This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Still Having Problems

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was helped on a previous thread http://forums.whatthetech.com/index.php?sh…113817&st=0. My topic was closed because I didn't respond. I apologize for not responding, but I had a family emergency and wasn't on my computer (or any computer) for awhile.

I could not do the Kapersy Virus Scan that was suggested. I have tried several times, but it fails to load. It keeps telling me that I have to have an uninterupted internet connection.

I still have trouble in being able to update Windows and my Antivirus. I unistalled and reinstalled my Antivirus because it was turned off. It is turned on now, but still won't update.

Malwarebytes gives errors on a lot of the exe files.

Here is a current Hijackthis log. It stalled on the 015 when scanning.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:54:29 AM, on 9/7/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\default\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SYSTEM32\calc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Documents and Settings\default\Desktop\CLEANERS\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Accessories\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\default\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\ACCESSORIES\MESSENGER\YHEXBMES0411.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\ACCESSORIES\MESSENGER\YHEXBMES0411.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://dcode.support.microsoft.com/dcode/A…veX/MSDcode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1122915321078
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (file missing)
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

–
End of file - 6668 bytes

Malwarebytes gives errors on a lot of the exe files.

1.Please post the scan results.
2. So MS wasn't able to get the Windows Updates to work?
3. Lets see if TeaTimer is causing some of the issues.

Use Add/Remove Programs and uninstall TeaTimer or SpyBot.

Try the updates
I will have to go back into safe mode to get the Malwarebytes log. I get an error trying to open it in regular mode. The logs are pretty simple. They say no malicious things were found. It doesn't find anything or fix anything on the scans. I just get a lot of pop up things that says there is an error when it is scanning. Microsoft was working with me on the updates, but I didn't get it all fixed - and then my father died - so I am just getting back to working with them also. I followed the instructions in their last email and was able to get the latest update to download, after renaming the Softwear Distribution folder, but it failed on the install. I have uninstalled Spybot.
Here is the Malwarebytes log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4553 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 8.0.6001.18702 9/6/2010 4:11:27 AM mbam-log-2010-09-06 (04-11-27).txt Scan type: Full scan (C:\|) Objects scanned: 198251 Time elapsed: 1 hour(s), 16 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
I really don't think it's an infection causing this but lets try another scanner.

http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Note: You will need to use Internet explorer for this scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
This is what I got (Scanning Safe Mode with Networking) ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=6123f363381532409f223f80ed41a55a # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-09-08 05:22:05 # local_time=2010-09-08 12:22:05 (-0600, Central Daylight Time) # country="United States" # lang=9 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 2658191 2658191 0 0 # compatibility_mode=768 16777215 100 0 39724051 39724051 0 0 # compatibility_mode=1797 16774106 100 93 0 42107681 0 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=9217 16777214 0 4 222373301 222373301 0 0 # scanned=59393 # found=2 # cleaned=0 # scan_time=5149 C:\System Volume Information\_restore{76EF5784-36BA-49EE-A163-7A60907D77DF}\RP12\A0001004.dll probably a variant of Win32/Adware.BargainBuddy.C application 00000000000000000000000000000000 I C:\System Volume Information\_restore{76EF5784-36BA-49EE-A163-7A60907D77DF}\RP12\A0001007.dll probably a variant of Win32/Adware.BargainBuddy.C application 00000000000000000000000000000000 I
I am not sure with the online virus scan. I have been doing most of the anitspyware scans in safe mode because either I can't open or update the scanners in normal mode, or because with Malwarebytes when it starts giving errors, I can't do anything. It won't even let me open Task Manager to close it. I tried the Kapersky scan again (in Safe with Networking) and it downloads everything (Program and Database) but then won't let me scan - It gives me a 0x8000040050 error. I can go back into normal mode and try to do the scans and see if they work.
I am trying the Eset in normal mode. It opened - but then the window flashed a couple times and then closed. Now when I click on the green scanner button, it doesn't open the other windo - for the scanner.
Now I am able to open it, but it won't update all the way. It goes to about 98% and then says it is unable to update - and asks if I have set proxy. It also says it has indentified my anti-virus, but if I turn the guard to disable, ESET still doesn't update.
check some settings on your system:
  • Enter your Control Panel and double-click on Network Connections
  • Then right click on your Default Connection
    • Usually Local Area Connection for Cable and DSL, or AOL Connection.
  • Left click on Properties
  • Double-Click on the Internet Protocol (TCP/IP) item
  • Select the radio dial that says Obtain DNS Servers Automatically
  • Press OK twice to get out of the properties screen
  • Restart the computer
Go to Start->Run->Type CMD and click Ok. The MSDOS Window will be displayed. At the command prompt, type the following and press Enter after each line:

ipconfig / (The space between g and / is needed)

IPCONFIG /release

IPCONFIG /renew

IPCONFIG /flushdns

IPCONFIG /registerdns
Exit

Restart the computer.
I did that, but am still getting the proxy message. I tried downloading it in safe mode, and then rebooting in normal mode to see if the scan would run, sinc eit had just been downloaded. That worked to get the scan to run - but I haven't been able to complete a scan yet. It runs for awhile and I get a visual c runtime error before it is over. So it has been hard to complete.
Uninstall SpyBot using Add/Remove programs.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Thanks!
I downloaded Combofix and ran it in safe mode. Then I was able to run it in normal mode also. In safe mode, it told me that my anti-virus was enabled - but I couldn't find anyway to find out of it was on or to turn it off.

Here are my logs:

ComboFix 10-09-11.02 - default 09/11/2010 23:20:55.3.1 - FAT32x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.254.67 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Microsoft
c:\microsoft\Protect\CREDHIST
c:\windows\Downloaded Program Files\ODCTOOLS

.
((((((((((((((((((((((((( Files Created from 2010-08-12 to 2010-09-12 )))))))))))))))))))))))))))))))
.

2010-09-10 15:27 . 2010-09-07 23:00 20464696 —-a-w- c:\documents and settings\default\Application Data\Google\Update\Download\{A28F1E34-AA28-4428-B7F6-D3B4E8717FFD}\chrome_installer.exe
2010-09-10 05:26 . 2010-09-10 05:26 5395512 —-a-w- c:\documents and settings\default\Application Data\Google\Update\Download\{1CDD5048-9203-40C6-BA4C-C5E80EA0822B}\chrome_updater.exe
2010-09-08 15:46 . 2010-09-08 15:46 ——– d—–w- c:\program files\ESET
2010-09-07 15:40 . 2010-09-07 15:40 ——– d—–w- c:\documents and settings\default\Application Data\Avira
2010-09-07 15:40 . 2010-09-07 15:40 ——– d—–w- c:\documents and settings\default\Application Data\Avira
2010-09-07 15:20 . 2010-03-01 15:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-07 15:20 . 2009-05-11 17:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-09-07 15:20 . 2010-02-16 19:24 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-07 15:20 . 2009-05-11 17:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-09-07 15:20 . 2010-09-07 15:20 ——– d—–w- c:\program files\Avira
2010-09-07 15:20 . 2010-09-07 15:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-09-06 07:19 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-06 07:18 . 2010-09-06 07:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-06 07:18 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-04 03:19 . 2010-09-04 03:19 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-08-29 16:13 . 2008-04-13 18:45 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-08-21 04:45 . 2010-09-09 00:06 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-20 22:26 . 2010-09-07 17:46 63488 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-20 22:25 . 2010-08-20 22:25 52224 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-08-20 17:40 . 2010-08-20 17:40 27288 —-a-w- c:\documents and settings\default\Application Data\Google\Update\1.2.183.29\goopdateres_tr.dll
2010-08-20 07:17 . 2010-08-20 07:17 ——– d—–w- c:\documents and settings\default\Application Data\Temp
2010-08-20 07:17 . 2010-08-20 07:17 ——– d—–w- c:\documents and settings\default\Application Data\Temp
2010-08-20 06:46 . 2010-05-21 19:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-08-20 06:42 . 2010-08-20 06:42 ——– d—–w- c:\program files\Windows Defender
2010-08-20 06:34 . 2010-09-07 17:45 117760 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-08-20 04:31 . 2010-06-24 12:21 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-15 17:09 . 2010-09-09 00:12 593 —-a-w- C:\register.bat
2010-08-15 16:23 . 2010-06-18 13:36 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-08-15 16:18 . 2010-06-14 14:31 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe
2010-08-15 16:07 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
2010-08-15 15:57 . 2010-08-15 15:57 ——– d—–w- c:\windows\SDOLD2
2010-08-14 18:42 . 2010-08-14 18:42 ——– d—–w- c:\documents and settings\default\Apps
2010-08-14 07:55 . 2010-08-14 07:55 ——– d—–w- c:\program files\Windows Live Safety Center
2010-08-14 05:51 . 2010-09-07 07:13 452104 —-a-w- c:\documents and settings\default\Application Data\Real\Update\setup3.12\setup.exe
2010-08-13 07:07 . 2010-08-13 07:07 ——– d—–w- c:\documents and settings\default\.ehdc

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-10 06:30 . 2002-12-10 18:58 3667 —-a-w- c:\program files\i_view32.ini
2010-08-18 01:58 . 2010-08-20 17:43 945720 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\chrome.exe
2010-08-18 01:57 . 2010-08-20 17:43 216120 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\sr.dll
2010-08-18 01:56 . 2010-08-20 17:43 3184184 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\gears.dll
2010-08-18 01:56 . 2010-08-20 17:43 8760 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\chrome_launcher.exe
2010-08-18 01:56 . 2010-08-20 17:43 17939512 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\chrome.dll
2010-08-18 01:56 . 2010-08-20 17:43 71224 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avutil-50.dll
2010-08-18 01:56 . 2010-08-20 17:43 151608 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avformat-52.dll
2010-08-18 01:56 . 2010-08-20 17:43 1186360 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avcodec-52.dll
2010-08-18 00:26 . 2010-08-20 17:43 5964752 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\gcswf32.dll
2010-08-18 00:00 . 2010-08-20 17:43 1127992 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Installer\setup.exe
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\SpywareBlaster
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\eCleaner
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\CCleaner
2010-08-08 04:44 . 2010-08-08 04:44 ——– d—–w- c:\program files\Ulead Systems
2010-08-08 03:37 . 2010-08-08 03:37 34144 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-07 21:33 . 2010-08-07 21:33 ——– d—–w- c:\program files\Trend Micro
2010-06-30 12:31 . 2003-08-30 17:05 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2004-02-06 23:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2003-08-30 17:06 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2003-08-30 17:05 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2003-08-30 17:03 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2003-08-30 17:33 744448 —-a-w- c:\windows\PCHEALTH\HELPCTR\BINARIES\HelpSvc.exe
2010-06-14 07:41 . 2003-08-30 17:04 1172480 —-a-w- c:\windows\system32\msxml3.dll
2006-12-24 23:56 . 2002-09-03 01:05 19129 —ha-w- c:\program files\I_VIEW32.GID
2006-10-11 23:21 . 2006-09-29 20:12 11177 —ha-w- c:\program files\hpothb07.dat
2006-10-11 23:21 . 2005-05-14 00:48 152081 —ha-w- c:\program files\hpothb07.tif
2006-10-05 20:34 . 2006-10-05 20:34 11996626 —-a-w- c:\program files\Scan0007.tif
2006-10-05 19:33 . 2006-10-05 19:33 1555 —-a-w- c:\program files\ganttproject.jnlp
2006-09-29 20:14 . 2006-09-29 20:14 11996628 —-a-w- c:\program files\Scan0006.tif
2006-09-28 03:32 . 2006-09-28 03:32 11996604 —-a-w- c:\program files\Scan0005.tif
2006-09-28 01:31 . 2006-09-28 01:31 11996604 —-a-w- c:\program files\Scan0004.tif
2006-09-28 01:21 . 2006-09-28 01:21 11996628 —-a-w- c:\program files\Scan0003.tif
2006-09-27 23:36 . 2006-09-27 23:36 11996628 —-a-w- c:\program files\Scan0002.tif
2006-09-27 23:32 . 2006-09-27 23:32 11996604 —-a-w- c:\program files\Scan0001.tif
2006-02-18 22:12 . 2003-10-05 12:55 5120 –sha-w- c:\program files\Thumbs.db
2005-01-11 18:53 . 2004-07-22 21:23 17 —-a-w- c:\program files\stinger.opt
2004-11-18 02:56 . 2002-08-16 01:15 661 —-a-w- c:\program files\i_view32.exe.manifest
2004-11-18 02:56 . 2001-12-23 02:42 765 —-a-w- c:\program files\i_languages.txt
2004-11-18 02:56 . 2001-12-23 02:42 5754 —-a-w- c:\program files\i_plugins.txt
2004-11-18 02:56 . 2001-12-23 02:42 55822 —-a-w- c:\program files\i_changes.txt
2004-11-18 02:56 . 2001-12-23 02:42 432128 —-a-w- c:\program files\i_view32.exe
2004-11-18 02:56 . 2001-12-23 02:42 3940 —-a-w- c:\program files\i_view32.cnt
2004-11-18 02:56 . 2001-12-23 02:42 31744 —-a-w- c:\program files\iv_uninstall.exe
2004-11-18 02:56 . 2001-12-23 02:42 2189 —-a-w- c:\program files\i_about.txt
2004-11-18 02:56 . 2001-12-23 02:42 168929 —-a-w- c:\program files\i_view32.hlp
2004-11-18 02:56 . 2001-12-23 02:42 10579 —-a-w- c:\program files\i_options.txt
2004-07-22 20:59 . 2004-07-22 20:57 800263 —-a-w- c:\program files\stinger.exe
2004-02-28 23:57 . 2004-02-28 23:57 36864 —-a-w- c:\program files\soc. paper.doc
2004-02-27 19:31 . 2004-02-27 01:30 29696 —-a-w- c:\program files\Capital Punishment.doc
2004-02-26 22:41 . 2004-02-26 22:41 10752 —-a-w- c:\program files\abortion paper-work cited.wps
2004-02-26 22:40 . 2004-02-26 22:40 26624 —-a-w- c:\program files\abortion paper-1.wps
2004-02-23 13:54 . 2004-02-23 13:54 1167762 —-a-w- c:\program files\kibler.pdf
2003-06-14 03:04 . 2003-06-14 03:04 487428 —-a-w- c:\program files\nokia.mpeg
2002-11-15 17:55 . 2002-11-15 17:55 456128 —-a-w- c:\program files\PopUpStopper.exe
2002-10-21 03:11 . 2002-10-21 03:11 553687 —-a-w- c:\program files\RegCleaner.exe
2002-08-16 01:14 . 2002-08-16 01:14 827392 —-a-w- c:\program files\iview375.exe
2002-05-29 04:22 . 2002-05-29 04:18 27 —-a-w- c:\program files\alias.dat
2002-05-29 04:20 . 2002-05-29 04:18 27 —-a-w- c:\program files\cfilter.dat
2002-05-29 04:18 . 2002-05-29 04:18 1688 —-a-w- c:\program files\cverinfo.ini
2002-05-29 04:18 . 2002-05-29 04:18 4484 —-a-w- c:\program files\unins000.dat
2002-05-29 04:18 . 2002-02-10 08:00 72748 —-a-w- c:\program files\unins000.exe
2002-05-21 14:55 . 2002-05-21 14:55 0 —-a-w- c:\program files\CUSTDATA.INI
2002-04-26 05:11 . 2002-04-26 05:11 1069056 —-a-w- c:\program files\cstub.exe
2002-04-15 20:34 . 2002-04-15 20:34 172032 —-a-w- c:\program files\cchat.exe
2002-03-25 17:59 . 2002-03-25 17:59 77824 —-a-w- c:\program files\CUpdater.exe
2002-03-23 03:04 . 2002-03-23 03:04 3222744 —-a-w- c:\program files\acdzip.exe
2002-03-20 13:56 . 2002-03-20 13:57 3877 —-a-w- c:\program files\AGBP.csv
2002-03-10 18:17 . 2002-03-10 18:17 877531 —-a-w- c:\program files\aaw.exe
2002-03-10 18:12 . 2002-03-10 18:12 14270 —-a-w- c:\program files\reflist.zip
2002-02-09 14:18 . 2002-02-09 14:18 383 —-a-w- c:\program files\smileys.txt
2002-01-16 02:05 . 2002-01-16 02:05 2654 —-a-w- c:\program files\catlist.dat
2002-01-14 23:30 . 2002-01-14 23:30 21823560 —-a-w- c:\program files\dotnetfx.exe
2001-12-23 02:41 . 2001-12-23 02:41 816640 —-a-w- c:\program files\iview361.exe
2001-09-08 19:25 . 2001-09-08 19:25 46 —-a-w- c:\program files\cconfig.ini
2001-02-02 21:59 . 2001-02-02 21:59 23357 —h–w- c:\program files\folder.htt
2000-10-13 11:01 . 2000-10-13 11:01 9322 —-a-w- c:\program files\macros.dat
2000-10-12 05:44 . 2002-05-21 14:55 167936 —-a-w- c:\program files\TIME.EXE
1999-11-20 01:29 . 1999-11-20 01:29 2499 —-a-w- c:\program files\quote.ini
1999-02-27 23:25 . 1999-02-27 23:25 31244 —-a-w- c:\program files\CHEETACHAT.HLP
1999-02-19 12:54 . 1999-02-19 12:54 40960 —-a-w- c:\program files\SSubTmr6.dll
1998-11-08 15:47 . 1998-11-08 15:47 8850 —-a-w- c:\program files\emotions.dat
1998-06-04 19:30 . 2002-07-04 19:53 709120 —-a-w- c:\program files\winzip95.exe
1997-08-13 16:19 . 2002-07-21 14:17 1714 —-a-w- c:\program files\UsingCC.txt
1997-08-13 16:10 . 2002-07-21 14:17 2930 —-a-w- c:\program files\general.txt
1997-08-13 16:09 . 2002-07-21 14:17 1121 —-a-w- c:\program files\tech.txt
1997-08-13 16:08 . 2002-07-21 14:17 3570 —-a-w- c:\program files\install.txt
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\default\Application Data\Google\Update\GoogleUpdate.exe" [2010-08-20 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-12-03 180269]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2005-01-27 16:17 1381376 ——w- c:\program files\Ahead\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 16:50 155648 —-a-w- c:\windows\SYSTEM32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2004-12-03 19:57 204845 —-a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"Pctspk"=2 (0x2)
"McShield"=3 (0x3)
"AvSynMgr"=2 (0x2)
"Messenger"=2 (0x2)
"InCDsrvR"=2 (0x2)
"InCDsrv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCHealth"=c:\windows\PCHealth\Support\PCHSchd.exe -s
"PCTVOICE"=pctvoice.exe
"eMachine eBoard"=c:\progra~1\ESOFT\EBOARD\eBoard.exe
"uTOK uSleep"=
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"LoadQM"=loadqm.exe
"CountrySelection"=pctptt.exe
"QuickTime Task"="c:\windows\SYSTEM\QTTASK.EXE" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"SchedulingAgent"=mstask.exe
"SSDPSRV"=c:\windows\SYSTEM\ssdpsrv.exe
"*StateMgr"=c:\windows\System\Restore\StateMgr.exe
"McAfeeVirusScanService"=c:\program files\Network Associates\VirusScan\AVSYNMGR.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R3 PD1030VID;Creative WebCam Pro;c:\windows\system32\DRIVERS\p1030vid.sys [2002-05-20 167673]
R3 Ptserli;PCTEL Serial Device Driver for INTEL;c:\windows\system32\DRIVERS\ptserli.sys [2001-08-17 128286]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
2001-03-23 21:17 7168 ——w- c:\windows\SYSTEM32\updcrl.exe
.
Contents of the 'Scheduled Tasks' folder

2010-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-688789844-1708537768-1004Core.job
- c:\documents and settings\default\Application Data\Google\Update\GoogleUpdate.exe [2010-08-20 17:40]

2010-09-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = 127.0.0.1
Trusted Zone: aol.com\free
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\default\Application Data\Mozilla\Firefox\Profiles\oltr6zob.default\
FF - plugin: c:\documents and settings\default\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-11 23:36
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(360)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2010-09-11 23:42:28
ComboFix-quarantined-files.txt 2010-09-12 04:42
ComboFix2.txt 2010-08-12 19:38

Pre-Run: 3,563,257,856 bytes free
Post-Run: 3,560,931,328 bytes free

- - End Of File - - 33D0752A47FF5952CC0159B77655D5F3



ComboFix 10-09-11.02 - default 09/12/2010 0:24.4.1 - FAT32x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((( Files Created from 2010-08-12 to 2010-09-12 )))))))))))))))))))))))))))))))
.

2010-09-12 05:12 . 2010-09-03 00:58 1534008 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\npchrome_frame.dll
2010-09-12 05:11 . 2010-09-03 00:57 3184184 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\gears.dll
2010-09-12 05:10 . 2010-09-03 00:57 20078648 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\chrome.dll
2010-09-12 05:09 . 2010-09-03 00:57 204344 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\ca.dll
2010-09-12 05:09 . 2010-09-03 00:57 203320 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\bn.dll
2010-09-12 05:09 . 2010-09-03 00:57 237112 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\bg.dll
2010-09-12 05:09 . 2010-09-03 00:57 91192 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\avutil-50.dll
2010-09-12 05:09 . 2010-09-03 00:57 193592 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\avformat-52.dll
2010-09-12 05:09 . 2010-09-03 00:57 1434680 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\avcodec-52.dll
2010-09-12 05:09 . 2010-09-03 00:57 193080 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\ar.dll
2010-09-12 05:09 . 2010-09-03 00:57 107064 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\am.dll
2010-09-10 05:26 . 2010-09-10 05:26 5395512 —-a-w- c:\documents and settings\default\Application Data\Google\Update\Download\{1CDD5048-9203-40C6-BA4C-C5E80EA0822B}\chrome_updater.exe
2010-09-08 15:46 . 2010-09-08 15:46 ——– d—–w- c:\program files\ESET
2010-09-07 15:40 . 2010-09-07 15:40 ——– d—–w- c:\documents and settings\default\Application Data\Avira
2010-09-07 15:40 . 2010-09-07 15:40 ——– d—–w- c:\documents and settings\default\Application Data\Avira
2010-09-07 15:20 . 2010-03-01 15:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-07 15:20 . 2009-05-11 17:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-09-07 15:20 . 2010-02-16 19:24 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-07 15:20 . 2009-05-11 17:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-09-07 15:20 . 2010-09-07 15:20 ——– d—–w- c:\program files\Avira
2010-09-07 15:20 . 2010-09-07 15:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-09-06 07:19 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-06 07:18 . 2010-09-06 07:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-06 07:18 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-04 03:19 . 2010-09-04 03:19 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-08-29 16:13 . 2008-04-13 18:45 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-08-21 04:45 . 2010-09-09 00:06 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-08-20 22:26 . 2010-09-07 17:46 63488 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-20 22:25 . 2010-08-20 22:25 52224 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-08-20 17:40 . 2010-08-20 17:40 27288 —-a-w- c:\documents and settings\default\Application Data\Google\Update\1.2.183.29\goopdateres_tr.dll
2010-08-20 07:17 . 2010-08-20 07:17 ——– d—–w- c:\documents and settings\default\Application Data\Temp
2010-08-20 07:17 . 2010-08-20 07:17 ——– d—–w- c:\documents and settings\default\Application Data\Temp
2010-08-20 06:46 . 2010-05-21 19:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-08-20 06:42 . 2010-08-20 06:42 ——– d—–w- c:\program files\Windows Defender
2010-08-20 06:34 . 2010-09-07 17:45 117760 —-a-w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\documents and settings\default\Application Data\SUPERAntiSpyware.com
2010-08-20 06:33 . 2010-08-20 06:33 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-08-20 04:31 . 2010-06-24 12:21 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-15 17:09 . 2010-09-09 00:12 593 —-a-w- C:\register.bat
2010-08-15 16:23 . 2010-06-18 13:36 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-08-15 16:18 . 2010-06-14 14:31 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe
2010-08-15 16:07 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
2010-08-15 15:57 . 2010-08-15 15:57 ——– d—–w- c:\windows\SDOLD2
2010-08-14 18:42 . 2010-08-14 18:42 ——– d—–w- c:\documents and settings\default\Apps
2010-08-14 07:55 . 2010-08-14 07:55 ——– d—–w- c:\program files\Windows Live Safety Center
2010-08-14 05:51 . 2010-09-07 07:13 452104 —-a-w- c:\documents and settings\default\Application Data\Real\Update\setup3.12\setup.exe
2010-08-13 07:07 . 2010-08-13 07:07 ——– d—–w- c:\documents and settings\default\.ehdc

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-10 06:30 . 2002-12-10 18:58 3667 —-a-w- c:\program files\i_view32.ini
2010-09-03 00:57 . 2010-09-12 05:11 178744 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\et.dll
2010-09-03 00:57 . 2010-09-12 05:11 207928 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\es.dll
2010-09-03 00:57 . 2010-09-12 05:11 204344 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\es-419.dll
2010-09-03 00:57 . 2010-09-12 05:11 174648 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\en-US.dll
2010-09-03 00:57 . 2010-09-12 05:11 175160 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\en-GB.dll
2010-09-03 00:57 . 2010-09-12 05:11 258616 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\el.dll
2010-09-03 00:57 . 2010-09-12 05:11 169016 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\de.dll
2010-09-03 00:57 . 2010-09-12 05:11 186936 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\da.dll
2010-09-03 00:57 . 2010-09-12 05:11 195128 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Locales\cs.dll
2010-09-03 00:57 . 2010-09-12 05:12 10911800 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\icudt42.dll
2010-09-03 00:57 . 2010-09-12 05:13 89656 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\chrome_launcher.exe
2010-09-02 23:01 . 2010-09-12 05:13 1131576 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\Installer\setup.exe
2010-09-02 22:53 . 2010-09-12 05:11 5964752 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\6.0.472.55\gcswf32.dll
2010-08-18 01:58 . 2010-08-20 17:43 111672 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\rlz.dll
2010-08-18 01:58 . 2010-08-20 17:43 1154616 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\npchrome_frame.dll
2010-08-18 01:58 . 2010-08-20 17:43 1133624 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\nacl64.exe
2010-08-18 01:58 . 2010-08-20 17:43 2158136 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\nacl64.dll
2010-08-18 01:58 . 2010-08-20 17:43 100920 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\zh-TW.dll
2010-08-18 01:58 . 2010-08-20 17:43 100920 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\zh-CN.dll
2010-08-18 01:58 . 2010-08-20 17:43 218168 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\uk.dll
2010-08-18 01:58 . 2010-08-20 17:43 197176 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\vi.dll
2010-08-18 01:58 . 2010-08-20 17:43 189496 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\tr.dll
2010-08-18 01:58 . 2010-08-20 17:43 234040 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\th.dll
2010-08-18 01:58 . 2010-08-20 17:43 228920 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\ta.dll
2010-08-18 01:58 . 2010-08-20 17:43 206392 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\te.dll
2010-08-18 01:58 . 2010-08-20 17:43 138808 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Locales\sw.dll
2010-08-18 01:56 . 2010-08-20 17:43 3184184 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\gears.dll
2010-08-18 01:56 . 2010-08-20 17:43 8760 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\chrome_launcher.exe
2010-08-18 01:56 . 2010-08-20 17:43 17939512 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\chrome.dll
2010-08-18 01:56 . 2010-08-20 17:43 71224 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avutil-50.dll
2010-08-18 01:56 . 2010-08-20 17:43 151608 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avformat-52.dll
2010-08-18 01:56 . 2010-08-20 17:43 1186360 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\avcodec-52.dll
2010-08-18 00:26 . 2010-08-20 17:43 5964752 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\gcswf32.dll
2010-08-18 00:00 . 2010-08-20 17:43 1127992 —-a-w- c:\documents and settings\default\Application Data\Google\Chrome\Application\5.0.375.127\Installer\setup.exe
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\SpywareBlaster
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\eCleaner
2010-08-08 04:45 . 2010-08-08 04:45 ——– d—–w- c:\program files\CCleaner
2010-08-08 04:44 . 2010-08-08 04:44 ——– d—–w- c:\program files\Ulead Systems
2010-08-08 03:37 . 2010-08-08 03:37 34144 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-07 21:33 . 2010-08-07 21:33 ——– d—–w- c:\program files\Trend Micro
2010-06-30 12:31 . 2003-08-30 17:05 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2004-02-06 23:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2003-08-30 17:06 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2003-08-30 17:05 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2003-08-30 17:03 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2003-08-30 17:33 744448 —-a-w- c:\windows\PCHEALTH\HELPCTR\BINARIES\HelpSvc.exe
2010-06-14 07:41 . 2003-08-30 17:04 1172480 —-a-w- c:\windows\system32\msxml3.dll
2006-12-24 23:56 . 2002-09-03 01:05 19129 —ha-w- c:\program files\I_VIEW32.GID
2006-10-11 23:21 . 2006-09-29 20:12 11177 —ha-w- c:\program files\hpothb07.dat
2006-10-11 23:21 . 2005-05-14 00:48 152081 —ha-w- c:\program files\hpothb07.tif
2006-10-05 20:34 . 2006-10-05 20:34 11996626 —-a-w- c:\program files\Scan0007.tif
2006-10-05 19:33 . 2006-10-05 19:33 1555 —-a-w- c:\program files\ganttproject.jnlp
2006-09-29 20:14 . 2006-09-29 20:14 11996628 —-a-w- c:\program files\Scan0006.tif
2006-09-28 03:32 . 2006-09-28 03:32 11996604 —-a-w- c:\program files\Scan0005.tif
2006-09-28 01:31 . 2006-09-28 01:31 11996604 —-a-w- c:\program files\Scan0004.tif
2006-09-28 01:21 . 2006-09-28 01:21 11996628 —-a-w- c:\program files\Scan0003.tif
2006-09-27 23:36 . 2006-09-27 23:36 11996628 —-a-w- c:\program files\Scan0002.tif
2006-09-27 23:32 . 2006-09-27 23:32 11996604 —-a-w- c:\program files\Scan0001.tif
2006-02-18 22:12 . 2003-10-05 12:55 5120 –sha-w- c:\program files\Thumbs.db
2005-01-11 18:53 . 2004-07-22 21:23 17 —-a-w- c:\program files\stinger.opt
2004-11-18 02:56 . 2002-08-16 01:15 661 —-a-w- c:\program files\i_view32.exe.manifest
2004-11-18 02:56 . 2001-12-23 02:42 765 —-a-w- c:\program files\i_languages.txt
2004-11-18 02:56 . 2001-12-23 02:42 5754 —-a-w- c:\program files\i_plugins.txt
2004-11-18 02:56 . 2001-12-23 02:42 55822 —-a-w- c:\program files\i_changes.txt
2004-11-18 02:56 . 2001-12-23 02:42 432128 —-a-w- c:\program files\i_view32.exe
2004-11-18 02:56 . 2001-12-23 02:42 3940 —-a-w- c:\program files\i_view32.cnt
2004-11-18 02:56 . 2001-12-23 02:42 31744 —-a-w- c:\program files\iv_uninstall.exe
2004-11-18 02:56 . 2001-12-23 02:42 2189 —-a-w- c:\program files\i_about.txt
2004-11-18 02:56 . 2001-12-23 02:42 168929 —-a-w- c:\program files\i_view32.hlp
2004-11-18 02:56 . 2001-12-23 02:42 10579 —-a-w- c:\program files\i_options.txt
2004-07-22 20:59 . 2004-07-22 20:57 800263 —-a-w- c:\program files\stinger.exe
2004-02-28 23:57 . 2004-02-28 23:57 36864 —-a-w- c:\program files\soc. paper.doc
2004-02-27 19:31 . 2004-02-27 01:30 29696 —-a-w- c:\program files\Capital Punishment.doc
2004-02-26 22:41 . 2004-02-26 22:41 10752 —-a-w- c:\program files\abortion paper-work cited.wps
2004-02-26 22:40 . 2004-02-26 22:40 26624 —-a-w- c:\program files\abortion paper-1.wps
2004-02-23 13:54 . 2004-02-23 13:54 1167762 —-a-w- c:\program files\kibler.pdf
2003-06-14 03:04 . 2003-06-14 03:04 487428 —-a-w- c:\program files\nokia.mpeg
2002-11-15 17:55 . 2002-11-15 17:55 456128 —-a-w- c:\program files\PopUpStopper.exe
2002-10-21 03:11 . 2002-10-21 03:11 553687 —-a-w- c:\program files\RegCleaner.exe
2002-08-16 01:14 . 2002-08-16 01:14 827392 —-a-w- c:\program files\iview375.exe
2002-05-29 04:22 . 2002-05-29 04:18 27 —-a-w- c:\program files\alias.dat
2002-05-29 04:20 . 2002-05-29 04:18 27 —-a-w- c:\program files\cfilter.dat
2002-05-29 04:18 . 2002-05-29 04:18 1688 —-a-w- c:\program files\cverinfo.ini
2002-05-29 04:18 . 2002-05-29 04:18 4484 —-a-w- c:\program files\unins000.dat
2002-05-29 04:18 . 2002-02-10 08:00 72748 —-a-w- c:\program files\unins000.exe
2002-05-21 14:55 . 2002-05-21 14:55 0 —-a-w- c:\program files\CUSTDATA.INI
2002-04-26 05:11 . 2002-04-26 05:11 1069056 —-a-w- c:\program files\cstub.exe
2002-04-15 20:34 . 2002-04-15 20:34 172032 —-a-w- c:\program files\cchat.exe
2002-03-25 17:59 . 2002-03-25 17:59 77824 —-a-w- c:\program files\CUpdater.exe
2002-03-23 03:04 . 2002-03-23 03:04 3222744 —-a-w- c:\program files\acdzip.exe
2002-03-20 13:56 . 2002-03-20 13:57 3877 —-a-w- c:\program files\AGBP.csv
2002-03-10 18:17 . 2002-03-10 18:17 877531 —-a-w- c:\program files\aaw.exe
2002-03-10 18:12 . 2002-03-10 18:12 14270 —-a-w- c:\program files\reflist.zip
2002-02-09 14:18 . 2002-02-09 14:18 383 —-a-w- c:\program files\smileys.txt
2002-01-16 02:05 . 2002-01-16 02:05 2654 —-a-w- c:\program files\catlist.dat
2002-01-14 23:30 . 2002-01-14 23:30 21823560 —-a-w- c:\program files\dotnetfx.exe
2001-12-23 02:41 . 2001-12-23 02:41 816640 —-a-w- c:\program files\iview361.exe
2001-09-08 19:25 . 2001-09-08 19:25 46 —-a-w- c:\program files\cconfig.ini
2001-02-02 21:59 . 2001-02-02 21:59 23357 —h–w- c:\program files\folder.htt
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\default\Application Data\Google\Update\GoogleUpdate.exe" [2010-08-20 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-12-03 180269]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2005-01-27 16:17 1381376 ——w- c:\program files\Ahead\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 16:50 155648 —-a-w- c:\windows\SYSTEM32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2004-12-03 19:57 204845 —-a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"Pctspk"=2 (0x2)
"McShield"=3 (0x3)
"AvSynMgr"=2 (0x2)
"Messenger"=2 (0x2)
"InCDsrvR"=2 (0x2)
"InCDsrv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"PCHealth"=c:\windows\PCHealth\Support\PCHSchd.exe -s
"PCTVOICE"=pctvoice.exe
"eMachine eBoard"=c:\progra~1\ESOFT\EBOARD\eBoard.exe
"uTOK uSleep"=
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"LoadQM"=loadqm.exe
"CountrySelection"=pctptt.exe
"QuickTime Task"="c:\windows\SYSTEM\QTTASK.EXE" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"SchedulingAgent"=mstask.exe
"SSDPSRV"=c:\windows\SYSTEM\ssdpsrv.exe
"*StateMgr"=c:\windows\System\Restore\StateMgr.exe
"McAfeeVirusScanService"=c:\program files\Network Associates\VirusScan\AVSYNMGR.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/7/2010 10:21 AM 135336]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 PD1030VID;Creative WebCam Pro;c:\windows\SYSTEM32\DRIVERS\p1030vid.sys [3/28/2004 3:25 PM 167673]
S3 Ptserli;PCTEL Serial Device Driver for INTEL;c:\windows\SYSTEM32\DRIVERS\ptserli.sys [8/30/2003 12:24 PM 128286]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-14 00:12 73216 —-a-w- c:\progra~1\OUTLOO~1\setup50.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
2001-03-23 21:17 7168 ——w- c:\windows\SYSTEM32\updcrl.exe
.
Contents of the 'Scheduled Tasks' folder

2010-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-688789844-1708537768-1004Core.job
- c:\documents and settings\default\Application Data\Google\Update\GoogleUpdate.exe [2010-08-20 17:40]

2010-09-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = 127.0.0.1
Trusted Zone: aol.com\free
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\default\Application Data\Mozilla\Firefox\Profiles\oltr6zob.default\
FF - plugin: c:\documents and settings\default\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-12 00:46
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(412)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(8644)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2010-09-12 00:54:52
ComboFix-quarantined-files.txt 2010-09-12 05:54
ComboFix2.txt 2010-09-12 04:42
ComboFix3.txt 2010-08-12 19:38

Pre-Run: 3,147,005,952 bytes free
Post-Run: 3,144,908,800 bytes free

- - End Of File - - 1CCD24B0B7A2DE8697346DE5D7252291

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI