This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HJT Log

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This computer is having some Anti-virus software issues as well as many pop-ups.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:26:39 PM, on 12/21/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchgateway.net/search/
O4 - HKLM\..\Run: [Synchronization Manager] "C:\WINDOWS\system32\mobsync.exe" /logon
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe -m
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1203642423562
O20 - AppInit_DLLs: zqxepm.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 4236 bytes
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • Save and quit any work your doing before beginning the fix.
  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!







I see no signs of an anti virus program.. I suggest you get one in asap.
I will list 2 free anti virus programs just choose 1.


Avast

Avira AntiVir Personal Edition Classic


Download and install one of these and run a full scan.


______________________________________________




Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:





_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
This computer had McAfee on it but it started producing errors. I removed it to reinstall and was not able to due to strange window errors. The AV program you suggested found quite a few trojans as well as viruses

Here's the new HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:54:17 PM, on 12/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Synchronization Manager] "C:\WINDOWS\system32\mobsync.exe" /logon
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1203642423562
O20 - AppInit_DLLs: uxlvpc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 5226 bytes


Here's the combofix log:

ComboFix 08-12-23.01 - Franklins 2008-12-23 23:31:24.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.247 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\RichVideoCodec
c:\windows\IE4 Error Log.txt
c:\windows\system32\aitppgfc.dll
c:\windows\system32\bhgsxeod.dll
c:\windows\system32\cfgpptia.ini
c:\windows\system32\cvpwgbod.ini
c:\windows\system32\dobgwpvc.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\dwfrjfts.ini
c:\windows\system32\fcavlhng.dll
c:\windows\system32\fkcofybn.dll
c:\windows\system32\gmimoumy.dll
c:\windows\system32\gyoosy.dll
c:\windows\system32\ijyxvtvt.dll
c:\windows\system32\iutuiw.dll
c:\windows\system32\jlonnUtv.ini
c:\windows\system32\jlonnUtv.ini2
c:\windows\system32\oetsxx.dll
c:\windows\system32\pdkcpoin.ini
c:\windows\system32\pkmjdnwm.ini
c:\windows\system32\rjqjbquj.ini
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tjxyjpig.dll
c:\windows\system32\tmp.reg
c:\windows\system32\uxlvpc.dll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vtUnnolj.dll
c:\windows\system32\WS2Fix.exe
c:\windows\system32\ymuomimg.ini
c:\windows\system32\zqxepm.dll
c:\windows\Tasks\vhvpuqcc.job
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2008-11-24 to 2008-12-24 )))))))))))))))))))))))))))))))
.

2008-12-23 21:47 . 2008-12-23 21:47 d——– c:\program files\Avira
2008-12-23 21:47 . 2008-12-23 21:47 d——– c:\documents and settings\All Users\Application Data\Avira
2008-12-20 09:06 . 2008-12-20 09:05 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-17 20:47 . 2007-10-05 13:39 d——– c:\documents and settings\Administrator\Application Data\Yahoo!
2008-12-17 20:47 . 2008-12-17 20:47 d——– c:\documents and settings\Administrator
2008-12-17 18:51 . 2008-12-17 18:51 75,776 –a—— C:\7d8c1112331c2220.bup
2008-12-16 21:25 . 2008-12-16 21:25 1 –a—— c:\windows\system32\edl.dat
2008-12-13 22:46 . 2008-12-13 22:46 d——– C:\Games
2008-12-13 22:03 . 2008-12-13 22:03 d——– c:\program files\IObit
2008-12-13 22:03 . 2008-12-13 22:19 d——– c:\documents and settings\Franklins\Application Data\IObit
2008-12-07 17:09 . 2008-12-07 17:09 d——– c:\program files\ReflexiveArcade
2008-12-07 17:09 . 2008-12-15 21:01 d——– c:\program files\Off Road Arena
2008-12-07 17:04 . 2008-12-15 20:46 d——– c:\program files\Street Challenge LLC

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-24 02:51 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-21 20:48 ——— d—–w c:\documents and settings\Franklins\Application Data\SiteAdvisor
2008-12-21 20:26 ——— d—–w c:\program files\LimeWire
2008-12-20 14:04 ——— d—–w c:\program files\Java
2008-12-18 01:59 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2008-12-18 01:51 ——— d—–w c:\documents and settings\Franklins\Application Data\McAfee
2008-12-18 00:08 ——— d—–w c:\program files\Common Files\Adobe
2008-12-14 06:21 ——— d—–w c:\documents and settings\Franklins\Application Data\LimeWire
2008-12-07 21:06 ——— d—–w c:\program files\Yahoo!
2008-12-07 21:06 ——— d—–w c:\program files\Common Files\Blizzard Entertainment
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-09-19 4347120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-13 143360]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-20 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=uxlvpc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Avant Browser\\avant.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 papycpu;papycpu;c:\windows\system32\drivers\papycpu.sys [2008-03-16 1984]
S3 I97DRIVER;I97DRIVER;\??\c:\program files\Avanquest\Fix-It\dgs.sys []
S3 MailScan;MailScan;\??\c:\progra~1\AVANQU~1\Fix-It\MailScan.sys []
S3 PCAlertDriver;PCAlertDriver;\??\c:\program files\MSI\PC Alert 4\NTGLM7X.sys []
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\system32\DRIVERS\rt2500usb.sys [2007-09-09 79616]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3baebf12-b299-11dd-8a1d-000c7692adf9}]
\Shell\AutoRun\command - E:\rcaeasyrip_setup.exe
\Shell\install\command - E:\rcaeasyrip_setup.exe
\Shell\usermanualEnglish\command - E:\rcaeasyrip_setup.exe /pdf_English
\Shell\usermanualFrench\command - E:\rcaeasyrip_setup.exe /pdf_French
\Shell\usermanualSpanish\command - E:\rcaeasyrip_setup.exe /pdf_Spanish

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8ff51df4-0449-11dd-89ad-000c7692adf9}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-12-18 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2008-01-03 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
- - - - ORPHANS REMOVED - - - -

BHO-{38d2b11d-6fad-4184-8928-a6f0b780e530} - c:\windows\system32\uxlvpc.dll
BHO-{418F222B-1F33-4FD4-B950-0A03874BCAD5} - c:\windows\system32\vtUnnolj.dll
Toolbar-SITEguard - (no file)
HKCU-Run-Performance Center - c:\program files\Ascentive\Performance Center\ApcMain.exe
Notify-xxyaaBus - xxyaaBus.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://comcast.net/
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath - c:\documents and settings\Franklins\Application Data\Mozilla\Firefox\Profiles\rt2siwvw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/comcast.html
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll

ATTENTION: FIREFOX POLICES IS IN FORCE
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-23 23:46:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-12-23 23:52:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-24 04:51:47
ComboFix2.txt 2008-05-22 02:27:02

Pre-Run: 5,143,617,536 bytes free
Post-Run: 5,159,636,992 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

178 — E O F — 2008-09-20 04:39:14
I see your using Lime Wire. Please don't use it or any files tyou have gotten through this program untill we are finished.
A majority of infected computers we see are infected by files downloaded with these P2P programs.
When you download withthis program you are downloading from unknown sources and it's risky at best.

Personally I would lose that program fast.



______________________________
RUN HJT

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked


O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O20 - AppInit_DLLs: uxlvpc.dll

Close that.






________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File:: 
c:\windows\system32\edl.dat


Registry:: 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""


NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.





_______________________________________



Download and install CCleaner from here


If you use either the Firefox/ Mozilla browsers, the box to uncheck for Cookies (using ccleaner) is on the Applications tab, under Firefox/Mozilla.
[external image: Posted Image]

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".

    Now run the program by clicking on Run Cleaner

    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).




_________________________________

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please post the contents of that log.

    If you accidently close it you may find it here.
    Start -> All Programs -> Malwarebytes' Anti-Malware -> Logs


    ____________________________________

    If McAfee has been completely un-installed you can navigate to and delete these folders.
    Just delete the folders I have in BOLD[b/] type

    c:\documents and settings\All Users\Application Data\McAfee

    c:\documents and settings\Franklins\Application Data\McAfee





    _________________________
    In your next reply I would like to see:
    • A new HJT log
    • The report from ComboFix
    • The report from malwarebytes
Limewire has been removed and I would like ti remove all traces of that software as well.

HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:57:25 PM, on 12/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Synchronization Manager] "C:\WINDOWS\system32\mobsync.exe" /logon
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1203642423562
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 5212 bytes

Combo Fix log:

ComboFix 08-12-23.01 - Franklins 2008-12-26 23:09:33.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.305 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point

FILE ::
c:\windows\system32\edl.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\edl.dat

.
((((((((((((((((((((((((( Files Created from 2008-11-27 to 2008-12-27 )))))))))))))))))))))))))))))))
.

2008-12-23 21:47 . 2008-12-23 21:47 d——– c:\program files\Avira
2008-12-23 21:47 . 2008-12-23 21:47 d——– c:\documents and settings\All Users\Application Data\Avira
2008-12-20 09:06 . 2008-12-20 09:05 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-17 20:47 . 2007-10-05 13:39 d——– c:\documents and settings\Administrator\Application Data\Yahoo!
2008-12-17 20:47 . 2008-12-17 20:47 d——– c:\documents and settings\Administrator
2008-12-17 18:51 . 2008-12-17 18:51 75,776 –a—— C:\7d8c1112331c2220.bup
2008-12-13 22:46 . 2008-12-13 22:46 d——– C:\Games
2008-12-13 22:03 . 2008-12-13 22:03 d——– c:\program files\IObit
2008-12-13 22:03 . 2008-12-13 22:19 d——– c:\documents and settings\Franklins\Application Data\IObit
2008-12-07 17:09 . 2008-12-07 17:09 d——– c:\program files\ReflexiveArcade
2008-12-07 17:09 . 2008-12-15 21:01 d——– c:\program files\Off Road Arena
2008-12-07 17:04 . 2008-12-15 20:46 d——– c:\program files\Street Challenge LLC

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-27 04:10 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-21 20:48 ——— d—–w c:\documents and settings\Franklins\Application Data\SiteAdvisor
2008-12-21 20:26 ——— d—–w c:\program files\LimeWire
2008-12-20 14:04 ——— d—–w c:\program files\Java
2008-12-18 01:59 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2008-12-18 01:51 ——— d—–w c:\documents and settings\Franklins\Application Data\McAfee
2008-12-18 00:08 ——— d—–w c:\program files\Common Files\Adobe
2008-12-14 06:21 ——— d—–w c:\documents and settings\Franklins\Application Data\LimeWire
2008-12-07 21:06 ——— d—–w c:\program files\Yahoo!
2008-12-07 21:06 ——— d—–w c:\program files\Common Files\Blizzard Entertainment
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
.

((((((((((((((((((((((((((((( snapshot@2008-12-23_23.50.46.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-27 04:04:56 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_7f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-09-19 4347120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-13 143360]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-20 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Avant Browser\\avant.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 papycpu;papycpu;c:\windows\system32\drivers\papycpu.sys [2008-03-16 1984]
S3 I97DRIVER;I97DRIVER;\??\c:\program files\Avanquest\Fix-It\dgs.sys []
S3 MailScan;MailScan;\??\c:\progra~1\AVANQU~1\Fix-It\MailScan.sys []
S3 PCAlertDriver;PCAlertDriver;\??\c:\program files\MSI\PC Alert 4\NTGLM7X.sys []
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\system32\DRIVERS\rt2500usb.sys [2007-09-09 79616]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3baebf12-b299-11dd-8a1d-000c7692adf9}]
\Shell\AutoRun\command - E:\rcaeasyrip_setup.exe
\Shell\install\command - E:\rcaeasyrip_setup.exe
\Shell\usermanualEnglish\command - E:\rcaeasyrip_setup.exe /pdf_English
\Shell\usermanualFrench\command - E:\rcaeasyrip_setup.exe /pdf_French
\Shell\usermanualSpanish\command - E:\rcaeasyrip_setup.exe /pdf_Spanish

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8ff51df4-0449-11dd-89ad-000c7692adf9}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-12-18 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2008-01-03 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://comcast.net/
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath - c:\documents and settings\Franklins\Application Data\Mozilla\Firefox\Profiles\rt2siwvw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/comcast.html
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll

ATTENTION: FIREFOX POLICES IS IN FORCE
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-26 23:11:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-12-26 23:13:44
ComboFix-quarantined-files.txt 2008-12-27 04:12:55
ComboFix2.txt 2008-12-24 04:52:22
ComboFix3.txt 2008-05-22 02:27:02

Pre-Run: 5,158,973,440 bytes free
Post-Run: 5,146,509,312 bytes free

135 — E O F — 2008-09-20 04:39:14


Malwarebytes log:

Malwarebytes' Anti-Malware 1.31
Database version: 1552
Windows 5.1.2600 Service Pack 3

12/26/2008 11:54:43 PM
mbam-log-2008-12-26 (23-54-43).txt

Scan type: Full Scan (C:\|)
Objects scanned: 87418
Time elapsed: 32 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 35

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3ba4271e-5c1e-48e2-b432-d8bf420dd31d} (Rogue.DeusCleaner) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c24d7016-d00f-41ef-9781-984b6b5ff38f} (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{ec88fcd0-2ed5-4d65-9b4c-71d146b43a2e} (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e532cfb1-5edd-4663-8c22-bcd67b5e5bd4} (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\SystemErrorFixerDownloader (Rogue.SystemErrorFixer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\ConTest.dll (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\SysRestore.dll (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Ascentive (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SalesMon\Data (Rogue.Multiple) -> Quarantined and deleted successfully.

Files Infected:
C:\Qoobox\Quarantine\C\WINDOWS\system32\bhgsxeod.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dobgwpvc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fcavlhng.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fkcofybn.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\gyoosy.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ijyxvtvt.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\iutuiw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\oetsxx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tjxyjpig.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\uxlvpc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\vtUnnolj.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\zqxepm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP214\A0030760.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP215\A0032800.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP215\A0032802.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP215\A0032803.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP215\A0032804.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP215\A0032805.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP215\A0032806.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP215\A0032807.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032820.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032823.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032826.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032828.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032829.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032830.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032831.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032835.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032836.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032837.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032839.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{355B9294-9C40-493C-99D3-9C943CA42217}\RP216\A0032825.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ConTest.dll (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysRestore.dll (Rogue.AscentivePerformance) -> Quarantined and deleted successfully.
C:\Program Files\Ascentive\Performance Centertemp.htm (Rogue.Multiple) -> Quarantined and deleted successfully.
remove this folder

c:\documents and settings\Franklins\Application Data\LimeWire


________________________
The following programs are missing files need to be removed and re-installed if your going to continue to use them.

Have you uninstalled them?

PC Alert 4

Avanquest

SpeedUpMyPC 3


-_____________________________________
Everything else looks good .
How are things running ?
Those programs are not used yet do not show in the program group or add/remove programs. Can you suggest a means to remove all traces of those programs?

Also, I downloaded a bunch of MS updates and would like to repost a HJT log for you to look at.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:55:47 PM, on 12/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Synchronization Manager] "C:\WINDOWS\system32\mobsync.exe" /logon
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1203642423562
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 5530 bytes
The following 3 steps will remove those leftovers you asked about.





Step 1
___________________________________
Delete these folders if they exsist. The may or may not.
ONLY delete the folders I have in bold type.

c:\program files\Uniblue\SpeedUpMyPC 3
c:\prograam files\AVANQUEST
c:\program files\MSI\PC Alert 4





Step 2
_____________________________
click Start, >
All Programs,>
Accessories, >
System Tools>
Scheduled Tasks

right-click Uniblue SpeedUpMyPC Nag.job (if it exists}
in the Scheduled Tasks window, and then click Delete.




Step 3
________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

Driver:: 
dgs
MailScan
NTGLM7X


NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.








________________________________________
I see no evidence of a fire wall. I suggest you get one in place now.

A few words on Microsofts firewall in XP . It only works in one direction. Incoming.
That means if something gets by it you would never know it was trying
to contact the internet.
Example: A bad program installs itself. You would never know it was contacting the internet.
Downloading other nasties and so forth.

If you decide to run one of these you should be certain Microsofts firewall is disabled.
To disable it.

I will list a few free firewalls for you. These are good (free) firewalls:

Never run 2 firewalls together. They will interfere with each other.
So just download and install one!


Firewalls
Comodo If choosing this one be sure to UNCHECK install ask tool bar during installation,

Sunbelt Personal Firewall

Online armor Firewall









_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from combofix
  • How are things running ?
Things seem to be running ok, however, the new anit-virus software claims to be finding a suspect file in the Combofix directory. I assume this is ok?

Here's the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:56:56 PM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oacat.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Tall Emu\Online Armor\oahlp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Synchronization Manager] "C:\WINDOWS\system32\mobsync.exe" /logon
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1203642423562
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oacat.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe

–
End of file - 6133 bytes

ComboFix 08-12-23.01 - Franklins 2008-12-28 22:04:30.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.263 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: E:\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_MAILSCAN
——-\Service_MailScan


((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.

2008-12-27 22:40 . 2008-12-27 22:40 d——– c:\program files\MSXML 4.0
2008-12-27 22:30 . 2008-12-27 22:30 d——– c:\documents and settings\Franklins\Application Data\Windows Desktop Search
2008-12-27 22:29 . 2008-12-27 22:29 d——– c:\windows\system32\GroupPolicy
2008-12-27 22:29 . 2008-12-27 22:29 d——– c:\program files\Windows Desktop Search
2008-12-27 22:28 . 2008-03-07 12:02 192,000 —–c— c:\windows\system32\dllcache\offfilt.dll
2008-12-27 22:28 . 2008-03-07 12:02 98,304 —–c— c:\windows\system32\dllcache\nlhtml.dll
2008-12-27 22:28 . 2008-03-07 12:02 29,696 —–c— c:\windows\system32\dllcache\mimefilt.dll
2008-12-27 22:25 . 2008-10-16 15:38 6,066,176 —–c— c:\windows\system32\dllcache\ieframe.dll
2008-12-27 22:25 . 2007-04-17 04:32 2,455,488 —–c— c:\windows\system32\dllcache\ieapfltr.dat
2008-12-27 22:25 . 2007-03-08 00:10 991,232 —–c— c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-27 22:25 . 2008-10-16 15:38 459,264 —–c— c:\windows\system32\dllcache\msfeeds.dll
2008-12-27 22:25 . 2008-10-16 15:38 383,488 —–c— c:\windows\system32\dllcache\ieapfltr.dll
2008-12-27 22:25 . 2008-10-16 15:38 267,776 —–c— c:\windows\system32\dllcache\iertutil.dll
2008-12-27 22:25 . 2008-10-16 15:38 63,488 —–c— c:\windows\system32\dllcache\icardie.dll
2008-12-27 22:25 . 2008-10-16 15:38 52,224 —–c— c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-27 22:25 . 2008-10-16 08:11 13,824 —–c— c:\windows\system32\dllcache\ieudinit.exe
2008-12-27 22:22 . 2008-12-27 22:51 1,393 –a—— c:\windows\imsins.BAK
2008-12-27 22:14 . 2008-09-15 07:12 1,846,400 —–c— c:\windows\system32\dllcache\win32k.sys
2008-12-27 22:14 . 2008-09-08 05:41 333,824 —–c— c:\windows\system32\dllcache\srv.sys
2008-12-27 22:13 . 2008-08-14 05:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-27 22:13 . 2008-08-14 05:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-27 22:13 . 2008-08-14 04:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-27 22:13 . 2008-08-14 04:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-27 22:13 . 2008-09-04 12:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-12-27 22:13 . 2008-10-24 06:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-12-27 22:13 . 2008-10-15 11:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2008-12-26 23:17 . 2008-12-26 23:17 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-26 23:17 . 2008-12-03 19:59 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-26 23:17 . 2008-12-03 19:59 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-26 23:15 . 2008-12-26 23:15 d——– c:\program files\CCleaner
2008-12-23 21:47 . 2008-12-23 21:47 d——– c:\program files\Avira
2008-12-23 21:47 . 2008-12-23 21:47 d——– c:\documents and settings\All Users\Application Data\Avira
2008-12-20 09:06 . 2008-12-20 09:05 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-17 20:47 . 2007-10-05 13:39 d——– c:\documents and settings\Administrator\Application Data\Yahoo!
2008-12-17 20:47 . 2008-12-17 20:47 d——– c:\documents and settings\Administrator
2008-12-17 18:51 . 2008-12-17 18:51 75,776 –a—— C:\7d8c1112331c2220.bup
2008-12-13 22:46 . 2008-12-13 22:46 d——– C:\Games
2008-12-13 22:03 . 2008-12-13 22:03 d——– c:\program files\IObit
2008-12-13 22:03 . 2008-12-13 22:19 d——– c:\documents and settings\Franklins\Application Data\IObit
2008-12-07 17:09 . 2008-12-07 17:09 d——– c:\program files\ReflexiveArcade
2008-12-07 17:09 . 2008-12-15 21:01 d——– c:\program files\Off Road Arena
2008-12-07 17:04 . 2008-12-15 20:46 d——– c:\program files\Street Challenge LLC

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 03:04 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-21 20:48 ——— d—–w c:\documents and settings\Franklins\Application Data\SiteAdvisor
2008-12-21 20:26 ——— d—–w c:\program files\LimeWire
2008-12-20 14:04 ——— d—–w c:\program files\Java
2008-12-18 00:08 ——— d—–w c:\program files\Common Files\Adobe
2008-12-07 21:06 ——— d—–w c:\program files\Yahoo!
2008-12-07 21:06 ——— d—–w c:\program files\Common Files\Blizzard Entertainment
.

((((((((((((((((((((((((((((( snapshot@2008-12-23_23.50.46.68 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-09-09 17:27:13 151,552 -c–a-w c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2008-12-28 03:33:50 151,552 —-a-w c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
- 2007-09-09 17:28:03 3,915,776 -c–a-w c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2008-12-28 03:34:09 4,174,336 —-a-w c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
- 2007-09-09 17:28:08 344,064 -c–a-w c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2008-12-28 03:34:08 346,624 —-a-w c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
- 2007-09-09 17:27:12 352,256 -c–a-w c:\windows\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
+ 2008-12-28 03:33:51 397,312 —-a-w c:\windows\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
- 2007-09-09 17:28:03 593,920 -c–a-w c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
+ 2008-12-28 03:33:41 602,112 —-a-w c:\windows\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
- 2007-09-09 17:28:03 32,768 -c–a-w c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
+ 2008-12-28 03:34:11 32,768 —-a-w c:\windows\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
- 2007-09-09 17:28:08 184,320 -c–a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
+ 2008-12-28 03:34:04 184,320 —-a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
- 2007-09-09 17:28:07 126,976 -c–a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
+ 2008-12-28 03:34:04 131,072 —-a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
- 2007-09-09 17:28:07 376,832 -c–a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
+ 2008-12-28 03:34:03 376,832 —-a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
- 2007-09-09 17:28:07 151,552 -c–a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
+ 2008-12-28 03:34:03 151,552 —-a-w c:\windows\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
- 2007-09-09 17:28:05 4,972,544 -c–a-w c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2008-12-28 03:34:01 5,210,112 —-a-w c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
- 2007-09-09 17:28:06 897,024 -c–a-w c:\windows\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
+ 2008-12-28 03:33:59 897,024 —-a-w c:\windows\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
- 2007-09-09 17:28:08 528,384 -c–a-w c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
+ 2008-12-28 03:34:09 528,384 —-a-w c:\windows\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
- 2007-09-09 17:27:14 94,208 -c–a-w c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
+ 2008-12-28 03:33:53 102,400 —-a-w c:\windows\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
- 2007-09-09 17:27:14 126,976 -c–a-w c:\windows\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
+ 2008-12-28 03:34:16 126,976 —-a-w c:\windows\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
- 2007-09-09 17:27:14 401,408 -c–a-w c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
+ 2008-12-28 03:34:15 430,080 —-a-w c:\windows\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
- 2007-09-09 17:27:15 131,072 -c–a-w c:\windows\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
+ 2008-12-28 03:33:49 131,072 —-a-w c:\windows\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
- 2007-09-09 17:27:15 884,736 -c–a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
+ 2008-12-28 03:33:48 929,792 —-a-w c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
- 2007-09-09 17:27:22 159,744 -c–a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
+ 2008-12-28 03:33:42 159,744 —-a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
- 2007-09-09 17:27:22 16,384 -c–a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
+ 2008-12-28 03:33:41 32,768 —-a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
- 2007-09-09 17:27:17 5,623,808 -c–a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2008-12-28 03:33:44 5,971,968 —-a-w c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
- 2007-09-09 17:28:08 688,128 -c–a-w c:\windows\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
+ 2008-12-28 03:33:40 688,128 —-a-w c:\windows\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
- 2007-09-09 17:32:34 1,108,784 -c–a-w c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2008-12-28 03:34:13 1,152,040 —-a-w c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
- 2007-09-09 17:32:35 1,641,272 -c–a-w c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2008-12-28 03:34:12 1,635,376 —-a-w c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
- 2007-09-09 17:32:35 588,592 -c–a-w c:\windows\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
+ 2008-12-28 03:34:13 578,592 —-a-w c:\windows\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
- 2007-09-09 17:28:06 163,840 -c–a-w c:\windows\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
+ 2008-12-28 03:33:40 163,840 —-a-w c:\windows\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
- 2007-09-09 17:28:06 372,736 -c–a-w c:\windows\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
+ 2008-12-28 03:33:39 372,736 —-a-w c:\windows\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
- 2007-09-09 17:28:06 32,768 -c–a-w c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
+ 2008-12-28 03:34:08 32,768 —-a-w c:\windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
- 2007-09-09 17:28:06 86,016 -c–a-w c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
+ 2008-12-28 03:34:08 86,016 —-a-w c:\windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
- 2007-09-09 17:28:02 1,167,360 -c–a-w c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2008-12-28 03:34:06 1,204,224 —-a-w c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
- 2007-09-09 17:28:09 81,920 -c–a-w c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2008-12-28 03:33:38 81,920 —-a-w c:\windows\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
+ 2008-12-28 03:39:59 40,960 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\3df824565150953afd560ca20237b881\PresentationCFFRasterizer.ni.dll
+ 2008-12-28 03:39:51 12,570,624 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\011f8e31d197b4ccb6a61c2267a38e5c\PresentationCore.ni.dll
+ 2008-12-28 03:37:39 48,640 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\4ce7fd62d4107fbe996ab305eb21ee6a\PresentationFontCache.ni.exe
+ 2008-12-28 03:44:34 393,216 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\36c6cfd5d4e80d5c548f823b2bbf5457\PresentationFramework.Aero.ni.dll
+ 2008-12-28 03:44:45 552,960 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\3f18bff5107c9a8accae6c248fdf3c2e\PresentationFramework.Luna.ni.dll
+ 2008-12-28 03:42:18 15,036,416 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\60421dda88800b14dc101ed9dca422fe\PresentationFramework.ni.dll
+ 2008-12-28 03:44:50 274,432 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\81d2540bc1c18190d0431d9a61bee65b\PresentationFramework.Royale.ni.dll
+ 2008-12-28 03:44:40 245,760 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9df61ec7aad39fe0bac82139cd84e5e5\PresentationFramework.Classic.ni.dll
+ 2008-12-28 03:43:33 2,035,712 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\6d2716a55eb8ce6fc4cbf83f3ab329e3\PresentationUI.ni.dll
+ 2008-12-28 03:43:54 2,416,640 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\840c64bba900a6ed333ca39e63a9ca3b\ReachFramework.ni.dll
+ 2008-12-28 03:44:29 1,134,592 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\f94fbbe7d7c6e76d02cd9fb94ee8d910\System.Printing.ni.dll
+ 2008-12-28 03:39:53 50,688 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\9e249f5c0ef3e391c5aec1f9da805519\UIAutomationProvider.ni.dll
+ 2008-12-28 03:39:57 196,608 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\46e3ec015dd7b25d5ddc185534458122\UIAutomationTypes.ni.dll
+ 2008-12-28 03:38:27 3,395,584 —-a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\0703021437c2ec71213a6b701771be86\WindowsBase.ni.dll
+ 2008-10-24 11:21:09 455,296 ——w c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2008-08-14 10:09:26 2,145,280 ——w c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 09:33:16 2,066,048 ——w c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,023,936 ——w c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 10:11:02 2,189,184 ——w c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-04-14 00:11:48 61,440 -c–a-w c:\windows\ie7\admparse.dll
+ 2008-04-14 00:11:48 99,840 -c–a-w c:\windows\ie7\advpack.dll
+ 2008-04-14 00:11:51 33,792 -c–a-w c:\windows\ie7\custsat.dll
+ 2008-04-14 00:11:52 357,888 -c–a-w c:\windows\ie7\dxtmsft.dll
+ 2008-04-14 00:11:52 205,312 -c–a-w c:\windows\ie7\dxtrans.dll
+ 2008-04-14 00:11:53 55,808 -c–a-w c:\windows\ie7\extmgr.dll
+ 2008-04-14 00:11:54 38,912 -c–a-w c:\windows\ie7\hmmapi.dll
+ 2008-04-14 00:12:22 34,304 -c–a-w c:\windows\ie7\ie4uinit.exe
+ 2008-04-14 00:11:54 143,360 -c–a-w c:\windows\ie7\ieakeng.dll
+ 2008-04-14 00:11:54 216,576 -c–a-w c:\windows\ie7\ieaksie.dll
+ 2001-08-23 12:00:00 221,184 -c–a-w c:\windows\ie7\ieakui.dll
+ 2008-04-14 00:11:54 323,584 -c–a-w c:\windows\ie7\iedkcs32.dll
+ 2008-04-14 00:12:22 18,432 -c–a-w c:\windows\ie7\iedw.exe
+ 2008-04-14 00:11:54 251,904 -c–a-w c:\windows\ie7\iepeers.dll
+ 2008-04-14 00:11:54 48,640 -c–a-w c:\windows\ie7\iernonce.dll
+ 2008-04-14 00:11:54 62,976 -c–a-w c:\windows\ie7\iesetup.dll
+ 2008-04-14 00:12:22 93,184 -c–a-w c:\windows\ie7\iexplore.exe
+ 2008-04-14 00:11:54 35,840 -c–a-w c:\windows\ie7\imgutil.dll
+ 2008-04-14 00:11:55 96,256 -c–a-w c:\windows\ie7\inseng.dll
+ 2008-04-14 00:11:56 15,872 -c–a-w c:\windows\ie7\jsproxy.dll
+ 2008-04-14 00:11:56 22,016 -c–a-w c:\windows\ie7\licmgr10.dll
+ 2008-04-14 00:12:27 29,184 -c–a-w c:\windows\ie7\mshta.exe
+ 2008-06-23 15:09:27 3,067,392 -c–a-w c:\windows\ie7\mshtml.dll
+ 2008-04-14 00:11:59 449,024 -c–a-w c:\windows\ie7\mshtmled.dll
+ 2008-04-13 16:26:26 56,832 -c–a-w c:\windows\ie7\mshtmler.dll
+ 2001-08-23 12:00:00 146,432 -c–a-w c:\windows\ie7\msls31.dll
+ 2008-04-14 00:12:00 146,432 -c–a-w c:\windows\ie7\msrating.dll
+ 2008-04-14 00:12:00 532,480 -c–a-w c:\windows\ie7\mstime.dll
+ 2008-04-14 00:12:02 96,256 -c–a-w c:\windows\ie7\occache.dll
+ 2008-04-14 00:12:02 39,424 -c–a-w c:\windows\ie7\pngfilt.dll
+ 2007-08-13 23:54:42 32,960 -c–a-w c:\windows\ie7\spuninst\iecustom.dll
+ 2007-08-13 23:52:06 66,048 -c–a-w c:\windows\ie7\spuninst\ieResetIcons.exe
+ 2006-09-06 22:43:16 213,216 -c–a-w c:\windows\ie7\spuninst\spuninst.exe
+ 2006-09-06 22:43:18 371,424 -c–a-w c:\windows\ie7\spuninst\updspapi.dll
+ 2008-04-14 00:12:08 37,888 -c–a-w c:\windows\ie7\url.dll
+ 2008-06-26 08:15:30 619,520 -c–a-w c:\windows\ie7\urlmon.dll
+ 2008-04-14 00:12:08 851,968 -c–a-w c:\windows\ie7\vgx.dll
+ 2008-04-14 00:12:08 276,480 -c–a-w c:\windows\ie7\webcheck.dll
+ 2008-06-23 15:09:27 666,112 -c–a-w c:\windows\ie7\wininet.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c—-w c:\windows\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll
+ 2007-08-13 23:54:10 765,952 -c—-w c:\windows\ie7updates\KB938127-v2-IE7\vgx.dll
+ 2007-08-13 23:39:00 123,904 -c—-w c:\windows\ie7updates\KB956390-IE7\advpack.dll
+ 2007-08-13 23:39:00 123,904 -c—-w c:\windows\ie7updates\KB956390-IE7\advpack.dll.000
+ 2007-08-13 23:35:46 346,624 -c—-w c:\windows\ie7updates\KB956390-IE7\dxtmsft.dll
+ 2007-08-13 23:35:46 346,624 -c—-w c:\windows\ie7updates\KB956390-IE7\dxtmsft.dll.000
+ 2007-08-13 23:35:38 214,528 -c—-w c:\windows\ie7updates\KB956390-IE7\dxtrans.dll
+ 2007-08-13 23:35:38 214,528 -c—-w c:\windows\ie7updates\KB956390-IE7\dxtrans.dll.000
+ 2007-08-13 23:54:10 131,584 -c—-w c:\windows\ie7updates\KB956390-IE7\extmgr.dll
+ 2007-08-13 23:54:10 131,584 -c—-w c:\windows\ie7updates\KB956390-IE7\extmgr.dll.000
+ 2007-08-13 23:36:26 61,952 -c—-w c:\windows\ie7updates\KB956390-IE7\icardie.dll
+ 2007-08-13 23:39:06 54,784 -c—-w c:\windows\ie7updates\KB956390-IE7\ie4uinit.exe
+ 2007-08-13 23:39:06 54,784 -c—-w c:\windows\ie7updates\KB956390-IE7\ie4uinit.exe.000
+ 2007-08-13 23:39:26 152,064 -c—-w c:\windows\ie7updates\KB956390-IE7\ieakeng.dll
+ 2007-08-13 23:39:26 152,064 -c—-w c:\windows\ie7updates\KB956390-IE7\ieakeng.dll.000
+ 2007-08-13 23:39:54 229,376 -c—-w c:\windows\ie7updates\KB956390-IE7\ieaksie.dll
+ 2007-08-13 23:39:54 229,376 -c—-w c:\windows\ie7updates\KB956390-IE7\ieaksie.dll.000
+ 2007-08-13 22:56:54 161,792 -c—-w c:\windows\ie7updates\KB956390-IE7\ieakui.dll
+ 2007-02-12 21:10:12 2,451,312 -c—-w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dat
+ 2007-07-11 17:27:48 383,488 -c—-w c:\windows\ie7updates\KB956390-IE7\ieapfltr.dll
+ 2007-08-13 23:39:50 382,976 -c—-w c:\windows\ie7updates\KB956390-IE7\iedkcs32.dll
+ 2007-08-13 23:39:50 382,976 -c—-w c:\windows\ie7updates\KB956390-IE7\iedkcs32.dll.000
+ 2007-08-13 23:54:10 6,049,280 -c—-w c:\windows\ie7updates\KB956390-IE7\ieframe.dll
+ 2007-08-13 23:39:10 43,008 -c—-w c:\windows\ie7updates\KB956390-IE7\iernonce.dll
+ 2007-08-13 23:39:10 43,008 -c—-w c:\windows\ie7updates\KB956390-IE7\iernonce.dll.000
+ 2007-08-13 23:34:04 266,752 -c—-w c:\windows\ie7updates\KB956390-IE7\iertutil.dll
+ 2007-08-13 23:39:10 13,312 -c—-w c:\windows\ie7updates\KB956390-IE7\ieudinit.exe
+ 2007-08-13 23:43:56 622,080 -c—-w c:\windows\ie7updates\KB956390-IE7\iexplore.exe
+ 2007-08-13 23:43:56 622,080 -c—-w c:\windows\ie7updates\KB956390-IE7\iexplore.exe.000
+ 2007-08-13 23:54:10 27,136 -c—-w c:\windows\ie7updates\KB956390-IE7\jsproxy.dll
+ 2007-08-13 23:54:10 27,136 -c—-w c:\windows\ie7updates\KB956390-IE7\jsproxy.dll.000
+ 2007-08-13 23:54:10 458,752 -c—-w c:\windows\ie7updates\KB956390-IE7\msfeeds.dll
+ 2007-08-13 23:54:10 50,688 -c—-w c:\windows\ie7updates\KB956390-IE7\msfeedsbs.dll
+ 2007-08-13 23:54:12 3,578,368 -c—-w c:\windows\ie7updates\KB956390-IE7\mshtml.dll
+ 2007-08-13 23:54:10 475,648 -c—-w c:\windows\ie7updates\KB956390-IE7\mshtmled.dll
+ 2007-08-13 23:54:10 475,648 -c—-w c:\windows\ie7updates\KB956390-IE7\mshtmled.dll.000
+ 2007-08-13 23:44:26 192,000 -c—-w c:\windows\ie7updates\KB956390-IE7\msrating.dll
+ 2007-08-13 23:44:26 192,000 -c—-w c:\windows\ie7updates\KB956390-IE7\msrating.dll.000
+ 2007-08-13 23:54:10 670,720 -c—-w c:\windows\ie7updates\KB956390-IE7\mstime.dll
+ 2007-08-13 23:54:10 670,720 -c—-w c:\windows\ie7updates\KB956390-IE7\mstime.dll.000
+ 2007-08-13 23:44:06 101,376 -c—-w c:\windows\ie7updates\KB956390-IE7\occache.dll
+ 2007-08-13 23:44:06 101,376 -c—-w c:\windows\ie7updates\KB956390-IE7\occache.dll.000
+ 2007-08-13 23:36:12 44,544 -c—-w c:\windows\ie7updates\KB956390-IE7\pngfilt.dll
+ 2007-08-13 23:36:12 44,544 -c—-w c:\windows\ie7updates\KB956390-IE7\pngfilt.dll.000
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB956390-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB956390-IE7\spuninst\updspapi.dll
+ 2007-08-13 23:44:30 105,984 -c—-w c:\windows\ie7updates\KB956390-IE7\url.dll
+ 2007-08-13 23:44:30 105,984 -c—-w c:\windows\ie7updates\KB956390-IE7\url.dll.000
+ 2007-08-13 23:54:10 1,162,240 -c—-w c:\windows\ie7updates\KB956390-IE7\urlmon.dll
+ 2007-08-13 23:54:10 231,424 -c—-w c:\windows\ie7updates\KB956390-IE7\webcheck.dll
+ 2007-08-13 23:54:10 231,424 -c—-w c:\windows\ie7updates\KB956390-IE7\webcheck.dll.000
+ 2007-08-13 23:54:10 818,688 -c—-w c:\windows\ie7updates\KB956390-IE7\wininet.dll
+ 2008-08-26 07:24:28 124,928 -c—-w c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2008-08-26 07:24:28 124,928 -c—-w c:\windows\ie7updates\KB958215-IE7\advpack.dll.000
+ 2008-08-26 07:24:28 347,136 -c—-w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2008-08-26 07:24:28 214,528 -c—-w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2008-08-26 07:24:28 133,120 -c—-w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2008-08-26 07:24:28 63,488 -c—-w c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2008-08-26 07:24:28 63,488 -c—-w c:\windows\ie7updates\KB958215-IE7\icardie.dll.000
+ 2008-08-25 08:37:59 70,656 -c—-w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2008-08-26 07:24:28 153,088 -c—-w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2008-08-26 07:24:28 230,400 -c—-w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2008-08-23 05:54:51 161,792 -c—-w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 -c—-w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dat
+ 2008-08-26 07:24:28 383,488 -c—-w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2008-08-26 07:24:28 383,488 -c—-w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll.000
+ 2008-08-26 07:24:29 384,512 -c—-w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2008-10-03 17:41:15 6,066,176 -c—-w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2008-10-03 17:41:15 6,066,176 -c—-w c:\windows\ie7updates\KB958215-IE7\ieframe.dll.000
+ 2008-08-26 07:24:29 44,544 -c—-w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2008-08-26 07:24:29 267,776 -c—-w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2008-08-26 07:24:29 267,776 -c—-w c:\windows\ie7updates\KB958215-IE7\iertutil.dll.000
+ 2008-08-25 08:38:00 13,824 -c—-w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2008-08-23 05:56:15 635,848 -c—-w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2008-08-23 05:56:15 635,848 -c—-w c:\windows\ie7updates\KB958215-IE7\iexplore.exe.000
+ 2008-08-26 07:24:30 27,648 -c—-w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2008-08-26 07:24:30 459,264 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2008-08-26 07:24:30 459,264 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll.000
+ 2008-08-26 07:24:30 52,224 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2008-08-26 07:24:30 52,224 -c—-w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll.000
+ 2008-08-27 18:54:32 3,593,216 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtml.dll
+ 2008-08-27 18:54:32 3,593,216 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtml.dll.000
+ 2008-08-26 07:24:30 477,696 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2008-08-26 07:24:30 477,696 -c—-w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll.000
+ 2008-08-26 07:24:30 193,024 -c—-w c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2008-08-26 07:24:30 671,232 -c—-w c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2008-08-26 07:24:30 102,912 -c—-w c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2008-08-26 07:24:30 44,544 -c—-w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2008-08-26 07:24:30 105,984 -c—-w c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2008-08-26 07:24:30 105,984 -c—-w c:\windows\ie7updates\KB958215-IE7\url.dll.000
+ 2008-08-26 07:24:31 1,159,680 -c—-w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2008-08-26 07:24:31 1,159,680 -c—-w c:\windows\ie7updates\KB958215-IE7\urlmon.dll.000
+ 2008-08-26 07:24:31 233,472 -c—-w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2008-08-26 07:24:31 233,472 -c—-w c:\windows\ie7updates\KB958215-IE7\webcheck.dll.000
+ 2008-08-26 07:24:31 826,368 -c—-w c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2008-08-26 07:24:31 826,368 -c—-w c:\windows\ie7updates\KB958215-IE7\wininet.dll.000
+ 2008-10-17 07:08:40 3,593,216 -c—-w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 01:22:39 213,216 -c—-w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c—-w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
+ 2008-12-28 03:40:59 32,768 —-a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
- 2006-10-30 07:34:02 159,744 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
+ 2007-10-11 14:55:14 159,744 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
- 2006-10-30 07:33:58 741,376 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
+ 2007-10-11 14:55:10 864,256 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
- 2006-10-30 07:34:00 352,256 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.dll
+ 2007-10-11 14:55:12 397,312 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.dll
- 2006-10-30 07:34:00 151,552 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll
+ 2007-10-11 14:55:12 151,552 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll
- 2006-10-30 07:34:02 2,560 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
+ 2007-10-11 14:55:14 2,560 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelEvents.dll
- 2006-10-30 07:34:02 61,440 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
+ 2007-10-11 14:55:14 61,440 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
- 2006-10-30 07:34:02 11,264 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
+ 2007-10-11 14:55:14 11,264 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
- 2006-10-30 07:34:00 94,208 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMDiagnostics.dll
+ 2007-10-11 14:55:14 102,400 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMDiagnostics.dll
- 2006-10-30 07:34:02 122,880 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
+ 2007-10-11 14:55:14 122,880 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
- 2006-10-30 07:34:02 884,736 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
+ 2007-10-11 14:55:14 929,792 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
- 2006-10-30 07:34:02 5,623,808 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
+ 2007-10-11 14:55:14 5,971,968 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
- 2006-10-30 07:34:00 159,744 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
+ 2007-10-11 14:55:14 159,744 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
- 2006-10-30 07:34:00 16,384 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
+ 2007-10-11 14:55:14 32,768 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
- 2006-10-30 07:34:02 143,360 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
+ 2007-10-11 14:55:14 143,360 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
- 2006-07-26 01:32:00 14,648 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
+ 2007-10-06 08:18:12 16,936 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
- 2006-10-21 01:29:46 72,992 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
+ 2007-10-09 18:03:00 76,312 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
- 2006-10-21 01:21:24 32,768 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
+ 2007-10-09 17:58:12 32,768 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
- 2006-10-21 01:21:24 36,864 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
+ 2007-10-09 17:58:12 36,864 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
- 2006-10-21 01:29:52 106,272 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
+ 2007-10-09 18:03:08 121,368 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
- 2006-10-21 01:21:26 897,024 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationUI.dll
+ 2007-10-09 17:58:14 897,024 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationUI.dll
- 2006-10-21 01:21:26 14,848 -c–a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe
+ 2007-10-09 17:58:20 14,848 —-a-w c:\windows\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe
- 2008-04-14 00:11:48 61,440 —-a-w c:\windows\system32\admparse.dll
+ 2007-08-13 23:39:20 71,680 —-a-w c:\windows\system32\admparse.dll
- 2008-04-14 00:11:48 99,840 —-a-w c:\windows\system32\advpack.dll
+ 2008-10-16 20:38:34 124,928 —-a-w c:\windows\system32\advpack.dll
+ 2007-08-13 23:39:20 71,680 -c—-w c:\windows\system32\dllcache\admparse.dll
+ 2008-10-16 20:38:34 124,928 -c—-w c:\windows\system32\dllcache\advpack.dll
- 2008-06-20 11:40:08 138,496 -c—-w c:\windows\system32\dllcache\afd.sys
+ 2008-08-14 10:04:36 138,496 -c—-w c:\windows\system32\dllcache\afd.sys
+ 2006-09-23 18:12:50 1,022,976 -c—-w c:\windows\system32\dllcache\browseui.dll
+ 2007-08-13 23:42:54 17,408 -c—-w c:\windows\system32\dllcache\corpol.dll
- 2008-04-14 00:11:51 33,792 -c–a-w c:\windows\system32\dllcache\custsat.dll
+ 2007-08-13 23:54:10 33,792 -c–a-w c:\windows\system32\dllcache\custsat.dll
+ 2008-10-16 20:38:34 347,136 -c—-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 20:38:34 214,528 -c—-w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 20:38:35 133,120 -c—-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-23 12:36:14 286,720 -c—-w c:\windows\system32\dllcache\gdi32.dll
- 2008-04-14 00:11:54 38,912 -c–a-w c:\windows\system32\dllcache\hmmapi.dll
+ 2007-08-13 23:18:02 60,416 -c–a-w c:\windows\system32\dllcache\hmmapi.dll
+ 2008-10-16 13:11:09 70,656 -c—-w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-16 20:38:35 153,088 -c—-w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-16 20:38:35 230,400 -c—-w c:\windows\system32\dllcache\ieaksie.dll
- 2001-08-23 12:00:00 221,184 -c–a-w c:\windows\system32\dllcache\ieakui.dll
+ 2008-10-15 07:04:53 161,792 -c—-w c:\windows\system32\dllcache\ieakui.dll
+ 2008-10-16 20:38:35 384,512 -c—-w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-14 00:12:22 18,432 -c–a-w c:\windows\system32\dllcache\iedw.exe
+ 2007-08-13 23:44:02 69,120 -c–a-w c:\windows\system32\dllcache\iedw.exe
+ 2007-08-13 23:45:18 78,336 -c—-w c:\windows\system32\dllcache\ieencode.dll
+ 2007-08-13 23:54:10 191,488 -c—-w c:\windows\system32\dllcache\iepeers.dll
+ 2008-10-16 20:38:37 44,544 -c—-w c:\windows\system32\dllcache\iernonce.dll
+ 2007-08-13 23:39:12 55,296 -c—-w c:\windows\system32\dllcache\iesetup.dll
+ 2008-10-15 07:06:26 633,632 -c—-w c:\windows\system32\dllcache\iexplore.exe
+ 2007-08-13 23:36:06 36,352 -c—-w c:\windows\system32\dllcache\imgutil.dll
+ 2007-08-13 23:39:02 92,672 -c—-w c:\windows\system32\dllcache\inseng.dll
+ 2008-10-16 20:38:37 27,648 -c—-w c:\windows\system32\dllcache\jsproxy.dll
+ 2007-08-13 23:44:18 40,960 -c—-w c:\windows\system32\dllcache\licmgr10.dll
+ 2008-06-18 06:09:22 100,864 -c—-w c:\windows\system32\dllcache\logagent.exe
+ 2007-08-13 23:32:30 45,568 -c—-w c:\windows\system32\dllcache\mshta.exe
- 2008-06-23 15:09:27 3,067,392 -c—-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 -c—-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-10-16 20:38:38 477,696 -c—-w c:\windows\system32\dllcache\mshtmled.dll
+ 2007-08-13 23:01:12 48,128 -c—-w c:\windows\system32\dllcache\mshtmler.dll
- 2001-08-23 12:00:00 146,432 -c–a-w c:\windows\system32\dllcache\msls31.dll
+ 2007-08-13 23:54:10 156,160 -c–a-w c:\windows\system32\dllcache\msls31.dll
+ 2008-10-16 20:38:38 193,024 -c—-w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 20:38:39 671,232 -c—-w c:\windows\system32\dllcache\mstime.dll
- 2008-04-14 00:12:01 1,306,624 -c—-w c:\windows\system32\dllcache\msxml6.dll
+ 2008-09-10 01:14:56 1,307,648 -c—-w c:\windows\system32\dllcache\msxml6.dll
+ 2008-10-16 20:38:39 102,912 -c—-w c:\windows\system32\dllcache\occache.dll
+ 2008-10-16 20:38:39 44,544 -c—-w c:\windows\system32\dllcache\pngfilt.dll
+ 2006-09-23 18:12:50 474,112 -c—-w c:\windows\system32\dllcache\shlwapi.dll
- 2008-04-14 00:12:07 246,814 -c—-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:02:42 247,326 -c—-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-16 20:38:39 105,984 -c—-w c:\windows\system32\dllcache\url.dll
- 2008-06-26 08:15:30 619,520 -c—-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 -c—-w c:\windows\system32\dllcache\urlmon.dll
- 2008-04-14 00:12:08 851,968 -c–a-w c:\windows\system32\dllcache\vgx.dll
+ 2008-05-27 17:23:58 765,952 -c–a-w c:\windows\system32\dllcache\vgx.dll
+ 2008-10-16 20:38:39 233,472 -c—-w c:\windows\system32\dllcache\webcheck.dll
- 2007-04-10 19:00:46 236,928 -c—-w c:\windows\system32\dllcache\WgaLogon.dll
+ 2008-09-06 04:30:42 241,704 -c—-w c:\windows\system32\dllcache\wgaLogon.dll
- 2007-04-10 19:01:18 336,768 -c—-w c:\windows\system32\dllcache\WgaTray.exe
+ 2008-09-06 04:29:58 917,032 -c—-w c:\windows\system32\dllcache\WgaTray.exe
- 2008-06-23 15:09:27 666,112 -c—-w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 20:38:40 826,368 -c—-w c:\windows\system32\dllcache\wininet.dll
+ 2008-06-18 10:03:08 938,496 -c—-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-10-19 01:47:22 2,450,944 -c—-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 -c—-w c:\windows\system32\dllcache\WMVCore.dll
- 2008-06-20 11:40:08 138,496 —-a-w c:\windows\system32\drivers\afd.sys
+ 2008-08-14 10:04:36 138,496 —-a-w c:\windows\system32\drivers\afd.sys
- 2008-04-13 19:17:01 456,576 —-a-w c:\windows\system32\drivers\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
- 2008-04-13 19:15:11 334,848 —-a-w c:\windows\system32\drivers\srv.sys
+ 2008-09-08 10:41:42 333,824 —-a-w c:\windows\system32\drivers\srv.sys
- 2008-04-14 00:11:52 357,888 —-a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 ——w c:\windows\system32\dxtmsft.dll
- 2008-04-14 00:11:52 205,312 —-a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 ——w c:\windows\system32\dxtrans.dll
- 2006-10-21 01:29:46 69,408 —-a-w c:\windows\system32\dxva2.dll
+ 2007-10-09 18:03:00 73,752 —-a-w c:\windows\system32\dxva2.dll
- 2006-10-21 01:30:00 478,496 —-a-w c:\windows\system32\evr.dll
+ 2007-10-09 18:03:12 493,080 —-a-w c:\windows\system32\evr.dll
- 2008-04-14 00:11:53 55,808 —-a-w c:\windows\system32\extmgr.dll
+ 2008-10-16 20:38:35 133,120 ——w c:\windows\system32\extmgr.dll
- 2008-05-23 01:47:57 118,152 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-28 03:47:31 118,152 —-a-w c:\windows\system32\FNTCACHE.DAT
- 2008-04-14 00:11:54 285,184 —-a-w c:\windows\system32\gdi32.dll
+ 2008-10-23 12:36:14 286,720 —-a-w c:\windows\system32\gdi32.dll
+ 2008-05-29 16:16:52 633,344 ——w c:\windows\system32\gpprefcl.dll
- 2006-10-30 07:33:58 556,296 —-a-w c:\windows\system32\icardagt.exe
+ 2007-10-11 14:55:10 579,584 —-a-w c:\windows\system32\icardagt.exe
+ 2008-10-16 20:38:35 63,488 —-a-w c:\windows\system32\icardie.dll
- 2006-10-30 07:33:58 9,480 —-a-w c:\windows\system32\icardres.dll
+ 2007-10-11 14:55:10 11,776 —-a-w c:\windows\system32\icardres.dll
+ 2006-06-29 13:05:44 26,112 ——w c:\windows\system32\idndl.dll
- 2008-04-14 00:12:22 34,304 —-a-w c:\windows\system32\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 ——w c:\windows\system32\ie4uinit.exe
- 2008-04-14 00:11:54 143,360 —-a-w c:\windows\system32\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 ——w c:\windows\system32\ieakeng.dll
- 2008-04-14 00:11:54 216,576 —-a-w c:\windows\system32\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 ——w c:\windows\system32\ieaksie.dll
- 2001-08-23 12:00:00 221,184 —-a-w c:\windows\system32\ieakui.dll
+ 2008-10-15 07:04:53 161,792 ——w c:\windows\system32\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w c:\windows\system32\ieapfltr.dat
+ 2008-10-16 20:38:35 383,488 —-a-w c:\windows\system32\ieapfltr.dll
- 2008-04-14 00:11:54 323,584 —-a-w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 ——w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:38:37 6,066,176 —-a-w c:\windows\system32\ieframe.dll
- 2008-04-14 00:11:54 251,904 —-a-w c:\windows\system32\iepeers.dll
+ 2007-08-13 23:54:10 191,488 —-a-w c:\windows\system32\iepeers.dll
- 2008-04-14 00:11:54 48,640 —-a-w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:38:37 44,544 ——w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:38:37 267,776 —-a-w c:\windows\system32\iertutil.dll
- 2008-04-14 00:11:54 62,976 —-a-w c:\windows\system32\iesetup.dll
+ 2007-08-13 23:39:12 55,296 —-a-w c:\windows\system32\iesetup.dll
+ 2008-10-16 13:11:09 13,824 —-a-w c:\windows\system32\ieudinit.exe
+ 2007-08-13 23:54:10 180,736 ——w c:\windows\system32\ieui.dll
- 2008-04-14 00:11:54 35,840 —-a-w c:\windows\system32\imgutil.dll
+ 2007-08-13 23:36:06 36,352 —-a-w c:\windows\system32\imgutil.dll
- 2006-10-30 07:33:58 83,968 —-a-w c:\windows\system32\infocardapi.dll
+ 2007-10-11 14:55:10 88,576 —-a-w c:\windows\system32\infocardapi.dll
- 2008-04-14 00:11:55 96,256 —-a-w c:\windows\system32\inseng.dll
+ 2007-08-13 23:39:02 92,672 —-a-w c:\windows\system32\inseng.dll
- 2008-04-14 00:11:56 15,872 —-a-w c:\windows\system32\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 ——w c:\windows\system32\jsproxy.dll
- 2008-03-20 22:06:36 1,480,232 —-a-w c:\windows\system32\LegitCheckControl.dll
+ 2008-09-06 04:30:06 1,480,232 —-a-w c:\windows\system32\LegitCheckControl.dll
- 2008-04-14 00:11:56 22,016 —-a-w c:\windows\system32\licmgr10.dll
+ 2007-08-13 23:44:18 40,960 —-a-w c:\windows\system32\licmgr10.dll
- 2006-10-19 00:03:58 100,864 —-a-w c:\windows\system32\logagent.exe
+ 2008-06-18 06:09:22 100,864 —-a-w c:\windows\system32\logagent.exe
- 2006-10-21 01:30:06 1,980,704 —-a-w c:\windows\system32\milcore.dll
+ 2007-10-09 18:03:14 1,986,072 —-a-w c:\windows\system32\milcore.dll
- 2008-04-14 00:11:57 29,696 —-a-w c:\windows\system32\mimefilt.dll
+ 2008-03-07 17:02:08 29,696 —-a-w c:\windows\system32\mimefilt.dll
- 2008-08-26 17:28:14 16,208,504 —-a-w c:\windows\system32\MRT.exe
+ 2008-12-09 20:24:38 17,593,280 —-a-w c:\windows\system32\MRT.exe
+ 2008-10-16 20:38:37 459,264 —-a-w c:\windows\system32\msfeeds.dll
+ 2008-10-16 20:38:37 52,224 —-a-w c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 23:36:40 12,288 ——w c:\windows\system32\msfeedssync.exe
- 2008-04-14 00:12:27 29,184 —-a-w c:\windows\system32\mshta.exe
+ 2007-08-13 23:32:30 45,568 —-a-w c:\windows\system32\mshta.exe
- 2008-06-23 15:09:27 3,067,392 —-a-w c:\windows\system32\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 —-a-w c:\windows\system32\mshtml.dll
- 2008-04-14 00:11:59 449,024 —-a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 —-a-w c:\windows\system32\mshtmled.dll
- 2008-04-13 16:26:26 56,832 —-a-w c:\windows\system32\mshtmler.dll
+ 2007-08-13 23:01:12 48,128 —-a-w c:\windows\system32\mshtmler.dll
- 2001-08-23 12:00:00 146,432 —-a-w c:\windows\system32\msls31.dll
+ 2007-08-13 23:54:10 156,160 —-a-w c:\windows\system32\msls31.dll
- 2008-04-14 00:12:00 146,432 —-a-w c:\windows\system32\msrating.dll
+ 2008-10-16 20:38:38 193,024 ——w c:\windows\system32\msrating.dll
+ 2008-05-27 03:17:44 34,816 ——w c:\windows\system32\msscb.dll
+ 2008-05-27 03:17:26 60,416 ——w c:\windows\system32\msscntrs.dll
+ 2008-05-27 03:17:38 11,776 ——w c:\windows\system32\msshooks.dll
+ 2008-05-27 03:18:34 231,936 ——w c:\windows\system32\msshsq.dll
+ 2008-05-27 03:17:26 87,552 ——w c:\windows\system32\mssitlb.dll
+ 2008-05-27 03:18:26 350,208 ——w c:\windows\system32\mssph.dll
+ 2008-05-27 03:18:56 203,776 ——w c:\windows\system32\mssphtb.dll
+ 2008-05-27 03:17:28 32,768 ——w c:\windows\system32\mssprxy.dll
+ 2008-05-27 03:21:26 1,418,240 ——w c:\windows\system32\mssrch.dll
+ 2008-05-27 03:18:42 44,032 ——w c:\windows\system32\msstrc.dll
- 2008-04-14 00:12:00 532,480 —-a-w c:\windows\system32\mstime.dll
+ 2008-10-16 20:38:39 671,232 ——w c:\windows\system32\mstime.dll
- 2008-04-14 00:12:01 1,104,896 —-a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 17:15:04 1,106,944 —-a-w c:\windows\system32\msxml3.dll
- 2007-05-08 20:03:04 1,275,392 —-a-w c:\windows\system32\msxml4.dll
+ 2008-09-30 21:43:34 1,286,152 —-a-w c:\windows\system32\msxml4.dll
- 2008-04-14 00:12:01 1,306,624 —-a-w c:\windows\system32\msxml6.dll
+ 2008-09-10 01:14:56 1,307,648 —-a-w c:\windows\system32\msxml6.dll
- 2008-04-14 00:12:01 337,408 —-a-w c:\windows\system32\netapi32.dll
+ 2008-10-15 16:34:24 337,408 —-a-w c:\windows\system32\netapi32.dll
- 2008-04-14 00:12:02 98,304 —-a-w c:\windows\system32\nlhtml.dll
+ 2008-03-07 17:02:08 98,304 —-a-w c:\windows\system32\nlhtml.dll
+ 2006-06-28 22:59:26 24,576 ——w c:\windows\system32\nlsdl.dll
+ 2006-06-29 13:05:44 23,552 ——w c:\windows\system32\normaliz.dll
- 2008-04-13 18:31:21 2,065,792 —-a-w c:\windows\system32\ntkrnlpa.exe
+ 2008-08-14 09:33:16 2,066,048 —-a-w c:\windows\system32\ntkrnlpa.exe
- 2008-04-13 19:27:53 2,188,928 —-a-w c:\windows\system32\ntoskrnl.exe
+ 2008-08-14 10:11:02 2,189,184 —-a-w c:\windows\system32\ntoskrnl.exe
- 2008-04-14 00:12:02 96,256 —-a-w c:\windows\system32\occache.dll
+ 2008-10-16 20:38:39 102,912 ——w c:\windows\system32\occache.dll
+ 2008-05-27 03:19:36 273,408 ——w c:\windows\system32\oeph.dll
+ 2008-05-27 03:19:16 11,264 ——w c:\windows\system32\oephRes.dll
- 2008-04-14 00:12:02 192,000 —-a-w c:\windows\system32\offfilt.dll
+ 2008-03-07 17:02:08 192,000 —-a-w c:\windows\system32\offfilt.dll
- 2008-11-14 00:02:41 71,308 —-a-w c:\windows\system32\perfc009.dat
+ 2008-12-28 03:29:38 78,362 —-a-w c:\windows\system32\perfc009.dat
- 2008-11-14 00:02:41 441,624 —-a-w c:\windows\system32\perfh009.dat
+ 2008-12-28 03:29:38 462,668 —-a-w c:\windows\system32\perfh009.dat
- 2008-04-14 00:12:02 39,424 —-a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 ——w c:\windows\system32\pngfilt.dll
- 2006-10-21 01:29:52 104,224 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
+ 2007-10-09 18:03:04 106,520 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
- 2006-10-21 01:29:58 344,352 —-a-w c:\windows\system32\PresentationHost.exe
+ 2007-10-09 18:03:08 350,744 —-a-w c:\windows\system32\PresentationHost.exe
- 2006-10-21 01:29:46 20,768 —-a-w c:\windows\system32\PresentationHostProxy.dll
+ 2007-10-09 18:03:02 33,304 —-a-w c:\windows\system32\PresentationHostProxy.dll
- 2006-10-21 01:30:02 769,312 —-a-w c:\windows\system32\PresentationNative_v0300.dll
+ 2007-10-09 18:03:12 779,800 —-a-w c:\windows\system32\PresentationNative_v0300.dll
+ 2008-05-27 03:18:08 71,680 ——w c:\windows\system32\propdefs.dll
+ 2008-05-27 03:17:48 754,176 ——w c:\windows\system32\propsys.dll
+ 2008-05-27 03:18:32 38,400 ——w c:\windows\system32\rtffilt.dll
+ 2008-05-27 03:17:56 87,552 ——w c:\windows\system32\searchfilterhost.exe
+ 2008-05-27 03:18:44 439,808 ——w c:\windows\system32\searchindexer.exe
+ 2008-05-27 03:18:18 184,832 ——w c:\windows\system32\searchprotocolhost.exe
- 2006-09-25 21:58:48 14,640 —-a-w c:\windows\system32\spmsg.dll
+ 2007-11-30 12:39:22 17,272 ——w c:\windows\system32\spmsg.dll
+ 2008-05-27 03:17:30 301,568 ——w c:\windows\system32\srchadmin.dll
- 2008-04-14 00:12:07 246,814 —-a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:02:42 247,326 —-a-w c:\windows\system32\strmdll.dll
+ 2008-05-27 02:59:40 106,605 ——w c:\windows\system32\structuredqueryschema.bin
+ 2008-05-27 02:59:42 18,904 ——w c:\windows\system32\structuredqueryschematrivial.bin
+ 2008-05-27 03:21:08 1,582,592 ——w c:\windows\system32\tquery.dll
+ 2007-10-09 17:58:20 16,896 —-a-w c:\windows\system32\tswpfwrp.exe
- 2008-07-11 12:42:28 62,976 —-a-w c:\windows\system32\tzchange.exe
+ 2008-10-23 10:06:59 62,976 —-a-w c:\windows\system32\tzchange.exe
- 2006-10-21 01:29:54 159,008 —-a-w c:\windows\system32\UIAutomationCore.dll
+ 2007-10-09 18:03:08 161,304 —-a-w c:\windows\system32\UIAutomationCore.dll
+ 2008-05-27 03:19:20 97,792 ——w c:\windows\system32\UncCplExt.dll
+ 2008-05-27 03:19:22 143,872 ——w c:\windows\system32\UncDMS.dll
+ 2008-05-27 03:19:28 108,032 ——w c:\windows\system32\UncNE.dll
+ 2008-05-27 03:19:28 131,072 ——w c:\windows\system32\UncPH.dll
+ 2008-05-27 03:19:26 2,048 ——w c:\windows\system32\UncRes.dll
- 2008-04-14 00:12:08 37,888 —-a-w c:\windows\system32\url.dll
+ 2008-10-16 20:38:39 105,984 —-a-w c:\windows\system32\url.dll
- 2008-06-26 08:15:30 619,520 —-a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 —-a-w c:\windows\system32\urlmon.dll
- 2008-04-14 00:12:08 276,480 —-a-w c:\windows\system32\webcheck.dll
+ 2008-10-16 20:38:39 233,472 —-a-w c:\windows\system32\webcheck.dll
- 2007-04-10 19:00:46 236,928 —-a-w c:\windows\system32\WgaLogon.dll
+ 2008-09-06 04:30:42 241,704 —-a-w c:\windows\system32\WgaLogon.dll
- 2007-04-10 19:01:18 336,768 —-a-w c:\windows\system32\WgaTray.exe
+ 2008-09-06 04:29:58 917,032 —-a-w c:\windows\system32\WgaTray.exe
- 2008-04-13 19:30:10 1,845,632 —-a-w c:\windows\system32\win32k.sys
+ 2008-09-15 12:12:56 1,846,400 —-a-w c:\windows\system32\win32k.sys
+ 2007-08-13 23:45:16 206,336 ——w c:\windows\system32\WinFXDocObj.exe
- 2008-06-23 15:09:27 666,112 —-a-w c:\windows\system32\wininet.dll
+ 2008-10-16 20:38:40 826,368 —-a-w c:\windows\system32\wininet.dll
- 2006-10-19 01:47:20 937,984 —-a-w c:\windows\system32\WMNetMgr.dll
+ 2008-06-18 10:03:08 938,496 —-a-w c:\windows\system32\WMNetmgr.dll
- 2006-10-19 01:47:22 2,450,944 —-a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 —-a-w c:\windows\system32\WMVCore.dll
+ 2008-05-27 03:18:34 56,320 ——w c:\windows\system32\xmlfilter.dll
- 2006-10-21 01:29:54 304,928 —-a-w c:\windows\system32\XPSViewer\XPSViewer.exe
+ 2007-10-09 18:03:08 308,760 —-a-w c:\windows\system32\XPSViewer\XPSViewer.exe
+ 2008-12-29 03:10:37 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_5bc.dat
+ 2008-12-29 03:09:14 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_6cc.dat
+ 2008-09-30 21:42:08 1,286,152 —-a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-30 21:45:12 91,656 —-a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-09-19 4347120]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-13 143360]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-20 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Avant Browser\\avant.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 papycpu;papycpu;c:\windows\system32\drivers\papycpu.sys [2008-03-16 1984]
S3 I97DRIVER;I97DRIVER;\??\c:\program files\Avanquest\Fix-It\dgs.sys []
S3 PCAlertDriver;PCAlertDriver;\??\c:\program files\MSI\PC Alert 4\NTGLM7X.sys []
S3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\system32\DRIVERS\rt2500usb.sys [2007-09-09 79616]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3baebf12-b299-11dd-8a1d-000c7692adf9}]
\Shell\AutoRun\command - E:\rcaeasyrip_setup.exe
\Shell\install\command - E:\rcaeasyrip_setup.exe
\Shell\usermanualEnglish\command - E:\rcaeasyrip_setup.exe /pdf_English
\Shell\usermanualFrench\command - E:\rcaeasyrip_setup.exe /pdf_French
\Shell\usermanualSpanish\command - E:\rcaeasyrip_setup.exe /pdf_Spanish

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8ff51df4-0449-11dd-89ad-000c7692adf9}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://comcast.net/
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath - c:\documents and settings\Franklins\Application Data\Mozilla\Firefox\Profiles\rt2siwvw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/comcast.html
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll

ATTENTION: FIREFOX POLICES IS IN FORCE
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-28 22:09:53
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\searchindexer.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-12-28 22:14:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-29 03:14:03
ComboFix2.txt 2008-12-27 04:13:46
ComboFix3.txt 2008-12-24 04:52:22
ComboFix4.txt 2008-05-22 02:27:02

Pre-Run: 4,912,218,112 bytes free
Post-Run: 4,904,587,264 bytes free

681 — E O F — 2008-09-20 04:39:14

Things seem to be running ok, however, the new anit-virus software claims to be finding a suspect file in the Combofix directory. I assume this is ok?

Yes that's OK and we're going to take care of that now.




Great news ! [external image: Posted Image]

Your log now appears to be clean.

Just a little clean up to do.





___________________________________
The following will implement some cleanup procedures for the tool we used as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /u







A few things to help with possible threats

These are optional . But will help protect you further.
and
Some of these you may already have.





_______________________________________
So many people are point and click crazy either because there naive or their in a rush.

Always watch closely to any software your installing.
If they want to install something more than their program stop right there and investigate what it is they want to place on your computer.
If they give you the option not to install it choose that until you investigate it completely.
The more you install that you don't want or need the more you'll wish you didn't.


________________________________________
Windows Updates
Be certain automatic updates is turned on for XP. - For Vista Or if you like to do it manually be sure to visit http://update.microsoft.com/ regularly. This requires internet explorer to do so.

This will ensure your computer has always the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
___________________________________

SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Browser settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.


Here's a site with great advise on how to AVOID malware. Much easier to do than removing it.




Safe and Happy Surfing. :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI