Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Browser Hijacker [CLOSED]


  • This topic is locked This topic is locked

#1
Anne Kuhns

Anne Kuhns

    Member

  • Member
  • PipPip
  • 26 posts
I believe my computer has a browser hijacker or some sort of virus on it. I keep getting redirected to unrelated pages on link clicks, as well as countless unwarranted popups. Attached is my HJT log. Thanks!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:47:12, on 8/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Weather Pulse\weatherpulse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\IncrediMail\bin\IMApp.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Mom\Application Data\U3\000018444471A234\LaunchPad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://militarybank...itary/login.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061121
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] "C:\WINDOWS\stsystra.exe"
O4 - HKLM\..\Run: [DLA] "C:\WINDOWS\System32\DLA\DLACTRLW.EXE"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe"
O4 - HKLM\..\Run: [KEMailKb] "C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE"
O4 - HKLM\..\Run: [KPDrv4XP] "C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [CanonSolutionMenu] "C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" /logon
O4 - HKLM\..\Run: [CanonMyPrinter] "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [masqform.exe] "C:\Program Files\PureEdge\Viewer 6.5\masqform.exe" -RunOnce
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\Mom\lsass.exe
O4 - HKLM\..\Run: [5c27375a] "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\sxlfejfi.dll",b
O4 - HKLM\..\Run: [BM5f1404c6] Rundll32.exe "C:\WINDOWS\system32\saqdbdop.dll",s
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
O4 - HKCU\..\Run: [Weather Pulse] "C:\Program Files\Weather Pulse\weatherpulse.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter...oad/tgctlcm.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://sctcdm09.ext...om/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmar...martActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1218590944937
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.co...nstallAsst2.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.h...edsolutions.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://plugin.fileop...nt/FileOpen.CAB
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.incrediga...aploader_v6.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.co.../MathPlayer.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 10550 bytes
  • 0

Advertisements


#2
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello Anne Kuhns, sorry about the delay everyone here has been very busy.
If you could please post a new HijackThis log in your next reply.
  • 0

#3
Anne Kuhns

Anne Kuhns

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
I can only boot my computer in safe mode now, so I can't easily get on the internet at home. I know I'm dealing with something called virtumonde adware, and I've seen a few trojans listed when I run a webroot scan. I'll try to post another log tonight if I can get the computer up. When I boot up regularly, I don't even get a start bar sometimes. Also, I can't do any windows updates.

I know you are busy, thank you so much for your help. Whatever it is is also on my laptop at home, so it it making me crazy!

Anne
  • 0

#4
Anne Kuhns

Anne Kuhns

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Here is a new log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:49:36, on 8/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Weather Pulse\weatherpulse.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://militarybank...itary/login.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061121
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4871C9B7-E933-42FF-8195-6B35C04FFE18} - C:\WINDOWS\system32\nnnnOIcY.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: {ed14c170-5db6-8558-2c84-f8bf48d055de} - {ed550d84-fb8f-48c2-8558-6bd5071c41de} - C:\WINDOWS\system32\dgpinx.dll (file missing)
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] "C:\WINDOWS\stsystra.exe"
O4 - HKLM\..\Run: [DLA] "C:\WINDOWS\System32\DLA\DLACTRLW.EXE"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe"
O4 - HKLM\..\Run: [KEMailKb] "C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE"
O4 - HKLM\..\Run: [KPDrv4XP] "C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [CanonSolutionMenu] "C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" /logon
O4 - HKLM\..\Run: [CanonMyPrinter] "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [masqform.exe] "C:\Program Files\PureEdge\Viewer 6.5\masqform.exe" -RunOnce
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\Mom\lsass.exe
O4 - HKLM\..\Run: [5c27375a] rundll32.exe "C:\WINDOWS\system32\sxlfejfi.dll",b
O4 - HKLM\..\Run: [BM5f1404c6] Rundll32.exe "C:\WINDOWS\system32\kjveribk.dll",s
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
O4 - HKCU\..\Run: [Weather Pulse] "C:\Program Files\Weather Pulse\weatherpulse.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter...oad/tgctlcm.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://sctcdm09.ext...om/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmar...martActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1218590944937
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.co...nstallAsst2.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.h...edsolutions.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://plugin.fileop...nt/FileOpen.CAB
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.incrediga...aploader_v6.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.co.../MathPlayer.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9954 bytes
  • 0

#5
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello Anne Kuhns,
If you have any questions please feel free to ask. :)

STEP 1
Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum
STEP 2
Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingc...to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
~~~~~~~~~~
In your next reply please have these logs.
The SDFix log
The ComboFix log
And a fresh HijackThis log
  • 0

#6
Anne Kuhns

Anne Kuhns

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Ok, so I'm somewhat competant with computers, but I couldn't get the SDFix to run - it kept shutting down mid way through the install. I got the combofix to run and I thought I had gotten the recovery console on, but apparently not. Here are the ComboFix and Hijack This logs... I ran Spysweeper after I ran the fixes, and only got 3 small cookies. The only remaining problem I've found is that my clock is on miliary time...(irritating but not as bad as a browser hijacker!) Let me know how it looks!

Anne

ComboFix 08-08-21.02 - Mom 2008-08-22 17:36:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.375 [GMT -4:00]
Running from: C:\Documents and Settings\Mom\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Mom\Application Data\macromedia\Flash Player\#SharedObjects\F8XYVDK7\interclick.com
C:\Documents and Settings\Mom\Application Data\macromedia\Flash Player\#SharedObjects\F8XYVDK7\interclick.com\ud.sol
C:\Documents and Settings\Mom\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Mom\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
C:\Documents and Settings\Mom\Cookies\mom@aggregateknowledge[1].txt
C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
C:\Documents and Settings\Mom\Cookies\mom@insightexpressai[2].txt
C:\Documents and Settings\Mom\Cookies\mom@media6degrees[2].txt
C:\Documents and Settings\Mom\Cookies\mom@myspace[1].txt
C:\Documents and Settings\Mom\Cookies\mom@spamblockerutility[2].txt
C:\Documents and Settings\Mom\Cookies\mom@superstats[2].txt
C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
C:\Documents and Settings\Mom\Cookies\[email protected][1].txt
C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
C:\Documents and Settings\Mom\Local Settings\Temporary Internet Files\favicon.ico
C:\Documents and Settings\Mom\services.exe
C:\WINDOWS\BM5f1404c6.txt
C:\WINDOWS\BM5f1404c6.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ehxoduqm.ini
C:\WINDOWS\system32\ifjeflxs.ini
C:\WINDOWS\system32\jicxhbwx.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\oitbtuwh.ini
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rtyqawob.ini
C:\WINDOWS\system32\sxlfejfi.dll
C:\WINDOWS\system32\wvkcbz.dll
C:\WINDOWS\system32\xdabgoia.dll
C:\WINDOWS\system32\yrqkgdle.dll

.
((((((((((((((((((((((((( Files Created from 2008-07-22 to 2008-08-22 )))))))))))))))))))))))))))))))
.

2008-08-22 15:59 . 2008-08-22 16:38 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-22 15:48 . 2008-08-18 22:49 <DIR> d-------- C:\SDFix
2008-08-21 23:12 . 2008-08-21 23:12 <DIR> d-------- C:\Documents and Settings\Mom\Application Data\Uniblue
2008-08-21 22:42 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-21 22:13 . 2008-08-21 22:36 <DIR> d-------- C:\VundoFix Backups
2008-08-15 23:43 . 2008-08-15 23:43 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-15 23:19 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-15 23:17 . 2008-08-15 23:17 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-08-14 22:00 . 2008-08-14 22:00 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-08-14 22:00 . 2008-07-28 16:44 166,512 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-08-14 22:00 . 2008-01-04 20:34 23,920 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-08-14 22:00 . 2008-07-28 16:44 23,152 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-08-14 21:59 . 2008-08-14 21:59 <DIR> d-------- C:\Program Files\Webroot
2008-08-14 21:59 . 2008-08-14 21:59 <DIR> d-------- C:\Documents and Settings\Mom\Application Data\Webroot
2008-08-14 21:59 . 2008-08-14 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-08-14 21:59 . 2008-07-28 18:15 1,538,928 --a------ C:\WINDOWS\WRSetup.dll
2008-08-14 21:55 . 2008-08-14 23:19 164 --a------ C:\install.dat
2008-08-14 21:35 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-14 21:35 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-14 21:35 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-14 21:35 . 2008-08-14 21:52 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-14 21:35 . 2008-08-09 15:37 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-14 21:35 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-14 21:35 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-14 21:35 . 2008-08-15 23:20 5,368 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-11 23:11 . 2008-08-11 23:11 <DIR> d-------- C:\WINDOWS\system32\kBin02
2008-08-11 23:11 . 2008-08-11 23:11 <DIR> d-------- C:\temp\epr1
2008-08-11 23:11 . 2008-08-11 23:11 83,456 --a------ C:\ctfmon.exe
2008-08-11 23:11 . 2008-08-11 23:11 355 --a------ C:\870.bat
2008-08-11 23:11 . 2008-08-11 23:11 77 --a------ C:\Documents and Settings\Mom\4330.bat
2008-08-06 16:09 . 2008-08-06 16:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IM
2008-08-06 16:07 . 2008-08-06 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-07-28 16:44 . 2008-07-28 16:44 29,808 --a------ C:\WINDOWS\system32\drivers\ssfs0bbc.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-22 19:43 --------- d-----w C:\Program Files\Weather Pulse
2008-08-22 03:04 --------- d-----w C:\Program Files\Quicken
2008-08-22 02:46 --------- d-----w C:\Program Files\Java
2008-08-17 12:43 --------- d-----w C:\Program Files\McAfee
2008-08-17 12:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-17 00:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-08-17 00:26 --------- d-----w C:\Program Files\Coupons
2008-08-16 03:41 --------- d-----w C:\Documents and Settings\Mom\Application Data\U3
2008-08-15 21:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-08-12 21:50 --------- d-----w C:\Program Files\Yahoo!
2008-08-12 21:46 --------- d-----w C:\Program Files\Canon
2008-08-12 21:46 --------- d-----w C:\Documents and Settings\Mom\Application Data\Canon
2008-08-06 20:08 --------- d-----w C:\Program Files\IncrediMail
2008-07-14 00:07 --------- d-----w C:\Program Files\Hasbro Interactive
2008-07-10 21:08 --------- d-----w C:\Program Files\Common Files\supportsoft
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-25 21:34 --------- d-----w C:\Documents and Settings\Mom\Application Data\Viewpoint
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:23 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 14:57 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2007-10-27 19:38 74,056 ----a-w C:\Documents and Settings\Mom\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-28 22:57 395776]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-07-24 14:22 243072]
"Weather Pulse"="C:\Program Files\Weather Pulse\weatherpulse.exe" [2008-04-24 00:01 1859072]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-23 13:12 7630848]
"nwiz"="C:\WINDOWS\system32\nwiz.exe" [2006-08-23 13:12 1617920]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-23 13:12 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 04:12 94208]
"SigmatelSysTrayApp"="C:\WINDOWS\stsystra.exe" [2006-08-15 03:38 282624]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 17:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 17:50 81920]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-20 00:10 196608]
"KEMailKb"="C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE" [2005-08-09 04:27 401408]
"KPDrv4XP"="C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE" [2005-02-21 07:15 40960]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 02:33 582992]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-04-03 21:00 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 21:50 1603152]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-27 18:28 185896]
"masqform.exe"="C:\Program Files\PureEdge\Viewer 6.5\masqform.exe" [2005-07-04 09:50 643072]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-07-28 18:15 5418864]

C:\Documents and Settings\Mom\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-11-26 02:35:34 157008]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-10-02 15:08:08 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 DRVMCDB;DRVMCDB;C:\WINDOWS\system32\Drivers\DRVMCDB.SYS [2005-09-12 04:30]
R0 ssfs0bbc;ssfs0bbc;C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys [2008-07-28 16:44]
R0 SSHRMD;Sshrmd;C:\WINDOWS\system32\Drivers\SSHRMD.SYS [2008-07-28 16:44]
R0 SSIDRV;Ssidrv;C:\WINDOWS\system32\Drivers\SSIDRV.SYS [2008-07-28 16:44]
R1 DLACDBHM;DLACDBHM;C:\WINDOWS\system32\Drivers\DLACDBHM.SYS [2005-08-25 13:16]
R1 DLARTL_N;DLARTL_N;C:\WINDOWS\system32\Drivers\DLARTL_N.SYS [2005-08-25 13:16]
R2 Apple Mobile Device;Apple Mobile Device;C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-09-06 13:28]
R2 DLABOIOM;DLABOIOM;C:\WINDOWS\system32\DLA\DLABOIOM.SYS [2005-09-08 06:20]
R2 DLADResN;DLADResN;C:\WINDOWS\system32\DLA\DLADResN.SYS [2005-09-08 06:20]
R2 DLAIFS_M;DLAIFS_M;C:\WINDOWS\system32\DLA\DLAIFS_M.SYS [2005-09-08 06:20]
R2 DLAOPIOM;DLAOPIOM;C:\WINDOWS\system32\DLA\DLAOPIOM.SYS [2005-09-08 06:20]
R2 DLAPoolM;DLAPoolM;C:\WINDOWS\system32\DLA\DLAPoolM.SYS [2005-09-08 06:20]
R2 DLAUDF_M;DLAUDF_M;C:\WINDOWS\system32\DLA\DLAUDF_M.SYS [2005-09-08 06:20]
R2 DLAUDFAM;DLAUDFAM;C:\WINDOWS\system32\DLA\DLAUDFAM.SYS [2005-09-08 06:20]
R2 DRVNDDM;DRVNDDM;C:\WINDOWS\system32\Drivers\DRVNDDM.SYS [2005-08-12 06:20]
R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 12:20]
R2 MSK80Service;McAfee SpamKiller Service;C:\Program Files\McAfee\MSK\MskSrver.exe [2007-08-24 05:00]
R2 NVSvc;NVIDIA Display Driver Service;C:\WINDOWS\system32\nvsvc32.exe [2006-08-23 13:12]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver;C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2006-08-14 07:29]
R3 SSKBFD;Webroot Spy Sweeper Keylogger Shield Keyboard Filter;C:\WINDOWS\system32\Drivers\sskbfd.sys [2008-01-04 20:34]
R3 STHDA;SigmaTel High Definition Audio CODEC;C:\WINDOWS\system32\drivers\sthda.sys [2006-08-15 03:38]
S2 Fax;Fax;C:\WINDOWS\system32\fxssvc.exe [2004-08-04 06:00]
S3 DSproct;DSproct;C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys [2006-01-10 12:07]
S3 E100B;Intel® PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 13:12]
S3 SupportSoft RemoteAssist;SupportSoft RemoteAssist;C:\Program Files\Common Files\supportsoft\bin\ssrc.exe [2007-12-11 04:39]
S3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys []
S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2004-08-04 00:07]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57ba671a-9c61-11db-924a-00038a000015}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-08-21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

2008-08-15 C:\WINDOWS\Tasks\McDefragTask.job
- C:\WINDOWS\system32\defrag.exe [2004-08-04 06:00]

2008-07-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2008-08-15 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-28 18:15]

2008-08-15 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-28 18:15]

2008-08-15 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\","D:\","F:\","G:\","H:\","I:\" []
.
- - - - ORPHANS REMOVED - - - -

BHO-{4871C9B7-E933-42FF-8195-6B35C04FFE18} - C:\WINDOWS\system32\nnnnOIcY.dll
BHO-{ed550d84-fb8f-48c2-8558-6bd5071c41de} - C:\WINDOWS\system32\dgpinx.dll
HKCU-Run-Magentic - C:\PROGRA~1\Magentic\bin\Magentic.exe
HKCU-Run-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKLM-Run-5c27375a - C:\WINDOWS\system32\sxlfejfi.dll
ShellExecuteHooks-{57DF73C0-833C-48B7-9146-1E18930D57FF} - (no file)


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\r94qyam7.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-22 19:37:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-08-22 19:59:50 - machine was rebooted [Mom]
ComboFix-quarantined-files.txt 2008-08-22 23:58:16

Pre-Run: 55,078,883,328 bytes free
Post-Run: 55,213,772,800 bytes free

261 --- E O F --- 2008-08-22 03:18:44



HIJACK LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:35:39, on 8/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://militarybank...itary/login.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061121
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] "C:\WINDOWS\stsystra.exe"
O4 - HKLM\..\Run: [DLA] "C:\WINDOWS\System32\DLA\DLACTRLW.EXE"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe"
O4 - HKLM\..\Run: [KEMailKb] "C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE"
O4 - HKLM\..\Run: [KPDrv4XP] "C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [CanonSolutionMenu] "C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" /logon
O4 - HKLM\..\Run: [CanonMyPrinter] "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [masqform.exe] "C:\Program Files\PureEdge\Viewer 6.5\masqform.exe" -RunOnce
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
O4 - HKCU\..\Run: [Weather Pulse] "C:\Program Files\Weather Pulse\weatherpulse.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter...oad/tgctlcm.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://sctcdm09.ext...om/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmar...martActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1218590944937
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.co...nstallAsst2.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.h...edsolutions.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://plugin.fileop...nt/FileOpen.CAB
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.co.../MathPlayer.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
  • 0

#7
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello Anne Kuhns,

but I couldn't get the SDFix to run - it kept shutting down mid way through the install.

Ok, thats no problem. We will try again at the end of this post.

The only remaining problem I've found is that my clock is on miliary time

ComboFix should have fixed that when it was done, but since it did not we will take care of that in a bit. :)

Let me know how it looks!

Looking better, still a few more things that need to be took care of. :)


STEP 1
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\ctfmon.exe
C:\870.bat
C:\Documents and Settings\Mom\4330.bat

Folder::
C:\WINDOWS\system32\kBin02
C:\Documents and Settings\Mom\Application Data\Viewpoint
C:\temp\epr1
C:\Program Files\Coupons

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57ba671a-9c61-11db-924a-00038a000015}]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
STEP 2
Please remove SDFix and re-download it. Once you have re-downloaded it please try running it again and see if it works this time.
~~~~~~~~~~~
In your next reply please have these logs.
The ComboFix log
A fresh HijackThis log
And the SDFix log (if you can get it to run)
  • 0

#8
Anne Kuhns

Anne Kuhns

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
I've got all 3 logs, and got everything to scan. It looks good, however my clock is still on military time. See what you think:

ComboFix 08-08-23.01 - Mom 2008-08-23 23:26:30.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.408 [GMT -4:00]
Running from: C:\Documents and Settings\Mom\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mom\Desktop\CFScript.txt.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\870.bat
C:\ctfmon.exe
C:\Documents and Settings\Mom\4330.bat
.

((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.

2008-08-23 16:21 . 2008-08-23 16:21 <DIR> d-------- C:\WINDOWS\LastGood
2008-08-22 21:55 . 2008-08-22 21:55 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-08-22 21:55 . 2008-08-22 21:55 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-08-22 21:55 . 2008-08-22 21:55 10,563 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-08-22 21:55 . 2008-08-22 21:55 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-08-22 21:38 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-22 21:18 . 2008-08-22 21:18 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-22 21:18 . 2008-08-22 21:18 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-22 21:18 . 2008-08-22 21:18 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-22 21:18 . 2008-08-22 21:18 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-22 21:14 . 2008-08-22 21:14 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-22 21:00 . 2008-08-22 21:00 <DIR> d-------- C:\WINDOWS\EHome
2008-08-22 16:35 . 2008-04-13 20:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-08-22 16:34 . 2008-04-13 20:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-22 15:48 . 2008-08-18 22:49 <DIR> d-------- C:\SDFix
2008-08-21 23:12 . 2008-08-21 23:12 <DIR> d-------- C:\Documents and Settings\Mom\Application Data\Uniblue
2008-08-21 22:42 . 2008-05-01 10:33 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-21 22:41 . 2008-04-11 15:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-21 22:13 . 2008-08-22 22:54 <DIR> d-------- C:\VundoFix Backups
2008-08-15 23:43 . 2008-08-15 23:43 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-15 23:19 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-15 23:17 . 2008-08-15 23:17 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-08-14 22:00 . 2008-08-14 22:00 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-08-14 22:00 . 2008-07-28 16:44 166,512 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-08-14 22:00 . 2008-01-04 20:34 23,920 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-08-14 22:00 . 2008-07-28 16:44 23,152 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-08-14 21:59 . 2008-08-14 21:59 <DIR> d-------- C:\Program Files\Webroot
2008-08-14 21:59 . 2008-08-14 21:59 <DIR> d-------- C:\Documents and Settings\Mom\Application Data\Webroot
2008-08-14 21:59 . 2008-08-14 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-08-14 21:59 . 2008-07-28 18:15 1,538,928 --a------ C:\WINDOWS\WRSetup.dll
2008-08-14 21:55 . 2008-08-14 23:19 164 --a------ C:\install.dat
2008-08-14 21:35 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-14 21:35 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-14 21:35 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-14 21:35 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-14 21:35 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-14 21:35 . 2008-08-15 23:20 5,368 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-06 16:09 . 2008-08-06 16:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IM
2008-08-06 16:07 . 2008-08-06 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-07-28 16:44 . 2008-07-28 16:44 29,808 --a------ C:\WINDOWS\system32\drivers\ssfs0bbc.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-23 11:14 --------- d-----w C:\Program Files\Weather Pulse
2008-08-23 03:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\PureEdge
2008-08-23 02:06 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-08-23 02:06 23,888 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-08-23 02:06 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-08-23 02:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-23 01:57 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-23 01:55 --------- d-----w C:\Program Files\Symantec
2008-08-23 01:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-23 01:41 --------- d-----w C:\Program Files\McAfee
2008-08-23 01:40 --------- d-----w C:\Program Files\Google
2008-08-23 01:38 --------- d-----w C:\Program Files\Java
2008-08-22 03:04 --------- d-----w C:\Program Files\Quicken
2008-08-17 00:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-08-16 03:41 --------- d-----w C:\Documents and Settings\Mom\Application Data\U3
2008-08-15 21:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-08-12 21:50 --------- d-----w C:\Program Files\Yahoo!
2008-08-12 21:46 --------- d-----w C:\Program Files\Canon
2008-08-12 21:46 --------- d-----w C:\Documents and Settings\Mom\Application Data\Canon
2008-08-06 20:08 --------- d-----w C:\Program Files\IncrediMail
2008-07-14 00:07 --------- d-----w C:\Program Files\Hasbro Interactive
2008-07-10 21:08 --------- d-----w C:\Program Files\Common Files\supportsoft
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:26 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 14:57 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2007-10-27 19:38 74,056 ----a-w C:\Documents and Settings\Mom\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-28 22:57 395776]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 20:12 1695232]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-07-24 14:22 243072]
"Weather Pulse"="C:\Program Files\Weather Pulse\weatherpulse.exe" [2008-04-24 00:01 1859072]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-23 13:12 7630848]
"nwiz"="C:\WINDOWS\system32\nwiz.exe" [2006-08-23 13:12 1617920]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-23 13:12 86016]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 04:12 94208]
"SigmatelSysTrayApp"="C:\WINDOWS\stsystra.exe" [2006-08-15 03:38 282624]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 17:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 17:50 81920]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-20 00:10 196608]
"KEMailKb"="C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE" [2005-08-09 04:27 401408]
"KPDrv4XP"="C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE" [2005-02-21 07:15 40960]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-04-03 21:00 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 21:50 1603152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-27 18:28 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-04-30 16:44 115560]

C:\Documents and Settings\Mom\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-11-26 02:35:34 157008]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-10-02 15:08:08 57344]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=

R0 ssfs0bbc;ssfs0bbc;C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys [2008-07-28 16:44]
R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 12:20]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-08-22 22:06]

*Newly Created Service* - CATCHME
*Newly Created Service* - COH_MON
.
Contents of the 'Scheduled Tasks' folder

2008-08-21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

2008-08-23 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-28 18:15]

2008-08-23 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-28 18:15]

2008-08-23 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\","D:\","F:\","G:\","H:\","I:\" []
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-23 23:46:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-23 23:53:39
ComboFix-quarantined-files.txt 2008-08-24 03:53:17
ComboFix2.txt 2008-08-24 03:16:35
ComboFix3.txt 2008-08-23 00:00:36

Pre-Run: 55,360,876,544 bytes free
Post-Run: 55,343,861,760 bytes free

190 --- E O F --- 2008-08-23 01:25:02

SDFix: Version 1.218
Run by Mom on Sun 08/24/2008 at 00:07

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 00:14:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Disabled:LEXPPS.EXE"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"="C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe:*:Enabled:SMC Service"
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"="C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE:*:Enabled:SNAC Service"
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"="C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe:*:Enabled:Symantec Email"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :



Files with Hidden Attributes :

Wed 21 Nov 2007 31 A..H. --- "C:\WINDOWS\uccspecc.sys"
Wed 30 Apr 2008 407 A..H. --- "C:\Program Files\Common Files\Symantec Shared\COH\COH32LU.reg"
Wed 30 Apr 2008 400 A..H. --- "C:\Program Files\Common Files\Symantec Shared\COH\COHDLU.reg"
Thu 7 Dec 2006 3,096,576 A..H. --- "C:\Documents and Settings\Mom\Application Data\U3\temp\Launchpad Removal.exe"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS02C5E752-9C0C-428D-8371-0357445CCAEE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS04E8C580-7B8F-426A-8E02-EAFB58928B79.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS05AB17F7-C20A-4B1D-8F6B-B543A97DD2BC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS08FD501D-D8A1-4FC7-8F39-44CAD83ADDAC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS08333F73-3306-4625-822E-1E28FDD13417.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0CA2C93C-D8AB-4511-AB71-9050643F1BD6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0E4D13E7-0989-4438-B415-964F73A7CD8A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS100F82C8-286A-4D34-827D-F41AC78F61F3.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS12C09D5B-EA47-4DD6-86EC-240F7A10F771.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS14FEA605-5902-4644-B31A-F00C11DA2B2B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS15BDE9FF-6D79-41B0-9B92-7CFAE04FEF7F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS16258776-B0F0-4590-ADD2-6BBFF8D04E29.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS19E27F8D-757D-4A4D-8D0A-9895940282A5.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS190CA79C-08CD-4FB2-8CF6-DA9E97FEFDAA.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A396195-EA7F-4BE4-BE4D-B48B1446E4D2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1D75994D-E73B-49E8-A3BF-889736791499.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS21172202-1226-4477-85F9-EA59BFAFF9A1.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS25CB5C01-338B-4265-938F-D0909B587101.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS256789AF-033C-4716-B1EE-F1E05CA1D139.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS25478CA7-AF0B-459E-AE6F-A0E860B6FA2C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2BE2B22C-F28C-4475-A1D6-69580B4214F3.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2BD0F11D-713C-4D25-8962-6F18B3C23D61.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2C51CFD2-C09C-4B66-A8E2-D20DEE4FB2B3.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2FC3AC41-9E3D-4083-BD60-8D2DB0CFA441.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS31DAF372-6D74-46B1-AC43-74D4E7722D2B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS372AF2E1-C5CD-4B10-BE56-DBA25DBF6DF1.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS42342076-76A3-428F-886B-177690B113CE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS481F505F-3B28-44AE-8DB2-604656F1260C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4900AE5F-4288-4EA2-8DA2-D7C9F078795F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4EF626BA-D789-455A-8C7E-C5C6C74A9F51.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS50A024DA-8AAE-4746-9C8C-E4C636FFBC6F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS51B4ADDD-F209-4365-9898-613C42052F94.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5468B136-F2D6-4854-837E-E55E3E7773D9.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS540D9E25-A311-47B1-9938-A714ED6B4545.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5A3EE7C7-C887-48D1-BB86-AB107A2883F6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5BAFD38D-F239-4978-B330-539BE446C418.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5D6F514F-9D57-4016-8320-D096AE06DF87.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5F376FDF-519A-48BF-AE37-769C5A1B8694.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS60EB1F9A-F22A-4C85-833D-F99104853B95.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS65D39DE8-759D-48F0-A419-95B54569ACF4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6E425A27-7CA9-4B81-A45D-3A368B1BA99F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6F57FA4D-36E3-4700-A934-A940D7471454.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS744F00C2-C049-4AB4-AA24-F9AC78EB7080.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS74D1071F-240F-4970-B184-BFB88BF53770.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS76387E90-A572-4D81-A670-854593D50E1F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS768E1D4E-1E91-4FB0-B8ED-363373127178.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7786CACF-0465-4883-9D91-99B4D736C721.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS79D650DE-EFAA-44C3-875A-124BFC99970C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7E44214A-CE23-4580-9AF9-81D441EE0582.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS803DDA59-DCDD-4C35-B623-0512AD5B362A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS838B2265-5ED2-4244-A01D-0E956B99FC0A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS877EB464-F318-47F6-92F0-6B23D0AECFE6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8B4DEDEE-E22C-458C-9BF2-B5A7E6E9CC88.tmp"
Sun 24 Aug 2008 65,536 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8DE83512-518D-465D-9D2D-7062C52879D4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8D145840-6BC0-44C6-BCD7-BFCCEC124B9C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8E16BAEC-45BC-4299-A309-4AB95F518A43.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8F89AE72-CE13-462E-BC28-22F2A577CDD4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS90A44CAE-5422-47FF-8EF6-A40120D76483.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9472FC41-40B8-4801-9DB2-4784E6DE45DD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS962F5CFF-E2DF-413C-BCF3-DAFE5F20CEA0.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS977B4CC2-8D95-4D00-B973-A01D31B9851E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9993C513-F75B-46B9-A616-358C899C5724.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS99D7156D-B95A-46FB-A672-1DBCEFB69E1C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9C3BA3DC-F7EF-4F3C-99FC-98778AEBBD74.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9ED22E09-1162-451D-98B4-9B4FD0ACFD51.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA2C56682-F9B1-4055-BBF9-1CB50DA26CD5.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA3EA462D-3312-480F-AA91-ABAE47126315.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA50F83A2-056C-4116-A897-71ACB260778B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAAFE91DA-EDD6-47FF-ABCE-A72FA1BC32F4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAF55C295-371F-4778-95E2-1762CDA5E271.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB00F60E0-32F7-4C37-96FE-E94B022FC4F2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB07559B6-CF45-4FD4-A028-8B7353E26471.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB22E0EC3-FDBF-4A55-BAF9-524F22CD8F18.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB60B2718-8875-44A4-832E-D98466A20564.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB858CF86-2A27-4A90-85E9-67CA15EB5306.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBA6EA8E7-8BFA-41A4-B969-71E25802D4B9.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBB16B8A4-6BBD-48C9-A1D2-884BE404A4C2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBB8C03A4-D5AE-4E2F-8A95-311DE1B8A2BB.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBC8D9793-174A-4326-9AAD-54F3DCF0CABC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBEDD25EF-E1E2-4791-8AAA-EC9A6CFF342D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBEBA7285-7CD6-409C-8346-CF3853DE606E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBFBFCDE7-5EF2-47DD-A003-C139A5C5509D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC37B4B99-48FB-44DC-B4D9-2DCC24D20965.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC7D4006F-4269-48C0-80D9-67D95A254F50.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC916CBD1-824B-44AE-88E8-04E3150D23B4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD9788F33-A5A4-4BA2-A08D-FC2A43162091.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD9D3067C-0B69-429C-A87B-17C1BC80A599.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0BB641F-3E0C-4B9F-991D-914B6EA9309D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0AFAB6E-2A54-449E-90DE-7A503E7134C5.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE1C8C1BA-66DA-4BE5-B00C-028C9FC04060.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE3E6EAEA-E0E2-4019-9D20-71C7D30B3A95.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE5CE9DE9-139E-418D-84CB-28C6D5EC0B4D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE6605B12-C817-49FE-A640-12CFA308AD51.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE908FB01-4063-47E1-8678-7D342438185E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE9907E3D-DC7C-4A5D-92BC-C16B6102A310.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEEF96F1A-F38D-4ED8-82FC-45287E64184E.tmp"
Sun 24 Aug 2008 65,536 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF2EF2A59-48F0-4781-A0D5-45CBA203A34C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF2E11E51-AB66-4572-ABDC-58554BC63FC9.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF5097887-7109-4160-9EEE-501A4962ADE0.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF5C44A2E-2BA6-4EFD-AB65-A0568272F02A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF5F20642-C94F-435E-9A6B-268D72637969.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF8BDC3D3-2CB1-41BC-853C-3431E0762E0F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFCA6F7AE-359B-436F-A05D-E0E1B6EABE78.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFD17CCBA-F2F8-4D7B-9233-F92583C2A395.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0040202A-AE70-4209-80AD-D6539B5197EB.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS025FA4DF-81EB-4F6C-BCE1-FAAF9581C7DD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0856E15A-D14C-4289-AAC5-9FFAB6931B88.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0AE28794-FA85-4844-A3CC-E60F5A8F9833.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1291A7C2-835D-42ED-8B8E-F174D5E18D6F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS164F968C-99A3-4ECA-819F-C6CD2DAD062A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1E2E9BD4-5A39-46F4-AFA6-929F781F017D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1F527AA3-7763-48A4-9FF0-388A3DA6816F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS279E436C-F476-485D-95C6-D11C4E59409B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS295BDE77-A421-43FA-92FD-3CA67AC422FC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2B5C83CD-9038-4A27-BF93-A5B426CF2A93.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2CE49159-D144-42AF-86E9-DAB991035D6E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS341D3601-34A7-4F9F-A4BF-21AA35317398.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3ACDF065-5C83-4B01-99B6-022B8D7FF7F2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3A24B62E-06F4-4A41-B667-2661DCEA3B65.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3CC3126C-A3ED-4125-A1F2-7619547FDA29.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS407137FB-27C2-47A8-9E04-84B4545FC51F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS42F01F39-DF9C-4F6F-B760-CCE95289AF21.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS445C55EE-5898-4665-BEA2-C3A130714052.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS458D61C5-71CF-4590-8842-F4D3B868F8FF.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS460F3485-F9B7-494D-98B6-84EA5249D1E3.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS49650641-0198-4977-90CD-28950D5020C6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4983E58C-590D-4473-A41D-19B72EC497D8.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS49F07772-DDE5-4130-B438-1465D1AFB12D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4F9691FE-762C-46EE-97AF-33379B5B1750.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4FC1F48D-C72F-46E5-A881-87E8C9FE65AD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5270A8F1-246F-4882-BBB6-E27004B5EC8C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5391D480-17DE-41A0-8D54-8EA8EBF7B2A7.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5AEB31CF-4B55-438E-A34A-D204BBA5DF53.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5B6FB05B-27BF-44FF-B8C9-D28E6A7C1EB8.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS60A3046F-1475-4CD3-A491-6B4D53F49605.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS614FDC05-38CD-4F5D-A680-EB90B20B3C2B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS631F0950-FACD-4A82-9E01-88226AABA005.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS695CC580-4035-4389-AC5F-8566F73BB658.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6B5902A4-50EF-4C04-A70B-0801650C4804.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6EE8330A-0CFB-495D-B977-D8A52F9A6261.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6F1F1A98-FB3A-4AA4-9A58-B2D1DF997D7D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS70A18CA1-9415-40A1-B269-570C1ABEEA71.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS71AC14E3-2630-42C7-B8FF-A1E1CBDAD53D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS75B556F1-E813-4E05-B3E4-73A2D6FCF626.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS77445269-6288-49EE-968D-660BF82C3E41.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7C7B0379-A7BC-4FDB-B7FA-7918E6A2DED4.tmp"
Sun 24 Aug 2008 65,536 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7DA6B8E4-35E3-4DAF-BB40-DAC005ECD53A.tmp"
Sun 24 Aug 2008 65,536 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7E9E78C8-9505-4D90-9244-705BB7E43942.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7E63C032-0F52-4895-A401-6D51A807A0FD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8594FD55-9A9E-4312-825D-463CDD33491A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS867FA5CD-2B11-4231-B4A8-BFEFD3500E99.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8F236680-CF26-41DE-B0BE-7EAE923F55FB.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS903A8A1D-6BBC-4586-B1AF-6C59EF2C29CD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS92E8ACCE-B2F0-4F00-B056-5A2B7B37530D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS93869B51-395A-4FB1-9BED-CABB3837384C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9466C60F-1789-4538-A341-89E5FEAE88CC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9687D1E1-A994-4950-B7BF-E9B90DC73524.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS96ECC867-87CC-48FF-B7BE-113F04268BC4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS96C9528F-D4DB-48DF-BEA2-4F99288F8099.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS99A3F71C-0DDF-4A24-BEB9-A3907616F08C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9A356721-1A63-47A9-9850-8B95C55F8887.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9FC0FC2C-8806-4BF4-BD60-6F56D0DE180B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA17C3657-84AB-414F-935A-ABD1431FF06F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA7190043-FD6F-42AD-A6BD-25F21B249913.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSABA638EE-039C-4BF1-A1BA-24F6A5DE0CEE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAC340A83-8926-4C6A-A89C-86A05DC39F50.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAC235005-1436-4403-BC7F-A15E07001171.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSADEDCFBE-9410-4F49-978E-99F2B33D502D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAE73ABFF-2363-45D9-AE37-7E2461FB3E5B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB150C0FD-5589-49E8-B98E-0661968373A2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB3082D60-1061-472B-8C4A-C1012B43CD12.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB4D00148-FAA2-4AD5-BCA4-9A6AE49529CC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB624CAB3-5E18-41D7-8D20-8C773FDEB595.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB6067CFF-F2F4-4EA9-870C-75EE249695E2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB7EE31CA-75F7-4931-9605-BE82C64CFAFE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB97772F2-972F-4277-AE4B-FF9FF08A2DA8.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBCA70405-5D9D-4925-9FF9-DD669BA6872D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBEE3B768-04AD-4E3F-B264-230EBD4EFEA7.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC431FBAD-EAEC-4A9E-9956-0587A3662627.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC4CA1431-D8F3-4BEE-8B6A-18655DA98D0E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC54555CB-F10D-40FE-A3A8-BDEE23137AEE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC545DC6B-33C1-4780-8229-2D1AAEABDD34.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC8FC6AB1-1084-4042-8D8B-5284C387769A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCAD2D9F3-FF41-46DB-84F0-2DB80905B0E0.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCD03F745-EFD1-4FDC-8D54-5A40E42C862B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCEE43E75-B2BF-4984-9668-7126BA0D8BA4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCE984510-9FB9-44E5-A091-1E141D33CA1D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD095F55E-D67F-4340-B948-11957C93BD12.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD148D658-1B8A-4E60-AD01-CF83A10A9C91.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD6FA0437-5BBE-4A5E-9151-19AF7AF365A6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD87B7DBA-2DAC-48E4-A363-AF7F49F0B1ED.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDB79B199-062F-4402-BC3C-2756911B9E49.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDDD671BE-3DBC-427F-B6B6-850E17EAD657.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\Netw
  • 0

#9
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello Anne Kuhns,
Your SDFix log got cutoff, please repost it in your next reply. The log should be in the C:\SDFix folder, just open that folder and open this file Report.txt and copy/paste the text inside that file in your next reply.
  • 0

#10
Anne Kuhns

Anne Kuhns

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Sorry about that...

SDFix: Version 1.218
Run by Mom on Sun 08/24/2008 at 00:07

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 00:14:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Disabled:LEXPPS.EXE"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"="C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe:*:Enabled:SMC Service"
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"="C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE:*:Enabled:SNAC Service"
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"="C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe:*:Enabled:Symantec Email"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :



Files with Hidden Attributes :

Wed 21 Nov 2007 31 A..H. --- "C:\WINDOWS\uccspecc.sys"
Wed 30 Apr 2008 407 A..H. --- "C:\Program Files\Common Files\Symantec Shared\COH\COH32LU.reg"
Wed 30 Apr 2008 400 A..H. --- "C:\Program Files\Common Files\Symantec Shared\COH\COHDLU.reg"
Thu 7 Dec 2006 3,096,576 A..H. --- "C:\Documents and Settings\Mom\Application Data\U3\temp\Launchpad Removal.exe"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS02C5E752-9C0C-428D-8371-0357445CCAEE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS04E8C580-7B8F-426A-8E02-EAFB58928B79.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS05AB17F7-C20A-4B1D-8F6B-B543A97DD2BC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS08FD501D-D8A1-4FC7-8F39-44CAD83ADDAC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS08333F73-3306-4625-822E-1E28FDD13417.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0CA2C93C-D8AB-4511-AB71-9050643F1BD6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0E4D13E7-0989-4438-B415-964F73A7CD8A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS100F82C8-286A-4D34-827D-F41AC78F61F3.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS12C09D5B-EA47-4DD6-86EC-240F7A10F771.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS14FEA605-5902-4644-B31A-F00C11DA2B2B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS15BDE9FF-6D79-41B0-9B92-7CFAE04FEF7F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS16258776-B0F0-4590-ADD2-6BBFF8D04E29.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS19E27F8D-757D-4A4D-8D0A-9895940282A5.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS190CA79C-08CD-4FB2-8CF6-DA9E97FEFDAA.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A396195-EA7F-4BE4-BE4D-B48B1446E4D2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1D75994D-E73B-49E8-A3BF-889736791499.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS21172202-1226-4477-85F9-EA59BFAFF9A1.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS25CB5C01-338B-4265-938F-D0909B587101.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS256789AF-033C-4716-B1EE-F1E05CA1D139.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS25478CA7-AF0B-459E-AE6F-A0E860B6FA2C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2BE2B22C-F28C-4475-A1D6-69580B4214F3.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2BD0F11D-713C-4D25-8962-6F18B3C23D61.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2C51CFD2-C09C-4B66-A8E2-D20DEE4FB2B3.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2FC3AC41-9E3D-4083-BD60-8D2DB0CFA441.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS31DAF372-6D74-46B1-AC43-74D4E7722D2B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS372AF2E1-C5CD-4B10-BE56-DBA25DBF6DF1.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS42342076-76A3-428F-886B-177690B113CE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS481F505F-3B28-44AE-8DB2-604656F1260C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4900AE5F-4288-4EA2-8DA2-D7C9F078795F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4EF626BA-D789-455A-8C7E-C5C6C74A9F51.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS50A024DA-8AAE-4746-9C8C-E4C636FFBC6F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS51B4ADDD-F209-4365-9898-613C42052F94.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5468B136-F2D6-4854-837E-E55E3E7773D9.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS540D9E25-A311-47B1-9938-A714ED6B4545.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5A3EE7C7-C887-48D1-BB86-AB107A2883F6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5BAFD38D-F239-4978-B330-539BE446C418.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5D6F514F-9D57-4016-8320-D096AE06DF87.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5F376FDF-519A-48BF-AE37-769C5A1B8694.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS60EB1F9A-F22A-4C85-833D-F99104853B95.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS65D39DE8-759D-48F0-A419-95B54569ACF4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6E425A27-7CA9-4B81-A45D-3A368B1BA99F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6F57FA4D-36E3-4700-A934-A940D7471454.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS744F00C2-C049-4AB4-AA24-F9AC78EB7080.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS74D1071F-240F-4970-B184-BFB88BF53770.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS76387E90-A572-4D81-A670-854593D50E1F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS768E1D4E-1E91-4FB0-B8ED-363373127178.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7786CACF-0465-4883-9D91-99B4D736C721.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS79D650DE-EFAA-44C3-875A-124BFC99970C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7E44214A-CE23-4580-9AF9-81D441EE0582.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS803DDA59-DCDD-4C35-B623-0512AD5B362A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS838B2265-5ED2-4244-A01D-0E956B99FC0A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS877EB464-F318-47F6-92F0-6B23D0AECFE6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8B4DEDEE-E22C-458C-9BF2-B5A7E6E9CC88.tmp"
Sun 24 Aug 2008 65,536 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8DE83512-518D-465D-9D2D-7062C52879D4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8D145840-6BC0-44C6-BCD7-BFCCEC124B9C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8E16BAEC-45BC-4299-A309-4AB95F518A43.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8F89AE72-CE13-462E-BC28-22F2A577CDD4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS90A44CAE-5422-47FF-8EF6-A40120D76483.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9472FC41-40B8-4801-9DB2-4784E6DE45DD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS962F5CFF-E2DF-413C-BCF3-DAFE5F20CEA0.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS977B4CC2-8D95-4D00-B973-A01D31B9851E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9993C513-F75B-46B9-A616-358C899C5724.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS99D7156D-B95A-46FB-A672-1DBCEFB69E1C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9C3BA3DC-F7EF-4F3C-99FC-98778AEBBD74.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9ED22E09-1162-451D-98B4-9B4FD0ACFD51.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA2C56682-F9B1-4055-BBF9-1CB50DA26CD5.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA3EA462D-3312-480F-AA91-ABAE47126315.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA50F83A2-056C-4116-A897-71ACB260778B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAAFE91DA-EDD6-47FF-ABCE-A72FA1BC32F4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAF55C295-371F-4778-95E2-1762CDA5E271.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB00F60E0-32F7-4C37-96FE-E94B022FC4F2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB07559B6-CF45-4FD4-A028-8B7353E26471.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB22E0EC3-FDBF-4A55-BAF9-524F22CD8F18.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB60B2718-8875-44A4-832E-D98466A20564.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB858CF86-2A27-4A90-85E9-67CA15EB5306.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBA6EA8E7-8BFA-41A4-B969-71E25802D4B9.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBB16B8A4-6BBD-48C9-A1D2-884BE404A4C2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBB8C03A4-D5AE-4E2F-8A95-311DE1B8A2BB.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBC8D9793-174A-4326-9AAD-54F3DCF0CABC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBEDD25EF-E1E2-4791-8AAA-EC9A6CFF342D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBEBA7285-7CD6-409C-8346-CF3853DE606E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBFBFCDE7-5EF2-47DD-A003-C139A5C5509D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC37B4B99-48FB-44DC-B4D9-2DCC24D20965.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC7D4006F-4269-48C0-80D9-67D95A254F50.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC916CBD1-824B-44AE-88E8-04E3150D23B4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD9788F33-A5A4-4BA2-A08D-FC2A43162091.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD9D3067C-0B69-429C-A87B-17C1BC80A599.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0BB641F-3E0C-4B9F-991D-914B6EA9309D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0AFAB6E-2A54-449E-90DE-7A503E7134C5.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE1C8C1BA-66DA-4BE5-B00C-028C9FC04060.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE3E6EAEA-E0E2-4019-9D20-71C7D30B3A95.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE5CE9DE9-139E-418D-84CB-28C6D5EC0B4D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE6605B12-C817-49FE-A640-12CFA308AD51.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE908FB01-4063-47E1-8678-7D342438185E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE9907E3D-DC7C-4A5D-92BC-C16B6102A310.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEEF96F1A-F38D-4ED8-82FC-45287E64184E.tmp"
Sun 24 Aug 2008 65,536 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF2EF2A59-48F0-4781-A0D5-45CBA203A34C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF2E11E51-AB66-4572-ABDC-58554BC63FC9.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF5097887-7109-4160-9EEE-501A4962ADE0.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF5C44A2E-2BA6-4EFD-AB65-A0568272F02A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF5F20642-C94F-435E-9A6B-268D72637969.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF8BDC3D3-2CB1-41BC-853C-3431E0762E0F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFCA6F7AE-359B-436F-A05D-E0E1B6EABE78.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFD17CCBA-F2F8-4D7B-9233-F92583C2A395.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0040202A-AE70-4209-80AD-D6539B5197EB.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS025FA4DF-81EB-4F6C-BCE1-FAAF9581C7DD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0856E15A-D14C-4289-AAC5-9FFAB6931B88.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0AE28794-FA85-4844-A3CC-E60F5A8F9833.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1291A7C2-835D-42ED-8B8E-F174D5E18D6F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS164F968C-99A3-4ECA-819F-C6CD2DAD062A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1E2E9BD4-5A39-46F4-AFA6-929F781F017D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1F527AA3-7763-48A4-9FF0-388A3DA6816F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS279E436C-F476-485D-95C6-D11C4E59409B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS295BDE77-A421-43FA-92FD-3CA67AC422FC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2B5C83CD-9038-4A27-BF93-A5B426CF2A93.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2CE49159-D144-42AF-86E9-DAB991035D6E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS341D3601-34A7-4F9F-A4BF-21AA35317398.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3ACDF065-5C83-4B01-99B6-022B8D7FF7F2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3A24B62E-06F4-4A41-B667-2661DCEA3B65.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3CC3126C-A3ED-4125-A1F2-7619547FDA29.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS407137FB-27C2-47A8-9E04-84B4545FC51F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS42F01F39-DF9C-4F6F-B760-CCE95289AF21.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS445C55EE-5898-4665-BEA2-C3A130714052.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS458D61C5-71CF-4590-8842-F4D3B868F8FF.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS460F3485-F9B7-494D-98B6-84EA5249D1E3.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS49650641-0198-4977-90CD-28950D5020C6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4983E58C-590D-4473-A41D-19B72EC497D8.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS49F07772-DDE5-4130-B438-1465D1AFB12D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4F9691FE-762C-46EE-97AF-33379B5B1750.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4FC1F48D-C72F-46E5-A881-87E8C9FE65AD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5270A8F1-246F-4882-BBB6-E27004B5EC8C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5391D480-17DE-41A0-8D54-8EA8EBF7B2A7.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5AEB31CF-4B55-438E-A34A-D204BBA5DF53.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5B6FB05B-27BF-44FF-B8C9-D28E6A7C1EB8.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS60A3046F-1475-4CD3-A491-6B4D53F49605.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS614FDC05-38CD-4F5D-A680-EB90B20B3C2B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS631F0950-FACD-4A82-9E01-88226AABA005.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS695CC580-4035-4389-AC5F-8566F73BB658.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6B5902A4-50EF-4C04-A70B-0801650C4804.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6EE8330A-0CFB-495D-B977-D8A52F9A6261.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6F1F1A98-FB3A-4AA4-9A58-B2D1DF997D7D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS70A18CA1-9415-40A1-B269-570C1ABEEA71.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS71AC14E3-2630-42C7-B8FF-A1E1CBDAD53D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS75B556F1-E813-4E05-B3E4-73A2D6FCF626.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS77445269-6288-49EE-968D-660BF82C3E41.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7C7B0379-A7BC-4FDB-B7FA-7918E6A2DED4.tmp"
Sun 24 Aug 2008 65,536 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7DA6B8E4-35E3-4DAF-BB40-DAC005ECD53A.tmp"
Sun 24 Aug 2008 65,536 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7E9E78C8-9505-4D90-9244-705BB7E43942.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7E63C032-0F52-4895-A401-6D51A807A0FD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8594FD55-9A9E-4312-825D-463CDD33491A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS867FA5CD-2B11-4231-B4A8-BFEFD3500E99.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8F236680-CF26-41DE-B0BE-7EAE923F55FB.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS903A8A1D-6BBC-4586-B1AF-6C59EF2C29CD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS92E8ACCE-B2F0-4F00-B056-5A2B7B37530D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS93869B51-395A-4FB1-9BED-CABB3837384C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9466C60F-1789-4538-A341-89E5FEAE88CC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9687D1E1-A994-4950-B7BF-E9B90DC73524.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS96ECC867-87CC-48FF-B7BE-113F04268BC4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS96C9528F-D4DB-48DF-BEA2-4F99288F8099.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS99A3F71C-0DDF-4A24-BEB9-A3907616F08C.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9A356721-1A63-47A9-9850-8B95C55F8887.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9FC0FC2C-8806-4BF4-BD60-6F56D0DE180B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA17C3657-84AB-414F-935A-ABD1431FF06F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA7190043-FD6F-42AD-A6BD-25F21B249913.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSABA638EE-039C-4BF1-A1BA-24F6A5DE0CEE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAC340A83-8926-4C6A-A89C-86A05DC39F50.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAC235005-1436-4403-BC7F-A15E07001171.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSADEDCFBE-9410-4F49-978E-99F2B33D502D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAE73ABFF-2363-45D9-AE37-7E2461FB3E5B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB150C0FD-5589-49E8-B98E-0661968373A2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB3082D60-1061-472B-8C4A-C1012B43CD12.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB4D00148-FAA2-4AD5-BCA4-9A6AE49529CC.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB624CAB3-5E18-41D7-8D20-8C773FDEB595.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB6067CFF-F2F4-4EA9-870C-75EE249695E2.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB7EE31CA-75F7-4931-9605-BE82C64CFAFE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB97772F2-972F-4277-AE4B-FF9FF08A2DA8.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBCA70405-5D9D-4925-9FF9-DD669BA6872D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBEE3B768-04AD-4E3F-B264-230EBD4EFEA7.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC431FBAD-EAEC-4A9E-9956-0587A3662627.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC4CA1431-D8F3-4BEE-8B6A-18655DA98D0E.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC54555CB-F10D-40FE-A3A8-BDEE23137AEE.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC545DC6B-33C1-4780-8229-2D1AAEABDD34.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC8FC6AB1-1084-4042-8D8B-5284C387769A.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCAD2D9F3-FF41-46DB-84F0-2DB80905B0E0.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCD03F745-EFD1-4FDC-8D54-5A40E42C862B.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCEE43E75-B2BF-4984-9668-7126BA0D8BA4.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCE984510-9FB9-44E5-A091-1E141D33CA1D.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD095F55E-D67F-4340-B948-11957C93BD12.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD148D658-1B8A-4E60-AD01-CF83A10A9C91.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD6FA0437-5BBE-4A5E-9151-19AF7AF365A6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD87B7DBA-2DAC-48E4-A363-AF7F49F0B1ED.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDB79B199-062F-4402-BC3C-2756911B9E49.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDDD671BE-3DBC-427F-B6B6-850E17EAD657.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDE89F22A-BFB4-4A0C-A825-0427BD5B9ACD.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE1A5D68F-25C9-4F4A-A28C-E9ACFD98B0F9.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE26E4761-F542-4C3A-A5DA-BE0B6253C2F6.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE51153E8-0EC9-4F91-BE8B-F8081F400E2F.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE63912B0-2960-4488-ACDD-724125D02F34.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE667930F-167B-417D-A6A3-CDD3B3F92584.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE6999643-16C9-4678-AA6B-333256682AF7.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE6F5F772-6BDE-4CE7-9B2B-00E1472DC625.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE8B11483-CA31-44F2-AEA2-218558DA1A08.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSECB0F133-D320-46FC-892B-652296633584.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSECF24F55-5B2A-4E1F-BE5F-B6C4283DC762.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEE45A64D-ECAA-482B-B3D2-7267B4ED3642.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF85BAD98-3E23-4AE8-8466-C58EEA38A213.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFE57A372-134D-45C3-A391-609C3EAD4297.tmp"
Sun 24 Aug 2008 0 A..H. --- "C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFF9EA7D9-6785-481E-AE52-2365A42DAB33.tmp"
Tue 21 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Tue 21 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Tue 21 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
Tue 21 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"
Tue 21 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Tue 21 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch6\lock.tmp"
Sun 26 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch7\lock.tmp"

Finished!
  • 0

Advertisements


#11
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello Anne Kuhns,

STEP 1
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

Rootkit::
C:\WINDOWS\uccspecc.sys

Sysrst::

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

STEP 2
Please do an online scan with Kaspersky WebScanner
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure the following is checked.
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
~~~~~~~~~~
In your next reply please have these logs/info.
The ComboFix log
A fresh HijackThis log
The Kaspersky log
And please tell me how your computer is running
  • 0

#12
Anne Kuhns

Anne Kuhns

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Here are the lastest scans, looks like there are still a few irritating things hanging on! My computer seems to be running well, but the clock is still on military time. Thanks for persisting....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:21:01, on 8/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Weather Pulse\weatherpulse.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://militarybank...itary/login.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4061121
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] "C:\WINDOWS\stsystra.exe"
O4 - HKLM\..\Run: [DLA] "C:\WINDOWS\System32\DLA\DLACTRLW.EXE"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe"
O4 - HKLM\..\Run: [KEMailKb] "C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE"
O4 - HKLM\..\Run: [KPDrv4XP] "C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE"
O4 - HKLM\..\Run: [CanonSolutionMenu] "C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" /logon
O4 - HKLM\..\Run: [CanonMyPrinter] "C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IncrediMail] "C:\Program Files\IncrediMail\bin\IncMail.exe" /c
O4 - HKCU\..\Run: [Weather Pulse] "C:\Program Files\Weather Pulse\weatherpulse.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter...oad/tgctlcm.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://sctcdm09.ext...om/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmar...martActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1218590944937
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.co...nstallAsst2.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.h...edsolutions.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://plugin.fileop...nt/FileOpen.CAB
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.co.../MathPlayer.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 8503 bytes

ComboFix 08-08-23.01 - Mom 2008-08-25 20:18:05.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.536 [GMT -4:00]
Running from: C:\Documents and Settings\Mom\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mom\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Mom\Cookies\[email protected][2].txt
C:\Documents and Settings\Mom\Cookies\mom@revsci[2].txt
C:\Documents and Settings\Mom\Local Settings\Temporary Internet Files\favicon.ico
C:\WINDOWS\uccspecc.sys

.
((((((((((((((((((((((((( Files Created from 2008-07-26 to 2008-08-26 )))))))))))))))))))))))))))))))
.

2008-08-24 00:06 . 2008-08-24 00:06 578,560 --a------ C:\WINDOWS\system32\dllcache\user32.dll
2008-08-24 00:03 . 2008-08-24 00:04 <DIR> d-------- C:\WINDOWS\ERUNT
2008-08-22 21:55 . 2008-08-22 21:55 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-08-22 21:55 . 2008-08-22 21:55 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-08-22 21:55 . 2008-08-22 21:55 10,563 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-08-22 21:55 . 2008-08-22 21:55 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-08-22 21:38 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-22 21:18 . 2008-08-22 21:18 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-22 21:18 . 2008-08-22 21:18 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-22 21:18 . 2008-08-22 21:18 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-22 21:18 . 2008-08-22 21:18 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-22 21:14 . 2008-08-22 21:14 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-22 21:00 . 2008-08-22 21:00 <DIR> d-------- C:\WINDOWS\EHome
2008-08-22 16:35 . 2008-04-13 20:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-08-22 16:34 . 2008-04-13 20:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-22 15:48 . 2008-08-24 00:19 <DIR> d-------- C:\SDFix
2008-08-21 23:12 . 2008-08-21 23:12 <DIR> d-------- C:\Documents and Settings\Mom\Application Data\Uniblue
2008-08-21 22:42 . 2008-05-01 10:33 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-21 22:41 . 2008-04-11 15:04 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-21 22:13 . 2008-08-22 22:54 <DIR> d-------- C:\VundoFix Backups
2008-08-15 23:43 . 2008-08-15 23:43 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-15 23:19 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-15 23:17 . 2008-08-15 23:17 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-08-14 22:00 . 2008-08-14 22:00 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-08-14 22:00 . 2008-07-28 16:44 166,512 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-08-14 22:00 . 2008-01-04 20:34 23,920 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-08-14 22:00 . 2008-07-28 16:44 23,152 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-08-14 21:59 . 2008-08-14 21:59 <DIR> d-------- C:\Program Files\Webroot
2008-08-14 21:59 . 2008-08-14 21:59 <DIR> d-------- C:\Documents and Settings\Mom\Application Data\Webroot
2008-08-14 21:59 . 2008-08-14 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-08-14 21:59 . 2008-07-28 18:15 1,538,928 --a------ C:\WINDOWS\WRSetup.dll
2008-08-14 21:55 . 2008-08-14 23:19 164 --a------ C:\install.dat
2008-08-14 21:35 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-14 21:35 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-14 21:35 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-14 21:35 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-14 21:35 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-14 21:35 . 2008-08-15 23:20 5,368 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-06 16:09 . 2008-08-06 16:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IM
2008-08-06 16:07 . 2008-08-06 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-07-28 16:44 . 2008-07-28 16:44 29,808 --a------ C:\WINDOWS\system32\drivers\ssfs0bbc.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-25 23:02 --------- d-----w C:\Program Files\Weather Pulse
2008-08-25 03:16 --------- d-----w C:\Program Files\Quicken
2008-08-23 03:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\PureEdge
2008-08-23 02:06 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-08-23 02:06 23,888 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-08-23 02:06 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-08-23 02:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-23 01:57 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-23 01:55 --------- d-----w C:\Program Files\Symantec
2008-08-23 01:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-23 01:41 --------- d-----w C:\Program Files\McAfee
2008-08-23 01:40 --------- d-----w C:\Program Files\Google
2008-08-23 01:38 --------- d-----w C:\Program Files\Java
2008-08-17 00:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-08-16 03:41 --------- d-----w C:\Documents and Settings\Mom\Application Data\U3
2008-08-15 21:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
2008-08-12 21:50 --------- d-----w C:\Program Files\Yahoo!
2008-08-12 21:46 --------- d-----w C:\Program Files\Canon
2008-08-12 21:46 --------- d-----w C:\Documents and Settings\Mom\Application Data\Canon
2008-08-06 20:08 --------- d-----w C:\Program Files\IncrediMail
2008-07-14 00:07 --------- d-----w C:\Program Files\Hasbro Interactive
2008-07-10 21:08 --------- d-----w C:\Program Files\Common Files\supportsoft
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:26 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:43 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 14:57 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:46 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:46 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2007-10-27 19:38 74,056 ----a-w C:\Documents and Settings\Mom\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot_2008-08-23_23.12.07.84 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-07 09:07:23 135,168 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\cscript.exe
+ 2008-05-09 10:45:15 512,000 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\jscript.dll
+ 2008-05-09 10:45:16 180,224 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\scrobj.dll
+ 2008-05-09 10:45:16 172,032 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\scrrun.dll
+ 2008-05-09 10:45:16 430,080 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\vbscript.dll
+ 2008-05-08 11:24:44 155,648 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wscript.exe
+ 2008-05-09 10:45:17 90,112 ----a-w C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wshext.dll
+ 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB951978\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB951978\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\spcustom.dll
+ 2007-11-30 12:39:18 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\update.exe
+ 2007-11-30 12:39:19 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB951978\update\updspapi.dll
+ 2008-08-07 20:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-08-24 04:04:14 6,103,040 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-08-24 04:04:14 290,816 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-08-24 04:04:01 6,103,040 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-08-24 04:04:02 290,816 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-04-14 00:12:15 139,264 ----a-w C:\WINDOWS\system32\cscript.exe
+ 2008-05-07 09:07:23 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
+ 2008-05-07 09:07:23 135,168 ------w C:\WINDOWS\system32\dllcache\cscript.exe
+ 2008-05-09 10:53:39 512,000 ------w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2008-05-09 10:53:39 180,224 ------w C:\WINDOWS\system32\dllcache\scrobj.dll
+ 2008-05-09 10:53:40 172,032 ------w C:\WINDOWS\system32\dllcache\scrrun.dll
+ 2008-05-09 10:53:40 430,080 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
+ 2008-05-08 11:24:44 155,648 ------w C:\WINDOWS\system32\dllcache\wscript.exe
+ 2008-05-09 10:53:40 90,112 ------w C:\WINDOWS\system32\dllcache\wshext.dll
- 2008-04-14 00:11:56 512,000 ----a-w C:\WINDOWS\system32\jscript.dll
+ 2008-05-09 10:53:39 512,000 ----a-w C:\WINDOWS\system32\jscript.dll
- 2008-04-14 00:12:05 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
+ 2008-05-09 10:53:39 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
- 2008-04-14 00:12:05 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
+ 2008-05-09 10:53:40 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
- 2008-04-14 00:12:08 434,176 ----a-w C:\WINDOWS\system32\vbscript.dll
+ 2008-05-09 10:53:40 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
- 2008-04-14 00:12:41 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
+ 2008-05-08 11:24:44 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
- 2008-04-14 00:12:10 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
+ 2008-05-09 10:53:40 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
+ 2008-08-26 00:40:12 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_538.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\870.bat
2008-08-11 23:11 355 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP639\A0119319.bat

C:\ctfmon.exe
2008-08-11 23:11 83456 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP639\A0119320.exe

C:\Documents and Settings\Mom\4330.bat
2008-08-11 23:11 77 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP639\A0119321.bat

2008-08-22 22:05 371248 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2008-08-22 22:05 371248 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119515.sys

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.004\CCERASER.DLL
2008-08-22 22:05 2389552 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123578.DLL

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.004\ECMSVR32.DLL
2008-08-22 22:05 259440 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123580.DLL

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.004\EECTRL.SYS
2008-08-22 22:05 371248 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123581.SYS

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.004\ERASER.SYS
2008-08-22 22:05 99376 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123583.SYS

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.004\NAVENG.SYS
2008-08-22 22:05 89104 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123584.SYS

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.004\NAVENG32.DLL
2008-08-22 22:05 177520 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123586.DLL

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.004\NAVEX15.SYS
2008-08-22 22:05 873552 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123587.SYS

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.004\NAVEX32A.DLL
2008-08-22 22:05 1176944 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123589.DLL

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.019\CCERASER.DLL
2008-08-22 22:05 2389552 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123608.DLL

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.019\ECMSVR32.DLL
2008-08-22 22:05 259440 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123610.DLL

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.019\EECTRL.SYS
2008-08-22 22:05 371248 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123611.SYS

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.019\ERASER.SYS
2008-08-22 22:05 99376 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123613.SYS

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.019\NAVENG.SYS
2008-08-22 22:05 89104 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123614.SYS

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.019\NAVENG32.DLL
2008-08-22 22:05 177520 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123616.DLL

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.019\NAVEX15.SYS
2008-08-22 22:05 873552 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123617.SYS

C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080823.019\NAVEX32A.DLL
2008-08-22 22:05 1176944 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP642\A0123619.DLL

C:\Program Files\Coupons\uninstall.exe
2007-11-21 16:21 473600 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP639\A0119318.exe

2008-08-07 16:26 1218 C:\SDFix\apps\assosfix.reg
2008-08-07 16:26 1218 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119479.reg

2008-08-07 16:26 10240 C:\SDFix\apps\cliptext.exe
2008-08-07 16:26 10240 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119447.exe

2008-08-07 16:27 61440 C:\SDFix\apps\download.exe
2008-08-07 16:27 61440 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119448.exe

2008-08-07 16:27 1024 C:\SDFix\apps\dummy.sys
2008-08-07 16:27 1024 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119475.sys

2008-08-07 16:27 344 C:\SDFix\apps\Enable_Command_Prompt.reg
2008-08-07 16:27 344 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119480.reg

2008-08-07 16:27 157696 C:\SDFix\apps\ERUNT.EXE
2008-08-07 16:27 157696 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119449.EXE

2008-08-07 16:27 4538 C:\SDFix\apps\fix.reg
2008-08-07 16:27 4538 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119481.reg

2008-08-13 00:15 748 C:\SDFix\apps\FixBeep.reg
2008-08-13 00:15 748 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119482.reg

2008-08-18 03:11 272804 C:\SDFix\apps\FixBH.reg
2008-08-18 03:11 272804 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119483.reg

2008-08-07 16:27 2010 C:\SDFix\apps\FixComponents.reg
2008-08-07 16:27 2010 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119484.reg

2008-08-18 04:46 43088 C:\SDFix\apps\FIXCU.reg
2008-08-18 04:46 43088 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119485.reg

2008-08-18 20:10 83224 C:\SDFix\apps\FIXLM.reg
2008-08-18 20:10 83224 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119486.reg

2008-08-07 16:27 27136 C:\SDFix\apps\FixPath.exe
2008-08-07 16:27 27136 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119450.exe

2008-08-07 16:27 619 C:\SDFix\apps\FixRedir.reg
2008-08-07 16:27 619 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119487.reg

2008-08-07 16:27 826 C:\SDFix\apps\FixSchedule.reg
2008-08-07 16:27 826 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119488.reg

2008-08-07 16:27 932 C:\SDFix\apps\FixWebCheck.reg
2008-08-07 16:27 932 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119489.reg

2008-08-07 16:27 1610 C:\SDFix\apps\fixXP.reg
2008-08-07 16:27 1610 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119490.reg

2008-08-07 16:27 404 C:\SDFix\apps\FixXPsp2.reg
2008-08-07 16:27 404 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119491.reg

2008-08-07 16:27 80412 C:\SDFix\apps\grep.exe
2008-08-07 16:27 80412 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119451.exe

2008-08-07 16:27 1069 C:\SDFix\apps\HaxdFix.reg
2008-08-07 16:27 1069 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119492.reg

2008-08-07 16:27 870 C:\SDFix\apps\HPFix.reg
2008-08-07 16:27 870 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119493.reg

2008-08-07 16:27 185 C:\SDFix\apps\HPFix2.reg
2008-08-07 16:27 185 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119494.reg

2008-08-07 16:27 1772 C:\SDFix\apps\HPFix3.reg
2008-08-07 16:27 1772 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119495.reg

2008-08-07 16:27 1400 C:\SDFix\apps\HPFix4.reg
2008-08-07 16:27 1400 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119496.reg

2008-08-07 16:27 690 C:\SDFix\apps\HPFix5.reg
2008-08-07 16:27 690 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119497.reg

2008-08-07 16:27 1228 C:\SDFix\apps\HPFix6.reg
2008-08-07 16:27 1228 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119498.reg

2008-08-07 16:27 2456 C:\SDFix\apps\HPFix7.reg
2008-08-07 16:27 2456 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119499.reg

2008-08-07 16:27 1360 C:\SDFix\apps\HPFix8.reg
2008-08-07 16:27 1360 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119500.reg

2008-08-07 16:27 2278 C:\SDFix\apps\HPFix9.reg
2008-08-07 16:27 2278 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119501.reg

2008-08-07 16:27 33280 C:\SDFix\apps\isadmin.exe
2008-08-07 16:27 33280 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119452.exe

2003-12-09 01:31 11254 C:\SDFix\apps\locate.com
2003-12-09 01:31 11254 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119445.com

2008-08-07 16:27 49152 C:\SDFix\apps\LS.exe
2008-08-07 16:27 49152 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119453.exe

2008-08-07 16:27 6656 C:\SDFix\apps\MD5File.exe
2008-08-07 16:27 6656 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119454.exe

2008-08-07 16:27 38400 C:\SDFix\apps\moveex.exe
2008-08-07 16:27 38400 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119455.exe

2008-08-07 16:27 402 C:\SDFix\apps\MyGcpvFix.reg
2008-08-07 16:27 402 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119502.reg

2008-08-07 16:27 2286 C:\SDFix\apps\MyGkFix2.reg
2008-08-07 16:27 2286 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119503.reg

2008-08-07 16:27 53248 C:\SDFix\apps\Process.exe
2008-08-07 16:27 53248 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119456.exe

2008-08-07 16:27 16414 C:\SDFix\apps\procs.exe
2008-08-07 16:27 16414 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119457.exe

2008-08-07 16:27 61440 C:\SDFix\apps\psservice.exe
2008-08-07 16:27 61440 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119458.exe

2008-08-07 16:27 146432 C:\SDFix\apps\Replace\regedit.exe
2008-08-07 16:27 146432 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119459.exe

2008-08-07 16:27 94208 C:\SDFix\apps\Replace\W2K.exe
2008-08-07 16:27 94208 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119469.exe

2008-08-07 16:27 4080 C:\SDFix\apps\Replace\w2k\beep.sys
2008-08-07 16:27 4080 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119473.sys

2008-08-07 16:27 2800 C:\SDFix\apps\Replace\w2k\null.sys
2008-08-07 16:27 2800 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119477.sys

2008-08-07 16:27 94208 C:\SDFix\apps\Replace\XP.exe
2008-08-07 16:27 94208 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119471.exe

2008-08-07 16:27 4224 C:\SDFix\apps\Replace\xp\beep.sys
2008-08-07 16:27 4224 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119474.sys

2008-08-07 16:27 2944 C:\SDFix\apps\Replace\xp\null.sys
2008-08-07 16:27 2944 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119478.sys

2008-08-07 16:27 134 C:\SDFix\apps\Reset_AppInit_DLLs.reg
2008-08-07 16:27 134 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119504.reg

2008-08-07 16:27 8192 C:\SDFix\apps\RestartIt!.exe
2008-08-07 16:27 8192 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119460.exe

2007-12-08 11:50 24098 C:\SDFix\apps\Restore_SafeBoot_Windows2000.reg
2007-12-08 11:50 24098 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119505.reg

2007-02-19 00:21 27054 C:\SDFix\apps\Restore_SafeBoot_WindowsXP_SP2.reg
2007-02-19 00:21 27054 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119506.reg

2008-07-30 00:06 27144 C:\SDFix\apps\Restore_SafeBoot_WindowsXP_SP3.reg
2008-07-30 00:06 27144 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119507.reg

2008-08-07 16:27 3654 C:\SDFix\apps\Restore_SecurityCenter.reg
2008-08-07 16:27 3654 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119508.reg

2008-08-07 16:27 5768 C:\SDFix\apps\Restore_SharedAccess.reg
2008-08-07 16:27 5768 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119509.reg

2008-08-07 16:27 31232 C:\SDFix\apps\sc.exe
2008-08-07 16:27 31232 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119461.exe

2008-08-07 16:27 98816 C:\SDFix\apps\sed.exe
2008-08-07 16:27 98816 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119462.exe

2008-08-07 16:27 49152 C:\SDFix\apps\SF.exe
2008-08-07 16:27 49152 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119463.exe

2008-08-07 16:27 19456 C:\SDFix\apps\shutdown.exe
2008-08-07 16:27 19456 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119464.exe

2008-08-07 16:27 167936 C:\SDFix\apps\unzip.exe
2008-08-07 16:27 167936 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119467.exe

2008-08-07 16:27 41472 C:\SDFix\apps\WINMSG.EXE
2008-08-07 16:27 41472 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119470.EXE

2008-08-07 16:27 304 C:\SDFix\apps\winsec.reg
2008-08-07 16:27 304 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119510.reg

2008-08-07 16:27 126976 C:\SDFix\apps\zip.exe
2008-08-07 16:27 126976 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119472.exe

2008-08-07 16:27 145920 C:\SDFix\catchme.exe
2008-08-07 16:27 145920 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119446.exe

2008-08-07 16:27 1024 C:\SDFix\dummy.sys
2008-08-07 16:27 1024 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119476.sys

2008-08-19 01:36 735372 C:\SDFix\RunThis.bat
2008-08-19 01:36 735372 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP640\A0119442.bat

C:\WINDOWS\inf\_000000_.tmp.dll
2008-06-24 12:48 926 {202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP641\A0121516.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-28 22:57 395776]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 20:12 1695232]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-07-24 14:22 243072]
"Weather Pulse"="C:\Program Files\Weather Pulse\weatherpulse.exe" [2008-04-24 00:01 1859072]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-23 13:12 7630848]
"nwiz"="C:\WINDOWS\system32\nwiz.exe" [2006-08-23 13:12 1617920]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-23 13:12 86016]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 04:12 94208]
"SigmatelSysTrayApp"="C:\WINDOWS\stsystra.exe" [2006-08-15 03:38 282624]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 17:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 17:50 81920]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-20 00:10 196608]
"KEMailKb"="C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE" [2005-08-09 04:27 401408]
"KPDrv4XP"="C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE" [2005-02-21 07:15 40960]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-04-03 21:00 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 21:50 1603152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-27 18:28 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-04-30 16:44 115560]

C:\Documents and Settings\Mom\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-11-26 02:35:34 157008]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-10-02 15:08:08 57344]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=

R0 ssfs0bbc;ssfs0bbc;C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys [2008-07-28 16:44]
R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 12:20]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-08-22 22:06]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57ba671a-9c61-11db-924a-00038a000015}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-08-21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

2008-08-23 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-28 18:15]

2008-08-23 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-28 18:15]

2008-08-23 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job
- C:\","D:\","F:\","G:\","H:\","I:\" []
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-25 20:46:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-08-25 21:00:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-26 00:59:44
ComboFix2.txt 2008-08-24 03:53:49
ComboFix3.txt 2008-08-24 03:16:35
ComboFix4.txt 2008-08-23 00:00:36

Pre-Run: 55,195,844,608 bytes free
Post-Run: 55,236,108,288 bytes free

431 --- E O F --- 2008-08-24 05:04:12

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, August 25, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, August 26, 2008 02:33:53
Records in database: 1146436
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
F:\
G:\
H:\
I:\

Scan statistics:
Files scanned: 69940
Threat name: 3
Infected objects: 5
Suspicious objects: 0
Duration of the scan: 01:17:45


File name / Threat name / Threats count
C:\QooBox\Quarantine\C\WINDOWS\system32\sxlfejfi.dll.vir Infected: Trojan.Win32.Monder.fxl 1
C:\QooBox\Quarantine\C\WINDOWS\system32\wvkcbz.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.cvf 1
C:\VundoFix Backups\efcASlmj.dll.bad Infected: Trojan.Win32.Monderb.few 1
C:\VundoFix Backups\slvlgyrn.dll.bad Infected: not-a-virus:AdWare.Win32.SuperJuan.cvf 1
C:\VundoFix Backups\sxlfejfi.dll.bad Infected: Trojan.Win32.Monder.fxl 1

The selected area was scanned.
  • 0

#13
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello Anne Kuhns,

STEP 1
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\WINDOWS\inf\_000000_.tmp.dll
    purity
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

STEP 2
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    • C:\WINDOWS\system32\dllcache\user32.dll
  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
~~~~~~~~~~
In your next reply please have these logs.
The OTMoveIt2 log
And the VirScan log
  • 0

#14
Anne Kuhns

Anne Kuhns

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Here are the two latest logs...

VirSCAN.org Scanned Report :
Scanner results: 3% Scanner(1/36) found malware!
File Name : user32.dll
File Size : 578560 byte
File Type : MS-DOS executable (EXE), OS/2 or MS Windows
MD5 : b26b135ff1b9f60c9388b4a7d16f600b
SHA1 : 08fe9ff1fe9b8fd237adedb10d65fb0447b91fe5
Online report : http://virscan.org/r...3632c60d33.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 3.5.0.18 2008.06.04 2008-06-04 4.28 -
AhnLab V3 2008.06.05.01 2008.06.05 2008-06-05 2.04 -
AntiVir 7.8.0.26 7.0.4.145 2008-06-05 7.08 -
Arcavir 1.0.4 200806041951 2008-06-04 3.63 -
AVAST! 1.0.8 080605-0 2008-06-05 7.69 -
AVG 7.5.51.442 270.0.0/1484 2008-06-04 6.53 -
BitDefender 7.60825.1256309 7.19350 2008-06-05 7.21 -
CA (VET) 9.0.0.143 31.6.5849 2008-06-05 11.93 -
ClamAV 0.93 7367 2008-06-05 0.21 -
Comodo 2.11 2.0.0.546 2008-06-05 1.47 -
CP Secure 1.1.0.715 2008.06.05 2008-06-05 20.28 -
Dr.Web 4.44.0.9170 2008.06.05 2008-06-05 14.40 -
ewido 4.0.0.2 2008.06.04 2008-06-04 3.48 -
F-Prot 4.4.1.52 20080604 2008-06-04 4.82 -
F-Secure 5.51.6100 2008.06.04.06 2008-06-04 0.07 -
Fortinet 2.81-3.11 9.168 2008-06-05 2.89 -
ViRobot 20080604 2008.06.04 2008-06-04 0.79 -
Ikarus T3.1.01.26 2008.06.05.70870 2008-06-05 8.97 -
JiangMin 11.0.706 2008.06.05 2008-06-05 2.87 -
Kaspersky 5.5.10 2008.06.05 2008-06-05 15.68 -
KingSoft 2008.1.14.15 2008.6.5.14 2008-06-05 1.33 -
McAfee 5.2.00 5310 2008-06-04 4.06 -
Microsoft 1.3604 2008.06.05 2008-06-05 8.19 -
mks_vir 2.01 2008.06.04 2008-06-04 6.16 -
Norman 5.92.08 5.92.00 2008-06-04 11.70 -
Panda 9.04.03.0001 2008.06.04 2008-06-04 3.41 -
Trend Micro 8.700-1004 5.320.02 2008-06-04 0.04 -
Prevx V2 20080605 2008-06-05 3.02 TROJAN.PWDSTEALER.GEN
Quick Heal 9.00 2008.06.04 2008-06-04 0.47 -
Rising 20.0 20.47.30.00 2008-06-05 1.79 -
Sophos 2.74.1 4.30 2008-06-05 8.33 -
Symantec 1.3.0.24 20080604.003 2008-06-04 0.25 -
nProtect 2008-06-05.00 1534841 2008-06-05 5.83 -
The Hacker 6.2.92 v00335 2008-06-04 1.50 -
VBA32 3.12.6.7 20080604.1021 2008-06-04 4.76 -
VirusBuster 4.3.19:9 9.130.14/11.0 2008-06-04 3.32 -

Explorer killed successfully
File/Folder C:\WINDOWS\inf\_000000_.tmp.dll not found.
< purity >
< EmptyTemp >
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5a8.dat scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08262008_153326

Files moved on Reboot...
File C:\WINDOWS\temp\Perflib_Perfdata_5a8.dat not found!
  • 0

#15
Jimmy2012

Jimmy2012

    Trusted Helper

  • Retired Staff
  • 6,238 posts
Hello Anne Kuhns,

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\dllcache\user32.dll

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log
  • Please tell me how your computer is running.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP