Problem with Virtumonde and Win32.WinFixer [RESOLVED] |
![]() ![]() |
Problem with Virtumonde and Win32.WinFixer [RESOLVED] |
Sep 9 2007, 09:12 PM
Post
#1
|
|
![]() Member ![]() ![]() Posts: 26 From: Boise, ID OS: Windows XP |
Hi, I completed all tasks In the "Before Posting" section. Problem before arriving at your site: The kids formatted drive C: and loaded Windows XP. They failed to process any upgrades. System became sluggish with numerous pop-ups about every 30 seconds. I processed all Windows updates to SP2 then found this site which advises not to put SP2 on top of viruses. Sorry! The problem of pop-ups seems to be gone for now, but each step in your pre-post process identifies malware, viruses, or rootkits still in the system. Thanks in advance for all your help. FYI a Drive E: is present and has some infections. All scans were run on both drives. Home Network sharing currently enabled. Do you recommend stopping all shared files?
HJT: Logfile of HijackThis v1.99.1 Scan saved at 9:01:41 PM, on 9/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Setup Files\HijackThis\HijackThis.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S66.tmp" /EF "HKCU" O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1) on MAIN] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S3.tmp" /EF "HKCU" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1187927644452 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe KASPERSKI Sunday, September 09, 2007 11:57:22 AM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.1 Kaspersky Anti-Virus database last update: 9/09/2007 Kaspersky Anti-Virus database records: 410615 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target Folders C:\Documents and Settings\ C:\Program Files\ C:\System Volume Information\ C:\WINDOWS\ Scan Statistics Total number of scanned objects 29784 Number of viruses found 4 Number of infected objects 11 Number of suspicious objects 0 Duration of the scan process 00:23:37 Infected Object Name Virus Name Last Action C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Sarah\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Sarah\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Sarah\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Sarah\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Sarah\Local Settings\History\History.IE5\MSHist012007090920070910\index.dat Object is locked skipped C:\Documents and Settings\Sarah\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Sarah\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Sarah\NTUSER.DAT.LOG Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP36\A0009107.exe/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP36\A0009107.exe Inno: infected - 1 skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe/file05/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe/file05 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe/file26 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe/file39 Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013313.exe Inno: infected - 4 skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP40\A0013314.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP41\A0013923.exe/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP41\A0013923.exe Inno: infected - 1 skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP41\A0013938.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped C:\System Volume Information\_restore{6B2242CF-1819-4A14-BF82-3E9F3C958AA7}\RP43\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{B653C56E-E8F9-45C7-8555-17CBF50D6CA9}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_604.dat Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_698.dat Object is locked skipped C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. PANDA ACTIVESCAN Incident Status Location Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Sarah\Desktop\ComboFix.exe[nircmd.exe] Virus:Generic Malware Disinfected C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\AsAgents.dll.vir Virus:Generic Malware Disinfected C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\fopnl.dll.vir Virus:Generic Malware Disinfected C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir Virus:Generic Malware Disinfected C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\shellext.dll.vir Spyware:Spyware/Virtumonde Not disinfected C:\qoobox\Quarantine\catchme2007-09-09_ 01126.07.zip[fccdcbc.dll] Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe Regards - TaterState |
|
|
Sep 13 2007, 04:50 PM
Post
#2
|
|
![]() GeekU Junior Posts: 2,435 From: California OS: Windows XP Media Center Editon SP3 |
Hello and Welcome to Geeks to Go.
I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. Sorry for the delay, we have been quite busy around here. Step 1 Download Deckard's System Scanner (DSS) to your Desktop.
Step 2 Download and scan with SUPERAntiSpyware Free for Home Users
|
|
|
Sep 13 2007, 10:14 PM
Post
#3
|
|
![]() Member ![]() ![]() Posts: 26 From: Boise, ID OS: Windows XP |
Thank you for replying. Step 1 and Step 2 ran smoothly, here are the results:
MAIN.TXT Deckard's System Scanner v20070905.67 Run by Sarah on 2007-09-13 19:49:09 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 7: 2007-09-14 01:49:12 UTC - RP50 - Deckard's System Scanner Restore Point 6: 2007-09-13 03:17:18 UTC - RP49 - System Checkpoint 5: 2007-09-12 03:00:15 UTC - RP48 - Software Distribution Service 3.0 4: 2007-09-11 16:17:18 UTC - RP47 - System Checkpoint 3: 2007-09-10 15:37:25 UTC - RP46 - Installed Ad-Aware 2007 -- First Restore Point -- 1: 2007-09-09 20:01:18 UTC - RP44 - With Virus pre Geeks To Go Backed up registry hives. Performed disk cleanup. -- HijackThis (run as Sarah.exe) ----------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 7:49:21 PM, on 9/13/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Sarah\Desktop\dss.exe C:\SETUPF~1\HIJACK~1\Sarah.exe O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S66.tmp" /EF "HKCU" O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1) on MAIN] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S3.tmp" /EF "HKCU" O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1187927644452 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware> S3 catchme - c:\docume~1\sarah\locals~1\temp\catchme.sys (file missing) S3 SABProcEnum - c:\program files\internet explorer\sabprocenum.sys (file missing) -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- All services whitelisted. -- Device Manager: Disabled ---------------------------------------------------- Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Camera Device ID: USB\VID_046D&PID_08A6&MI_00\6&260B400A&0&0000 Manufacturer: Name: Camera PNP Device ID: USB\VID_046D&PID_08A6&MI_00\6&260B400A&0&0000 Service: Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Universal Serial Bus (USB) Controller Device ID: PCI\VEN_1039&DEV_7002&SUBSYS_70021039&REV_00\3&267A616A&0&1B Manufacturer: Name: Universal Serial Bus (USB) Controller PNP Device ID: PCI\VEN_1039&DEV_7002&SUBSYS_70021039&REV_00\3&267A616A&0&1B Service: -- Files created between 2007-08-13 and 2007-09-13 ----------------------------- 2007-09-12 20:21:57 0 d-------- C:\WINDOWS\LastGood 2007-09-10 09:37:27 0 d-------- C:\Program Files\Lavasoft 2007-09-10 09:37:26 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2007-09-09 19:52:51 0 d-------- C:\WINDOWS\system32\ActiveScan 2007-09-09 17:34:29 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2007-09-09 17:34:22 0 d-------- C:\Program Files\SUPERAntiSpyware 2007-09-09 17:34:22 0 d-------- C:\Documents and Settings\Sarah\Application Data\SUPERAntiSpyware.com 2007-09-09 17:33:59 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard 2007-09-09 14:48:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft 2007-09-09 14:07:38 0 d-------- C:\Documents and Settings\Sarah\Application Data\Grisoft 2007-09-09 14:07:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft 2007-09-09 14:03:20 0 d-------- C:\WINDOWS\pss 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Templates 2007-09-09 12:42:09 0 dr------- C:\Documents and Settings\Administrator\Start Menu 2007-09-09 12:42:09 0 dr-h----- C:\Documents and Settings\Administrator\SendTo 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Recent 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\PrintHood 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\NetHood 2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\My Documents 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Local Settings 2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\Favorites 2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\Desktop 2007-09-09 12:42:09 0 d---s---- C:\Documents and Settings\Administrator\Cookies 2007-09-09 12:42:09 0 dr-h----- C:\Documents and Settings\Administrator\Application Data 2007-09-09 12:42:09 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft 2007-09-09 12:42:08 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT 2007-09-09 00:32:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage 2007-09-09 00:31:47 0 d-------- C:\WINDOWS\system32\PreInstall 2007-09-09 00:31:45 0 d--h----- C:\WINDOWS\$hf_mig$ 2007-09-09 00:01:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2007-09-09 00:00:55 0 d-------- C:\WINDOWS\system32\Kaspersky Lab 2007-09-08 23:10:22 0 d-------- C:\Documents and Settings\LocalService\Start Menu 2007-09-08 23:07:22 0 d-------- C:\WINDOWS\Prefetch 2007-09-08 23:07:21 0 d---s---- C:\WINDOWS\system32\Microsoft 2007-09-08 23:03:49 0 d-------- C:\Program Files\Ace Utilities 2007-09-08 22:48:19 0 d-------- C:\WINDOWS\provisioning 2007-09-08 22:48:19 0 d-------- C:\WINDOWS\peernet 2007-09-08 22:46:44 0 d-------- C:\WINDOWS\ServicePackFiles 2007-09-08 22:41:57 0 d-------- C:\WINDOWS\system32\ReinstallBackups 2007-09-08 22:38:56 0 d-------- C:\WINDOWS\EHome 2007-09-08 02:04:38 0 d-------- C:\Documents and Settings\Sarah\Application Data\WinRAR 2007-08-27 15:28:56 0 d-------- C:\Documents and Settings\Sarah\Contacts 2007-08-27 15:28:34 0 d------c- C:\WINDOWS\system32\DRVSTORE 2007-08-27 15:15:50 0 d-------- C:\Documents and Settings\Sarah\Application Data\Help 2007-08-26 21:00:29 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System> 2007-08-26 21:00:29 0 d--h---c- C:\WINDOWS\$xpsp1hfm$ 2007-08-25 23:16:38 0 d-------- C:\Documents and Settings\All Users\Application Data\EPSON 2007-08-25 23:04:21 0 d-------- C:\WINDOWS\system32\FxsTmp 2007-08-25 22:29:44 0 d-------- C:\WINDOWS\system32\bits 2007-08-25 22:11:59 0 d-------- C:\Program Files\EPSON 2007-08-24 15:51:22 0 d-------- C:\Program Files\Electronic Arts 2007-08-24 15:48:15 0 d-------- C:\WINDOWS\RegisteredPackages 2007-08-24 15:47:21 0 d--h----- C:\Program Files\win32Gl 2007-08-23 22:01:04 0 d-------- C:\WINDOWS\Sun 2007-08-23 22:01:04 0 d-------- C:\Documents and Settings\Sarah\Application Data\Sun 2007-08-23 22:00:25 0 d-------- C:\Program Files\Java 2007-08-23 21:58:47 0 d-------- C:\Program Files\Common Files\Java 2007-08-23 21:54:17 0 d-------- C:\WINDOWS\SoftwareDistribution 2007-08-23 21:51:24 0 d---s---- C:\Documents and Settings\Sarah\UserData 2007-08-23 12:05:05 0 d-------- C:\Documents and Settings\Sarah\Application Data\Adobe 2007-08-23 12:04:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe 2007-08-23 12:04:15 0 d-------- C:\Program Files\Common Files\Adobe 2007-08-23 11:27:07 0 d-------- C:\Program Files\uTorrent 2007-08-23 11:27:03 0 d-------- C:\Documents and Settings\Sarah\Application Data\uTorrent 2007-08-23 11:24:56 0 d-------- C:\Program Files\DAEMON Tools 2007-08-23 11:23:40 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-08-22 22:52:23 266240 --a------ C:\WINDOWS\CMIUninstall.exe <Not Verified; ; GeneralUninstall Application> 2007-08-22 22:52:23 225280 --a------ C:\WINDOWS\CmiRmRedundDir.exe <Not Verified; ; CmiRmRedundDir Application> 2007-08-22 22:52:23 28672 --a------ C:\WINDOWS\CMIRmDriver.dll 2007-08-22 22:52:23 0 d--h----- C:\Program Files\InstallShield Installation Information 2007-08-22 22:52:23 0 d-------- C:\Program Files\C-Media 3D Audio 2007-08-22 22:43:30 984 --a------ C:\WINDOWS\system32\d3d8caps.dat 2007-08-20 00:56:37 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program> 2007-08-20 00:24:30 0 d-------- C:\Documents and Settings\Sarah\Application Data\Google 2007-08-20 00:15:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Google 2007-08-20 00:15:18 0 d-------- C:\Program Files\Google 2007-08-20 00:15:07 0 d-------- C:\Documents and Settings\Sarah\Application Data\Macromedia 2007-08-19 22:29:46 0 d-------- C:\Program Files\MSN Messenger 2007-08-19 22:12:34 0 d-------- C:\WINDOWS\nview 2007-08-19 22:11:39 0 d-------- C:\Program Files\Common Files\InstallShield 2007-08-19 22:11:32 0 d-------- C:\NVIDIA 2007-08-19 21:45:05 0 d-------- C:\Program Files\Alwil Software 2007-08-19 21:43:31 0 d-------- C:\Setup Files 2007-08-19 21:30:20 0 d--hs---- C:\WINDOWS\Installer 2007-08-19 21:30:18 0 d-------- C:\Documents and Settings\Sarah\Application Data\Identities 2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\Templates 2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\Start Menu 2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\SendTo 2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\Recent 2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\PrintHood 2007-08-19 21:30:11 1835008 --ah----- C:\Documents and Settings\Sarah\NTUSER.DAT 2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\NetHood 2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\My Documents 2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\Local Settings 2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\Favorites 2007-08-19 21:30:11 0 d-------- C:\Documents and Settings\Sarah\Desktop 2007-08-19 21:30:11 0 d---s---- C:\Documents and Settings\Sarah\Cookies 2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\Application Data 2007-08-19 21:28:25 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings 2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\NetworkService\Cookies 2007-08-19 21:28:25 0 d-------- C:\Documents and Settings\NetworkService\Application Data 2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft 2007-08-19 21:28:25 233472 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT 2007-08-19 21:28:25 0 d--h----- C:\Documents and Settings\LocalService\Local Settings 2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\LocalService\Cookies 2007-08-19 21:28:25 0 d-------- C:\Documents and Settings\LocalService\Application Data 2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft 2007-08-19 21:28:24 233472 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT 2007-08-19 21:25:47 0 d-------- C:\WINDOWS\system32\xircom 2007-08-19 21:25:47 0 d-------- C:\Program Files\microsoft frontpage 2007-08-19 21:25:46 233472 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT 2007-08-19 21:25:37 0 -rahs---- C:\MSDOS.SYS 2007-08-19 21:25:37 0 -rahs---- C:\IO.SYS 2007-08-19 21:25:37 0 --a------ C:\CONFIG.SYS 2007-08-19 21:25:37 0 --a------ C:\AUTOEXEC.BAT 2007-08-19 21:24:49 0 d--hs---- C:\Documents and Settings\All Users\DRM 2007-08-19 21:24:41 0 dr------- C:\WINDOWS\Offline Web Pages 2007-08-19 21:24:41 0 d---s---- C:\WINDOWS\Downloaded Program Files 2007-08-19 21:23:42 0 d-------- C:\WINDOWS\Registration 2007-08-19 20:41:45 0 d-------- C:\WINDOWS\srchasst 2007-08-19 20:41:40 0 d-------- C:\WINDOWS\system32\DirectX 2007-08-19 20:41:39 0 d-------- C:\WINDOWS\system32\Macromed 2007-08-19 20:41:30 0 d-------- C:\Program Files\Movie Maker 2007-08-19 20:41:09 0 d-------- C:\WINDOWS\system32\Restore 2007-08-19 20:41:04 0 d-------- C:\WINDOWS\PCHEALTH 2007-08-19 20:41:00 0 d---s---- C:\WINDOWS\Tasks 2007-08-19 20:40:57 0 d-------- C:\Program Files\Common Files\MSSoap 2007-08-19 20:40:48 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-08-19 20:40:03 0 d--h----- C:\Program Files\WindowsUpdate 2007-08-19 20:40:03 0 d-------- C:\Program Files\Online Services 2007-08-19 20:39:58 0 d-------- C:\Program Files\Messenger 2007-08-19 20:39:50 0 d-------- C:\Program Files\MSN Gaming Zone 2007-08-19 20:39:43 0 d-------- C:\Program Files\Windows NT 2007-08-19 20:39:35 0 d-------- C:\WINDOWS\system32\MsDtc 2007-08-19 20:39:33 0 d-------- C:\WINDOWS\system32\Com 2007-08-19 19:37:08 0 d--hs---- C:\System Volume Information 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\Templates 2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\Default User\Start Menu 2007-08-19 15:00:12 0 dr-h----- C:\Documents and Settings\Default User\SendTo 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\Recent 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\PrintHood 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\NetHood 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\My Documents 2007-08-19 15:00:12 0 dr-h----- C:\Documents and Settings\Default User\Local Settings 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\Favorites 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\Desktop 2007-08-19 15:00:12 0 d---s---- C:\Documents and Settings\Default User\Cookies 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\All Users\Templates 2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\All Users\Start Menu 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\All Users\Favorites 2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\All Users\Documents 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\All Users\Desktop 2007-08-19 14:59:51 0 dr-h----- C:\Documents and Settings\Default User\Application Data 2007-08-19 14:59:51 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft 2007-08-19 14:59:51 0 dr-h----- C:\Documents and Settings\All Users\Application Data 2007-08-19 14:59:51 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft 2007-08-19 14:33:23 0 d-------- C:\Program Files\Common Files\ODBC 2007-08-19 14:33:21 0 d-------- C:\Program Files\Common Files\SpeechEngines 2007-08-19 14:33:20 0 dr------- C:\Program Files 2007-08-19 14:33:20 0 d-------- C:\Program Files\Common Files 2007-08-19 14:32:48 0 d-------- C:\WINDOWS\system32\CatRoot2 2007-08-19 14:32:48 0 d-------- C:\WINDOWS\system32\CatRoot 2007-08-19 14:32:27 0 d-------- C:\Documents and Settings 2007-08-19 14:28:02 0 d-------- C:\WINDOWS 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\WinSxS 2007-08-19 14:28:02 0 dr------- C:\WINDOWS\Web 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\twain_32 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\wins 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\wbem 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\usmt 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\spool 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ShellExt 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\Setup 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ras 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\oobe 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\npp 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\mui 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\inetsrv 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\IME 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\icsxml 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ias 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\export 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers\etc 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers\disdn 2007-08-19 14:28:02 0 dr-hs--c- C:\WINDOWS\system32\dllcache 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\dhcp 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\config 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\3com_dmi 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\3076 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\2052 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1054 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1042 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1041 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1037 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1033 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1031 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1028 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1025 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\security 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Resources 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\repair 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\mui 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\msapps 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\msagent 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Media 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\java 2007-08-19 14:28:02 0 d--h----- C:\WINDOWS\inf 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\ime 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Help 2007-08-19 14:28:02 0 dr--s---- C:\WINDOWS\Fonts 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Driver Cache 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Debug 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Cursors 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Connection Wizard 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\Config 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\AppPatch 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\addins -- Find3M Report --------------------------------------------------------------- 2007-08-19 15:00:12 62 --ahs---- C:\Documents and Settings\Sarah\Application Data\desktop.ini 2007-06-29 00:43:00 1626112 --a------ C:\WINDOWS\system32\nwiz.exe 2007-06-29 00:43:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll 2007-06-29 00:43:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll 2007-06-29 00:43:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll 2007-06-29 00:43:00 1474560 --a------ C:\WINDOWS\system32\nview.dll 2007-06-29 00:43:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe 2007-06-29 00:43:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe 2007-06-29 00:43:00 425984 --a------ C:\WINDOWS\system32\keystone.exe -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [09/06/2007 04:06 AM] "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [06/29/2007 12:43 AM] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 04:00 AM] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM] "nwiz"="nwiz.exe" [06/29/2007 12:43 AM C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [06/29/2007 12:43 AM] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 03:25 AM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.exe" [05/23/2006 04:00 AM] "Auto EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1) on MAIN"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.exe" [05/23/2006 04:00 AM] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [09/09/2007 08:47 PM] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [09/12/2007 08:22 PM] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 09/09/2007 08:47 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] "Authentication Packages"= msv1_0 C:\\WINDOWS\\System32\\jkhhe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume shadow copy" *Newly Created Service* - AAWSERVICE *Newly Created Service* - USNJSVC [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7F991010-A396-8AFF-D343-9DD3B6A205D0}] C:\Program Files\win32Gl\svhost.exe s -- End of Deckard's System Scanner: finished at 2007-09-13 19:51:29 ------------ EXTRA.TXT Deckard's System Scanner v20070905.67 Run by Sarah on 2007-09-13 19:49:09 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 7: 2007-09-14 01:49:12 UTC - RP50 - Deckard's System Scanner Restore Point 6: 2007-09-13 03:17:18 UTC - RP49 - System Checkpoint 5: 2007-09-12 03:00:15 UTC - RP48 - Software Distribution Service 3.0 4: 2007-09-11 16:17:18 UTC - RP47 - System Checkpoint 3: 2007-09-10 15:37:25 UTC - RP46 - Installed Ad-Aware 2007 -- First Restore Point -- 1: 2007-09-09 20:01:18 UTC - RP44 - With Virus pre Geeks To Go Backed up registry hives. Performed disk cleanup. -- HijackThis (run as Sarah.exe) ----------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 7:49:21 PM, on 9/13/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Sarah\Desktop\dss.exe C:\SETUPF~1\HIJACK~1\Sarah.exe O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S66.tmp" /EF "HKCU" O4 - HKCU\..\Run: [Auto EPSON Stylus Photo RX580 Series on DPR1260 (dlinkps-fb2b65 USB Port_1) on MAIN] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBPA.EXE /FU "C:\WINDOWS\TEMP\E_S3.tmp" /EF "HKCU" O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1187927644452 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R1 SASDIFSV - c:\program files\superantispyware\sasdifsv.sys R1 SASKUTIL - c:\program files\superantispyware\saskutil.sys R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware> S3 catchme - c:\docume~1\sarah\locals~1\temp\catchme.sys (file missing) S3 SABProcEnum - c:\program files\internet explorer\sabprocenum.sys (file missing) -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- All services whitelisted. -- Device Manager: Disabled ---------------------------------------------------- Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Camera Device ID: USB\VID_046D&PID_08A6&MI_00\6&260B400A&0&0000 Manufacturer: Name: Camera PNP Device ID: USB\VID_046D&PID_08A6&MI_00\6&260B400A&0&0000 Service: Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Universal Serial Bus (USB) Controller Device ID: PCI\VEN_1039&DEV_7002&SUBSYS_70021039&REV_00\3&267A616A&0&1B Manufacturer: Name: Universal Serial Bus (USB) Controller PNP Device ID: PCI\VEN_1039&DEV_7002&SUBSYS_70021039&REV_00\3&267A616A&0&1B Service: -- Files created between 2007-08-13 and 2007-09-13 ----------------------------- 2007-09-12 20:21:57 0 d-------- C:\WINDOWS\LastGood 2007-09-10 09:37:27 0 d-------- C:\Program Files\Lavasoft 2007-09-10 09:37:26 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft 2007-09-09 19:52:51 0 d-------- C:\WINDOWS\system32\ActiveScan 2007-09-09 17:34:29 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2007-09-09 17:34:22 0 d-------- C:\Program Files\SUPERAntiSpyware 2007-09-09 17:34:22 0 d-------- C:\Documents and Settings\Sarah\Application Data\SUPERAntiSpyware.com 2007-09-09 17:33:59 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard 2007-09-09 14:48:41 0 d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft 2007-09-09 14:07:38 0 d-------- C:\Documents and Settings\Sarah\Application Data\Grisoft 2007-09-09 14:07:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft 2007-09-09 14:03:20 0 d-------- C:\WINDOWS\pss 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Templates 2007-09-09 12:42:09 0 dr------- C:\Documents and Settings\Administrator\Start Menu 2007-09-09 12:42:09 0 dr-h----- C:\Documents and Settings\Administrator\SendTo 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Recent 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\PrintHood 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\NetHood 2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\My Documents 2007-09-09 12:42:09 0 d--h----- C:\Documents and Settings\Administrator\Local Settings 2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\Favorites 2007-09-09 12:42:09 0 d-------- C:\Documents and Settings\Administrator\Desktop 2007-09-09 12:42:09 0 d---s---- C:\Documents and Settings\Administrator\Cookies 2007-09-09 12:42:09 0 dr-h----- C:\Documents and Settings\Administrator\Application Data 2007-09-09 12:42:09 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft 2007-09-09 12:42:08 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT 2007-09-09 00:32:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage 2007-09-09 00:31:47 0 d-------- C:\WINDOWS\system32\PreInstall 2007-09-09 00:31:45 0 d--h----- C:\WINDOWS\$hf_mig$ 2007-09-09 00:01:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2007-09-09 00:00:55 0 d-------- C:\WINDOWS\system32\Kaspersky Lab 2007-09-08 23:10:22 0 d-------- C:\Documents and Settings\LocalService\Start Menu 2007-09-08 23:07:22 0 d-------- C:\WINDOWS\Prefetch 2007-09-08 23:07:21 0 d---s---- C:\WINDOWS\system32\Microsoft 2007-09-08 23:03:49 0 d-------- C:\Program Files\Ace Utilities 2007-09-08 22:48:19 0 d-------- C:\WINDOWS\provisioning 2007-09-08 22:48:19 0 d-------- C:\WINDOWS\peernet 2007-09-08 22:46:44 0 d-------- C:\WINDOWS\ServicePackFiles 2007-09-08 22:41:57 0 d-------- C:\WINDOWS\system32\ReinstallBackups 2007-09-08 22:38:56 0 d-------- C:\WINDOWS\EHome 2007-09-08 02:04:38 0 d-------- C:\Documents and Settings\Sarah\Application Data\WinRAR 2007-08-27 15:28:56 0 d-------- C:\Documents and Settings\Sarah\Contacts 2007-08-27 15:28:34 0 d------c- C:\WINDOWS\system32\DRVSTORE 2007-08-27 15:15:50 0 d-------- C:\Documents and Settings\Sarah\Application Data\Help 2007-08-26 21:00:29 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System> 2007-08-26 21:00:29 0 d--h---c- C:\WINDOWS\$xpsp1hfm$ 2007-08-25 23:16:38 0 d-------- C:\Documents and Settings\All Users\Application Data\EPSON 2007-08-25 23:04:21 0 d-------- C:\WINDOWS\system32\FxsTmp 2007-08-25 22:29:44 0 d-------- C:\WINDOWS\system32\bits 2007-08-25 22:11:59 0 d-------- C:\Program Files\EPSON 2007-08-24 15:51:22 0 d-------- C:\Program Files\Electronic Arts 2007-08-24 15:48:15 0 d-------- C:\WINDOWS\RegisteredPackages 2007-08-24 15:47:21 0 d--h----- C:\Program Files\win32Gl 2007-08-23 22:01:04 0 d-------- C:\WINDOWS\Sun 2007-08-23 22:01:04 0 d-------- C:\Documents and Settings\Sarah\Application Data\Sun 2007-08-23 22:00:25 0 d-------- C:\Program Files\Java 2007-08-23 21:58:47 0 d-------- C:\Program Files\Common Files\Java 2007-08-23 21:54:17 0 d-------- C:\WINDOWS\SoftwareDistribution 2007-08-23 21:51:24 0 d---s---- C:\Documents and Settings\Sarah\UserData 2007-08-23 12:05:05 0 d-------- C:\Documents and Settings\Sarah\Application Data\Adobe 2007-08-23 12:04:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe 2007-08-23 12:04:15 0 d-------- C:\Program Files\Common Files\Adobe 2007-08-23 11:27:07 0 d-------- C:\Program Files\uTorrent 2007-08-23 11:27:03 0 d-------- C:\Documents and Settings\Sarah\Application Data\uTorrent 2007-08-23 11:24:56 0 d-------- C:\Program Files\DAEMON Tools 2007-08-23 11:23:40 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys 2007-08-22 22:52:23 266240 --a------ C:\WINDOWS\CMIUninstall.exe <Not Verified; ; GeneralUninstall Application> 2007-08-22 22:52:23 225280 --a------ C:\WINDOWS\CmiRmRedundDir.exe <Not Verified; ; CmiRmRedundDir Application> 2007-08-22 22:52:23 28672 --a------ C:\WINDOWS\CMIRmDriver.dll 2007-08-22 22:52:23 0 d--h----- C:\Program Files\InstallShield Installation Information 2007-08-22 22:52:23 0 d-------- C:\Program Files\C-Media 3D Audio 2007-08-22 22:43:30 984 --a------ C:\WINDOWS\system32\d3d8caps.dat 2007-08-20 00:56:37 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program> 2007-08-20 00:24:30 0 d-------- C:\Documents and Settings\Sarah\Application Data\Google 2007-08-20 00:15:27 0 d-------- C:\Documents and Settings\All Users\Application Data\Google 2007-08-20 00:15:18 0 d-------- C:\Program Files\Google 2007-08-20 00:15:07 0 d-------- C:\Documents and Settings\Sarah\Application Data\Macromedia 2007-08-19 22:29:46 0 d-------- C:\Program Files\MSN Messenger 2007-08-19 22:12:34 0 d-------- C:\WINDOWS\nview 2007-08-19 22:11:39 0 d-------- C:\Program Files\Common Files\InstallShield 2007-08-19 22:11:32 0 d-------- C:\NVIDIA 2007-08-19 21:45:05 0 d-------- C:\Program Files\Alwil Software 2007-08-19 21:43:31 0 d-------- C:\Setup Files 2007-08-19 21:30:20 0 d--hs---- C:\WINDOWS\Installer 2007-08-19 21:30:18 0 d-------- C:\Documents and Settings\Sarah\Application Data\Identities 2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\Templates 2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\Start Menu 2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\SendTo 2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\Recent 2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\PrintHood 2007-08-19 21:30:11 1835008 --ah----- C:\Documents and Settings\Sarah\NTUSER.DAT 2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\NetHood 2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\My Documents 2007-08-19 21:30:11 0 d--h----- C:\Documents and Settings\Sarah\Local Settings 2007-08-19 21:30:11 0 dr------- C:\Documents and Settings\Sarah\Favorites 2007-08-19 21:30:11 0 d-------- C:\Documents and Settings\Sarah\Desktop 2007-08-19 21:30:11 0 d---s---- C:\Documents and Settings\Sarah\Cookies 2007-08-19 21:30:11 0 dr-h----- C:\Documents and Settings\Sarah\Application Data 2007-08-19 21:28:25 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings 2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\NetworkService\Cookies 2007-08-19 21:28:25 0 d-------- C:\Documents and Settings\NetworkService\Application Data 2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft 2007-08-19 21:28:25 233472 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT 2007-08-19 21:28:25 0 d--h----- C:\Documents and Settings\LocalService\Local Settings 2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\LocalService\Cookies 2007-08-19 21:28:25 0 d-------- C:\Documents and Settings\LocalService\Application Data 2007-08-19 21:28:25 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft 2007-08-19 21:28:24 233472 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT 2007-08-19 21:25:47 0 d-------- C:\WINDOWS\system32\xircom 2007-08-19 21:25:47 0 d-------- C:\Program Files\microsoft frontpage 2007-08-19 21:25:46 233472 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT 2007-08-19 21:25:37 0 -rahs---- C:\MSDOS.SYS 2007-08-19 21:25:37 0 -rahs---- C:\IO.SYS 2007-08-19 21:25:37 0 --a------ C:\CONFIG.SYS 2007-08-19 21:25:37 0 --a------ C:\AUTOEXEC.BAT 2007-08-19 21:24:49 0 d--hs---- C:\Documents and Settings\All Users\DRM 2007-08-19 21:24:41 0 dr------- C:\WINDOWS\Offline Web Pages 2007-08-19 21:24:41 0 d---s---- C:\WINDOWS\Downloaded Program Files 2007-08-19 21:23:42 0 d-------- C:\WINDOWS\Registration 2007-08-19 20:41:45 0 d-------- C:\WINDOWS\srchasst 2007-08-19 20:41:40 0 d-------- C:\WINDOWS\system32\DirectX 2007-08-19 20:41:39 0 d-------- C:\WINDOWS\system32\Macromed 2007-08-19 20:41:30 0 d-------- C:\Program Files\Movie Maker 2007-08-19 20:41:09 0 d-------- C:\WINDOWS\system32\Restore 2007-08-19 20:41:04 0 d-------- C:\WINDOWS\PCHEALTH 2007-08-19 20:41:00 0 d---s---- C:\WINDOWS\Tasks 2007-08-19 20:40:57 0 d-------- C:\Program Files\Common Files\MSSoap 2007-08-19 20:40:48 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat 2007-08-19 20:40:03 0 d--h----- C:\Program Files\WindowsUpdate 2007-08-19 20:40:03 0 d-------- C:\Program Files\Online Services 2007-08-19 20:39:58 0 d-------- C:\Program Files\Messenger 2007-08-19 20:39:50 0 d-------- C:\Program Files\MSN Gaming Zone 2007-08-19 20:39:43 0 d-------- C:\Program Files\Windows NT 2007-08-19 20:39:35 0 d-------- C:\WINDOWS\system32\MsDtc 2007-08-19 20:39:33 0 d-------- C:\WINDOWS\system32\Com 2007-08-19 19:37:08 0 d--hs---- C:\System Volume Information 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\Templates 2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\Default User\Start Menu 2007-08-19 15:00:12 0 dr-h----- C:\Documents and Settings\Default User\SendTo 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\Recent 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\PrintHood 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\Default User\NetHood 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\My Documents 2007-08-19 15:00:12 0 dr-h----- C:\Documents and Settings\Default User\Local Settings 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\Favorites 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\Default User\Desktop 2007-08-19 15:00:12 0 d---s---- C:\Documents and Settings\Default User\Cookies 2007-08-19 15:00:12 0 d--h----- C:\Documents and Settings\All Users\Templates 2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\All Users\Start Menu 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\All Users\Favorites 2007-08-19 15:00:12 0 dr------- C:\Documents and Settings\All Users\Documents 2007-08-19 15:00:12 0 d-------- C:\Documents and Settings\All Users\Desktop 2007-08-19 14:59:51 0 dr-h----- C:\Documents and Settings\Default User\Application Data 2007-08-19 14:59:51 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft 2007-08-19 14:59:51 0 dr-h----- C:\Documents and Settings\All Users\Application Data 2007-08-19 14:59:51 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft 2007-08-19 14:33:23 0 d-------- C:\Program Files\Common Files\ODBC 2007-08-19 14:33:21 0 d-------- C:\Program Files\Common Files\SpeechEngines 2007-08-19 14:33:20 0 dr------- C:\Program Files 2007-08-19 14:33:20 0 d-------- C:\Program Files\Common Files 2007-08-19 14:32:48 0 d-------- C:\WINDOWS\system32\CatRoot2 2007-08-19 14:32:48 0 d-------- C:\WINDOWS\system32\CatRoot 2007-08-19 14:32:27 0 d-------- C:\Documents and Settings 2007-08-19 14:28:02 0 d-------- C:\WINDOWS 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\WinSxS 2007-08-19 14:28:02 0 dr------- C:\WINDOWS\Web 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\twain_32 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\wins 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\wbem 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\usmt 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\spool 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ShellExt 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\Setup 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ras 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\oobe 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\npp 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\mui 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\inetsrv 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\IME 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\icsxml 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\ias 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\export 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers\etc 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\drivers\disdn 2007-08-19 14:28:02 0 dr-hs--c- C:\WINDOWS\system32\dllcache 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\dhcp 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\config 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\3com_dmi 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\3076 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\2052 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1054 2007-08-19 14:28:02 0 d-------- C:\WINDOWS\system32\1042 2007-08-19 |
|
|
Sep 13 2007, 10:20 PM
Post
#4
|
|
![]() Member ![]() ![]() Posts: 26 From: Boise, ID OS: Windows XP |
Sorry, I didn't realize part of the first post got ignored. Here's the snipped file and the Scan log missing from above
EXTRA.TXT (complete file) Deckard's System Scanner v20070905.67 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Home Edition (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: AMD Athlon XP 3000+ Percentage of Memory in Use: 40% Physical Memory (total/avail): 1023.36 MiB / 605.48 MiB Pagefile Memory (total/avail): 2461.72 MiB / 2121.63 MiB Virtual Memory (total/avail): 2047.88 MiB / 1963.26 MiB A: is Removable (Unformatted) C: is Fixed (NTFS) - 27.95 GiB total, 17.18 GiB free. D: is CDROM (No Media) E: is Fixed (NTFS) - 232.88 GiB total, 136.72 GiB free. F: is CDROM (No Media) P: is Network (NTFS) \\.\PHYSICALDRIVE1 - WDC WD2500JB-00REA0 - 232.88 GiB - 1 partition \PARTITION0 - Installable File System - 232.88 GiB - E: \\.\PHYSICALDRIVE0 - WDC WD300AB-00BVA0 - 27.95 GiB - 1 partition \PARTITION0 (bootable) - Installable File System - 27.95 GiB - C: -- Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. Windows Internal Firewall is enabled. AV: avast! antivirus 4.7.1043 [VPS 000774-5] v4.7.1043 (ALWIL Software) Disabled [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Sarah\Application Data CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=UPSTAIRS ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Sarah LOGONSERVER=\\UPSTAIRS NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 10 Stepping 0, AuthenticAMD PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0a00 ProgramFiles=C:\Program Files PROMPT=$P$G SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\Sarah\LOCALS~1\Temp TMP=C:\DOCUME~1\Sarah\LOCALS~1\Temp USERDOMAIN=UPSTAIRS USERNAME=Sarah USERPROFILE=C:\Documents and Settings\Sarah windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Sarah (admin) Administrator (admin) -- Add/Remove Programs --------------------------------------------------------- --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL Ace Utilities --> "C:\Program Files\Ace Utilities\uninstall.exe" Ad-Aware 2007 --> MsiExec.exe /X{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF} Adobe Flash Player ActiveX --> C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 8.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003} avast! Antivirus --> rundll32 C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe C-Media 3D Audio --> C:\WINDOWS\CMIUnInstall.exe C-Media WDM Audio Driver --> C:\WINDOWS\system32\cmirmdrv.exe EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R getPlus®_ocx --> rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\inf\GETPLUSo.INF, DefaultUninstall Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29} Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll" HijackThis 1.99.1 --> C:\DOCUME~1\Sarah\LOCALS~1\Temp\Rar$EX00.078\HijackThis.exe /uninstall Java 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020} Kaspersky Online Scanner --> C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe Need for Speed™ Carbon --> C:\Program Files\Electronic Arts\Need for Speed Carbon\EAUninstall.exe NVIDIA Drivers --> C:\WINDOWS\System32\nvudisp.exe UninstallGUI Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA} Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F} WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe -- Application Event Log ------------------------------------------------------- Event Record #/Type264 / Success Event Submitted/Written: 09/10/2007 08:54:48 AM Event ID/Source: 12001 / usnjsvc Event Description: The Messenger Sharing USN Journal Reader service started successfully. Event Record #/Type258 / Success Event Submitted/Written: 09/10/2007 08:50:45 AM Event ID/Source: 12001 / usnjsvc Event Description: The Messenger Sharing USN Journal Reader service started successfully. Event Record #/Type257 / Warning Event Submitted/Written: 09/10/2007 08:13:47 AM Event ID/Source: 1015 / EvntAgnt Event Description: TraceLevel parameter not located in registry; Default trace level used is 32. Event Record #/Type256 / Warning Event Submitted/Written: 09/10/2007 08:13:47 AM Event ID/Source: 1003 / EvntAgnt Event Description: TraceFileName parameter not located in registry; Default trace file used is . Event Record #/Type255 / Warning Event Submitted/Written: 09/10/2007 08:13:46 AM Event ID/Source: 32068 / Microsoft Fax Event Description: The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly. Country/region code: '*' Area code: '*' -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type1294 / Error Event Submitted/Written: 09/11/2007 00:15:29 PM Event ID/Source: 59 / SideBySide Event Description: Generate Activation Context failed for C:\Program Files\Ace Utilities\MFC80.DLL. Reference error message: The operation completed successfully. . Event Record #/Type1293 / Error Event Submitted/Written: 09/11/2007 00:15:29 PM Event ID/Source: 59 / SideBySide Event Description: Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. . Event Record #/Type1292 / Error Event Submitted/Written: 09/11/2007 00:15:29 PM Event ID/Source: 32 / SideBySide Event Description: Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system. Event Record #/Type1291 / Error Event Submitted/Written: 09/11/2007 00:15:29 PM Event ID/Source: 59 / SideBySide Event Description: Generate Activation Context failed for C:\Program Files\Ace Utilities\MFC80.DLL. Reference error message: The operation completed successfully. . Event Record #/Type1290 / Error Event Submitted/Written: 09/11/2007 00:15:29 PM Event ID/Source: 59 / SideBySide Event Description: Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. . -- End of Deckard's System Scanner: finished at 2007-09-13 19:51:29 ------------ SUPERANTISPYWARE Scan Log SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 09/13/2007 at 09:26 PM Application Version : 3.9.1008 Core Rules Database Version : 3306 Trace Rules Database Version: 1312 Scan type : Complete Scan Total Scan Time : 01:30:03 Memory items scanned : 410 Memory threats detected : 0 Registry items scanned : 3618 Registry threats detected : 0 File items scanned : 100562 File threats detected : 0 |
|
|
Sep 14 2007, 07:20 PM
Post
#5
|
|
![]() GeekU Junior Posts: 2,435 From: California OS: Windows XP Media Center Editon SP3 |
Well I only see one thing, and it is as follows.
I see you have µTorrent installed on your system. While the program itself is legal, most of the files downloaded with it are not. Also, quite often the files can be infected with viruses, malware, and other undesirable applications. I highly recommend uninstalling µTorrent via Add or Remove Programs, but this program is optional for you if you choose to want to keep it. See HERE for details on P2P file sharing programs. Other than that, your log looks clean! Nice job! How is it running ? Please use the following suggestion to help prevent reinfection. Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)Now we need to make a new System Restore Point for your PC, please do the following
I highly recommend downloading the following programs, to keep malware of your computer to begin with. The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again. SUPERAntiSpyware - A very powerful tool which searches and kills malware that infect your system. SpywareBlaster - Great prevention tool to keep malware from installing on your system. **Tutorial on installing & using this product can be found HERE** SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place. **Tutorial on installing & using this product can be found HERE** IE-SpyAd - Puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all. **Tutorial on installing & using this product can be found HERE** ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out malware that like to reside in the temp folders. AntiVirus Program An AntiVirus program is a must in today's digital world! I recommend avast! 4 Home Edition, AVG, or Anti-Vir. DO NOT install more than one antivirus program. They will conflict, and provide less protection, not more. Firewall A firewall is definitely a must have to protect your computer from hackers. I recommend Comodo, Zone Alarm, or Outpost. **Tutorial on Firewalls can be found HERE** Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there. You must stay on top of your updates at all times, for the above mentioned applications. It is vitally important to stay on top of your critical updates provided by microsoft. And finally a little How did I get infected in the first place?(by Tony Klein)Good luck and safe surfing |
|
|
Sep 15 2007, 10:13 AM
Post
#6
|
|
![]() Member ![]() ![]() Posts: 26 From: Boise, ID OS: Windows XP |
MoNsTeReNeRgY22,
Thanks so much for helping with this issue. I deleted Torrent using Add or Remove after reviewing the file sharing sheet. I then ran Ad-Aware. which found viruses. On closer examination, they were in quarantine folders. From Add or Remove I deleted the programs uploaded during this suport cycle and there was an option to delete the quarantine folder and files. I selected yes. I rebooted and ran a full Ad-Aware scan. Clean!! I then cleaned the registry with a utility, deleted my restore points, and then created a new one. As you know, the difference is amazing. Currently, Ad-Aware will be run frequently, Avast 4 is running continuously, and the modem has a built-in firewall which is PW protected. I spent some time with the TaterTots reviewing some of the additional information you supplied. Again, thanks to you personally and the entire staff at G2G. fp in id |
|
|
Sep 15 2007, 10:32 AM
Post
#7
|
|
![]() GeekU Junior Posts: 2,435 From: California OS: Windows XP Media Center Editon SP3 |
No Problem!
Glad I could help! |
|
|
Sep 15 2007, 10:32 AM
Post
#8
|
|
![]() GeekU Junior Posts: 2,435 From: California OS: Windows XP Media Center Editon SP3 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
15 / 814 | 18th June 2005 - 04:07 PM atome started - last by therock247uk |
|||||
![]() |
7 / 7,026 | 31st July 2005 - 03:46 AM davewave started - last by Metallica |
|||||
![]() |
20 / 1,713 | 21st July 2007 - 06:01 AM m8edy started - last by Essexboy |
|||||
![]() |
31 / 1,726 | 10th January 2008 - 01:16 PM ahhoss started - last by Rorschach112 |
|||||
|
Time is now: 21st November 2009 - 06:53 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising