This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with Virtumonde Hijack removal

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am pretty competent on the computer, although my self infection of this hijack wouldn't indicate that…LOL
I opened an exe file that I thought was safe. It seems I have taken care of the bulk of the initial Hijack (popups, IE problems ect)

I have done sweeps in safe mode with SPYBOT S and D and it keeps seeing the virtumonde hijack. I tried Spysweeper, it won't even run
in safe mode (what a waste of money !) I have run adaware in safe mode, ect ect.

I do not have the knowledge to fix the registry myself, but with help from an expert on this forum , I am not afraid to jump in. I will use the force to guide me…LOL

Thank you so very much in advance for any of you that take the time to help.

Regards,

Jim

My Hijack this info : (Done in safe mode)

Logfile of HijackThis v1.99.1
Scan saved at 7:19:11 AM, on 10/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Jewel\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {1AA7EAD5-E40B-4E63-8804-D98C95BE8394} - C:\WINDOWS\system32\awtst.dll (file missing)
O2 - BHO: (no name) - {95D07BC7-72D2-4633-A9E1-0C9EF924835C} - C:\WINDOWS\system32\awtqo.dll (file missing)
O2 - BHO: (no name) - {BEFABC1C-5A8A-4086-94D5-81EF2DC82354} - C:\WINDOWS\system32\jkhff.dll (file missing)
O2 - BHO: (no name) - {E45CC07D-DF8B-4B3A-A55D-F5C1D9E38B83} - C:\WINDOWS\system32\jkkjg.dll (file missing)
O2 - BHO: (no name) - {F10D3C0E-95B2-4D91-AE3C-238974316DF1} - C:\WINDOWS\system32\geedd.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [58f43bf9] rundll32.exe "C:\WINDOWS\system32\fqrjdsph.dll",b
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131536962468
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144933503406
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: efcabab - C:\WINDOWS\SYSTEM32\efcabab.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: MagicTuneEngine - Unknown owner - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
O23 - Service: 3Dlabs LMM (miasvc) - Unknown owner - C:\WINDOWS\system32\MiaSvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)

Hello and welcome to the forum. :)

Download Combofix and save it to your desktop.

**Note: It is important that it is saved directly to your desktop**

1. Close any open browsers. Disconnect from the internet.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Remember to re-enable them once you're done.

Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log ( use v2.0.2. please) for further review.
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall


P.S. You are using an old version of HijackThis. Please do the following to download and install the latest version of HijackThis v2.0.2:

CLICK HERE to download the HijackThis Installer:
  • Save HJTInstall.exe to your desktop.
  • Double-click on HJTInstall.exe to run the program.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis.
  • Accept the license agreement by clicking the "I Accept" button.
  • Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
  • Click "Save log" to save the log file and then the log will open in Notepad.
  • Click on "Edit -> Select All" then click on "Edit -> Copy" to copy the entire contents of the log.
  • Come back here to this thread and paste the log in your next reply.
You may delete the older version once you have successfully downloaded and installed the latest version of HijackThis v2.0.2.
Amateur,

Thanks so much for using your knowledge to help people, rather than harm them !

I did what you said, to the letter, and am posting the 2 logs. I didn't do in safe mode (you didn't mention)

ComboFix 07-10-30.5 - Jewel 2007-10-31 13:27:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1695 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\racle~1
C:\WINDOWS\racle~1\?racle\
C:\WINDOWS\system32\abeeg.bak1
C:\WINDOWS\system32\abeeg.ini
C:\WINDOWS\system32\boopfbjn.dll
C:\WINDOWS\system32\ccvacepq.dll
C:\WINDOWS\system32\ddeeg.bak1
C:\WINDOWS\system32\ddeeg.ini
C:\WINDOWS\system32\dnolqmbj.dll
C:\WINDOWS\system32\egrabpqy.ini
C:\WINDOWS\system32\ffhkj.bak1
C:\WINDOWS\system32\ffhkj.bak2
C:\WINDOWS\system32\ffhkj.ini
C:\WINDOWS\system32\gjkkj.bak2
C:\WINDOWS\system32\gjkkj.ini
C:\WINDOWS\system32\gjkkj.ini2
C:\WINDOWS\system32\hgjlm.bak1
C:\WINDOWS\system32\hgjlm.bak2
C:\WINDOWS\system32\hgjlm.ini
C:\WINDOWS\system32\hgjlm.ini2
C:\WINDOWS\system32\hhkmp.bak1
C:\WINDOWS\system32\hhkmp.ini
C:\WINDOWS\system32\hlqxgtuj.dll
C:\WINDOWS\system32\hlxherjx.dll
C:\WINDOWS\system32\iemm.dll
C:\WINDOWS\system32\jlvmnxes.ini
C:\WINDOWS\system32\kjllm.bak1
C:\WINDOWS\system32\kjllm.bak2
C:\WINDOWS\system32\kjllm.ini
C:\WINDOWS\system32\mlljk.dll
C:\WINDOWS\system32\njbfpoob.ini
C:\WINDOWS\system32\nqtwa.bak1
C:\WINDOWS\system32\nqtwa.ini
C:\WINDOWS\system32\oqtwa.bak2
C:\WINDOWS\system32\oqtwa.ini
C:\WINDOWS\system32\oqtwa.ini2
C:\WINDOWS\system32\pskill.exe
C:\WINDOWS\system32\sexnmvlj.dll
C:\WINDOWS\system32\sfyrxdyf.dllbox
C:\WINDOWS\system32\tstwa.bak1
C:\WINDOWS\system32\tstwa.ini
C:\WINDOWS\system32\vytojxhg.dll
C:\WINDOWS\system32\wbqbbdug.dll
C:\WINDOWS\system32\xjrehxlh.ini
C:\WINDOWS\system32\yqpbarge.dll

.
((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-31 )))))))))))))))))))))))))))))))
.

2007-10-31 13:26 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-29 19:31 589 –a—— C:\WINDOWS\system32\hxdqdppy.dll
2007-10-28 19:31 589 –a—— C:\WINDOWS\system32\mdajmrbv.dll
2007-10-26 15:19 d——– C:\Program Files\Lavasoft
2007-10-26 15:19 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-26 15:18 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-20 06:05 1,165 –a—— C:\WINDOWS\mozver.dat
2007-10-19 17:45 d——– C:\Program Files\AceLogix
2007-10-19 16:47 d——– C:\Documents and Settings\Administrator\Application Data\Webroot
2007-10-19 16:46 d——– C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-10-19 15:56 d——– C:\Program Files\Ace Utilities
2007-10-18 14:00 d——– C:\Documents and Settings\LocalService\Application Data\Webroot
2007-10-18 14:00 163,640 –a—— C:\WINDOWS\system32\drivers\ssidrv.sys
2007-10-18 14:00 23,864 –a—— C:\WINDOWS\system32\drivers\sskbfd.sys
2007-10-18 14:00 21,816 –a—— C:\WINDOWS\system32\drivers\sshrmd.sys
2007-10-18 14:00 20,280 –a—— C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2007-10-18 13:59 d——– C:\Program Files\Webroot
2007-10-18 13:59 d——– C:\Documents and Settings\Jewel\Application Data\Webroot
2007-10-18 13:59 d——– C:\Documents and Settings\All Users\Application Data\Webroot
2007-10-18 13:59 1,526,072 –a—— C:\WINDOWS\WRSetup.dll
2007-10-18 13:25 d——– C:\Program Files\Enigma Software Group
2007-10-16 17:40 d——– C:\Documents and Settings\Jewel\Application Data\AdwareAlert
2007-10-16 16:53 d——– C:\Documents and Settings\Jewel\Application Data\Talkback
2007-10-16 16:53 0 –a—— C:\WINDOWS\nsreg.dat
2007-10-14 14:44 36,352 –a—— C:\WINDOWS\system32\efcabab.dll
2007-10-13 17:11 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-10-13 17:11 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-09-26 08:41 2,164,411 –a—— C:\WINDOWS\system32\haspds_windows.dll
2007-09-26 08:41 685,056 –a—— C:\WINDOWS\system32\drivers\hardlock.sys
2007-09-26 08:41 24,576 –a—— C:\WINDOWS\system32\hdduinst.exe
2007-09-26 08:41 6,656 –a—— C:\WINDOWS\system32\haspvdd.dll
2007-09-26 07:54 47,616 –a—— C:\WINDOWS\system32\drivers\Haspnt.sys
2007-09-26 07:54 383 –a—— C:\WINDOWS\system32\haspdos.sys
2007-09-25 13:19 d——– C:\kwicktrig
2007-09-13 16:28 d——– C:\Incomplete
2007-09-13 16:23 d——– C:\Documents and Settings\Jewel\Incomplete
2007-09-13 16:22 d——– C:\Program Files\LimeWire
2007-09-13 16:22 d——– C:\Documents and Settings\Jewel\Application Data\LimeWire
2007-09-12 15:40 d——– C:\Documents and Settings\Jewel\Application Data\CyberLink
2007-09-12 15:40 d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2007-09-12 15:08 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-09-12 15:07 d——– C:\Program Files\CyberLink
2007-09-12 14:57 61,056 –a—— C:\WINDOWS\system32\drivers\ohci1394.sys
2007-09-12 14:57 61,056 –a–c— C:\WINDOWS\system32\dllcache\ohci1394.sys
2007-09-12 14:57 53,248 –a—— C:\WINDOWS\system32\drivers\1394bus.sys
2007-09-12 14:57 53,248 –a–c— C:\WINDOWS\system32\dllcache\1394bus.sys
2007-09-12 14:57 6,400 –a—— C:\WINDOWS\system32\drivers\enum1394.sys
2007-09-12 14:57 6,400 –a–c— C:\WINDOWS\system32\dllcache\enum1394.sys
2007-09-12 09:25 d——– C:\Documents and Settings\Jewel\Application Data\DVD Flick
2007-09-12 09:24 d——– C:\Program Files\DVD Flick
2007-09-11 19:28 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2007-09-11 19:28 14,848 –a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2007-09-11 19:26 159,744 –a—— C:\WINDOWS\system32\WmJoyFrc.dll
2007-09-11 19:26 45,504 –a—— C:\WINDOWS\system32\drivers\WmXlCore.sys
2007-09-11 19:26 22,240 –a—— C:\WINDOWS\system32\drivers\WmFilter.sys
2007-09-11 19:26 17,632 –a—— C:\WINDOWS\system32\drivers\WmHidLo.sys
2007-09-11 19:26 10,144 –a—— C:\WINDOWS\system32\drivers\WmBEnum.sys
2007-09-11 19:26 5,600 –a—— C:\WINDOWS\system32\drivers\WmVirHid.sys
2007-09-11 18:44 d——– C:\nascar
2007-09-03 19:27 d——– C:\Music

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-31 17:08 ——— d—–w C:\Documents and Settings\Jewel\Application Data\U3
2007-10-31 17:07 ——— d—–w C:\Program Files\Plaxo
2007-10-29 22:37 ——— d—–w C:\Documents and Settings\Jewel\Application Data\AdobeUM
2007-10-26 23:33 ——— d—–w C:\Program Files\Java
2007-10-26 23:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-19 23:25 ——— d—–w C:\Program Files\MagicTune Premium
2007-10-19 23:22 ——— d—–w C:\Program Files\EndItAll
2007-10-17 21:10 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-16 21:57 ——— d—–w C:\Documents and Settings\Jewel\Application Data\Lavasoft
2007-09-12 21:54 ——— d—–w C:\Program Files\NCH Swift Sound
2007-09-12 00:26 ——— d—–w C:\Program Files\Logitech
2007-09-12 00:26 ——— d—–w C:\Program Files\Common Files\Logitech
2007-09-06 14:29 ——— d—–w C:\Documents and Settings\Jewel\Application Data\Skype
2007-08-31 02:04 ——— d—–w C:\Documents and Settings\Jewel\Application Data\Hewlett-Packard
2007-08-31 02:01 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2007-08-31 02:00 ——— d—–w C:\Program Files\Hewlett-Packard
2007-08-31 01:33 ——— d—–w C:\Program Files\Hp
2007-02-08 20:06 32,768 —-a-w C:\Documents and Settings\Jewel\WebVpnRegKey6-verge-insulet-com.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1AA7EAD5-E40B-4E63-8804-D98C95BE8394}]
C:\WINDOWS\system32\awtst.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95D07BC7-72D2-4633-A9E1-0C9EF924835C}]
C:\WINDOWS\system32\awtqo.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BEFABC1C-5A8A-4086-94D5-81EF2DC82354}]
C:\WINDOWS\system32\jkhff.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E45CC07D-DF8B-4B3A-A55D-F5C1D9E38B83}]
C:\WINDOWS\system32\jkkjg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10D3C0E-95B2-4D91-AE3C-238974316DF1}]
C:\WINDOWS\system32\geedd.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-01-15 07:54]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcabab]
efcabab.dll 2007-10-14 14:44 36352 C:\WINDOWS\system32\efcabab.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mlljk.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
"PlaxoUpdate"="C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe" -a
"Hrdo"="C:\WINDOWS\RACLE~1\regsvr32.exe" –ru -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
"58f43bf9"=rundll32.exe "C:\WINDOWS\system32\yqpbarge.dll",b
"Logitech Utility"=Logi_MwX.Exe

R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\WINDOWS\system32\Drivers\SSFS0BB9.SYS
R2 miasvc;3Dlabs LMM;C:\WINDOWS\system32\MiaSvc.exe
R2 Sense3;Sense3;C:\WINDOWS\system32\Drivers\sense3.sys
R3 miranda;miranda;C:\WINDOWS\system32\DRIVERS\3dlMP.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 USBLOCK;Senselock USB Lock driver;C:\WINDOWS\system32\Drivers\usblock.sys
S3 akshasp;Aladdin HASP Key;C:\WINDOWS\system32\DRIVERS\akshasp.sys
S3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
S3 WmHidLo;Logitech Gaming USB Filter Driver;C:\WINDOWS\system32\drivers\WmHidLo.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
S3 yukonx86;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\yukonx86.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53fec509-020a-11dc-bf91-0016b657555f}]
AutoRun\command - F:\LaunchU3.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-10-18 07:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\Adware\AdwareAlert.exe
"2007-10-07 02:04:09 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1188525803.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-31 13:33:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-31 13:33:37 - machine was rebooted
.
— E O F —


Log from Hijack this :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:37:25 PM, on 10/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
C:\WINDOWS\system32\MiaSvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\MagicTune Premium\MagicTune.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: (no name) - {1AA7EAD5-E40B-4E63-8804-D98C95BE8394} - C:\WINDOWS\system32\awtst.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {95D07BC7-72D2-4633-A9E1-0C9EF924835C} - C:\WINDOWS\system32\awtqo.dll (file missing)
O2 - BHO: (no name) - {BEFABC1C-5A8A-4086-94D5-81EF2DC82354} - C:\WINDOWS\system32\jkhff.dll (file missing)
O2 - BHO: (no name) - {E45CC07D-DF8B-4B3A-A55D-F5C1D9E38B83} - C:\WINDOWS\system32\jkkjg.dll (file missing)
O2 - BHO: (no name) - {F10D3C0E-95B2-4D91-AE3C-238974316DF1} - C:\WINDOWS\system32\geedd.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131536962468
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144933503406
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: efcabab - C:\WINDOWS\SYSTEM32\efcabab.dll
O22 - SharedTaskScheduler: OLE Module - {03B1C4D9-BC71-8916-38AD-9DEA5D213614} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: MagicTuneEngine - Unknown owner - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
O23 - Service: 3Dlabs LMM (miasvc) - Unknown owner - C:\WINDOWS\system32\MiaSvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

–
End of file - 4921 bytes



I am really hoping this is the end of my hijack. When I do a Spybot S & D, it still finds the virtumonde, but that isn't since you had me do all this.

Looks like there was lots of junk still going on.

I will keep an eye out for your analysis of these logs.

Thanks so much again. I am going to try and get my money back from Spy Sweeper and donate it here !!

Jim
Hi,

It's looking better but not out of the woods yet.

I noticed that you are using LimeWire which is a p2p file sharing program. I would like to warn you that the nature of P2P filesharing is so that even if one is using a "clean" program, many of the files downloaded from non-documented sources have the potential of being infected. So, regardless of whether one is using a "clean" program, one may still be prone to infection by malware because more than half of all files available for download from peer-to-peer networks have been deliberately infected with some form of malware. I recommend that you remove it from your system via Add/Remove Programs in Control Panel.

================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Click Start>Run, type in appwiz.cpl and press Enter.
  • Remove all entries of Runtime Environment (J2SE or JRE) that are listed.
  • Now reboot your computer.
  • Download the latest version of Java Runtime Environment, and install it to your computer.

================================

Please disable SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean. To disable SpySweeper: Open Spysweeper and click on Options over to the left then >program options >Uncheck "load at windows startup". Over to the left click "shields" and uncheck all there. Uncheck "home page shield". Uncheck 'automaticly restore default without notification".

================================

Open notepad (it must be notepad, not wordpad, or it won't work) and copy/paste the text in the quotebox below into it (starting from File::):
File::
C:\WINDOWS\system32\hxdqdppy.dll
C:\WINDOWS\system32\mdajmrbv.dll
C:\WINDOWS\system32\efcabab.dll
Folder::
C:\Program Files\Enigma Software Group
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1AA7EAD5-E40B-4E63-8804-D98C95BE8394}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95D07BC7-72D2-4633-A9E1-0C9EF924835C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BEFABC1C-5A8A-4086-94D5-81EF2DC82354}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E45CC07D-DF8B-4B3A-A55D-F5C1D9E38B83}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10D3C0E-95B2-4D91-AE3C-238974316DF1}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcabab]

DirLook::
C:\kwicktrig
C:\Incomplete
Save this as CFScript.txt
[external image: Posted Image]
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you. Post that log in your next reply.
Amateur,

Thanks so much again ! Its amazing what stuff goes on in a puter ! You seem to really know your stuff. I uninstalled Spysweeper (waste of money).

If I eliminate Limewire, what do you recommend I use asa a peer to peer ? I mostly use it to link up to my computer while I am away, but I do download
the odd music file. I did what you said about the Java. It was taking up a lot of space for nothing and I was wondering if I could do what you had me do, now I know, Thanks.
What about Microsoft update ? There is tons of space be taken up by those ? More than a year ago, my computer crashed and I have not been able to receive any updates anyway. If I try to do a Microsoft update, it just sits there, freezes. This is mostly a working computer, hi end cad sort of workstation anyway. I have decided never to use IE ever again, its security seems to be full of holes and something malware targets. I wish I could fully uninstall it, but I just disabled it in the control panel>add/remove.

Here is log:

ComboFix 07-10-30.5 - Jewel 2007-11-01 6:56:59.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1671 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jewel\Desktop\cfscript.txt
* Created a new restore point

FILE::
C:\WINDOWS\system32\efcabab.dll
C:\WINDOWS\system32\hxdqdppy.dll
C:\WINDOWS\system32\mdajmrbv.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Enigma Software Group
C:\WINDOWS\system32\efcabab.dll
C:\WINDOWS\system32\hxdqdppy.dll
C:\WINDOWS\system32\mdajmrbv.dll

.
((((((((((((((((((((((((( Files Created from 2007-10-01 to 2007-11-01 )))))))))))))))))))))))))))))))
.

2007-11-01 06:53 d——– C:\Program Files\Java
2007-11-01 06:53 d——– C:\Program Files\Common Files\Java
2007-10-31 13:37 d——– C:\Program Files\Trend Micro
2007-10-31 13:26 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-26 15:19 d——– C:\Program Files\Lavasoft
2007-10-26 15:19 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-26 15:18 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-20 06:05 1,165 –a—— C:\WINDOWS\mozver.dat
2007-10-19 17:45 d——– C:\Program Files\AceLogix
2007-10-19 15:56 d——– C:\Program Files\Ace Utilities
2007-10-16 17:40 d——– C:\Documents and Settings\Jewel\Application Data\AdwareAlert
2007-10-16 16:53 d——– C:\Documents and Settings\Jewel\Application Data\Talkback
2007-10-16 16:53 0 –a—— C:\WINDOWS\nsreg.dat
2007-10-13 17:11 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-10-13 17:11 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-01 11:52 ——— d—–w C:\Program Files\Plaxo
2007-10-31 22:22 ——— d—–w C:\Documents and Settings\Jewel\Application Data\AdobeUM
2007-10-31 17:08 ——— d—–w C:\Documents and Settings\Jewel\Application Data\U3
2007-10-26 23:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-20 13:01 ——— d—–w C:\Documents and Settings\Jewel\Application Data\LimeWire
2007-10-19 23:25 ——— d—–w C:\Program Files\MagicTune Premium
2007-10-19 23:22 ——— d—–w C:\Program Files\EndItAll
2007-10-17 21:10 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-16 21:57 ——— d—–w C:\Documents and Settings\Jewel\Application Data\Lavasoft
2007-10-14 19:32 ——— d—–w C:\Program Files\LimeWire
2007-09-26 13:41 47,616 —-a-w C:\WINDOWS\system32\drivers\Haspnt.sys
2007-09-12 23:51 ——— d—–w C:\Documents and Settings\Jewel\Application Data\DVD Flick
2007-09-12 21:54 ——— d—–w C:\Program Files\NCH Swift Sound
2007-09-12 21:16 ——— d—–w C:\Documents and Settings\Jewel\Application Data\CyberLink
2007-09-12 21:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-09-12 20:08 ——— d—–w C:\Program Files\CyberLink
2007-09-12 14:25 ——— d—–w C:\Program Files\DVD Flick
2007-09-12 00:26 ——— d—–w C:\Program Files\Logitech
2007-09-12 00:26 ——— d—–w C:\Program Files\Common Files\Logitech
2007-09-06 14:29 ——— d—–w C:\Documents and Settings\Jewel\Application Data\Skype
2007-02-08 20:06 32,768 —-a-w C:\Documents and Settings\Jewel\WebVpnRegKey6-verge-insulet-com.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Incomplete —-

2007-10-20 08:17 1244 –a—— C:\Incomplete\downloads.dat
2007-10-20 08:15 1244 –a—— C:\Incomplete\downloads.bak
2007-10-14 19:27 695264632 –a—— C:\Incomplete\T-734570496-Star Wars I - The Phantom Menace.avi
2007-10-14 16:23 4169555 –a—— C:\Incomplete\CORRUPT-0-Movie Songs - Star Wars- The Imperial March (Darth Vader's Theme).mp3
2007-10-14 14:45 0 –a—— C:\Incomplete\T-3981312-Def Leppard-Pyromania.mp3
2007-09-23 20:48 26704 –a—— C:\Incomplete\UOYDJU3WXNMFR3AM5GK3OT62JCVZHOOJ\.datThe Wizard of Oz - deleted scarecrow dance.avi
2007-09-23 20:48 105381888 –a—— C:\Incomplete\UOYDJU3WXNMFR3AM5GK3OT62JCVZHOOJ\The Wizard of Oz - deleted scarecrow dance.avi

—- Directory of C:\kwicktrig —-

2007-09-25 13:22 12 –a—— C:\kwicktrig\BOLTCIRC.INI
2007-09-25 13:21 29 –a—— C:\kwicktrig\TRIGO.INI
2007-09-25 13:20 29 –a—— C:\kwicktrig\TRIGR.INI
2007-09-24 07:01 196809 –a—— C:\kwicktrig\ktrig212(2).zip
2001-01-24 19:15 113665 –a—— C:\kwicktrig\KWIKTRIG.EXE
2001-01-24 18:46 2460 –a—— C:\kwicktrig\readme.txt
1991-05-10 00:00 271264 –a—— C:\kwicktrig\VBRUN100.DLL


((((((((((((((((((((((((((((( snapshot@2007-10-31_13.33.10.84 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-12 05:22:00 135,168 —-a-w C:\WINDOWS\system32\java.exe
+ 2007-09-25 03:30:28 135,168 —-a-w C:\WINDOWS\system32\java.exe
- 2007-07-12 05:22:04 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2007-09-25 03:30:30 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
- 2007-07-12 06:22:38 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
+ 2007-09-25 04:31:42 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-01-15 07:54]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
"PlaxoUpdate"="C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe" -a
"Hrdo"="C:\WINDOWS\RACLE~1\regsvr32.exe" –ru -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
"58f43bf9"=rundll32.exe "C:\WINDOWS\system32\yqpbarge.dll",b
"Logitech Utility"=Logi_MwX.Exe

R2 miasvc;3Dlabs LMM;C:\WINDOWS\system32\MiaSvc.exe
R2 Sense3;Sense3;C:\WINDOWS\system32\Drivers\sense3.sys
R3 miranda;miranda;C:\WINDOWS\system32\DRIVERS\3dlMP.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 USBLOCK;Senselock USB Lock driver;C:\WINDOWS\system32\Drivers\usblock.sys
S3 akshasp;Aladdin HASP Key;C:\WINDOWS\system32\DRIVERS\akshasp.sys
S3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
S3 WmHidLo;Logitech Gaming USB Filter Driver;C:\WINDOWS\system32\drivers\WmHidLo.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
S3 yukonx86;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\yukonx86.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53fec509-020a-11dc-bf91-0016b657555f}]
AutoRun\command - F:\LaunchU3.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-10-18 07:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\Adware\AdwareAlert.exe
"2007-10-07 02:04:09 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1188525803.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-01 07:00:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-01 7:00:48 - machine was rebooted
.
— E O F —



Cheers, Jim
Sorry about that ,

Here is the Hijack log now.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:21:09 PM, on 11/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\MiaSvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\avwin\avwin.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131536962468
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144933503406
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: OLE Module - {03B1C4D9-BC71-8916-38AD-9DEA5D213614} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: MagicTuneEngine - Unknown owner - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
O23 - Service: 3Dlabs LMM (miasvc) - Unknown owner - C:\WINDOWS\system32\MiaSvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 4153 bytes
Hi,

No worries.

If I eliminate Limewire, what do you recommend I use asa a peer to peer ?

Sorry, but I would advise no p2p software.

==============================

Scan with HijackThis and put a checkmark against the following entry:

O22 - SharedTaskScheduler: OLE Module - {03B1C4D9-BC71-8916-38AD-9DEA5D213614} - (no file)

Close all browsers/windows other than HijackThis and click on "fix checked".

==============================

Open notepad (it must be notepad, not wordpad, or it won't work) and copy/paste the text in the quotebox below into it, starting from Registry:

Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Hrdo"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"=-
"SpySweeper"=-
"58f43bf9"=-

Save this as CFScript.txt

[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

==================================

This is mostly a working computer, hi end cad sort of workstation anyway. I have decided never to use IE ever again, its security seems to be full of holes and something malware targets. I wish I could fully uninstall it, but I just disabled it in the control panel>add/remove.


What version of IE do you have? You cannot uninstall IE and you need it, not only to access some web pages, but also to update your operating system.

What about Microsoft update ? There is tons of space be taken up by those ? More than a year ago, my computer crashed and I have not been able to receive any updates anyway. If I try to do a Microsoft update, it just sits there, freezes

.
Now, that's not good. If you are not keeping your system patched with the monthly updates from Microsoft then you are still open to many exploits. Before trying the following fix, you'll need to re-enable your Internet Explorer. You cannot get the updates with any other browser. Once you do that, if you still cannot update, try the following fix:

Download this file HERE and unzip it to your desktop. When unzipped it will be named Fix_Windwws_Update.bat. Double click to run it. Click OK at the prompts until it has finished. This program re-registers some dlls and has fixed this problem in the past.

Reboot and check if you can get your updates now. Keep your system patched. Set your Windows up for automatic updates.

=================================

Perform an online scan using Internet Explorer with Panda ActiveScan
  • Click on [external image: Posted Image] located at the bottom of the page.
  • A "pop up" window will appear. Please ensure that your pop up blocker doesn't block it
  • Enter your e-mail address, country, and state & click "Free Online Scan" The download of the 8 MB Panda's ActiveX control will take place
Begin the scan by selecting [external image: Posted Image]
  • If it finds any malware, it will offer you a report.
  • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
  • Click on [external image: Posted Image] then click [external image: Posted Image] and post back the contents please.
=================================

Please post the Combofix.txt , Panda Online scan results and another fresh HijackThis log, taken after a reboot.
Holy Cats,

This is more serious and harder work than I thought ! Amazing, these puter things, but a pain in the rump too ! LOL

I reinstalled IE 7 (much to my dismay), the fix you gave me seems to have let me get my Microsoft updates now also.

Here is the combofix log : (Iys a long one !)

ComboFix 07-10-30.5 - Jewel 2007-11-02 8:40:30.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1578 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jewel\Desktop\cfscript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-10-02 to 2007-11-02 )))))))))))))))))))))))))))))))
.

2007-11-02 06:54 d——– C:\WINDOWS\system32\ActiveScan
2007-11-02 06:54 d——– C:\WINDOWS\LastGood
2007-11-01 22:05 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-01 22:03 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-11-01 22:03 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-11-01 22:03 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-11-01 20:23 582,656 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-11-01 20:12 6,058,496 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-11-01 20:12 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-11-01 20:12 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-11-01 20:12 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-11-01 20:12 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-11-01 20:12 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2007-11-01 20:12 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-11-01 20:12 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-11-01 20:09 33,792 –a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2007-11-01 07:53 d——– C:\Program Files\Java
2007-11-01 07:53 d——– C:\Program Files\Common Files\Java
2007-10-31 14:37 d——– C:\Program Files\Trend Micro
2007-10-31 14:26 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-26 16:19 d——– C:\Program Files\Lavasoft
2007-10-26 16:19 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-26 16:18 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-20 07:05 1,165 –a—— C:\WINDOWS\mozver.dat
2007-10-19 18:45 d——– C:\Program Files\AceLogix
2007-10-19 16:56 d——– C:\Program Files\Ace Utilities
2007-10-16 18:40 d——– C:\Documents and Settings\Jewel\Application Data\AdwareAlert
2007-10-16 17:53 d——– C:\Documents and Settings\Jewel\Application Data\Talkback
2007-10-16 17:53 0 –a—— C:\WINDOWS\nsreg.dat
2007-10-13 18:11 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-10-13 18:11 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-02 11:21 ——— d—–w C:\Program Files\Plaxo
2007-10-31 22:22 ——— d—–w C:\Documents and Settings\Jewel\Application Data\AdobeUM
2007-10-31 17:08 ——— d—–w C:\Documents and Settings\Jewel\Application Data\U3
2007-10-26 23:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-20 13:01 ——— d—–w C:\Documents and Settings\Jewel\Application Data\LimeWire
2007-10-19 23:25 ——— d—–w C:\Program Files\MagicTune Premium
2007-10-19 23:22 ——— d—–w C:\Program Files\EndItAll
2007-10-17 21:10 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-16 21:57 ——— d—–w C:\Documents and Settings\Jewel\Application Data\Lavasoft
2007-10-14 19:32 ——— d—–w C:\Program Files\LimeWire
2007-09-26 13:41 6,656 —-a-w C:\WINDOWS\system32\haspvdd.dll
2007-09-26 13:41 47,616 —-a-w C:\WINDOWS\system32\drivers\Haspnt.sys
2007-09-12 23:51 ——— d—–w C:\Documents and Settings\Jewel\Application Data\DVD Flick
2007-09-12 21:54 ——— d—–w C:\Program Files\NCH Swift Sound
2007-09-12 21:16 ——— d—–w C:\Documents and Settings\Jewel\Application Data\CyberLink
2007-09-12 21:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2007-09-12 20:08 ——— d—–w C:\Program Files\CyberLink
2007-09-12 14:25 ——— d—–w C:\Program Files\DVD Flick
2007-09-12 00:26 ——— d—–w C:\Program Files\Logitech
2007-09-12 00:26 ——— d—–w C:\Program Files\Common Files\Logitech
2007-09-06 14:29 ——— d—–w C:\Documents and Settings\Jewel\Application Data\Skype
2007-08-13 23:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-13 23:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-13 23:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-13 23:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-13 23:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-13 23:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-13 23:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-13 23:32 45,568 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-13 23:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-02-08 20:06 32,768 —-a-w C:\Documents and Settings\Jewel\WebVpnRegKey6-verge-insulet-com.dll
.

((((((((((((((((((((((((((((( snapshot@2007-11-01_18.53.36.79 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-29 23:56:19 136,192 —-a-w C:\WINDOWS\catchme.exe
+ 2007-10-29 22:56:19 136,192 —-a-w C:\WINDOWS\catchme.exe
+ 2006-08-24 12:28:54 141,424 —-a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
+ 2006-02-15 00:22:26 142,464 ——w C:\WINDOWS\Driver Cache\i386\aec.sys
- 2004-10-08 23:48:21 262,400 ——w C:\WINDOWS\Driver Cache\i386\http.sys
+ 2006-03-17 00:33:10 262,784 ——w C:\WINDOWS\Driver Cache\i386\http.sys
+ 2006-06-14 08:47:45 172,416 ——w C:\WINDOWS\Driver Cache\i386\kmixer.sys
- 2005-01-19 04:26:52 451,584 ——w C:\WINDOWS\Driver Cache\i386\mrxsmb.sys
+ 2006-05-05 09:41:45 453,120 ——w C:\WINDOWS\Driver Cache\i386\mrxsmb.sys
- 2005-03-02 00:57:44 2,135,552 ——w C:\WINDOWS\Driver Cache\i386\ntkrnlmp.exe
+ 2007-02-28 09:08:48 2,136,064 ——w C:\WINDOWS\Driver Cache\i386\ntkrnlmp.exe
- 2005-03-02 00:34:40 2,056,832 ——w C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
+ 2007-02-28 08:38:55 2,057,600 ——w C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
- 2005-03-02 00:34:42 2,015,232 ——w C:\WINDOWS\Driver Cache\i386\ntkrpamp.exe
+ 2007-02-28 08:38:57 2,015,744 ——w C:\WINDOWS\Driver Cache\i386\ntkrpamp.exe
- 2005-03-02 00:59:53 2,179,328 ——w C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
+ 2007-02-28 09:10:57 2,180,352 ——w C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
+ 2006-06-14 08:47:46 6,400 ——w C:\WINDOWS\Driver Cache\i386\splitter.sys
+ 2006-06-14 09:00:45 82,944 ——w C:\WINDOWS\Driver Cache\i386\wdmaud.sys
- 2004-08-04 07:56:49 1,032,192 —-a-w C:\WINDOWS\explorer.exe
+ 2007-06-13 10:23:07 1,033,216 —-a-w C:\WINDOWS\explorer.exe
+ 2004-08-04 07:56:41 61,440 -c–a-w C:\WINDOWS\ie7\admparse.dll
+ 2004-08-04 07:56:41 99,840 -c–a-w C:\WINDOWS\ie7\advpack.dll
+ 2006-03-04 03:33:40 1,022,976 -c–a-w C:\WINDOWS\ie7\browseui.dll
+ 2004-08-04 07:56:41 35,328 -c–a-w C:\WINDOWS\ie7\corpol.dll
+ 2006-06-03 11:40:49 33,792 -c–a-w C:\WINDOWS\ie7\custsat.dll
+ 2004-08-04 07:56:42 357,888 -c–a-w C:\WINDOWS\ie7\dxtmsft.dll
+ 2006-03-04 03:33:41 205,312 -c–a-w C:\WINDOWS\ie7\dxtrans.dll
+ 2006-03-04 03:33:41 55,808 -c–a-w C:\WINDOWS\ie7\extmgr.dll
+ 2004-08-04 07:56:42 38,912 -c–a-w C:\WINDOWS\ie7\hmmapi.dll
+ 2004-08-04 07:56:50 34,304 -c–a-w C:\WINDOWS\ie7\ie4uinit.exe
+ 2004-08-04 07:56:42 139,264 -c–a-w C:\WINDOWS\ie7\ieakeng.dll
+ 2004-08-04 07:56:42 216,576 -c–a-w C:\WINDOWS\ie7\ieaksie.dll
+ 2003-03-31 12:00:00 221,184 -c–a-w C:\WINDOWS\ie7\ieakui.dll
+ 2004-08-04 07:56:42 323,584 -c–a-w C:\WINDOWS\ie7\iedkcs32.dll
+ 2004-08-04 07:56:50 18,432 -c–a-w C:\WINDOWS\ie7\iedw.exe
+ 2004-08-04 07:56:42 81,920 -c–a-w C:\WINDOWS\ie7\ieencode.dll
+ 2006-03-04 03:33:41 251,392 -c–a-w C:\WINDOWS\ie7\iepeers.dll
+ 2004-08-04 07:56:42 48,640 -c–a-w C:\WINDOWS\ie7\iernonce.dll
+ 2004-08-04 07:56:42 62,976 -c–a-w C:\WINDOWS\ie7\iesetup.dll
+ 2004-08-04 07:56:42 35,840 -c–a-w C:\WINDOWS\ie7\imgutil.dll
+ 2006-03-04 03:33:41 96,256 -c–a-w C:\WINDOWS\ie7\inseng.dll
+ 2004-08-04 07:56:42 450,560 -c–a-w C:\WINDOWS\ie7\jscript.dll
+ 2004-08-04 07:56:42 15,872 -c–a-w C:\WINDOWS\ie7\jsproxy.dll
+ 2004-08-04 07:56:42 22,016 -c–a-w C:\WINDOWS\ie7\licmgr10.dll
+ 2004-08-04 07:56:53 29,184 -c–a-w C:\WINDOWS\ie7\mshta.exe
+ 2006-03-23 20:32:42 3,053,568 -c–a-w C:\WINDOWS\ie7\mshtml.dll
+ 2006-03-04 03:33:43 448,512 -c–a-w C:\WINDOWS\ie7\mshtmled.dll
+ 2004-08-04 07:56:14 56,832 -c–a-w C:\WINDOWS\ie7\mshtmler.dll
+ 2003-03-31 12:00:00 146,432 -c–a-w C:\WINDOWS\ie7\msls31.dll
+ 2006-03-04 03:33:43 146,432 -c–a-w C:\WINDOWS\ie7\msrating.dll
+ 2006-03-04 03:33:43 532,480 -c–a-w C:\WINDOWS\ie7\mstime.dll
+ 2004-08-04 07:56:44 96,256 -c–a-w C:\WINDOWS\ie7\occache.dll
+ 2006-03-04 03:33:43 39,424 -c–a-w C:\WINDOWS\ie7\pngfilt.dll
+ 2006-03-30 09:16:03 1,492,480 -c–a-w C:\WINDOWS\ie7\shdocvw.dll
+ 2006-03-04 03:33:44 474,112 -c–a-w C:\WINDOWS\ie7\shlwapi.dll
+ 2007-08-13 23:54:42 32,960 -c–a-w C:\WINDOWS\ie7\spuninst\iecustom.dll
+ 2007-08-13 23:52:06 66,048 -c–a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2006-09-06 22:43:16 213,216 -c–a-w C:\WINDOWS\ie7\spuninst\spuninst.exe
+ 2006-09-06 22:43:18 371,424 -c–a-w C:\WINDOWS\ie7\spuninst\updspapi.dll
+ 2004-08-04 07:56:46 37,888 -c–a-w C:\WINDOWS\ie7\url.dll
+ 2006-03-18 11:09:37 613,376 -c–a-w C:\WINDOWS\ie7\urlmon.dll
+ 2004-08-04 07:56:46 417,792 -c–a-w C:\WINDOWS\ie7\vbscript.dll
+ 2004-08-04 07:56:46 848,384 -c–a-w C:\WINDOWS\ie7\vgx.dll
+ 2004-08-04 07:56:46 276,480 -c–a-w C:\WINDOWS\ie7\webcheck.dll
+ 2006-03-04 03:33:45 658,432 -c–a-w C:\WINDOWS\ie7\wininet.dll
+ 2007-08-13 23:39:00 123,904 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\advpack.dll
+ 2007-08-13 23:39:00 123,904 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\advpack.dll.000
+ 2007-08-13 23:35:38 214,528 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\dxtrans.dll
+ 2007-08-13 23:35:38 214,528 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\dxtrans.dll.000
+ 2007-08-13 23:54:10 131,584 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\extmgr.dll
+ 2007-08-13 23:54:10 131,584 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\extmgr.dll.000
+ 2007-08-13 23:36:26 61,952 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\icardie.dll
+ 2007-08-13 23:39:06 54,784 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe
+ 2007-08-13 23:39:06 54,784 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe.000
+ 2007-08-13 23:39:26 152,064 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakeng.dll
+ 2007-08-13 23:39:26 152,064 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakeng.dll.000
+ 2007-08-13 23:39:54 229,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieaksie.dll
+ 2007-08-13 23:39:54 229,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieaksie.dll.000
+ 2007-08-13 22:56:54 161,792 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakui.dll
+ 2007-02-12 21:10:12 2,451,312 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dat
+ 2007-07-11 17:27:48 383,488 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dll
+ 2007-08-13 23:39:50 382,976 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iedkcs32.dll
+ 2007-08-13 23:39:50 382,976 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iedkcs32.dll.000
+ 2007-08-13 23:54:10 6,049,280 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieframe.dll
+ 2007-08-13 23:39:10 43,008 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iernonce.dll
+ 2007-08-13 23:39:10 43,008 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iernonce.dll.000
+ 2007-08-13 23:34:04 266,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iertutil.dll
+ 2007-08-13 23:39:10 13,312 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieudinit.exe
+ 2007-08-13 23:43:56 622,080 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
+ 2007-08-13 23:54:10 27,136 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\jsproxy.dll
+ 2007-08-13 23:54:10 27,136 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\jsproxy.dll.000
+ 2007-08-13 23:54:10 458,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeeds.dll
+ 2007-08-13 23:54:10 50,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeedsbs.dll
+ 2007-08-13 23:54:12 3,578,368 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtml.dll
+ 2007-08-13 23:54:12 3,578,368 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtml.dll.000
+ 2007-08-13 23:54:10 475,648 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtmled.dll
+ 2007-08-13 23:54:10 475,648 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtmled.dll.000
+ 2007-08-13 23:44:26 192,000 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msrating.dll
+ 2007-08-13 23:44:26 192,000 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msrating.dll.000
+ 2007-08-13 23:54:10 670,720 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mstime.dll
+ 2007-08-13 23:54:10 670,720 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mstime.dll.000
+ 2007-08-13 23:44:06 101,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\occache.dll
+ 2007-08-13 23:44:06 101,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\occache.dll.000
+ 2007-03-06 01:22:39 213,216 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\updspapi.dll
+ 2007-08-13 23:44:30 105,984 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\url.dll
+ 2007-08-13 23:44:30 105,984 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\url.dll.000
+ 2007-08-13 23:54:10 1,162,240 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\urlmon.dll
+ 2007-08-13 23:54:10 1,162,240 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\urlmon.dll.000
+ 2007-08-13 23:54:10 231,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\webcheck.dll
+ 2007-08-13 23:54:10 231,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\webcheck.dll.000
+ 2007-08-13 23:54:10 818,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll
+ 2007-08-13 23:54:10 818,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll.000
- 2006-11-20 16:38:31 593,920 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2007-11-02 02:03:34 593,920 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2006-11-20 16:38:31 12,288 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2007-11-02 02:03:34 12,288 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-11-20 16:38:31 86,016 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2007-11-02 02:03:34 86,016 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2006-11-20 16:38:31 135,168 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2007-11-02 02:03:34 135,168 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2006-11-20 16:38:32 11,264 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2007-11-02 02:03:34 11,264 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2006-11-20 16:38:32 27,136 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2007-11-02 02:03:34 27,136 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-11-20 16:38:32 4,096 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2007-11-02 02:03:34 4,096 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2006-11-20 16:38:32 794,624 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2007-11-02 02:03:34 794,624 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2006-11-20 16:38:31 249,856 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2007-11-02 02:03:34 249,856 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2006-11-20 16:38:31 61,440 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2007-11-02 02:03:34 61,440 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-11-20 16:38:32 23,040 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2007-11-02 02:03:34 23,040 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2006-11-20 16:38:31 286,720 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2007-11-02 02:03:34 286,720 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2006-11-20 16:38:31 409,600 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2007-11-02 02:03:34 409,600 —-a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2004-08-04 07:56:41 41,984 —-a-w C:\WINDOWS\msagent\agentdp2.dll
+ 2006-10-12 13:54:18 42,496 —-a-w C:\WINDOWS\msagent\agentdp2.dll
- 2005-04-22 05:06:42 57,344 —-a-w C:\WINDOWS\msagent\agentdpv.dll
+ 2007-03-09 13:58:57 57,344 —-a-w C:\WINDOWS\msagent\agentdpv.dll
- 2004-08-04 07:56:47 256,512 —-a-w C:\WINDOWS\msagent\agentsvr.exe
+ 2006-10-12 11:54:07 256,512 —-a-w C:\WINDOWS\msagent\agentsvr.exe
+ 2006-06-03 11:40:49 33,792 ——w C:\WINDOWS\network diagnostic\custsat.dll
+ 2006-10-10 12:44:50 557,568 ——w C:\WINDOWS\network diagnostic\xpnetdiag.exe
+ 2007-11-02 10:44:07 6,188 —-a-w C:\WINDOWS\SoftwareDistribution\EventCache\{D7137B16-CDB4-46EC-B133-55C707AEEB41}.bin
- 2004-08-04 07:56:41 100,352 —-a-w C:\WINDOWS\system32\6to4svc.dll
+ 2006-08-16 11:58:05 100,352 —-a-w C:\WINDOWS\system32\6to4svc.dll
+ 2007-03-29 13:20:50 110,592 —-a-w C:\WINDOWS\system32\ActiveScan\as.dll
+ 2006-10-05 20:15:26 233,472 —-a-w C:\WINDOWS\system32\ActiveScan\ascontrol.dll
+ 2005-06-03 18:03:18 96,256 —-a-w C:\WINDOWS\system32\ActiveScan\asmdat.dll
+ 2003-08-01 15:00:16 36,864 —-a-w C:\WINDOWS\system32\ActiveScan\certdll.dll
+ 2005-05-20 17:42:44 86,016 —-a-w C:\WINDOWS\system32\ActiveScan\instlsp.dll
+ 2006-02-16 22:20:20 4,608 —-a-w C:\WINDOWS\system32\ActiveScan\memvfile.dll
+ 2005-10-25 22:08:32 348,160 —-a-w C:\WINDOWS\system32\ActiveScan\msvcr71.dll
+ 2004-05-04 19:01:02 139,264 —-a-w C:\WINDOWS\system32\ActiveScan\pavaleas.dll
+ 2006-07-14 17:04:10 45,056 —-a-w C:\WINDOWS\system32\ActiveScan\pavdr.exe
+ 2006-04-10 14:50:02 159,832 —-a-w C:\WINDOWS\system32\ActiveScan\pavexcom.dll
+ 2006-02-14 17:05:38 94,208 —-a-w C:\WINDOWS\system32\ActiveScan\pavinas.dll
+ 2006-02-16 22:35:38 180,224 —-a-w C:\WINDOWS\system32\ActiveScan\pavoe.dll
+ 2006-10-05 20:15:38 122,880 —-a-w C:\WINDOWS\system32\ActiveScan\pavpz.dll
+ 2006-06-30 18:13:38 8,704 —-a-w C:\WINDOWS\system32\ActiveScan\pfdnnt.exe
+ 2004-02-04 18:08:42 49,152 —-a-w C:\WINDOWS\system32\ActiveScan\port32.dll
+ 2006-08-01 17:23:10 69,632 —-a-w C:\WINDOWS\system32\ActiveScan\pscpu.dll
+ 2006-08-23 17:06:08 1,388,544 —-a-w C:\WINDOWS\system32\ActiveScan\pskahk.dll
+ 2006-08-17 15:38:14 10,752 —-a-w C:\WINDOWS\system32\ActiveScan\pskalloc.dll
+ 2006-09-04 15:49:54 61,440 —-a-w C:\WINDOWS\system32\ActiveScan\pskas.dll
+ 2006-08-18 12:46:18 779,264 —-a-w C:\WINDOWS\system32\ActiveScan\pskavs.dll
+ 2007-03-26 18:25:34 417,792 —-a-w C:\WINDOWS\system32\ActiveScan\pskcmp.dll
+ 2006-08-09 14:42:24 90,112 —-a-w C:\WINDOWS\system32\ActiveScan\pskfss.dll
+ 2006-07-19 14:55:58 208,896 —-a-w C:\WINDOWS\system32\ActiveScan\pskhtml.dll
+ 2006-01-20 20:57:00 9,728 —-a-w C:\WINDOWS\system32\ActiveScan\pskmas.dll
+ 2006-05-17 13:50:12 14,336 —-a-w C:\WINDOWS\system32\ActiveScan\pskmdfs.dll
+ 2006-08-16 14:58:12 33,280 —-a-w C:\WINDOWS\system32\ActiveScan\pskpack.dll
+ 2006-06-30 18:42:36 266,240 —-a-w C:\WINDOWS\system32\ActiveScan\pskscs.dll
+ 2006-08-17 18:33:14 62,976 —-a-w C:\WINDOWS\system32\ActiveScan\pskutil.dll
+ 2006-08-08 17:13:10 13,312 —-a-w C:\WINDOWS\system32\ActiveScan\pskvfile.dll
+ 2006-08-18 12:53:08 69,632 —-a-w C:\WINDOWS\system32\ActiveScan\pskvfs.dll
+ 2006-08-18 12:49:50 167,936 —-a-w C:\WINDOWS\system32\ActiveScan\pskvm.dll
+ 2007-04-18 21:16:04 353,840 —-a-w C:\WINDOWS\system32\ActiveScan\psscan.dll
+ 2007-01-22 18:42:48 35,328 —-a-w C:\WINDOWS\system32\ActiveScan\rawvfile.dll
+ 1997-09-18 10:12:32 9,488 —-a-w C:\WINDOWS\system32\ActiveScan\sporder.dll
+ 2006-02-28 21:23:40 69,632 —-a-w C:\WINDOWS\system32\ActiveScan\tcpvfile.dll
- 2004-08-04 07:56:41 99,840 —-a-w C:\WINDOWS\system32\advpack.dll
+ 2007-08-20 10:04:34 124,928 —-a-w C:\WINDOWS\system32\advpack.dll
+ 2006-08-02 16:39:06 73,728 —-a-w C:\WINDOWS\system32\asuninst.exe
- 2006-03-04 03:33:40 1,022,976 —-a-w C:\WINDOWS\system32\browseui.dll
+ 2006-09-23 18:12:50 1,022,976 —-a-w C:\WINDOWS\system32\browseui.dll
- 2005-05-26 09:16:24 75,544 —-a-w C:\WINDOWS\system32\cdm.dll
+ 2007-07-31 00:19:20 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
- 2004-08-04 07:56:41 69,120 —-a-w C:\WINDOWS\system32\ciodm.dll
+ 2006-06-22 05:06:29 69,120 —-a-w C:\WINDOWS\system32\ciodm.dll
- 2004-08-04 07:56:41 611,328 —-a-w C:\WINDOWS\system32\comctl32.dll
+ 2006-08-25 15:45:58 617,472 —-a-w C:\WINDOWS\system32\comctl32.dll
- 2004-08-04 07:56:42 111,104 —-a-w C:\WINDOWS\system32\dhcpcsvc.dll
+ 2006-05-19 12:59:41 111,616 —-a-w C:\WINDOWS\system32\dhcpcsvc.dll
+ 2006-08-16 11:58:05 100,352 -c—-w C:\WINDOWS\system32\dllcache\6to4svc.dll
+ 2007-08-13 23:39:20 71,680 -c—-w C:\WINDOWS\system32\dllcache\admparse.dll
+ 2007-08-20 10:04:34 124,928 -c—-w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2006-10-12 13:54:18 42,496 -c—-w C:\WINDOWS\system32\dllcache\agentdp2.dll
- 2005-04-22 05:06:42 57,344 -c–a-w C:\WINDOWS\system32\dllcache\agentdpv.dll
+ 2007-03-09 13:58:57 57,344 -c–a-w C:\WINDOWS\system32\dllcache\agentdpv.dll
+ 2006-10-12 11:54:07 256,512 -c—-w C:\WINDOWS\system32\dllcache\agentsvr.exe
+ 2006-09-23 18:12:50 1,022,976 -c—-w C:\WINDOWS\system32\dllcache\browseui.dll
- 2005-05-26 09:16:24 75,544 -c–a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2007-07-31 00:19:20 92,504 -c–a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2006-06-22 05:06:29 69,120 -c—-w C:\WINDOWS\system32\dllcache\ciodm.dll
+ 2006-08-25 15:45:58 617,472 -c—-w C:\WINDOWS\system32\dllcache\comctl32.dll
+ 2007-08-13 23:42:54 17,408 -c—-w C:\WINDOWS\system32\dllcache\corpol.dll
+ 2006-05-19 12:59:41 111,616 -c—-w C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
+ 2006-06-26 17:37:10 148,480 -c—-w C:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2007-08-13 23:35:46 346,624 -c—-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2007-08-20 10:04:34 214,528 -c—-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2007-06-13 10:23:07 1,033,216 -c—-w C:\WINDOWS\system32\dllcache\explorer.exe
+ 2007-08-20 10:04:34 132,608 -c—-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2007-06-19 13:31:19 282,112 -c—-w C:\WINDOWS\system32\dllcache\gdi32.dll
- 2004-11-16 21:17:00 68,096 -c–a-w C:\WINDOWS\system32\dllcache\hlink.dll
+ 2006-07-21 08:24:43 72,704 -c–a-w C:\WINDOWS\system32\dllcache\hlink.dll
- 2004-08-04 07:56:42 38,912 -c–a-w C:\WINDOWS\system32\dllcache\hmmapi.dll
+ 2007-08-13 23:18:02 60,416 -c–a-w C:\WINDOWS\system32\dllcache\hmmapi.dll
+ 2007-08-17 10:20:54 63,488 -c—-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2007-08-20 10:04:34 153,088 -c—-w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2007-08-20 10:04:35 230,400 -c—-w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2003-03-31 12:00:00 221,184 -c–a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2007-08-17 07:34:25 161,792 -c—-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2007-08-20 10:04:35 384,512 -c—-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2004-08-04 07:56:50 18,432 -c–a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2007-08-13 23:44:02 69,120 -c–a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2007-08-13 23:45:18 78,336 -c—-w C:\WINDOWS\system32\dllcache\ieencode.dll
+ 2007-08-13 23:54:10 191,488 -c—-w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2007-08-20 10:04:38 44,544 -c—-w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2007-08-13 23:39:12 55,296 -c—-w C:\WINDOWS\system32\dllcache\iesetup.dll
+ 2007-08-17 10:21:21 625,152 -c—-w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2007-08-13 23:36:06 36,352 -c—-w C:\WINDOWS\system32\dllcache\imgutil.dll
+ 2007-08-13 23:39:02 92,672 -c—-w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2006-05-19 12:59:41 94,720 -c—-w C:\WINDOWS\system32\dllcache\iphlpapi.dll
- 2003-03-31 12:00:00 144,896 -c–a-w C:\WINDOWS\system32\dllcache\jgdw400.dll
+ 2006-06-01 18:47:07 163,840 -c–a-w C:\WINDOWS\system32\dllcache\jgdw400.dll
- 2003-03-31 12:00:00 42,496 -c–a-w C:\WINDOWS\system32\dllcache\jgpl400.dll
+ 2006-06-01 18:47:07 27,648 -c–a-w C:\WINDOWS\system32\dllcache\jgpl400.dll
+ 2007-08-13 23:38:04 491,520 -c—-w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2007-08-20 10:04:39 27,648 -c—-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2007-04-16 15:52:53 984,576 -c—-w C:\WINDOWS\system32\dllcache\kernel32.dll
+ 2006-06-14 08:47:45 172,416 -c—-w C:\WINDOWS\system32\dllcache\kmixer.sys
+ 2007-08-13 23:44:18 40,960 -c—-w C:\WINDOWS\system32\dllcache\licmgr10.dll
+ 2006-08-17 12:28:27 721,920 -c—-w C:\WINDOWS\system32\dllcache\lsasrv.dll
+ 2007-03-08 15:36:28 40,960 -c—-w C:\WINDOWS\system32\dllcache\mf3216.dll
- 2003-03-31 12:00:00 924,432 -c–a-w C:\WINDOWS\system32\dllcache\mfc40u.dll
+ 2006-11-01 19:17:45 927,504 -c–a-w C:\WINDOWS\system32\dllcache\mfc40u.dll
+ 2006-10-14 08:13:25 981,760 -c—-w C:\WINDOWS\system32\dllcache\mfc42u.dll
+ 2006-05-05 09:41:45 453,120 -c—-w C:\WINDOWS\system32\dllcache\mrxsmb.sys
+ 2006-12-26 13:07:23 536,576 -c—-w C:\WINDOWS\system32\dllcache\msado15.dll
+ 2006-12-26 13:07:23 180,224 -c—-w C:\WINDOWS\system32\dllcache\msadomd.dll
+ 2006-12-26 13:07:23 200,704 -c—-w C:\WINDOWS\system32\dllcache\msadox.dll
+ 2006-11-27 14:54:06 539,136 -c—-w C:\WINDOWS\system32\dllcache\msftedit.dll
+ 2007-08-13 23:32:30 45,568 -c—-w C:\WINDOWS\system32\dllcache\mshta.exe
+ 2007-08-20 20:34:42 3,584,512 -c—-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2007-08-20 10:04:41 477,696 -c—-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2007-08-13 23:01:12 48,128 -c—-w C:\WINDOWS\system32\dllcache\mshtmler.dll
- 2005-05-04 19:45:32 2,890,240 -c–a-w C:\WINDOWS\system32\dllcache\msi.dll
+ 2007-04-18 16:12:23 2,854,400 -c–a-w C:\WINDOWS\system32\dllcache\msi.dll
+ 2006-12-26 13:07:23 102,400 -c—-w C:\WINDOWS\system32\dllcache\msjro.dll
- 2003-03-31 12:00:00 146,432 -c–a-w C:\WINDOWS\system32\dllcache\msls31.dll
+ 2007-08-13 23:54:10 156,160 -c–a-w C:\WINDOWS\system32\dllcache\msls31.dll
+ 2007-08-20 10:04:41 193,024 -c—-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2007-08-20 10:04:42 671,232 -c—-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2004-08-04 07:56:44 1,236,480 -c–a-w C:\WINDOWS\system32\dllcache\msxml3.dll
+ 2007-06-26 06:08:16 1,104,896 -c–a-w C:\WINDOWS\system32\dllcache\msxml3.dll
+ 2006-08-17 12:28:27 332,288 -c—-w C:\WINDOWS\system32\dllcache\netapi32.dll
+ 2007-02-09 11:10:35 574,464 -c—-w C:\WINDOWS\system32\dllcache\ntfs.sys
+ 2007-02-28 09:08:48 2,136,064 -c—-w C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
+ 2007-02-28 08:38:55 2,057,600 -c—-w C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
+ 2007-02-28 08:38:57 2,015,744 -c—-w C:\WINDOWS\system32\dllcache\ntkrpamp.exe
+ 2007-02-28 09:10:57 2,180,352 -c—-w C:\WINDOWS\system32\dllcache\ntoskrnl.exe
- 2003-03-31 12:00:00 58,880 -c–a-w C:\WINDOWS\system32\dllcache\nwapi32.dll
+ 2006-10-13 12:35:12 64,000 -c–a-w C:\WINDOWS\system32\dllcache\nwapi32.dll
+ 2006-10-13 12:35:12 142,336 -c—-w C:\WINDOWS\system32\dllcache\nwprovau.dll
+ 2006-10-13 10:23:15 163,584 -c—-w C:\WINDOWS\system32\dllcache\nwrdr.sys
+ 2006-10-13 12:35:12 65,536 -c—-w C:\WINDOWS\system32\dllcache\nwwks.dll
+ 2007-08-20 10:04:42 102,400 -c—-w C:\WINDOWS\system32\dllcache\occache.dll
+ 2007-05-17 11:28:05 549,376 -c—-w C:\WINDOWS\system32\dllcache\oleaut32.dll
- 2003-03-31 12:00:00 117,760 -c–a-w C:\WINDOWS\system32\dllcache\oledlg.dll
+ 2006-10-16 16:15:00 122,880 -c–a-w C:\WINDOWS\system32\dllcache\oledlg.dll
+ 2007-08-13 23:36:12 44,544 -c—-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2006-06-22 05:06:30 1,435,648 -c—-w C:\WINDOWS\system32\dllcache\query.dll
+ 2006-06-26 17:37:10 8,192 -c—-w C:\WINDOWS\system32\dllcache\rasadhlp.dll
+ 2006-06-22 10:47:18 181,248 -c—-w C:\WINDOWS\system32\dllcache\rasmans.dll
+ 2006-05-05 09:47:57 174,592 -c—-w C:\WINDOWS\system32\dllcache\rdbss.sys
+ 2006-11-27 14:54:06 433,152 -c—-w C:\WINDOWS\system32\dllcache\riched20.dll
- 2003-03-31 12:00:00 200,064 -c–a-w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2006-07-13 08:48:58 202,240 -c–a-w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2007-04-25 14:21:15 144,896 -c—-w C:\WINDOWS\system32\dllcache\schannel.dll
+ 2006-09-23 18:12:50 1,497,088 -c—-w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2006-12-19 21:52:18 8,453,632 -c—-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2006-09-23 18:12:50 474,112 -c—-w C:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2006-12-19 21:52:18 134,656 -c—-w C:\WINDOWS\system32\dllcache\shsvcs.dll
+ 2006-06-14 08:47:46 6,400 -c—-w C:\WINDOWS\system32\dllcache\splitter.sys
+ 2006-08-14 10:34:41 332,928 -c—-w C:\WINDOWS\system32\dllcache\srv.sys
+ 2006-10-19 13:56:32 713,216 -c—-w C:\WINDOWS\system32\dllcache\sxs.dll
+ 2006-04-20 11:51:50 359,808 -c—-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2006-08-16 09:37:30 225,664 -c—-w C:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2007-04-23 10:32:54 364,160 -c—-w C:\WINDOWS\system32\dllcache\update.sys
+ 2007-02-05 20:17:02 185,344 -c—-w C:\WINDOWS\system32\dllcache\upnphost.dll
+ 2007-08-20 10:04:42 105,984 -c—-w C:\WINDOWS\system32\dllcache\url.dll
+ 2007-08-20 10:04:42 1,152,000 -c—-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2007-03-08 15:36:28 577,536 -c—-w C:\WINDOWS\system32\dllcache\user32.dll
+ 2007-08-13 23:54:10 413,696 -c—-w C:\WINDOWS\system32\dllcache\vbscript.dll
+ 2007-08-13 23:54:10 765,952 -c—-w C:\WINDOWS\system32\dllcache\VGX.dll
+ 2006-06-14 09:00:45 82,944 -c—-w C:\WINDOWS\system32\dllcache\wdmaud.sys
+ 2007-08-20 10:04:42 232,960 -c—-w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2006-12-19 18:16:47 333,824 -c—-w C:\WINDOWS\system32\dllcache\wiaservc.dll
+ 2007-03-08 13:47:48 1,843,584 -c—-w C:\WINDOWS\system32\dllcache\win32k.sys
+ 2007-08-20 10:04:43 824,832 -c—-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2007-03-17 13:43:01 292,864 -c—-w C:\WINDOWS\system32\dllcache\winsrv.dll
+ 2006-08-17 12:28:27 132,096 -c—-w C:\WINDOWS\system32\dllcache\wkssvc.dll
- 2004-09-22 23:46:32 2,362,104 -c–a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
+ 2006-12-07 06:40:49 2,362,184 -c–a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
+ 2007-07-31 00:19:36 549,720 -c–a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2005-05-26 09:16:30 124,184 -c–a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2007-07-31 00:19:16 53,080 -c–a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2005-05-26 09:16:30 1,343,768 -c–a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2007-07-31 00:19:42 1,712,984 -c–a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2007-07-31 00:19:32 325,976 -c–a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2007-07-31 00:18:40 33,624 -c–a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2007-07-31 00:19:28 203,096 -c–a-w C:\WINDOWS\system32\dllcache\wuweb.dll
- 2004-08-04 07:56:42 148,480 —-a-w C:\WINDOWS\system32\dnsapi.dll
+ 2006-06-26 17:37:10 148,480 —-a-w C:\WINDOWS\system32\dnsapi.dll
- 2004-08-04 05:39:36 142,464 —-a-w C:\WINDOWS\system32\drivers\aec.sys
+ 2006-02-15 00:22:26 142,464 —-a-w C:\WINDOWS\system32\drivers\aec.sys
- 2004-08-04 06:01:19 124,800 ——w C:\WINDOWS\system32\drivers\fltmgr.sys
+ 2006-08-21 09:14:58 128,896 ——w C:\WINDOWS\system32\drivers\fltmgr.sys
- 2004-10-08 23:48:21 262,400 ——w C:\WINDOWS\system32\drivers\http.sys
+ 2006-03-17 00:33:10 262,784 ——w C:\WINDOWS\system32\drivers\http.sys
- 2004-08-04 06:07:48 171,776 —-a-w C:\WINDOWS\system32\drivers\kmixer.sys
+ 2006-06-14 08:47:45 172,416 —-a-w C:\WINDOWS\system32\drivers\kmixer.sys
- 2005-01-19 04:26:52 451,584 —-a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
+ 2006-05-05 09:41:45 453,120 —-a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
- 2004-08-04 06:15:09 574,592 —-a-w C:\WINDOWS\system32\drivers\ntfs.sys
+ 2007-02-09 11:10:35 574,464 —-a-w C:\WINDOWS\system32\drivers\ntfs.sys
- 2004-08-04 06:02:22 163,584 —-a-w C:\WINDOWS\system32\drivers\nwrdr.sys
+ 2006-10-13 10:23:15 163,584 —-a-w C:\WINDOWS\system32\drivers\nwrdr.sys
- 2004-10-28 01:13:58 174,592 —-a-w C:\WINDOWS\system32\drivers\rdbss.sys
+ 2006-05-05 09:47:57 174,592 —-a-w C:\WINDOWS\system32\drivers\rdbss.sys
- 2003-03-31 12:00:00 200,064 —-a-w C:\WINDOWS\system32\drivers\RMCast.sys
+ 2006-07-13 08:48:58 202,240 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
- 2004-08-04 06:07:47 6,400 —-a-w C:\WINDOWS\system32\drivers\splitter.sys
+ 2006-06-14 08:47:46 6,400 —-a-w C:\WINDOWS\system32\drivers\splitter.sys
- 2005-05-10 00:17:51 332,544 —-a-w C:\WINDOWS\system32\drivers\srv.sys
+ 2006-08-14 10:34:41 332,928 —-a-w C:\WINDOWS\system32\drivers\srv.sys
- 2006-01-13 02:28:14 359,808 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
+ 2006-04-20 11:51:50 359,808 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
- 2004-08-04 06:07:45 223,616 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
+ 2006-08-16 09:37:30 225,664 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
- 2004-08-04 05:58:32 209,408 —-a-w C:\WINDOWS\system32\drivers\update.sys
+ 2007-04-23 10:32:54 364,160 —-a-w C:\WINDOWS\system32\drivers\update.sys
- 2004-08-04 06:15:04 82,944 —-a-w C:\WINDOWS\system32\drivers\wdmaud.sys
+ 2006-06-14 09:00:45 82,944 —-a-w C:\WINDOWS\system32\drivers\wdmaud.sys
- 2004-08-04 07:56:42 357,888 —-a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2007-08-13 23:35:46 346,624 —-a-w C:\WINDOWS\system32\dxtmsft.dll
- 2006-03-04 03:33:41 205,312 —-a-w C:\WINDOWS\system32\dxtrans.dll
+ 2007-08-20 10:04:34 214,528 ——w C:\WINDOWS\system32\dxtrans.dll
- 2006-03-04 03:33:41 55,808 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-08-20 10:04:34 132,608 ——w C:\WINDOWS\system32\extmgr.dll
- 2004-08-04 07:56:42 16,896 —-a-w C:\WINDOWS\system32\fltlib.dll
+ 2006-08-21 12:21:06 16,896 —-a-w C:\WINDOWS\system32\fltlib.dll
- 2004-08-04 07:56:49 22,528 —-a-w C:\WINDOWS\system32\fltmc.exe
+ 2006-08-21 09:14:58 23,040 —-a-w C:\WINDOWS\system32\fltmc.exe
- 2007-10-19 22:25:50 465,208 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2007-11-02 11:39:24 465,208 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2005-12-29 02:54:35 280,064 —-a-w C:\WINDOWS\system32\gdi32.dll
+ 2007-06-19 13:31:19 282,112 —-a-w C:\WINDOWS\system32\gdi32.dll
- 2004-11-16 21:17:00 68,096 —-a-w C:\WINDOWS\system32\hlink.dll
+ 2006-07-21 08:24:43 72,704 —-a-w C:\WINDOWS\system32\hlink.dll
+ 2007-08-20 10:04:34 63,488 —-a-w C:\WINDOWS\system32\icardie.dll
+ 2006-06-29 13:05:44 26,112 ——w C:\WINDOWS\system32\idndl.dll
- 2004-08-04 07:56:50 34,304 —-a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2007-08-17 10:20:54 63,488 ——w C:\WINDOWS\system32\ie4uinit.exe
- 2004-08-04 07:56:42 139,264 —-a-w C:\WINDOWS\system32\ieakeng.dll
+ 2007-08-20 10:04:34 153,088 ——w C:\WINDOWS\system32\ieakeng.dll
- 2004-08-04 07:56:42 216,576 —-a-w C:\WINDOWS\system32\ieaksie.dll
+ 2007-08-20 10:04:35 230,400 ——w C:\WINDOWS\system32\ieaksie.dll
- 2003-03-31 12:00:00 221,184 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-08-17 07:34:25 161,792 ——w C:\WINDOWS\system32\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w C:\WINDOWS\system32\ieapfltr.dat
+ 2007-08-20 10:04:35 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
- 2004-08-04 07:56:42 323,584 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-08-20 10:04:35 384,512 ——w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-08-20 10:04:37 6,058,496 —-a-w C:\WINDOWS\system32\ieframe.dll
- 2006-03-04 03:33:41 251,392 —-a-w C:\WINDOWS\system32\iepeers.dll
+ 2007-08-13 23:54:10 191,488 —-a-w C:\WINDOWS\system32\iepeers.dll
- 2004-08-04 07:56:42 48,640 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-20 10:04:38 44,544 ——w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-20 10:04:38 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll
+ 2007-08-17 10:20:54 13,824 —-a-w C:\WINDOWS\system32\ieudinit.exe
+ 2007-08-13 23:54:10 180,736 ——w C:\WINDOWS\system32\ieui.dll
- 2006-03-04 03:33:41 96,256 —-a-w C:\WINDOWS\system32\inseng.dll
+ 2007-08-13 23:39:02 92,672 —-a-w C:\WINDOWS\system32\inseng.dll
- 2004-08-04 07:56:42 94,720 —-a-w C:\WINDOWS\system32\iphlpapi.dll
+ 2006-05-19 12:59:41 94,720 —-a-w C:\WINDOWS\system32\iphlpapi.dll
- 2003-03-31 12:00:00 144,896 —-a-w C:\WINDOWS\system32\jgdw400.dll
+ 2006-06-01 18:47:07 163,840 —-a-w C:\WINDOWS\system32\jgdw400.dll
- 2003-03-31 12:00:00 42,496 —-a-w C:\WINDOWS\system32\jgpl400.dll
+ 2006-06-01 18:47:07 27,648 —-a-w C:\WINDOWS\system32\jgpl400.dll
- 2004-08-04 07:56:42 450,560 —-a-w C:\WINDOWS\system32\jscript.dll
+ 2007-08-13 23:38:04 491,520 —-a-w C:\WINDOWS\system32\jscript.dll
- 2004-08-04 07:56:42 15,872 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2007-08-20 10:04:39 27,648 ——w C:\WINDOWS\system32\jsproxy.dll
- 2004-08-04 07:56:42 983,552 —-a-w C:\WINDOWS\system32\kernel32.dll
+ 2007-04-16 15:52:53 984,576 —-a-w C:\WINDOWS\system32\kernel32.dll
- 2004-10-28 01:21:01 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
+ 2006-08-17 12:28:27 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
- 2004-08-04 07:56:42 39,936 —-a-w C:\WINDOWS\system32\mf3216.dll
+ 2007-03-08 15:36:28 40,960 —-a-w C:\WINDOWS\system32\mf3216.dll
- 2003-03-31 12:00:00 924,432 —-a-w C:\WINDOWS\system32\mfc40u.dll
+ 2006-11-01 19:17:45 927,504 —-a-w C:\WINDOWS\system32\mfc40u.dll
- 2004-08-04 07:56:42 1,024,000 —-a-w C:\WINDOWS\system32\mfc42u.dll
+ 2006-10-14 08:13:25 981,760 —-a-w C:\WINDOWS\system32\mfc42u.dll
- 2005-07-26 04:39:46 425,472 —-a-w C:\WINDOWS\system32\msdtcprx.dll
+ 2006-03-01 19:42:42 426,496 —-a-w C:\WINDOWS\system32\msdtcprx.dll
- 2005-07-26 04:39:47 945,152 —-a-w C:\WINDOWS\system32\msdtctm.dll
+ 2006-03-01 19:42:42 956,416 —-a-w C:\WINDOWS\system32\msdtctm.dll
- 2005-07-26 04:39:47 161,280 —-a-w C:\WINDOWS\system32\msdtcuiu.dll
+ 2006-03-01 19:42:42 161,280 —-a-w C:\WINDOWS\system32\msdtcuiu.dll
+ 2007-08-20 10:04:39 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll
+ 2007-08-20 10:04:39 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2007-08-13 23:36:40 12,288 ——w C:\WINDOWS\system32\msfeedssync.exe
- 2004-08-04 07:56:43 537,088 —-a-w C:\WINDOWS\system32\msftedit.dll
+ 2006-11-27 14:54:06 539,136 —-a-w C:\WINDOWS\system32\msftedit.dll
- 2006-03-23 20:32:42 3,053,568 —-a-w C:\WINDOWS\system32\mshtml.dll
+ 2007-08-20 20:34:42 3,584,512 —-a-w C:\WINDOWS\system32\mshtml.dll
- 2006-03-04 03:33:43 448,512 —-a-w C:\WINDOWS\system32\mshtmled.dll
+ 2007-08-20 10:04:41 477,696 ——w C:\WINDOWS\system32\mshtmled.dll
- 2005-05-04 19:45:32 2,890,240 —-a-w C:\WINDOWS\system32\msi.dll
+ 2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
- 2006-03-04 03:33:43 146,432 —-a-w C:\WINDOWS\system32\msrating.dll
+ 2007-08-20 10:04:41 193,024 ——w C:\WINDOWS\system32\msrating.dll
- 2006-03-04 03:33:43 532,480 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2007-08-20 10:04:42 671,232 ——w C:\WINDOWS\system32\mstime.dll
- 2004-08-04 07:56:44 1,236,480 —-a-w C:\WINDOWS\system32\msxml3.dll
+ 2007-06-26 06:08:16 1,104,896 —-a-w C:\WINDOWS\system32\msxml3.dll
- 2005-07-26 04:39:47 66,560 —-a-w C:\WINDOWS\system32\mtxclu.dll
+ 2006-03-01 19:42:42 66,560 —-a-w C:\WINDOWS\system32\mtxclu.dll
- 2005-07-26 04:39:47 91,136 —-a-w C:\WINDOWS\system32\mtxoci.dll
+ 2006-03-01 19:42:42 91,136 —-a-w C:\WINDOWS\system32\mtxoci.dll
- 2005-05-26 08:16:24 127,208 —-a-w C:\WINDOWS\system32\mucltui.dll
+ 2007-07-31 00:19:10 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
- 2005-05-26 08:19:32 178,408 —-a-w C:\WINDOWS\system32\muweb.dll
+ 2007-07-31 00:19:04 207,736 —-a-w C:\WINDOWS\system32\muweb.dll
- 2004-08-04 07:56:44 332,288 —-a-w C:\WINDOWS\system32\netapi32.dll
+ 2006-08-17 12:28:27 332,288 —-a-w C:\WINDOWS\system32\netapi32.dll
+ 2006-06-28 22:59:26 24,576 ——w C:\WINDOWS\system32\nlsdl.dll
+ 2006-06-29 13:05:44 23,552 ——w C:\WINDOWS\system32\normaliz.dll
- 2005-03-02 00:34:40 2,056,832 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
+ 2007-02-28 08:38:55 2,057,600 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
- 2005-03-02 00:59:53 2,179,328 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
+ 2007-02-28 09:10:57 2,180,352 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
- 2003-03-31 12:00:00 58,880 —-a-w C:\WINDOWS\system32\nwapi32.dll
+ 2006-10-13 12:35:12 64,000 —-a-w C:\WINDOWS\system32\nwapi32.dll
- 2004-08-04 07:56:44 144,384 —-a-w C:\WINDOWS\system32\nwprovau.dll
+ 2006-10-13 12:35:12 142,336 —-a-w C:\WINDOWS\system32\nwprovau.dll
- 2005-08-11 15:09:59 65,024 —-a-w C:\WINDOWS\system32\nwwks.dll
+ 2006-10-13 12:35:12 65,536 —-a-w C:\WINDOWS\system32\nwwks.dll
- 2004-08-04 07:56:44 96,256 —-a-w C:\WINDOWS\system32\occache.dll
+ 2007-08-20 10:04:42 102,400 ——w C:\WINDOWS\system32\occache.dll
- 2004-08-04 07:56:44 553,472 —-a-w C:\WINDOWS\system32\oleaut32.dll
+ 2007-05-17 11:28:05 549,376 —-a-w C:\WINDOWS\system32\oleaut32.dll
- 2003-03-31 12:00:00 117,760 —-a-w C:\WINDOWS\system32\oledlg.dll
+ 2006-10-16 16:15:00 122,880 —-a-w C:\WINDOWS\system32\oledlg.dll
- 2007-11-01 23:43:09 40,836 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-02 11:41:01 40,836 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-01 23:43:09 314,508 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-02 11:41:01 314,508 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2006-03-04 03:33:43 39,424 —-a-w C:\WINDOWS\system32\pngfilt.dll
+ 2007-08-13 23:36:12 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll
- 2004-08-04 07:56:44 1,435,648 —-a-w C:\WINDOWS\system32\query.dll
+ 2006-06-22 05:06:30 1,435,648 —-a-w C:\WINDOWS\system32\query.dll
- 2004-08-04 07:56:44 8,192 —-a-w C:\WINDOWS\system32\rasadhlp.dll
+ 2006-06-26 17:37:10 8,192 —-a-w C:\WINDOWS\system32\rasadhlp.dll
- 2004-08-04 07:56:44 174,080 —-a-w C:\WINDOWS\system32\rasmans.dll
+ 2006-06-22 10:47:18 181,248 —-a-w C:\WINDOWS\system32\rasmans.dll
- 2004-08-04 07:56:44 431,616 —-a-w C:\WINDOWS\system32\riched20.dll
+ 2006-11-27 14:54:06 433,152 —-a-w C:\WINDOWS\system32\riched20.dll
- 2004-08-04 07:56:44 581,120 —-a-w C:\WINDOWS\system32\rpcrt4.dll
+ 2007-07-09 13:16:16 582,656 —-a-w C:\WINDOWS\system32\rpcrt4.dll
- 2004-08-04 07:56:44 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
+ 2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
- 2006-03-30 09:16:03 1,492,480 —-a-w C:\WINDOWS\system32\shdocvw.dll
+ 2006-09-23 18:12:50 1,497,088 —-a-w C:\WINDOWS\system32\shdocvw.dll
- 2006-03-17 04:03:54 8,452,096 —-a-w C:\WINDOWS\system32\shell32.dll
+ 2006-12-19 21:52:18 8,453,632 —-a-w C:\WINDOWS\system32\shell32.dll
- 2006-03-04 03:33:44 474,112 —-a-w C:\WINDOWS\system32\shlwapi.dll
+ 2006-09-23 18:12:50 474,112 —-a-w C:\WINDOWS\system32\shlwapi.dll
- 2004-08-04 07:56:45 134,656 —-a-w C:\WINDOWS\system32\shsvcs.dll
+ 2006-12-19 21:52:18 134,656 —-a-w C:\WINDOWS\system32\shsvcs.dll
+ 2007-07-31 00:18:40 33,624 —-a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
+ 2007-07-31 00:19:12 43,352 —-a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.381\wups2.dll
- 2005-10-12 23:12:25 14,048 —-a-w C:\WINDOWS\system32\spmsg.dll
+ 2006-01-19 19:29:19 14,048 ——w C:\WINDOWS\system32\spmsg.dll
- 2005-06-28 13:21:34 22,752 —-a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2005-06-28 15:21:34 22,752 —-a-w C:\WINDOWS\system32\spupdsvc.exe
- 2007-07-22 23:39:27 279,552 —-a-w C:\WINDOWS\system32\swreg.exe
+ 2007-07-22 22:39:27 279,552 —-a-w C:\WINDOWS\system32\swreg.exe
- 2004-08-04 07:56:46 713,216 —-a-w C:\WINDOWS\system32\sxs.dll
+ 2006-10-19 13:56:32 713,216 —-a-w C:\WINDOWS\system32\sxs.dll
+ 2007-07-18 12:42:22 60,416 ——w C:\WINDOWS\system32\tzchange.exe
- 2004-08-04 07:56:46 185,344 —-a-w C:\WINDOWS\system32\upnphost.dll
+ 2007-02-05 20:17:02 185,344 —-a-w C:\WINDOWS\system32\upnphost.dll
- 2004-08-04 07:56:46 37,888 —-a-w C:\WINDOWS\system32\url.dll
+ 2007-08-20 10:04:42 105,984 —-a-w C:\WINDOWS\system32\url.dll
- 2006-03-18 11:09:37 613,376 —-a-w C:\WINDOWS\system32\urlmon.dll
+ 2007-08-20 10:04:42 1,152,000 —-a-w C:\WINDOWS\system32\urlmon.dll
- 2005-03-02 18:09:30 577,024 —-a-w C:\WINDOWS\system32\user32.dll
+ 2007-03-08 15:36:28 577,536 —-a-w C:\WINDOWS\system32\user32.dll
- 2004-08-04 07:56:46 49,152 —-a-w C:\WINDOWS\system32\wdigest.dll
+ 2006-03-24 04:37:50 49,152 —-a-w C:\WINDOWS\system32\wdigest.dll
- 2004-08-04 07:56:46 276,480 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-08-20 10:04:42 232,960 —-a-w C:\WINDOWS\system32\webcheck.dll
- 2004-08-04 07:56:46 333,312 —-a-w C:\WINDOWS\system32\wiaservc.dll
+ 2006-12-19 18:16:47 333,824 —-a-w C:\WINDOWS\system32\wiaservc.dll
- 2005-10-06 00:05:59 1,839,488 —-a-w C:\WINDOWS\system32\win32k.sys
+ 2007-03-08 13:47:48 1,843,584 —-a-w C:\WINDOWS\system32\win32k.sys
+ 2007-08-13 23:45:16 206,336 ——w C:\WINDOWS\system32\WinFXDocObj.exe
- 2006-03-04 03:33:45 658,432 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2007-08-20 10:04:43 824,832 —-a-w C:\WINDOWS\system32\wininet.dll
- 2005-09-01 01:41:54 291,840 —-a-w C:\WINDOWS\system32\winsrv.dll
+ 2007-03-17 13:43:01 292,864 —-a-w C:\WINDOWS\system32\winsrv.dll
- 2004-08-04 07:56:46 132,096 —-a-w C:\WINDOWS\system32\wkssvc.dll
+ 2006-08-17 12:28:27 132,096 —-a-w C:\WINDOWS\system32\wkssvc.dll
- 2006-03-10 10:09:14 5,533,696 —-a-w C:\WINDOWS\system32\wmp.dll
+ 2007-04-30 13:20:24 5,537,792 —-a-w C:\WINDOWS\system32\wmp.dll
- 2004-09-22 23:46:32 2,362,104 —-a-w C:\WINDOWS\system32\wmvcore.dll
+ 2006-12-07 06:40:49 2,362,184 —-a-w C:\WINDOWS\system32\wmvcore.dll
- 2005-05-26 09:16:30 465,176 —-a-w C:\WINDOWS\system32\wuapi.dll
+ 2007-07-31 00:19:36 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
- 2005-05-26 09:16:30 124,184 —-a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-07-31 00:19:16 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
- 2005-05-26 09:16:30 1,343,768 —-a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-31 00:19:42 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
- 2005-05-26 09:16:30 127,256 —-a-w C:\WINDOWS\system32\wucltui.dll
+ 2007-07-31 00:19:32 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
- 2005-05-26 09:16:30 41,240 —-a-w C:\WINDOWS\system32\wups.dll
+ 2007-07-31 00:18:40 33,624 —-a-w C:\WINDOWS\system32\wups.dll
- 2005-05-26 09:16:30 18,200 —-a-w C:\WINDOWS\system32\wups2.dll
+ 2007-07-31 00:19:12 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
- 2005-05-26 09:19:32 173,536 —-a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-31 00:19:28 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
+ 2006-07-14 15:51:52 121,856 ——w C:\WINDOWS\system32\xmllite.dll
- 2005-07-26 04:39:49 11,776 —-a-w C:\WINDOWS\system32\xolehlp.dll
+ 2006-03-01 19:42:42 11,776 —-a-w C:\WINDOWS\system32\xolehlp.dll
- 2006-03-30 01:00:14 16,384 —-a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-06-19 07:24:36 350,720 —-a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2003-03-25 22:53:50 11,776 —-a-w C:\WINDOWS\system32\ZPORT4AS.dll
+ 2007-01-19 20:15:24 74,802 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2007-01-19 20:15:24 995,383 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2007-01-19 20:15:24 1,011,774 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2007-01-19 20:15:24 401,462 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2006-08-25 15:45:55 1,054,208 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-01-15 08:54]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
"PlaxoUpdate"="C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe" -a

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Logitech Utility"=Logi_MwX.Exe

R2 miasvc;3Dlabs LMM;C:\WINDOWS\system32\MiaSvc.exe
R2 Sense3;Sense3;C:\WINDOWS\system32\Drivers\sense3.sys
R3 miranda;miranda;C:\WINDOWS\system32\DRIVERS\3dlMP.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 USBLOCK;Senselock USB Lock driver;C:\WINDOWS\system32\Drivers\usblock.sys
S3 akshasp;Aladdin HASP Key;C:\WINDOWS\system32\DRIVERS\akshasp.sys
S3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
S3 WmHidLo;Logitech Gaming USB Filter Driver;C:\WINDOWS\system32\drivers\WmHidLo.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
S3 yukonx86;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\yukonx86.sys

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53fec509-020a-11dc-bf91-0016b657555f}]
AutoRun\command - F:\LaunchU3.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-10-18 07:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\Adware\AdwareAlert.exe
"2007-10-07 02:04:09 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2200 series#1188525803.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-02 08:41:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-02 8:42:29
C:\ComboFix2.txt … 2007-11-01 19:54
C:\ComboFix3.txt … 2007-11-01 08:00
.
— E O F —

Here is the Panda scan, I think I did it right…
Incident Status Location

Adware:adware/memorywatcher Not disinfected Windows Registry
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.ads.addynamix.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[.2o7.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jewel\Application Data\Mozilla\Firefox\Profiles\zmxrf6sm.default\cookies.txt[ad.yieldmanager.com/]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Jewel\Desktop\ComboFix.exe[nircmd.exe]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Jewel\Desktop\ComboFix.exe[nircmd.cfexe]
Hacktool:HackTool/Samdump Not disinfected C:\junk\XP Pro.zip[Make XP Pro Genuine/Port_RockXP_v4.exe]
Virus:Generic Trojan Disinfected C:\Program Files\GlobalSCAPE\CuteFTP Professional\patch.exe
Virus:W32/Nuwar.C.worm Disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\efcabab.dll.vir
Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\hlqxgtuj.dll.vir
Virus:Trj/Agent.EOC Disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\iemm.dll.vir
Potentially unwanted tool:Application/Pskill.A Not disinfected C:\qoobox\Quarantine\C\WINDOWS\system32\pskill.exe.vir
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe
Virus:Trj/Agent.EOC Disinfected C:\WINDOWS\system32\iemm.dll_
Virus:Trj/Agent.EOC Disinfected C:\WINDOWS\system32\setup192.exe
Hacktool:HackTool/CrackSearch.A Not disinfected H:\Sys_Bckup_Jan12_07\Metrology Solutions Inc\GD & T and CMM stuff\Searcher.zip[CrackSearcher.exe]
Hacktool:HackTool/CrackSearch.A Not disinfected H:\Sys_Bckup_Jan12_07\Server\carp**\Searcher.zip[CrackSearcher.exe]
Hacktool:HackTool/CrackSearch.A Not disinfected H:\Server Aug27_07\Metrology Solutions Inc\GD & T and CMM stuff\Searcher.zip[CrackSearcher.exe]
Hacktool:HackTool/CrackSearch.A Not disinfected H:\Server Aug27_07\Server\carp**\Searcher.zip[CrackSearcher.exe]


It would appear there is still detection of the Virtumonde Hijack…What the Heck ?

Thanks much AGAIN !

Jim
Oops, sorry. Here it is :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:13:13 AM, on 11/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\MiaSvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131536962468
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144933503406
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: MagicTuneEngine - Unknown owner - C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
O23 - Service: 3Dlabs LMM (miasvc) - Unknown owner - C:\WINDOWS\system32\MiaSvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 5049 bytes
Hi,

I am happy to hear that you have IE7 working and that the Windows updates are done. The HijackThis log is clean. Panda report indicates that you have downloaded some crack programs. I think we now know how you may have gotten infected…. visiting crack sites……. The rest are some tracking cookies.

Delete the following infected files using Windows Explorer to located them (right click on Start, click on Explore):

C:\junk\XP Pro.zip
Not disinfected H:\Sys_Bckup_Jan12_07\Metrology Solutions Inc\GD & T and CMM stuff\Searcher.zip
H:\Sys_Bckup_Jan12_07\Server\carp**\Searcher.zip
H:\Server Aug27_07\Metrology Solutions Inc\GD & T and CMM stuff\Searcher.zip
H:\Server Aug27_07\Server\carp**\Searcher.zip

=========================================

Please download Ccleaner and save it to your desktop
.
Tutorial for CCleaner

Set Options in CCleaner and run Cleaning Scan. Open the CCleaner program.

( Do not use the Registry block to clean anything with this program. It is for experts only and it is risky).
  • Select Cleaner block and Windows tab

    Check all items under Internet Explorer, except Auto Complete Form History; everything under Windows Explorer; and everything under System except Memory Dump and Windows Log Files. In the Advanced section, have a check only on Old PreFetch Data.
  • Click on the Options block on the left. Select Advanced.
    Uncheck "Only delete files in Windows Temp folders older than 48 hours".
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Run Cleaning Scan. Click on the Cleaner block on the left. Choose the Windows tab.
    Click the Run Cleaner button. This process could take a while. When CCleaner shows how much has been removed, cleaning is finished.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button. Check "Only delete files in Windows Temp folders older than 48 hours".
Please run Ccleaner with the above settings for each user account.

========================================

Let me know if you run into any problems. Otherwise, continue with the following steps to finish up:
  • Click Start then Run
  • Now type Combofix /u in the runbox and click OK. Notice the space between the x and the /u

    [external image: Posted Image]

    This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore to prevent reinfection from old restore points.
Here are some steps to make your surfing more secure in future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:

From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Avoid illegal sites, because that's where most malware is present.

* Don't click on links inside popups.
* Don't click on links in spam messages claiming to offer anti-spyware software; because most of these so called removers ARE spyware.
* Download free software only from sites you know and trust. Because a lot of free software can bundle other software, including spyware.

Keep your antivirus-program up-to-date and do regular scans with it. Please make sure that you have only one active antivirus program on your system.

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site http://windowsupdate.microsoft.com/ to get the critical updates.

If you are running Microsoft, or any portion thereof, go to the Microsoft's Office Update site http://office.microsoft.com/officeupdate/m…g.aspx?lc=en-us and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

Keep your pestware-scanners up-to-date and do regular scans with them.

To keep your computer free of Spyware, Adware, Hijackers etc., download and install the following free pestware-scanners (if you haven't installed them already):
AdAwareA tutorial on installing & using this product can be found here: http://www.bleepingcomputer.com/forums/tutorial43.html
Spybot A tutorial on installing & using this product can be found here: http://www.bleepingcomputer.com/forums/tutorial43.html
Windows Defender here

The following free realtime pestscanners prevent a number of malware-variants from entering your computer, in the first place:

SpywareBlaster A tutorial on installing & using this product can be found here: http://www.bleepingcomputer.com/forums/tutorial49.html
SpywareGuard here

If you haven't got one, already, install a firewall and keep it up-to-date. Please make sure that you have only one active firewall on your system.

A firewall will prevent unauthorized contact between your computer and internet. A tutorial on Firewalls and a listing of some available ones can be found here:
http://forum.malwareremoval.com/viewtopic.php?p=56#56
http://www.bleepingcomputer.com/forums/tutorial60.html

Test your firewall here to make sure that it's working properly

Install these programs, to make surfing with Internet Explorer safer:

A popup-blocker, e.g. Google Toolbar here: A popup-blocker prevents popup-windows from opening, when you come along a websites that uses them, during internet-surfing. To provide privacy, select disable advanced features when installing.

IE-SPYAD This utility adds a long list of known bad sites to Internet Explorer's Restricted Sites zone. This prevents those sites from executing their malicious programs on your computer. A tutorial on installing this product can be found here: http://www.spywarewarrior.com/uiuc/resource.htm

SiteHound by Firetrust introduces the SiteHound Toolbar - the safe way to browse the Internet. With SiteHound, when you browse the Internet, you're shown a warning page every time you go to a site which is a known scam, potentially loads viruses or spyware on to your computer, has questionable content or anything you would not consider reasonable.
This product can be downloaded from here: here:

Install and use an alternative browser to surf on the internet.

Because Internet Explorer is the most-used browser on the planet, most of the hijackers, adware and spyware are made to abuse your computer thru Internet Explorer.
Here are some good alternative browsers:
Mozilla Suite here
Mozilla Firefox here
Opera here
Netscape here
Important: You can not uninstall Internet Explorer.
First of all, it's part of Windows and you'll need it to download and install Windows Updates.
Secondly, There are some sites that are only accessable with Internet Explorer, e.g. most of the Online Malware-scanners.

But above all, keep all your software UP-TO-DATE at all time!!

A colleague of ours has excellent information and tips on the prevention of malware here and more on improving speed/system performance after malware removal here .

If you want to fight back the Malware Writers, please take a look here and read what you can do against it.

Please respond to this thread one more time so we can mark this thread as resolved.

Happy Surfing! :)
Wow ! That was a lot of work, on your part. Thank you for sticking with me and helping me fix this problem. Thank you doesn't seem enough for a total stranger to help another stranger out for free ! Its ppl like you that make this world a better place. Not to be outdone, I paid for the coffees of the ppl behind me at Tim Hortons yesterday !! I had to pass on your kindness. Sincerest Regards, Jim
You're very welcome. Glad I could help.

Not to be outdone, I paid for the coffees of the ppl behind me at Tim Hortons yesterday !!

:lol: Wish I were the ppl behind you. :lol:

Stay safe! :)
Since your problem appears to be resolved, this thread will now be closed. If you need this topic reopened, please PM me with the address of the thread, and we will reopen it for you. This applies only to the original topic starter. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI