Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

IRCbot [RESOLVED]


  • This topic is locked This topic is locked

#1
synesthesia

synesthesia

    Member

  • Member
  • PipPip
  • 43 posts
I'm not sure how to get rid of the IRCbot thing that's infecting my computer. When it came up in the scan on Adware I quarantined it, but when I ran another scan a few days later, it came up again. I'm not sure why it keeps coming back. I am hoping you guys will be able to help me get rid of it for good.

Here's the Hijack log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:03:09 PM, on 8/23/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\System32\TFNF5.exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\AccessRamp\ARMon32.exe
C:\WINDOWS\System32\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AdwareAlert\AdwareAlert.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\help\svchost.exe
C:\WINDOWS\help\svchost32.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aol\aim toolbar 5.0\AolTbServer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.mindsprin.../searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.freeart1cile.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.mindspring.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by MindSpring Internet Services
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
F2 - REG:system.ini: Shell=explorer.exe "C:\WINDOWS\Fonts\wmsncs.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [AccessRampMonitor] C:\Program Files\AccessRamp\ARMon32.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Wmsncs Service] C:\WINDOWS\Fonts\wmsncs.exe
O4 - HKLM\..\Run: [NvidMediaCenter] C:\Program Files\Common Files\System\wmsncs.exe
O4 - HKLM\..\Run: [Spool Driver Service] C:\WINDOWS\System32\spool\drivers\wmsncs.exe
O4 - HKLM\..\Run: [Wins Service] C:\WINDOWS\System32\wins\wmsncs.exe
O4 - HKLM\..\Run: [EPSON Stylus C88 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE /P23 "EPSON Stylus C88 Series" /O5 "LPT1:" /M "Stylus C88"
O4 - HKLM\..\Run: [Background Intelligent Transfer Service] C:\WINDOWS\help\svchost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKCU\..\Run: [Network Connections] C:\WINDOWS\help\internat.exe
O4 - HKUS\S-1-5-18\..\Run: [Wmsncs Service] C:\WINDOWS\Fonts\wmsncs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [NvidMediaCenter] C:\Program Files\Common Files\System\wmsncs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Spool Driver Service] C:\WINDOWS\System32\spool\drivers\wmsncs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Wins Service] C:\WINDOWS\System32\wins\wmsncs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Network Connections] C:\WINDOWS\help\internat.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Networking Monitoring] C:\WINDOWS\System32\mdm.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Wmsncs Service] C:\WINDOWS\Fonts\wmsncs.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: wmsncs.exe
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://start.mindspring.net
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 7130 bytes


thanks,
Soleil
  • 0

Advertisements


#2
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

Please run the MGA Diagnostic Tool and post back the report it shall produce:
  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.

  • 0

#3
synesthesia

synesthesia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
here's the report you asked for

Diagnostic Report (1.7.0095.0):
-----------------------------------------
WGA Data-->
Validation Status: Validation Control not Installed
Validation Code: 0
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-W3R3K-J2VF4-JFP8W
Windows Product Key Hash: XPfxGkd+SaYWqIyXYZav/kIic8c=
Windows Product ID: 55277-OEM-2111907-00111
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010300.1.0.hom
CSVLK Server: N/A
CSVLK PID: N/A
ID: {AC32276D-A7C7-47ED-8E90-86196A711CF3}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1
Resolution Status: N/A

WgaER Data-->
ThreatID(s): N/A
Version: N/A

WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-171-1

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control:
Active scripting:
Script ActiveX controls marked as safe for scripting:

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{AC32276D-A7C7-47ED-8E90-86196A711CF3}</UGUID><Version>1.7.0095.0</Version><OS>5.1.2600.2.00010300.1.0.hom</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-JFP8W</PKey><PID>55277-OEM-2111907-00111</PID><PIDType>2</PIDType><SID>S-1-5-21-1238604406-4063022668-1793010294</SID><SYSTEM><Manufacturer>TOSHIBA</Manufacturer><Model>Satellite A15</Model></SYSTEM><BIOS><Manufacturer>TOSHIBA</Manufacturer><Version>Version 1.20</Version><SMBIOSVersion major="2" minor="3"/><Date>20030520******.******+***</Date><SLPBIOS>TOSHIBA</SLPBIOS></BIOS><HWID>E3613C07018400C2</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>2</stat><msppid></msppid><name>Toshiba</name><model>Satellite</model></SBID><OEM/><BRT/></MachineData> <Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>
  • 0

#4
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Your Windows isn't validated, this is a sign of a pirated OS

Once you validate it, we can help you. Otherwise we cant.
  • 0

#5
admin

admin

    Founder Geek

  • Community Leader
  • 24,639 posts
Windows validated. Topic opened per request of the topic starter.

Diagnostic Report (1.7.0095.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Validation Code: 0
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-W3R3K-J2VF4-JFP8W
Windows Product Key Hash: XPfxGkd+SaYWqIyXYZav/kIic8c=
Windows Product ID: 55277-OEM-2111907-00111
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010300.1.0.hom
CSVLK Server: N/A
CSVLK PID: N/A
ID: {AC32276D-A7C7-47ED-8E90-86196A711CF3}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.69.2
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1
Resolution Status: N/A
WgaER Data-->
ThreatID(s): N/A
Version: N/A
WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-604-645_025D1FF3-171-1
Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Prompt
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control:
Active scripting:
Script ActiveX controls marked as safe for scripting:
File Scan Data-->
Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{AC32276D-A7C7-47ED-8E90-86196A711CF3}</UGUID><Version>1.7.0095.0</Version><OS>5.1.2600.2.00010300.1.0.hom</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-JFP8W</PKey><PID>55277-OEM-2111907-00111</PID><PIDType>2</PIDType><SID>S-1-5-21-1238604406-4063022668-1793010294</SID><SYSTEM><Manufacturer>TOSHIBA</Manufacturer><Model>Satellite A15</Model></SYSTEM><BIOS><Manufacturer>TOSHIBA</Manufacturer><Version>Version 1.20</Version><SMBIOSVersion major="2" minor="3"/><Date>20030520******.******+***</Date><SLPBIOS>TOSHIBA</SLPBIOS></BIOS><HWID>E3613C07018400C2</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>2</stat><msppid></msppid><name>Toshiba</name><model>Satellite</model></SBID><OEM/><BRT/></MachineData> <Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>


  • 0

#6
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Now we can help you :)

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.



Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingc...to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
  • 0

#7
synesthesia

synesthesia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
I hope I did everything right.



SDFix report:


SDFix: Version 1.219
Run by Soleil Robichaud on Sun 08/24/2008 at 07:57 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\g.bat - Deleted
C:\WINDOWS\Help\svchost.exe - Deleted
C:\WINDOWS\system32\i - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 20:03:43
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

C:\WINDOWS\Fonts\wmsncs.exe [1704] 0xFF9DA4C0

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...


scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Thu 7 Aug 2008 126,823 ..SHR --- "C:\WINDOWS\Fonts\wmsncs.exe"
Thu 7 Aug 2008 126,823 ..SHR --- "C:\Program Files\Common Files\System\wmsncs.exe"
Mon 4 Jun 2007 20,809 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti3.tmp"
Thu 7 Aug 2008 126,823 ..SHR --- "C:\WINDOWS\system32\wins\wmsncs.exe"
Wed 13 Aug 2008 21,504 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL0001.tmp"
Sun 10 Aug 2008 28,672 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL0002.tmp"
Sun 10 Aug 2008 33,280 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL0005.tmp"
Wed 20 Aug 2008 19,456 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL0006.tmp"
Sun 10 Aug 2008 31,232 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL0331.tmp"
Sun 10 Aug 2008 32,256 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL0513.tmp"
Wed 13 Aug 2008 42,496 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL0800.tmp"
Sun 10 Aug 2008 32,256 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL1937.tmp"
Mon 4 Aug 2008 22,528 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL2081.tmp"
Wed 13 Aug 2008 22,528 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL2388.tmp"
Wed 13 Aug 2008 19,968 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL2405.tmp"
Sun 10 Aug 2008 32,768 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL2562.tmp"
Wed 20 Aug 2008 26,624 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL2625.tmp"
Sun 10 Aug 2008 32,768 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL2845.tmp"
Thu 7 Aug 2008 23,552 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL3033.tmp"
Wed 13 Aug 2008 19,456 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL3499.tmp"
Sun 10 Aug 2008 29,184 ...H. --- "C:\Documents and Settings\Soleil Robichaud\My Documents\Soleil\~WRL3552.tmp"
Thu 7 Aug 2008 126,823 ..SHR --- "C:\WINDOWS\system32\spool\drivers\wmsncs.exe"
Thu 7 Aug 2008 126,823 ..SHR --- "C:\Documents and Settings\All Users\Start Menu\Programs\Startup\wmsncs.exe"
Wed 13 Aug 2008 38,912 ...H. --- "C:\Documents and Settings\Soleil Robichaud\Application Data\Microsoft\Word\~WRL1821.tmp"
Wed 12 Nov 2003 65,024 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL0013.tmp"
Tue 11 Nov 2003 31,744 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL0928.tmp"
Tue 11 Nov 2003 54,784 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL1105.tmp"
Wed 12 Nov 2003 64,512 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL1110.tmp"
Wed 12 Nov 2003 68,096 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL1924.tmp"
Tue 11 Nov 2003 53,760 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL2454.tmp"
Tue 11 Nov 2003 40,960 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL2620.tmp"
Tue 11 Nov 2003 65,024 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL2759.tmp"
Tue 11 Nov 2003 55,296 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL2916.tmp"
Wed 12 Nov 2003 65,024 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL2932.tmp"
Wed 12 Nov 2003 69,120 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL2997.tmp"
Wed 12 Nov 2003 65,536 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL3387.tmp"
Tue 11 Nov 2003 29,184 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL3431.tmp"
Wed 12 Nov 2003 118,272 A..H. --- "C:\Documents and Settings\Ron Robichaud\My Documents\Ron\CDS-Info\Awise General\~WRL3564.tmp"

Finished!




ComboFix log:


ComboFix 08-08-23.03 - Soleil Robichaud 2008-08-24 20:41:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.94 [GMT -4:00]
Running from: C:\Documents and Settings\Soleil Robichaud\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Soleil Robichaud\Application Data\macromedia\Flash Player\#SharedObjects\FUYZS8F5\interclick.com
C:\Documents and Settings\Soleil Robichaud\Application Data\macromedia\Flash Player\#SharedObjects\FUYZS8F5\interclick.com\ud.sol
C:\Documents and Settings\Soleil Robichaud\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Soleil Robichaud\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Trevor Robichaud\Application Data\macromedia\Flash Player\#SharedObjects\R6B6SHBX\interclick.com
C:\Documents and Settings\Trevor Robichaud\Application Data\macromedia\Flash Player\#SharedObjects\R6B6SHBX\interclick.com\ud.sol
C:\Documents and Settings\Trevor Robichaud\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Trevor Robichaud\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\help\svchost.exe
C:\WINDOWS\system32\mdm.exe

.
((((((((((((((((((((((((( Files Created from 2008-07-25 to 2008-08-25 )))))))))))))))))))))))))))))))
.

2008-08-24 19:54 . 2008-08-24 19:54 <DIR> d-------- C:\WINDOWS\ERUNT
2008-08-24 19:48 . 2008-08-24 20:05 <DIR> d-------- C:\SDFix
2008-08-24 18:02 . 2008-08-24 18:55 <DIR> d-------- C:\Documents and Settings\Trevor Robichaud\Application Data\AdwareAlert
2008-08-24 12:30 . 2008-08-24 12:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-23 19:25 . 2008-08-23 19:25 <DIR> d-------- C:\Program Files\AdwareAlert
2008-08-23 19:01 . 2008-08-23 19:01 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-23 18:52 . 2008-08-23 19:28 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\AdwareAlert
2008-08-23 18:52 . 2008-08-24 16:14 <DIR> d-------- C:\Documents and Settings\Ron Robichaud\Application Data\AdwareAlert
2008-08-23 18:49 . 2008-08-23 18:52 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\AdwareAlert(2)
2008-08-23 18:32 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-08-23 18:32 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-08-23 18:32 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-08-23 18:32 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-08-23 18:20 . 2008-08-23 18:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-23 18:20 . 2008-08-23 18:20 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\Malwarebytes
2008-08-23 18:20 . 2008-08-23 18:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-23 18:19 . 2008-08-23 18:19 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-08-23 18:13 . 2008-08-23 18:59 <DIR> d-------- C:\Program Files\ERUNT
2008-08-22 13:32 . 2008-08-24 18:08 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-22 13:32 . 2008-08-22 13:32 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-14 22:37 . 2008-08-14 22:37 <DIR> d-------- C:\Program Files\EPSON
2008-08-14 22:37 . 2004-06-24 01:20 309,760 --a------ C:\WINDOWS\system32\EAL32.DLL
2008-08-14 22:37 . 2004-03-12 01:30 82,944 --a------ C:\WINDOWS\system32\EAL.EXE
2008-08-14 22:37 . 2004-11-25 05:07 79,679 --a------ C:\WINDOWS\system32\E_FLMABA.DLL
2008-08-14 22:37 . 2003-05-21 02:27 64,000 --a------ C:\WINDOWS\system32\E_FBCBABA.DLL
2008-08-14 22:37 . 2000-06-07 01:01 34,304 --a------ C:\WINDOWS\system32\E_FBCHABA.DLL
2008-08-14 22:37 . 2004-06-24 01:20 51 --a------ C:\WINDOWS\system32\EAL32.INI
2008-08-11 00:33 . 2008-08-11 00:33 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\acccore
2008-08-11 00:31 . 2008-08-11 00:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-08-11 00:30 . 2008-08-11 00:30 21 --a------ C:\WINDOWS\atid.ini
2008-08-11 00:29 . 2008-08-11 00:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-08-11 00:29 . 2008-08-11 00:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-08-11 00:29 . 2008-08-11 00:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\acccore
2008-08-11 00:27 . 2008-08-11 00:33 <DIR> d-------- C:\Program Files\AIM6
2008-08-08 22:46 . 2008-08-08 22:46 53 --a------ C:\WINDOWS\system32\g.ftp
2008-08-07 17:31 . 2008-08-07 17:31 159,744 --a------ C:\WINDOWS\system32\Bsmtp.dll
2008-08-07 17:31 . 2008-08-07 17:31 108,336 --a------ C:\WINDOWS\system32\MSWINSCK.OCX
2008-08-07 15:46 . 2008-08-07 15:46 <DIR> d---s---- C:\Documents and Settings\Ron Robichaud\UserData
2008-08-01 23:09 . 2008-08-01 23:09 <DIR> d-------- C:\WINDOWS\A8B9466986544126BD28D0D2412CDED6.TMP
2008-08-01 13:01 . 2008-08-15 12:21 <DIR> d-------- C:\Documents and Settings\Trevor Robichaud\Application Data\OnRez
2008-08-01 12:07 . 2008-08-01 12:07 <DIR> d---s---- C:\Documents and Settings\Trevor Robichaud\UserData
2008-07-31 22:03 . 2008-08-15 01:49 <DIR> d-------- C:\Documents and Settings\Trevor Robichaud\Application Data\SecondLife
2008-07-31 21:53 . 2008-07-31 21:53 <DIR> d---s---- C:\Documents and Settings\Soleil Robichaud\UserData
2008-07-31 21:40 . 2008-07-31 21:40 2,838 --a------ C:\WINDOWS\machine.ver
2008-07-31 14:02 . 2008-07-31 14:02 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\MAGIX
2008-07-25 10:37 . 2006-05-23 17:41 626,688 --a------ C:\WINDOWS\system32\mgxoschk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-23 22:47 79,270 ----a-w C:\Program Files\hptdvnkb.txt
2008-08-11 04:28 --------- d-----w C:\Program Files\Common Files\AOL
2008-08-08 07:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-08-07 21:31 83,968 ----a-w C:\WINDOWS\Help\svchost32.exe
2008-08-07 21:31 409,600 ----a-w C:\WINDOWS\Help\ipconfig.sys
2008-08-07 21:31 409,600 ----a-w C:\WINDOWS\Help\internat.exe
2008-08-07 19:17 126,823 --sh--r C:\WINDOWS\Fonts\wmsncs.exe
2008-08-02 03:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-01 15:16 --------- d-----w C:\Program Files\MindSpring 4.0
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-20 18:08 1511453]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-08-06 11:21 50472]
"AdwareAlert"="C:\Program Files\AdwareAlert\AdwareAlert.exe" [2008-08-22 15:20 9093120]
"Network Connections"="C:\WINDOWS\help\internat.exe" [2008-08-07 17:31 409600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="C:\WINDOWS\System32\00THotkey.exe" [2003-04-15 23:01 258048]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-04-07 03:19 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-07 03:07 114688]
"PmProxy"="C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe" [2003-02-28 22:54 40960]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-01-02 20:16 172032]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2002-12-25 17:38 159744]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2003-01-21 21:00 126976]
"NDSTray.exe"="C:\Program Files\Toshiba\ConfigFree\NDSTray.exe" [2003-01-17 23:26 458752]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 13:29 40960]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2002-10-17 16:21 159744]
"AccessRampMonitor"="C:\Program Files\AccessRamp\ARMon32.exe" [1999-08-03 13:13 68096]
"QuickTime Task"="C:\WINDOWS\System32\qttask.exe" [2006-08-20 22:28 28672]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 02:12 49152]
"Wmsncs Service"="C:\WINDOWS\Fonts\wmsncs.exe" [2008-08-07 15:17 126823]
"NvidMediaCenter"="C:\Program Files\Common Files\System\wmsncs.exe" [2008-08-07 15:17 126823]
"Spool Driver Service"="C:\WINDOWS\System32\spool\drivers\wmsncs.exe" [2008-08-07 15:17 126823]
"Wins Service"="C:\WINDOWS\System32\wins\wmsncs.exe" [2008-08-07 15:17 126823]
"EPSON Stylus C88 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" [2005-01-27 04:00 98304]
"000StTHK"="000StTHK.exe" [2001-06-23 23:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2003-04-18 14:20 88363 C:\WINDOWS\agrsmmsg.exe]
"TFNF5"="TFNF5.exe" [2001-08-03 20:08 73728 C:\WINDOWS\system32\TFNF5.exe]
"Tpwrtray"="TPWRTRAY.EXE" [2002-12-10 13:49 237568 C:\WINDOWS\system32\TPWRTRAY.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Wmsncs Service"="C:\WINDOWS\Fonts\wmsncs.exe" [2008-08-07 15:17 126823]
"NvidMediaCenter"="C:\Program Files\Common Files\System\wmsncs.exe" [2008-08-07 15:17 126823]
"Spool Driver Service"="C:\WINDOWS\System32\spool\drivers\wmsncs.exe" [2008-08-07 15:17 126823]
"Wins Service"="C:\WINDOWS\System32\wins\wmsncs.exe" [2008-08-07 15:17 126823]
"Network Connections"="C:\WINDOWS\help\internat.exe" [2008-08-07 17:31 409600]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 02:23:26 282624]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-09-04 18:23:00 65588]
wmsncs.exe [2008-08-07 15:17:21 126823]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="explorer.exe \"C:\\WINDOWS\\Fonts\\wmsncs.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

R2 NET Runtime Optimization Service v2.1.41329_X86;NET Runtime Optimization Service v2.1.41329_X86;C:\WINDOWS\Fonts\wmsncs.exe [2008-08-07 15:17]
S3 CBEN5;Xircom CardBus Ethernet 10/100 Adapter family Driver;C:\WINDOWS\System32\DRIVERS\cben5.sys [2001-08-17 08:13]
S3 wlags48b;Wireless LAN PCCard Driver;C:\WINDOWS\System32\DRIVERS\wlags48b.sys [2002-06-28 19:29]

*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
*Newly Created Service* - PROCEXP90
*Newly Created Service* - SHAREDACCESS

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{103L3C30-C3B3-4130-9363-E59E1375PERM}]
C:\WINDOWS\Fonts\wmsncs.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Background Intelligent Transfer Service - C:\WINDOWS\help\svchost.exe


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R1 -: HKCU-Internet Settings,ProxyOverride = <local>
O8 -: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 -: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm

O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 20:45:33
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

C:\WINDOWS\Fonts\wmsncs.exe [1704] 0xFF9DA4C0

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-24 20:48:55
ComboFix-quarantined-files.txt 2008-08-25 00:48:48

Pre-Run: 1,221,816,320 bytes free
Post-Run: 2,029,334,528 bytes free

179





HijackThis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:57:00 PM, on 8/24/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\System32\TFNF5.exe
C:\WINDOWS\System32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\AccessRamp\ARMon32.exe
C:\WINDOWS\System32\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
c:\program files\aol\aim toolbar 5.0\AolTbServer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
F2 - REG:system.ini: Shell=explorer.exe "C:\WINDOWS\Fonts\wmsncs.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [AccessRampMonitor] C:\Program Files\AccessRamp\ARMon32.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Wmsncs Service] C:\WINDOWS\Fonts\wmsncs.exe
O4 - HKLM\..\Run: [NvidMediaCenter] C:\Program Files\Common Files\System\wmsncs.exe
O4 - HKLM\..\Run: [Spool Driver Service] C:\WINDOWS\System32\spool\drivers\wmsncs.exe
O4 - HKLM\..\Run: [Wins Service] C:\WINDOWS\System32\wins\wmsncs.exe
O4 - HKLM\..\Run: [EPSON Stylus C88 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE /P23 "EPSON Stylus C88 Series" /O5 "LPT1:" /M "Stylus C88"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKCU\..\Run: [Network Connections] C:\WINDOWS\help\internat.exe
O4 - HKUS\S-1-5-18\..\Run: [Wmsncs Service] C:\WINDOWS\Fonts\wmsncs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [NvidMediaCenter] C:\Program Files\Common Files\System\wmsncs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Spool Driver Service] C:\WINDOWS\System32\spool\drivers\wmsncs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Wins Service] C:\WINDOWS\System32\wins\wmsncs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Network Connections] C:\WINDOWS\help\internat.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Wmsncs Service] C:\WINDOWS\Fonts\wmsncs.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: wmsncs.exe
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://start.mindspring.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 6773 bytes
  • 0

#8
synesthesia

synesthesia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
I did another scan on AdWare Alert this morning and it found another backdoor trojan called Bifrose. =[
  • 0

#9
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Hello

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::

KillAll::

Rootkit::
C:\WINDOWS\Fonts\wmsncs.exe
C:\WINDOWS\system32\spool\drivers\wmsncs.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\wmsncs.exe
C:\Program Files\hptdvnkb.txt
C:\WINDOWS\Help\svchost32.exe
C:\WINDOWS\Help\ipconfig.sys
C:\WINDOWS\Help\internat.exe
C:\WINDOWS\Fonts\wmsncs.exe


Folder::
C:\WINDOWS\system32\wins

Registry::
O9 -: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{103L3C30-C3B3-4130-9363-E59E1375PERM}]
[-HKEY_CLASSES_ROOT\CLSID\{103L3C30-C3B3-4130-9363-E59E1375PERM}]

Sysrst::

Driver::
NET Runtime Optimization Service v2.1.41329_X86


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • 0

#10
synesthesia

synesthesia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
doing that won't mess up my computer in any way right? because I couldn't figure out how to install the windows recovery console, and I just want to be sure. thanks =]
  • 0

Advertisements


#11
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
If I thought it would, I wouldn't have you do it
  • 0

#12
synesthesia

synesthesia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
here's the log

ComboFix 08-08-23.03 - Soleil Robichaud 2008-08-25 20:03:35.2 - NTFSx86
Running from: C:\Documents and Settings\Soleil Robichaud\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Soleil Robichaud\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\wins :#:
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\wmsncs.exe
C:\Program Files\hptdvnkb.txt
C:\WINDOWS\Fonts\wmsncs.exe
C:\WINDOWS\Help\internat.exe
C:\WINDOWS\Help\ipconfig.sys
C:\WINDOWS\help\svchost.exe
C:\WINDOWS\Help\svchost32.exe
C:\WINDOWS\system32\spool\drivers\wmsncs.exe
C:\WINDOWS\web\related.htm

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NET_RUNTIME_OPTIMIZATION_SERVICE_V2.1.41329_X86
-------\Service_NET Runtime Optimization Service v2.1.41329_X86


((((((((((((((((((((((((( Files Created from 2008-07-26 to 2008-08-26 )))))))))))))))))))))))))))))))
.

2008-08-25 16:30 . 2008-08-25 19:57 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\PrivacyControl
2008-08-25 14:33 . 2008-08-25 14:34 <DIR> d-------- C:\Program Files\PrivacyControl
2008-08-25 14:33 . 2008-08-25 14:34 <DIR> d-------- C:\Documents and Settings\Ron Robichaud\Application Data\PrivacyControl
2008-08-24 22:57 . 2008-08-24 23:35 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-24 22:57 . 2008-08-24 22:57 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-24 19:54 . 2008-08-24 19:54 <DIR> d-------- C:\WINDOWS\ERUNT
2008-08-24 19:48 . 2008-08-24 20:05 <DIR> d-------- C:\SDFix
2008-08-24 18:02 . 2008-08-24 18:55 <DIR> d-------- C:\Documents and Settings\Trevor Robichaud\Application Data\AdwareAlert
2008-08-24 12:30 . 2008-08-24 12:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-08-23 19:25 . 2008-08-23 19:25 <DIR> d-------- C:\Program Files\AdwareAlert
2008-08-23 19:01 . 2008-08-23 19:01 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-23 18:52 . 2008-08-23 19:28 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\AdwareAlert
2008-08-23 18:52 . 2008-08-25 13:09 <DIR> d-------- C:\Documents and Settings\Ron Robichaud\Application Data\AdwareAlert
2008-08-23 18:49 . 2008-08-23 18:52 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\AdwareAlert(2)
2008-08-23 18:32 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-08-23 18:32 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-08-23 18:32 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-08-23 18:32 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-08-23 18:20 . 2008-08-23 18:52 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-23 18:20 . 2008-08-23 18:20 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\Malwarebytes
2008-08-23 18:20 . 2008-08-23 18:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-23 18:19 . 2008-08-23 18:19 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-08-23 18:13 . 2008-08-23 18:59 <DIR> d-------- C:\Program Files\ERUNT
2008-08-14 22:37 . 2008-08-14 22:37 <DIR> d-------- C:\Program Files\EPSON
2008-08-14 22:37 . 2004-06-24 01:20 309,760 --a------ C:\WINDOWS\system32\EAL32.DLL
2008-08-14 22:37 . 2004-03-12 01:30 82,944 --a------ C:\WINDOWS\system32\EAL.EXE
2008-08-14 22:37 . 2004-11-25 05:07 79,679 --a------ C:\WINDOWS\system32\E_FLMABA.DLL
2008-08-14 22:37 . 2003-05-21 02:27 64,000 --a------ C:\WINDOWS\system32\E_FBCBABA.DLL
2008-08-14 22:37 . 2000-06-07 01:01 34,304 --a------ C:\WINDOWS\system32\E_FBCHABA.DLL
2008-08-14 22:37 . 2004-06-24 01:20 51 --a------ C:\WINDOWS\system32\EAL32.INI
2008-08-11 00:33 . 2008-08-11 00:33 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\acccore
2008-08-11 00:31 . 2008-08-11 00:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-08-11 00:30 . 2008-08-11 00:30 21 --a------ C:\WINDOWS\atid.ini
2008-08-11 00:29 . 2008-08-11 00:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-08-11 00:29 . 2008-08-11 00:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-08-11 00:29 . 2008-08-11 00:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\acccore
2008-08-11 00:27 . 2008-08-11 00:33 <DIR> d-------- C:\Program Files\AIM6
2008-08-08 22:46 . 2008-08-08 22:46 53 --a------ C:\WINDOWS\system32\g.ftp
2008-08-07 17:31 . 2008-08-07 17:31 159,744 --a------ C:\WINDOWS\system32\Bsmtp.dll
2008-08-07 17:31 . 2008-08-07 17:31 108,336 --a------ C:\WINDOWS\system32\MSWINSCK.OCX
2008-08-07 15:46 . 2008-08-07 15:46 <DIR> d---s---- C:\Documents and Settings\Ron Robichaud\UserData
2008-08-01 23:09 . 2008-08-01 23:09 <DIR> d-------- C:\WINDOWS\A8B9466986544126BD28D0D2412CDED6.TMP
2008-08-01 13:01 . 2008-08-15 12:21 <DIR> d-------- C:\Documents and Settings\Trevor Robichaud\Application Data\OnRez
2008-08-01 12:07 . 2008-08-01 12:07 <DIR> d---s---- C:\Documents and Settings\Trevor Robichaud\UserData
2008-07-31 22:03 . 2008-08-15 01:49 <DIR> d-------- C:\Documents and Settings\Trevor Robichaud\Application Data\SecondLife
2008-07-31 21:53 . 2008-07-31 21:53 <DIR> d---s---- C:\Documents and Settings\Soleil Robichaud\UserData
2008-07-31 21:40 . 2008-07-31 21:40 2,838 --a------ C:\WINDOWS\machine.ver
2008-07-31 14:02 . 2008-07-31 14:02 <DIR> d-------- C:\Documents and Settings\Soleil Robichaud\Application Data\MAGIX

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-11 04:28 --------- d-----w C:\Program Files\Common Files\AOL
2008-08-08 07:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-08-07 19:17 126,823 ------w C:\WINDOWS\Fonts\wmsncs.exe
2008-08-02 03:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-01 15:16 --------- d-----w C:\Program Files\MindSpring 4.0
.

((((((((((((((((((((((((((((( snapshot@2008-08-24_20.47.45.80 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 00:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Dc10\TI Connect\TILauncher.exe
2004-02-27 17:31 40960 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0032225.exe

C:\Dc10\TI ProgramEditor\TIShelExLib.dll
{1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0032213."

C:\ComboFix\T

C:\Holt World Languages\Holt World Languages.exe
2004-01-28 08:26 2318120 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0032421.exe

C:\Holt World Languages\uninst\g2d1\UNWISE.EXE
2001-09-28 20:00 128608 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0032425.EXE

C:\Holt World Languages\xtras\PMatic.reg
2004-01-21 11:31 43 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0032422.reg

C:\MAGIX\Movie_Edit_Pro_11\addoninstall.exe
2006-05-12 12:32 269159 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030784.exe

C:\MAGIX\Movie_Edit_Pro_11\CDBurnProfiler.exe
2005-03-09 16:17 34304 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030717.exe

C:\MAGIX\Movie_Edit_Pro_11\CPUINF32.DLL
2003-04-03 11:09 49152 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030505.DLL

C:\MAGIX\Movie_Edit_Pro_11\DAC37.DLL
2000-04-11 15:53 90112 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030506.DLL

C:\MAGIX\Movie_Edit_Pro_11\Default\fcdummy.exe
2005-10-08 17:14 40960 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030582.exe

C:\MAGIX\Movie_Edit_Pro_11\DSETUP.dll
2002-12-11 10:58 60416 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030507.dll

C:\MAGIX\Movie_Edit_Pro_11\DVD\WMV_DISC\components\shelexec.exe
1997-10-15 22:03 18944 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030589.exe

C:\MAGIX\Movie_Edit_Pro_11\DVD\WMV_DISC\components\videowritetest.exe
2003-11-04 18:20 6144 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030590.exe

C:\MAGIX\Movie_Edit_Pro_11\DVD\WMV_DISC\licgen.exe
2004-09-13 13:29 200704 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030584.exe

C:\MAGIX\Movie_Edit_Pro_11\DVD\WMV_DISC\WMDS.dll
2003-10-09 11:56 513088 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030586.dll

C:\MAGIX\Movie_Edit_Pro_11\DVDMaker.dll
2005-12-15 15:42 1302528 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030685.dll

C:\MAGIX\Movie_Edit_Pro_11\DynDVDMenu.dll
2004-08-17 16:11 460800 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030509.dll

C:\MAGIX\Movie_Edit_Pro_11\eModeUpgradeDlg.dll
2004-10-18 17:15 212992 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030777.dll

C:\MAGIX\Movie_Edit_Pro_11\explore.exe
2003-02-12 11:20 28672 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030684.exe

C:\MAGIX\Movie_Edit_Pro_11\FxVdx30.dll
2001-05-25 14:12 315392 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030720.dll

C:\MAGIX\Movie_Edit_Pro_11\GmDV2Mpeg.dll
2002-11-07 11:41 86016 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030510.dll

C:\MAGIX\Movie_Edit_Pro_11\GmDvsd.dll
2002-12-30 13:10 184320 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030511.dll

C:\MAGIX\Movie_Edit_Pro_11\GMEdit.dll
2004-03-17 16:34 1736704 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030512.dll

C:\MAGIX\Movie_Edit_Pro_11\GmProK7.dll
2004-12-06 12:49 696320 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030513.dll

C:\MAGIX\Movie_Edit_Pro_11\GmProP3.dll
2004-12-06 12:49 798720 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030514.dll

C:\MAGIX\Movie_Edit_Pro_11\GmProP4.dll
2004-12-06 12:49 806912 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030515.dll

C:\MAGIX\Movie_Edit_Pro_11\GmProP5.dll
2004-12-06 12:49 806912 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030516.dll

C:\MAGIX\Movie_Edit_Pro_11\GmVfwCap.dll
2002-03-07 08:59 139264 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030517.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMo4E.dll
2002-08-20 11:36 1667072 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030518.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMoK7.dll
2004-12-06 12:49 696320 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030519.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMoK7x.dll
2004-12-06 12:49 696320 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030520.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMoP2.dll
2004-12-06 12:49 688128 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030521.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMoP2x.dll
2004-12-06 12:49 688128 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030522.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMoP3.dll
2004-12-06 12:49 798720 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030523.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMoP3x.dll
2004-12-06 12:49 798720 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030524.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMoP4.dll
2004-12-06 12:49 811008 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030525.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMoP5.dll
2004-12-06 12:49 811008 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030526.dll

C:\MAGIX\Movie_Edit_Pro_11\GoMotion.dll
2005-10-03 16:18 335872 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030527.dll

C:\MAGIX\Movie_Edit_Pro_11\hhrashlp.dll
2000-08-18 10:57 28672 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030529.dll

C:\MAGIX\Movie_Edit_Pro_11\HHWMPrxy.dll
2004-05-27 16:59 40960 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030530.dll

C:\MAGIX\Movie_Edit_Pro_11\IJL10.DLL
1999-02-09 10:46 137728 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030531.DLL

C:\MAGIX\Movie_Edit_Pro_11\instslct.exe
2005-08-22 17:26 176128 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030704.exe

C:\MAGIX\Movie_Edit_Pro_11\LFBMP13N.DLL
2002-09-12 09:36 30208 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030532.DLL

C:\MAGIX\Movie_Edit_Pro_11\LFCMP13n.DLL
2002-09-12 09:39 392704 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030533.DLL

C:\MAGIX\Movie_Edit_Pro_11\LFFAX13N.DLL
2002-09-12 09:36 73216 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030534.DLL

C:\MAGIX\Movie_Edit_Pro_11\lfgif13n.dll
2001-11-16 18:50 35840 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030535.dll

C:\MAGIX\Movie_Edit_Pro_11\LFMSP13N.DLL
2002-09-12 09:36 18944 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030536.DLL

C:\MAGIX\Movie_Edit_Pro_11\LFPCD13N.DLL
2002-09-12 09:36 19968 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030537.DLL

C:\MAGIX\Movie_Edit_Pro_11\LFPCX13N.DLL
2002-09-12 09:36 26112 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030538.DLL

C:\MAGIX\Movie_Edit_Pro_11\Lfpng13n.dll
2002-09-12 09:40 181248 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030539.dll

C:\MAGIX\Movie_Edit_Pro_11\LFPNM13n.dll
2002-09-12 09:37 31232 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030540.dll

C:\MAGIX\Movie_Edit_Pro_11\LFPSD13N.DLL
2002-09-12 09:37 55296 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030541.DLL

C:\MAGIX\Movie_Edit_Pro_11\LFRAS13N.DLL
2002-09-12 09:37 20480 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030542.DLL

C:\MAGIX\Movie_Edit_Pro_11\LFTGA13N.DLL
2002-09-12 09:37 24576 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030543.DLL

C:\MAGIX\Movie_Edit_Pro_11\LFTIF13N.DLL
2002-09-12 09:39 126464 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030544.DLL

C:\MAGIX\Movie_Edit_Pro_11\LTCLR13n.dll
2002-09-11 11:26 1684992 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030545.dll

C:\MAGIX\Movie_Edit_Pro_11\LTDIS13n.dll
2002-09-12 09:36 265728 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030546.dll

C:\MAGIX\Movie_Edit_Pro_11\LTEFX13N.DLL
2002-09-12 09:36 205312 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030547.DLL

C:\MAGIX\Movie_Edit_Pro_11\LTFIL13N.DLL
2002-09-12 09:36 139264 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030548.DLL

C:\MAGIX\Movie_Edit_Pro_11\LTIMG13N.DLL
2002-09-12 09:36 445952 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030549.DLL

C:\MAGIX\Movie_Edit_Pro_11\LTKRN13N.DLL
2002-09-12 09:35 445440 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030550.DLL

C:\MAGIX\Movie_Edit_Pro_11\MagixOFA-uk.dll
2005-12-20 16:57 81920 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030687.dll

C:\MAGIX\Movie_Edit_Pro_11\MagixOFA.dll
2005-12-20 16:57 626688 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030551.dll

C:\MAGIX\Movie_Edit_Pro_11\MagixUpdater.exe
2004-04-15 15:48 32768 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030778.exe

C:\MAGIX\Movie_Edit_Pro_11\mdabase.dll
2005-12-08 13:22 251904 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030552.dll

C:\MAGIX\Movie_Edit_Pro_11\MDLL32.DLL
2003-10-20 11:29 49152 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030553.DLL

C:\MAGIX\Movie_Edit_Pro_11\MFL.dll
2005-08-01 15:40 442368 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030554.dll

C:\MAGIX\Movie_Edit_Pro_11\MovieEdit.exe
2006-05-30 14:30 10125312 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030703.exe

C:\MAGIX\Movie_Edit_Pro_11\MP3UTIL.DLL
2001-09-05 16:23 55808 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030555.DLL

C:\MAGIX\Movie_Edit_Pro_11\MumaIpl.dll
2002-02-22 15:32 24576 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030556.dll

C:\MAGIX\Movie_Edit_Pro_11\MumaIplA6.dll
2002-02-22 15:32 983040 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030557.dll

C:\MAGIX\Movie_Edit_Pro_11\MumaIplM6.dll
2002-02-22 15:32 942080 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030558.dll

C:\MAGIX\Movie_Edit_Pro_11\MumaIplP6.dll
2002-02-22 15:32 815104 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030559.dll

C:\MAGIX\Movie_Edit_Pro_11\MumaIplPX.dll
2002-02-22 15:32 811008 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030560.dll

C:\MAGIX\Movie_Edit_Pro_11\MumaIplW7.dll
2002-02-22 15:32 987136 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030561.dll

C:\MAGIX\Movie_Edit_Pro_11\MxAutoUpdate.dll
2005-08-15 16:31 237568 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030692.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\AudioVis.dll
2000-08-29 16:13 176128 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030723.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\Dac32.dll
2002-10-06 17:48 131072 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030724.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\EXIF09.dll
2004-08-19 12:51 45056 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030725.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\HHWM9Prxy.dll
2003-04-09 17:30 40960 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030726.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\HHWMPrxy.dll
2003-02-20 08:51 28672 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030727.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\HtmlWH.dll
1998-10-15 17:28 85504 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030762.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\IJL10.DLL
1999-02-09 11:46 137728 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030728.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\INETWH32.dll
1999-01-28 14:44 49152 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030763.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFBMP13N.DLL
2002-09-12 09:36 30208 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030730.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFCMP13n.DLL
2002-09-12 09:39 392704 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030731.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFFAX13N.DLL
2002-09-12 09:36 73216 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030732.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFMSP13N.DLL
2002-09-12 09:36 18944 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030733.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFPCD13N.DLL
2002-09-12 09:36 19968 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030734.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFPCX13N.DLL
2002-09-12 09:36 26112 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030735.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\Lfpng13n.dll
2002-09-12 09:40 181248 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030736.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFPNM13n.dll
2002-09-12 09:37 31232 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030737.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFPSD13N.DLL
2002-09-12 09:37 55296 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030738.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFRAS13N.DLL
2002-09-12 09:37 20480 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030739.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFTGA13N.DLL
2002-09-12 09:37 24576 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030740.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LFTIF13N.DLL
2002-09-12 09:39 126464 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030741.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\libexpat.dll
2003-10-21 00:11 143360 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030742.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LTCLR13n.dll
2002-09-11 11:26 1684992 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030743.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LTDIS13n.dll
2002-09-12 09:36 265728 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030744.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LTEFX13N.DLL
2002-09-12 09:36 205312 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030745.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LTFIL13N.DLL
2002-09-12 09:36 139264 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030746.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LTIMG13N.DLL
2002-09-12 09:36 445952 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030747.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\LTKRN13N.DLL
2002-09-12 09:35 445440 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030748.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\Ltwvc13n.dll
2002-09-12 09:38 1013248 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030749.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\MediaManager.exe
2004-11-09 17:01 4620288 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030759.exe

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\mpeg2.dll
2004-08-20 15:16 144896 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030750.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\MXTLC.dll
2004-08-26 17:07 233472 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030751.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\PlayRIpl.dll
2004-08-03 11:43 716800 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030752.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\QMP2.dll
2001-02-20 18:51 60928 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030753.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\QMP2DC.DLL
2001-02-20 18:52 107008 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030754.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\ROBOEX32.DLL
2002-09-21 00:33 1089536 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030764.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\thunk16.dll
2003-01-28 12:23 3200 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030755.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\thunk3216.dll
2003-01-28 12:18 40960 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030756.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\CDR_MediaManager\UNZDLL.DLL
1997-12-22 01:30 94208 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030757.DLL

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\Ijl10.dll
1999-02-09 10:46 137728 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030766.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\mxcdr.exe
2005-10-20 12:08 643072 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030769.exe

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\MXTLC_cdr.dll
2005-01-17 12:13 225280 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030767.dll

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\restore.exe
2005-09-05 15:13 249856 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030771.exe

C:\MAGIX\Movie_Edit_Pro_11\mxcdr\startup.exe
2004-07-12 11:58 45056 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030772.exe

C:\MAGIX\Movie_Edit_Pro_11\MXTLC.dll
2005-11-10 15:44 471040 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030693.dll

C:\MAGIX\Movie_Edit_Pro_11\optgraph.dll
2006-06-02 07:52 118784 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030781.dll

C:\MAGIX\Movie_Edit_Pro_11\PlayRIpl.dll
2001-05-10 17:26 20480 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030562.dll

C:\MAGIX\Movie_Edit_Pro_11\PlayRIplPX.dll
2001-05-10 17:26 638976 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030563.dll

C:\MAGIX\Movie_Edit_Pro_11\Plugins\DSETUP.dll
2003-08-18 15:14 60416 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030601.dll

C:\MAGIX\Movie_Edit_Pro_11\Plugins\MORPH.dll
2005-11-03 12:41 917504 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030604.dll

C:\MAGIX\Movie_Edit_Pro_11\Plugins\MX3dVfx_DXCreator.dll
2005-01-19 17:46 40960 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030605.dll

C:\MAGIX\Movie_Edit_Pro_11\Plugins\MX3dVfx_Manager.dll
2005-11-03 12:41 282624 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030606.dll

C:\MAGIX\Movie_Edit_Pro_11\Plugins\TILES.dll
2005-11-03 12:41 909312 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030609.dll

C:\MAGIX\Movie_Edit_Pro_11\pncrt.dll
2001-06-22 16:31 278528 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030564.dll

C:\MAGIX\Movie_Edit_Pro_11\Preview.dll
2002-10-02 10:56 28672 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030565.dll

C:\MAGIX\Movie_Edit_Pro_11\qtmlClient.dll
2002-10-31 12:40 237568 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030566.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\atrc3260.dll
2002-10-14 08:28 73728 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030613.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\cook3260.dll
2002-10-14 08:05 65536 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030614.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\drv23260.dll
2002-10-14 08:29 176128 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030615.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\drv33260.dll
2002-10-14 07:59 208896 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030616.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\drv43260.dll
2002-10-14 08:07 217088 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030617.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\erv23260.dll
2002-10-14 08:29 294912 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030618.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\erv33260.dll
2002-10-14 07:59 204800 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030619.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\erv43260.dll
2002-10-14 08:07 299008 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030620.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\rnco3260.dll
2002-10-14 07:44 536576 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030621.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\rv203260.dll
2002-10-14 08:29 98304 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030622.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\rv303260.dll
2002-10-14 07:59 94208 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030623.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\rv403260.dll
2002-10-14 08:07 90112 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030624.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\codecs\sipr3260.dll
2002-10-14 08:28 102400 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030625.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\common\encn3260.dll
2002-10-14 07:54 393216 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030626.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\common\remb3260.dll
2002-10-14 08:02 364544 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030627.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\plugins\auth3260.dll
2002-10-14 07:54 49152 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030628.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\plugins\basc3260.dll
2002-10-14 07:54 40960 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030629.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\plugins\ntau3260.dll
2002-10-14 07:54 45056 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030630.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\plugins\rmwr3260.dll
2002-10-14 07:55 245760 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030631.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\plugins\rn5a3260.dll
2002-10-14 07:54 45056 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030632.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\plugins\sdpp3260.dll
2002-10-14 07:53 61440 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030633.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\plugins\smpl3260.dll
2002-10-14 08:04 65536 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030634.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\plugins\xmlp3261.dll
2002-10-14 07:43 86016 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030635.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\enlv3260.dll
2002-10-14 07:54 36864 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030636.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\file3290.dll
2002-10-14 08:04 45056 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030637.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\riav3290.dll
2002-10-14 07:49 65536 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030638.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rica3290.dll
2002-10-14 07:50 266240 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030639.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rids3290.dll
2002-10-14 07:51 167936 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030640.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rims3290.dll
2002-10-14 08:02 57344 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030641.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rimv3290.dll
2002-10-14 07:50 77824 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030642.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\riwv3290.dll
2002-10-14 07:56 36864 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030643.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rmme3260.dll
2002-09-06 09:10 548864 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030644.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rmse3290.dll
2002-10-14 08:03 737280 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030645.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rmto3260.dll
2002-09-06 09:10 352256 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030646.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rogb3290.dll
2002-10-14 07:54 65536 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030647.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rorb3290.dll
2002-10-14 08:02 327680 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030648.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rorw3290.dll
2002-10-14 07:56 245760 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030649.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rslo3290.dll
2002-10-14 07:53 180224 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030650.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtae3290.dll
2002-10-14 07:57 114688 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030651.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtal3290.dll
2002-10-14 07:56 53248 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030652.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtam3290.dll
2002-10-14 07:57 57344 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030653.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtcc3290.dll
2002-10-14 07:54 53248 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030654.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtep3290.dll
2002-10-14 08:02 53248 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030655.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtfc3290.dll
2002-10-14 08:02 53248 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030656.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtin3290.dll
2002-10-14 08:00 65536 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030657.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtla3290.dll
2002-10-14 07:57 49152 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030658.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtnf3290.dll
2002-10-14 07:57 61440 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030659.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtpr3290.dll
2002-10-14 07:57 61440 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030660.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtrx3290.dll
2002-10-14 07:54 331776 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030661.dll

C:\MAGIX\Movie_Edit_Pro_11\RealDlls\tools\rtve3290.dll
2002-10-14 08:00 163840 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030662.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\AudioVis.dll
2000-08-29 16:13 176128 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030663.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\mpeg2.dll
2006-03-29 16:36 205312 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030695.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\mxavird.dll
2003-01-29 12:41 90112 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030677.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\MXAVIREADER.dll
2006-01-05 15:19 77824 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030696.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\MxExp.dll
2005-12-16 11:42 655360 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030697.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\MxMp3s.dll
2005-12-16 17:49 835584 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030698.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\MXMPEG2.dll
2006-03-29 16:36 98304 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030699.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\MxQtm.dll
2005-12-16 16:29 303104 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030700.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\MXVisuals.dll
2004-02-23 12:11 28672 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030678.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\RenderVisual.dll
2003-04-16 12:02 176128 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030680.dll

C:\MAGIX\Movie_Edit_Pro_11\RegModule\WMServerReader.dll
2005-09-09 09:06 151552 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030683.dll

C:\MAGIX\Movie_Edit_Pro_11\reinstall3rdParty.exe
2005-05-20 14:10 192512 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030785.exe

C:\MAGIX\Movie_Edit_Pro_11\RemoveWaggle.dll
2003-04-15 11:42 102400 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030567.dll

C:\MAGIX\Movie_Edit_Pro_11\riched20.dll
1999-12-10 13:00 431376 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030779.dll

C:\MAGIX\Movie_Edit_Pro_11\Rn5b3260.dll
1998-11-05 11:07 102400 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030702.dll

C:\MAGIX\Movie_Edit_Pro_11\SAMSIG.DLL
2002-06-24 12:00 20480 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030568.DLL

C:\MAGIX\Movie_Edit_Pro_11\samsigA6.dll
2002-06-24 12:00 192512 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030569.dll

C:\MAGIX\Movie_Edit_Pro_11\samsigM5.dll
2002-06-24 12:00 155648 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030570.dll

C:\MAGIX\Movie_Edit_Pro_11\samsigM6.dll
2002-06-24 12:00 163840 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030571.dll

C:\MAGIX\Movie_Edit_Pro_11\samsigP5.dll
2002-06-24 12:00 86016 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030572.dll

C:\MAGIX\Movie_Edit_Pro_11\samsigP6.dll
2002-06-24 12:00 147456 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030573.dll

C:\MAGIX\Movie_Edit_Pro_11\samsigPX.dll
2002-06-24 12:00 86016 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030574.dll

C:\MAGIX\Movie_Edit_Pro_11\samsigW7.dll
2002-06-24 12:00 204800 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030575.dll

C:\MAGIX\Movie_Edit_Pro_11\StdPropPage.dll
2005-10-04 20:03 192512 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030694.dll

C:\MAGIX\Movie_Edit_Pro_11\thunk16.dll
2003-01-28 11:23 3200 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030576.dll

C:\MAGIX\Movie_Edit_Pro_11\thunk3216.dll
2003-01-28 11:18 40960 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030577.dll

C:\MAGIX\Movie_Edit_Pro_11\Trayserver.exe
2004-09-29 13:50 69632 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030578.exe

C:\MAGIX\Movie_Edit_Pro_11\uninstall.exe
2005-06-22 15:42 128512 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030787.exe

C:\MAGIX\Movie_Edit_Pro_11\unwise.exe
2006-03-22 16:23 176128 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030705.exe

C:\MAGIX\Movie_Edit_Pro_11\UNZDLL.DLL
1997-12-22 01:30 94208 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030579.DLL

C:\MAGIX\Movie_Edit_Pro_11\Validation.exe
2006-02-27 10:43 24576 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030780.exe

C:\MAGIX\Movie_Edit_Pro_11\VstConfig.exe
2001-05-23 12:03 372808 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030721.exe

C:\MAGIX\Movie_Edit_Pro_11\ZIPDLL.DLL
2004-10-22 16:41 118784 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030581.DLL

2008-08-22 15:20 9093120 C:\Program Files\AdwareAlert\AdwareAlert.exe
2008-08-20 07:08 9093120 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP81\A0086577.exe
2008-08-23 18:49 9093120 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086585.exe

2008-08-22 15:16 790528 C:\Program Files\AdwareAlert\SpyCleaner.dll
2008-08-20 07:05 790528 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP81\A0086576.dll
2008-08-23 18:49 790528 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086586.dll

2008-08-22 15:15 159744 C:\Program Files\AdwareAlert\TCL.dll
{1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP81\A0086579.dllC:\Program Files\AdwareAlert\TCL.dll
2008-08-23 18:49 159744 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086581.dll

2008-08-22 15:12 155648 C:\Program Files\AdwareAlert\zlib.dll
2008-08-20 07:01 155648 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP81\A0086578.dll
2008-08-23 18:49 155648 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086582.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Album.dll
2003-01-15 17:26 258048 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032554.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\AlbumBase.dll
2002-06-05 17:17 339968 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032553.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\ArcInet.dll
2001-06-14 16:20 69632 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032552.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\BJEPMAN.dll
2002-08-07 14:45 135168 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032534.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Brush.dll
2002-09-09 12:58 110592 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032551.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\c2c.dll
2001-09-13 17:39 69632 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032531.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\c2cdel.exe
2001-09-13 17:39 64000 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032530.exe

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\cdac01aa.dll
2001-09-13 14:32 31952 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032529.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\cdac01ba.dll
2001-09-13 14:32 47104 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032528.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\CdaLMS.exe
2001-09-13 14:32 1130389 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032527.exe

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\cdilla51.dll
2001-09-13 14:32 8208 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032526.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\cdilla52.dll
2001-09-13 14:32 58368 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032525.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\DGUI.dll
1999-11-12 10:41 57344 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032550.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\DibPro.dll
2002-10-16 14:45 389120 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032549.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\eeUi.dll
2002-11-05 17:47 200704 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032548.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\EXIF.dll
2002-10-18 13:37 331776 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032547.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\EzDll.dll
2002-12-16 23:47 724992 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032546.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Filefpx.dll
1997-12-23 18:34 115712 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032545.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Fpxlib.dll
2002-01-18 14:46 332800 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032544.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\ImgPro.dll
2002-11-08 18:17 65536 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032543.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Jpeglib.dll
2002-01-18 14:47 122880 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032542.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Macro.dll
2002-11-05 14:41 139264 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032541.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\myCtrl.dll
2002-11-04 18:19 122880 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032540.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\PhotoStudio.exe
2003-03-13 14:03 279040 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032523.exe

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\piapi.dll
2001-11-27 13:50 61440 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032539.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Plug-Ins\Filters\3D Text Factory\3DTextPlugInRes.dll
2002-05-16 11:30 106496 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032504.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\PScan.dll
2002-09-10 20:18 94208 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032538.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\psplug.dll
2001-12-04 12:49 53248 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032537.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\RDisk.dll
2003-01-13 22:56 188416 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032536.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Res_Dll.dll
2002-11-15 13:39 225280 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032508.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Res_ps.dll
2002-10-11 12:46 2592768 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032506.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\Sti.dll
1998-05-11 22:01 61440 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032535.dll

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\THK16.DLL
2001-03-08 00:07 4608 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032533.DLL

C:\Program Files\ArcSoft\Software Suite\PhotoStudio\thk32.dll
2001-03-04 23:35 14848 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032532.dll

C:\Program Files\ArcSoft\Software Suite\Web Registration\ArcRegister.exe
2002-06-06 11:57 131072 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032555.exe

C:\Program Files\Core Design\Tomb Raider Chronicles (Demo)\binkw32.dll
2000-09-12 02:09 291840 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0032437.dll

C:\Program Files\Core Design\Tomb Raider Chronicles (Demo)\PCTomb5.exe
2001-07-20 14:54 880697 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0032436.exe

2005-10-20 12:04 38912 C:\Program Files\ERUNT\AUTOBACK.EXE
2005-10-20 12:04 38912 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086634.EXE

2005-10-20 12:00 157696 C:\Program Files\ERUNT\ERUNT.EXE
2005-10-20 12:00 157696 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086633.EXE

2005-10-20 12:03 140288 C:\Program Files\ERUNT\NTREGOPT.EXE
2005-10-20 12:03 140288 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086632.EXE

2004-06-27 01:00 77257 C:\Program Files\ERUNT\unins000.exe
2004-06-27 01:00 77257 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086635.exe

C:\Program Files\InstallShield Installation Information\{80D95911-28E9-40AC-A6B5-1DA6D9F14B29}\Setup.exe
2001-09-05 00:23 56320 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP78\A0032560.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam-dor.exe
2008-08-17 15:01 380024 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086621.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll
2008-08-17 15:01 61048 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086622.dll

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
2008-08-17 15:01 1195640 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086620.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
2008-08-17 15:01 73336 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086618.dll

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
2008-08-17 15:01 110200 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086613.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamtrayctrl.exe
2008-08-17 15:01 372344 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086614.exe

C:\Program Files\Malwarebytes' Anti-Malware\ssubtmr6.dll
2008-08-17 15:01 44664 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086616.dll

C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe
2008-08-23 18:19 688760 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086623.exe

C:\Program Files\Malwarebytes' Anti-Malware\zlib.dll
2008-08-17 15:01 77944 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP82\A0086617.dll

C:\Program Files\Microsoft Games\Age of Empires II\clcd16.dll
1999-09-14 13:43 6784 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031091.dll

C:\Program Files\Microsoft Games\Age of Empires II\clcd32.dll
1999-09-14 13:43 27648 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031090.dll

C:\Program Files\Microsoft Games\Age of Empires II\clokspl.exe
1999-09-14 13:43 177152 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031089.exe

C:\Program Files\Microsoft Games\Age of Empires II\Data\closedpw.exe
1997-09-09 15:44 29184 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031106.exe

C:\Program Files\Microsoft Games\Age of Empires II\DPLAY61A.EXE
1999-06-18 12:35 485600 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031092.EXE

C:\Program Files\Microsoft Games\Age of Empires II\dplayerx.dll
1999-09-14 13:43 163328 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031088.dll

C:\Program Files\Microsoft Games\Age of Empires II\drvmgt.dll
1999-09-14 13:43 32256 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031087.dll

C:\Program Files\Microsoft Games\Age of Empires II\EBUEula.dll
1999-09-02 06:41 53304 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031098.dll

C:\Program Files\Microsoft Games\Age of Empires II\empires2.exe
1999-09-14 13:43 280307 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031097.exe

C:\Program Files\Microsoft Games\Age of Empires II\HA312W32.DLL
1998-09-27 23:01 365568 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031095.DLL

C:\Program Files\Microsoft Games\Age of Empires II\language.dll
1999-09-08 02:25 499712 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031094.dll

C:\Program Files\Microsoft Games\Age of Empires II\SHW32.DLL
1998-11-03 05:10 112688 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0031093.DLL

C:\Program Files\SecondLife\alut.dll
2008-07-07 18:06 131072 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030864.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\auth.dll
2008-07-07 18:05 14848 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030821.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\autoconfig.dll
2008-07-07 18:05 19456 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030820.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\pipboot.dll
2008-07-07 18:05 18944 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030819.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\pipnss.dll
2008-07-07 18:05 225280 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030818.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\pippki.dll
2008-07-07 18:05 19968 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030817.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\transformiix.dll
2008-07-07 18:05 200704 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030816.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\universalchardet.dll
2008-07-07 18:05 110592 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030815.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\websrvcs.dll
2008-07-07 18:05 282624 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030814.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\xmlextras.dll
2008-07-07 18:05 15872 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030813.dll

C:\Program Files\SecondLife\app_settings\mozilla\components\xulutil.dll
2008-07-07 18:05 7680 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030812.dll

C:\Program Files\SecondLife\app_settings\mozilla\plugins\npnul32.dll
2008-07-07 18:05 17408 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030811.dll

C:\Program Files\SecondLife\dbghelp.dll
2008-07-07 18:07 813568 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030863.dll

C:\Program Files\SecondLife\fmod.dll
2008-07-07 18:07 161280 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030862.dll

C:\Program Files\SecondLife\freebl3.dll
2008-07-07 18:02 200704 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030861.dll

C:\Program Files\SecondLife\gksvggdiplus.dll
2008-07-07 18:02 37888 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030860.dll

C:\Program Files\SecondLife\js3250.dll
2008-07-07 18:02 462848 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030859.dll

C:\Program Files\SecondLife\libeay32.dll
2008-07-07 18:06 1064960 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030858.dll

C:\Program Files\SecondLife\llkdu.dll
2008-07-18 13:58 684032 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030857.dll

C:\Program Files\SecondLife\msvcp71.dll
2008-07-07 18:07 499712 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030856.dll

C:\Program Files\SecondLife\msvcr71.dll
2008-07-07 18:07 348160 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030855.dll

C:\Program Files\SecondLife\nspr4.dll
2008-07-07 18:02 159744 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030854.dll

C:\Program Files\SecondLife\nss3.dll
2008-07-07 18:02 380928 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030853.dll

C:\Program Files\SecondLife\nssckbi.dll
2008-07-07 18:02 274432 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030852.dll

C:\Program Files\SecondLife\openjpeg.dll
2008-07-07 18:02 176128 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030851.dll

C:\Program Files\SecondLife\ortp.dll
2008-07-07 18:06 143360 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030850.dll

C:\Program Files\SecondLife\plc4.dll
2008-07-07 18:02 13312 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030849.dll

C:\Program Files\SecondLife\plds4.dll
2008-07-07 18:02 9216 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030848.dll

C:\Program Files\SecondLife\SecondLife.exe
2008-07-18 14:03 16076800 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030865.exe

C:\Program Files\SecondLife\SLVoice.exe
2008-07-07 18:06 540672 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030867.exe

C:\Program Files\SecondLife\SLVoiceAgent.exe
2008-07-07 18:06 929792 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030866.exe

C:\Program Files\SecondLife\smime3.dll
2008-07-07 18:02 106496 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030847.dll

C:\Program Files\SecondLife\softokn3.dll
2008-07-07 18:02 282624 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030846.dll

C:\Program Files\SecondLife\srtp.dll
2008-07-07 18:06 102400 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030845.dll

C:\Program Files\SecondLife\ssl3.dll
2008-07-07 18:02 135168 {1D754853-CD2B-4287-9A0D-7BEC62082DED}\RP77\A0030844.dll

C:�
  • 0

#13
synesthesia

synesthesia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
I don't know if this has anything to do with a backdoor trojan or some other kind of thing infecting my computer, but a few weeks ago my computer started randomly restarting on its own while I was in the middle of doing something. I happens suddenly, without warning, and a dark blue screen comes up with a bunch of white text. I never get to read what it says because it basically just appears for a millisecond and then the screen goes black, and then it restarts. I was hoping you could tell me if this has anything to do with my computer being infected.

Thanks,
Soleil
  • 0

#14
synesthesia

synesthesia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
I just realized that the combofix log got cutoff when i posted it so i'm attaching the file to this post =]

Attached Files


  • 0

#15
Rorschach112

Rorschach112

    Ralphie

  • Retired Staff
  • 47,710 posts
Due to malware probably

Please click on Start > Control Panel > Add/Remove Programs and uninstall the following programs(if present):

PrivacyControl



1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\Fonts\wmsncs.exe
C:\WINDOWS\Help\internat.exe
C:\WINDOWS\Help\ipconfig.sys
C:\WINDOWS\Help\svchost.exe
C:\WINDOWS\Help\svchost32.exe
C:\WINDOWS\system32\a.exe
C:\WINDOWS\system32\drivers\hljc.sys
C:\WINDOWS\system32\g.bat
C:\WINDOWS\system32\spool\drivers\wmsncs.exe
C:\WINDOWS\system32\wins\wmsncs.exe
C:\WINDOWS\system32\wmsoft35025.exe

KillAll::

Folder::
C:\Documents and Settings\Soleil Robichaud\Application Data\PrivacyControl
C:\Program Files\PrivacyControl
C:\Documents and Settings\Ron Robichaud\Application Data\PrivacyControl

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"wmsncs.exe"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{103L3C30-C3B3-4130-9363-E59E1375PERM}]
[-HKEY_CLASSES_ROOT\CLSID\{103L3C30-C3B3-4130-9363-E59E1375PERM}]


Rootkit::
C:\WINDOWS\Fonts\wmsncs.exe

Driver::
NET Runtime Optimization Service v2.1.41329_X86


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP