096 —-a-w- c:\windows\d3dx.dat
2010-06-02 13:55 . 2009-11-23 23:08 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-07 18:39 . 2009-12-07 18:39 88 –sh–r- c:\windows\system32\3457F750C5.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\Aboluna\Local Settings\Application Data\.# —-


—- Directory of c:\windows\Help32 —-

2010-08-06 20:58 . 2010-08-06 21:03 84 —-a-w- c:\windows\Help32\state.txt
2010-08-06 20:40 . 2010-08-06 20:41 20443 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\AE598F5Cd01
2010-08-06 20:40 . 2010-08-06 20:41 49661 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\DFD97C4Ad01
2010-08-06 20:40 . 2010-08-06 20:40 36064 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\105D09C7d01
2010-08-06 20:40 . 2010-08-06 20:40 27620 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\437383DEd01
2010-08-06 20:40 . 2010-08-06 20:40 20467 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\0A7309C7d01
2010-08-06 20:40 . 2010-08-06 20:40 57254 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\EEC96B3Ed01
2010-08-06 20:40 . 2010-08-06 20:40 34189 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\CFF82FA2d01
2010-08-06 20:40 . 2010-08-06 20:40 40647 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\9123C400d01
2010-08-06 20:40 . 2010-08-06 20:40 34101 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\870109CEd01
2010-08-06 20:40 . 2010-08-06 20:40 64841 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\E879F26Ed01
2010-08-06 20:40 . 2010-08-06 20:40 17531 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\E34CBB7Fd01
2010-08-06 20:40 . 2010-08-06 20:40 37892 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\27C0759Bd01
2010-08-06 20:40 . 2010-08-06 20:40 27620 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\8A1CFEB2d01
2010-08-06 20:40 . 2010-08-06 20:40 22854 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\650E650Ed01
2010-08-06 20:33 . 2010-08-06 20:33 19076 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\37C2F0D3d01
2010-08-06 20:33 . 2010-08-06 20:33 23889 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\2B38CFEFd01
2010-08-06 20:33 . 2010-08-06 20:33 69039 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\92B20517d01
2010-08-06 20:33 . 2010-08-06 20:33 106499 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\37FB9B46d01
2010-08-06 20:33 . 2010-08-06 20:33 50849 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\63196A21d01
2010-08-06 20:33 . 2010-08-06 20:33 48861 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\1FE8960Bd01
2010-08-06 20:33 . 2010-08-06 20:33 41142 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\45E0F999d01
2010-08-06 20:33 . 2010-08-06 20:33 37501 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\DE791729d01
2010-08-06 20:33 . 2010-08-06 20:33 48034 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\F1FFF418d01
2010-08-06 20:33 . 2010-08-06 20:33 35204 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\A76DAD3Ad01
2010-08-06 20:33 . 2010-08-06 20:33 45327 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\F449706Cd01
2010-08-06 20:33 . 2010-08-06 20:33 16556 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\97AB8031d01
2010-08-06 20:33 . 2010-08-06 20:33 50894 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\13E66A26d01
2010-08-06 20:32 . 2010-08-06 20:32 17229 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\43987B1Ad01
2010-08-06 20:32 . 2010-08-06 20:32 17074 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\43867B1Ad01
2010-08-06 20:32 . 2010-08-06 20:32 39991 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\1011F48Ed01
2010-08-06 20:32 . 2010-08-06 20:32 22270 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\15E18183d01
2010-08-06 20:32 . 2010-08-06 20:32 29510 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\29E3F48Ed01
2010-08-06 20:32 . 2010-08-06 20:32 41641 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\BB4F76E0d01
2010-08-06 20:32 . 2010-08-06 20:32 25137 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\7BD6A121d01
2010-08-06 20:32 . 2010-08-06 20:32 65570 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\C93D0F76d01
2010-08-06 20:32 . 2010-08-06 20:32 49971 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\1A5865E4d01
2010-08-06 20:32 . 2010-08-06 20:32 50177 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\BE324BA4d01
2010-08-06 20:32 . 2010-08-06 20:32 28917 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\18560130d01
2010-08-06 20:32 . 2010-08-06 20:32 28978 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\18480130d01
2010-08-06 20:32 . 2010-08-06 20:32 64680 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\DDD8AE71d01
2010-08-06 20:31 . 2010-08-06 20:31 32511 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\57C46313d01
2010-08-06 20:30 . 2010-08-06 20:30 19741 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\8E941880d01
2010-08-06 20:10 . 2010-08-06 20:10 22933 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\2072E1E1d01
2010-08-06 20:10 . 2010-08-06 20:10 22440 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\6B974514d01
2010-08-06 20:10 . 2010-08-06 20:10 18960 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\ED0BAA50d01
2010-08-06 20:10 . 2010-08-06 20:10 22348 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\1FBDEACEd01
2010-08-06 20:10 . 2010-08-06 20:10 30602 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\F18108FBd01
2010-08-06 20:10 . 2010-08-06 20:10 27557 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\AEF98A0Fd01
2010-08-06 20:10 . 2010-08-06 20:10 66964 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\417DD7D4d01
2010-08-06 20:10 . 2010-08-06 20:10 63112 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\C15B571Cd01
2010-08-06 20:10 . 2010-08-06 20:10 45568 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\985055ABd01
2010-08-06 20:10 . 2010-08-06 20:10 23525 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\3DC1C0BCd01
2010-08-06 20:10 . 2010-08-06 20:10 49538 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\59FC31E8d01
2010-08-06 20:10 . 2010-08-06 20:10 20548 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\E1953FF8d01
2010-08-06 20:10 . 2010-08-06 20:10 25280 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\7A1CC78Dd01
2010-08-06 20:09 . 2010-08-06 20:10 31138 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\7DCC57FCd01
2010-08-06 20:09 . 2010-08-06 20:09 49893 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\A950A0AEd01
2010-08-06 20:09 . 2010-08-06 20:09 76304 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\E1943FF8d01
2010-08-06 20:09 . 2010-08-06 20:09 67112 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\802C2C56d01
2010-08-06 20:02 . 2010-08-06 20:02 20106 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\A196F878d01
2010-08-06 20:02 . 2010-08-06 20:02 20106 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\0D90DEB0d01
2010-08-06 20:02 . 2010-08-06 20:02 146441 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\9B931903d01
2010-08-06 20:02 . 2010-08-06 20:02 81076 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\1C9EC1A3d01
2010-08-06 20:01 . 2010-08-06 20:01 23192 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\12A278B1d01
2010-08-06 20:01 . 2010-08-06 20:02 79459 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\1C9DC1A3d01
2010-08-06 20:01 . 2010-08-06 20:01 2334 —-a-w- c:\windows\Help32\f\1\defaults\profile\pluginreg.dat
2010-08-06 20:01 . 2010-08-06 20:01 20518 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\FE95EDD3d01
2010-08-06 19:51 . 2010-08-06 20:57 32768 —-a-w- c:\windows\Help32\f\1\defaults\profile\urlclassifier3.sqlite
2010-08-06 19:51 . 2010-08-06 20:57 16384 —-a-w- c:\windows\Help32\f\1\defaults\profile\key3.db
2010-08-06 19:51 . 2010-08-06 20:57 65536 —-a-w- c:\windows\Help32\f\1\defaults\profile\cert8.db
2010-08-06 19:51 . 2010-08-06 19:51 16384 —-a-w- c:\windows\Help32\f\1\defaults\profile\secmod.db
2010-08-06 19:51 . 2010-08-06 20:57 427261 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\_CACHE_002_
2010-08-06 19:51 . 2010-08-06 20:57 775569 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\_CACHE_003_
2010-08-06 19:51 . 2010-08-06 20:57 324509 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\_CACHE_001_
2010-08-06 19:51 . 2010-08-06 20:57 276 —-a-w- c:\windows\Help32\f\1\defaults\profile\Cache\_CACHE_MAP_
2010-08-06 19:51 . 2010-08-06 20:57 2048 —-a-w- c:\windows\Help32\f\1\defaults\profile\webappsstore.sqlite
2010-08-06 19:51 . 2010-08-06 20:57 5120 —-a-w- c:\windows\Help32\f\1\defaults\profile\cookies.sqlite
2010-08-06 19:51 . 2010-08-06 20:57 2048 —-a-w- c:\windows\Help32\f\1\defaults\profile\permissions.sqlite
2010-08-06 19:51 . 2010-08-06 20:57 66176 —-a-w- c:\windows\Help32\f\1\defaults\profile\places.sqlite-journal
2010-08-06 19:51 . 2010-08-06 20:57 192512 —-a-w- c:\windows\Help32\f\1\defaults\profile\places.sqlite
2010-08-06 19:51 . 2010-08-06 19:51 142385 —-a-w- c:\windows\Help32\f\1\components\compreg.dat
2010-08-06 19:50 . 2010-08-06 19:50 101992 —-a-w- c:\windows\Help32\f\1\components\xpti.dat
2010-08-06 19:50 . 2010-03-15 16:33 619 —-a-w- c:\windows\Help32\f\1\res\html\folder.png
2010-08-06 19:50 . 2010-03-15 16:33 841 —-a-w- c:\windows\Help32\f\1\res\table-remove-row.gif
2010-08-06 19:50 . 2010-03-15 16:33 841 —-a-w- c:\windows\Help32\f\1\res\table-remove-row-hover.gif
2010-08-06 19:50 . 2010-03-15 16:33 835 —-a-w- c:\windows\Help32\f\1\res\table-remove-row-active.gif
2010-08-06 19:50 . 2010-03-15 16:33 841 —-a-w- c:\windows\Help32\f\1\res\table-remove-column.gif
2010-08-06 19:50 . 2010-03-15 16:33 841 —-a-w- c:\windows\Help32\f\1\res\table-remove-column-hover.gif
2010-08-06 19:50 . 2010-03-15 16:33 835 —-a-w- c:\windows\Help32\f\1\res\table-remove-column-active.gif
2010-08-06 19:50 . 2010-03-15 16:33 825 —-a-w- c:\windows\Help32\f\1\res\table-add-row-before.gif
2010-08-06 19:50 . 2010-03-15 16:33 825 —-a-w- c:\windows\Help32\f\1\res\table-add-row-before-hover.gif
2010-08-06 19:50 . 2010-03-15 16:33 826 —-a-w- c:\windows\Help32\f\1\res\table-add-row-after-hover.gif
2010-08-06 19:50 . 2010-03-15 16:33 826 —-a-w- c:\windows\Help32\f\1\res\table-add-row-after.gif
2010-08-06 19:50 . 2010-03-15 16:33 57 —-a-w- c:\windows\Help32\f\1\res\table-add-row-before-active.gif
2010-08-06 19:50 . 2010-03-15 16:33 826 —-a-w- c:\windows\Help32\f\1\res\table-add-column-after.gif
2010-08-06 19:50 . 2010-03-15 16:33 57 —-a-w- c:\windows\Help32\f\1\res\table-add-column-before-active.gif
2010-08-06 19:50 . 2010-03-15 16:33 825 —-a-w- c:\windows\Help32\f\1\res\table-add-column-before-hover.gif
2010-08-06 19:50 . 2010-03-15 16:33 825 —-a-w- c:\windows\Help32\f\1\res\table-add-column-before.gif
2010-08-06 19:50 . 2010-03-15 16:33 57 —-a-w- c:\windows\Help32\f\1\res\table-add-row-after-active.gif
2010-08-06 19:50 . 2010-03-15 16:33 122 —-a-w- c:\windows\Help32\f\1\res\loading-image.gif
2010-08-06 19:50 . 2010-03-15 16:33 58 —-a-w- c:\windows\Help32\f\1\res\table-add-column-after-active.gif
2010-08-06 19:50 . 2010-03-15 16:33 826 —-a-w- c:\windows\Help32\f\1\res\table-add-column-after-hover.gif
2010-08-06 19:50 . 2010-03-15 16:33 858 —-a-w- c:\windows\Help32\f\1\res\grabber.gif
2010-08-06 19:50 . 2010-02-19 14:32 771 —-a-w- c:\windows\Help32\f\1\components\zipwriter.xpt
2010-08-06 19:50 . 2010-03-15 16:33 56 —-a-w- c:\windows\Help32\f\1\res\arrow.gif
2010-08-06 19:50 . 2010-03-15 16:33 59 —-a-w- c:\windows\Help32\f\1\res\arrowd.gif
2010-08-06 19:50 . 2010-03-15 16:33 106 —-a-w- c:\windows\Help32\f\1\res\broken-image.gif
2010-08-06 19:50 . 2010-02-19 14:41 2425 —-a-w- c:\windows\Help32\f\1\components\xultmpl.xpt
2010-08-06 19:50 . 2010-02-19 14:41 1209 —-a-w- c:\windows\Help32\f\1\components\xuldoc.xpt
2010-08-06 19:50 . 2010-02-19 15:03 1111 —-a-w- c:\windows\Help32\f\1\components\xpinstall.xpt
2010-08-06 19:50 . 2010-02-19 15:03 613 —-a-w- c:\windows\Help32\f\1\components\xulapp.xpt
2010-08-06 19:50 . 2010-02-19 15:13 198 —-a-w- c:\windows\Help32\f\1\components\xulapp_setup.xpt
2010-08-06 19:50 . 2010-02-19 14:22 1560 —-a-w- c:\windows\Help32\f\1\components\xpcom_xpti.xpt
2010-08-06 19:50 . 2010-02-19 14:30 8438 —-a-w- c:\windows\Help32\f\1\components\xpconnect.xpt
2010-08-06 19:50 . 2010-02-19 14:22 1896 —-a-w- c:\windows\Help32\f\1\components\xpcom_system.xpt
2010-08-06 19:50 . 2010-02-19 14:22 2240 —-a-w- c:\windows\Help32\f\1\components\xpcom_thread.xpt
2010-08-06 19:50 . 2010-02-19 14:21 7420 —-a-w- c:\windows\Help32\f\1\components\xpcom_io.xpt
2010-08-06 19:50 . 2010-02-19 14:22 3040 —-a-w- c:\windows\Help32\f\1\components\xpcom_components.xpt
2010-08-06 19:50 . 2010-02-19 14:21 11095 —-a-w- c:\windows\Help32\f\1\components\xpcom_ds.xpt
2010-08-06 19:50 . 2010-02-19 15:11 1011 —-a-w- c:\windows\Help32\f\1\components\xml-rpc.xpt
2010-08-06 19:50 . 2010-02-19 14:21 3185 —-a-w- c:\windows\Help32\f\1\components\xpcom_base.xpt
2010-08-06 19:50 . 2010-02-19 15:01 212 —-a-w- c:\windows\Help32\f\1\components\windowds.xpt
2010-08-06 19:50 . 2010-02-19 14:56 2793 —-a-w- c:\windows\Help32\f\1\components\windowwatcher.xpt
2010-08-06 19:50 . 2010-02-19 14:37 11151 —-a-w- c:\windows\Help32\f\1\components\widget.xpt
2010-08-06 19:50 . 2010-02-19 15:01 172 —-a-w- c:\windows\Help32\f\1\components\urlformatter.xpt
2010-08-06 19:50 . 2010-02-19 14:56 2074 —-a-w- c:\windows\Help32\f\1\components\webbrowserpersist.xpt
2010-08-06 19:50 . 2010-02-19 14:56 5510 —-a-w- c:\windows\Help32\f\1\components\webBrowser_core.xpt
2010-08-06 19:50 . 2010-02-19 14:56 1293 —-a-w- c:\windows\Help32\f\1\components\webshell_idls.xpt
2010-08-06 19:50 . 2010-02-19 14:23 1181 —-a-w- c:\windows\Help32\f\1\components\unicharutil.xpt
2010-08-06 19:50 . 2010-02-19 15:03 2646 —-a-w- c:\windows\Help32\f\1\components\update.xpt
2010-08-06 19:50 . 2010-02-19 14:33 2713 —-a-w- c:\windows\Help32\f\1\components\uriloader.xpt
2010-08-06 19:50 . 2010-02-19 14:47 1258 —-a-w- c:\windows\Help32\f\1\components\txmgr.xpt
2010-08-06 19:50 . 2010-02-19 14:46 759 —-a-w- c:\windows\Help32\f\1\components\txtsvc.xpt
2010-08-06 19:50 . 2010-02-19 14:23 1491 —-a-w- c:\windows\Help32\f\1\components\uconv.xpt
2010-08-06 19:50 . 2010-02-19 15:02 1060 —-a-w- c:\windows\Help32\f\1\components\spellchecker.xpt
2010-08-06 19:50 . 2010-02-19 14:32 3155 —-a-w- c:\windows\Help32\f\1\components\storage.xpt
2010-08-06 19:50 . 2010-02-19 15:02 1088 —-a-w- c:\windows\Help32\f\1\components\toolkitprofile.xpt
2010-08-06 19:50 . 2010-02-19 14:56 2958 —-a-w- c:\windows\Help32\f\1\components\shistory.xpt
2010-08-06 19:50 . 2010-02-19 14:32 4908 —-a-w- c:\windows\Help32\f\1\components\rdf.xpt
2010-08-06 19:50 . 2010-02-19 15:02 718 —-a-w- c:\windows\Help32\f\1\components\satchel.xpt
2010-08-06 19:50 . 2010-02-19 14:33 2369 —-a-w- c:\windows\Help32\f\1\components\saxparser.xpt
2010-08-06 19:50 . 2010-02-19 14:23 3290 —-a-w- c:\windows\Help32\f\1\components\pref.xpt
2010-08-06 19:50 . 2010-02-19 14:33 1179 —-a-w- c:\windows\Help32\f\1\components\prefetch.xpt
2010-08-06 19:50 . 2010-02-19 15:01 652 —-a-w- c:\windows\Help32\f\1\components\profile.xpt
2010-08-06 19:50 . 2010-02-19 14:22 287 —-a-w- c:\windows\Help32\f\1\components\proxyObject.xpt
2010-08-06 19:50 . 2010-02-19 15:01 11652 —-a-w- c:\windows\Help32\f\1\components\places.xpt
2010-08-06 19:50 . 2010-02-19 14:35 5145 —-a-w- c:\windows\Help32\f\1\components\plugin.xpt
2010-08-06 19:50 . 2010-02-19 15:07 377 —-a-w- c:\windows\Help32\f\1\components\pippki.xpt
2010-08-06 19:50 . 2010-02-19 15:06 628 —-a-w- c:\windows\Help32\f\1\components\pipboot.xpt
2010-08-06 19:50 . 2010-02-19 15:07 12938 —-a-w- c:\windows\Help32\f\1\components\pipnss.xpt
2010-08-06 19:50 . 2010-02-19 15:02 537 —-a-w- c:\windows\Help32\f\1\components\parentalcontrols.xpt
2010-08-06 19:50 . 2010-02-19 14:25 1475 —-a-w- c:\windows\Help32\f\1\components\necko_strconv.xpt
2010-08-06 19:50 . 2010-02-19 14:26 188 —-a-w- c:\windows\Help32\f\1\components\necko_viewsource.xpt
2010-08-06 19:50 . 2010-02-19 14:57 1120 —-a-w- c:\windows\Help32\f\1\components\oji.xpt
2010-08-06 19:50 . 2010-02-19 14:26 285 —-a-w- c:\windows\Help32\f\1\components\necko_res.xpt
2010-08-06 19:50 . 2010-02-19 14:25 893 —-a-w- c:\windows\Help32\f\1\components\necko_socket.xpt
2010-08-06 19:50 . 2010-02-19 14:26 437 —-a-w- c:\windows\Help32\f\1\components\necko_file.xpt
2010-08-06 19:50 . 2010-02-19 14:26 201 —-a-w- c:\windows\Help32\f\1\components\necko_ftp.xpt
2010-08-06 19:50 . 2010-02-19 14:26 2602 —-a-w- c:\windows\Help32\f\1\components\necko_http.xpt
2010-08-06 19:50 . 2010-02-19 14:25 1648 —-a-w- c:\windows\Help32\f\1\components\necko_cookie.xpt
2010-08-06 19:50 . 2010-02-19 14:25 1081 —-a-w- c:\windows\Help32\f\1\components\necko_dns.xpt
2010-08-06 19:50 . 2010-02-19 14:26 312 —-a-w- c:\windows\Help32\f\1\components\necko_about.xpt
2010-08-06 19:50 . 2010-02-19 14:26 2595 —-a-w- c:\windows\Help32\f\1\components\necko_cache.xpt
2010-08-06 19:50 . 2010-02-19 14:25 17215 —-a-w- c:\windows\Help32\f\1\components\necko.xpt
2010-08-06 19:50 . 2010-02-19 15:01 845 —-a-w- c:\windows\Help32\f\1\components\mozfind.xpt
2010-08-06 19:50 . 2010-02-19 14:25 2008 —-a-w- c:\windows\Help32\f\1\components\mimetype.xpt
2010-08-06 19:50 . 2010-02-19 15:01 296 —-a-w- c:\windows\Help32\f\1\components\mozbrwsr.xpt
2010-08-06 19:50 . 2010-02-19 14:25 174 —-a-w- c:\windows\Help32\f\1\components\lwbrk.xpt
2010-08-06 19:50 . 2010-02-19 15:02 1784 —-a-w- c:\windows\Help32\f\1\components\loginmgr.xpt
2010-08-06 19:50 . 2010-02-19 14:24 1260 —-a-w- c:\windows\Help32\f\1\components\locale.xpt
2010-08-06 19:50 . 2010-02-19 14:52 3731 —-a-w- c:\windows\Help32\f\1\components\layout_xul_tree.xpt
2010-08-06 19:50 . 2010-02-19 14:51 2122 —-a-w- c:\windows\Help32\f\1\components\layout_xul.xpt
2010-08-06 19:50 . 2010-02-19 14:53 911 —-a-w- c:\windows\Help32\f\1\components\layout_printing.xpt
2010-08-06 19:50 . 2010-02-19 14:33 6029 —-a-w- c:\windows\Help32\f\1\components\jsdservice.xpt
2010-08-06 19:50 . 2010-02-19 14:49 302 —-a-w- c:\windows\Help32\f\1\components\layout_base.xpt
2010-08-06 19:50 . 2010-02-19 14:25 645 —-a-w- c:\windows\Help32\f\1\components\intl.xpt
2010-08-06 19:50 . 2010-02-19 14:32 1346 —-a-w- c:\windows\Help32\f\1\components\jar.xpt
2010-08-06 19:50 . 2010-02-19 14:35 3021 —-a-w- c:\windows\Help32\f\1\components\imglib2.xpt
2010-08-06 19:50 . 2010-02-19 14:55 2502 —-a-w- c:\windows\Help32\f\1\components\inspector.xpt
2010-08-06 19:50 . 2010-02-19 14:34 1451 —-a-w- c:\windows\Help32\f\1\components\gfx.xpt
2010-08-06 19:50 . 2010-02-19 14:33 694 —-a-w- c:\windows\Help32\f\1\components\htmlparser.xpt
2010-08-06 19:50 . 2010-02-19 14:35 326 —-a-w- c:\windows\Help32\f\1\components\imgicon.xpt
2010-08-06 19:50 . 2010-06-16 02:14 856 —-a-w- c:\windows\Help32\f\1\plugins\flashplayer.xpt
2010-08-06 19:50 . 2010-02-19 14:56 1036 —-a-w- c:\windows\Help32\f\1\components\find.xpt
2010-08-06 19:50 . 2010-02-19 15:02 3274 —-a-w- c:\windows\Help32\f\1\components\feeds.xpt
2010-08-06 19:50 . 2010-02-19 15:02 599 —-a-w- c:\windows\Help32\f\1\components\fastfind.xpt
2010-08-06 19:50 . 2010-02-19 15:02 1508 —-a-w- c:\windows\Help32\f\1\components\exthelper.xpt
2010-08-06 19:50 . 2010-02-19 15:03 3831 —-a-w- c:\windows\Help32\f\1\components\extensions.xpt
2010-08-06 19:50 . 2010-02-19 14:33 1981 —-a-w- c:\windows\Help32\f\1\components\exthandler.xpt
2010-08-06 19:50 . 2010-02-19 14:46 11557 —-a-w- c:\windows\Help32\f\1\components\editor.xpt
2010-08-06 19:50 . 2010-02-19 14:56 530 —-a-w- c:\windows\Help32\f\1\components\embed_base.xpt
2010-08-06 19:50 . 2010-02-19 14:35 7408 —-a-w- c:\windows\Help32\f\1\components\dom_xul.xpt
2010-08-06 19:50 . 2010-02-19 15:02 2232 —-a-w- c:\windows\Help32\f\1\components\downloads.xpt
2010-08-06 19:50 . 2010-02-19 14:35 226 —-a-w- c:\windows\Help32\f\1\components\dom_views.xpt
2010-08-06 19:50 . 2010-02-19 14:35 451 —-a-w- c:\windows\Help32\f\1\components\dom_xbl.xpt
2010-08-06 19:50 . 2010-02-19 14:35 1417 —-a-w- c:\windows\Help32\f\1\components\dom_xpath.xpt
2010-08-06 19:50 . 2010-02-19 14:36 23460 —-a-w- c:\windows\Help32\f\1\components\dom_svg.xpt
2010-08-06 19:50 . 2010-02-19 14:35 1282 —-a-w- c:\windows\Help32\f\1\components\dom_traversal.xpt
2010-08-06 19:50 . 2010-02-19 14:35 1019 —-a-w- c:\windows\Help32\f\1\components\dom_stylesheets.xpt
2010-08-06 19:50 . 2010-02-19 14:35 874 —-a-w- c:\windows\Help32\f\1\components\dom_storage.xpt
2010-08-06 19:50 . 2010-02-19 14:35 551 —-a-w- c:\windows\Help32\f\1\components\dom_sidebar.xpt
2010-08-06 19:50 . 2010-02-19 14:35 1240 —-a-w- c:\windows\Help32\f\1\components\dom_range.xpt
2010-08-06 19:50 . 2010-02-19 14:35 349 —-a-w- c:\windows\Help32\f\1\components\dom_json.xpt
2010-08-06 19:50 . 2010-02-19 14:35 2621 —-a-w- c:\windows\Help32\f\1\components\dom_loadsave.xpt
2010-08-06 19:50 . 2010-02-19 14:35 1263 —-a-w- c:\windows\Help32\f\1\components\dom_offline.xpt
2010-08-06 19:50 . 2010-02-19 14:35 11997 —-a-w- c:\windows\Help32\f\1\components\dom_css.xpt
2010-08-06 19:50 . 2010-02-19 14:35 6869 —-a-w- c:\windows\Help32\f\1\components\dom_events.xpt
2010-08-06 19:50 . 2010-02-19 14:35 18049 —-a-w- c:\windows\Help32\f\1\components\dom_html.xpt
2010-08-06 19:50 . 2010-02-19 14:35 1930 —-a-w- c:\windows\Help32\f\1\components\dom_canvas.xpt
2010-08-06 19:50 . 2010-02-19 14:35 7301 —-a-w- c:\windows\Help32\f\1\components\dom_core.xpt
2010-08-06 19:50 . 2010-02-19 14:35 377 —-a-w- c:\windows\Help32\f\1\components\dom.xpt
2010-08-06 19:50 . 2010-02-19 14:35 9477 —-a-w- c:\windows\Help32\f\1\components\dom_base.xpt
2010-08-06 19:50 . 2010-02-19 15:01 373 —-a-w- c:\windows\Help32\f\1\components\directory.xpt
2010-08-06 19:50 . 2010-02-19 14:56 10561 —-a-w- c:\windows\Help32\f\1\components\docshell_base.xpt
2010-08-06 19:50 . 2010-02-19 14:32 488 —-a-w- c:\windows\Help32\f\1\components\cookie.xpt
2010-08-06 19:50 . 2010-02-19 15:01 724 —-a-w- c:\windows\Help32\f\1\components\contentprefs.xpt
2010-08-06 19:50 . 2010-02-19 14:42 1326 —-a-w- c:\windows\Help32\f\1\components\content_xslt.xpt
2010-08-06 19:50 . 2010-02-19 14:45 2512 —-a-w- c:\windows\Help32\f\1\components\content_xtf.xpt
2010-08-06 19:50 . 2010-02-19 14:40 605 —-a-w- c:\windows\Help32\f\1\components\content_htmldoc.xpt
2010-08-06 19:50 . 2010-02-19 14:41 693 —-a-w- c:\windows\Help32\f\1\components\content_xmldoc.xpt
2010-08-06 19:50 . 2010-02-19 14:39 700 —-a-w- c:\windows\Help32\f\1\components\content_html.xpt
2010-08-06 19:50 . 2010-02-19 14:47 755 —-a-w- c:\windows\Help32\f\1\components\composer.xpt
2010-08-06 19:50 . 2010-02-19 14:37 9066 —-a-w- c:\windows\Help32\f\1\components\content_base.xpt
2010-08-06 19:50 . 2010-02-19 15:02 960 —-a-w- c:\windows\Help32\f\1\components\commandlines.xpt
2010-08-06 19:50 . 2010-02-19 15:01 344 —-a-w- c:\windows\Help32\f\1\components\chrome.xpt
2010-08-06 19:50 . 2010-02-19 14:56 1789 —-a-w- c:\windows\Help32\f\1\components\commandhandler.xpt
2010-08-06 19:50 . 2010-02-19 14:32 679 —-a-w- c:\windows\Help32\f\1\components\chardet.xpt
2010-08-06 19:50 . 2010-02-19 14:33 2719 —-a-w- c:\windows\Help32\f\1\components\caps.xpt
2010-08-06 19:50 . 2010-03-15 16:33 348994 —-a-w- c:\windows\Help32\f\1\components\browser.xpt
2010-08-06 19:50 . 2010-02-19 15:07 211 —-a-w- c:\windows\Help32\f\1\components\autoconfig.xpt
2010-08-06 19:50 . 2010-02-19 15:02 543 —-a-w- c:\windows\Help32\f\1\components\appstartup.xpt
2010-08-06 19:50 . 2010-02-19 15:02 3603 —-a-w- c:\windows\Help32\f\1\components\autocomplete.xpt
2010-08-06 19:50 . 2010-02-19 15:02 211 —-a-w- c:\windows\Help32\f\1\components\alerts.xpt
2010-08-06 19:50 . 2010-02-19 14:56 2547 —-a-w- c:\windows\Help32\f\1\components\appshell.xpt
2010-08-06 19:50 . 2010-02-19 14:57 233 —-a-w- c:\windows\Help32\f\1\components\accessibility-msaa.xpt
2010-08-06 19:50 . 2010-02-19 14:57 19182 —-a-w- c:\windows\Help32\f\1\components\accessibility.xpt
2010-08-06 19:50 . 2010-03-15 16:33 356 —-a-w- c:\windows\Help32\f\1\defaults\profile\mimeTypes.rdf
2010-08-06 19:50 . 2004-08-05 19:38 153 —-a-w- c:\windows\Help32\f\1\defaults\profile\US\localstore.rdf
2010-08-06 19:50 . 2004-08-05 19:38 153 —-a-w- c:\windows\Help32\f\1\defaults\profile\localstore.rdf
2010-08-06 19:50 . 2010-03-15 16:33 2080 —-a-w- c:\windows\Help32\f\1\res\wincharset.properties
2010-08-06 19:50 . 2010-03-15 16:33 38499 —-a-w- c:\windows\Help32\f\1\res\entityTables\transliterate.properties
2010-08-06 19:50 . 2010-03-15 16:33 30004 —-a-w- c:\windows\Help32\f\1\res\entityTables\mathml20.properties
2010-08-06 19:50 . 2010-03-15 16:33 3954 —-a-w- c:\windows\Help32\f\1\res\fonts\mathfontSymbol.properties
2010-08-06 19:50 . 2010-03-15 16:33 6719 —-a-w- c:\windows\Help32\f\1\res\fonts\mathfontUnicode.properties
2010-08-06 19:50 . 2010-03-15 16:33 3033 —-a-w- c:\windows\Help32\f\1\res\fonts\mathfontSTIXSize1.properties
2010-08-06 19:50 . 2010-03-15 16:33 3902 —-a-w- c:\windows\Help32\f\1\res\fonts\mathfontStandardSymbolsL.properties
2010-08-06 19:50 . 2010-03-15 16:33 5493 —-a-w- c:\windows\Help32\f\1\res\fonts\mathfontSTIXNonUnicode.properties
2010-08-06 19:50 . 2010-03-15 16:33 56411 —-a-w- c:\windows\Help32\f\1\res\fonts\mathfont.properties
2010-08-06 19:50 . 2010-03-15 16:33 5490 —-a-w- c:\windows\Help32\f\1\res\language.properties
2010-08-06 19:50 . 2010-03-15 16:33 5649 —-a-w- c:\windows\Help32\f\1\res\langGroups.properties
2010-08-06 19:50 . 2010-03-15 16:33 1967 —-a-w- c:\windows\Help32\f\1\res\entityTables\htmlEntityVersions.properties
2010-08-06 19:50 . 2010-03-15 16:33 4090 —-a-w- c:\windows\Help32\f\1\res\entityTables\html40Symbols.properties
2010-08-06 19:50 . 2010-03-15 16:33 2396 —-a-w- c:\windows\Help32\f\1\res\entityTables\html40Special.properties
2010-08-06 19:50 . 2010-03-15 16:33 3690 —-a-w- c:\windows\Help32\f\1\res\entityTables\html40Latin1.properties
2010-08-06 19:50 . 2010-03-15 16:33 9551 —-a-w- c:\windows\Help32\f\1\res\charsetData.properties
2010-08-06 19:50 . 2010-03-15 16:33 11392 —-a-w- c:\windows\Help32\f\1\res\charsetalias.properties
2010-08-06 19:50 . 2008-06-27 05:15 172 —-a-w- c:\windows\Help32\f\1\chrome\geckofx.manifest
2010-08-06 19:50 . 2010-02-19 15:07 69 —-a-w- c:\windows\Help32\f\1\chrome\pippki.manifest
2010-08-06 19:50 . 2010-02-19 15:03 517 —-a-w- c:\windows\Help32\f\1\chrome\toolkit.manifest
2010-08-06 19:50 . 2010-02-19 15:07 774 —-a-w- c:\windows\Help32\f\1\chrome\en-US.manifest
2010-08-06 19:50 . 2010-02-19 15:02 144 —-a-w- c:\windows\Help32\f\1\chrome\comm.manifest
2010-08-06 19:50 . 2010-02-19 15:03 552 —-a-w- c:\windows\Help32\f\1\chrome\classic.manifest
2010-08-06 19:50 . 2010-03-15 16:33 9998 —-a-w- c:\windows\Help32\f\1\modules\XPCOMUtils.jsm
2010-08-06 19:50 . 2010-03-15 16:33 7039 —-a-w- c:\windows\Help32\f\1\modules\ISO8601DateUtils.jsm
2010-08-06 19:50 . 2010-03-15 16:33 6721 —-a-w- c:\windows\Help32\f\1\modules\JSON.jsm
2010-08-06 19:50 . 2010-03-15 16:33 7585 —-a-w- c:\windows\Help32\f\1\modules\PluralForm.jsm
2010-08-06 19:50 . 2010-03-15 16:33 17380 —-a-w- c:\windows\Help32\f\1\modules\DownloadUtils.jsm
2010-08-06 19:50 . 2010-02-19 15:13 3930 —-a-w- c:\windows\Help32\f\1\defaults\pref\xulrunner.js
2010-08-06 19:50 . 2010-02-19 15:03 85 —-a-w- c:\windows\Help32\f\1\greprefs\xpinstall.js
2010-08-06 19:50 . 2010-03-15 16:33 34011 —-a-w- c:\windows\Help32\f\1\components\WebContentConverter.js
2010-08-06 19:50 . 2008-02-17 15:21 6667 —-a-w- c:\windows\Help32\f\1\components\txEXSLTRegExFunctions.js
2010-08-06 19:50 . 2010-03-15 16:33 61758 —-a-w- c:\windows\Help32\f\1\modules\utils.js
2010-08-06 19:50 . 2008-10-03 21:49 49926 —-a-w- c:\windows\Help32\f\1\components\storage-Legacy.js
2010-08-06 19:50 . 2010-03-15 16:33 208 —-a-w- c:\windows\Help32\f\1\defaults\pref\reporter.js
2010-08-06 19:50 . 2010-03-15 16:33 347 —-a-w- c:\windows\Help32\f\1\defaults\profile\prefs.js
2010-08-06 19:50 . 2010-02-19 14:25 3378 —-a-w- c:\windows\Help32\f\1\greprefs\security-prefs.js
2010-08-06 19:50 . 2005-12-31 10:14 7296 —-a-w- c:\windows\Help32\f\1\defaults\autoconfig\prefcalls.js
2010-08-06 19:50 . 2005-12-29 12:14 3142 —-a-w- c:\windows\Help32\f\1\components\pluginGlue.js
2010-08-06 19:50 . 2002-04-16 16:42 87 —-a-w- c:\windows\Help32\f\1\defaults\autoconfig\platform.js
2010-08-06 19:50 . 2010-02-19 15:13 8278 —-a-w- c:\windows\Help32\f\1\components\nsXULAppInstall.js
2010-08-06 19:50 . 2006-10-24 14:02 35256 —-a-w- c:\windows\Help32\f\1\components\nsXmlRpcClient.js
2010-08-06 19:50 . 2007-10-23 16:20 6920 —-a-w- c:\windows\Help32\f\1\components\nsWebHandlerApp.js
2010-08-06 19:50 . 2010-02-19 15:01 3115 —-a-w- c:\windows\Help32\f\1\components\nsURLFormatter.js
2010-08-06 19:50 . 2010-03-15 16:33 19983 —-a-w- c:\windows\Help32\f\1\components\nsUrlClassifierListManager.js
2010-08-06 19:50 . 2010-03-15 16:33 50600 —-a-w- c:\windows\Help32\f\1\components\nsUrlClassifierLib.js
2010-08-06 19:50 . 2007-08-31 01:28 3268 —-a-w- c:\windows\Help32\f\1\components\nsTryToClose.js
2010-08-06 19:50 . 2010-02-19 15:03 115501 —-a-w- c:\windows\Help32\f\1\components\nsUpdateService.js
2010-08-06 19:50 . 2010-03-15 16:33 2854 —-a-w- c:\windows\Help32\f\1\components\nsSetDefaultBrowser.js
2010-08-06 19:50 . 2010-03-15 16:33 12513 —-a-w- c:\windows\Help32\f\1\components\nsSidebar.js
2010-08-06 19:50 . 2010-02-19 15:02 9967 —-a-w- c:\windows\Help32\f\1\components\nsTaggingService.js
2010-08-06 19:50 . 2010-03-15 16:33 76993 —-a-w- c:\windows\Help32\f\1\components\nsSessionStore.js
2010-08-06 19:50 . 2010-03-15 16:33 11428 —-a-w- c:\windows\Help32\f\1\components\nsSessionStartup.js
2010-08-06 19:50 . 2010-03-15 16:33 24273 —-a-w- c:\windows\Help32\f\1\components\nsSearchSuggestions.js
2010-08-06 19:50 . 2010-03-15 16:33 110913 —-a-w- c:\windows\Help32\f\1\components\nsSearchService.js
2010-08-06 19:50 . 2010-03-15 16:33 25176 —-a-w- c:\windows\Help32\f\1\components\nsSafebrowsingApplication.js
2010-08-06 19:50 . 2010-06-28 04:11 4769 —-a-w- c:\windows\Help32\f\1\components\nsRequestService.js
2010-08-06 19:50 . 2004-10-29 17:28 7049 —-a-w- c:\windows\Help32\f\1\components\nsResetPref.js
2010-08-06 19:50 . 2008-03-10 23:40 13682 —-a-w- c:\windows\Help32\f\1\components\nsProxyAutoConfig.js
2010-08-06 19:50 . 2007-07-05 17:31 37314 —-a-w- c:\windows\Help32\f\1\components\nsProgressDialog.js
2010-08-06 19:50 . 2007-07-30 18:16 21420 —-a-w- c:\windows\Help32\f\1\components\nsPostUpdateWin.js
2010-08-06 19:50 . 2010-03-15 16:33 33805 —-a-w- c:\windows\Help32\f\1\components\nsPlacesTransactionsService.js
2010-08-06 19:50 . 2010-03-15 16:33 77051 —-a-w- c:\windows\Help32\f\1\components\nsMicrosummaryService.js
2010-08-06 19:50 . 2008-05-02 05:44 40367 —-a-w- c:\windows\Help32\f\1\components\nsLoginManagerPrompter.js
2010-08-06 19:50 . 2009-09-23 19:06 44106 —-a-w- c:\windows\Help32\f\1\components\nsLoginManager.js
2010-08-06 19:50 . 2008-01-15 00:50 4302 —-a-w- c:\windows\Help32\f\1\components\nsLoginInfo.js
2010-08-06 19:50 . 2010-02-19 15:02 36111 —-a-w- c:\windows\Help32\f\1\components\nsLivemarkService.js
2010-08-06 19:50 . 2010-02-19 15:03 41950 —-a-w- c:\windows\Help32\f\1\components\nsHelperAppDlg.js
2010-08-06 19:50 . 2008-04-29 22:21 51214 —-a-w- c:\windows\Help32\f\1\components\nsHandlerService.js
2010-08-06 19:50 . 2010-02-19 15:03 333726 —-a-w- c:\windows\Help32\f\1\components\nsExtensionManager.js
2010-08-06 19:50 . 2004-04-18 20:14 4805 —-a-w- c:\windows\Help32\f\1\components\nsDictionary.js
2010-08-06 19:50 . 2008-04-03 01:05 5737 —-a-w- c:\windows\Help32\f\1\components\nsDownloadManagerUI.js
2010-08-06 19:50 . 2010-02-19 15:02 6265 —-a-w- c:\windows\Help32\f\1\components\nsDefaultCLH.js
2010-08-06 19:50 . 2008-01-07 22:10 5005 —-a-w- c:\windows\Help32\f\1\components\nsContentDispatchChooser.js
2010-08-06 19:50 . 2008-05-25 23:05 29973 —-a-w- c:\windows\Help32\f\1\components\nsContentPrefService.js
2010-08-06 19:50 . 2010-03-15 16:33 32409 —-a-w- c:\windows\Help32\f\1\components\nsBrowserGlue.js
2010-08-06 19:50 . 2010-03-15 16:33 33087 —-a-w- c:\windows\Help32\f\1\components\nsBrowserContentHandler.js
2010-08-06 19:50 . 2008-03-18 22:14 3104 —-a-w- c:\windows\Help32\f\1\components\nsBadCertHandler.js
2010-08-06 19:50 . 2010-02-19 15:03 30074 —-a-w- c:\windows\Help32\f\1\components\nsBlocklistService.js
2010-08-06 19:50 . 2010-02-19 15:03 11677 —-a-w- c:\windows\Help32\f\1\components\nsAddonRepository.js
2010-08-06 19:50 . 2010-03-15 16:33 64412 —-a-w- c:\windows\Help32\f\1\modules\Microformats.js
2010-08-06 19:50 . 2010-02-19 15:02 1512 —-a-w- c:\windows\Help32\f\1\components\jsconsole-clhandler.js
2010-08-06 19:50 . 2010-03-15 16:33 38238 —-a-w- c:\windows\Help32\f\1\components\fuelApplication.js
2010-08-06 19:50 . 2010-03-15 16:33 224 —-a-w- c:\windows\Help32\f\1\defaults\pref\firefox-l10n.js
2010-08-06 19:50 . 2010-03-15 16:33 35102 —-a-w- c:\windows\Help32\f\1\defaults\pref\firefox.js
2010-08-06 19:50 . 2010-03-15 16:33 915 —-a-w- c:\windows\Help32\f\1\defaults\pref\firefox-branding.js
2010-08-06 19:50 . 2010-03-15 16:33 49780 —-a-w- c:\windows\Help32\f\1\components\FeedWriter.js
2010-08-06 19:50 . 2008-04-25 14:51 66215 —-a-w- c:\windows\Help32\f\1\components\FeedProcessor.js
2010-08-06 19:50 . 2010-03-15 16:33 25339 —-a-w- c:\windows\Help32\f\1\components\FeedConverter.js
2010-08-06 19:50 . 2010-03-15 16:33 12091 —-a-w- c:\windows\Help32\f\1\modules\distribution.js
2010-08-06 19:50 . 2010-03-15 16:33 126 —-a-w- c:\windows\Help32\f\1\defaults\pref\channel-prefs.js
2010-08-06 19:50 . 2010-03-15 16:33 2738 —-a-w- c:\windows\Help32\f\1\modules\debug.js
2010-08-06 19:50 . 2010-03-15 16:33 2927 —-a-w- c:\windows\Help32\f\1\components\aboutRobots.js
2010-08-06 19:50 . 2010-05-27 01:26 72928 —-a-w- c:\windows\Help32\f\1\greprefs\all.js
2010-08-06 19:50 . 2010-03-15 16:33 2925 —-a-w- c:\windows\Help32\f\1\components\aboutRights.js
2010-08-06 19:50 . 2010-03-06 17:52 1915137 —-a-w- c:\windows\Help32\f\1\chrome\toolkit.jar
2010-08-06 19:50 . 2008-06-27 05:15 13443 —-a-w- c:\windows\Help32\f\1\chrome\geckofx.jar
2010-08-06 19:50 . 2010-02-19 15:07 317480 —-a-w- c:\windows\Help32\f\1\chrome\pippki.jar
2010-08-06 19:50 . 2010-02-19 15:07 332438 —-a-w- c:\windows\Help32\f\1\chrome\en-US.jar
2010-08-06 19:50 . 2010-02-19 15:02 39680 —-a-w- c:\windows\Help32\f\1\chrome\comm.jar
2010-08-06 19:50 . 2010-02-19 15:03 777705 —-a-w- c:\windows\Help32\f\1\chrome\classic.jar
2010-08-06 19:50 . 2010-03-15 16:33 8427 —-a-w- c:\windows\Help32\f\1\res\dtd\xhtml11.dtd
2010-08-06 19:50 . 2010-03-15 16:33 63788 —-a-w- c:\windows\Help32\f\1\res\dtd\mathml.dtd
2010-08-06 19:50 . 2004-08-05 19:38 663 —-a-w- c:\windows\Help32\f\1\defaults\profile\chrome\userContent-example.css
2010-08-06 19:50 . 2004-08-05 19:38 663 —-a-w- c:\windows\Help32\f\1\defaults\profile\US\chrome\userContent-example.css
2010-08-06 19:50 . 2010-04-08 20:02 14848 –sha-w- c:\windows\Help32\f\1\res\Thumbs.db
2010-08-06 19:50 . 2010-03-15 16:33 3037 —-a-w- c:\windows\Help32\f\1\res\viewsource.css
2010-08-06 19:50 . 2010-04-08 20:02 5632 –sha-w- c:\windows\Help32\f\1\res\html\Thumbs.db
2010-08-06 19:50 . 2004-08-05 19:38 1078 —-a-w- c:\windows\Help32\f\1\defaults\profile\chrome\userChrome-example.css
2010-08-06 19:50 . 2004-08-05 19:38 1078 —-a-w- c:\windows\Help32\f\1\defaults\profile\US\chrome\userChrome-example.css
2010-08-06 19:50 . 2010-03-15 16:33 2295 —-a-w- c:\windows\Help32\f\1\res\svg.css
2010-08-06 19:50 . 2010-03-15 16:33 6469 —-a-w- c:\windows\Help32\f\1\res\ua.css
2010-08-06 19:50 . 2010-03-15 16:33 11608 —-a-w- c:\windows\Help32\f\1\res\quirk.css
2010-08-06 19:50 . 2010-03-15 16:33 11096 —-a-w- c:\windows\Help32\f\1\res\html.css
2010-08-06 19:50 . 2010-03-15 16:33 14664 —-a-w- c:\windows\Help32\f\1\res\mathml.css
2010-08-06 19:50 . 2010-03-15 16:33 10740 —-a-w- c:\windows\Help32\f\1\res\EditorOverride.css
2010-08-06 19:50 . 2010-03-15 16:33 15416 —-a-w- c:\windows\Help32\f\1\res\forms.css
2010-08-06 19:50 . 2010-03-15 16:33 1861 —-a-w- c:\windows\Help32\f\1\res\designmode.css
2010-08-06 19:50 . 2010-03-15 16:33 478 —-a-w- c:\windows\Help32\f\1\freebl3.chk
2010-08-06 19:50 . 2010-03-15 16:33 478 —-a-w- c:\windows\Help32\f\1\softokn3.chk
2010-08-06 19:50 . 2010-03-15 16:33 11637 —-a-w- c:\windows\Help32\f\1\res\contenteditable.css
2010-08-06 19:50 . 2010-03-16 02:00 17880 —-a-w- c:\windows\Help32\f\1\xpcom.dll
2010-08-06 19:50 . 2010-03-16 02:00 9799128 —-a-w- c:\windows\Help32\f\1\xul.dll
2010-08-06 19:50 . 2010-03-16 02:00 136664 —-a-w- c:\windows\Help32\f\1\ssl3.dll
2010-08-06 19:50 . 2010-03-16 02:00 443352 —-a-w- c:\windows\Help32\f\1\sqlite3.dll
2010-08-06 19:50 . 2010-03-15 16:33 155648 —-a-w- c:\windows\Help32\f\1\softokn3.dll
2010-08-06 19:50 . 2010-03-16 02:00 20440 —-a-w- c:\windows\Help32\f\1\plc4.dll
2010-08-06 19:50 . 2010-03-16 02:00 17368 —-a-w- c:\windows\Help32\f\1\plds4.dll
2010-08-06 19:50 . 2010-03-16 02:00 103896 —-a-w- c:\windows\Help32\f\1\smime3.dll
2010-08-06 19:50 . 2010-03-16 02:00 87512 —-a-w- c:\windows\Help32\f\1\nssutil3.dll
2010-08-06 19:50 . 2010-03-15 16:33 98304 —-a-w- c:\windows\Help32\f\1\nssdbm3.dll
2010-08-06 19:50 . 2010-03-16 02:00 316888 —-a-w- c:\windows\Help32\f\1\nssckbi.dll
2010-08-06 19:50 . 2010-03-16 02:00 632280 —-a-w- c:\windows\Help32\f\1\nss3.dll
2010-08-06 19:50 . 2010-03-16 02:00 198104 —-a-w- c:\windows\Help32\f\1\nspr4.dll
2010-08-06 19:50 . 2010-03-16 02:00 65496 —-a-w- c:\windows\Help32\f\1\plugins\npnul32.dll
2010-08-06 19:50 . 2010-06-16 02:14 5612496 —-a-w- c:\windows\Help32\f\1\plugins\NPSWF32.dll
2010-08-06 19:50 . 2010-03-16 02:00 710104 —-a-w- c:\windows\Help32\f\1\mozcrt19.dll
2010-08-06 19:50 . 2010-03-16 02:00 701400 —-a-w- c:\windows\Help32\f\1\js3250.dll
2010-08-06 19:50 . 2010-03-15 16:33 249856 —-a-w- c:\windows\Help32\f\1\freebl3.dll
2010-08-06 19:50 . 2010-03-16 02:00 23000 —-a-w- c:\windows\Help32\f\1\components\browserdirprovider.dll
2010-08-06 19:50 . 2010-03-16 02:00 134616 —-a-w- c:\windows\Help32\f\1\components\brwsrcmp.dll
2010-08-06 19:50 . 2010-03-15 16:33 117 —-a-w- c:\windows\Help32\f\1\res\hiddenWindow.html
2010-08-06 19:50 . 2010-03-15 16:33 7139 —-a-w- c:\windows\Help32\f\1\defaults\profile\bookmarks.html
2010-08-06 18:36 . 2010-08-06 20:51 35 —-a-w- c:\windows\Help32\auth.txt
2010-08-06 18:36 . 2010-08-06 18:36 13430 —-a-w- c:\windows\Help32\block.txt
2010-08-06 18:35 . 2009-09-08 22:54 158720 —-a-w- c:\windows\Help32\skybound.gecko.dll
2010-08-06 18:35 . 2010-08-06 18:35 445565 —-a-w- c:\windows\Help32\f\sfa.txt
2010-08-06 18:28 . 2010-08-06 18:35 9450011 —-a-w- c:\windows\Help32\f\jet.exe
2010-06-16 22:57 . 2010-06-16 22:57 830976 —-a-w- c:\windows\Help32\Helper.exe

—- Directory of c:\windows\system32\weber —-

2010-06-16 23:13 . 2010-06-16 23:13 559439 —-a-w- c:\windows\system32\weber\key.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" [2005-03-11 73728]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 82009]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-08-18 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 88203]
"TPSMain"="TPSMain.exe" [2005-06-01 282624]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 122880]
"dla"="c:\windows\system32\dla\DLACTRLW.exe" [2005-10-06 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-14 2065760]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-02-16 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Ralink Wireless Utility.lnk - c:\program files\Ralink\Common\RaUI.exe [2009-11-23 1560576]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-15 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-14 14:03 12536 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Ralink\\Common\\RaUI.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ralink\\Common\\ApUI.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\EA GAMES\\American McGee's Alice\\alice.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/23/2009 6:08 PM 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/23/2009 6:08 PM 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [7/14/2010 9:03 AM 308136]
R2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\drivers\Scutum50.sys [11/23/2009 4:16 PM 19072]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [5/9/2010 7:44 PM 41504]
S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\StumbleUpon\StumbleUponUpdateService.exe [4/7/2010 3:03 PM 120232]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/9/2010 5:07 PM 691696]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://partnerpage.google.com/toshibadirect.com
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
TCP: {0F0496EB-DA6E-4F6C-9A75-B64F3264BC96} = 208.67.220.220,208.67.222.222
TCP: {3C2B5551-66B8-47A0-81EA-8BF5DFB5B319} = 208.67.220.220,208.67.222.222
TCP: {F5296D1C-0456-4F13-8298-0CF334ACB00C} = 208.67.220.220,208.67.222.222
FF - ProfilePath - c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.demonoid.com/
FF - prefs.js: keyword.URL - hxxp://search.search-go.net/?sid=10101049100&s=
FF - component: c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\documents and settings\Aboluna\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.order.1 - Google
FF - user.js: keyword.URL - hxxp://search.search-go.net/?sid=10101049100&s=c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-15 21:11
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3712)
c:\windows\system32\WININET.dll
c:\windows\system32\TDispVol.dll
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\TDispVol.exe
c:\windows\AGRSMMSG.exe
c:\program files\Synaptics\SynTP\Toshiba.exe
c:\windows\system32\TPSBattM.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PSIService.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Ralink\Common\RaRegistry.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2010-08-15 21:16:57 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-16 02:16

Pre-Run: 9,074,159,616 bytes free
Post-Run: 9,062,653,952 bytes free

- - End Of File - - 3F40F83D0588C9E44ECD3C84F2D177A9

Here is the VirusTotal link

http://www.virustotal.com/file-scan/report…fe16-1281925268
submit a file to virustotal for analysis
  • Use the browse button on that page to navigate to the location of the file to be scanned.
  • In the right hand panel,
  • click on the file c:\windows\system32\weber\key.exe
  • then click the open button.
  • The file will now be displayed in the submit box.
  • Scroll down a bit and click "send file", wait for the results
  • If you get a message saying File has already been analyzed: click Reanalyze file now
  • Once scanned, copy and paste the link to the results page in your next reply.


next


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Here is the VirusTotal link

http://www.virustotal.com/file-scan/report…1b69-1281926550


Here is the MalwareBytes scan result

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4434

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

8/15/2010 10:02:55 PM
mbam-log-2010-08-15 (22-02-55).txt

Scan type: Quick scan
Objects scanned: 159847
Time elapsed: 14 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)






The Kaspersky scan is attached

Attachments:

Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showforum=27

Collect::
C:\Documents and Settings\Aboluna\My Documents\Invaders! Possibly from Space\IPFS.exe	
c:\windows\system32\weber\key.exe

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Here is the combo fix log


ComboFix 10-08-16.01 - Aboluna 08/16/2010 15:05:11.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.437 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Aboluna\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\documents and settings\Aboluna\My Documents\Invaders! Possibly from Space\IPFS.exe
file zipped: c:\windows\system32\weber\key.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Aboluna\My Documents\Invaders! Possibly from Space\IPFS.exe
c:\windows\system32\weber\key.exe

.
((((((((((((((((((((((((( Files Created from 2010-07-16 to 2010-08-16 )))))))))))))))))))))))))))))))
.

2010-08-15 01:45 . 2010-08-15 01:45 ——– d—–w- c:\program files\EA GAMES
2010-08-14 23:56 . 2010-08-14 23:56 388096 —-a-r- c:\documents and settings\Aboluna\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-14 23:56 . 2010-08-14 23:56 ——– d—–w- c:\program files\Trend Micro
2010-08-14 23:29 . 2010-08-14 23:29 ——– d—–w- c:\documents and settings\Aboluna\Application Data\Uniblue
2010-08-14 05:05 . 2010-08-14 05:05 ——– d—–w- c:\program files\Wedding Dash 4 Ever
2010-08-13 03:39 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-13 03:39 . 2010-08-13 03:39 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-13 03:39 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-13 03:26 . 2010-08-13 03:26 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-08-13 03:20 . 2010-08-13 03:20 ——– d—–w- c:\program files\CCleaner
2010-08-13 03:15 . 2010-08-13 03:15 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2010-08-13 03:15 . 2010-08-13 03:15 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-08-12 04:35 . 2010-08-12 04:35 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2010-08-12 04:34 . 2010-08-12 04:34 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-08-12 03:01 . 2010-08-13 05:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Update
2010-08-08 03:05 . 2010-08-08 03:05 ——– d—–w- c:\documents and settings\Aboluna\Application Data\Jumb-O-Fun Games
2010-08-06 18:28 . 2010-08-06 21:03 ——– d—–w- c:\windows\Help32
2010-08-06 18:28 . 2010-08-16 20:11 ——– d—–w- c:\windows\system32\weber
2010-07-30 23:20 . 2010-07-30 23:20 286720 ——w- c:\windows\Setup1.exe
2010-07-30 23:20 . 2010-07-30 23:20 73216 —-a-w- c:\windows\ST6UNST.EXE
2010-07-29 05:21 . 2008-04-13 15:39 5504 -c–a-w- c:\windows\system32\dllcache\mstee.sys
2010-07-29 05:21 . 2008-04-13 15:39 5504 —-a-w- c:\windows\system32\drivers\MSTEE.sys
2010-07-29 05:21 . 2008-04-13 15:46 10880 -c–a-w- c:\windows\system32\dllcache\ndisip.sys
2010-07-29 05:21 . 2008-04-13 15:46 10880 —-a-w- c:\windows\system32\drivers\NdisIP.sys
2010-07-29 05:21 . 2008-04-13 15:46 15232 -c–a-w- c:\windows\system32\dllcache\streamip.sys
2010-07-29 05:21 . 2008-04-13 15:46 15232 —-a-w- c:\windows\system32\drivers\StreamIP.sys
2010-07-29 05:20 . 2008-04-13 15:46 11136 -c–a-w- c:\windows\system32\dllcache\slip.sys
2010-07-29 05:20 . 2008-04-13 15:46 11136 —-a-w- c:\windows\system32\drivers\SLIP.sys
2010-07-29 05:20 . 2008-04-13 15:46 19200 -c–a-w- c:\windows\system32\dllcache\wstcodec.sys
2010-07-29 05:20 . 2008-04-13 15:46 19200 —-a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2010-07-29 05:20 . 2008-04-13 15:46 85248 -c–a-w- c:\windows\system32\dllcache\nabtsfec.sys
2010-07-29 05:20 . 2008-04-13 15:46 85248 —-a-w- c:\windows\system32\drivers\NABTSFEC.sys
2010-07-29 05:20 . 2008-04-13 15:46 17024 -c–a-w- c:\windows\system32\dllcache\ccdecode.sys
2010-07-29 05:20 . 2008-04-13 15:46 17024 —-a-w- c:\windows\system32\drivers\CCDECODE.sys
2010-07-29 05:20 . 2008-04-13 15:45 60032 -c–a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-07-29 05:20 . 2008-04-13 15:45 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-07-29 05:20 . 2010-07-29 05:20 ——– d—–w- c:\windows\OvtCam
2010-07-29 05:19 . 2008-04-13 21:12 53760 -c–a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-07-29 05:19 . 2008-04-13 21:12 53760 —-a-w- c:\windows\system32\vfwwdm32.dll
2010-07-29 05:19 . 2008-04-13 15:45 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-07-29 05:19 . 2008-04-13 15:45 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2010-07-29 05:17 . 2003-10-14 10:13 200704 —-a-w- c:\windows\sel3110.exe
2010-07-29 05:17 . 2003-09-25 07:00 61440 —-a-w- c:\windows\ov519dib.dll
2010-07-29 05:17 . 2003-09-25 07:00 40960 —-a-w- c:\windows\system32\ov519ext.dll
2010-07-29 05:17 . 2003-09-25 07:00 25211 —-a-w- c:\windows\system32\drivers\ov519cmd.sys
2010-07-29 05:17 . 2003-09-25 07:00 174530 —-a-w- c:\windows\system32\drivers\ov519vid.sys
2010-07-29 05:17 . 2003-09-25 07:00 16426 —-a-w- c:\windows\system32\ov519usd.dll
2010-07-29 05:17 . 2003-09-25 07:00 135168 —-a-w- c:\windows\ov519cap.exe
2010-07-29 05:16 . 2010-07-29 05:16 ——– d—–w- c:\program files\GE
2010-07-29 05:16 . 2003-09-25 07:00 307200 —-a-w- c:\windows\vidcap32.exe
2010-07-29 05:16 . 2003-06-02 13:35 40960 —-a-w- c:\windows\CleanDev.exe
2010-07-29 05:16 . 2002-07-07 20:15 32528 —-a-w- c:\windows\amcap.exe
2010-07-26 02:27 . 2001-08-18 03:36 8704 -c–a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-07-26 02:27 . 2001-08-18 03:36 8704 —-a-w- c:\windows\system32\kbdjpn.dll
2010-07-26 02:27 . 2001-08-18 03:36 8192 -c–a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-07-26 02:27 . 2001-08-18 03:36 8192 —-a-w- c:\windows\system32\kbdkor.dll
2010-07-26 02:27 . 2001-08-17 19:55 6144 -c–a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-07-26 02:27 . 2001-08-17 19:55 6144 —-a-w- c:\windows\system32\kbd101c.dll
2010-07-26 02:27 . 2001-08-17 19:55 5632 -c–a-w- c:\windows\system32\dllcache\kbd103.dll
2010-07-26 02:27 . 2001-08-17 19:55 5632 —-a-w- c:\windows\system32\kbd103.dll
2010-07-26 02:27 . 2001-08-17 19:55 6144 -c–a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-07-26 02:27 . 2001-08-17 19:55 6144 —-a-w- c:\windows\system32\kbd101b.dll
2010-07-26 02:27 . 2008-04-13 21:09 6144 -c–a-w- c:\windows\system32\dllcache\kbd106.dll
2010-07-26 02:27 . 2008-04-13 21:09 6144 —-a-w- c:\windows\system32\kbd106.dll
2010-07-25 23:08 . 2010-07-25 23:08 503808 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5b6fb651-n\msvcp71.dll
2010-07-25 23:08 . 2010-07-25 23:08 499712 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5b6fb651-n\jmc.dll
2010-07-25 23:08 . 2010-07-25 23:08 348160 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5b6fb651-n\msvcr71.dll
2010-07-25 23:07 . 2010-07-25 23:07 12800 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2e93519c-n\decora-d3d.dll
2010-07-25 23:07 . 2010-07-25 23:07 61440 —-a-w- c:\documents and settings\Aboluna\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2e93519c-n\decora-sse.dll
2010-07-25 23:06 . 2010-07-25 23:06 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-25 05:58 . 2010-08-16 17:16 ——– d—–w- c:\documents and settings\Aboluna\Application Data\StumbleUpon
2010-07-25 05:57 . 2010-07-25 05:58 ——– d—–w- c:\program files\StumbleUpon
2010-07-22 09:20 . 2010-07-22 09:38 ——– d-sh–w- c:\documents and settings\Aboluna\Local Settings\Application Data\.#
2010-07-22 03:12 . 2010-07-22 03:12 389120 –sh–w- c:\windows\Launcher.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 20:02 . 2009-11-24 00:20 ——– d—–w- c:\documents and settings\Aboluna\Application Data\uTorrent
2010-08-16 07:18 . 2010-04-19 07:11 ——– d—–w- c:\documents and settings\Aboluna\Application Data\vlc
2010-08-15 20:01 . 2009-11-27 18:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Soulseek
2010-08-15 04:23 . 2009-12-22 16:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-15 01:46 . 2006-02-15 16:20 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-13 02:35 . 2006-02-25 07:02 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-11 23:02 . 2009-12-07 18:39 2880 –sha-w- c:\windows\system32\KGyGaAvL.sys
2010-08-08 21:58 . 2010-05-12 22:22 ——– d—–w- c:\program files\Steam
2010-08-07 22:18 . 2010-06-09 21:42 86016 —-a-w- c:\windows\system32\OpenAL32.dll
2010-08-07 22:18 . 2010-06-09 21:42 262144 —-a-w- c:\windows\system32\wrap_oal.dll
2010-08-06 18:28 . 2006-02-16 16:59 53432 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-05 18:15 . 2006-02-18 15:03 ——– d—–w- c:\program files\RGB
2010-07-25 23:07 . 2006-02-16 09:28 ——– d—–w- c:\program files\Common Files\Java
2010-07-25 23:06 . 2006-02-16 09:28 ——– d—–w- c:\program files\Java
2010-07-17 00:58 . 2010-07-17 00:58 ——– d—–w- c:\program files\DAEMON Tools Lite
2010-07-14 14:03 . 2009-11-23 23:08 243024 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-14 14:03 . 2010-07-14 14:03 12536 —-a-w- c:\windows\system32\avgrsstx.dll
2010-07-14 14:02 . 2009-11-23 23:08 216400 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-13 02:39 . 2010-07-13 02:39 ——– d—–w- c:\documents and settings\Aboluna\Application Data\IBAGroup
2010-07-12 17:42 . 2009-12-01 23:24 2580 —-a-w- c:\documents and settings\Aboluna\Application Data\wklnhst.dat
2010-07-11 02:10 . 2010-07-11 02:10 ——– d—–w- c:\documents and settings\Aboluna\Application Data\NCH Swift Sound
2010-07-11 02:10 . 2010-07-11 02:10 ——– d—–w- c:\program files\NCH Swift Sound
2010-07-08 16:05 . 2010-07-08 16:05 129160 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-07-04 19:50 . 2010-07-04 19:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Gamers Digital
2010-07-04 19:50 . 2010-07-04 19:50 ——– d—–w- c:\documents and settings\Aboluna\Application Data\Gamers Digital
2010-07-02 17:28 . 2010-07-01 02:04 ——– d—–w- c:\documents and settings\Aboluna\Application Data\Be a King 2
2010-06-30 12:31 . 2006-02-15 14:03 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-26 19:16 . 2010-06-25 20:32 139336 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-06-26 19:16 . 2010-06-25 20:03 371776 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\baseq3\cgamex86.dll
2010-06-26 19:16 . 2010-06-25 20:03 187456 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\baseq3\uix86.dll
2010-06-26 19:16 . 2010-06-25 19:39 214720 —-a-w- c:\windows\system32\PnkBstrB.exe
2010-06-26 19:16 . 2010-06-25 20:03 887448 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\pb\pbcl.dll
2010-06-26 19:16 . 2010-06-25 20:03 57344 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\pb\pbag.dll
2010-06-26 19:16 . 2010-06-25 20:03 2436160 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\baseq3\quakelive.dll
2010-06-25 20:17 . 2010-06-25 20:03 465984 —-a-w- c:\documents and settings\Aboluna\Application Data\id Software\quakelive\home\baseq3\qagamex86.dll
2010-06-25 20:12 . 2010-06-25 19:39 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2010-06-25 20:12 . 2010-06-25 19:39 2373712 —-a-w- c:\windows\system32\pbsvc.exe
2010-06-25 19:39 . 2010-06-25 19:39 ——– d—–w- c:\documents and settings\Aboluna\Application Data\id Software
2010-06-25 19:39 . 2010-06-25 19:39 ——– d—–w- c:\documents and settings\All Users\Application Data\id Software
2010-06-25 16:02 . 2009-12-15 22:03 ——– d—–w- c:\documents and settings\All Users\Application Data\PlayFirst
2010-06-25 16:02 . 2009-12-15 22:03 ——– d—–w- c:\documents and settings\Aboluna\Application Data\PlayFirst
2010-06-24 18:42 . 2010-06-24 18:42 ——– d—–w- c:\documents and settings\Aboluna\Application Data\YoudaGames
2010-06-24 12:22 . 2006-02-15 14:04 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2006-02-15 14:04 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-23 01:10 . 2010-06-23 01:10 ——– d—–w- c:\program files\NCH Software
2010-06-23 01:02 . 2010-06-23 01:02 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2010-06-23 00:42 . 2010-06-23 00:42 200 —-a-w- c:\windows\QCPC80UI.dat
2010-06-22 03:17 . 2010-06-22 03:17 5694 —-a-r- c:\documents and settings\Aboluna\Application Data\Microsoft\Installer\{CA8056BC-05E8-41FB-82C2-4750568CD379}\_86C6042DE7694DB98B69E7.exe
2010-06-22 03:17 . 2010-06-22 03:17 5694 —-a-r- c:\documents and settings\Aboluna\Application Data\Microsoft\Installer\{CA8056BC-05E8-41FB-82C2-4750568CD379}\_3DB404C70A7AFA578074FD.exe
2010-06-22 03:17 . 2010-06-22 03:17 ——– d—–w- c:\program files\MiniTheatre
2010-06-21 15:27 . 2006-02-15 14:04 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 14:58 . 2010-06-18 14:58 ——– d—–w- c:\documents and settings\All Users\Application Data\MythPeople
2010-06-17 14:03 . 2006-02-15 14:02 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 17:08 . 2010-06-21 16:18 545280 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\PicLensHelper.exe
2010-06-14 17:08 . 2010-06-21 16:18 4687360 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\cooliris192.dll
2010-06-14 17:08 . 2010-06-21 16:18 103424 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\pixomatic.dll
2010-06-14 17:08 . 2010-06-21 16:18 425984 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\LaunchCooliris.exe
2010-06-14 17:08 . 2010-06-21 16:18 152064 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\plugins\npcoolirisplugin.dll
2010-06-14 17:08 . 2010-06-21 16:18 4687872 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\libs\cooliris190.dll
2010-06-14 17:08 . 2010-06-21 16:18 57856 —-a-w- c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\components\coolirisstub.dll
2010-06-14 14:31 . 2006-02-15 15:36 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2006-02-15 14:03 1172480 —-a-w- c:\windows\system32\msxml3.dll
2010-06-09 22:07 . 2010-06-09 22:07 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-06-08 01:04 . 2010-06-08 01:04 4096 —-a-w- c:\windows\d3dx.dat
2010-06-02 13:55 . 2009-11-23 23:08 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-07 18:39 . 2009-12-07 18:39 88 –sh–r- c:\windows\system32\3457F750C5.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" [2005-03-11 73728]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 82009]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-08-18 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 88203]
"TPSMain"="TPSMain.exe" [2005-06-01 282624]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-27 122880]
"dla"="c:\windows\system32\dla\DLACTRLW.exe" [2005-10-06 122940]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-14 2065760]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-02-16 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Ralink Wireless Utility.lnk - c:\program files\Ralink\Common\RaUI.exe [2009-11-23 1560576]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-15 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-14 14:03 12536 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Ralink\\Common\\RaUI.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ralink\\Common\\ApUI.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\EA GAMES\\American McGee's Alice\\alice.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/23/2009 6:08 PM 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/23/2009 6:08 PM 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [7/14/2010 9:03 AM 308136]
R2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\drivers\Scutum50.sys [11/23/2009 4:16 PM 19072]
R3 DKRtWrt;DKRtWrt;c:\windows\system32\drivers\DKRtWrt.sys [5/9/2010 7:44 PM 41504]
S3 StumbleUponUpdateService;StumbleUponUpdateService;c:\program files\StumbleUpon\StumbleUponUpdateService.exe [4/7/2010 3:03 PM 120232]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/9/2010 5:07 PM 691696]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://partnerpage.google.com/toshibadirect.com
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: StumbleUpon PhotoBlog It! - StumbleUponIEBar.dll/blogimage
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
TCP: {0F0496EB-DA6E-4F6C-9A75-B64F3264BC96} = 208.67.220.220,208.67.222.222
TCP: {3C2B5551-66B8-47A0-81EA-8BF5DFB5B319} = 208.67.220.220,208.67.222.222
TCP: {F5296D1C-0456-4F13-8298-0CF334ACB00C} = 208.67.220.220,208.67.222.222
FF - ProfilePath - c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.demonoid.com/
FF - prefs.js: keyword.URL - hxxp://search.search-go.net/?sid=10101049100&s=
FF - component: c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\documents and settings\Aboluna\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Aboluna\Application Data\Mozilla\Firefox\Profiles\3lmyblkw.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: browser.search.selectedEngine - Google
FF - user.js: browser.search.order.1 - Google
FF - user.js: keyword.URL - hxxp://search.search-go.net/?sid=10101049100&s=c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-16 15:12
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2010-08-16 15:16:22
ComboFix-quarantined-files.txt 2010-08-16 20:16

Pre-Run: 9,164,902,400 bytes free
Post-Run: 9,287,122,944 bytes free

- - End Of File - - 1FF7CC8F12DD78F3C89D678C894C7D73
Upload was successful
Hi

Just need to do some housekeeping to do now,

Please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT



[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 21 and save it to your desktop.
  • Scroll down to where it says JDK 6 Update 21 (JDK or JRE)
  • Click the Download JRE button to the right
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u21 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u21-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT



You can delete the MBRCheck, DDS and GMER logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI