This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Funmoods redirect virus [Closed]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,
My PC became infected with a funmoods redirect virus and probably more a while ago - some of which MalwareBytes and McAfee recognised and cleared. Unfortunately though this didn't seem to do the trick and the system became progressively more and more snarled up (please excuse my basic language - I'm really no computer expert! ).

Two days ago, I came across an old thread from here whilst googling on my laptop - with the user describing a similar problem (link). Having no previous knowledge of this forum and therefore not knowing the 'forum rules', I followed the step by step advice given by one of your experts - including installing and running ComboFix. Having subsequently looked at your forum and read more information, I realise that this was very naive….but luckily it seems to have helped a bit rather than hindered the running of the system. The internet connection is still virtually unusable though ( I had downloaded the programs given on the thread onto a USB memory stick from my laptop to put them on my PC). Also, I stopped following the advice given in the thread after post 9 when, in contrast to that particular user, the running of the MBRCheck.exe program DID seem to indicate a problem on my system.

I would be extremely grateful for any help and I apologise for unintentionally flouting the forum rules!

Thanks,

Jen.


Here's the current logfile from Highjackthis (which I've only just downloaded, unfortunately)…..

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:09:26, on 12/07/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Microsoft\BingBar\7.1.382.0\BBSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\mfevtps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Kontiki\KHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\SoftwareDistribution\Download\Install\Windows-KB890830-V4.9-delta.exe
c:\32997d239546bcd60879fe\mrtstub.exe
C:\WINDOWS\system32\MRT.exe
C:\Documents and Settings\Dougie\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.search.yahoo.com/search?fr=mcafee&p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120524054249.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.382.0\BingExt.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.382.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [McAfeeWrapperApplication] "C:\Program Files\McAfeeMOBK\WrapperTrayIcon.exe"
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,RunDLLEntry
O4 - HKLM\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: BBC iPlayer Desktop.lnk = C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll (file missing)
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1cac295ec48ec54) (gupdate1cac295ec48ec54) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (file missing)
O23 - Service: McAfee Proxy Service (McProxy) - Unknown owner - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (file missing)
O23 - Service: McAfee McShield (McShield) - Unknown owner - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe (file missing)
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 15155 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———

Since you ran ComboFix already could you post that log please? It should be located at C:\ComboFix.txt
——–

OTL
  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in

    netsvcs
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If asked whether you would like to update the Avast virus database please do.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the ComboFix log if you can find it and the logs made by OTL and aswMBR. :)
Hi!

Thanks a lot for helping me and for a super speedy reply. I really appreciate it. Just got in from work and have been able to follow your instructions - up to a point…..

Here's the ComboFix log…

ComboFix 12-07-10.01 - Dougie 11/07/2012 3:45.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1420 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dougie\Desktop\CFScript.txt
.
FILE ::
"c:\program files\Common Files\McAfee\MNA\McNASvc.exe"
"c:\program files\McAfee.com\Agent\mcagent.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\McAfee
c:\documents and settings\All Users\Application Data\McAfee\dspwrp\SmartMessaging.db
c:\documents and settings\All Users\Application Data\McAfee\HackerWatch\data\hwid.idx
c:\documents and settings\All Users\Application Data\McAfee\HackerWatch\data\HwLocal.xdb
c:\documents and settings\All Users\Application Data\McAfee\HackerWatch\data\HwShared.xdb
c:\documents and settings\All Users\Application Data\McAfee\HackerWatch\sum_04_hw.htm
c:\documents and settings\All Users\Application Data\McAfee\McCleanup\mccleanup.log
c:\documents and settings\All Users\Application Data\McAfee\mcdndb.dat
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Anti-Spam\mcinst\mcinst000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Anti-Spam\McSvHost\McSvHost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\antitheft\AutoUninstall\AutoUninstall000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\antitheft\Explorer\Explorer000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\Install\Install001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\Install\Install002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\Install\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\McAfeeSetup(1)\McAfeeSetup(1)000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\McAfeeSetup(2)\McAfeeSetup(2)000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\McAfeeSetup(3)\McAfeeSetup(3)000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\McAfeeSetup(4)\McAfeeSetup(4)000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\McAfeeSetup\McAfeeSetup000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\mcagent\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\mcagent\mcagent000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\mcagent\mcagent001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\mcagent\mcagent002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\McUICnt\McUICnt000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\mcuihost\mcuihost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\RiskScan\RiskScan000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\Explorer\Explorer000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mcagent\mcagent000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mcalert\mcalert000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\McAltHst\McAltHst000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mcinfo\mcinfo000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mcinst\mcinst000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\McInstru\McInstru000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mcocrollback\mcocrollback000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mcods\mcods000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\McPvTray\McPvTray000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\McSvHost\McSvHost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\McSync\McSync000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\McUICnt\McUICnt000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mcuihost\mcuihost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\McUpdate\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\McUpdate\McUpdate000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\McUpdate\McUpdate001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mcupdmgr\mcupdmgr000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mcvsshld\mcvsshld000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\mpfalert\mpfalert000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\rundll32\rundll32000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\verclsid\verclsid000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\CoreTech\WINWORD\WINWORD000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\DetectMPSdll\mcinst\mcinst000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\HomeNet\McSvHost\McSvHost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\HWAPI\mcinst\mcinst000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\HWAPI\regsvr32\regsvr32000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MasterInstaller\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\mcdspwrp\mcagent\mcagent000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\mcdspwrp\McUICnt\McUICnt000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\mcdspwrp\mcuihost\mcuihost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\mcinfo\mcinfo000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\Cleanup000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\Delfolders000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\instLD.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mclgtmpl.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\McOcInstru.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mcocrollback.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mcpins.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mcpLD.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mcqc.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mcshr.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mna32.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mpfLD.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mpsmisp.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mqsuc.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\msccmn.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\msclgmis.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mscLI.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mscmisc.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mscreg.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mscshll.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mscsvc.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\mscupd.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\rmoldfile.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\rmoldmpsfile.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\sa_main.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\subst.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\vso.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\vsopost.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McItInfo\McItInfo000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\mcitinfo_1337650810\mcitinfo_1337650810000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\mcagent\mcagent000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\mcsync\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\mcsync\mcsync000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\mcsync\McSync001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\mcsync\McSync002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\rundll32\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\rundll32\rundll32000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\rundll32\rundll32001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McOneClickAct\McInstru\McInstru000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McOneClickAct\mcocrollback\mcocrollback000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McProxy\McSvHost\McSvHost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\mcsmttsk\McUpdate\McUpdate000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\mcsvrcnt\mcsvrcnt000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McSync\mcsync\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McSync\mcsync\mcsync000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McSync\mcsync\McSync001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McSync\mcsync\McSync002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McSync\mcsync000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McUICnt\McUICnt\McUICnt000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McUninst\mcuihost\mcuihost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\mfehidin.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcagent\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcagent\mcagent000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcagent\mcagent001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcagent\mcagent002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcappcfg\mcappcfg000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\McHlp32\McHlp32000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mchost\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mchost\mchost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mchost\mchost001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mchost\mchost002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcinfo\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcinfo\mcinfo000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcinfo\McInfo001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcinfo\mcinfo002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcinst\mcinst000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\McItInfo\McItInfo000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcitinfo_1337650810\mcitinfo_1337650810000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcods\mcods000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\McSmtFwk\McSmtFwk000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\McSvHost\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\McSvHost\McSvHost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\McSvHost\McSvHost001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\McSvHost\McSvHost002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcsvrcnt\mcsvrcnt000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcsync\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcsync\mcsync000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcsync\McSync001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcsync\McSync002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcuihost\mcuihost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\McUpdate\McUpdate000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcupdmgr\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcupdmgr\mcupdmgr000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcupdmgr\mcupdmgr001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcupdmgr\mcupdmgr002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mcvsshld\mcvsshld000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\mispreg\mispreg000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\mcinst\mcinst000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\McSmtFwk\McSmtFwk000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\McSvHost\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\McSvHost\McSvHost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\McSvHost\McSvHost001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\McSvHost\McSvHost002.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\mcuihost\mcuihost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\mcupdmgr\mcupdmgr000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\mpfalert\mpfalert000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPF\regsvr32\regsvr32000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Mps\McSvHost\McSvHost000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPV\Explorer\Explorer000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MPV\mcinst\mcinst000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MQS\McPvTray\McPvTray000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MSC\Explorer\Explorer000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MSC\McPvTray\McPvTray000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\PartnerCustom\McUICnt\McUICnt000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\PartnerCustom\SSScheduler\SSScheduler000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Pearl\mcagent\mcagent000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\SecurityScanner\McUICnt\McUICnt000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\VSCore\mcupdmgr\mcupdmgr000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\VSCore\rundll32\rundll32000.log
c:\documents and settings\All Users\Application Data\McAfee\MNA\NAData
c:\documents and settings\All Users\Application Data\McAfee\MNM\NDData
c:\documents and settings\All Users\Application Data\McAfee\MSC\Cache\McSubDB.Bak
c:\documents and settings\All Users\Application Data\McAfee\MSC\installinstru.dat
c:\documents and settings\All Users\Application Data\McAfee\MSC\installinstru_pre.dat
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{0A6B6099-936F-4209-B31A-123F694F295C}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{0A9AF731-EEC1-4ED2-8E7D-66C08512138D}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{1E1FEB0E-ABA0-4074-B363-BE2ADC6D4CE8}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{34144B7A-8AD8-4DF3-A766-A1D15615E4A9}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{39828ECD-9C08-4B82-8F5C-29E45289CF5A}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{3D2DDDCB-E952-457A-8575-E0D454773B67}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{8C99B8FE-3478-4A9D-AB1B-77F05ABB114D}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{96111A4D-9614-478E-AC99-079CCB2872C8}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{9B49996C-6291-4616-B5B4-03791ACB464C}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{B94E1AF4-CD9E-4C3C-9524-0270A17EFBEF}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\{D7FB805D-8827-4A38-8241-340B5D18D9F7}.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\settings.dat
c:\documents and settings\All Users\Application Data\McAfee\MSC\McConfig.dat
c:\documents and settings\All Users\Application Data\McAfee\MSC\mcifolog.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\mcini.ini
c:\documents and settings\All Users\Application Data\McAfee\MSC\McSubDB.Dat
c:\documents and settings\All Users\Application Data\McAfee\MSC\McUsers.dat
c:\documents and settings\All Users\Application Data\McAfee\SiteAdvisor\mcsacore.exe\log.txt
c:\documents and settings\All Users\Application Data\McAfee\SiteAdvisor\SA.dat
c:\documents and settings\All Users\Application Data\McAfee\SiteAdvisor\SACore\sacore.db
c:\documents and settings\All Users\Application Data\McAfee\SiteAdvisor\SACore\sacore_cache.db
c:\documents and settings\All Users\Application Data\McAfee\SiteAdvisor\SACore\sacore_priv.db
c:\documents and settings\All Users\Application Data\McAfee\SiteAdvisor\sasshmod.dll\log.txt
c:\documents and settings\All Users\Application Data\McAfee\SiteAdvisor\saupkeep.dll\log.txt
c:\documents and settings\All Users\Application Data\McAfee\WinCore\persist.mtk
c:\program files\Common Files\McAfee
c:\program files\Common Files\McAfee\FWDriver\fwdrv.inf
c:\program files\Common Files\McAfee\FWDriver\fwdrvins.exe
c:\program files\Common Files\McAfee\FWDriver\fwdrvver.dll
c:\program files\Common Files\McAfee\FWDriver\mpfp.cat
c:\program files\Common Files\McAfee\FWDriver\mpfp.sys
c:\program files\Common Files\McAfee\FWDriver\Vista\fwdrvex.inf
c:\program files\Common Files\McAfee\FWDriver\Vista\fwdrvv.cab
c:\program files\Common Files\McAfee\HackerWatch\HWAPI.dll
c:\program files\Common Files\McAfee\HackerWatch\hwapi.inf
c:\program files\Common Files\McAfee\HackerWatch\hwupdchk.exe
c:\program files\Common Files\McAfee\Installer\mcinst.exe
c:\program files\Common Files\McAfee\McProxy\McProxy.dll
c:\program files\Common Files\McAfee\McProxy\McProxy.inf
c:\program files\Common Files\McAfee\McProxy\Proxyver.dll
c:\program files\Common Files\McAfee\McProxy\rmoldfile.inf
c:\program files\Common Files\McAfee\McSvcHost\McSHIns.dll
c:\program files\Common Files\McAfee\McSvcHost\McSvcHost.inf
c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe
c:\program files\Common Files\McAfee\McSvcHost\McSvHVer.dll
c:\program files\Common Files\McAfee\MNA\McAltHPS.dll
c:\program files\Common Files\McAfee\MNA\McAltHst.exe
c:\program files\Common Files\McAfee\MNA\McNaIns.dll
c:\program files\Common Files\McAfee\MNA\McNAReg.dll
c:\program files\Common Files\McAfee\MNA\McNARgPS.dll
c:\program files\Common Files\McAfee\MNA\McNASvc.dll
c:\program files\Common Files\McAfee\MNA\McNASvPS.dll
c:\program files\Common Files\McAfee\MNA\McNAVer.dll
c:\program files\Common Files\McAfee\MNA\McTrstPS.dll
c:\program files\Common Files\McAfee\MNA\mna32.inf
c:\program files\Common Files\McAfee\SystemCore\chrome.manifest
c:\program files\Common Files\McAfee\SystemCore\components\ScriptFF.gif
c:\program files\Common Files\McAfee\SystemCore\components\scriptff.js
c:\program files\Common Files\McAfee\SystemCore\components\ScriptFF.xul
c:\program files\Common Files\McAfee\SystemCore\dainstall.exe
c:\program files\Common Files\McAfee\SystemCore\ftl.dll
c:\program files\Common Files\McAfee\SystemCore\fwinfo.exe
c:\program files\Common Files\McAfee\SystemCore\install.rdf
c:\program files\Common Files\McAfee\SystemCore\lockdown.dll
c:\program files\Common Files\McAfee\SystemCore\mcshield.dll
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\McAfee\SystemCore\mfeapfa.dll
c:\program files\Common Files\McAfee\SystemCore\mfeavfa.dll
c:\program files\Common Files\McAfee\SystemCore\mfebopa.dll
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\program files\Common Files\McAfee\SystemCore\mfefwctl.dll
c:\program files\Common Files\McAfee\SystemCore\mfehida.dll
c:\program files\Common Files\McAfee\SystemCore\mfehidin.exe
c:\program files\Common Files\McAfee\SystemCore\mfehidk_messages.dll
c:\program files\Common Files\McAfee\SystemCore\mferkda.dll
c:\program files\Common Files\McAfee\SystemCore\mfevtpa.dll
c:\program files\Common Files\McAfee\SystemCore\mytilus3.dll
c:\program files\Common Files\McAfee\SystemCore\mytilus3_server.dll
c:\program files\Common Files\McAfee\SystemCore\mytilus3_worker.dll
c:\program files\Common Files\McAfee\SystemCore\naevent.dll
c:\program files\Common Files\McAfee\SystemCore\naievent.dll
c:\program files\Common Files\McAfee\SystemCore\rkscan.dll
c:\program files\Common Files\McAfee\SystemCore\scriptff.dll
c:\program files\Common Files\McAfee\SystemCore\ScriptFF.gif
c:\program files\Common Files\McAfee\SystemCore\Scriptff.js
c:\program files\Common Files\McAfee\SystemCore\ScriptFF.xul
c:\program files\Common Files\McAfee\SystemCore\ScriptSn.20120520155218.dll
c:\program files\Common Files\McAfee\SystemCore\ScriptSn.20120520155219.dll
c:\program files\Common Files\McAfee\SystemCore\ScriptSn.20120709005209.dll
c:\program files\Common Files\McAfee\SystemCore\scriptsn.dll
c:\program files\Common Files\McAfee\SystemCore\strings.bin
c:\program files\Common Files\McAfee\SystemCore\vscan.bof
c:\program files\Common Files\McAfee\SystemCore\vtp_catcache
c:\program files\Common Files\McAfee\VSCore\av.inf
c:\program files\Common Files\McAfee\VSCore\cfwids.cat
c:\program files\Common Files\McAfee\VSCore\cfwids.inf
c:\program files\Common Files\McAfee\VSCore\cfwids.sys
c:\program files\Common Files\McAfee\VSCore\chrome.manifest
c:\program files\Common Files\McAfee\VSCore\DAInstall.exe
c:\program files\Common Files\McAfee\VSCore\ftl.dll
c:\program files\Common Files\McAfee\VSCore\fw.inf
c:\program files\Common Files\McAfee\VSCore\install.rdf
c:\program files\Common Files\McAfee\VSCore\lockdown.dll
c:\program files\Common Files\McAfee\VSCore\McShield.dll
c:\program files\Common Files\McAfee\VSCore\Mcshield.exe
c:\program files\Common Files\McAfee\VSCore\mfeapfa.dll
c:\program files\Common Files\McAfee\VSCore\mfeapfk.cat
c:\program files\Common Files\McAfee\VSCore\mfeapfk.inf
c:\program files\Common Files\McAfee\VSCore\mfeapfk.sys
c:\program files\Common Files\McAfee\VSCore\mfeavfa.dll
c:\program files\Common Files\McAfee\VSCore\mfeavfk.cat
c:\program files\Common Files\McAfee\VSCore\mfeavfk.inf
c:\program files\Common Files\McAfee\VSCore\mfeavfk.sys
c:\program files\Common Files\McAfee\VSCore\mfebopa.dll
c:\program files\Common Files\McAfee\VSCore\mfebopk.cat
c:\program files\Common Files\McAfee\VSCore\mfebopk.inf
c:\program files\Common Files\McAfee\VSCore\mfebopk.sys
c:\program files\Common Files\McAfee\VSCore\mfeclnk.cat
c:\program files\Common Files\McAfee\VSCore\mfeclnk.inf
c:\program files\Common Files\McAfee\VSCore\mfeclnk.sys
c:\program files\Common Files\McAfee\VSCore\mfefire.exe
c:\program files\Common Files\McAfee\VSCore\mfefirek.cat
c:\program files\Common Files\McAfee\VSCore\mfefirek.inf
c:\program files\Common Files\McAfee\VSCore\mfefirek.sys
c:\program files\Common Files\McAfee\VSCore\mfefwctl.dll
c:\program files\Common Files\McAfee\VSCore\mfehida.dll
c:\program files\Common Files\McAfee\VSCore\mfehidin.exe
c:\program files\Common Files\McAfee\VSCore\mfehidk.cat
c:\program files\Common Files\McAfee\VSCore\mfehidk.inf
c:\program files\Common Files\McAfee\VSCore\mfehidk.sys
c:\program files\Common Files\McAfee\VSCore\mfehidk_messages.dll
c:\program files\Common Files\McAfee\VSCore\mfendisk.cat
c:\program files\Common Files\McAfee\VSCore\mfendisk.inf
c:\program files\Common Files\McAfee\VSCore\mfendisk.sys
c:\program files\Common Files\McAfee\VSCore\mfendisk_m.cat
c:\program files\Common Files\McAfee\VSCore\mfendisk_m.inf
c:\program files\Common Files\McAfee\VSCore\mfenlfk.cat
c:\program files\Common Files\McAfee\VSCore\mfenlfk.inf
c:\program files\Common Files\McAfee\VSCore\mfenlfk.sys
c:\program files\Common Files\McAfee\VSCore\mferkda.dll
c:\program files\Common Files\McAfee\VSCore\mferkdet.cat
c:\program files\Common Files\McAfee\VSCore\mferkdet.inf
c:\program files\Common Files\McAfee\VSCore\mferkdet.sys
c:\program files\Common Files\McAfee\VSCore\mfetdi2k.cat
c:\program files\Common Files\McAfee\VSCore\mfetdi2k.inf
c:\program files\Common Files\McAfee\VSCore\mfetdi2k.sys
c:\program files\Common Files\McAfee\VSCore\mfevtpa.dll
c:\program files\Common Files\McAfee\VSCore\mfevtps.exe
c:\program files\Common Files\McAfee\VSCore\mfewfpk.cat
c:\program files\Common Files\McAfee\VSCore\mfewfpk.inf
c:\program files\Common Files\McAfee\VSCore\mfewfpk.sys
c:\program files\Common Files\McAfee\VSCore\mytilus3.dll
c:\program files\Common Files\McAfee\VSCore\mytilus3_server.dll
c:\program files\Common Files\McAfee\VSCore\mytilus3_worker.dll
c:\program files\Common Files\McAfee\VSCore\NaEvent.dll
c:\program files\Common Files\McAfee\VSCore\NaiEvent.dll
c:\program files\Common Files\McAfee\VSCore\reinstall.log
c:\program files\Common Files\McAfee\VSCore\RkScan.dll
c:\program files\Common Files\McAfee\VSCore\scriptff.dll
c:\program files\Common Files\McAfee\VSCore\scriptff.gif
c:\program files\Common Files\McAfee\VSCore\scriptff.js
c:\program files\Common Files\McAfee\VSCore\scriptff.xul
c:\program files\Common Files\McAfee\VSCore\scriptsn.dll
c:\program files\Common Files\McAfee\VSCore\strings.bin
c:\program files\Common Files\McAfee\VSCore\tools\fwinfo.exe
c:\program files\Common Files\McAfee\VSCore\vscore.inf
c:\program files\Common Files\McAfee\VSCore\vscore.xml
c:\program files\Common Files\McAfee\VSCore\VSCVer.dll
c:\program files\Common Files\McAfee\VSCore\vtp_catcache
c:\program files\McAfee
c:\program files\McAfee.com\Agent
c:\program files\McAfee.com\Agent\mcscentr.adf
c:\program files\McAfee\MQC\2057\mcpLD.inf
c:\program files\McAfee\MQC\2057\mcqchelp.inf
c:\program files\McAfee\MQC\2057\mcqcres.inf
c:\program files\McAfee\MQC\2057\QcLog.xml
c:\program files\McAfee\MQC\2057\QcRes.dll
c:\program files\McAfee\MQC\2057\Readme.htm
c:\program files\McAfee\MQC\McpAdmin.exe
c:\program files\McAfee\MQC\McpIns.dll
c:\program files\McAfee\MQC\mcpins.inf
c:\program files\McAfee\MQC\mcpLI.inf
c:\program files\McAfee\MQC\mcpmain.inf
c:\program files\McAfee\MQC\McpSched.dll
c:\program files\McAfee\MQC\mcqc.inf
c:\program files\McAfee\MQC\MRU.bak
c:\program files\McAfee\MQC\MRU.ini
c:\program files\McAfee\MQC\qcconf.bak
c:\program files\McAfee\MQC\qcconf.dat
c:\program files\McAfee\MQC\QcConsol.exe
c:\program files\McAfee\MQC\QCLite.dll
c:\program files\McAfee\MQC\QCMISP.dll
c:\program files\McAfee\MSC\2057\instLD.inf
c:\program files\McAfee\MSC\2057\msclcres.inf
c:\program files\McAfee\MSC\2057\mscpstLD.inf
c:\program files\McAfee\MSC\Custom_Uninstall\McOcInstru.inf
c:\program files\McAfee\MSC\Custom_Uninstall\mcocrollback.inf
c:\program files\McAfee\MSC\langmap.dat
c:\program files\McAfee\MSC\mcactui.dll
c:\program files\McAfee\MSC\mcactwiz.dll
c:\program files\McAfee\MSC\mcactwiz_ld.dll
c:\program files\McAfee\MSC\mcinstru.dll
c:\program files\McAfee\MSC\McInstru.exe
c:\program files\McAfee\MSC\mcmscins.dll
c:\program files\McAfee\MSC\msccust.inf
c:\program files\McAfee\MSC\mscdfoem.inf
c:\program files\McAfee\MSC\mscLD.inf
c:\program files\McAfee\MSC\mscLI.inf
c:\program files\McAfee\MSC\mscuicfg.dat
c:\program files\McAfee\MSC\MSFix.inf
c:\program files\McAfee\MSC\OOBE\mcocrollback.exe
c:\program files\McAfee\MSC\override.inf
c:\program files\McAfee\MSC\subst.inf
c:\program files\McAfee\MSC\subst2.inf
c:\program files\McAfee\MSC\vscan.bof
c:\program files\McAfee\MSHR\2057\mcshrres.inf
c:\program files\McAfee\MSHR\2057\ShrRes.dll
c:\program files\McAfee\MSHR\mcshr.inf
c:\program files\McAfee\MSHR\Readme.txt
c:\program files\McAfee\MSHR\ShrCL.exe
c:\program files\McAfee\MSHR\ShrCore.dll
c:\program files\McAfee\MSHR\Shredder.ini
c:\program files\McAfee\MSHR\ShrMISP.dll
c:\program files\McAfee\SiteAdvisor\ActUtil.exe
c:\program files\McAfee\SiteAdvisor\chr.inf
c:\program files\McAfee\SiteAdvisor\chrome.manifest
c:\program files\McAfee\SiteAdvisor\contents.rdf
c:\program files\McAfee\SiteAdvisor\default.txt
c:\program files\McAfee\SiteAdvisor\Download\s19o
c:\program files\McAfee\SiteAdvisor\Download\s1ms
c:\program files\McAfee\SiteAdvisor\Download\s26o
c:\program files\McAfee\SiteAdvisor\Download\s2p8
c:\program files\McAfee\SiteAdvisor\Download\s2sc
c:\program files\McAfee\SiteAdvisor\Download\s3eo
c:\program files\McAfee\SiteAdvisor\Download\s3n8
c:\program files\McAfee\SiteAdvisor\Download\s3s4
c:\program files\McAfee\SiteAdvisor\Download\s3tk
c:\program files\McAfee\SiteAdvisor\Download\s43c
c:\program files\McAfee\SiteAdvisor\Download\s48
c:\program files\McAfee\SiteAdvisor\Download\s4u0
c:\program files\McAfee\SiteAdvisor\Download\s5cg
c:\program files\McAfee\SiteAdvisor\Download\s5j4
c:\program files\McAfee\SiteAdvisor\Download\s5n0
c:\program files\McAfee\SiteAdvisor\Download\s5nc
c:\program files\McAfee\SiteAdvisor\Download\s5og
c:\program files\McAfee\SiteAdvisor\Download\s5q8
c:\program files\McAfee\SiteAdvisor\elist.dat
c:\program files\McAfee\SiteAdvisor\install.rdf
c:\program files\McAfee\SiteAdvisor\mcbrwctl.dll
c:\program files\McAfee\SiteAdvisor\McChPlg.crx
c:\program files\McAfee\SiteAdvisor\McIEPlg.dll
c:\program files\McAfee\SiteAdvisor\McPlgUI.dll
c:\program files\McAfee\SiteAdvisor\McSACore.exe
c:\program files\McAfee\SiteAdvisor\McSACorePS.dll
c:\program files\McAfee\SiteAdvisor\NPMcFFPlg32.dll
c:\program files\McAfee\SiteAdvisor\Oem.txt
c:\program files\McAfee\SiteAdvisor\SA_indep.inf
c:\program files\McAfee\SiteAdvisor\SA_main.inf
c:\program files\McAfee\SiteAdvisor\SA_win32.inf
c:\program files\McAfee\SiteAdvisor\sahook.dll
c:\program files\McAfee\SiteAdvisor\saplugin.dll
c:\program files\McAfee\SiteAdvisor\sares.dll
c:\program files\McAfee\SiteAdvisor\saSets.ini
c:\program files\McAfee\SiteAdvisor\SaSSHMod.dll
c:\program files\McAfee\SiteAdvisor\saUI.exe
c:\program files\McAfee\SiteAdvisor\saUpd.exe
c:\program files\McAfee\SiteAdvisor\saupkeep.dll
c:\program files\McAfee\SiteAdvisor\Scripts\balloon.html
c:\program files\McAfee\SiteAdvisor\Scripts\balloon.js
c:\program files\McAfee\SiteAdvisor\Scripts\balloon_logo.gif
c:\program files\McAfee\SiteAdvisor\Scripts\balloon_logo_plus.gif
c:\program files\McAfee\SiteAdvisor\Scripts\blackpixel.gif
c:\program files\McAfee\SiteAdvisor\Scripts\bullet.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_black.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_black_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_disabled.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_green.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_green_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_grey.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_grey_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_hs.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_hs_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_red.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_red_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_yellow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\button_yellow_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\common.js
c:\program files\McAfee\SiteAdvisor\Scripts\corner-solid.gif
c:\program files\McAfee\SiteAdvisor\Scripts\cornersm-hollow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\cornersm-solid.gif
c:\program files\McAfee\SiteAdvisor\Scripts\down_arrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\download_careful.gif
c:\program files\McAfee\SiteAdvisor\Scripts\download_unsafe.gif
c:\program files\McAfee\SiteAdvisor\Scripts\empty.gif
c:\program files\McAfee\SiteAdvisor\Scripts\engine.js
c:\program files\McAfee\SiteAdvisor\Scripts\error-icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\facebook.js
c:\program files\McAfee\SiteAdvisor\Scripts\favicon.ico
c:\program files\McAfee\SiteAdvisor\Scripts\g_banner_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_banner_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_banner_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_banner_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_bottom_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_bottom_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_bottom_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_bottom_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_facet.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_footer_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_footer_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_footer_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_header_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_header_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_header_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\g_upsell_border.gif
c:\program files\McAfee\SiteAdvisor\Scripts\gleftarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\google.js
c:\program files\McAfee\SiteAdvisor\Scripts\green.gif
c:\program files\McAfee\SiteAdvisor\Scripts\grightarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\hackersafe.gif
c:\program files\McAfee\SiteAdvisor\Scripts\hs.gif
c:\program files\McAfee\SiteAdvisor\Scripts\hs_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\inst-background.gif
c:\program files\McAfee\SiteAdvisor\Scripts\inst-top.gif
c:\program files\McAfee\SiteAdvisor\Scripts\inst-xup.gif
c:\program files\McAfee\SiteAdvisor\Scripts\large-buttonC.gif
c:\program files\McAfee\SiteAdvisor\Scripts\large-buttonL.gif
c:\program files\McAfee\SiteAdvisor\Scripts\large-buttonR.gif
c:\program files\McAfee\SiteAdvisor\Scripts\main.js
c:\program files\McAfee\SiteAdvisor\Scripts\mcafee_logo.gif
c:\program files\McAfee\SiteAdvisor\Scripts\mcafee_logo_shield.png
c:\program files\McAfee\SiteAdvisor\Scripts\mcafee_yahoo_cobranded_toolbar.gif
c:\program files\McAfee\SiteAdvisor\Scripts\mcafeesiteadvisor.gif
c:\program files\McAfee\SiteAdvisor\Scripts\mcwedge.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_arrow_down.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_arrow_up.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_black.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_black_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_disabled.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_green.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_green_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_grey.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_grey_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_hs.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_hs_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_red.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_red_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_yellow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\nb_button_yellow_lock.gif
c:\program files\McAfee\SiteAdvisor\Scripts\protectedmode.gif
c:\program files\McAfee\SiteAdvisor\Scripts\protection.gif
c:\program files\McAfee\SiteAdvisor\Scripts\protmode-off.gif
c:\program files\McAfee\SiteAdvisor\Scripts\protmode-on.gif
c:\program files\McAfee\SiteAdvisor\Scripts\question-icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_banner_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_banner_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_banner_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_banner_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_blocked.png
c:\program files\McAfee\SiteAdvisor\Scripts\r_bottom_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_bottom_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_bottom_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_bottom_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_facet.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_footer_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_footer_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_footer_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_header_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_header_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_header_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_header_r_nox.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_upsell_border.gif
c:\program files\McAfee\SiteAdvisor\Scripts\r_x_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\red.gif
c:\program files\McAfee\SiteAdvisor\Scripts\redarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\rleftarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\rrightarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\sa-logo-plus.gif
c:\program files\McAfee\SiteAdvisor\Scripts\sa-logo-white.gif
c:\program files\McAfee\SiteAdvisor\Scripts\sa-logo.gif
c:\program files\McAfee\SiteAdvisor\Scripts\sachplg.js
c:\program files\McAfee\SiteAdvisor\Scripts\safe.js
c:\program files\McAfee\SiteAdvisor\Scripts\safe.xul
c:\program files\McAfee\SiteAdvisor\Scripts\safe_im.js
c:\program files\McAfee\SiteAdvisor\Scripts\safeshare_green.gif
c:\program files\McAfee\SiteAdvisor\Scripts\safeshare_grey.gif
c:\program files\McAfee\SiteAdvisor\Scripts\safeshare_red.gif
c:\program files\McAfee\SiteAdvisor\Scripts\safeshare_yellow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\saffplg.js
c:\program files\McAfee\SiteAdvisor\Scripts\SAPlus-graphic.gif
c:\program files\McAfee\SiteAdvisor\Scripts\searchglass.gif
c:\program files\McAfee\SiteAdvisor\Scripts\selected_tab.gif
c:\program files\McAfee\SiteAdvisor\Scripts\selectors.js
c:\program files\McAfee\SiteAdvisor\Scripts\siteadvisor.gif
c:\program files\McAfee\SiteAdvisor\Scripts\sizzle.js
c:\program files\McAfee\SiteAdvisor\Scripts\SliderA1.gif
c:\program files\McAfee\SiteAdvisor\Scripts\SliderA2.gif
c:\program files\McAfee\SiteAdvisor\Scripts\SliderA3.gif
c:\program files\McAfee\SiteAdvisor\Scripts\SliderA4.gif
c:\program files\McAfee\SiteAdvisor\Scripts\SliderD1.gif
c:\program files\McAfee\SiteAdvisor\Scripts\SliderD2.gif
c:\program files\McAfee\SiteAdvisor\Scripts\SliderD3.gif
c:\program files\McAfee\SiteAdvisor\Scripts\SliderD4.gif
c:\program files\McAfee\SiteAdvisor\Scripts\small-buttonC.gif
c:\program files\McAfee\SiteAdvisor\Scripts\small-buttonL.gif
c:\program files\McAfee\SiteAdvisor\Scripts\small-buttonR.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_bottom_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_bottom_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_bottom_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_copylink_off.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_copylink_on.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_facebook_off.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_facebook_on.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_footer_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_footer_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_footer_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_header_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_header_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_header_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_twitter_off.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ss_twitter_on.gif
c:\program files\McAfee\SiteAdvisor\Scripts\unselected_tab.gif
c:\program files\McAfee\SiteAdvisor\Scripts\untested.gif
c:\program files\McAfee\SiteAdvisor\Scripts\vertical_divider.png
c:\program files\McAfee\SiteAdvisor\Scripts\vertical_divider_live.png
c:\program files\McAfee\SiteAdvisor\Scripts\w_banner_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_banner_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_banner_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_banner_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_bottom_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_bottom_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_bottom_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_bottom_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_footer_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_footer_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_footer_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_header_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_header_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_header_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\w_upsell_border.gif
c:\program files\McAfee\SiteAdvisor\Scripts\warning.html
c:\program files\McAfee\SiteAdvisor\Scripts\warning.js
c:\program files\McAfee\SiteAdvisor\Scripts\wleftarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\wrightarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\xdown.gif
c:\program files\McAfee\SiteAdvisor\Scripts\xup.gif
c:\program files\McAfee\SiteAdvisor\Scripts\xup_light.png
c:\program files\McAfee\SiteAdvisor\Scripts\y_banner_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_banner_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_banner_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_banner_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_bottom_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_bottom_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_bottom_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_bottom_sep.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_facet.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_footer_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_footer_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_footer_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_header_c.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_header_l.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_header_r.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_header_r_nox.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_icon.gif
c:\program files\McAfee\SiteAdvisor\Scripts\y_upsell_border.gif
c:\program files\McAfee\SiteAdvisor\Scripts\yahoo.js
c:\program files\McAfee\SiteAdvisor\Scripts\yellow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\yleftarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\yrightarrow.gif
c:\program files\McAfee\SiteAdvisor\Scripts\ytri.gif
c:\program files\McAfee\SiteAdvisor\uninstall.exe
c:\program files\McAfee\Temp\qxzCE\actwizui.inf
c:\program files\McAfee\Temp\qxzCE\avap.inf
c:\program files\McAfee\Temp\qxzCE\extra.rul
c:\program files\McAfee\Temp\qxzCE\Fix519818.exe
c:\program files\McAfee\Temp\qxzCE\InstProg.dll
c:\program files\McAfee\Temp\qxzCE\langmap.dat
c:\program files\McAfee\Temp\qxzCE\LangSel.dll
c:\program files\McAfee\Temp\qxzCE\license.txt
c:\program files\McAfee\Temp\qxzCE\mcactui.dll
c:\program files\McAfee\Temp\qxzCE\mcactui.inf
c:\program files\McAfee\Temp\qxzCE\mcactwiz.dll
c:\program files\McAfee\Temp\qxzCE\mcactwiz.inf
c:\program files\McAfee\Temp\qxzCE\mcactwiz_ld.dll
c:\program files\McAfee\Temp\qxzCE\mcafee.html
c:\program files\McAfee\Temp\qxzCE\mcagent.exe
c:\program files\McAfee\Temp\qxzCE\mcagntps.dll
c:\program files\McAfee\Temp\qxzCE\mcawlang.inf
c:\program files\McAfee\Temp\qxzCE\mcbrwsr2.dll
c:\program files\McAfee\Temp\qxzCE\mccontextust.dll
c:\program files\McAfee\Temp\qxzCE\mccore.inf
c:\program files\McAfee\Temp\qxzCE\McCorePS.dll
c:\program files\McAfee\Temp\qxzCE\McCtxMenuFrmWrk.dll
c:\program files\McAfee\Temp\qxzCE\McDBMgr.dll
c:\program files\McAfee\Temp\qxzCE\McDisc.dll
c:\program files\McAfee\Temp\qxzCE\McDiscPS.dll
c:\program files\McAfee\Temp\qxzCE\McDspWrp.dll
c:\program files\McAfee\Temp\qxzCE\mcdspwrp.inf
c:\program files\McAfee\Temp\qxzCE\McEvtBrk.dll
c:\program files\McAfee\Temp\qxzCE\McGsShm.dll
c:\program files\McAfee\Temp\qxzCE\mchlp32.exe
c:\program files\McAfee\Temp\qxzCE\McHNShim.dll
c:\program files\McAfee\Temp\qxzCE\McHNShPS.dll
c:\program files\McAfee\Temp\qxzCE\mchost.exe
c:\program files\McAfee\Temp\qxzCE\mcinfo.exe
c:\program files\McAfee\Temp\qxzCE\McInstru.dll
c:\program files\McAfee\Temp\qxzCE\mcinstru.exe
c:\program files\McAfee\Temp\qxzCE\McIPTShm.dll
c:\program files\McAfee\Temp\qxzCE\mclangmap.inf
c:\program files\McAfee\Temp\qxzCE\McLib.lib
c:\program files\McAfee\Temp\qxzCE\McLogShm.dll
c:\program files\McAfee\Temp\qxzCE\mcltvers.ini
c:\program files\McAfee\Temp\qxzCE\mclwapi.dll
c:\program files\McAfee\Temp\qxzCE\McMISPPS.dll
c:\program files\McAfee\Temp\qxzCE\mcmispps.inf
c:\program files\McAfee\Temp\qxzCE\McMPFEvt.dll
c:\program files\McAfee\Temp\qxzCE\mcmschlp.dll
c:\program files\McAfee\Temp\qxzCE\mcmscins.dll
c:\program files\McAfee\Temp\qxzCE\McMscShm.dll
c:\program files\McAfee\Temp\qxzCE\mcmscsub.dll
c:\program files\McAfee\Temp\qxzCE\McMscVer.dll
c:\program files\McAfee\Temp\qxzCE\McNdAtpg.dll
c:\program files\McAfee\Temp\qxzCE\McNDLor.dll
c:\program files\McAfee\Temp\qxzCE\McNDSv.dll
c:\program files\McAfee\Temp\qxzCE\McNDSVPS.dll
c:\program files\McAfee\Temp\qxzCE\McNMAtpg.dll
c:\program files\McAfee\Temp\qxzCE\McNmcIns.dll
c:\program files\McAfee\Temp\qxzCE\McNmcLoR.dll
c:\program files\McAfee\Temp\qxzCE\McNmcShell.exe
c:\program files\McAfee\Temp\qxzCE\McNmcSPS.dll
c:\program files\McAfee\Temp\qxzCE\McNmcSrv.dll
c:\program files\McAfee\Temp\qxzCE\McNmcVer.dll
c:\program files\McAfee\Temp\qxzCE\mcocdisable.inf
c:\program files\McAfee\Temp\qxzCE\mcocenable.inf
c:\program files\McAfee\Temp\qxzCE\mcocinstru.inf
c:\program files\McAfee\Temp\qxzCE\mcoemmgr.exe
c:\program files\McAfee\Temp\qxzCE\mcoemmgr.inf
c:\program files\McAfee\Temp\qxzCE\mcoemres.dll
c:\program files\McAfee\Temp\qxzCE\mcoemres.inf
c:\program files\McAfee\Temp\qxzCE\mcprlalt.dll
c:\program files\McAfee\Temp\qxzCE\mcprlres.dll
c:\program files\McAfee\Temp\qxzCE\McPrsShm.dll
c:\program files\McAfee\Temp\qxzCE\McRegObj.dll
c:\program files\McAfee\Temp\qxzCE\McRTMui.dll
c:\program files\McAfee\Temp\qxzCE\mcscindx.dat
c:\program files\McAfee\Temp\qxzCE\mcscrhlp.dll
c:\program files\McAfee\Temp\qxzCE\McSmpUI.dll
c:\program files\McAfee\Temp\qxzCE\McSmtFWk.exe
c:\program files\McAfee\Temp\qxzCE\mcsmtmsg.inf
c:\program files\McAfee\Temp\qxzCE\McSmtStr.dll
c:\program files\McAfee\Temp\qxzCE\McSmtTsk.dll
c:\program files\McAfee\Temp\qxzCE\McSnIEPl.dll
c:\program files\McAfee\Temp\qxzCE\mcsubmgr.dll
c:\program files\McAfee\Temp\qxzCE\mcsvrcnt.exe
c:\program files\McAfee\Temp\qxzCE\mcsync.exe
c:\program files\McAfee\Temp\qxzCE\mcuc.inf
c:\program files\McAfee\Temp\qxzCE\McUiCfg.dll
c:\program files\McAfee\Temp\qxzCE\mcuicnt.exe
c:\program files\McAfee\Temp\qxzCE\mcuihost.exe
c:\program files\McAfee\Temp\qxzCE\mcuinshm.dll
c:\program files\McAfee\Temp\qxzCE\mcuninst.exe
c:\program files\McAfee\Temp\qxzCE\mcupdate.exe
c:\program files\McAfee\Temp\qxzCE\McUpdMgr.exe
c:\program files\McAfee\Temp\qxzCE\McUpdShm.dll
c:\program files\McAfee\Temp\qxzCE\mcutil.dll
c:\program files\McAfee\Temp\qxzCE\mcutil2.dll
c:\program files\McAfee\Temp\qxzCE\misplf.dll
c:\program files\McAfee\Temp\qxzCE\mispreg.exe
c:\program files\McAfee\Temp\qxzCE\msc\mscLI.inf
c:\program files\McAfee\Temp\qxzCE\msccmn.inf
c:\program files\McAfee\Temp\qxzCE\msccust.inf
c:\program files\McAfee\Temp\qxzCE\mscinres.dll
c:\program files\McAfee\Temp\qxzCE\mscjsres.dll
c:\program files\McAfee\Temp\qxzCE\msclgmis.inf
c:\program files\McAfee\Temp\qxzCE\mscmisc.inf
c:\program files\McAfee\Temp\qxzCE\mscoobe.inf
c:\program files\McAfee\Temp\qxzCE\mscprmgr.inf
c:\program files\McAfee\Temp\qxzCE\mscpstLI.inf
c:\program files\McAfee\Temp\qxzCE\mscreg.inf
c:\program files\McAfee\Temp\qxzCE\mscrem.inf
c:\program files\McAfee\Temp\qxzCE\mscres.inf
c:\program files\McAfee\Temp\qxzCE\mscshll.inf
c:\program files\McAfee\Temp\qxzCE\mscsvc.inf
c:\program files\McAfee\Temp\qxzCE\mscuild.dll
c:\program files\McAfee\Temp\qxzCE\mscuimgr.inf
c:\program files\McAfee\Temp\qxzCE\mscupd.inf
c:\program files\McAfee\Temp\qxzCE\nmcdef.inf
c:\program files\McAfee\Temp\qxzCE\NMCJsRes.dll
c:\program files\McAfee\Temp\qxzCE\nmcLI32.inf
c:\program files\McAfee\Temp\qxzCE\nmcuicfg.dat
c:\program files\McAfee\Temp\qxzCE\npMcSnFFPl.dll
c:\program files\McAfee\Temp\qxzCE\oemui.dll
c:\program files\McAfee\Temp\qxzCE\oemui.inf
c:\program files\McAfee\Temp\qxzCE\oemuild.dll
c:\program files\McAfee\Temp\qxzCE\oemuild.inf
c:\program files\McAfee\Temp\qxzCE\RprtShm.dll
c:\program files\McAfee\Temp\qxzCE\sqlite3.dll
c:\program files\McAfee\Temp\qxzCE\TskTCShm.dll
c:\program files\McAfee\Temp\qxzCE\vscore.inf
c:\program files\McAfee\Temp\qxzCE\vscore_fresh.inf
c:\program files\McAfee\Temp\qxzCE\vscore_pre.inf
c:\program files\McAfee\Temp\qxzCE\vscore_update.inf
c:\program files\McAfee\Temp\qxzCE\x64\mcactui.dll
c:\program files\McAfee\Temp\qxzCE\x64\mcactwiz.dll
c:\program files\McAfee\Temp\qxzCE\x64\mcactwiz_ld.dll
c:\program files\McAfee\Temp\qxzCE\x64\McInstru.dll
c:\program files\McAfee\Temp\qxzCE\x64\mcinstru.exe
c:\program files\McAfee\Temp\qxzCE\x64\mcoemmgr.exe
c:\program files\McAfee\Temp\qxzD3\actwizui.inf
c:\program files\McAfee\Temp\qxzD3\avap.inf
c:\program files\McAfee\Temp\qxzD3\extra.rul
c:\program files\McAfee\Temp\qxzD3\Fix519818.exe
c:\program files\McAfee\Temp\qxzD3\InstProg.dll
c:\program files\McAfee\Temp\qxzD3\langmap.dat
c:\program files\McAfee\Temp\qxzD3\LangSel.dll
c:\program files\McAfee\Temp\qxzD3\license.txt
c:\program files\McAfee\Temp\qxzD3\mcactui.dll
c:\program files\McAfee\Temp\qxzD3\mcactui.inf
c:\program files\McAfee\Temp\qxzD3\mcactwiz.dll
c:\program files\McAfee\Temp\qxzD3\mcactwiz.inf
c:\program files\McAfee\Temp\qxzD3\mcactwiz_ld.dll
c:\program files\McAfee\Temp\qxzD3\mcafee.html
c:\program files\McAfee\Temp\qxzD3\mcagent.exe
c:\program files\McAfee\Temp\qxzD3\mcagntps.dll
c:\program files\McAfee\Temp\qxzD3\mcawlang.inf
c:\program files\McAfee\Temp\qxzD3\mcbrwsr2.dll
c:\program files\McAfee\Temp\qxzD3\mccontextust.dll
c:\program files\McAfee\Temp\qxzD3\mccore.inf
c:\program files\McAfee\Temp\qxzD3\McCorePS.dll
c:\program files\McAfee\Temp\qxzD3\McCtxMenuFrmWrk.dll
c:\program files\McAfee\Temp\qxzD3\McDBMgr.dll
c:\program files\McAfee\Temp\qxzD3\McDisc.dll
c:\program files\McAfee\Temp\qxzD3\McDiscPS.dll
c:\program files\McAfee\Temp\qxzD3\McDspWrp.dll
c:\program files\McAfee\Temp\qxzD3\mcdspwrp.inf
c:\program files\McAfee\Temp\qxzD3\McEvtBrk.dll
c:\program files\McAfee\Temp\qxzD3\McGsShm.dll
c:\program files\McAfee\Temp\qxzD3\mchlp32.exe
c:\program files\McAfee\Temp\qxzD3\McHNShim.dll
c:\program files\McAfee\Temp\qxzD3\McHNShPS.dll
c:\program files\McAfee\Temp\qxzD3\mchost.exe
c:\program files\McAfee\Temp\qxzD3\mcinfo.exe
c:\program files\McAfee\Temp\qxzD3\McInstru.dll
c:\program files\McAfee\Temp\qxzD3\mcinstru.exe
c:\program files\McAfee\Temp\qxzD3\McIPTShm.dll
c:\program files\McAfee\Temp\qxzD3\mclangmap.inf
c:\program files\McAfee\Temp\qxzD3\McLib.lib
c:\program files\McAfee\Temp\qxzD3\McLogShm.dll
c:\program files\McAfee\Temp\qxzD3\mcltvers.ini
c:\program files\McAfee\Temp\qxzD3\mclwapi.dll
c:\program files\McAfee\Temp\qxzD3\McMISPPS.dll
c:\program files\McAfee\Temp\qxzD3\mcmispps.inf
c:\program files\McAfee\Temp\qxzD3\McMPFEvt.dll
c:\program files\McAfee\Temp\qxzD3\mcmschlp.dll
c:\program files\McAfee\Temp\qxzD3\mcmscins.dll
c:\program files\McAfee\Temp\qxzD3\McMscShm.dll
c:\program files\McAfee\Temp\qxzD3\mcmscsub.dll
c:\program files\McAfee\Temp\qxzD3\McMscVer.dll
c:\program files\McAfee\Temp\qxzD3\McNdAtpg.dll
c:\program files\McAfee\Temp\qxzD3\McNDLor.dll
c:\program files\McAfee\Temp\qxzD3\McNDSv.dll
c:\program files\McAfee\Temp\qxzD3\McNDSVPS.dll
c:\program files\McAfee\Temp\qxzD3\McNMAtpg.dll
c:\program files\McAfee\Temp\qxzD3\McNmcIns.dll
c:\program files\McAfee\Temp\qxzD3\McNmcLoR.dll
c:\program files\McAfee\Temp\qxzD3\McNmcShell.exe
c:\program files\McAfee\Temp\qxzD3\McNmcSPS.dll
c:\program files\McAfee\Temp\qxzD3\McNmcSrv.dll
c:\program files\McAfee\Temp\qxzD3\McNmcVer.dll
c:\program files\McAfee\Temp\qxzD3\mcocdisable.inf
c:\program files\McAfee\Temp\qxzD3\mcocenable.inf
c:\program files\McAfee\Temp\qxzD3\mcocinstru.inf
c:\program files\McAfee\Temp\qxzD3\mcoemmgr.exe
c:\program files\McAfee\Temp\qxzD3\mcoemmgr.inf
c:\program files\McAfee\Temp\qxzD3\mcoemres.dll
c:\program files\McAfee\Temp\qxzD3\mcoemres.inf
c:\program files\McAfee\Temp\qxzD3\mcprlalt.dll
c:\program files\McAfee\Temp\qxzD3\mcprlres.dll
c:\program files\McAfee\Temp\qxzD3\McPrsShm.dll
c:\program files\McAfee\Temp\qxzD3\McRegObj.dll
c:\program files\McAfee\Temp\qxzD3\McRTMui.dll
c:\program files\McAfee\Temp\qxzD3\mcscindx.dat
c:\program files\McAfee\Temp\qxzD3\mcscrhlp.dll
c:\program files\McAfee\Temp\qxzD3\McSmpUI.dll
c:\program files\McAfee\Temp\qxzD3\McSmtFWk.exe
c:\program files\McAfee\Temp\qxzD3\mcsmtmsg.inf
c:\program files\McAfee\Temp\qxzD3\McSmtStr.dll
c:\program files\McAfee\Temp\qxzD3\McSmtTsk.dll
c:\program files\McAfee\Temp\qxzD3\McSnIEPl.dll
c:\program files\McAfee\Temp\qxzD3\mcsubmgr.dll
c:\program files\McAfee\Temp\qxzD3\mcsvrcnt.exe
c:\program files\McAfee\Temp\qxzD3\mcsync.exe
c:\program files\McAfee\Temp\qxzD3\mcuc.inf
c:\program files\McAfee\Temp\qxzD3\McUiCfg.dll
c:\program files\McAfee\Temp\qxzD3\mcuicnt.exe
c:\program files\McAfee\Temp\qxzD3\mcuihost.exe
c:\program files\McAfee\Temp\qxzD3\mcuinshm.dll
c:\program files\McAfee\Temp\qxzD3\mcuninst.exe
c:\program files\McAfee\Temp\qxzD3\mcupdate.exe
c:\program files\McAfee\Temp\qxzD3\McUpdMgr.exe
c:\program files\McAfee\Temp\qxzD3\McUpdShm.dll
c:\program files\McAfee\Temp\qxzD3\mcutil.dll
c:\program files\McAfee\Temp\qxzD3\mcutil2.dll
c:\program files\McAfee\Temp\qxzD3\misplf.dll
c:\program files\McAfee\Temp\qxzD3\mispreg.exe
c:\program files\McAfee\Temp\qxzD3\msc\mscLI.inf
c:\program files\McAfee\Temp\qxzD3\msccmn.inf
c:\program files\McAfee\Temp\qxzD3\msccust.inf
c:\program files\McAfee\Temp\qxzD3\mscinres.dll
c:\program files\McAfee\Temp\qxzD3\mscjsres.dll
c:\program files\McAfee\Temp\qxzD3\msclgmis.inf
c:\program files\McAfee\Temp\qxzD3\mscmisc.inf
c:\program files\McAfee\Temp\qxzD3\mscoobe.inf
c:\program files\McAfee\Temp\qxzD3\mscprmgr.inf
c:\program files\McAfee\Temp\qxzD3\mscpstLI.inf
c:\program files\McAfee\Temp\qxzD3\mscreg.inf
c:\program files\McAfee\Temp\qxzD3\mscrem.inf
c:\program files\McAfee\Temp\qxzD3\mscres.inf
c:\program files\McAfee\Temp\qxzD3\mscshll.inf
c:\program files\McAfee\Temp\qxzD3\mscsvc.inf
c:\program files\McAfee\Temp\qxzD3\mscuild.dll
c:\program files\McAfee\Temp\qxzD3\mscuimgr.inf
c:\program files\McAfee\Temp\qxzD3\mscupd.inf
c:\program files\McAfee\Temp\qxzD3\nmcdef.inf
c:\program files\McAfee\Temp\qxzD3\NMCJsRes.dll
c:\program files\McAfee\Temp\qxzD3\nmcLI32.inf
c:\program files\McAfee\Temp\qxzD3\nmcuicfg.dat
c:\program files\McAfee\Temp\qxzD3\npMcSnFFPl.dll
c:\program files\McAfee\Temp\qxzD3\oemui.dll
c:\program files\McAfee\Temp\qxzD3\oemui.inf
c:\program files\McAfee\Temp\qxzD3\oemuild.dll
c:\program files\McAfee\Temp\qxzD3\oemuild.inf
c:\program files\McAfee\Temp\qxzD3\RprtShm.dll
c:\program files\McAfee\Temp\qxzD3\sqlite3.dll
c:\program files\McAfee\Temp\qxzD3\TskTCShm.dll
c:\program files\McAfee\Temp\qxzD3\vscore.inf
c:\program files\McAfee\Temp\qxzD3\vscore_fresh.inf
c:\program files\McAfee\Temp\qxzD3\vscore_pre.inf
c:\program files\McAfee\Temp\qxzD3\vscore_update.inf
c:\program files\McAfee\Temp\qxzD3\x64\mcactui.dll
c:\program files\McAfee\Temp\qxzD3\x64\mcactwiz.dll
c:\program files\McAfee\Temp\qxzD3\x64\mcactwiz_ld.dll
c:\program files\McAfee\Temp\qxzD3\x64\McInstru.dll
c:\program files\McAfee\Temp\qxzD3\x64\mcinstru.exe
c:\program files\McAfee\Temp\qxzD3\x64\mcoemmgr.exe
c:\program files\McAfee\Temp\qxzD4\mscLD.inf
c:\program files\McAfee\Temp\qxzD5\mclgtmpl.inf
c:\program files\McAfee\Temp\qxzDA\mscLD.inf
c:\program files\McAfee\Temp\qxzDB\mclgtmpl.inf
c:\program files\McAfee\Temp\qxzE2\override.inf
c:\program files\McAfee\Temp\qxzF0\override.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_McAfee_SiteAdvisor_Service
——-\Legacy_McAfee_SiteAdvisor_Service
——-\Legacy_mfefire
——-\Service_McAfee SiteAdvisor Service
——-\Service_McAfee SiteAdvisor Service
——-\Service_mfefire
.
.
((((((((((((((((((((((((( Files Created from 2012-06-11 to 2012-07-11 )))))))))))))))))))))))))))))))
.
.
2012-07-09 01:21 . 2012-07-09 01:21 ——– d–h–w- c:\windows\system32\GroupPolicy
2012-07-09 00:44 . 2012-04-04 14:56 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-02 14:19 . 2007-05-30 22:39 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 14:19 . 2007-05-30 22:39 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 14:19 . 2005-08-16 03:40 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 14:19 . 2005-08-16 03:40 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 14:19 . 2005-08-16 03:40 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 14:19 . 2007-05-30 22:39 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 14:19 . 2005-08-16 03:40 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 14:19 . 2005-08-16 03:40 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 14:19 . 2005-08-16 03:18 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 14:19 . 2005-05-26 03:16 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 14:19 . 2007-05-30 22:39 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 14:19 . 2005-08-16 03:40 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 14:19 . 2005-08-16 03:40 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 14:18 . 2007-05-31 18:20 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 14:18 . 2006-12-20 00:22 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 14:18 . 2006-12-20 00:22 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-05-24 01:40 . 2012-05-24 01:40 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2012-05-24 00:37 . 2012-05-24 00:37 8072272 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\BingBar\BBSvc\7.1.382.0oemBingBarSetup-Partner.EXE
2012-05-19 18:50 . 2011-08-18 00:46 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-09-01 11:12 . 2008-08-27 13:08 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2011-04-14 13:01 . 2010-08-21 19:07 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-11_02.21.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-11 02:56 . 2012-07-11 02:56 16384 c:\windows\Temp\Perflib_Perfdata_47c.dat
+ 2012-07-11 02:56 . 2012-07-11 02:56 16384 c:\windows\Temp\Perflib_Perfdata_23c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-14 7323648]
"CTHelper"="CTHELPER.EXE" [2005-11-08 16384]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-03-02 18944]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-11-09 497240]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-09-01 30192]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-12-18 296056]
"McAfeeWrapperApplication"="c:\program files\McAfeeMOBK\WrapperTrayIcon.exe" [2010-11-01 453344]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-13 73728]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Dougie\Start Menu\Programs\Startup\
BBC iPlayer Desktop.lnk - c:\program files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe [2011-6-26 142848]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
AOL 9.0 Tray Icon.lnk - c:\program files\AOL 9.0\aoltray.exe [2006-4-6 156784]
Audible Download Manager.lnk - c:\program files\Audible\Bin\AudibleDownloadHelper.exe [2009-4-29 1787224]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Huawei technologies\\Huawei UMTS Data Card\\3 USB Modem.exe"=
"c:\\Program Files\\Intel\\PROSetWired\\NCS\\PROSet\\PROSet.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [31/01/2012 04:46 31952]
R1 AvgLdx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [22/02/2012 05:25 235216]
R1 AvgTdiX;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [19/03/2012 05:17 301248]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [13/03/2012 17:42 89792]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [24/05/2012 02:39 285392]
R2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.382.0\BBSvc.EXE [16/04/2012 17:49 193616]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [18/09/2011 23:25 151880]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [13/03/2012 17:42 340920]
R3 xpsec;IPSEC driver;c:\windows\system32\drivers\xpsec.sys –> c:\windows\system32\drivers\xpsec.sys [?]
S0 pfdewi;pfdewi;c:\windows\system32\drivers\cnrn.sys –> c:\windows\system32\drivers\cnrn.sys [?]
S2 gupdate1cac295ec48ec54;Google Update Service (gupdate1cac295ec48ec54);c:\program files\Google\Update\GoogleUpdate.exe [13/03/2010 11:14 133104]
S3 1syqo.sys;1syqo.sys;\??\c:\windows\system32\drivers\1syqo.sys –> c:\windows\system32\drivers\1syqo.sys [?]
S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.382.0\SeaPort.EXE [16/04/2012 17:49 240208]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [13/03/2012 17:42 57600]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [07/11/2010 18:52 112640]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [21/04/2006 19:47 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [13/03/2010 11:14 133104]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [13/03/2012 17:42 83856]
S3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [13/03/2012 17:42 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [13/03/2012 17:42 87656]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [19/05/2012 19:51 129976]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - xcpip
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 11:34]
.
2012-07-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 10:13]
.
2012-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 10:13]
.
2012-07-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1038292835-2904995092-2848636223-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-07-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1038292835-2904995092-2848636223-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-05-21 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1038292835-2904995092-2848636223-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-05-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1038292835-2904995092-2848636223-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-07-11 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]
.
2012-05-24 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Dougie\Application Data\Mozilla\Firefox\Profiles\pmio7n0d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.type - 4
FF - user.js: extensions.funmoods_i.hmpg - true
FF - user.js: extensions.funmoods_i.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=bf4
FF - user.js: extensions.funmoods_i.dfltSrch - true
FF - user.js: extensions.funmoods_i.srchPrvdr - Search
FF - user.js: extensions.funmoods_i.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods_i.newTabUrl - hxxp://start.funmoods.com/?f=2&a=bf4
FF - user.js: extensions.funmoods_i.tlbrSrchUrl - hxxp://start.funmoods.com/results.php?f=3&a=bf4&q=
FF - user.js: extensions.funmoods_i.id - e0387ce20000000000000014a589c33a
FF - user.js: extensions.funmoods_i.instlDay - 15440
FF - user.js: extensions.funmoods_i.vrsn - [removed]
FF - user.js: extensions.funmoods_i.vrsni - [removed]
FF - user.js: extensions.funmoods_i.vrsnTs - [removed]:55
FF - user.js: extensions.funmoods_i.prtnrId - funmoods
FF - user.js: extensions.funmoods_i.prdct - funmoods
FF - user.js: extensions.funmoods_i.aflt - bf4
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods_i.tlbrId - base
FF - user.js: extensions.funmoods_i.instlRef -
FF - user.js: extensions.funmoods_i.dfltLng -
FF - user.js: extensions.funmoods_i.excTlbr - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-11 03:58
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,RunDLLEntry???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\irtqbvfwosecigi]
"imagepath"="\??\c:\windows\TEMP\58.tmp"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1688)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\SYSTEM32\CTXFISPI.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dlcccoms.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2012-07-11 04:03:05 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-11 03:03
ComboFix2.txt 2012-07-11 02:27
.
Pre-Run: 85,262,409,728 bytes free
Post-Run: 85,096,763,392 bytes free
.
- - End Of File - - 0A6CAC5F9AAFE5277E9F6435E1D40511






I havent been able to run the OTL and aswMBR programs as the Administrator as it keeps telling me that the password is invalid (have tried everything I can think of!). I've ran them as the person who I'm assuming must be the administrator though. Unfortunately once the OTL scan has finished, I'm only getting two Notepad pop-up messages:

'Cannot find the C:\Documents and Settings\Dougie\Desktop\OTL(or Extras).Txt file.

Do you want to create a new file?' - YES/NO/CANCEL



Have had more success with the MBR scan though. Here's the log:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-13 12:32:27
—————————–
12:32:27.812 OS Version: Windows 5.1.2600 Service Pack 3
12:32:27.812 Number of processors: 2 586 0x602
12:32:27.812 ComputerName: INNIT UserName:
12:32:28.984 Initialize success
12:44:02.028 AVAST engine defs: 12071300
12:45:25.559 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
12:45:25.559 Disk 0 Vendor: Intel___ 1.0. Size: 476832MB BusType: 3
12:45:25.559 Disk 0 MBR read successfully
12:45:25.559 Disk 0 MBR scan
12:45:25.621 Disk 0 unknown MBR code
12:45:25.637 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63
12:45:25.653 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 471925 MB offset 96390
12:45:25.684 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 4855 MB offset 966598920
12:45:25.684 Disk 0 scanning sectors +976543155
12:45:25.778 Disk 0 scanning C:\WINDOWS\system32\drivers
12:45:41.715 Service scanning
12:46:03.059 Modules scanning
12:46:21.918 Module: C:\WINDOWS\System32\DLA\DLADResN.SYS **SUSPICIOUS**
12:46:22.574 Disk 0 trace - called modules:
12:46:22.590 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x881dbda8]<<
12:46:22.590 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ad4aab8]
12:46:22.606 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8accc030]
12:46:23.574 AVAST engine scan C:\WINDOWS
12:46:48.418 AVAST engine scan C:\WINDOWS\system32
12:50:55.824 AVAST engine scan C:\WINDOWS\system32\drivers
12:51:32.074 AVAST engine scan C:\Documents and Settings\Dougie
13:12:46.996 AVAST engine scan C:\Documents and Settings\All Users
13:14:32.731 Scan finished successfully
13:16:03.809 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Dougie\Desktop\MBR.dat"
13:16:03.824 The log file has been saved successfully to "C:\Documents and Settings\Dougie\Desktop\aswMBR.txtyupyup.txt"





Thanks again.

Jen.
Oh, and I've tried every YES/NO/CANCEL option for the OTL……none of which seem to make any difference. Shoulda mentioned that.
Hi,

Ok….

Let's do this…

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Attach the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-
Hi, Please find the two txts attached (I hope!). Uploading the TDSSKiller log failed - 'You are not permitted to upload this type of file' - so I've copied and pasted it below. Thanks, Jen. 2006/07/03-06:31:08.828 ComClient LcsGetClientIdRunnable() exception=0 2006/07/03-06:31:08.906 ComClient LcsGetClientIdRunnable() exception=0 2007/03/30-23:38:01.968 ComClient LcsGetClientIdRunnable() exception=0 2007/03/30-23:38:02.015 ComClient LcsGetClientIdRunnable() exception=0 2007/04/21-07:29:47.765 ComClient LcsEnumWindowsHidsRunnable() COM error = 0x80010105 2007/10/06-11:24:27.625 ComClient LcsGetClientIdRunnable() exception=0 2008/01/05-00:04:56.281 ComClient LcsEnumWindowsHidsRunnable() COM error = 0x80010105 2008/07/21-22:23:58.734 ComClient LcsEnumWindowsScannersRunnable() COM error = 0x80010105 2008/08/09-14:36:53.656 ComClient LcsEnumWindowsScannersRunnable() COM error = 0x80010105 2009/11/29-11:28:14.843 ComClient LcsGetClientIdRunnable() exception=0 2009/12/02-20:51:05.921 ComClient LcsGetClientIdRunnable() exception=0 2009/12/03-14:35:51.687 ComClient LcsGetClientIdRunnable() exception=0 2009/12/04-00:07:49.187 ComClient LcsGetClientIdRunnable() exception=0 2009/12/04-00:30:58.578 ComClient LcsGetClientIdRunnable() exception=0 2009/12/04-16:11:44.109 ComClient LcsGetClientIdRunnable() exception=0 2009/12/05-22:39:38.734 ComClient LcsGetClientIdRunnable() exception=0 2009/12/06-19:34:12.031 ComClient LcsGetClientIdRunnable() exception=0 2009/12/06-19:37:29.546 ComClient LcsGetClientIdRunnable() exception=0 2009/12/08-19:05:24.953 ComClient LcsGetClientIdRunnable() exception=0 2009/12/08-22:01:47.750 ComClient LcsGetClientIdRunnable() exception=0 2009/12/11-00:25:54.843 ComClient LcsGetClientIdRunnable() exception=0 2010/01/06-18:30:29.375 ComClient LcsGetClientIdRunnable() exception=0 2010/01/06-18:30:29.640 ComClient LcsGetClientIdRunnable() exception=0 2010/01/06-18:49:16.671 ComClient LcsGetClientIdRunnable() exception=0 2010/01/06-18:49:16.718 ComClient LcsGetClientIdRunnable() exception=0 2010/01/06-21:26:54.156 ComClient LcsGetClientIdRunnable() exception=0 2010/01/06-21:26:54.390 ComClient LcsGetClientIdRunnable() exception=0 2010/01/06-23:54:10.890 ComClient LcsGetClientIdRunnable() exception=0 2010/01/06-23:54:11.015 ComClient LcsGetClientIdRunnable() exception=0 2010/01/07-01:06:31.843 ComClient LcsGetClientIdRunnable() exception=0 2010/01/08-02:29:23.593 ComClient LcsGetClientIdRunnable() exception=0 2010/01/12-12:13:43.406 ComClient LcsGetClientIdRunnable() exception=0 2010/01/12-15:50:23.828 ComClient LcsGetClientIdRunnable() exception=0 2010/01/12-17:51:38.531 ComClient LcsGetClientIdRunnable() exception=0 2010/01/12-20:15:54.125 ComClient LcsGetClientIdRunnable() exception=0 2010/01/13-10:53:23.859 ComClient LcsGetClientIdRunnable() exception=0 2010/01/14-12:40:35.703 ComClient LcsGetClientIdRunnable() exception=0 2010/01/14-21:34:48.625 ComClient LcsGetClientIdRunnable() exception=0 2010/01/15-01:00:56.312 ComClient LcsGetClientIdRunnable() exception=0 2010/01/15-12:38:20.765 ComClient LcsGetClientIdRunnable() exception=0 2010/01/17-15:48:55.375 ComClient LcsGetClientIdRunnable() exception=0 2010/01/17-23:14:18.953 ComClient LcsGetClientIdRunnable() exception=0 2010/01/18-12:20:11.781 ComClient LcsGetClientIdRunnable() exception=0 2010/01/18-21:15:09.031 ComClient LcsGetClientIdRunnable() exception=0 2010/01/20-12:16:39.875 ComClient LcsGetClientIdRunnable() exception=0 2010/01/20-18:13:54.406 ComClient LcsGetClientIdRunnable() exception=0 2010/01/20-19:53:03.406 ComClient LcsGetClientIdRunnable() exception=0 2010/01/21-14:52:05.656 ComClient LcsGetClientIdRunnable() exception=0 2010/01/22-00:10:55.734 ComClient LcsGetClientIdRunnable() exception=0 2010/01/24-22:10:06.515 ComClient LcsGetClientIdRunnable() exception=0 2010/01/24-22:32:37.312 ComClient LcsGetClientIdRunnable() exception=0 2010/01/26-02:43:57.437 ComClient LcsGetClientIdRunnable() exception=0 2010/01/27-14:17:43.140 ComClient LcsGetClientIdRunnable() exception=0 2010/01/28-00:22:56.796 ComClient LcsGetClientIdRunnable() exception=0 2010/01/28-14:33:56.468 ComClient LcsGetClientIdRunnable() exception=0 2010/01/29-11:17:47.718 ComClient LcsGetClientIdRunnable() exception=0 2010/01/30-01:15:50.406 ComClient LcsGetClientIdRunnable() exception=0 2010/01/30-12:41:12.593 ComClient LcsGetClientIdRunnable() exception=0 2010/01/30-12:57:24.937 ComClient LcsGetClientIdRunnable() exception=0 2010/01/31-14:35:30.500 ComClient LcsGetClientIdRunnable() exception=0 2010/02/03-13:36:01.500 ComClient LcsGetClientIdRunnable() exception=0 2010/02/04-10:48:51.812 ComClient LcsGetClientIdRunnable() exception=0 2010/02/04-23:07:37.250 ComClient LcsGetClientIdRunnable() exception=0 2010/02/07-09:56:57.312 ComClient LcsGetClientIdRunnable() exception=0 2010/02/10-11:33:57.781 ComClient LcsGetClientIdRunnable() exception=0 2010/02/10-18:03:46.734 ComClient LcsGetClientIdRunnable() exception=0 2010/02/15-12:34:38.890 ComClient LcsGetClientIdRunnable() exception=0 2010/02/16-15:34:23.609 ComClient LcsGetClientIdRunnable() exception=0 2010/02/17-11:56:04.484 ComClient LcsGetClientIdRunnable() exception=0 2010/02/17-16:42:51.906 ComClient LcsGetClientIdRunnable() exception=0 2010/02/17-17:53:46.578 ComClient LcsGetClientIdRunnable() exception=0 2010/02/18-00:08:47.453 ComClient LcsGetClientIdRunnable() exception=0 2010/02/18-16:33:48.937 ComClient LcsGetClientIdRunnable() exception=0 2010/02/19-12:15:33.859 ComClient LcsGetClientIdRunnable() exception=0 2010/02/24-21:17:17.687 ComClient LcsGetClientIdRunnable() exception=0 2010/02/25-12:16:14.328 ComClient LcsGetClientIdRunnable() exception=0 2010/02/25-14:06:06.359 ComClient LcsGetClientIdRunnable() exception=0 2010/02/25-22:31:39.640 ComClient LcsGetClientIdRunnable() exception=0 2010/03/03-12:48:24.656 ComClient LcsGetClientIdRunnable() exception=0 2010/03/03-18:13:54.593 ComClient LcsGetClientIdRunnable() exception=0 2010/03/04-00:54:00.859 ComClient LcsGetClientIdRunnable() exception=0 2010/03/04-12:45:07.515 ComClient LcsGetClientIdRunnable() exception=0 2010/03/05-00:55:10.296 ComClient LcsGetClientIdRunnable() exception=0 2010/03/05-12:18:10.609 ComClient LcsGetClientIdRunnable() exception=0 2010/03/07-10:09:45.421 ComClient LcsGetClientIdRunnable() exception=0 2010/03/08-10:21:35.171 ComClient LcsGetClientIdRunnable() exception=0 2010/03/08-20:49:13.500 ComClient LcsGetClientIdRunnable() exception=0 2010/03/09-16:26:38.453 ComClient LcsGetClientIdRunnable() exception=0 2010/03/11-21:36:27.234 ComClient LcsGetClientIdRunnable() exception=0 2010/03/12-10:07:18.609 ComClient LcsGetClientIdRunnable() exception=0 2010/03/12-13:06:51.339 ComClient LcsGetClientIdRunnable() exception=0 2010/03/12-13:11:52.921 ComClient LcsGetClientIdRunnable() exception=0 2010/03/13-09:36:39.421 ComClient LcsGetClientIdRunnable() exception=0 2010/03/13-15:44:25.326 ComClient LcsGetClientIdRunnable() exception=0 2010/03/13-15:52:19.195 ComClient LcsGetClientIdRunnable() exception=0 2010/03/14-08:44:49.203 ComClient LcsGetClientIdRunnable() exception=0 2010/03/14-10:32:33.828 ComClient LcsGetClientIdRunnable() exception=0 2010/03/16-11:03:34.234 ComClient LcsGetClientIdRunnable() exception=0 2010/03/16-11:23:21.125 ComClient LcsGetClientIdRunnable() exception=0 2010/03/18-15:54:21.765 ComClient LcsGetClientIdRunnable() exception=0 2010/03/20-09:51:55.640 ComClient LcsGetClientIdRunnable() exception=0 2010/03/23-10:55:29.890 ComClient LcsGetClientIdRunnable() exception=0 2010/03/24-11:13:41.640 ComClient LcsGetClientIdRunnable() exception=0 2010/03/25-23:10:44.484 ComClient LcsGetClientIdRunnable() exception=0 2010/03/28-12:55:14.609 ComClient LcsGetClientIdRunnable() exception=0 2010/03/29-20:58:55.828 ComClient LcsGetClientIdRunnable() exception=0 2010/04/01-18:36:24.252 ComClient LcsGetClientIdRunnable() exception=0 2010/04/01-19:09:21.953 ComClient LcsGetClientIdRunnable() exception=0 2010/04/04-16:54:19.528 ComClient LcsGetClientIdRunnable() exception=0 2010/04/05-21:39:17.718 ComClient LcsGetClientIdRunnable() exception=0 2010/04/10-17:30:49.562 ComClient LcsGetClientIdRunnable() exception=0 2010/04/13-20:04:59.093 ComClient LcsGetClientIdRunnable() exception=0 2010/04/15-00:27:26.859 ComClient LcsGetClientIdRunnable() exception=0 2010/04/15-11:29:43.140 ComClient LcsGetClientIdRunnable() exception=0 2010/04/15-22:42:15.953 ComClient LcsGetClientIdRunnable() exception=0 2010/04/16-17:25:11.515 ComClient LcsGetClientIdRunnable() exception=0 2010/04/17-11:51:30.406 ComClient LcsGetClientIdRunnable() exception=0 2010/04/17-16:14:30.125 ComClient LcsGetClientIdRunnable() exception=0 2010/04/18-12:36:30.062 ComClient LcsGetClientIdRunnable() exception=0 2010/04/18-15:50:04.562 ComClient LcsGetClientIdRunnable() exception=0 2010/04/19-08:28:18.062 ComClient LcsGetClientIdRunnable() exception=0 2010/04/19-16:25:42.921 ComClient LcsGetClientIdRunnable() exception=0 2010/04/20-19:03:36.445 ComClient LcsGetClientIdRunnable() exception=0 2010/04/20-22:42:55.781 ComClient LcsGetClientIdRunnable() exception=0 2010/04/21-16:04:59.906 ComClient LcsGetClientIdRunnable() exception=0 2010/04/21-17:23:22.812 ComClient LcsGetClientIdRunnable() exception=0 2010/04/22-19:53:13.109 ComClient LcsGetClientIdRunnable() exception=0 2010/04/23-12:13:17.406 ComClient LcsGetClientIdRunnable() exception=0 2010/04/26-17:47:15.812 ComClient LcsGetClientIdRunnable() exception=0 2010/04/28-12:58:06.953 ComClient LcsGetClientIdRunnable() exception=0 2010/04/29-20:18:12.578 ComClient LcsGetClientIdRunnable() exception=0 2010/05/02-00:33:13.234 ComClient LcsGetClientIdRunnable() exception=0 2010/05/03-11:14:59.484 ComClient LcsGetClientIdRunnable() exception=0 2010/05/04-14:34:53.973 ComClient LcsGetClientIdRunnable() exception=0 2010/05/04-15:56:58.891 ComClient LcsGetClientIdRunnable() exception=0 2010/05/05-10:58:07.796 ComClient LcsGetClientIdRunnable() exception=0 2010/05/06-12:43:10.828 ComClient LcsGetClientIdRunnable() exception=0 2010/05/08-10:45:20.385 ComClient LcsGetClientIdRunnable() exception=0 2010/05/09-11:56:53.595 ComClient LcsGetClientIdRunnable() exception=0 2010/05/09-17:08:16.390 ComClient LcsGetClientIdRunnable() exception=0 2010/05/10-00:25:50.546 ComClient LcsGetClientIdRunnable() exception=0 2010/05/10-11:55:31.765 ComClient LcsGetClientIdRunnable() exception=0 2010/05/11-20:51:36.562 ComClient LcsGetClientIdRunnable() exception=0 2010/05/12-17:15:12.765 ComClient LcsGetClientIdRunnable() exception=0 2010/05/12-19:52:04.093 ComClient LcsGetClientIdRunnable() exception=0 2010/05/13-08:23:51.843 ComClient LcsGetClientIdRunnable() exception=0 2010/05/14-06:25:43.937 ComClient LcsGetClientIdRunnable() exception=0 2010/05/15-01:23:31.921 ComClient LcsGetClientIdRunnable() exception=0 2010/05/15-01:39:43.093 ComClient LcsGetClientIdRunnable() exception=0 2010/05/15-02:02:40.031 ComClient LcsGetClientIdRunnable() exception=0 2010/05/15-11:12:30.609 ComClient LcsGetClientIdRunnable() exception=0 2010/05/17-18:23:10.360 ComClient LcsGetClientIdRunnable() exception=0 2010/05/18-00:13:44.775 ComClient LcsGetClientIdRunnable() exception=0 2010/05/18-09:30:07.890 ComClient LcsGetClientIdRunnable() exception=0 2010/05/18-21:17:31.484 ComClient LcsGetClientIdRunnable() exception=0 2010/06/01-22:46:34.088 ComClient LcsGetClientIdRunnable() exception=0 2010/06/06-13:53:06.531 ComClient LcsGetClientIdRunnable() exception=0 2010/06/08-22:18:03.734 ComClient LcsGetClientIdRunnable() exception=0 2010/06/08-22:29:09.921 ComClient LcsGetClientIdRunnable() exception=0 2010/06/19-19:49:58.031 ComClient LcsGetClientIdRunnable() exception=0 2010/07/19-01:09:22.031 ComClient LcsGetClientIdRunnable() exception=0 2010/07/20-00:02:38.218 ComClient LcsGetClientIdRunnable() exception=0 2010/07/21-00:06:39.635 ComClient LcsGetClientIdRunnable() exception=0 2010/07/27-22:56:13.875 ComClient LcsGetClientIdRunnable() exception=0 2010/08/01-01:08:20.165 ComClient LcsGetClientIdRunnable() exception=0 2010/08/01-11:19:05.906 ComClient LcsGetClientIdRunnable() exception=0 2010/08/04-01:00:39.125 ComClient LcsGetClientIdRunnable() exception=0 2010/08/04-23:48:55.890 ComClient LcsGetClientIdRunnable() exception=0 2010/08/06-00:19:22.653 ComClient LcsGetClientIdRunnable() exception=0 2010/08/21-16:26:22.234 ComClient LcsGetClientIdRunnable() exception=0 2010/08/23-22:55:06.761 ComClient LcsGetClientIdRunnable() exception=0 2010/08/25-20:03:24.328 ComClient LcsGetClientIdRunnable() exception=0 2010/08/26-12:40:28.625 ComClient LcsGetClientIdRunnable() exception=0 2010/08/30-19:29:10.459 ComClient LcsGetClientIdRunnable() exception=0 2010/08/30-23:33:52.421 ComClient LcsGetClientIdRunnable() exception=0 2010/09/01-12:11:43.140 ComClient LcsGetClientIdRunnable() exception=0 2010/09/01-12:26:33.593 ComClient LcsGetClientIdRunnable() exception=0 2010/09/05-13:02:12.296 ComClient LcsGetClientIdRunnable() exception=0 2010/09/05-15:32:52.359 ComClient LcsGetClientIdRunnable() exception=0 2010/09/12-09:20:46.328 ComClient LcsGetClientIdRunnable() exception=0 2010/09/13-01:55:43.703 ComClient LcsGetClientIdRunnable() exception=0 2010/09/13-20:51:14.515 ComClient LcsGetClientIdRunnable() exception=0 2010/09/13-20:51:14.593 ComClient LcsGetClientIdRunnable() exception=0 2010/09/14-15:15:30.606 ComClient LcsGetClientIdRunnable() exception=0 2010/09/15-10:15:47.078 ComClient LcsGetClientIdRunnable() exception=0 2010/09/17-11:25:19.596 ComClient LcsGetClientIdRunnable() exception=0 2010/09/19-16:48:19.140 ComClient LcsGetClientIdRunnable() exception=0 2010/09/19-16:48:19.703 ComClient LcsGetClientIdRunnable() exception=0 2010/09/22-22:33:16.390 ComClient LcsGetClientIdRunnable() exception=0 2010/09/26-00:25:52.085 ComClient LcsGetClientIdRunnable() exception=0 2010/10/07-21:15:40.199 ComClient LcsGetClientIdRunnable() exception=0 2010/10/08-15:47:40.687 ComClient LcsGetClientIdRunnable() exception=0 2010/10/09-19:44:11.703 ComClient LcsGetClientIdRunnable() exception=0 2010/10/10-17:19:58.078 ComClient LcsGetClientIdRunnable() exception=0 2010/10/15-21:13:47.518 ComClient LcsGetClientIdRunnable() exception=0 2010/10/21-22:47:43.312 ComClient LcsGetClientIdRunnable() exception=0 2010/10/22-09:46:40.406 ComClient LcsGetClientIdRunnable() exception=0 2010/10/22-16:43:22.656 ComClient LcsGetClientIdRunnable() exception=0 2010/10/22-22:13:32.765 ComClient LcsGetClientIdRunnable() exception=0 2010/10/23-15:29:43.234 ComClient LcsGetClientIdRunnable() exception=0 2010/10/23-21:16:17.968 ComClient LcsGetClientIdRunnable() exception=0 2010/10/24-10:35:57.687 ComClient LcsGetClientIdRunnable() exception=0 2010/10/24-10:42:31.328 ComClient LcsGetClientIdRunnable() exception=0 2010/10/29-00:29:37.552 ComClient LcsGetClientIdRunnable() exception=0 2010/10/29-19:11:56.468 ComClient LcsGetClientIdRunnable() exception=0 2010/10/30-16:25:18.938 ComClient LcsGetClientIdRunnable() exception=0 2010/10/31-16:16:40.859 ComClient LcsGetClientIdRunnable() exception=0 2010/11/04-16:53:40.578 ComClient LcsGetClientIdRunnable() exception=0 2010/11/06-15:31:22.289 ComClient LcsGetClientIdRunnable() exception=0 2010/11/06-19:38:59.953 ComClient LcsGetClientIdRunnable() exception=0 2010/11/07-20:17:30.281 ComClient LcsGetClientIdRunnable() exception=0 2010/12/13-16:25:04.875 ComClient LcsGetClientIdRunnable() exception=0 2010/12/15-09:27:33.843 ComClient LcsGetClientIdRunnable() exception=0 2010/12/15-22:05:46.250 ComClient LcsGetClientIdRunnable() exception=0 2010/12/17-13:02:22.953 ComClient LcsGetClientIdRunnable() exception=0 2010/12/21-11:15:21.156 ComClient LcsGetClientIdRunnable() exception=0 2010/12/22-16:34:01.031 ComClient LcsGetClientIdRunnable() exception=0 2010/12/26-02:13:38.953 ComClient LcsGetClientIdRunnable() exception=0 2011/01/03-14:05:13.468 ComClient LcsGetClientIdRunnable() exception=0 2011/01/05-22:40:54.390 ComClient LcsGetClientIdRunnable() exception=0 2011/01/06-14:07:07.796 ComClient LcsGetClientIdRunnable() exception=0 2011/01/08-19:11:14.031 ComClient LcsGetClientIdRunnable() exception=0 2011/01/09-15:04:09.609 ComClient LcsGetClientIdRunnable() exception=0 2011/01/10-13:24:19.218 ComClient LcsGetClientIdRunnable() exception=0 2011/01/21-19:42:29.421 ComClient LcsGetClientIdRunnable() exception=0 2011/01/21-21:36:38.875 ComClient LcsGetClientIdRunnable() exception=0 2011/01/22-00:06:25.015 ComClient LcsGetClientIdRunnable() exception=0 2011/01/22-00:22:42.781 ComClient LcsGetClientIdRunnable() exception=0 2011/01/22-00:34:47.828 ComClient LcsGetClientIdRunnable() exception=0 2011/01/22-01:06:53.750 ComClient LcsGetClientIdRunnable() exception=0 2011/01/28-00:39:50.484 ComClient LcsGetClientIdRunnable() exception=0 2011/01/28-10:18:59.906 ComClient LcsGetClientIdRunnable() exception=0 2011/01/29-23:27:37.734 ComClient LcsGetClientIdRunnable() exception=0 2011/01/29-23:55:14.656 ComClient LcsGetClientIdRunnable() exception=0 2011/01/30-00:03:30.734 ComClient LcsGetClientIdRunnable() exception=0 2011/01/30-01:07:59.406 ComClient LcsGetClientIdRunnable() exception=0 2011/01/30-01:35:53.421 ComClient LcsGetClientIdRunnable() exception=0 2011/01/30-02:31:28.125 ComClient LcsGetClientIdRunnable() exception=0 2011/01/31-10:23:02.281 ComClient LcsGetClientIdRunnable() exception=0 2011/02/01-02:55:03.734 ComClient LcsGetClientIdRunnable() exception=0 2011/02/11-20:35:57.718 ComClient LcsGetClientIdRunnable() exception=0 2011/02/12-21:46:24.925 ComClient LcsGetClientIdRunnable() exception=0 2011/02/13-00:02:56.187 ComClient LcsGetClientIdRunnable() exception=0 2011/02/13-02:16:00.843 ComClient LcsGetClientIdRunnable() exception=0 2011/02/25-18:11:24.605 ComClient LcsGetClientIdRunnable() exception=0 2011/03/02-19:57:48.171 ComClient LcsGetClientIdRunnable() exception=0 2011/03/03-18:01:18.125 ComClient LcsGetClientIdRunnable() exception=0 2011/03/04-12:49:23.806 ComClient LcsGetClientIdRunnable() exception=0 2011/03/05-21:08:08.104 ComClient LcsGetClientIdRunnable() exception=0 2011/03/07-12:07:33.531 ComClient LcsGetClientIdRunnable() exception=0 2011/03/13-16:16:55.328 ComClient LcsGetClientIdRunnable() exception=0 2011/03/17-18:31:58.218 ComClient LcsGetClientIdRunnable() exception=0 2011/03/22-18:08:58.078 ComClient LcsGetClientIdRunnable() exception=0 2011/03/31-20:11:17.188 ComClient LcsGetClientIdRunnable() exception=0 2011/04/10-02:51:46.406 ComClient LcsGetClientIdRunnable() exception=0 2011/07/04-09:15:12.437 ComClient LcsGetClientIdRunnable() exception=0 2011/07/05-10:39:04.390 ComClient LcsGetClientIdRunnable() exception=0 2011/07/11-00:58:17.781 ComClient LcsGetClientIdRunnable() exception=0 2011/07/12-13:43:27.843 ComClient LcsGetClientIdRunnable() exception=0 2011/07/12-21:40:40.859 ComClient LcsGetClientIdRunnable() exception=0 2011/07/13-17:20:33.968 ComClient LcsGetClientIdRunnable() exception=0 2011/07/14-14:35:19.984 ComClient LcsGetClientIdRunnable() exception=0 2011/07/16-15:59:48.843 ComClient LcsGetClientIdRunnable() exception=0 2011/07/18-21:14:44.093 ComClient LcsGetClientIdRunnable() exception=0 2011/07/19-19:23:36.656 ComClient LcsGetClientIdRunnable() exception=0 2011/07/20-13:34:30.625 ComClient LcsGetClientIdRunnable() exception=0 2011/07/22-15:35:18.765 ComClient LcsGetClientIdRunnable() exception=0 2011/07/25-15:34:31.000 ComClient LcsGetClientIdRunnable() exception=0 2011/08/03-22:35:12.562 ComClient LcsGetClientIdRunnable() exception=0 2011/08/09-13:27:40.390 ComClient LcsGetClientIdRunnable() exception=0 2011/08/09-15:21:09.234 ComClient LcsGetClientIdRunnable() exception=0 2011/08/11-21:04:44.375 ComClient LcsGetClientIdRunnable() exception=0 2011/08/14-17:44:32.390 ComClient LcsGetClientIdRunnable() exception=0 2011/08/16-16:20:51.359 ComClient LcsGetClientIdRunnable() exception=0 2011/08/17-22:52:52.598 ComClient LcsGetClientIdRunnable() exception=0 2011/08/18-00:38:05.562 ComClient LcsGetClientIdRunnable() exception=0 2011/08/18-01:01:10.156 ComClient LcsGetClientIdRunnable() exception=0 2011/08/21-09:15:13.937 ComClient LcsGetClientIdRunnable() exception=0 2011/08/21-20:46:22.962 ComClient LcsGetClientIdRunnable() exception=0 2011/08/27-12:04:15.218 ComClient LcsGetClientIdRunnable() exception=0 2011/09/06-02:58:38.498 ComClient LcsGetClientIdRunnable() exception=0 2011/09/07-00:41:59.671 ComClient LcsGetClientIdRunnable() exception=0 2011/09/07-14:45:50.562 ComClient LcsGetClientIdRunnable() exception=0 2011/09/08-17:11:00.859 ComClient LcsGetClientIdRunnable() exception=0 2011/09/11-23:22:47.208 ComClient LcsGetClientIdRunnable() exception=0 2011/11/05-17:09:45.342 ComClient LcsGetClientIdRunnable() exception=0 2011/12/04-02:38:05.272 ComClient LcsGetClientIdRunnable() exception=0 2011/12/04-15:09:10.625 ComClient LcsGetClientIdRunnable() exception=0 2011/12/12-04:19:40.855 ComClient LcsGetClientIdRunnable() exception=0 2011/12/12-13:40:08.390 ComClient LcsGetClientIdRunnable() exception=0 2011/12/12-13:56:14.765 ComClient LcsGetClientIdRunnable() exception=0 2011/12/13-01:23:32.609 ComClient LcsGetClientIdRunnable() exception=0 2011/12/16-17:25:07.734 ComClient LcsGetClientIdRunnable() exception=0 2011/12/17-23:37:48.718 ComClient LcsGetClientIdRunnable() exception=0 2011/12/19-17:24:42.593 ComClient LcsGetClientIdRunnable() exception=0 2011/12/20-18:26:14.546 ComClient LcsGetClientIdRunnable() exception=0 2011/12/20-22:10:04.140 ComClient LcsGetClientIdRunnable() exception=0 2011/12/22-00:58:46.948 ComClient LcsGetClientIdRunnable() exception=0 2011/12/22-21:11:08.406 ComClient LcsGetClientIdRunnable() exception=0 2011/12/25-18:21:47.156 ComClient LcsGetClientIdRunnable() exception=0 2011/12/26-03:31:12.405 ComClient LcsGetClientIdRunnable() exception=0 2011/12/27-03:21:55.125 ComClient LcsGetClientIdRunnable() exception=0 2011/12/28-01:41:36.078 ComClient LcsGetClientIdRunnable() exception=0 2011/12/28-12:01:05.156 ComClient LcsGetClientIdRunnable() exception=0 2011/12/29-02:02:28.093 ComClient LcsGetClientIdRunnable() exception=0 2011/12/30-00:29:30.042 ComClient LcsGetClientIdRunnable() exception=0 2011/12/30-01:45:33.500 ComClient LcsGetClientIdRunnable() exception=0 2011/12/30-15:04:41.812 ComClient LcsGetClientIdRunnable() exception=0 2011/12/31-01:16:15.845 ComClient LcsGetClientIdRunnable() exception=0 2012/01/02-00:58:40.593 ComClient LcsGetClientIdRunnable() exception=0 2012/01/02-16:51:16.643 ComClient LcsGetClientIdRunnable() exception=0 2012/01/03-03:43:22.782 ComClient LcsGetClientIdRunnable() exception=0 2012/01/03-05:07:10.282 ComClient LcsGetClientIdRunnable() exception=0 2012/01/04-03:10:20.781 ComClient LcsGetClientIdRunnable() exception=0 2012/01/04-03:50:10.359 ComClient LcsGetClientIdRunnable() exception=0 2012/01/06-15:48:51.359 ComClient LcsGetClientIdRunnable() exception=0 2012/01/06-16:07:36.390 ComClient LcsGetClientIdRunnable() exception=0 2012/01/09-02:52:32.784 ComClient LcsGetClientIdRunnable() exception=0 2012/01/09-17:38:31.000 ComClient LcsGetClientIdRunnable() exception=0 2012/01/14-00:22:39.252 ComClient LcsGetClientIdRunnable() exception=0 2012/01/14-14:13:54.812 ComClient LcsGetClientIdRunnable() exception=0 2012/01/21-16:26:48.739 ComClient LcsGetClientIdRunnable() exception=0 2012/03/09-15:59:20.188 ComClient LcsGetClientIdRunnable() exception=0 2012/03/09-16:40:24.718 ComClient LcsGetClientIdRunnable() exception=0 2012/03/09-18:41:00.046 ComClient LcsGetClientIdRunnable() exception=0 2012/03/09-18:52:36.489 ComClient LcsGetClientIdRunnable() exception=0 2012/03/09-19:47:13.453 ComClient LcsGetClientIdRunnable() exception=0 2012/03/10-00:23:23.187 ComClient LcsGetClientIdRunnable() exception=0 2012/03/10-08:21:13.843 ComClient LcsGetClientIdRunnable() exception=0 2012/03/10-08:31:42.703 ComClient LcsGetClientIdRunnable() exception=0 2012/03/10-10:39:05.078 ComClient LcsGetClientIdRunnable() exception=0 2012/03/10-15:00:31.187 ComClient LcsGetClientIdRunnable() exception=0 2012/03/10-15:58:45.843 ComClient LcsGetClientIdRunnable() exception=0 2012/03/11-09:56:03.171 ComClient LcsGetClientIdRunnable() exception=0 2012/03/11-12:32:11.312 ComClient LcsGetClientIdRunnable() exception=0 2012/03/11-23:26:43.812 ComClient LcsGetClientIdRunnable() exception=0 2012/03/13-11:00:05.266 ComClient LcsGetClientIdRunnable() exception=0 2012/03/13-15:25:16.718 ComClient LcsGetClientIdRunnable() exception=0 2012/03/13-15:35:40.984 ComClient LcsGetClientIdRunnable() exception=0 2012/03/15-14:30:38.681 ComClient LcsGetClientIdRunnable() exception=0 2012/03/15-15:01:40.093 ComClient LcsGetClientIdRunnable() exception=0 2012/03/16-18:17:08.771 ComClient LcsGetClientIdRunnable() exception=0 2012/03/17-14:26:10.984 ComClient LcsGetClientIdRunnable() exception=0 2012/03/17-20:51:42.187 ComClient LcsGetClientIdRunnable() exception=0 2012/03/17-21:13:52.125 ComClient LcsGetClientIdRunnable() exception=0 2012/03/18-09:04:16.171 ComClient LcsGetClientIdRunnable() exception=0 2012/03/19-13:24:10.859 ComClient LcsGetClientIdRunnable() exception=0 2012/03/20-08:52:50.484 ComClient LcsGetClientIdRunnable() exception=0 2012/03/21-10:18:53.828 ComClient LcsGetClientIdRunnable() exception=0 2012/03/21-14:44:34.156 ComClient LcsGetClientIdRunnable() exception=0 2012/03/22-00:42:32.199 ComClient LcsGetClientIdRunnable() exception=0 2012/03/22-08:20:43.546 ComClient LcsGetClientIdRunnable() exception=0 2012/03/22-19:27:21.093 ComClient LcsGetClientIdRunnable() exception=0 2012/03/23-13:52:28.424 ComClient LcsGetClientIdRunnable() exception=0 2012/03/28-10:31:11.181 ComClient LcsGetClientIdRunnable() exception=0 2012/03/30-12:22:36.818 ComClient LcsGetClientIdRunnable() exception=0 2012/04/02-19:34:38.161 ComClient LcsGetClientIdRunnable() exception=0 2012/04/03-23:03:00.755 ComClient LcsGetClientIdRunnable() exception=0 2012/04/04-12:57:44.921 ComClient LcsGetClientIdRunnable() exception=0 2012/04/08-22:58:17.734 ComClient LcsGetClientIdRunnable() exception=0 2012/04/10-19:03:29.921 ComClient LcsGetClientIdRunnable() exception=0 2012/05/17-22:46:38.333 ComClient LcsGetClientIdRunnable() exception=0 2012/05/17-23:04:49.984 ComClient LcsGetClientIdRunnable() exception=0 2012/05/18-22:56:33.218 ComClient LcsGetClientIdRunnable() exception=0 2012/05/19-19:47:59.625 ComClient LcsGetClientIdRunnable() exception=0 2012/05/19-22:18:45.031 ComClient LcsGetClientIdRunnable() exception=0 2012/05/20-13:27:47.859 ComClient LcsGetClientIdRunnable() exception=0 2012/05/20-14:42:17.125 ComClient LcsGetClientIdRunnable() exception=0 2012/05/20-15:41:14.234 ComClient LcsGetClientIdRunnable() exception=0 2012/05/20-16:01:27.140 ComClient LcsGetClientIdRunnable() exception=0 2012/05/20-18:26:25.078 ComClient LcsGetClientIdRunnable() exception=0 2012/05/20-18:45:10.312 ComClient LcsGetClientIdRunnable() exception=0 2012/05/20-19:08:00.781 ComClient LcsGetClientIdRunnable() exception=0 2012/05/20-21:37:25.953 ComClient LcsGetClientIdRunnable() exception=0 2012/05/21-01:13:07.468 ComClient LcsGetClientIdRunnable() exception=0 2012/05/21-23:37:56.421 ComClient LcsGetClientIdRunnable() exception=0 2012/05/22-01:22:56.360 ComClient LcsGetClientIdRunnable() exception=0 2012/05/22-02:25:13.296 ComClient LcsGetClientIdRunnable() exception=0 2012/05/22-02:51:15.921 ComClient LcsGetClientIdRunnable() exception=0 2012/05/22-23:31:55.750 ComClient LcsGetClientIdRunnable() exception=0 2012/05/23-22:48:06.828 ComClient LcsGetClientIdRunnable() exception=0 2012/05/23-23:36:18.484 ComClient LcsGetClientIdRunnable() exception=0 2012/05/23-23:52:23.531 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-01:20:55.859 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-02:24:24.281 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-03:27:09.890 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:27:54.390 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:28:38.718 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:29:23.031 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:30:07.453 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:30:51.750 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:31:36.171 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:32:20.578 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:33:04.796 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:33:49.078 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:34:33.390 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:35:17.718 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:36:01.906 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:36:46.109 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:37:30.312 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:38:14.609 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:38:59.046 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:39:43.578 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:40:27.875 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:41:12.218 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:41:56.406 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:42:40.593 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:43:24.921 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:44:09.015 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:44:53.203 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:45:37.312 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:46:21.515 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:47:05.703 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:47:49.906 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:48:34.125 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:49:18.546 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:50:02.984 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:50:47.406 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:51:31.500 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:52:15.578 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:52:59.906 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:53:44.109 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:54:28.312 ComClient LcsGetClientIdRunnable() exception=2147944122 2012/05/24-03:59:04.609 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-04:26:15.234 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-04:51:23.562 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-05:32:23.937 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-06:55:54.812 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-09:10:09.828 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-09:26:47.812 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-14:18:49.906 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-18:48:49.234 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-19:09:54.437 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-19:35:02.468 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-19:55:54.031 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-21:10:03.609 ComClient LcsGetClientIdRunnable() exception=0 2012/05/24-22:31:23.687 ComClient LcsGetClientIdRunnable() exception=0 2012/05/25-23:18:14.203 ComClient LcsGetClientIdRunnable() exception=0 2012/05/27-01:39:00.387 ComClient LcsGetClientIdRunnable() exception=0 2012/07/09-00:41:09.593 ComClient LcsGetClientIdRunnable() exception=0 2012/07/09-01:26:09.125 ComClient LcsGetClientIdRunnable() exception=0 2012/07/09-01:42:30.468 ComClient LcsGetClientIdRunnable() exception=0 2012/07/09-01:55:04.718 ComClient LcsGetClientIdRunnable() exception=0 2012/07/09-02:32:12.906 ComClient LcsGetClientIdRunnable() exception=0 2012/07/10-03:17:18.593 ComClient LcsGetClientIdRunnable() exception=0 2012/07/10-03:28:47.500 ComClient LcsGetClientIdRunnable() exception=0 2012/07/10-11:24:14.781 ComClient LcsGetClientIdRunnable() exception=0 2012/07/10-17:05:13.718 ComClient LcsGetClientIdRunnable() exception=0 2012/07/10-17:41:12.859 ComClient LcsGetClientIdRunnable() exception=0 2012/07/10-19:45:00.437 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-01:45:59.859 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-01:55:50.921 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-03:00:13.421 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-03:22:45.968 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-03:58:41.890 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-04:50:13.265 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-04:58:07.343 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-05:09:47.609 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-16:43:30.578 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-17:06:41.421 ComClient LcsGetClientIdRunnable() exception=0 2012/07/11-17:22:21.906 ComClient LcsGetClientIdRunnable() exception=0 2012/07/12-23:26:00.109 ComClient LcsGetClientIdRunnable() exception=0 2012/07/12-23:31:31.859 ComClient LcsGetClientIdRunnable() exception=0 2012/07/13-00:45:56.437 ComClient LcsGetClientIdRunnable() exception=0 2012/07/13-11:33:25.921 ComClient LcsGetClientIdRunnable() exception=0 2012/07/13-18:49:53.656 ComClient LcsGetClientIdRunnable() exception=0 2012/07/14-11:33:47.312 ComClient LcsGetClientIdRunnable() exception=0
Hi,

Good job getting those ran.

Please delete your copy of ComboFix that is on your system and then follow these instructions…

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
4. If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.
———-
Here's the Combofix log.

Jen.


ComboFix 12-07-14.01 - Dougie 15/07/2012 1:39.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1335 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Dougie\ntuser.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_xcpip
.
.
((((((((((((((((((((((((( Files Created from 2012-06-15 to 2012-07-15 )))))))))))))))))))))))))))))))
.
.
2012-07-14 14:57 . 2012-07-15 00:05 ——– d—–w- c:\program files\Common Files\Mcafee
2012-07-14 10:31 . 2012-07-14 10:31 ——– d—–w- C:\TDSSKiller_Quarantine
2012-07-13 17:48 . 2012-07-13 17:48 ——– d—–w- c:\documents and settings\Neil\Application Data\Apple Computer
2012-07-13 17:45 . 2012-07-13 17:45 ——– d—–w- c:\documents and settings\Mary Jenny\Application Data\Apple Computer
2012-07-11 03:07 . 2012-07-15 00:31 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2012-07-11 02:00 . 2012-05-11 14:42 521728 ——w- c:\windows\system32\dllcache\jsdbgui.dll
2012-07-09 01:21 . 2012-07-09 01:21 ——– d–h–w- c:\windows\system32\GroupPolicy
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-13 13:19 . 2005-08-16 03:18 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-07-14 23:27 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2005-08-16 03:18 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2005-08-16 03:18 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 14:19 . 2007-05-30 22:39 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 14:19 . 2007-05-30 22:39 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 14:19 . 2005-08-16 03:40 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 14:19 . 2005-08-16 03:40 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 14:19 . 2005-08-16 03:40 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 14:19 . 2007-05-30 22:39 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 14:19 . 2005-08-16 03:40 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 14:19 . 2005-08-16 03:40 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 14:19 . 2005-08-16 03:18 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 14:19 . 2005-05-26 03:16 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 14:19 . 2007-05-30 22:39 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 14:19 . 2005-08-16 03:40 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 14:19 . 2005-08-16 03:40 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 14:18 . 2007-05-31 18:20 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 14:18 . 2006-12-20 00:22 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 14:18 . 2006-12-20 00:22 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:22 . 2005-08-16 03:18 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-24 01:40 . 2012-05-24 01:40 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2012-05-24 00:37 . 2012-05-24 00:37 8072272 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\BingBar\BBSvc\7.1.382.0oemBingBarSetup-Partner.EXE
2012-05-16 15:08 . 2005-08-16 03:18 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2005-08-16 03:18 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2005-08-16 03:18 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2005-08-16 03:18 385024 ——w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2005-08-16 03:18 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-03 21:59 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2005-08-16 03:37 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-05-19 18:50 . 2011-08-18 00:46 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-09-01 11:12 . 2008-08-27 13:08 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2011-04-14 13:01 . 2010-08-21 19:07 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-11_02.21.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-18 21:51 . 2011-04-18 21:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2012-07-15 00:48 . 2012-07-15 00:48 16384 c:\windows\Temp\Perflib_Perfdata_2e8.dat
+ 2012-07-15 00:48 . 2012-07-15 00:48 16384 c:\windows\Temp\Perflib_Perfdata_288.dat
- 2005-08-16 03:18 . 2012-07-11 02:06 78660 c:\windows\system32\perfc009.dat
+ 2005-08-16 03:18 . 2012-07-12 22:19 78660 c:\windows\system32\perfc009.dat
+ 2005-08-16 03:18 . 2012-05-11 14:42 67072 c:\windows\system32\mshtmled.dll
+ 2006-11-07 21:03 . 2012-05-11 14:42 55296 c:\windows\system32\msfeedsbs.dll
- 2006-11-07 21:03 . 2012-03-01 11:01 55296 c:\windows\system32\msfeedsbs.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 25600 c:\windows\system32\jsproxy.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 25600 c:\windows\system32\jsproxy.dll
+ 2009-07-10 09:01 . 2012-05-11 14:42 12800 c:\windows\system32\dllcache\xpshims.dll
- 2009-07-10 09:01 . 2012-03-01 11:01 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 67072 c:\windows\system32\dllcache\mshtmled.dll
- 2007-05-09 08:46 . 2012-03-01 11:01 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-05-09 08:46 . 2012-05-11 14:42 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2006-04-13 10:30 . 2012-05-20 15:04 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-04-13 10:30 . 2012-07-14 23:55 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-04-13 10:30 . 2012-07-14 23:55 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-04-13 10:30 . 2012-05-20 15:04 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2012-07-14 15:01 . 2012-07-14 23:55 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2006-04-13 10:30 . 2012-05-20 15:04 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2005-08-16 03:38 . 2012-01-28 18:26 12288 c:\windows\Microsoft.NET\Framework\v1.0.3705\zh-CHT\System.Drawing.Resources.dll
+ 2005-08-16 03:38 . 2012-04-26 07:28 12288 c:\windows\Microsoft.NET\Framework\v1.0.3705\zh-CHT\System.Drawing.Resources.dll
+ 2005-08-16 03:38 . 2012-04-26 07:21 12288 c:\windows\Microsoft.NET\Framework\v1.0.3705\zh-CHS\System.Drawing.Resources.dll
- 2005-08-16 03:38 . 2012-01-28 18:24 12288 c:\windows\Microsoft.NET\Framework\v1.0.3705\zh-CHS\System.Drawing.Resources.dll
+ 2005-08-16 03:38 . 2012-04-26 07:27 13824 c:\windows\Microsoft.NET\Framework\v1.0.3705\ko\System.Drawing.Resources.dll
- 2005-08-16 03:38 . 2012-01-28 18:25 13824 c:\windows\Microsoft.NET\Framework\v1.0.3705\ko\System.Drawing.Resources.dll
- 2005-08-16 03:38 . 2012-01-28 18:27 24576 c:\windows\Microsoft.NET\Framework\v1.0.3705\JA\System.Drawing.Resources.dll
+ 2005-08-16 03:38 . 2012-04-26 07:29 24576 c:\windows\Microsoft.NET\Framework\v1.0.3705\JA\System.Drawing.Resources.dll
+ 2005-08-16 03:38 . 2012-04-26 07:29 13312 c:\windows\Microsoft.NET\Framework\v1.0.3705\it\System.Drawing.Resources.dll
- 2005-08-16 03:38 . 2012-01-28 18:26 13312 c:\windows\Microsoft.NET\Framework\v1.0.3705\it\System.Drawing.Resources.dll
- 2005-08-16 03:38 . 2012-01-28 18:28 13824 c:\windows\Microsoft.NET\Framework\v1.0.3705\fr\System.Drawing.Resources.dll
+ 2005-08-16 03:38 . 2012-04-26 07:30 13824 c:\windows\Microsoft.NET\Framework\v1.0.3705\fr\System.Drawing.Resources.dll
+ 2005-08-16 03:38 . 2012-04-26 07:21 13312 c:\windows\Microsoft.NET\Framework\v1.0.3705\es\System.Drawing.Resources.dll
- 2005-08-16 03:38 . 2012-01-28 18:22 13312 c:\windows\Microsoft.NET\Framework\v1.0.3705\es\System.Drawing.Resources.dll
+ 2005-08-16 03:38 . 2012-04-26 07:27 13312 c:\windows\Microsoft.NET\Framework\v1.0.3705\DE\System.Drawing.Resources.dll
- 2005-08-16 03:38 . 2012-01-28 18:26 13312 c:\windows\Microsoft.NET\Framework\v1.0.3705\DE\System.Drawing.Resources.dll
+ 2012-07-14 14:49 . 2012-07-14 14:49 28672 c:\windows\Installer\20128.msi
- 2010-06-14 08:36 . 2012-05-19 19:14 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2010-06-14 08:36 . 2012-07-14 12:18 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2010-06-14 08:36 . 2012-07-14 12:18 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2010-06-14 08:36 . 2012-05-19 19:14 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2010-06-14 08:36 . 2012-07-14 12:18 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2010-06-14 08:36 . 2012-05-19 19:14 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2012-07-12 22:05 . 2012-03-01 11:01 12800 c:\windows\ie8updates\KB2699988-IE8\xpshims.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 66560 c:\windows\ie8updates\KB2699988-IE8\mshtmled.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 55296 c:\windows\ie8updates\KB2699988-IE8\msfeedsbs.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 43520 c:\windows\ie8updates\KB2699988-IE8\licmgr10.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 25600 c:\windows\ie8updates\KB2699988-IE8\jsproxy.dll
+ 2012-07-12 22:04 . 2012-07-12 22:04 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_0a03b720\System.Drawing.Design.dll
+ 2012-07-12 22:07 . 2012-07-12 22:07 90112 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a_2be400a0\System.Drawing.Design.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\3b34fc2c8c94ffe21f75168980b69dfe\System.Web.DynamicData.Design.ni.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
- 2012-07-11 02:04 . 2012-07-11 02:04 77824 c:\windows\assembly\GAC_MSIL\System.Web.RegularExpressions\2.0.0.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2012-07-11 02:04 . 2012-07-11 02:04 81920 c:\windows\assembly\GAC_MSIL\System.Drawing.Design\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 81920 c:\windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 32768 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 12800 c:\windows\assembly\GAC_MSIL\Microsoft.Vsa.Vb.CodeDOMProcessor\8.0.0.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 28672 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Vsa\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 77824 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Utilities\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Utilities.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 36864 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Framework\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Framework.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 77824 c:\windows\assembly\GAC_MSIL\IEHost\2.0.0.0__b03f5f7f11d50a3a\IEHost.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 13312 c:\windows\assembly\GAC_MSIL\cscompmgd\8.0.0.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
- 2012-05-20 12:33 . 2012-07-11 02:05 10752 c:\windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 72192 c:\windows\assembly\GAC_32\ISymWrapper\2.0.0.0__b03f5f7f11d50a3a\ISymWrapper.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 69120 c:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2012-07-12 22:06 . 2012-07-12 22:06 12288 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_zh-CHT_b03f5f7f11d50a3a\System.Drawing.Resources.dll
- 2012-05-20 12:35 . 2012-05-20 12:35 12288 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_zh-CHT_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2012-07-12 22:07 . 2012-07-12 22:07 12288 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_zh-CHS_b03f5f7f11d50a3a\System.Drawing.Resources.dll
- 2012-05-20 12:35 . 2012-05-20 12:35 12288 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_zh-CHS_b03f5f7f11d50a3a\System.Drawing.Resources.dll
- 2012-05-20 12:35 . 2012-05-20 12:35 13824 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_ko_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2012-07-12 22:06 . 2012-07-12 22:06 13824 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_ko_b03f5f7f11d50a3a\System.Drawing.Resources.dll
- 2012-05-20 12:35 . 2012-05-20 12:35 24576 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_ja_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2012-07-12 22:06 . 2012-07-12 22:06 24576 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_ja_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2012-07-12 22:06 . 2012-07-12 22:06 13312 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_it_b03f5f7f11d50a3a\System.Drawing.Resources.dll
- 2012-05-20 12:35 . 2012-05-20 12:35 13312 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_it_b03f5f7f11d50a3a\System.Drawing.Resources.dll
- 2012-05-20 12:35 . 2012-05-20 12:35 13824 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_fr_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2012-07-12 22:06 . 2012-07-12 22:06 13824 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_fr_b03f5f7f11d50a3a\System.Drawing.Resources.dll
- 2012-05-20 12:35 . 2012-05-20 12:35 13312 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_es_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2012-07-12 22:06 . 2012-07-12 22:06 13312 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_es_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2012-07-12 22:06 . 2012-07-12 22:07 13312 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_de_b03f5f7f11d50a3a\System.Drawing.Resources.dll
- 2012-05-20 12:35 . 2012-05-20 12:35 13312 c:\windows\assembly\GAC\System.Drawing.resources\1.0.3300.0_de_b03f5f7f11d50a3a\System.Drawing.Resources.dll
+ 2012-05-20 12:35 . 2012-01-28 18:26 13312 c:\windows\$NtUninstallKB2656378$\system.drawing.resources.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 8192 c:\windows\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e\IEExecRemote.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 7168 c:\windows\assembly\GAC_MSIL\Microsoft_VsaVb\8.0.0.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 5632 c:\windows\assembly\GAC_MSIL\Microsoft.VisualC\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualC.Dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 6656 c:\windows\assembly\GAC_MSIL\IIEHost\2.0.0.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 8192 c:\windows\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 113664 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.Wrapper.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 258048 c:\windows\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790\System.EnterpriseServices.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 105984 c:\windows\system32\url.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 105984 c:\windows\system32\url.dll
+ 2005-08-16 03:18 . 2012-07-12 22:19 458368 c:\windows\system32\perfh009.dat
- 2005-08-16 03:18 . 2012-07-11 02:06 458368 c:\windows\system32\perfh009.dat
- 2005-08-16 03:18 . 2012-03-01 11:01 206848 c:\windows\system32\occache.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 206848 c:\windows\system32\occache.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 611840 c:\windows\system32\mstime.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 611840 c:\windows\system32\mstime.dll
+ 2006-11-07 21:03 . 2012-05-11 14:42 629760 c:\windows\system32\msfeeds.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 184320 c:\windows\system32\iepeers.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 184320 c:\windows\system32\iepeers.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 387584 c:\windows\system32\iedkcs32.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 387584 c:\windows\system32\iedkcs32.dll
+ 2005-08-16 03:18 . 2012-05-11 11:38 174080 c:\windows\system32\ie4uinit.exe
- 2005-08-16 03:18 . 2012-02-29 12:17 174080 c:\windows\system32\ie4uinit.exe
+ 2005-08-16 03:27 . 2012-07-14 12:20 357752 c:\windows\system32\FNTCACHE.DAT
+ 2005-08-16 03:18 . 2012-05-16 15:08 916992 c:\windows\system32\dllcache\wininet.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 916992 c:\windows\system32\dllcache\wininet.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 105984 c:\windows\system32\dllcache\url.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 105984 c:\windows\system32\dllcache\url.dll
+ 2005-08-16 03:18 . 2012-06-04 04:32 152576 c:\windows\system32\dllcache\schannel.dll
+ 2005-08-16 03:37 . 2012-05-02 13:46 139656 c:\windows\system32\dllcache\rdpwd.sys
+ 2005-08-16 03:18 . 2012-05-11 14:42 206848 c:\windows\system32\dllcache\occache.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 206848 c:\windows\system32\dllcache\occache.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 611840 c:\windows\system32\dllcache\mstime.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 611840 c:\windows\system32\dllcache\mstime.dll
+ 2007-05-09 08:46 . 2012-05-11 14:42 629760 c:\windows\system32\dllcache\msfeeds.dll
+ 2005-08-16 03:40 . 2012-05-28 18:16 536576 c:\windows\system32\dllcache\msado15.dll
- 2005-08-16 03:40 . 2010-11-09 14:52 536576 c:\windows\system32\dllcache\msado15.dll
- 2009-07-10 09:01 . 2012-03-01 11:01 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2009-07-10 09:01 . 2012-05-11 14:42 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 184320 c:\windows\system32\dllcache\iepeers.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2010-06-10 07:24 . 2012-05-11 14:42 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2010-06-10 07:24 . 2012-03-01 11:01 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2005-08-16 03:18 . 2012-02-29 12:17 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2005-08-16 03:18 . 2012-05-11 11:38 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2005-08-16 03:18 . 2011-09-28 07:06 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2005-08-16 03:18 . 2012-05-31 13:22 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2012-04-21 06:15 . 2012-04-21 06:15 630784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
- 2012-01-31 02:38 . 2012-01-31 02:38 630784 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Drawing.dll
- 2012-01-27 16:35 . 2012-01-27 16:35 471040 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2012-04-25 16:45 . 2012-04-25 16:45 471040 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2005-08-16 03:38 . 2012-04-26 07:27 462848 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Drawing.dll
- 2005-08-16 03:38 . 2012-01-28 18:26 462848 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Drawing.dll
+ 2012-04-21 20:55 . 2012-04-21 20:55 980480 c:\windows\Installer\ed577.msp
+ 2012-07-12 22:17 . 2012-07-12 22:17 223744 c:\windows\Installer\ed571.msi
+ 2010-06-14 08:36 . 2012-07-14 12:18 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2010-06-14 08:36 . 2012-05-19 19:14 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2010-06-14 08:36 . 2012-05-19 19:14 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2010-06-14 08:36 . 2012-07-14 12:18 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2010-06-14 08:36 . 2012-05-19 19:14 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2010-06-14 08:36 . 2012-07-14 12:18 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2010-06-14 08:36 . 2012-07-14 12:18 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2010-06-14 08:36 . 2012-05-19 19:14 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2012-07-12 22:05 . 2012-03-01 11:01 916992 c:\windows\ie8updates\KB2699988-IE8\wininet.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 105984 c:\windows\ie8updates\KB2699988-IE8\url.dll
+ 2012-07-12 22:05 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2699988-IE8\spuninst\updspapi.dll
+ 2012-07-12 22:05 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2699988-IE8\spuninst\spuninst.exe
+ 2012-07-12 22:05 . 2012-03-01 11:01 206848 c:\windows\ie8updates\KB2699988-IE8\occache.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 611840 c:\windows\ie8updates\KB2699988-IE8\mstime.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 602112 c:\windows\ie8updates\KB2699988-IE8\msfeeds.dll
+ 2012-07-12 22:05 . 2009-03-08 03:35 521216 c:\windows\ie8updates\KB2699988-IE8\jsdbgui.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 247808 c:\windows\ie8updates\KB2699988-IE8\ieproxy.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 184320 c:\windows\ie8updates\KB2699988-IE8\iepeers.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 743424 c:\windows\ie8updates\KB2699988-IE8\iedvtool.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 387584 c:\windows\ie8updates\KB2699988-IE8\iedkcs32.dll
+ 2012-07-12 22:05 . 2012-02-29 12:17 174080 c:\windows\ie8updates\KB2699988-IE8\ie4uinit.exe
+ 2012-07-12 22:04 . 2012-07-12 22:04 843776 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_12603eb8\System.Drawing.dll
+ 2012-07-12 22:04 . 2012-07-12 22:04 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_8da942b5\System.Drawing.Design.dll
+ 2012-07-12 22:07 . 2012-07-12 22:07 851968 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a_78bea5cc\System.Drawing.dll
+ 2012-07-12 22:27 . 2012-07-12 22:27 240128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\86e11a59f02b2dda27ec2e7cba351744\WindowsFormsIntegration.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\698c2093d7ac57af935b399d1c0b1790\System.Web.Routing.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\75248baf640115daeb0e580f1c5ff98b\System.Web.Extensions.Design.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\40c3b61ac38613e2b4b0f196e86185eb\System.Web.Entity.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\39cc9a830f7f08fd9f397be452fd78b0\System.Web.Entity.Design.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\88b1fd4792e7b698b788594d8e5e3c09\System.Web.DynamicData.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\6333d22a2ea347432d46c40d93194c68\System.Web.Abstractions.ni.dll
+ 2012-07-12 22:44 . 2012-07-12 22:44 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b84bb74d7724e147a642a1d5358feb7\System.ServiceProcess.ni.dll
+ 2012-07-12 22:26 . 2012-07-12 22:26 208384 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\96a3fc1f74a00b618b70bd1701600408\System.Drawing.Design.ni.dll
+ 2012-07-12 22:44 . 2012-07-12 22:44 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\c0045c1c7c29c7e7cc7bd60001b729a7\AspNetMMCExt.ni.dll
- 2012-07-11 02:04 . 2012-07-11 02:04 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 839680 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
- 2012-07-11 02:04 . 2012-07-11 02:04 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 303104 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 372736 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2012-05-20 12:33 . 2012-07-11 02:05 630784 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 401408 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
- 2012-07-11 02:04 . 2012-07-11 02:04 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 970752 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 745472 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
- 2012-05-20 12:33 . 2012-07-11 02:05 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 425984 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 659456 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 749568 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 655360 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 348160 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2012-07-11 02:04 . 2012-07-11 02:04 507904 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 261632 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 113664 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 486400 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
- 2012-05-20 12:29 . 2012-05-20 12:29 471040 c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-07-12 22:04 . 2012-07-12 22:04 471040 c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-07-12 22:06 . 2012-07-12 22:06 462848 c:\windows\assembly\GAC\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.dll
- 2012-05-20 12:35 . 2012-05-20 12:35 462848 c:\windows\assembly\GAC\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2012-05-20 12:35 . 2012-01-28 18:26 462848 c:\windows\$NtUninstallKB2656378$\system.drawing.dll
- 2012-05-20 12:35 . 2004-07-19 17:54 462848 c:\windows\$NtUninstallKB2656378$\system.drawing.dll
- 2012-05-20 12:35 . 2009-04-13 11:42 371424 c:\windows\$NtUninstallKB2656378$\spuninst\updspapi.dll
+ 2012-05-20 12:35 . 2009-04-13 12:42 371424 c:\windows\$NtUninstallKB2656378$\spuninst\updspapi.dll
+ 2012-05-20 12:35 . 2009-04-13 12:42 213216 c:\windows\$NtUninstallKB2656378$\spuninst\spuninst.exe
- 2012-05-20 12:35 . 2009-04-13 11:42 213216 c:\windows\$NtUninstallKB2656378$\spuninst\spuninst.exe
+ 2011-04-18 21:51 . 2011-04-18 21:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-18 21:51 . 2011-04-18 21:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 1212416 c:\windows\system32\urlmon.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 1212416 c:\windows\system32\urlmon.dll
+ 2005-08-16 03:18 . 2012-06-08 14:26 8462848 c:\windows\system32\shell32.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 6007808 c:\windows\system32\mshtml.dll
+ 2006-10-17 11:57 . 2012-05-11 14:42 2000384 c:\windows\system32\iertutil.dll
- 2006-10-17 11:57 . 2012-03-01 11:01 2000384 c:\windows\system32\iertutil.dll
+ 2005-08-16 03:18 . 2012-06-13 13:19 1866112 c:\windows\system32\dllcache\win32k.sys
+ 2005-08-16 03:18 . 2012-05-11 14:42 1212416 c:\windows\system32\dllcache\urlmon.dll
- 2005-08-16 03:18 . 2012-03-01 11:01 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2005-08-16 03:18 . 2012-06-08 14:26 8462848 c:\windows\system32\dllcache\shell32.dll
+ 2008-10-14 20:22 . 2012-05-04 13:12 2192640 c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-10-14 20:22 . 2012-04-11 13:10 2192640 c:\windows\system32\dllcache\ntoskrnl.exe
- 2004-08-03 21:59 . 2012-04-11 12:35 2026496 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2004-08-03 21:59 . 2012-05-04 12:32 2026496 c:\windows\system32\dllcache\ntkrpamp.exe
- 2008-10-14 20:22 . 2012-04-11 12:35 2069120 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-10-14 20:22 . 2012-05-04 12:32 2069120 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2005-08-16 03:18 . 2012-04-11 13:14 2148352 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2005-08-16 03:18 . 2012-05-04 13:16 2148352 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-07-14 23:27 . 2012-06-05 15:50 1372672 c:\windows\system32\dllcache\msxml6.dll
- 2008-07-14 23:27 . 2009-07-31 10:05 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2005-08-16 03:18 . 2012-06-05 15:50 1172480 c:\windows\system32\dllcache\msxml3.dll
- 2005-08-16 03:18 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2005-08-16 03:18 . 2012-05-11 14:42 6007808 c:\windows\system32\dllcache\mshtml.dll
- 2007-05-09 08:46 . 2012-03-01 11:01 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2007-05-09 08:46 . 2012-05-11 14:42 2000384 c:\windows\system32\dllcache\iertutil.dll
- 2012-01-31 03:46 . 2012-01-31 03:46 6385664 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2656370\M2656370Uninstall.msp
+ 2012-04-26 01:32 . 2012-04-26 01:32 6385664 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2656370\M2656370Uninstall.msp
+ 2012-06-19 11:54 . 2012-06-19 11:54 2239488 c:\windows\Installer\61afdf.msp
+ 2012-04-25 18:32 . 2012-04-25 18:32 7069184 c:\windows\Installer\2bb2f.msp
+ 2012-04-04 21:37 . 2012-04-04 21:37 2540544 c:\windows\Installer\1a6f7c8.msp
- 2010-06-14 08:36 . 2012-05-19 19:14 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2010-06-14 08:36 . 2012-07-14 12:18 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2011-07-27 05:09 . 2011-07-27 05:09 5310848 c:\windows\Installer\$PatchCache$\Managed\00002119F20000000000000000F01FEC\12.0.6612\IPEDITOR.DLL
+ 2012-07-12 22:05 . 2012-03-01 11:01 1212416 c:\windows\ie8updates\KB2699988-IE8\urlmon.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 5978624 c:\windows\ie8updates\KB2699988-IE8\mshtml.dll
+ 2012-07-12 22:05 . 2012-03-01 11:01 2000384 c:\windows\ie8updates\KB2699988-IE8\iertutil.dll
+ 2008-10-14 20:22 . 2012-05-04 13:12 2192640 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2008-10-14 20:22 . 2012-04-11 13:10 2192640 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-10-14 20:22 . 2012-05-04 12:32 2026496 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-14 20:22 . 2012-04-11 12:35 2026496 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-14 20:22 . 2012-04-11 12:35 2069120 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-14 20:22 . 2012-05-04 12:32 2069120 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-14 20:22 . 2012-05-04 13:16 2148352 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2008-10-14 20:22 . 2012-04-11 13:14 2148352 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2012-07-12 22:04 . 2012-07-12 22:04 3035136 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_943aa65f\System.Windows.Forms.dll
+ 2012-07-12 22:04 . 2012-07-12 22:04 7917568 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_91627a08\System.Windows.Forms.dll
+ 2012-07-12 22:05 . 2012-07-12 22:05 2252800 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_4ed00a94\System.Drawing.dll
+ 2012-07-12 22:04 . 2012-07-12 22:04 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_c16108df\System.Design.dll
+ 2012-07-12 22:05 . 2012-07-12 22:05 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_4442b567\System.Design.dll
+ 2012-07-12 22:07 . 2012-07-12 22:07 2953216 c:\windows\assembly\NativeImages1_v1.0.3705\System.Windows.Forms\1.0.3300.0__b77a5c561934e089_d9074abe\System.Windows.Forms.dll
+ 2012-07-12 22:07 . 2012-07-12 22:07 1454080 c:\windows\assembly\NativeImages1_v1.0.3705\System.Design\1.0.3300.0__b03f5f7f11d50a3a_d73d4a61\System.Design.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\bd5bd406670d483b82bd51249eee59e3\System.WorkflowServices.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\1c12dfa7826b331b243b7b45daf9904d\System.Workflow.ComponentModel.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\514bf0e69e2c9fc8509cd23236057356\System.Workflow.Activities.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\77f8cde07b131839f1841be702837e8e\System.Web.Mobile.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 2405888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\242b168aaca18197eca371ec269e23ac\System.Web.Extensions.ni.dll
+ 2012-07-12 22:26 . 2012-07-12 22:26 1035776 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\d380f1813e27c2a086e62f0218669d67\System.Printing.ni.dll
+ 2012-07-12 22:26 . 2012-07-12 22:26 1592320 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\d86f2038209a4cf0d0f5b30f6375c9b2\System.Drawing.ni.dll
+ 2012-07-12 22:44 . 2012-07-12 22:44 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\7a53d68ad544f8e9edfdbd5a90a48fd3\System.Deployment.ni.dll
+ 2012-07-12 22:25 . 2012-07-12 22:25 2146304 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\443dd7f0b84c3de54b1a72be655e307c\ReachFramework.ni.dll
+ 2012-07-12 22:25 . 2012-07-12 22:25 1657856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\48ddcafff1a5603fb3289e90330275c0\PresentationUI.ni.dll
+ 2012-07-12 22:44 . 2012-07-12 22:44 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\359fd69eb60e9844ffd497e92345178c\Microsoft.VisualBasic.ni.dll
+ 2012-07-12 22:44 . 2012-07-12 22:44 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\4e463dcf2a03c71913a61b44c32e2389\Microsoft.Build.Tasks.ni.dll
+ 2012-07-12 22:44 . 2012-07-12 22:44 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\395b4a85c7941ac4dd9d1c6f5eb444c7\Microsoft.Build.Tasks.v3.5.ni.dll
- 2012-05-20 12:34 . 2012-07-11 02:05 3186688 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 3186688 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
- 2012-05-20 12:33 . 2012-07-11 02:05 2048000 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
- 2012-05-20 12:33 . 2012-07-11 02:04 5025792 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
- 2012-07-11 02:04 . 2012-07-11 02:04 5062656 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
- 2012-07-11 02:04 . 2012-07-11 02:04 5246976 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2012-07-11 02:05 . 2012-07-11 02:05 2933248 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
- 2012-03-10 01:45 . 2012-07-11 02:05 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2012-07-12 22:19 . 2012-07-12 22:19 4550656 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2006-04-20 12:14 . 2012-07-14 12:06 57442464 c:\windows\system32\MRT.exe
+ 2006-11-07 21:03 . 2012-05-11 19:12 11111424 c:\windows\system32\ieframe.dll
+ 2007-05-09 08:46 . 2012-05-11 19:12 11111424 c:\windows\system32\dllcache\ieframe.dll
+ 2012-07-12 22:05 . 2012-03-02 05:01 11082752 c:\windows\ie8updates\KB2699988-IE8\ieframe.dll
+ 2012-07-12 22:26 . 2012-07-12 22:26 12433920 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\01abbadafaf265d9f4ac9bbb247acb98\System.Windows.Forms.ni.dll
+ 2012-07-12 22:45 . 2012-07-12 22:45 11817472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\dbc413807cb7360b3e26ef3ca1d54f9a\System.Web.ni.dll
+ 2012-07-12 22:26 . 2012-07-12 22:26 10682368 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\f73a8455f384e90f6925309336fece24\System.Design.ni.dll
+ 2012-07-12 22:25 . 2012-07-12 22:25 14329856 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e4ecfaaf5417aceecb7fa8abddf06113\PresentationFramework.ni.dll
+ 2012-07-12 22:20 . 2012-07-12 22:20 12218368 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\f33e2a4d9b385234406fa2d662f78875\PresentationCore.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-14 7323648]
"CTHelper"="CTHELPER.EXE" [2005-11-08 16384]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-03-02 18944]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-11-09 497240]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-09-01 30192]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-12-18 296056]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-13 73728]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Dougie\Start Menu\Programs\Startup\
BBC iPlayer Desktop.lnk - c:\program files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe [2011-6-26 142848]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
AOL 9.0 Tray Icon.lnk - c:\program files\AOL 9.0\aoltray.exe [2006-4-6 156784]
Audible Download Manager.lnk - c:\program files\Audible\Bin\AudibleDownloadHelper.exe [2009-4-29 1787224]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Huawei technologies\\Huawei UMTS Data Card\\3 USB Modem.exe"=
"c:\\Program Files\\Intel\\PROSetWired\\NCS\\PROSet\\PROSet.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [31/01/2012 04:46 31952]
R1 AvgLdx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [22/02/2012 05:25 235216]
R1 AvgTdiX;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [19/03/2012 05:17 301248]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [24/05/2012 02:39 285392]
R3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.382.0\SeaPort.EXE [16/04/2012 17:49 240208]
S0 pfdewi;pfdewi;c:\windows\system32\drivers\cnrn.sys –> c:\windows\system32\drivers\cnrn.sys [?]
S2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.382.0\BBSvc.EXE [16/04/2012 17:49 193616]
S2 gupdate1cac295ec48ec54;Google Update Service (gupdate1cac295ec48ec54);c:\program files\Google\Update\GoogleUpdate.exe [13/03/2010 11:14 133104]
S3 1syqo.sys;1syqo.sys;\??\c:\windows\system32\drivers\1syqo.sys –> c:\windows\system32\drivers\1syqo.sys [?]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [07/11/2010 18:52 112640]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [21/04/2006 19:47 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [13/03/2010 11:14 133104]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [19/05/2012 19:51 129976]
S3 xpsec;IPSEC driver;c:\windows\system32\drivers\xpsec.sys –> c:\windows\system32\drivers\xpsec.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 11:34]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 10:13]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 10:13]
.
2012-07-15 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1038292835-2904995092-2848636223-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-07-15 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1038292835-2904995092-2848636223-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-05-21 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1038292835-2904995092-2848636223-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-05-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1038292835-2904995092-2848636223-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-07-15 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]
.
2012-05-24 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Dougie\Application Data\Mozilla\Firefox\Profiles\pmio7n0d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.type - 4
FF - user.js: extensions.funmoods_i.hmpg - true
FF - user.js: extensions.funmoods_i.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=bf4
FF - user.js: extensions.funmoods_i.dfltSrch - true
FF - user.js: extensions.funmoods_i.srchPrvdr - Search
FF - user.js: extensions.funmoods_i.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods_i.newTabUrl - hxxp://start.funmoods.com/?f=2&a=bf4
FF - user.js: extensions.funmoods_i.tlbrSrchUrl - hxxp://start.funmoods.com/results.php?f=3&a=bf4&q=
FF - user.js: extensions.funmoods_i.id - e0387ce20000000000000014a589c33a
FF - user.js: extensions.funmoods_i.instlDay - 15440
FF - user.js: extensions.funmoods_i.vrsn - [removed]
FF - user.js: extensions.funmoods_i.vrsni - [removed]
FF - user.js: extensions.funmoods_i.vrsnTs - [removed]:55
FF - user.js: extensions.funmoods_i.prtnrId - funmoods
FF - user.js: extensions.funmoods_i.prdct - funmoods
FF - user.js: extensions.funmoods_i.aflt - bf4
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods_i.tlbrId - base
FF - user.js: extensions.funmoods_i.instlRef -
FF - user.js: extensions.funmoods_i.dfltLng -
FF - user.js: extensions.funmoods_i.excTlbr - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-15 09:41
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,RunDLLEntry???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\irtqbvfwosecigi]
"imagepath"="\??\c:\windows\TEMP\58.tmp"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(6036)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\SYSTEM32\CTXFISPI.EXE
c:\windows\eHome\ehmsas.exe
c:\windows\system32\dlcccoms.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2012-07-15 09:47:04 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-15 08:47
ComboFix2.txt 2012-07-13 10:47
ComboFix3.txt 2012-07-11 02:27
.
Pre-Run: 83,866,865,664 bytes free
Post-Run: 84,135,116,800 bytes free
.
- - End Of File - - CA5BF35EF0A0D334F9C2D440FDC53C02
Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    File::
    c:\windows\system32\drivers\cnrn.sys
    c:\windows\system32\drivers\1syqo.sys
    c:\windows\Tasks\RegCure.job
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\Dougie\Application Data\Mozilla\Firefox\Profiles\pmio7n0d.default\
    FF - prefs.js: network.proxy.type - 4
    FF - user.js: extensions.funmoods_i.hmpg - true
    FF - user.js: extensions.funmoods_i.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=bf4
    FF - user.js: extensions.funmoods_i.dfltSrch - true
    FF - user.js: extensions.funmoods_i.srchPrvdr - Search
    FF - user.js: extensions.funmoods_i.dnsErr - true
    FF - user.js: extensions.funmoods_i.newTab - true
    FF - user.js: extensions.funmoods_i.newTabUrl - hxxp://start.funmoods.com/?f=2&a=bf4
    FF - user.js: extensions.funmoods_i.tlbrSrchUrl - hxxp://start.funmoods.com/results.php?f=3&a=bf4&q=
    FF - user.js: extensions.funmoods_i.id - e0387ce20000000000000014a589c33a
    FF - user.js: extensions.funmoods_i.instlDay - 15440
    FF - user.js: extensions.funmoods_i.vrsn - [removed]
    FF - user.js: extensions.funmoods_i.vrsni - [removed]
    FF - user.js: extensions.funmoods_i.vrsnTs - [removed]:55
    FF - user.js: extensions.funmoods_i.prtnrId - funmoods
    FF - user.js: extensions.funmoods_i.prdct - funmoods
    FF - user.js: extensions.funmoods_i.aflt - bf4
    FF - user.js: extensions.funmoods_i.smplGrp - none
    FF - user.js: extensions.funmoods_i.tlbrId - base
    FF - user.js: extensions.funmoods_i.instlRef -
    FF - user.js: extensions.funmoods_i.dfltLng -
    FF - user.js: extensions.funmoods_i.excTlbr - false
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\irtqbvfwosecigi]
    
    Driver::
    pfdewi
    1syqo.sys
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Here's the ComboFix log…

ComboFix 12-07-14.01 - Dougie 15/07/2012 15:16:37.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2046.1277 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dougie\Desktop\CFScript.txt
.
FILE ::
"c:\windows\system32\drivers\1syqo.sys"
"c:\windows\system32\drivers\cnrn.sys"
"c:\windows\Tasks\RegCure.job"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_1SYQO.SYS
——-\Service_1syqo.sys
——-\Service_pfdewi
.
.
((((((((((((((((((((((((( Files Created from 2012-06-15 to 2012-07-15 )))))))))))))))))))))))))))))))
.
.
2012-07-14 14:57 . 2012-07-15 14:07 ——– d—–w- c:\program files\Common Files\Mcafee
2012-07-14 10:31 . 2012-07-14 10:31 ——– d—–w- C:\TDSSKiller_Quarantine
2012-07-13 17:48 . 2012-07-13 17:48 ——– d—–w- c:\documents and settings\Neil\Application Data\Apple Computer
2012-07-13 17:45 . 2012-07-13 17:45 ——– d—–w- c:\documents and settings\Mary Jenny\Application Data\Apple Computer
2012-07-11 03:07 . 2012-07-15 14:07 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2012-07-11 02:00 . 2012-05-11 14:42 521728 ——w- c:\windows\system32\dllcache\jsdbgui.dll
2012-07-09 01:21 . 2012-07-09 01:21 ——– d–h–w- c:\windows\system32\GroupPolicy
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-13 13:19 . 2005-08-16 03:18 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2008-07-14 23:27 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2005-08-16 03:18 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2005-08-16 03:18 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 14:19 . 2007-05-30 22:39 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 14:19 . 2007-05-30 22:39 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 14:19 . 2005-08-16 03:40 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 14:19 . 2005-08-16 03:40 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 14:19 . 2005-08-16 03:40 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 14:19 . 2007-05-30 22:39 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 14:19 . 2005-08-16 03:40 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 14:19 . 2005-08-16 03:40 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 14:19 . 2005-08-16 03:18 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 14:19 . 2005-05-26 03:16 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 14:19 . 2007-05-30 22:39 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 14:19 . 2005-08-16 03:40 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 14:19 . 2005-08-16 03:40 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 14:18 . 2007-05-31 18:20 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 14:18 . 2006-12-20 00:22 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 14:18 . 2006-12-20 00:22 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:22 . 2005-08-16 03:18 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-24 01:40 . 2012-05-24 01:40 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2012-05-24 00:37 . 2012-05-24 00:37 8072272 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\BingBar\BBSvc\7.1.382.0oemBingBarSetup-Partner.EXE
2012-05-16 15:08 . 2005-08-16 03:18 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2005-08-16 03:18 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2005-08-16 03:18 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2005-08-16 03:18 385024 ——w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2005-08-16 03:18 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-03 21:59 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2005-08-16 03:37 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-05-19 18:50 . 2011-08-18 00:46 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-09-01 11:12 . 2008-08-27 13:08 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2011-04-14 13:01 . 2010-08-21 19:07 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-07-15_08.41.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-15 14:25 . 2012-07-15 14:25 16384 c:\windows\Temp\Perflib_Perfdata_8c.dat
+ 2012-07-15 14:25 . 2012-07-15 14:25 16384 c:\windows\Temp\Perflib_Perfdata_2f8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-14 7323648]
"CTHelper"="CTHELPER.EXE" [2005-11-08 16384]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-03-02 18944]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-11-09 497240]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 430080]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-09-01 30192]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-12-18 296056]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-13 73728]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Dougie\Start Menu\Programs\Startup\
BBC iPlayer Desktop.lnk - c:\program files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe [2011-6-26 142848]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
AOL 9.0 Tray Icon.lnk - c:\program files\AOL 9.0\aoltray.exe [2006-4-6 156784]
Audible Download Manager.lnk - c:\program files\Audible\Bin\AudibleDownloadHelper.exe [2009-4-29 1787224]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Huawei technologies\\Huawei UMTS Data Card\\3 USB Modem.exe"=
"c:\\Program Files\\Intel\\PROSetWired\\NCS\\PROSet\\PROSet.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [31/01/2012 04:46 31952]
R1 AvgLdx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [22/02/2012 05:25 235216]
R1 AvgTdiX;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [19/03/2012 05:17 301248]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [24/05/2012 02:39 285392]
R2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.382.0\BBSvc.EXE [16/04/2012 17:49 193616]
S2 gupdate1cac295ec48ec54;Google Update Service (gupdate1cac295ec48ec54);c:\program files\Google\Update\GoogleUpdate.exe [13/03/2010 11:14 133104]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe –> c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [?]
S3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.382.0\SeaPort.EXE [16/04/2012 17:49 240208]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [07/11/2010 18:52 112640]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [21/04/2006 19:47 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [13/03/2010 11:14 133104]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [19/05/2012 19:51 129976]
S3 xpsec;IPSEC driver;c:\windows\system32\drivers\xpsec.sys –> c:\windows\system32\drivers\xpsec.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MCAFEE_SITEADVISOR_SERVICE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 11:34]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 10:13]
.
2012-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-13 10:13]
.
2012-07-15 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1038292835-2904995092-2848636223-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-07-15 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1038292835-2904995092-2848636223-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-05-21 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1038292835-2904995092-2848636223-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-05-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1038292835-2904995092-2848636223-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 16:02]
.
2012-07-15 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]
.
2012-05-24 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Dougie\Application Data\Mozilla\Firefox\Profiles\pmio7n0d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=mcafee&p=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-15 15:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,RunDLLEntry???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2104)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\SYSTEM32\CTXFISPI.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\system32\dllhost.exe
c:\windows\system32\dlcccoms.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2012-07-15 15:30:50 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-15 14:30
ComboFix2.txt 2012-07-15 08:47
ComboFix3.txt 2012-07-13 10:47
ComboFix4.txt 2012-07-11 02:27
.
Pre-Run: 83,927,846,912 bytes free
Post-Run: 84,115,644,416 bytes free
.
- - End Of File - - 72A57CE65AB9378F49D48024CD5A14D9
Hi,

Malwarebytes

I see that you have Malwarebytes already on your computer. Please open Malwarebytes, update it and then run a Quick Scan. Save the log that is created for your next reply.
———-

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats is NOT selected and the option Scan unwanted applications is selected.
  • Click Scan (This scan can take several hours, so please be patient)
  • If there are threats that are found, please press List of found threats and then in the next window that opens press Export to text file…
  • Copy and paste/or attach that log as a reply to this topic
**Note** If not threats are found there will not be a log created.
———-
Ok…. I ran Malwarebytes and it found a couple of items - which I quarantined. Should I delete or restore them? The Malwarebytes log is below. The ESET online scanner picked up 1 Threat: C:\Documents and Settings\Dougie\Desktop\Dump_Hdd0_DR0.mbr Win32/Mebroot.FX trojan Should I now select 'FINISH' on the ESET scanner?? Thanks Jen Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.16.03 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Dougie :: INNIT [administrator] 16/07/2012 07:52:01 mbam-log-2012-07-16 (07-52-01).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 314754 Time elapsed: 14 minute(s), 37 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 2 HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi,

Malwarebytes you ran just fine and Quarantining them was good. Let's get rid of that entry ESET found.
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    File::
    C:\Documents and Settings\Dougie\Desktop\Dump_Hdd0_DR0.mbr
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

In your next reply please post the new ComboFix log and let me know how your system is running. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI