This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very annoying virus.

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I just got a virus and it's very persistent.
I'm not sure when, but my pop up blocker was turned off allowing pop ups to appear.
My first attempt to scan was stopped. My computer decided to freeze which I believe was caused by a virus.
I restarted the computer and tried scanning with Malwarebytes but it didn't work. I double clicked the icon but nothing comes up. Went to the source and tried only to end up with the same results.
I improvised by scanning with AVG 8, my antivirus program.
It picked up 15 threats. Then I restarted the computer and thought the Malwarebytes scan would work. Still doesn't work.
I also noticed that every time i restart that computer, my pop up blocker turns off. There seems to be an unusual amount of trusted sites, the only one I remember adding is download.com.
Throughout this whole process of scanning and restarting, I'm getting multiple pop ups and constant freezes.
So I decide to come here and ask for help. What's worse is that i can't get onto to forums through the home computer. I'm therefore using my laptop.
In dire need of help. Any advice on how to rid myself of this virus/problem?
I forgot to mention that my firewall and automatic update gets turned off from time to time. save me please, thanks in advance >.<

I have a Safenet Computer running Windows XP home edition service package 3
Here's the HiJackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:06 PM, on 12/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Documents and Settings\winxp\Application Data\Twain\Twain.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twex.exe,
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [60a8f0ce] rundll32.exe "C:\WINDOWS\system32\ltrmoeeh.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Twain] C:\Documents and Settings\winxp\Application Data\Twain\Twain.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.download.com
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusremover2008.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {0B96BF84-DA5C-46F4-A7FC-5319CFF74163} (MnetLauncher Control) - http://player.mnet.com/package/cjmuset.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} (DaumBGMCtrl Class) - http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-2062e4c29cecd973.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} - http://www.maxmp3.co.kr/Ver2/App/totalApp/…r/maxhelper.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWire…loadControl.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://cafeimg.hanmail.net/cto/1_2_3_5/xman.cab?ver=1,2,3,5
O16 - DPF: {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} (BugsInstallEx Control) - http://install.bugs.co.kr/install/BugsInstallerEx.cab
O16 - DPF: {BFB6D72C-1030-47E4-88A2-614ACCC92467} (MaxMp3VSet Class) - http://www.maxmp3.co.kr/MaxMP3/Html/MPlaye…ge/p3mxvset.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} (MultiUpload Control) - http://www.clubbox.co.kr/neo.fld/MultiUpload.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: cdhwph.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

–
End of file - 9234 bytes
Hello Akusan4 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


1. Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here.

2. Download random's system information tool (RSIT) and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Hi Trevuren, first off, thanks for helping me out, really appreciate it. :)
So I downloaded the stuff and ran them but there was a problem with RSIT.exe which prevented me from getting the two files. A window popped up saying the following:
Line -1:

Error: Subscript used with non-Array variable


Rooter worked fine, here's the Log:
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® 4 CPU 3.00GHz )
BIOS : Default System BIOS
USER : winxp ( Administrator )
BOOT : Normal boot

Antivirus : AVG Anti-Virus Free 8.0 (Activated)


A:\ (USB)
C:\ (Local Disk) - NTFS - Total:149 Go (Free:106 Go)
D:\ (CD or DVD)
E:\ (USB)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB) - FAT - Total:491 Mo (Free:0 Go)

Wed 12/24/2008|14:27

———————-\\ Search..

C:\WINDOWS\system32\VuDMlnmp.ini
C:\WINDOWS\system32\VuDMlnmp.ini2
C:\WINDOWS\system32\pmnlMDuV.dll
==> VUNDO <==
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix isn't working T~T. I double clicked it and nothing happened. By the way, I sleep at 1-9 am EST. What time do you usually check the forums? Just curious, is it possible for a virus to disable the use of scans or programs like combofix?

Just curious, is it possible for a virus to disable the use of scans or programs like combofix?

Most definitely.

Try one of these methods. If neither succeeds, we have other methods to try.


1. Click the Windows 'Start' button > Select 'Run' - then copy/paste this into the run box & click OK: (assuming ComboFix.exe is on the desktop as was instructed)

"%userprofile%\desktop\combofix.exe"



2. Open Task Manager by pressing the Ctrl Alt and Del keys, at the same time.

In the menu at the top of the dialog box, click File>New Task (Run…)

Copy/paste (or type) the following in the Run box and click OK: (assuming ComboFix.exe is on the desktop as was instructed)

"%userprofile%\desktop\combofix.exe"
1. Delete any versions of ComboFix that may be on your desktop

2. Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
I know you didn't confirm my last message but I tried it out and it worked.

Here's the combofix log file:
ComboFix 08-12-26.02 - winxp 2008-12-26 17:56:30.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.212 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboMix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\winxp\LOCALS~1\Temp\tmp1.tmp
c:\documents and settings\winxp\Application Data\Facegame
c:\documents and settings\winxp\Application Data\gadcom
c:\documents and settings\winxp\Application Data\SpeedRunner
c:\documents and settings\winxp\Application Data\twain\Twain.exe
c:\documents and settings\winxp\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\winxp\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\winxp\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
c:\program files\Mjcore
c:\windows\kernel32.exe
c:\windows\system32\abihis.dll
c:\windows\system32\cbXQjGxY.dll
c:\windows\system32\cdhwph.dll
c:\windows\system32\clvpwrgr.dll
c:\windows\system32\drivers\TDSSmplt.sys
c:\windows\system32\efcDttUk.dll
c:\windows\system32\heeomrtl.ini
c:\windows\system32\hljwcade.dll
c:\windows\system32\jkse73hedfdgf.dll
c:\windows\system32\ltrmoeeh.dll
c:\windows\system32\pmnlMDuV.dll
c:\windows\system32\TDSScfum.log
c:\windows\system32\TDSSfxmp.dll
c:\windows\system32\TDSSmhxt.dat
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSoity.dll
c:\windows\system32\TDSSosvd.dll
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsbhc.log
c:\windows\system32\tyshb36rfjdf.dll
c:\windows\system32\VuDMlnmp.ini
c:\windows\system32\VuDMlnmp.ini2
c:\windows\system32\wpv963.cpx
c:\windows\system32\ymmfkfia.ini
c:\windows\Temp\tmp3.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS


((((((((((((((((((((((((( Files Created from 2008-11-26 to 2008-12-26 )))))))))))))))))))))))))))))))
.

2008-12-26 17:49 . 2008-12-26 17:49 d——– C:\32788R22FWJFW
2008-12-24 21:45 . 2008-12-24 21:45 306,432 –a—— c:\windows\system32\TuneUpDefragService.exe
2008-12-24 21:45 . 2007-12-20 10:41 29,440 –a—— c:\windows\system32\uxtuneup.dll
2008-12-24 21:44 . 2008-12-24 21:44 d——– c:\documents and settings\All Users\Application Data\TuneUp Software
2008-12-24 21:33 . 2008-12-24 21:33 d——– c:\documents and settings\winxp\Application Data\TuneUp Software
2008-12-24 21:32 . 2008-12-24 21:44 d——– c:\program files\TuneUp Utilities 2008
2008-12-24 14:27 . 2008-12-24 14:32 d——– C:\Rooter$
2008-12-23 21:34 . 2008-12-23 21:34 d–hs—- c:\documents and settings\LocalService\Application Data\twain32
2008-12-23 21:33 . 2008-12-23 21:33 d–hs—- c:\documents and settings\NetworkService\Application Data\twain32
2008-12-23 21:29 . 2008-12-26 16:46 d–hs—- c:\windows\system32\twain32
2008-12-23 20:35 . 2008-12-23 20:35 d——– c:\documents and settings\Administrator
2008-12-23 17:03 . 2008-12-23 17:03 8,192 –a—— C:\ekejy.exe
2008-12-23 17:03 . 2008-12-23 17:03 0 –a—— C:\1621684321
2008-12-23 17:02 . 2008-12-23 17:02 21,504 –a—— C:\diopero.exe
2008-12-23 16:58 . 2008-12-26 17:58 d——– c:\documents and settings\winxp\Application Data\Twain
2008-12-23 16:53 . 2008-12-23 19:59 d——– c:\program files\Webtools
2008-12-23 16:48 . 2008-12-23 16:48 45,056 –a—— c:\windows\system32\khfcdcBs.dll
2008-12-19 21:33 . 2008-12-19 21:33 d——– c:\program files\XV6900 User Manual
2008-12-19 21:29 . 2008-12-19 21:29 d——– c:\program files\HTC
2008-12-01 19:46 . 2008-12-01 19:46 d——– c:\documents and settings\winxp\Application Data\MSNInstaller
2008-11-30 17:05 . 2008-11-30 17:05 d——– C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-25 02:43 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-24 01:30 ——— d—–w c:\program files\Steam
2008-12-23 03:09 ——— d—–w c:\documents and settings\winxp\Application Data\Apple Computer
2008-12-20 02:33 ——— d—–w c:\program files\Microsoft ActiveSync
2008-12-20 02:29 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-12 22:21 ——— d—–w c:\documents and settings\winxp\Application Data\Move Networks
2008-12-12 22:16 ——— d—–w c:\documents and settings\winxp\Application Data\MSN6
2008-11-20 23:53 ——— d—–w c:\program files\AIM6
2008-11-20 03:01 ——— d—–w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-12 00:55 ——— d—–w c:\program files\MSN Messenger
2008-10-01 03:27 60,416 —-a-w c:\windows\ALCFDRTM.EXE
2008-09-30 20:40 319,488 —-a-w c:\windows\HideWin.exe
2007-10-13 03:24 439,296 —-a-w c:\documents and settings\winxp\GoToAssist_phone__317_en.exe
2005-04-01 03:17 40,960 —-a-w c:\program files\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((( snapshot@2008-10-25_23.02.13.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-10 01:10:56 1,379,840 —-a-w c:\windows\$hf_mig$\KB954459\SP3QFE\msxml6.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\$hf_mig$\KB954459\spmsg.dll
+ 2007-11-30 12:39:22 231,288 —-a-w c:\windows\$hf_mig$\KB954459\spuninst.exe
+ 2007-11-30 12:39:22 26,488 —-a-w c:\windows\$hf_mig$\KB954459\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 —-a-w c:\windows\$hf_mig$\KB954459\update\update.exe
+ 2007-11-30 12:39:22 382,840 —-a-w c:\windows\$hf_mig$\KB954459\update\updspapi.dll
+ 2008-09-04 17:12:27 1,106,944 —-a-w c:\windows\$hf_mig$\KB955069\SP3QFE\msxml3.dll
+ 2007-11-30 11:18:51 17,272 —-a-w c:\windows\$hf_mig$\KB955069\spmsg.dll
+ 2007-11-30 11:18:51 231,288 —-a-w c:\windows\$hf_mig$\KB955069\spuninst.exe
+ 2007-11-30 11:18:51 26,488 —-a-w c:\windows\$hf_mig$\KB955069\update\spcustom.dll
+ 2007-11-30 11:18:51 755,576 —-a-w c:\windows\$hf_mig$\KB955069\update\update.exe
+ 2008-07-09 18:08:38 382,840 —-a-w c:\windows\$hf_mig$\KB955069\update\updspapi.dll
+ 2008-10-24 11:41:11 455,936 —-a-w c:\windows\$hf_mig$\KB957097\SP3QFE\mrxsmb.sys
+ 2008-07-08 13:02:01 17,272 —-a-w c:\windows\$hf_mig$\KB957097\spmsg.dll
+ 2008-07-08 13:02:02 231,288 —-a-w c:\windows\$hf_mig$\KB957097\spuninst.exe
+ 2008-07-08 13:02:01 26,488 —-a-w c:\windows\$hf_mig$\KB957097\update\spcustom.dll
+ 2008-07-08 13:02:04 755,576 —-a-w c:\windows\$hf_mig$\KB957097\update\update.exe
+ 2008-07-08 13:02:12 382,840 —-a-w c:\windows\$hf_mig$\KB957097\update\updspapi.dll
+ 2008-04-14 00:12:01 1,306,624 -c—-w c:\windows\$NtUninstallKB954459$\msxml6.dll
+ 2007-11-30 12:39:22 231,288 -c—-w c:\windows\$NtUninstallKB954459$\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c—-w c:\windows\$NtUninstallKB954459$\spuninst\updspapi.dll
+ 2008-04-14 00:12:01 1,104,896 -c—-w c:\windows\$NtUninstallKB955069$\msxml3.dll
+ 2007-11-30 11:18:51 231,288 -c—-w c:\windows\$NtUninstallKB955069$\spuninst\spuninst.exe
+ 2008-07-09 18:08:38 382,840 -c—-w c:\windows\$NtUninstallKB955069$\spuninst\updspapi.dll
+ 2008-04-13 19:17:01 456,576 -c—-w c:\windows\$NtUninstallKB957097$\mrxsmb.sys
+ 2008-07-08 13:02:02 231,288 -c—-w c:\windows\$NtUninstallKB957097$\spuninst\spuninst.exe
+ 2008-07-08 13:02:12 382,840 -c—-w c:\windows\$NtUninstallKB957097$\spuninst\updspapi.dll
+ 2006-10-20 16:15:50 405,504 —-a-w c:\windows\Downloaded Program Files\VerizonWirelessUploadControl.dll
+ 2008-10-24 11:21:09 455,296 ——w c:\windows\Driver Cache\i386\mrxsmb.sys
- 2005-10-21 00:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2005-10-21 00:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2007-09-14 03:13:48 29,926 —-a-r c:\windows\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\MsblIco.Exe
+ 2008-11-12 00:56:01 29,926 —-a-r c:\windows\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\MsblIco.Exe
+ 2008-11-12 04:42:44 32,768 —-a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
- 2008-10-15 03:13:43 38,240 —-a-r c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2008-12-13 04:29:41 38,240 —-a-r c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2008-10-15 03:17:54 12,288 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-12-13 04:29:01 12,288 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-10-15 03:17:54 135,168 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-12-13 04:29:01 135,168 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-10-15 03:17:54 11,264 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-12-13 04:29:01 11,264 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-10-15 03:17:54 27,136 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-12-13 04:29:01 27,136 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-10-15 03:17:55 4,096 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-12-13 04:29:02 4,096 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-10-15 03:17:55 794,624 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-12-13 04:29:02 794,624 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-10-15 03:17:54 249,856 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-12-13 04:29:01 249,856 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-10-15 03:17:55 23,040 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-12-13 04:29:02 23,040 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-10-15 03:17:54 286,720 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-12-13 04:29:01 286,720 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-10-15 03:17:54 409,600 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-12-13 04:29:01 409,600 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-12-20 02:33:57 22,486 —-a-r c:\windows\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\ARPPRODUCTICON.exe
+ 2008-12-20 02:33:57 22,486 —-a-r c:\windows\Installer\{99052DB7-9592-4522-A558-5417BBAD48EE}\WCESMgrIcon.exe
- 2000-08-31 12:00:00 28,672 —-a-w c:\windows\NIRCMD.exe
+ 2000-08-31 13:00:00 28,672 —-a-w c:\windows\NIRCMD.exe
- 2000-08-31 12:00:00 161,792 —-a-w c:\windows\SWREG.exe
+ 2000-08-31 13:00:00 161,792 —-a-w c:\windows\SWREG.exe
+ 2008-08-06 21:22:02 114,688 —-a-w c:\windows\system32\Adobe\Director\np32dsw.dll
+ 2008-08-06 21:30:48 202,168 —-a-w c:\windows\system32\Adobe\Director\SwDir.dll
+ 2008-08-06 21:22:42 499,712 —-a-w c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2008-08-06 20:45:40 1,798,144 —-a-w c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2008-08-06 21:22:44 9,216 —-a-w c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2008-08-06 20:35:52 706,048 —-a-w c:\windows\system32\Adobe\Shockwave 11\gi.dll
+ 2008-08-06 20:35:52 1,145,896 —-a-w c:\windows\system32\Adobe\Shockwave 11\gt.exe
+ 2008-08-06 20:35:52 52,288 —-a-w c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
+ 2008-08-06 20:42:04 892,928 —-a-w c:\windows\system32\Adobe\Shockwave 11\iml32.dll
+ 2008-08-06 20:35:52 54,656 —-a-w c:\windows\system32\Adobe\Shockwave 11\pccuapi.dll
+ 2008-08-06 21:21:14 266,240 —-a-w c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
+ 2008-08-06 21:24:14 446,464 —-a-w c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2008-08-06 21:30:30 447,928 —-a-w c:\windows\system32\Adobe\Shockwave 11\SwHelper_1100465.exe
+ 2008-08-06 21:24:56 114,688 —-a-w c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2008-08-06 21:21:04 94,208 —-a-w c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2008-08-06 20:35:52 50,808 —-a-w c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 1999-06-25 15:55:30 149,504 —-a-w c:\windows\system32\Adobe\Shockwave 11\UNWISE.EXE
- 2008-07-19 02:10:48 94,920 —-a-w c:\windows\system32\cdm.dll
+ 2008-10-16 19:09:44 92,696 —-a-w c:\windows\system32\cdm.dll
+ 2006-11-13 18:38:40 22,824 —-a-w c:\windows\system32\ceutil.dll
- 2008-10-22 01:26:12 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-26 23:04:31 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-10-22 01:26:12 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-26 23:04:31 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-10-22 01:26:12 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-26 23:04:31 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-07-19 02:10:48 94,920 -c–a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-16 19:09:44 92,696 -c–a-w c:\windows\system32\dllcache\cdm.dll
+ 2008-10-23 12:36:14 286,720 -c—-w c:\windows\system32\dllcache\gdi32.dll
- 2006-10-19 00:03:58 100,864 -c–a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-18 06:09:22 100,864 -c–a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-10-24 11:21:09 455,296 -c—-w c:\windows\system32\dllcache\mrxsmb.sys
- 2008-08-20 05:30:53 3,067,904 -c—-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-12 17:01:00 3,067,904 -c—-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-09-04 17:15:04 1,106,944 -c—-w c:\windows\system32\dllcache\msxml3.dll
- 2008-04-14 00:12:01 1,306,624 -c—-w c:\windows\system32\dllcache\msxml6.dll
+ 2008-09-10 01:14:56 1,307,648 -c—-w c:\windows\system32\dllcache\msxml6.dll
- 2008-08-20 05:30:51 1,499,136 -c—-w c:\windows\system32\dllcache\shdocvw.dll
+ 2008-10-16 01:00:10 1,499,136 -c—-w c:\windows\system32\dllcache\shdocvw.dll
- 2008-04-14 00:12:07 246,814 -c–a-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:02:42 247,326 -c–a-w c:\windows\system32\dllcache\strmdll.dll
- 2008-08-20 05:30:52 619,520 -c—-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 01:00:11 619,520 -c—-w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-20 05:30:51 666,112 -c—-w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 01:00:11 666,112 -c—-w c:\windows\system32\dllcache\wininet.dll
- 2006-10-19 01:47:20 937,984 -c–a-w c:\windows\system32\dllcache\WMNetMgr.dll
+ 2008-06-18 10:03:08 938,496 -c–a-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-10-19 01:47:22 2,450,944 -c–a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 -c–a-w c:\windows\system32\dllcache\WMVCore.dll
- 2008-07-19 02:09:44 563,912 -c–a-w c:\windows\system32\dllcache\wuapi.dll
+ 2008-10-16 19:12:20 561,688 -c–a-w c:\windows\system32\dllcache\wuapi.dll
- 2008-07-19 02:10:42 53,448 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 -c–a-w c:\windows\system32\dllcache\wuauclt.exe
- 2008-07-19 02:09:42 1,811,656 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 -c–a-w c:\windows\system32\dllcache\wuaueng.dll
- 2008-07-19 02:09:46 325,832 -c–a-w c:\windows\system32\dllcache\wucltui.dll
+ 2008-10-16 19:12:22 323,608 -c–a-w c:\windows\system32\dllcache\wucltui.dll
- 2008-07-19 02:10:20 36,552 -c–a-w c:\windows\system32\dllcache\wups.dll
+ 2008-10-16 19:08:58 34,328 -c–a-w c:\windows\system32\dllcache\wups.dll
- 2008-07-19 02:09:44 205,000 -c–a-w c:\windows\system32\dllcache\wuweb.dll
+ 2008-10-16 19:13:40 202,776 -c–a-w c:\windows\system32\dllcache\wuweb.dll
- 2008-04-13 19:17:01 456,576 —-a-w c:\windows\system32\drivers\mrxsmb.sys
+ 2008-10-24 11:21:09 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
+ 2006-12-27 23:43:28 94,080 -c–a-w c:\windows\system32\DRVSTORE\qcusbmdm_47ED784D2C54626E7C0AB462934223B2E1FC2E1C\qcmdm2k.sys
+ 2006-12-27 23:38:42 92,800 -c–a-w c:\windows\system32\DRVSTORE\qcusbmdm_47ED784D2C54626E7C0AB462934223B2E1FC2E1C\qcmdmxp.sys
+ 2006-12-27 23:43:28 94,080 -c–a-w c:\windows\system32\DRVSTORE\qcusbser_56F1027C71EF4E8BB90BBEBC67FFC3DAE7A12606\qcmdm2k.sys
+ 2006-12-27 23:38:42 92,800 -c–a-w c:\windows\system32\DRVSTORE\qcusbser_56F1027C71EF4E8BB90BBEBC67FFC3DAE7A12606\qcmdmxp.sys
- 2008-04-14 00:11:54 285,184 —-a-w c:\windows\system32\gdi32.dll
+ 2008-10-23 12:36:14 286,720 —-a-w c:\windows\system32\gdi32.dll
- 2006-10-19 00:03:58 100,864 —-a-w c:\windows\system32\logagent.exe
+ 2008-06-18 06:09:22 100,864 —-a-w c:\windows\system32\logagent.exe
+ 2008-10-05 03:16:26 235,936 —-a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
- 2008-06-12 14:29:36 74,137 —-a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-10-28 20:46:53 88,590 —-a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2007-08-07 17:35:56 585,728 —-a-w c:\windows\system32\Macromed\Shockwave 10\Control.dll
+ 2008-03-15 04:29:22 581,632 —-a-w c:\windows\system32\Macromed\Shockwave 10\Control.dll
+ 2008-03-15 04:12:30 1,490,944 —-a-w c:\windows\system32\Macromed\Shockwave 10\dirapiX.dll
- 2007-08-07 17:36:32 24,576 —-a-w c:\windows\system32\Macromed\Shockwave 10\DynaPlayer.dll
+ 2008-03-15 04:29:58 24,576 —-a-w c:\windows\system32\Macromed\Shockwave 10\DynaPlayer.dll
+ 2008-03-15 04:10:06 606,208 —-a-w c:\windows\system32\Macromed\Shockwave 10\iml32X.dll
- 2007-08-07 17:35:22 339,968 —-a-w c:\windows\system32\Macromed\Shockwave 10\Plugin.dll
+ 2008-03-15 04:28:48 339,968 —-a-w c:\windows\system32\Macromed\Shockwave 10\Plugin.dll
- 2007-08-07 17:35:32 483,328 —-a-w c:\windows\system32\Macromed\Shockwave 10\PluginPing.dll
+ 2008-03-15 04:28:56 475,136 —-a-w c:\windows\system32\Macromed\Shockwave 10\PluginPing.dll
- 2007-08-07 17:28:38 180,224 —-a-w c:\windows\system32\Macromed\Shockwave 10\Proj.dll
+ 2008-03-15 04:21:52 180,224 —-a-w c:\windows\system32\Macromed\Shockwave 10\Proj.dll
- 2007-08-07 17:37:56 77,824 —-a-w c:\windows\system32\Macromed\Shockwave 10\SwInit.exe
+ 2008-03-15 04:31:28 77,824 —-a-w c:\windows\system32\Macromed\Shockwave 10\SwInit.exe
+ 2008-03-15 16:38:08 86,016 —-a-w c:\windows\system32\Macromed\Shockwave 10\SwMenuX.dll
- 2007-08-07 17:37:58 98,304 —-a-w c:\windows\system32\Macromed\Shockwave 10\SwOnce.dll
+ 2008-03-15 04:31:28 98,304 —-a-w c:\windows\system32\Macromed\Shockwave 10\SwOnce.dll
- 2008-10-07 19:19:40 16,721,856 —-a-w c:\windows\system32\MRT.exe
+ 2008-12-09 23:24:37 17,593,280 —-a-w c:\windows\system32\MRT.exe
- 2008-08-20 05:30:53 3,067,904 —-a-w c:\windows\system32\mshtml.dll
+ 2008-12-12 17:01:00 3,067,904 —-a-w c:\windows\system32\mshtml.dll
- 2008-04-14 00:12:01 1,104,896 —-a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 17:15:04 1,106,944 —-a-w c:\windows\system32\msxml3.dll
- 2007-05-08 19:03:04 1,275,392 —-a-w c:\windows\system32\msxml4.dll
+ 2008-09-30 21:43:34 1,286,152 —-a-w c:\windows\system32\msxml4.dll
- 2008-04-14 00:12:01 1,306,624 —-a-w c:\windows\system32\msxml6.dll
+ 2008-09-10 01:14:56 1,307,648 —-a-w c:\windows\system32\msxml6.dll
- 2008-07-19 02:07:34 270,880 —-a-w c:\windows\system32\mucltui.dll
+ 2008-10-16 19:06:48 268,648 —-a-w c:\windows\system32\mucltui.dll
- 2008-07-19 02:07:32 210,976 —-a-w c:\windows\system32\muweb.dll
+ 2008-10-16 19:06:48 208,744 —-a-w c:\windows\system32\muweb.dll
- 2008-10-15 03:05:39 64,372 —-a-w c:\windows\system32\perfc009.dat
+ 2008-12-20 02:36:42 64,372 —-a-w c:\windows\system32\perfc009.dat
- 2008-10-15 03:05:39 409,232 —-a-w c:\windows\system32\perfh009.dat
+ 2008-12-20 02:36:42 409,232 —-a-w c:\windows\system32\perfh009.dat
+ 2006-11-13 18:39:28 138,024 —-a-w c:\windows\system32\rapi.dll
- 2008-08-20 05:30:51 1,499,136 —-a-w c:\windows\system32\shdocvw.dll
+ 2008-10-16 01:00:10 1,499,136 —-a-w c:\windows\system32\shdocvw.dll
+ 2008-10-16 19:08:58 34,328 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 19:09:44 43,544 —-a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
- 2007-11-30 11:18:51 17,272 ——w c:\windows\system32\spmsg.dll
+ 2007-11-30 12:39:22 17,272 —-a-w c:\windows\system32\spmsg.dll
- 2008-04-14 00:12:07 246,814 —-a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:02:42 247,326 —-a-w c:\windows\system32\strmdll.dll
+ 2008-04-14 00:11:24 236,032 —-a-r c:\windows\system32\twex.exe
- 2008-04-14 00:12:38 60,416 —-a-w c:\windows\system32\tzchange.exe
+ 2008-10-23 10:06:59 62,976 —-a-w c:\windows\system32\tzchange.exe
- 2008-08-20 05:30:52 619,520 —-a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 01:00:11 619,520 —-a-w c:\windows\system32\urlmon.dll
- 2008-08-20 05:30:51 666,112 —-a-w c:\windows\system32\wininet.dll
+ 2008-10-16 01:00:11 666,112 —-a-w c:\windows\system32\wininet.dll
- 2006-10-19 01:47:20 937,984 —-a-w c:\windows\system32\wmnetmgr.dll
+ 2008-06-18 10:03:08 938,496 —-a-w c:\windows\system32\WMNetmgr.dll
- 2006-10-19 01:47:22 2,450,944 —-a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 —-a-w c:\windows\system32\WMVCore.dll
- 2008-07-19 02:09:44 563,912 —-a-w c:\windows\system32\wuapi.dll
+ 2008-10-16 19:12:20 561,688 —-a-w c:\windows\system32\wuapi.dll
- 2008-07-19 02:10:42 53,448 —-a-w c:\windows\system32\wuauclt.exe
+ 2008-10-16 19:09:44 51,224 —-a-w c:\windows\system32\wuauclt.exe
- 2008-07-19 02:09:42 1,811,656 —-a-w c:\windows\system32\wuaueng.dll
+ 2008-10-16 19:13:40 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
- 2008-07-19 02:09:46 325,832 —-a-w c:\windows\system32\wucltui.dll
+ 2008-10-16 19:12:22 323,608 —-a-w c:\windows\system32\wucltui.dll
- 2008-07-19 02:10:20 36,552 —-a-w c:\windows\system32\wups.dll
+ 2008-10-16 19:08:58 34,328 —-a-w c:\windows\system32\wups.dll
- 2008-07-19 02:10:40 45,768 —-a-w c:\windows\system32\wups2.dll
+ 2008-10-16 19:09:44 43,544 —-a-w c:\windows\system32\wups2.dll
- 2008-07-19 02:09:44 205,000 —-a-w c:\windows\system32\wuweb.dll
+ 2008-10-16 19:13:40 202,776 —-a-w c:\windows\system32\wuweb.dll
+ 2008-09-30 21:42:08 1,286,152 —-a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-30 21:45:12 91,656 —-a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2006-09-13 05:43:06 96,256 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_c9ba3671\ATL80.dll
+ 2006-09-13 05:41:36 479,232 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_691a48fd\msvcm80.dll
+ 2006-09-13 05:41:36 548,864 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_691a48fd\msvcp80.dll
+ 2006-09-13 05:41:36 626,688 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_691a48fd\msvcr80.dll
+ 2006-09-13 07:12:34 1,101,824 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_3a00bc02\mfc80.dll
+ 2006-09-13 07:12:40 1,092,608 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_3a00bc02\mfc80u.dll
+ 2006-09-13 07:12:44 69,632 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_3a00bc02\mfcm80.dll
+ 2006-09-13 07:12:46 57,856 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_3a00bc02\mfcm80u.dll
+ 2006-09-13 06:54:30 40,960 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_8f4fd500\mfc80CHS.dll
+ 2006-09-13 06:54:30 45,056 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_8f4fd500\mfc80CHT.dll
+ 2006-09-13 06:54:28 65,536 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_8f4fd500\mfc80DEU.dll
+ 2006-09-13 06:54:30 57,344 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_8f4fd500\mfc80ENU.dll
+ 2006-09-13 06:54:30 61,440 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_8f4fd500\mfc80ESP.dll
+ 2006-09-13 06:54:28 61,440 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_8f4fd500\mfc80FRA.dll
+ 2006-09-13 06:54:30 61,440 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_8f4fd500\mfc80ITA.dll
+ 2006-09-13 06:54:30 49,152 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_8f4fd500\mfc80JPN.dll
+ 2006-09-13 06:54:30 49,152 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_8f4fd500\mfc80KOR.dll
+ 2006-09-13 07:33:02 65,536 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.363_x-ww_6a201697\vcomp.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\\WINDOWS\\system32\\userinit.exe,c:\\WINDOWS\\system32\\twex.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=cdhwph.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= DivXa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
–a—— 2008-07-22 19:42 116040 c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClubBox]
-ra—— 2008-02-28 05:58 1536000 c:\windows\system32\clubbox.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo R300 Series]
–a—— 2003-06-04 02:00 99840 c:\windows\system32\spool\drivers\w32x86\3\E_S4I2F1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
–a—— 2006-05-09 19:24 50760 c:\program files\Common Files\AOL\1140128537\ee\aolsoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
–a—— 2006-02-17 11:59 124520 c:\program files\Common Files\AOL\IPHSend\IPHSend.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPlusAgent2]
–a—— 2005-06-07 07:27 237568 c:\program files\iriver\iriver plus 2\iAgent2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-07-30 09:47 289064 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2008-04-14 16:36 227914 c:\program files\Plaxo\2.13.1.6\PlaxoHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar]
——— 2004-04-21 10:26 86016 c:\program files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SFP]
——— 2003-09-05 15:30 561152 c:\program files\Common Files\Verizon Online\SFP\vzSFPWin.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2008-11-05 17:10 1410296 c:\program files\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2006-11-09 15:07 49263 c:\program files\Java\jre1.5.0_10\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
"AVG8_TRAY"=c:\progra~1\AVG\AVG8\avgtray.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140128537\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140128537\\ee\\aim6.exe"=
"c:\\WINDOWS\\system32\\clubbox.exe"=
"c:\\WINDOWS\\system32\\fscagent.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1140128537\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\ijji\\ENGLISH\\u_gbound.exe"=
"c:\\ijji\\ENGLISH\\Gunbound Revolution\\GunBound.gme"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\steamapps\\never_fart\\counter-strike\\hl.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13613:TCP"= 13613:TCP:BitComet 13613 TCP
"13613:UDP"= 13613:UDP:BitComet 13613 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"15409:TCP"= 15409:TCP:BND
"4751:TCP"= 4751:TCP:BND
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-09-30 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-09-30 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-09-30 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-09-30 76040]
S3 ASPI;Advanced SCSI Programming Interface Driver;\??\c:\windows\System32\DRIVERS\ASPI32.sys [2006-12-15 16512]
S3 cusbohcn;cusbohcn;\??\c:\docume~1\winxp\LOCALS~1\Temp\cusbohcn.sys []
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys []

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f58603d9-d11f-11dd-b4ee-00600f449ac9}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Legacy VGA Drivers V1.0]
c:\windows\certproc32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Sony DVDRam Version 1.8B]
c:\windows\uiengine32.exe
.
Contents of the 'Scheduled Tasks' folder

2008-12-25 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 15:17]

2008-08-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-12-26 c:\windows\Tasks\oocjxuct.job
- c:\windows\system32\rundll32.exe [2008-04-13 19:12]
.
- - - - ORPHANS REMOVED - - - -

BHO-{0415d560-ce7d-476b-849c-645e78a2ce4c} - c:\windows\system32\cdhwph.dll
BHO-{2CEE3BDE-A384-4E3D-95C6-93286C681CAB} - c:\windows\system32\pmnlMDuV.dll
BHO-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\efcDttUk.dll
HKCU-Run-Aim6 - (no file)
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - c:\windows\system32\efcDttUk.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: *.download.com
Trusted Zone: *.amaena.com
Trusted Zone: *.avsystemcare.com
Trusted Zone: *.onerateld.com
Trusted Zone: *.safetydownload.com
Trusted Zone: *.trustedantivirus.com
Trusted Zone: *.virusremover2008.com
Trusted Zone: *.virusschlacht.com

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\system32\atl.dll - c:\windows\system32\MnetLauncher.ocx
c:\windows\system32\cjmuset.dll
O16 -: {0B96BF84-DA5C-46F4-A7FC-5319CFF74163}
hxxp://player.mnet.com/package/cjmuset.cab
c:\windows\Downloaded Program Files\cjmuset.inf

c:\windows\Downloaded Program Files\tpwin.ocx - O16 -: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5}
hxxp://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB

c:\windows\system32\OIBox.dll - c:\windows\system32\DaumCrypt.dll
c:\windows\system32\DaumBGM.dll
O16 -: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3}
hxxp://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
c:\windows\Downloaded Program Files\DaumBGM.inf

c:\windows\Downloaded Program Files\MaxHelper.ocx - O16 -: {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2}
hxxp://www.maxmp3.co.kr/Ver2/App/totalApp/maxhelper/maxhelper.cab
c:\windows\Downloaded Program Files\MaxHelper.inf

c:\windows\system32\dmvm.dll - c:\windows\Downloaded Program Files\dmcc2.dll
O16 -: {938527D1-CDB7-4147-998A-B20FCA5CC976}
hxxp://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
c:\windows\Downloaded Program Files\dmcc2.inf

c:\windows\system32\xmaninf.exe - c:\windows\system32\extract.exe
c:\windows\system32\xman.dll
O16 -: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C}
hxxp://cafeimg.hanmail.net/cto/1_2_3_5/xman.cab?ver=1,2,3,5
c:\windows\Downloaded Program Files\xman.inf

c:\windows\system32\mfc42.dll - c:\windows\system32\olepro32.dll
c:\windows\Downloaded Program Files\BugsInstallerEx.ocx
c:\windows\system32\bugs_install.gif
O16 -: {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69}
hxxp://install.bugs.co.kr/install/BugsInstallerEx.cab
c:\windows\Downloaded Program Files\BugsInstallerEx.inf

c:\windows\system32\atl.dll - c:\windows\system32\p3mxvset.dll
O16 -: {BFB6D72C-1030-47E4-88A2-614ACCC92467}
hxxp://www.maxmp3.co.kr/MaxMP3/Html/MPlayer/Movie/__P2P__/Package/p3mxvset.cab
c:\windows\Downloaded Program Files\p3mxvset.inf

c:\windows\system32\atl.dll - c:\windows\Downloaded Program Files\MultiUpload.ocx
O16 -: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4}
hxxp://www.clubbox.co.kr/neo.fld/MultiUpload.cab
c:\windows\Downloaded Program Files\MultiUpload.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-26 18:04:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(508)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Ahead\InCD\InCDsrv.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\PnkBstrA.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-26 18:11:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-26 23:11:40
ComboFix2.txt 2008-10-26 03:02:40
ComboFix3.txt 2008-10-01 01:12:38

Pre-Run: 114,378,887,168 bytes free
Post-Run: 114,410,840,064 bytes free

551 — E O F — 2008-12-18 05:46:59

Service_TDSSSERV.SYS

<==Rootkit

Identity Theft

Your system has been infected by one or more Rootkits/Backdoor Trojans.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we cannot guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities. I must remind you that i cannot guarantee that your computer will be completely clean afterwards since we have no way of knowing what has been done to it.

To help you make your decision, here are a few related articles that i suggest you read:

  • Danger: Remote Access Trojans.
  • When should I re-format? How should I reinstall?
  • How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.
Hi, thank you again for helping me out, I never would have known how serious this problem was.
Thankfully I'm not over 18 and do not keep very important things on this computer.
I have begun to start all my regular scans and will continue to use the computer without reformatting.
Here is my Malwarebyte log and HiJackThis log:


Malwarebyte:

Malwarebytes' Anti-Malware 1.28
Database version: 1222
Windows 5.1.2600 Service Pack 3

12/26/2008 7:26:37 PM
mbam-log-2008-12-26 (19-26-37).txt

Scan type: Full Scan (C:\|)
Objects scanned: 119869
Time elapsed: 48 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Webtools (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\khfcdcBs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.















HiJackThis:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:46:36 PM, on 12/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\twex.exe,
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.download.com
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusremover2008.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {0B96BF84-DA5C-46F4-A7FC-5319CFF74163} (MnetLauncher Control) - http://player.mnet.com/package/cjmuset.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} (Tpwin Control) - http://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {6A2E758A-028B-46BB-A11D-0608AB5A4ED3} (DaumBGMCtrl Class) - http://listen.daum.net/52st/bgmplayer/Daum52stBGMPlayer.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-2062e4c29cecd973.spaces.live.co…ad/MsnPUpld.cab
O16 - DPF: {882A7CC6-0163-4BC1-8BC1-505E36C9FFA2} - http://www.maxmp3.co.kr/Ver2/App/totalApp/…r/maxhelper.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWire…loadControl.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9_1/dmcc2.cab?Version=1,0,0,10
O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://cafeimg.hanmail.net/cto/1_2_3_5/xman.cab?ver=1,2,3,5
O16 - DPF: {BCEF5CDE-BAD4-4532-A30B-9D16D502DE69} (BugsInstallEx Control) - http://install.bugs.co.kr/install/BugsInstallerEx.cab
O16 - DPF: {BFB6D72C-1030-47E4-88A2-614ACCC92467} (MaxMp3VSet Class) - http://www.maxmp3.co.kr/MaxMP3/Html/MPlaye…ge/p3mxvset.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6E361B4-40F3-4C90-8A95-D95E0D8CBCD4} (MultiUpload Control) - http://www.clubbox.co.kr/neo.fld/MultiUpload.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: cdhwph.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

–
End of file - 8564 bytes
Please do not perform any more scans/procedures in an attempt to clean your machine. The best thing you can do is just pull the plug on it. I will get back to you later this evening with a comprehensive plan to eradicate this infection as much as possible. Trevuren
A. First we must disable some of your security programs so that they do not interfere with the running of our tools:

AVG
Please open the AVG Control Center program -> double-click on the "AVG Resident Shield" component (looks like this: [external image: Posted Image]) -> deselect the "Turn on AVG Resident Shield" checkmark and save the setting.
When you need to enable the AVG Resident Shield, ( I'll let you know when) just open the AVG Control Center program -> double-click on the "AVG Resident Shield" component -> select the "Turn on AVG Resident Shield" checkmark and save the setting.


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\ekejy.exe
C:\diopero.exe
c:\windows\system32\khfcdcBs.dll
c:\WINDOWS\system32\twex.exe
c:\WINDOWS\system32\cdhwph.dll
c:\WINDOWS\system32\
c:\windows\Tasks\oocjxuct.job

Folder::
C:\Rooter$
C:\Documents and Settings\winxp\Twain

DirLook::
C:\32788R22FWJFW
C:\1621684321

Driver::
cusbohcn
SetupNTGLM7X

Domains::

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"60a8f0ce"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Twain"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0B96BF84-DA5C-46F4-A7FC-5319CFF74163}]
[-HKEY_CLASSES_ROOT\CLSID\{0B96BF84-DA5C-46F4-A7FC-5319CFF74163}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6A2E758A-028B-46BB-A11D-0608AB5A4ED3}]
[-HKEY_CLASSES_ROOT\CLSID\{6A2E758A-028B-46BB-A11D-0608AB5A4ED3}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{882A7CC6-0163-4BC1-8BC1-505E36C9FFA2}]
[-HKEY_CLASSES_ROOT\CLSID\{882A7CC6-0163-4BC1-8BC1-505E36C9FFA2}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BCEF5CDE-BAD4-4532-A30B-9D16D502DE69}]
[-HKEY_CLASSES_ROOT\CLSID\{BCEF5CDE-BAD4-4532-A30B-9D16D502DE69}]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. Do not use your computer for any other purpose while ComboFix is running.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


C. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply along with a fresh HijackThis log.
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI