This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] msn virus

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello

Open notepad and copy/paste the text in the quotebox below into it:
http://forums.whatthetech.com/msn_virus_t96394.html

Collect::
C:\WINDOWS\system32\quejoosoo.exe
C:\WINDOWS\system32\quejoosoo.zip
C:\WINDOWS\system32\hougiwa.exe
C:\WINDOWS\system32\lekohi.exe

File::
C:\Program Files\RngInterstitial.dll

Driver::
aalfeia8ebf8tti

KillAll::

Sysrst::

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]

Folder::
C:\Program Files\RelevantKnowledge
C:\Program Files\Free Offers from Freeze.com
Suspect::
Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
  • A browser will open.
  • Simply follow the instructions to copy/paste/send the requested file.
ComboFix 08-10-27.05 - Home 2008-10-28 14:10:52.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.253 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Home\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Program Files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\quejoosoo.exe
.
—- Previous Run ——-
.
C:\Program Files\Free Offers from Freeze.com
C:\Program Files\Free Offers from Freeze.com\3766.url
C:\Program Files\Free Offers from Freeze.com\3773.url
C:\Program Files\Free Offers from Freeze.com\4416.url
C:\Program Files\Free Offers from Freeze.com\control.txt
C:\Program Files\Free Offers from Freeze.com\RegistryHelperINT2.ico
C:\Program Files\Free Offers from Freeze.com\wfallsaw.ico
C:\Program Files\Free Offers from Freeze.com\whalesico.ico
C:\Program Files\RelevantKnowledge
C:\Program Files\RelevantKnowledge\rloci.bin
C:\Program Files\RelevantKnowledge\rlservice.exe
C:\Program Files\RelevantKnowledge\rlvknlg.exe
C:\Program Files\RelevantKnowledge\sporder.dll
C:\Program Files\RngInterstitial.dll
C:\WINDOWS\system32\hougiwa.exe
C:\WINDOWS\system32\quejoosoo.exe
C:\WINDOWS\system32\quejoosoo.zip

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_AALFEIA8EBF8TTI
——-\Service_aalfeia8ebf8tti


((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 )))))))))))))))))))))))))))))))
.

2008-10-28 12:56 . 2008-10-28 13:48 960 –a—— C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-10-27 03:18 . 2008-10-14 23:37 233,472 –a—— C:\WINDOWS\system32\bouceh.exe
2008-10-27 03:05 . 2008-10-27 03:05 d——– C:\_OTScanIt
2008-10-23 08:38 . 2008-10-23 08:38 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-23 06:21 . 2008-10-23 06:21 d——– C:\Program Files\RegCure
2008-10-23 06:20 . 2008-10-23 06:20 d–h-c— C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-10-23 04:48 . 2008-10-23 04:48 d——– C:\New Folder
2008-10-23 03:40 . 2008-10-23 03:45 d——– C:\regres
2008-10-23 03:40 . 2008-10-23 03:45 720,896 –a—— C:\WINDOWS\iun6002.exe
2008-10-21 09:56 . 2008-10-21 09:56 d——– C:\My Drivers
2008-10-21 09:55 . 2008-10-21 09:55 d——– C:\Program Files\JerMar Software Corp
2008-10-21 09:55 . 2001-11-29 08:57 110,592 –a—— C:\WINDOWS\system32\ccrpbds6.dll
2008-10-20 23:09 . 2008-07-18 21:07 210,976 –a—— C:\WINDOWS\system32\muweb.dll
2008-10-20 18:56 . 2008-10-20 21:57 d——– C:\Program Files\jZip
2008-10-20 18:15 . 2008-10-20 18:15 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-10-20 17:52 . 2008-10-20 17:52 d——– C:\Program Files\7-Zip
2008-10-20 05:00 . 2008-10-20 05:00 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-20 05:00 . 2008-10-20 05:00 d——– C:\Documents and Settings\Home\Application Data\Malwarebytes
2008-10-20 05:00 . 2008-10-20 05:00 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-20 05:00 . 2008-10-16 19:25 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-20 05:00 . 2008-10-16 19:25 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-15 17:46 . 2008-10-18 18:39 d——– C:\Documents and Settings\Home\Application Data\EurekaLog
2008-10-15 15:54 . 2008-10-15 16:00 d——– C:\N360_BACKUP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 14:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-10-28 14:20 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-10-28 08:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-28 03:16 ——— d—–w C:\Documents and Settings\Home\Application Data\OpenOffice.org2
2008-10-27 02:25 ——— d—–w C:\Program Files\GSC
2008-10-26 12:56 ——— d—–w C:\Program Files\Veoh Networks
2008-10-26 04:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\SITEguard
2008-10-26 03:52 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-10-24 02:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-21 09:55 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-10-20 18:12 ——— d—–w C:\Program Files\Real
2008-10-20 18:12 ——— d—–w C:\Program Files\Common Files\Real
2008-10-20 17:52 ——— d—–w C:\Program Files\Yahoo!
2008-10-19 07:00 ——— d—–w C:\Documents and Settings\Home\Application Data\AVG7
2008-10-15 03:27 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-15 03:22 ——— d—–w C:\Program Files\Spyware Doctor
2008-10-11 15:57 ——— d—–w C:\Program Files\Norton 360
2008-10-09 21:11 ——— d—–w C:\Program Files\Picasa2
2008-10-06 21:21 ——— d—–w C:\Program Files\Google
2008-09-26 13:08 304,160 —-a-w C:\StiImg.dat
2008-09-24 04:44 ——— d—–w C:\Program Files\Perfect Uninstaller
2008-09-24 04:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-24 04:17 ——— d—–w C:\Program Files\AIM6
2008-09-24 04:17 ——— d—–w C:\Documents and Settings\Home\Application Data\acccore
2008-09-24 04:16 ——— d—–w C:\Program Files\Viewpoint
2008-09-24 04:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-24 04:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-09-24 04:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\acccore
2008-09-24 04:15 ——— d—–w C:\Program Files\Common Files\AOL
2008-09-16 17:09 30,080 —-a-w C:\WINDOWS\system32\drivers\RKHit.sys
2008-09-15 17:19 ——— d—–w C:\Program Files\RegistryCleanerPro
2008-09-15 17:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2008-09-13 05:44 ——— d—–w C:\Program Files\BitZipperSearch
2008-09-13 03:09 ——— d—–w C:\Documents and Settings\Home\Application Data\RegFixPro
2008-09-13 01:58 ——— d—–w C:\Program Files\Conduit
2008-09-13 01:58 ——— d—–w C:\Program Files\BitZipper
2008-09-13 01:24 ——— d—–w C:\Documents and Settings\Home\Application Data\BitZipper
2008-09-13 00:36 ——— d—–w C:\Program Files\Realtek AC97
2008-09-11 22:59 ——— d—–w C:\Program Files\Intel
2008-09-11 21:52 ——— d—–w C:\Program Files\PC Drivers HeadQuarters
2008-09-11 21:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-11 11:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-11 11:18 ——— d—–w C:\Program Files\Canon
2008-09-11 10:53 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-09-11 10:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-10 21:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-09-10 20:30 ——— d—–w C:\Program Files\Windows Live
2008-09-07 13:31 2,560 —ha-w C:\WINDOWS\system32\drivers\mchInjDrv.sys.szcpf
2008-08-29 22:57 ——— d—–w C:\Documents and Settings\Home\Application Data\Uniblue
2008-08-28 23:45 ——— d—–w C:\Documents and Settings\Home\Application Data\vlc
2008-08-28 08:33 ——— d—–w C:\Program Files\Java
2008-08-10 11:18 0 —-a-w C:\Documents and Settings\Home\jagex_runescape_preferences.dat
2004-12-01 08:49 2,264,443 —-a-w C:\Documents and Settings\MingJong3USBPCCam_v4.12.0.1_whql\MingJong3USBPCCam_v4.12.0.1_whql.exe
.

((((((((((((((((((((((((((((( snapshot@2008-10-28_ 3.59.39.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 20:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\0b31ac10e651be1e8f740c62\nlsdl.dll
2006-06-28 16:59 24576 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP268\A0084813.dll

C:\0b31ac10e651be1e8f740c62\spmsg.dll
2006-05-24 11:32 14048 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP268\A0084812.dll

C:\0b31ac10e651be1e8f740c62\spuninst.exe
2006-05-24 11:32 213216 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP268\A0084811.exe

C:\0b31ac10e651be1e8f740c62\spupdsvc.exe
2006-05-24 11:32 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP268\A0084810.exe

C:\0b31ac10e651be1e8f740c62\update\spcustom.dll
2006-05-24 11:32 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP268\A0084808.dll

C:\0b31ac10e651be1e8f740c62\update\update.exe
2006-05-24 11:32 716000 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP268\A0084806.exe

C:\0b31ac10e651be1e8f740c62\update\updspapi.dll
2006-05-24 11:32 371424 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP268\A0084807.dll

C:\238f10027cfc073f42996448\SP2GDR\xmllite.dll
2006-07-14 15:51 121856 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP267\A0084789.dll

C:\238f10027cfc073f42996448\SP2QFE\xmllite.dll
2006-07-14 15:52 121856 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP267\A0084788.dll

C:\238f10027cfc073f42996448\spmsg.dll
2005-10-12 23:12 14048 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP267\A0084787.dll

C:\238f10027cfc073f42996448\spuninst.exe
2005-10-12 23:12 213216 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP267\A0084794.exe

C:\238f10027cfc073f42996448\update\spcustom.dll
2005-10-12 23:12 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP267\A0084784.dll

C:\238f10027cfc073f42996448\update\update.exe
2005-10-12 23:12 716000 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP267\A0084795.exe

C:\238f10027cfc073f42996448\update\updspapi.dll
2005-10-12 23:12 371424 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP267\A0084790.dll

C:\30e64a2f4b0a4c73aa\admparse.dll
2006-11-07 02:26 71680 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074343.dll

C:\30e64a2f4b0a4c73aa\advpack.dll
2006-11-07 02:26 123904 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074342.dll

C:\30e64a2f4b0a4c73aa\browseui.dll
2006-09-23 11:12 1022976 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074341.dll

C:\30e64a2f4b0a4c73aa\corpol.dll
2006-10-17 11:03 17408 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074340.dll

C:\30e64a2f4b0a4c73aa\custsat.dll
2006-11-07 20:03 33792 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074339.dll

C:\30e64a2f4b0a4c73aa\dxtmsft.dll
2006-10-17 10:58 346624 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074338.dll

C:\30e64a2f4b0a4c73aa\dxtrans.dll
2006-10-17 10:57 214528 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074337.dll

C:\30e64a2f4b0a4c73aa\extmgr.dll
2006-11-07 20:03 131584 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074336.dll

C:\30e64a2f4b0a4c73aa\hmmapi.dll
2006-10-17 10:44 60416 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074335.dll

C:\30e64a2f4b0a4c73aa\icardie.dll
2006-10-17 10:58 61952 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074334.dll

C:\30e64a2f4b0a4c73aa\ie4uinit.exe
2006-11-07 02:26 54784 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074296.exe

C:\30e64a2f4b0a4c73aa\ieakeng.dll
2006-11-07 02:26 152064 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074333.dll

C:\30e64a2f4b0a4c73aa\ieaksie.dll
2006-11-07 02:27 229376 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074332.dll

C:\30e64a2f4b0a4c73aa\ieakui.dll
2006-11-07 02:25 161792 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074331.dll

C:\30e64a2f4b0a4c73aa\ieapfltr.dll
2006-10-17 10:27 380928 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074330.dll

C:\30e64a2f4b0a4c73aa\iedkcs32.dll
2006-11-07 02:27 382976 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074329.dll

C:\30e64a2f4b0a4c73aa\iedw.exe
2006-10-17 11:04 69120 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074295.exe

C:\30e64a2f4b0a4c73aa\ieencode.dll
2006-10-17 11:06 78336 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074328.dll

C:\30e64a2f4b0a4c73aa\ieframe.dll
2006-11-07 20:03 6049280 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074327.dll

C:\30e64a2f4b0a4c73aa\iepeers.dll
2006-11-07 20:03 191488 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074326.dll

C:\30e64a2f4b0a4c73aa\ieproxy.dll
2006-11-07 20:03 287744 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074325.dll

C:\30e64a2f4b0a4c73aa\iernonce.dll
2006-11-07 02:26 43008 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074324.dll

C:\30e64a2f4b0a4c73aa\iertutil.dll
2006-10-17 10:57 266752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074323.dll

C:\30e64a2f4b0a4c73aa\iesetup.dll
2006-11-07 02:26 55296 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074322.dll

C:\30e64a2f4b0a4c73aa\ieudinit.exe
2006-11-07 02:26 13312 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074294.exe

C:\30e64a2f4b0a4c73aa\ieui.dll
2006-11-07 20:03 180736 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074321.dll

C:\30e64a2f4b0a4c73aa\iexplore.exe
2006-10-17 11:04 622080 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074293.exe

C:\30e64a2f4b0a4c73aa\imgutil.dll
2006-10-17 10:57 36352 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074320.dll

C:\30e64a2f4b0a4c73aa\inseng.dll
2006-11-07 02:26 92672 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074319.dll

C:\30e64a2f4b0a4c73aa\jscript.dll
2006-10-17 11:00 491520 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074318.dll

C:\30e64a2f4b0a4c73aa\jsproxy.dll
2006-11-07 20:03 27136 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074317.dll

C:\30e64a2f4b0a4c73aa\licmgr10.dll
2006-10-17 11:05 40960 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074316.dll

C:\30e64a2f4b0a4c73aa\msfeeds.dll
2006-11-07 20:03 458752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074315.dll

C:\30e64a2f4b0a4c73aa\msfeedsbs.dll
2006-11-07 20:03 50688 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074314.dll

C:\30e64a2f4b0a4c73aa\msfeedssync.exe
2006-10-17 10:58 12288 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074292.exe

C:\30e64a2f4b0a4c73aa\mshta.exe
2006-10-17 10:56 45568 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074291.exe

C:\30e64a2f4b0a4c73aa\mshtml.dll
2006-11-07 20:03 3577856 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074313.dll

C:\30e64a2f4b0a4c73aa\mshtmled.dll
2006-11-07 20:03 475648 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074312.dll

C:\30e64a2f4b0a4c73aa\mshtmler.dll
2006-10-17 10:28 48128 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074311.dll

C:\30e64a2f4b0a4c73aa\msls31.dll
2006-11-07 20:03 156160 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074310.dll

C:\30e64a2f4b0a4c73aa\msrating.dll
2006-10-17 11:05 192000 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074309.dll

C:\30e64a2f4b0a4c73aa\mstime.dll
2006-11-07 20:03 670720 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074308.dll

C:\30e64a2f4b0a4c73aa\occache.dll
2006-10-17 11:04 101376 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074307.dll

C:\30e64a2f4b0a4c73aa\pngfilt.dll
2006-10-17 10:58 44544 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074306.dll

C:\30e64a2f4b0a4c73aa\shdocvw.dll
2006-09-23 11:12 1497088 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074305.dll

C:\30e64a2f4b0a4c73aa\shlwapi.dll
2006-09-23 11:12 474112 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074304.dll

C:\30e64a2f4b0a4c73aa\spmsg.dll
2006-09-06 15:43 14048 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074303.dll

C:\30e64a2f4b0a4c73aa\spuninst.exe
2006-09-06 15:43 213216 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074290.exe

C:\30e64a2f4b0a4c73aa\spupdsvc.exe
2006-09-06 15:43 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074289.exe

C:\30e64a2f4b0a4c73aa\update\idndl.exe
2006-09-06 15:42 589672 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074273.exe

C:\30e64a2f4b0a4c73aa\update\iecustom.dll
2006-11-07 20:04 31856 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074276.dll

C:\30e64a2f4b0a4c73aa\update\iereseticons.exe
2006-11-07 20:01 66048 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074272.exe

C:\30e64a2f4b0a4c73aa\update\iesetup.exe
2006-11-07 20:04 1162864 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074271.exe

C:\30e64a2f4b0a4c73aa\update\legitlibm.dll
2006-11-07 19:50 635696 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074275.dll

C:\30e64a2f4b0a4c73aa\update\nlsdl.exe
2006-09-06 15:42 498016 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074270.exe

C:\30e64a2f4b0a4c73aa\update\update.exe
2006-09-06 15:43 716000 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074269.exe

C:\30e64a2f4b0a4c73aa\update\updspapi.dll
2006-09-06 15:43 371424 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074274.dll

C:\30e64a2f4b0a4c73aa\update\xmllitesetup.exe
2006-09-06 15:43 536888 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074268.exe

C:\30e64a2f4b0a4c73aa\url.dll
2006-10-17 11:05 105984 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074302.dll

C:\30e64a2f4b0a4c73aa\urlmon.dll
2006-11-07 20:03 1162240 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074301.dll

C:\30e64a2f4b0a4c73aa\vbscript.dll
2006-11-07 20:03 413696 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074300.dll

C:\30e64a2f4b0a4c73aa\vgx.dll
2006-11-07 20:03 765952 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074299.dll

C:\30e64a2f4b0a4c73aa\webcheck.dll
2006-11-07 20:03 231424 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074298.dll

C:\30e64a2f4b0a4c73aa\winfxdocobj.exe
2006-10-17 11:05 206336 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074288.exe

C:\30e64a2f4b0a4c73aa\wininet.dll
2006-11-07 20:03 818688 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP250\A0074297.dll

C:\4f5cd1273a7a3348fce6a5d0ecf0440f\idndl.dll
2006-06-29 07:05 26112 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP269\A0084831.dll

C:\4f5cd1273a7a3348fce6a5d0ecf0440f\normaliz.dll
2006-06-29 07:05 23552 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP269\A0084830.dll

C:\4f5cd1273a7a3348fce6a5d0ecf0440f\spmsg.dll
2006-05-25 09:29 14048 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP269\A0084829.dll

C:\4f5cd1273a7a3348fce6a5d0ecf0440f\spuninst.exe
2006-05-25 09:29 213216 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP269\A0084828.exe

C:\4f5cd1273a7a3348fce6a5d0ecf0440f\spupdsvc.exe
2006-05-25 09:29 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP269\A0084827.exe

C:\4f5cd1273a7a3348fce6a5d0ecf0440f\update\spcustom.dll
2006-05-25 09:29 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP269\A0084825.dll

C:\4f5cd1273a7a3348fce6a5d0ecf0440f\update\update.exe
2006-05-25 09:29 716000 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP269\A0084823.exe

C:\4f5cd1273a7a3348fce6a5d0ecf0440f\update\updspapi.dll
2006-05-25 09:29 371424 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP269\A0084824.dll

C:\60ece6c72d37f35b7d\nlsdl.dll
2006-06-28 16:59 24576 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP247\A0074175.dll

C:\60ece6c72d37f35b7d\spmsg.dll
2006-05-24 11:32 14048 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP247\A0074174.dll

C:\60ece6c72d37f35b7d\spuninst.exe
2006-05-24 11:32 213216 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP247\A0074173.exe

C:\60ece6c72d37f35b7d\spupdsvc.exe
2006-05-24 11:32 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP247\A0074172.exe

C:\60ece6c72d37f35b7d\update\spcustom.dll
2006-05-24 11:32 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP247\A0074170.dll

C:\60ece6c72d37f35b7d\update\update.exe
2006-05-24 11:32 716000 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP247\A0074168.exe

C:\60ece6c72d37f35b7d\update\updspapi.dll
2006-05-24 11:32 371424 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP247\A0074169.dll

C:\7400b0914583a1bc571dae7a6b\sp3qfe\msi.dll
2008-05-19 05:33 4445184 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090100.dll

C:\7400b0914583a1bc571dae7a6b\sp3qfe\msiexec.exe
2008-05-19 00:57 95744 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090096.exe

C:\7400b0914583a1bc571dae7a6b\sp3qfe\msihnd.dll
2008-05-19 05:33 332800 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090099.dll

C:\7400b0914583a1bc571dae7a6b\sp3qfe\msimsg.dll
2008-04-17 00:43 2560 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090098.dll

C:\7400b0914583a1bc571dae7a6b\sp3qfe\msisip.dll
2008-05-19 05:33 18944 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090097.dll

C:\7400b0914583a1bc571dae7a6b\spmsg.dll
2007-11-30 04:39 17272 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090110.dll

C:\7400b0914583a1bc571dae7a6b\spuninst.exe
2007-11-30 04:39 231288 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090109.exe

C:\7400b0914583a1bc571dae7a6b\UPDATE\spcustom.dll
2007-11-30 04:39 26488 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090107.dll

C:\7400b0914583a1bc571dae7a6b\UPDATE\update.exe
2007-11-30 03:18 755576 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090105.exe

C:\7400b0914583a1bc571dae7a6b\UPDATE\updspapi.dll
2007-11-30 04:39 382840 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090106.dll

C:\Avenger\Alert.dll
2008-04-29 12:57 360472 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP295\A0086943.dll

C:\browseui.dll
2007-04-18 12:46 1022976 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP236\A0069915.dll

C:\de3cdddf26db5f52d5dc2a7e39cccd\idndl.dll
2006-06-29 07:05 26112 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP248\A0074193.dll

C:\de3cdddf26db5f52d5dc2a7e39cccd\normaliz.dll
2006-06-29 07:05 23552 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP248\A0074192.dll

C:\de3cdddf26db5f52d5dc2a7e39cccd\spmsg.dll
2006-05-25 09:29 14048 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP248\A0074191.dll

C:\de3cdddf26db5f52d5dc2a7e39cccd\spuninst.exe
2006-05-25 09:29 213216 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP248\A0074190.exe

C:\de3cdddf26db5f52d5dc2a7e39cccd\spupdsvc.exe
2006-05-25 09:29 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP248\A0074189.exe

C:\de3cdddf26db5f52d5dc2a7e39cccd\update\spcustom.dll
2006-05-25 09:29 22752 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP248\A0074187.dll

C:\de3cdddf26db5f52d5dc2a7e39cccd\update\update.exe
2006-05-25 09:29 716000 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP248\A0074185.exe

C:\de3cdddf26db5f52d5dc2a7e39cccd\update\updspapi.dll
2006-05-25 09:29 371424 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP248\A0074186.dll

C:\dllcache\_003468_.tmp.dll
2004-08-04 12:00 12288 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0076625.dll

C:\dllcache\_003994_.tmp.dll
2004-08-04 12:00 24064 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0077149.dll

C:\dllcache\extmgr.dll
2008-06-23 16:11 55808 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP270\A0084858.dll

C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}\registrybooster2\2B86F085\6383BC9B\UBVarRB.dll
2008-08-26 16:48 757760 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP258\A0075746.dll

C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}\registrybooster2\4E45A1A4\6383BC9B\RegistryBooster.dll
2008-08-26 16:48 6676480 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP258\A0075748.dll

C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}\registrybooster2\52CD59C9\6383BC9B\update.dll
2008-08-26 16:48 413696 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP258\A0075749.dll

C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}\registrybooster2\65B92A91\6383BC9B\KillRBProcess.exe
2008-08-26 16:48 111912 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP258\A0075750.exe

C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}\registrybooster2\7390E4F0\6383BC9B\StartRegistryBooster.exe
2008-08-26 16:48 99624 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP258\A0075751.exe

C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}\registrybooster2\7CE1607E\6383BC9B\RegistryBooster.exe
2008-08-26 16:48 2019624 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP258\A0075752.exe

C:\Documents and Settings\All Users\Application Data\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}\registrybooster2\AF01B0B\6383BC9B\XceedZip.dll
2008-08-26 16:48 497496 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP258\A0075753.dll

C:\Documents and Settings\All Users\Application Data\~0\Uniblue RegistryBooster.exe
2008-08-27 13:08 2567157 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP258\A0075799.exe

2008-09-10 21:25 1273280 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\AIMinst.exe
2007-11-03 02:33 1273280 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068531.exe

2008-09-10 21:24 481480 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\AIMLang.exe
2007-11-03 02:33 481480 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068524.exe

2008-09-10 21:24 477520 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\aimlang_uk.exe
2007-11-03 02:33 477520 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068521.exe

2008-09-10 21:25 141944 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\alsetup.exe
2007-11-03 02:34 141944 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068538.exe

2008-09-10 21:25 120368 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\aoldlmgr.exe
2007-11-03 02:34 120368 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068537.exe

2008-09-10 21:25 87600 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\AOLFirewallMgr.dll
2007-11-03 02:33 87600 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068530.dll

2008-09-10 21:24 237104 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\gui.dll
2007-11-03 02:33 237104 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068522.dll

2008-09-10 21:25 13872 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\imappver.dll
2007-11-03 02:33 13872 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068529.dll

2008-09-10 21:25 63024 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\instSup.dll
2007-11-03 02:34 63024 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068536.dll

2008-09-10 21:25 228912 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\migrator.exe
2007-11-03 02:34 228912 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068539.exe

2008-09-10 21:25 15920 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\ocpchk.dll
2007-11-03 02:33 15920 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068533.dll

2008-09-10 21:24 5095496 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\ocpinst.exe
2007-11-03 02:32 5095496 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068517.exe

2008-09-10 21:25 35888 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\postproc.exe
2007-11-03 02:33 35888 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068535.exe

2008-09-10 21:25 83504 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\ProgUpd.dll
2007-11-03 02:33 83504 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068534.dll

2008-09-10 21:25 169520 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\setup.exe
2007-11-03 02:33 169520 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068528.exe

2008-09-10 21:24 11824 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\tbinst.dll
2007-11-03 02:32 11824 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068516.dll

2008-09-10 21:24 357776 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\tbsetup.exe
2007-11-03 02:33 357776 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068519.exe

2008-09-10 21:25 376568 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\unagi3.exe
2007-11-03 02:33 376568 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068527.exe

2008-09-10 21:25 3858056 C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_uk\6.1.17.1\Vwpt.exe
2007-11-03 02:33 3858056 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068525.exe

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7upd\install.1\avgupd.dll
2008-10-19 07:01 620544 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP294\A0086865.dll

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2\RegGS1-Global.reg
2008-09-10 22:42 1715 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP236\A0069858.reg

C:\Documents and Settings\All Users\Application Data\Symantec\COHLU.reg
2008-07-30 17:54 403 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP189\A0055945.reg

2008-09-29 05:09 1290584 C:\Documents and Settings\All Users\Application Data\Symantec\SyKnAppS\SyKnAppS.dll
2008-03-07 15:17 1314648 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP274\A0085091.dll

C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools\_004110_.tmp.dll
2008-07-31 19:29 1583 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0077205.dll

C:\Documents and Settings\Home\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}-trash\components\googletoolbar.dll
2008-06-05 07:37 239616 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP185\A0055803.dll

C:\Documents and Settings\Home\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}-trash\components\metrics.dll
2008-06-05 07:37 243200 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP185\A0055804.dll

C:\Documents and Settings\Home\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\extensions\{34ea1c70-42cc-42c5-aa29-ec58b95a343e}-trash\components\FFAlert.dll
2008-08-04 20:17 11776 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068568.dll

C:\Documents and Settings\Home\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\extensions\{34ea1c70-42cc-42c5-aa29-ec58b95a343e}-trash\components\npmozax.dll
2008-08-04 20:17 114688 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068569.dll

2008-10-28 01:17 1 C:\Documents and Settings\Home\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2008-07-22 04:42 1 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP185\A0055673.sys
2008-10-14 02:13 1 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP308\A0090605.sys

2008-10-20 17:46 15445112 C:\Documents and Settings\Home\Desktop\7zipfree_8675.exe
2008-09-13 00:49 1048576 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP242\A0073891.exe

C:\Documents and Settings\Home\Desktop\AOLDNLD.exe
2008-09-10 21:23 309072 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068558.exe

C:\Documents and Settings\Home\Desktop\aolsetup.exe
2007-05-30 15:19 728624 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP234\A0068559.exe

C:\Documents and Settings\Home\Desktop\DriverDetective.exe
2008-09-11 21:41 5213928 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP290\A0085547.exe

2008-07-25 18:07 73728 C:\Documents and Settings\Home\Desktop\OperaTor\vbzlib1.dll
2008-07-25 18:07 73728 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP201\A0058945.dll

2007-11-27 15:14 140288 C:\Documents and Settings\Home\Desktop\OTScanIt2\catchme.exe
2007-11-27 14:14 140288 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP307\A0090506.exe

2008-10-19 20:52 417792 C:\Documents and Settings\Home\Desktop\OTScanIt2\OTScanIt2.exe
2008-10-19 19:52 417792 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP307\A0090507.exe

C:\Documents and Settings\Home\Desktop\setupxv.exe
2008-09-13 02:57 2007976 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP296\A0086972.exe
2008-09-13 03:57 2007976 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP306\A0090257.exe

C:\Documents and Settings\LocalService\Application Data\Microsoft\bouceh.exe
2008-10-14 23:37 233472 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP314\A0090774.exe

C:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2004-08-04 12:00 25600 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP304\A0090127.dll
2004-08-04 12:00 25600 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP314\A0090775.dll

C:\drivers\ati1xsxx.sys
{8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0080"

C:\ComboFix\ati2m

C:\drivers\atinraxx.sys
{8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A"

C:\ComboFix\atinrvxx

C:\i386\adv05nt5.dll
{8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A007"

C:\ComboFix\adv08n

C:\iernonce.dll
2008-06-23 16:57 44544 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP236\A0069930.dll

C:\iphlpapi.dll
2006-05-19 12:59 94720 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0081373.dll

C:\lmhsvc.dll
2008-04-14 00:11 13824 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0079389.dll

C:\mobsync.dll
2008-04-14 00:11 207360 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0081463.dll

C:\mstlsapi.dll
2004-08-04 12:00 115712 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0081528.dll

C:\odbccr32.dll
2004-08-04 12:00 65536 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0081602.dll

C:\odbcp32r.dll
2004-08-04 12:00 12288 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0081607.dll

C:\osk.exe
2008-04-14 00:12 215552 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP259\A0079884.exe

2008-07-29 18:19 26920 C:\Program Files\AIM6\addressBook.exe
2007-03-12 22:15 50736 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075573.exe

2008-08-12 14:43 49960 C:\Program Files\AIM6\aim6.exe
2007-05-09 16:54 50736 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075574.exe

2007-03-13 14:41 42032 C:\Program Files\AIM6\anotify.exe
2006-11-17 14:44 50736 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075575.exe

C:\Program Files\AIM6\AOLHostManager.exe
2006-09-26 00:52 14384 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075576.exe

C:\Program Files\AIM6\AOLHostMgr.dll
2006-09-26 00:51 126976 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075577.dll

2008-05-02 17:25 41824 C:\Program Files\AIM6\aollaunch.exe
2006-09-26 00:52 50736 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075578.exe

2008-05-02 17:25 41824 C:\Program Files\AIM6\aolsoftware.exe
2006-09-26 00:52 50736 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075579.exe

2008-05-02 17:24 597504 C:\Program Files\AIM6\AOLSvcMgr.dll
2006-09-26 00:51 300544 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075580.dll

C:\Program Files\AIM6\coolcore46.dll
2007-03-20 02:49 749568 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075581.dll

2007-01-22 18:25 45056 C:\Program Files\AIM6\jga0tlk.dll
2007-05-09 16:54 45056 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075582.dll

2007-01-22 18:25 36864 C:\Program Files\AIM6\jga1tlk.dll
2007-05-09 16:54 36864 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075583.dll

2007-01-22 18:25 65536 C:\Program Files\AIM6\jgattlk.dll
2007-05-09 16:54 65536 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075584.dll

2007-01-22 18:25 61440 C:\Program Files\AIM6\jgedtlk.dll
2007-05-09 16:54 61440 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075585.dll

2007-01-22 18:25 40960 C:\Program Files\AIM6\jgs2tlk.dll
2007-05-09 16:54 40960 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075586.dll

2007-01-22 18:25 32768 C:\Program Files\AIM6\jgs3tlk.dll
2007-05-09 16:54 32768 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075587.dll

2007-01-22 18:25 40960 C:\Program Files\AIM6\jgs6tlk.dll
2007-05-09 16:54 40960 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075588.dll

2007-01-22 18:25 32768 C:\Program Files\AIM6\jgs7tlk.dll
2007-05-09 16:54 32768 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075589.dll

2007-01-22 18:25 45056 C:\Program Files\AIM6\jgsetlk.dll
2007-05-09 16:54 45056 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075590.dll

2007-01-22 18:25 98304 C:\Program Files\AIM6\jgtktlk.dll
2007-05-09 16:54 98304 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075591.dll

2008-09-24 04:16 228136 C:\Program Files\AIM6\migrator.exe
2008-09-10 21:44 228912 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075592.exe

2003-08-13 01:17 348160 C:\Program Files\AIM6\msvcr71.dll
2003-08-13 01:17 348160 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075593.dll

2007-06-20 13:50 177448 C:\Program Files\AIM6\ocpctl.dll
2006-04-12 15:27 194152 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075594.dll

2008-07-23 18:51 14120 C:\Program Files\AIM6\ocpiman.dll
2007-02-15 20:46 14896 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075595.dll

2007-11-01 14:18 307200 C:\Program Files\AIM6\pb_videoconf.dll
2007-03-14 15:18 380928 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075596.dll

2008-09-24 04:16 36912 C:\Program Files\AIM6\rbm.exe
2008-09-10 21:44 35888 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075597.exe

C:\Program Files\AIM6\services\addressBook\ver1_10_1_1\absvc.dll
2007-02-15 19:30 360448 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075598.dll

C:\Program Files\AIM6\services\addressBookApp\ver1_0_5_1\addressBookAppController.dll
2007-03-12 22:15 86016 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075600.dll

C:\Program Files\AIM6\services\addressBookApp\ver1_0_5_1\addressBookAppService.dll
2007-03-12 22:15 118784 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075601.dll

C:\Program Files\AIM6\services\addressBookApp\ver1_0_5_1\imAppPlugin.dll
2007-03-12 22:15 159744 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075609.dll

2006-08-10 15:33 131072 C:\Program Files\AIM6\services\addressBookPrint\ver1_4_5_1\abPrintSvc.dll
2006-08-10 15:33 131072 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075626.dll

C:\Program Files\AIM6\services\authentication\ver6_1_7_1\authentication.dll
2007-03-05 19:42 102400 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075631.dll

C:\Program Files\AIM6\services\authentication\ver6_1_7_1\authenticationshadow.dll
2007-03-05 19:42 475136 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075633.dll

C:\Program Files\AIM6\services\basics\ver8_0_4_1\basics.dll
2006-07-18 20:02 385024 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075635.dll

C:\Program Files\AIM6\services\bfts\ver2_13_9_10\bfts.dll
2006-09-28 20:53 229376 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075636.dll

C:\Program Files\AIM6\services\boxelyrenderer\ver1_11_5_1\boxelyrenderer.dll
2007-03-08 19:05 1826816 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075640.dll

C:\Program Files\AIM6\services\compression\ver2_4_3_1\zipper.dll
2006-03-13 23:27 103424 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075647.dll

C:\Program Files\AIM6\services\connection\ver6_0_2_1\connection.dll
2006-04-27 17:46 111104 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075648.dll

C:\Program Files\AIM6\services\htmlRenderer\ver1_0_15_1\htmlRenderer.dll
2006-09-12 18:11 139264 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075650.dll

C:\Program Files\AIM6\services\http\ver2_6_11_1\http.dll
2007-02-12 21:13 104960 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075651.dll

C:\Program Files\AIM6\services\identityInformation\ver4_4_2_2\identityInformation.dll
2006-08-11 20:09 110592 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075652.dll

C:\Program Files\AIM6\services\im\ver1_14_9_1\acccore.dll
2007-03-20 20:32 540672 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075653.dll

C:\Program Files\AIM6\services\im\ver1_14_9_1\imservice.dll
2007-03-20 20:32 118784 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075654.dll

C:\Program Files\AIM6\services\imApp\ver6_1_42_2\imAppService.dll
2007-05-09 16:54 1445888 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075655.dll

C:\Program Files\AIM6\services\imApp\ver6_1_42_2\isAim.dll
2007-05-09 16:54 83504 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075541.dll

C:\Program Files\AIM6\services\localStorage\ver7_1_1_1\clsSvc.dll
2006-10-03 17:20 335872 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075656.dll

C:\Program Files\AIM6\services\miniXML\ver1_5_1_1\XMLMini.dll
2006-07-19 22:42 86016 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075657.dll

C:\Program Files\AIM6\services\notification\ver6_2_6_1\Notify.dll
2006-08-01 21:26 145920 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075660.dll

C:\Program Files\AIM6\services\onlineAlerts\ver2_4_1_1\oam.dll
2006-09-20 15:19 180224 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075661.dll

2006-09-21 15:18 5632 C:\Program Files\AIM6\services\os\ver5_2_1_1\AOLIdleMon.dll
2006-09-21 15:18 5632 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075663.dll

2006-09-21 15:19 180736 C:\Program Files\AIM6\services\os\ver5_2_1_1\os.dll
2006-09-21 15:19 180736 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075664.dll

C:\Program Files\AIM6\services\osInfo\ver1_1_1_3\AOLIdleMon.dll
2006-09-28 18:12 5632 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075665.dll

C:\Program Files\AIM6\services\osInfo\ver1_1_1_3\osInfo.dll
2006-09-28 18:12 180224 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075666.dll

C:\Program Files\AIM6\services\preferences\ver4_1_1_1\preferences.dll
2006-06-30 13:47 99328 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075667.dll

C:\Program Files\AIM6\services\security\ver1_0_6_2\security.dll
2006-03-24 19:19 94208 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075668.dll

C:\Program Files\AIM6\services\softwareUpdate\ver2_14_7_5\aolretc.exe
2007-02-21 15:02 17968 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075669.exe

C:\Program Files\AIM6\services\softwareUpdate\ver2_14_7_5\aolsetup.exe
2006-10-12 16:29 164912 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075670.exe

C:\Program Files\AIM6\services\softwareUpdate\ver2_14_7_5\gui.dll
2007-02-21 14:40 126976 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075673.dll

C:\Program Files\AIM6\services\softwareUpdate\ver2_14_7_5\instph.dll
2006-10-12 16:29 94256 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075674.dll

C:\Program Files\AIM6\services\softwareUpdate\ver2_14_7_5\instSup.dll
2006-09-25 17:07 63024 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075675.dll

C:\Program Files\AIM6\services\softwareUpdate\ver2_14_7_5\ProgUpd.dll
2006-10-12 16:29 83504 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075678.dll

C:\Program Files\AIM6\services\softwareUpdate\ver2_14_7_5\stic.dll
2007-02-21 14:46 593920 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075687.dll

C:\Program Files\AIM6\services\sync\ver3_7_1_1\sync.dll
2006-10-04 20:18 344064 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075691.dll

C:\Program Files\AIM6\services\toaster\ver4_2_4_3\toaster.dll
2006-11-17 14:44 208896 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075693.dll

C:\Program Files\AIM6\services\urlData\ver1_5_2_1\urlData.dll
2006-08-02 20:17 89600 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075694.dll

C:\Program Files\AIM6\services\urlDispatcher\ver4_2_8_1\urlDispatcher.dll
2006-05-11 19:12 118784 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075695.dll

2008-05-15 17:20 2916352 C:\Program Files\AIM6\sipXtapi.dll
2007-03-16 21:58 3002368 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075696.dll

2004-05-18 18:00 245408 C:\Program Files\AIM6\unicows.dll
2004-05-18 18:00 245408 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075697.dll

2008-09-24 04:16 123321 C:\Program Files\AIM6\uninst.exe
2008-09-10 21:40 93510 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075698.exe

2008-09-24 04:15 121408 C:\Program Files\AIM6\uninstall.exe
2008-09-10 21:38 119917 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075699.exe

2007-03-20 02:48 249856 C:\Program Files\AIM6\xprt5.dll
{8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075700.dllC:\Program Files\RegistryCleanerPro\uninst.exe
2008-09-13 02:53 48432 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP254\A0075721.exe

C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
2008-03-07 13:55 1090912 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP270\A0084947.dll

C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
2008-08-10 11:11 3563232 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP240\A0073030.exe

C:\Program Files\Babylon\Babylon-Pro\BabyServices.dll
2008-08-10 11:01 886784 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP240\A0073032.dll

C:\Program Files\Babylon\Babylon-Pro\BContentServer.dll
2008-08-10 11:10 2131456 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP240\A0073033.dll

C:\Program Files\Babylon\Babylon-Pro\BException.dll
2008-08-10 10:59 101376 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP240\A0073035.dll

C:\Program Files\Babylon\Babylon-Pro\captlib.dll
2008-08-10 11:03 181760 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP240\A0073034.dll

C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
2008-08-10 11:06 121856 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP240\A0073036.dll

C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonOfficePI.dll
2008-08-10 11:06 191488 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP240\A0073037.dll

C:\Program Files\Babylon\Babylon-Pro\Utils\uninstbb.exe
2008-08-10 11:11 304352 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP240\A0073031.exe

C:\Program Files\BrowsingEnhancer\pcre3.dll
2007-12-26 23:30 140288 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP295\A0086911.dll

C:\Program Files\BrowsingEnhancer\uninstall.exe
2008-06-05 00:11 42371 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP295\A0086912.exe

2007-11-26 20:21 307712 C:\Program Files\Common Files\AOL\AOLDiag\aoldiag.dll
2006-10-26 20:23 305664 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075602.dll

2007-11-26 20:21 23552 C:\Program Files\Common Files\AOL\AOLDiag\locale\de\tbdres.dll
2006-10-26 20:23 23040 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075604.dll

2007-11-26 20:21 69632 C:\Program Files\Common Files\AOL\AOLDiag\locale\en-CA\tbdres.dll
2006-10-26 20:23 69632 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075608.dll

2007-11-26 20:21 23552 C:\Program Files\Common Files\AOL\AOLDiag\locale\en-GB\tbdres.dll
2006-10-26 20:23 23040 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075611.dll

2007-11-26 20:21 23552 C:\Program Files\Common Files\AOL\AOLDiag\locale\en\tbdres.dll
2006-10-26 20:23 23040 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075606.dll

2007-11-26 20:21 23552 C:\Program Files\Common Files\AOL\AOLDiag\locale\es-US\tbdres.dll
2006-10-26 20:23 23040 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075617.dll

2007-11-26 20:21 23552 C:\Program Files\Common Files\AOL\AOLDiag\locale\es\tbdres.dll
2006-10-26 20:23 23040 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075614.dll

2007-11-26 20:21 23552 C:\Program Files\Common Files\AOL\AOLDiag\locale\fr-CA\tbdres.dll
2006-10-26 20:23 23040 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075623.dll

2007-11-26 20:21 23552 C:\Program Files\Common Files\AOL\AOLDiag\locale\fr\tbdres.dll
2006-10-26 20:23 23040 {8F767653-45E9-415D-99E0-579A3C78AE8A}\RP253\A0075620.dll

2007-11-26 20:21 23552 C:\Program Files\Common Files\AOL\AOLDiag\locale\ja\tbdres.dll

2008-10-28 14:17 0 C:\
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-08-12 49960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-29 185896]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]
"duquy"="C:\WINDOWS\system32\bouceh.exe" [2008-10-14 233472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"duquy"="C:\WINDOWS\system32\bouceh.exe" [2008-10-14 233472]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-20 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MSIServer"=3 (0x3)
"gusvc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 34432]
S2 aeyiztkqyaf7ci;PowerUtility TV Recording Reservation;C:\WINDOWS\system32\quejoosoo.exe [2008-10-14 233472]
S3 PAC207;SoC PC-Camer@;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 162176]
S3 RkHit;RkHit;C:\WINDOWS\system32\drivers\RKHit.sys [2008-09-16 30080]
S3 USB-100;Realtek RTL8150 USB 10/100 Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\RTL8150.SYS [2002-02-22 26505]
S4 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder

2008-10-24 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 13:42]

2008-10-28 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 21:21]

2008-10-23 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 21:21]

2008-10-27 C:\WINDOWS\Tasks\RegFixPro Scheduled Scan.job
- C:\Program Files\RegFixPro\RegFixPro.exe []

2008-10-27 C:\WINDOWS\Tasks\RegFixPro Scheduled Scan.job
- C:\Program Files\RegFixPro []
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-muwoum - C:\WINDOWS\system32\hougiwa.exe
HKLM-RunServices-muwoum - C:\WINDOWS\system32\hougiwa.exe



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 14:21:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


C:\WINDOWS\system32\quejoosoo.exe 233472 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-10-28 14:42:18 - machine was rebooted [Home]
ComboFix-quarantined-files.txt 2008-10-28 14:41:21
ComboFix2.txt 2008-10-28 04:01:05

Pre-Run: 50,950,848,512 bytes free
Post-Run: 50,959,581,184 bytes free

753 — E O F — 2008-10-24 02:05:45
Hello

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.




Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Malwarebytes' Anti-Malware 1.30 Database version: 1335 Windows 5.1.2600 Service Pack 3 29/10/2008 06:02:58 mbam-log-2008-10-29 (06-02-58).txt Scan type: Quick Scan Objects scanned: 49162 Time elapsed: 8 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\duquy (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\bouceh.exe (Trojan.FakeAlert.H) -> Delete on reboot. C:\Documents and Settings\Home\Desktop\winsock.exe (Backdoor.IRCBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Home\Desktop\Find And Fix Errors.lnk (Rogue.Link) -> Quarantined and deleted succes
——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Wednesday, October 29, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, October 29, 2008 03:24:23 Records in database: 1355093 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 115943 Threat name: 2 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 03:20:10 File name / Threat name / Threats count C:\Documents and Settings\Home\My Documents\Google Talk Received Files\hosts.msn Infected: Trojan.Win32.Qhost.r 1 C:\Qoobox\Quarantine\C\Program Files\RelevantKnowledge\rlvknlg.exe.vir Infected: not-a-virus:AdWare.Win32.RK.ad 1 The selected area was scanned.
Hello

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Documents and Settings\Home\My Documents\Google Talk Received Files\hosts.msn

Folder::

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
ComboFix 08-10-30.09 - Home 2008-10-31 4:22:08.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.250 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Home\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Documents and Settings\Home\My Documents\Google Talk Received Files\hosts.msn
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Home\My Documents\Google Talk Received Files\hosts.msn

.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-31 )))))))))))))))))))))))))))))))
.

2008-10-28 14:22 . 2008-10-14 23:37 233,472 ——— C:\WINDOWS\system32\bouceh.exe
2008-10-28 12:56 . 2008-10-29 06:14 2,160 –a—— C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-10-27 03:05 . 2008-10-27 03:05 d——– C:\_OTScanIt
2008-10-23 08:38 . 2008-10-23 08:38 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-23 06:21 . 2008-10-23 06:21 d——– C:\Program Files\RegCure
2008-10-23 06:20 . 2008-10-23 06:20 d–h-c— C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-10-23 04:48 . 2008-10-23 04:48 d——– C:\New Folder
2008-10-23 03:40 . 2008-10-23 03:45 d——– C:\regres
2008-10-23 03:40 . 2008-10-23 03:45 720,896 –a—— C:\WINDOWS\iun6002.exe
2008-10-21 09:56 . 2008-10-21 09:56 d——– C:\My Drivers
2008-10-21 09:55 . 2008-10-21 09:55 d——– C:\Program Files\JerMar Software Corp
2008-10-21 09:55 . 2001-11-29 08:57 110,592 –a—— C:\WINDOWS\system32\ccrpbds6.dll
2008-10-20 23:09 . 2008-07-18 21:07 210,976 –a—— C:\WINDOWS\system32\muweb.dll
2008-10-20 18:56 . 2008-10-20 21:57 d——– C:\Program Files\jZip
2008-10-20 18:15 . 2008-10-20 18:15 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-10-20 17:52 . 2008-10-20 17:52 d——– C:\Program Files\7-Zip
2008-10-20 05:00 . 2008-10-29 05:52 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-20 05:00 . 2008-10-20 05:00 d——– C:\Documents and Settings\Home\Application Data\Malwarebytes
2008-10-20 05:00 . 2008-10-20 05:00 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-20 05:00 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-20 05:00 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-15 17:46 . 2008-10-18 18:39 d——– C:\Documents and Settings\Home\Application Data\EurekaLog
2008-10-15 15:54 . 2008-10-15 16:00 d——– C:\N360_BACKUP
2008-09-24 05:13 . 2008-09-24 05:13 d——– C:\67515e7ee021f805937cb048f5429453
2008-09-24 04:39 . 2008-09-24 04:44 d——– C:\Program Files\Perfect Uninstaller
2008-09-24 04:39 . 2008-09-16 17:09 30,080 –a—— C:\WINDOWS\system32\drivers\RKHit.sys
2008-09-24 04:39 . 2008-09-24 04:39 42 –a—— C:\WINDOWS\system32\AK083E209605E394C.lie
2008-09-24 04:17 . 2008-09-24 04:17 d——– C:\Documents and Settings\Home\Application Data\acccore
2008-09-24 04:16 . 2008-09-24 04:16 d——– C:\Documents and Settings\All Users\Application Data\acccore
2008-09-24 04:15 . 2008-09-24 04:15 d——– C:\Program Files\Common Files\AOL
2008-09-24 04:15 . 2008-09-24 04:17 d——– C:\Program Files\AIM6
2008-09-16 08:15 . 2008-09-16 10:05 d——– C:\WINDOWS\system32\scripting
2008-09-16 08:15 . 2008-09-16 10:05 d——– C:\WINDOWS\system32\en
2008-09-16 08:15 . 2008-09-16 10:04 d——– C:\WINDOWS\l2schemas
2008-09-16 08:14 . 2008-09-16 10:05 d——– C:\WINDOWS\system32\bits
2008-09-16 08:05 . 2008-09-16 08:16 d——– C:\WINDOWS\ServicePackFiles
2008-09-16 07:55 . 2007-08-10 19:46 33,656 –a—— C:\WINDOWS\system32\sprecovr.exe
2008-09-16 07:46 . 2008-09-16 07:46 d——– C:\WINDOWS\EHome
2008-09-13 17:29 . 2008-09-24 05:39 754 –a—— C:\WINDOWS\WORDPAD.INI
2008-09-13 17:16 . 2008-09-13 17:16 d——– C:\Documents and Settings\Administrator
2008-09-13 05:32 . 2008-10-26 04:20 458,752 –ah—– C:\WINDOWS\system32\msfeeds.dll.szcpf
2008-09-13 05:32 . 2008-10-26 04:20 50,688 –ah—– C:\WINDOWS\system32\msfeedsbs.dll.szcpf
2008-09-13 02:53 . 2008-09-15 17:19 d——– C:\Program Files\RegistryCleanerPro
2008-09-13 01:58 . 2008-09-13 01:58 d——– C:\Program Files\Conduit
2008-09-13 01:25 . 2008-09-13 05:44 d——– C:\Program Files\BitZipperSearch
2008-09-13 01:24 . 2008-09-13 01:24 d——– C:\Documents and Settings\Home\Application Data\BitZipper
2008-09-13 01:23 . 2008-09-13 01:58 d——– C:\Program Files\BitZipper
2008-09-13 00:37 . 2008-08-06 14:45 4,122,112 –a—— C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2008-09-13 00:36 . 2008-09-13 00:36 d——– C:\Program Files\Realtek AC97
2008-09-13 00:36 . 2006-11-17 04:40 18,804,736 –a—— C:\WINDOWS\system32\ALSNDMGR.CPL
2008-09-13 00:36 . 2006-12-08 14:20 10,528,768 –a—— C:\WINDOWS\system32\RTLCPL.EXE
2008-09-13 00:36 . 2007-04-16 14:28 577,536 –a—— C:\WINDOWS\SOUNDMAN.EXE
2008-09-13 00:36 . 2006-07-31 10:19 315,392 –a—— C:\WINDOWS\alcupd.exe
2008-09-13 00:36 . 2006-07-31 10:27 217,088 –a—— C:\WINDOWS\Alcrmv.exe
2008-09-13 00:36 . 2006-10-18 01:53 147,456 –a—— C:\WINDOWS\system32\RTLCPAPI.dll
2008-09-13 00:36 . 2002-02-05 12:54 141,016 –a—— C:\WINDOWS\system32\ALSNDMGR.WAV
2008-09-11 22:59 . 2008-09-11 22:59 d——– C:\Program Files\Intel
2008-09-11 22:58 . 2008-09-11 22:58 d——– C:\Intel
2008-09-11 21:52 . 2008-09-11 21:52 d——– C:\Program Files\PC Drivers HeadQuarters
2008-09-11 21:52 . 2008-09-11 21:52 d——– C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-11 20:50 . 2007-09-02 19:56 1,686,016 –a—— C:\WINDOWS\system32\clinetsuitex6.ocx
2008-09-11 20:50 . 2004-06-14 13:56 427,864 –a—— C:\WINDOWS\system32\XceedZip.dll
2008-09-11 12:56 . 2008-09-15 17:10 d——– C:\Documents and Settings\All Users\Application Data\Skype
2008-09-11 11:44 . 2008-09-11 11:44 d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-11 11:18 . 2008-09-11 11:18 d——– C:\Program Files\Canon
2008-09-10 22:40 . 2008-09-11 10:53 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-10 22:40 . 2008-09-11 10:50 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-10 20:52 . 2008-10-20 17:52 d——– C:\Program Files\Yahoo!
2008-09-06 07:59 . 2008-04-14 00:12 7,680 –a—— C:\WINDOWS\system32\spdwnwxp.exe
2008-09-06 06:58 . 2008-09-16 07:25 d——– C:\WINDOWS\system32\CatRoot_bak

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-30 10:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-29 10:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-10-29 10:37 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-10-29 06:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\SITEguard
2008-10-28 03:16 ——— d—–w C:\Documents and Settings\Home\Application Data\OpenOffice.org2
2008-10-27 02:25 ——— d—–w C:\Program Files\GSC
2008-10-26 12:56 ——— d—–w C:\Program Files\Veoh Networks
2008-10-26 03:52 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-10-24 02:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-21 09:55 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-10-20 18:12 ——— d—–w C:\Program Files\Real
2008-10-20 18:12 ——— d—–w C:\Program Files\Common Files\Real
2008-10-19 07:00 ——— d—–w C:\Documents and Settings\Home\Application Data\AVG7
2008-10-15 03:27 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-15 03:22 ——— d—–w C:\Program Files\Spyware Doctor
2008-10-11 15:57 ——— d—–w C:\Program Files\Norton 360
2008-10-09 21:11 ——— d—–w C:\Program Files\Picasa2
2008-10-06 21:21 ——— d—–w C:\Program Files\Google
2008-09-26 13:08 304,160 —-a-w C:\StiImg.dat
2008-09-24 04:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-24 04:16 ——— d—–w C:\Program Files\Viewpoint
2008-09-24 04:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-24 04:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-09-13 03:09 ——— d—–w C:\Documents and Settings\Home\Application Data\RegFixPro
2008-09-10 21:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-09-10 20:30 ——— d—–w C:\Program Files\Windows Live
2008-09-07 13:31 2,560 —ha-w C:\WINDOWS\system32\drivers\mchInjDrv.sys.szcpf
2008-08-29 22:57 ——— d—–w C:\Documents and Settings\Home\Application Data\Uniblue
2008-08-28 23:45 ——— d—–w C:\Documents and Settings\Home\Application Data\vlc
2008-08-28 08:33 ——— d—–w C:\Program Files\Java
2008-08-10 11:18 0 —-a-w C:\Documents and Settings\Home\jagex_runescape_preferences.dat
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\dllcache\es.dll
2008-07-05 22:14 43,520 —-a-w C:\WINDOWS\system32\CmdLineExt03.dll
2004-12-01 08:49 2,264,443 —-a-w C:\Documents and Settings\MingJong3USBPCCam_v4.12.0.1_whql\MingJong3USBPCCam_v4.12.0.1_whql.exe
.

((((((((((((((((((((((((((((( snapshot@2008-10-28_ 3.59.39.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 20:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-08-12 49960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-29 185896]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"duquy"="C:\WINDOWS\system32\bouceh.exe" [2008-10-14 233472]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-20 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MSIServer"=3 (0x3)
"gusvc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 34432]
S2 aeyiztkqyaf7ci;PowerUtility TV Recording Reservation;C:\WINDOWS\system32\quejoosoo.exe [ ]
S3 PAC207;SoC PC-Camer@;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 162176]
S3 RkHit;RkHit;C:\WINDOWS\system32\drivers\RKHit.sys [2008-09-16 30080]
S3 USB-100;Realtek RTL8150 USB 10/100 Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\RTL8150.SYS [2002-02-22 26505]
S4 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder

2008-10-24 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 13:42]

2008-10-30 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 21:21]

2008-10-30 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 21:21]

2008-10-31 C:\WINDOWS\Tasks\RegFixPro Scheduled Scan.job
- C:\Program Files\RegFixPro\RegFixPro.exe []

2008-10-31 C:\WINDOWS\Tasks\RegFixPro Scheduled Scan.job
- C:\Program Files\RegFixPro []
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-31 04:31:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-31 4:37:16
ComboFix-quarantined-files.txt 2008-10-31 04:36:57
ComboFix2.txt 2008-10-28 14:42:35
ComboFix3.txt 2008-10-28 04:01:05

Pre-Run: 50,870,960,128 bytes free
Post-Run: 50,925,113,344 bytes free

206 — E O F — 2008-10-24 02:05:45
Hello

Open notepad and copy/paste the text in the quotebox below into it:
http://forums.whatthetech.com/msn_virus_t96394.html&st=15

Collect::
C:\WINDOWS\system32\bouceh.exe
C:\WINDOWS\system32\drivers\kgpcpy.cfg

Driver::
aeyiztkqyaf7ci

Suspect::
Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
  • A browser will open.
  • Simply follow the instructions to copy/paste/send the requested file.



Please download MsnCleaner.zip and Save it to your Desktop.
  • Unzip it to the Desktop.
  • Now reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit Enter.
  • Double-click MsnCleaner.exe to run it.
  • Click the Analyze button.
  • A report will be created once after you finish scan.
  • If it finds an infection, click the Deleted button.
  • Now, please reboot back to normal mode.
  • Please post the contents of C:\MsnCleaner.txt in a reply to this post along with a new HJT log.



Please download Gmer:

http://www.gmer.net/gmer.zip

Now let's perform a Gmer rootkit scan:

  • Double-click Gmer.exe to run the program.
  • When the program opens, click the >>> Tab
  • On the right-side, check all the items to be scanned, but leave "Show All" unchecked
  • Select all drives that are connected to your system to be scanned
  • Click the Scan button
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard
  • Open Notepad or a similar text editor
  • Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
  • Save the gmer scan log and post it in your next reply.
  • Close Gmer
  • Open a command prompt (Start | run |type cmd and hit Enter)
  • Type or paste the following to unload the Gmer driver:
    • net stop gmer
  • Hit Enter
  • Exit the command prompt.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI