I don't know how this happened, but it sure is wreaking havoc with Internet Explorer. It redirects every link to a page saying that my Internet connection is insecure, etc. It doesn't let me browse, whenever I go to a new URL, a pop -up stops me, saying that a Trojan has corrupted system files and I need to go to this link to stop it. Knowing better, I didn't click it. However, this problem still isn't getting any better. Luckily for me, I have an alternate browser I usually use. Nevertheless, could you please check this log? It gets really annoying after a while.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:14 PM, on 29/06/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Safari\Safari.exe
C:\Users\Calvin\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/?lang=en-CA
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\PROGRA~1\SPEEDB~1\vaproxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Spybot-S&D IE Protection - {B1892F58-1116-4DEC-92AA-577872EC3D3D} - C:\Windows\system32\xmlwin.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v ... b56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
--
End of file - 9654 bytes
EDIT: Now, explorer.exe is closing and not restarting, unless I start is from Task Manager. However, it still closes within the first 10 seconds after I open it. Knowing that I will need a ComboFix log, here it is:
ComboFix 08-06-20.4 - Calvin 2008-06-30 9:27:27.10 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1995 [GMT -7:00]
Running from: C:\Users\Calvin\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.
2008-06-30 09:15 . 2008-06-30 09:15 26,624 --a------ C:\Windows\System32\xmlview.dll
2008-06-30 09:15 . 2008-06-30 09:15 24,576 --a------ C:\Windows\System32\wvUNeEtR.dll
2008-06-30 08:55 . 2008-06-30 09:02 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-06-30 08:55 . 2008-06-30 09:02 <DIR> d-------- C:\ProgramData\Lavasoft
2008-06-30 08:55 . 2008-06-30 08:55 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-29 15:21 . 2008-06-29 15:22 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\VMware
2008-06-29 15:20 . 2008-06-29 15:20 26,624 --a------ C:\Windows\System32\xmlwin.dll
2008-06-29 15:10 . 2008-05-16 00:51 50,992 --a------ C:\Windows\System32\vmnetbridge.dll
2008-06-29 15:09 . 2008-06-29 15:09 1,024 --a------ C:\.rnd
2008-06-29 15:08 . 2008-06-29 15:28 <DIR> d-------- C:\Program Files\VMware
2008-06-26 13:59 . 2008-06-26 14:24 <DIR> d-------- C:\Program Files\Opera
2008-06-25 15:40 . 2008-06-29 17:23 <DIR> d-------- C:\Program Files\Free Download Manager
2008-06-25 15:31 . 2008-06-25 15:31 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-06-25 09:47 . 2008-06-25 09:47 <DIR> d-------- C:\Program Files\Freeze.com
2008-06-25 09:39 . 2008-06-25 09:39 <DIR> d-------- C:\Program Files\Xio
2008-06-25 09:38 . 2008-06-25 09:38 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\Xion
2008-06-24 23:23 . 2008-06-24 23:23 354,560 --a------ C:\Windows\System32\TuneUpDefragService.exe
2008-06-24 23:21 . 2008-04-04 14:51 28,416 --a------ C:\Windows\System32\uxtuneup.dll
2008-06-24 23:21 . 2008-04-04 14:51 16,640 --a------ C:\Windows\System32\authuitu.dll
2008-06-24 23:20 . 2008-06-29 18:21 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-06-24 23:19 . 2008-06-30 08:54 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-23 12:45 . 2008-06-23 12:45 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\TuneUp Software
2008-06-23 12:45 . 2008-06-23 12:45 <DIR> d-------- C:\Users\All Users\TuneUp Software
2008-06-23 12:45 . 2008-06-23 12:45 <DIR> d-------- C:\ProgramData\TuneUp Software
2008-06-23 12:38 . 2008-06-23 12:38 28,812,800 --a------ C:\Windows\System32\imageres.dll
2008-06-23 12:30 . 2008-06-23 12:30 <DIR> d-------- C:\Program Files\Stardock
2008-06-23 08:20 . 2008-06-23 08:20 <DIR> d-------- C:\Users\All Users\Stardock
2008-06-23 08:20 . 2008-06-23 08:20 <DIR> d-------- C:\ProgramData\Stardock
2008-06-23 08:19 . 2007-06-05 11:26 567,040 --a------ C:\Windows\System32\wbocx.ocx
2008-06-23 08:19 . 2007-06-05 11:26 56,496 --a------ C:\Windows\System32\wbhelp2.dll
2008-06-22 09:23 . 2008-06-22 09:23 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\Sibelius Software
2008-06-22 08:49 . 2008-06-22 08:56 <DIR> d-------- C:\Program Files\Unlocker
2008-06-22 02:18 . 2006-03-03 08:07 143,360 --a------ C:\Windows\System32\dunzip32.dll
2008-06-21 19:11 . 2008-06-21 19:11 50 --a------ C:\Windows\MegaManager.INI
2008-06-17 16:52 . 2008-06-28 10:46 <DIR> d-------- C:\Program Files\PokerStars
2008-06-16 07:47 . 2008-06-16 07:47 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-06-15 11:20 . 2008-06-15 11:20 <DIR> d-------- C:\Program Files\iPod
2008-06-14 08:39 . 2008-06-14 08:39 <DIR> d--h----- C:\Windows\msdownld.tmp
2008-06-12 17:46 . 2008-06-29 18:44 <DIR> d-------- C:\Users\Mom.Calvin-PC\AppData\Roaming\Apple Computer
2008-06-10 19:50 . 2008-04-22 21:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-06-10 19:50 . 2008-04-22 21:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-06-10 19:50 . 2008-04-22 21:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-10 19:50 . 2008-04-22 21:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-10 17:35 . 2008-05-09 20:35 885,248 --a------ C:\Windows\System32\RacEngn.dll
2008-06-10 17:35 . 2008-05-09 15:22 9,127 --a------ C:\Windows\System32\RacUR.xml
2008-06-10 17:35 . 2008-05-09 15:22 153 --a------ C:\Windows\System32\RacUREx.xml
2008-06-10 17:34 . 2008-04-24 19:12 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-06-10 17:34 . 2008-04-26 01:08 1,314,816 --a------ C:\Windows\System32\quartz.dll
2008-06-10 17:34 . 2008-04-24 21:35 826,880 --a------ C:\Windows\System32\wininet.dll
2008-06-10 17:34 . 2008-05-09 18:33 113,664 --a------ C:\Windows\System32\drivers\rmcast.sys
2008-06-08 21:53 . 2008-06-08 21:58 <DIR> d-------- C:\Users\All Users\PrevxCSI
2008-06-08 21:53 . 2008-06-08 21:58 <DIR> d-------- C:\ProgramData\PrevxCSI
2008-06-08 16:50 . 2008-06-08 16:50 32 --a------ C:\Windows\hip
2008-06-06 06:25 . 2008-06-06 06:25 <DIR> d-------- C:\Users\All Users\Microsoft Corporation
2008-06-06 06:25 . 2008-06-06 06:25 <DIR> d-------- C:\ProgramData\Microsoft Corporation
2008-06-04 23:11 . 2008-06-04 23:11 <DIR> d-------- C:\Users\All Users\PopCap
2008-06-04 23:11 . 2008-06-04 23:11 <DIR> d-------- C:\ProgramData\PopCap
2008-06-03 06:34 . 2008-06-03 06:35 <DIR> d-ahs---- C:\Users\Calvin\!
2008-06-01 09:29 . 2008-06-01 09:29 <DIR> d-------- C:\Users\Mom.Calvin-PC\AppData\Roaming\Roxio
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Videos
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Searches
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Saved Games
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Pictures
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Music
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Links
2008-06-01 09:28 . 2008-06-20 17:49 <DIR> dr------- C:\Users\Mom.Calvin-PC\Downloads
2008-06-01 09:28 . 2008-06-14 18:34 <DIR> dr------- C:\Users\Mom.Calvin-PC\Documents
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Contacts
2008-06-01 09:28 . 2006-11-02 05:37 <DIR> d-------- C:\Users\Mom.Calvin-PC\AppData\Roaming\Media Center Programs
2008-06-01 09:28 . 2008-06-04 22:08 <DIR> d--h----- C:\Users\Mom.Calvin-PC\AppData\Roaming\GTek
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> d--h----- C:\Users\Mom.Calvin-PC\AppData
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> d-------- C:\Users\Mom.Calvin-PC
2008-05-31 10:22 . 2008-05-31 10:22 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-05-27 16:41 . 2008-03-07 19:08 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-27 16:41 . 2008-03-07 21:21 1,695,744 --a------ C:\Windows\System32\gameux.dll
2008-05-27 10:50 . 2008-05-27 10:50 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 --a------ C:\Windows\System32\QuickTime.qts
2008-05-24 15:57 . 2008-05-25 07:44 <DIR> d-------- C:\Program Files\EA GAMES
2008-05-24 15:57 . 2004-08-18 02:17 442,368 -ra------ C:\Windows\System32\vp6vfw.dll
2008-05-24 10:38 . 2008-05-24 10:38 717,296 --a------ C:\Windows\System32\drivers\sptd.sys
2008-05-24 10:37 . 2008-05-24 10:37 <DIR> d-a------ C:\Users\Calvin\AppData\Roaming\DAEMON Tools
2008-05-22 19:19 . 2008-05-22 19:19 <DIR> d-------- C:\PerfLogs
2008-05-22 17:18 . 2008-01-19 00:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-05-22 17:17 . 2008-01-19 00:33 8,139,264 --a------ C:\Windows\System32\ssBranded.scr
2008-05-22 17:16 . 2008-01-19 00:36 2,588,160 --a------ C:\Windows\System32\UIHub.dll
2008-05-22 17:15 . 2008-01-19 00:34 6,103,040 --a------ C:\Windows\System32\chtbrkr.dll
2008-05-22 17:14 . 2008-06-27 11:08 8,372,224 --a------ C:\Windows\System32\wmploc.dll
2008-05-22 17:13 . 2008-01-19 00:33 599,552 --a------ C:\Windows\System32\vsp1cln.exe
2008-05-22 17:13 . 2008-01-05 04:31 145,455 --a------ C:\Windows\System32\perfmon.msc
2008-05-22 17:13 . 2008-01-05 04:31 3 --a------ C:\Windows\System32\drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf
2008-05-22 17:12 . 2008-01-19 00:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-05-22 17:12 . 2008-01-19 00:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-05-22 17:12 . 2008-01-19 00:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-05-22 17:12 . 2008-01-19 00:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-05-22 17:12 . 2008-01-19 00:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-05-22 17:12 . 2008-01-19 00:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-05-22 17:12 . 2008-01-19 00:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-05-22 17:12 . 2008-01-19 00:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-05-22 17:11 . 2008-01-19 00:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-05-18 18:07 . 2008-05-18 18:07 671 --a------ C:\Windows\System32\newaddies.xtc
2008-05-18 18:03 . 2008-05-31 12:37 <DIR> d--h----- C:\Users\~Administrator~\AppData
2008-05-18 18:03 . 2008-05-31 12:37 <DIR> d-------- C:\Users\~Administrator~
2008-05-18 11:19 . 2008-06-29 17:54 <DIR> d-------- C:\Program Files\Eusing Free Registry Cleaner
2008-05-17 21:13 . 2008-05-17 21:17 <DIR> d-------- C:\Program Files\GRETECH
2008-05-17 08:03 . 2008-06-04 22:48 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\Windows\System32\lsdelete.exe
2008-05-16 07:48 . 2008-05-16 07:54 <DIR> d-------- C:\Program Files\ShellExView
2008-05-16 07:48 . 2008-05-16 07:48 39,424 --a------ C:\Windows\zipinst.exe
2008-05-15 18:33 . 2008-05-15 18:45 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-05-15 17:29 . 2008-06-03 23:19 <DIR> d-------- C:\DVDVideoSoft
2008-05-15 00:16 . 2008-05-15 00:16 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2008-05-13 00:07 . 2008-05-13 00:07 524,288 --ahs---- C:\ntuser.dat{c39279b4-208c-11dd-8355-00e034123456}.TMContainer00000000000000000002.regtrans-ms
2008-05-13 00:07 . 2008-06-29 15:51 524,288 --ahs---- C:\ntuser.dat{c39279b4-208c-11dd-8355-00e034123456}.TMContainer00000000000000000001.regtrans-ms
2008-05-13 00:07 . 2008-05-13 00:07 524,288 --ahs---- C:\ntuser.dat{c39279b0-208c-11dd-8355-00e034123456}.TMContainer00000000000000000002.regtrans-ms
2008-05-13 00:07 . 2008-05-13 00:07 524,288 --ahs---- C:\ntuser.dat{c39279b0-208c-11dd-8355-00e034123456}.TMContainer00000000000000000001.regtrans-ms
2008-05-13 00:07 . 2008-06-29 15:23 262,144 --a------ C:\ntuser.dat
2008-05-13 00:07 . 2008-06-29 15:51 65,536 --ahs---- C:\ntuser.dat{c39279b4-208c-11dd-8355-00e034123456}.TM.blf
2008-05-13 00:07 . 2008-05-13 00:07 65,536 --ahs---- C:\ntuser.dat{c39279b0-208c-11dd-8355-00e034123456}.TM.blf
2008-05-13 00:07 . 2008-06-29 15:23 5,120 --ah----- C:\ntuser.dat.LOG1
2008-05-13 00:07 . 2008-05-13 00:07 0 --ah----- C:\ntuser.dat.LOG2
2008-05-11 15:31 . 2008-05-11 15:31 <DIR> d-------- C:\NVIDIA
2008-05-11 12:59 . 2008-05-11 12:59 <DIR> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-05-11 12:55 . 2007-02-20 16:04 2,463,976 --a------ C:\Windows\System32\NPSWF32.dll
2008-05-11 12:55 . 2007-02-20 16:04 190,696 --a------ C:\Windows\System32\NPSWF32_FlashUtil.exe
2008-05-11 09:19 . 2008-05-11 11:53 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\Download Manager
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-30 16:07 --------- d---a-w C:\Users\Calvin\AppData\Roaming\LimeWire
2008-06-30 15:57 --------- d-----w C:\Program Files\McAfee
2008-06-30 15:51 --------- d-----w C:\Program Files\Dl_cats
2008-06-30 00:55 --------- d-----w C:\Program Files\Bonjour
2008-06-27 18:08 615,424 ----a-w C:\Windows\System32\themeui.dll
2008-06-27 18:08 240,128 ----a-w C:\Windows\System32\uxtheme.dll
2008-06-27 18:08 2,140,672 ----a-w C:\Windows\System32\authui.dll
2008-06-27 18:08 1,991,680 ----a-w C:\Windows\System32\oobefldr.dll
2008-06-25 22:27 --------- d---a-w C:\ProgramData\TEMP
2008-06-23 19:40 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-06-22 14:10 --------- d-----w C:\Program Files\Common Files\McAfee
2008-06-22 02:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 18:53 --------- d-----w C:\Program Files\Nexon
2008-06-18 22:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-15 18:20 --------- d-----w C:\Program Files\iTunes
2008-06-15 18:03 --------- d-----w C:\Program Files\QuickTime
2008-06-11 02:39 --------- d-----w C:\Program Files\Windows Mail
2008-06-04 00:12 --------- d-----w C:\Program Files\LimeWire
2008-05-31 18:31 --------- d---a-w C:\Users\Calvin\AppData\Roaming\U3
2008-05-25 04:34 --------- d-----w C:\ProgramData\Roxio
2008-05-23 03:26 --------- d-----w C:\ProgramData\NVIDIA
2008-05-23 02:33 174 --sha-w C:\Program Files\desktop.ini
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Sidebar
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Journal
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Defender
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Collaboration
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Calendar
2008-05-23 01:28 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-05-23 01:28 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-05-15 02:01 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-15 01:13 --------- d-----w C:\Program Files\Java
2008-05-14 00:05 --------- d-----w C:\Program Files\SoundSpectrum
2008-05-11 22:31 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-11 19:47 --------- d-----w C:\Program Files\Macromedia
2008-05-11 19:47 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-05-01 02:14 --------- d-----w C:\Program Files\CCleaner
2008-05-01 02:10 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Crystal Art Software
2008-04-30 06:14 --------- d-----w C:\Program Files\Dell DataSafe Online
2008-04-29 18:20 15,648 ----a-w C:\Windows\system32\drivers\NSDriver.sys
2008-04-29 18:19 15,648 ----a-w C:\Windows\system32\drivers\Awrtrd.sys
2008-04-29 18:19 12,960 ----a-w C:\Windows\system32\drivers\Awrtpd.sys
2008-04-29 05:27 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Astro Gemini Software
2008-04-29 02:54 --------- d-----w C:\Program Files\Windows Live
2008-04-29 02:46 --------- d-----w C:\ProgramData\WLInstaller
2008-04-28 00:17 --------- d-----w C:\Users\Calvin\AppData\Roaming\Hamachi
2008-04-28 00:10 25,280 ----a-w C:\Windows\system32\drivers\hamachi.sys
2008-03-31 05:01 691,545 ----a-w C:\Windows\unins000.exe
2008-03-09 01:45 21,764 ----a-w C:\Windows\System32\CoreAAC-uninstall.exe
2008-03-08 04:19 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-08 04:19 458,752 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-03-08 04:19 2,153,984 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-03-08 04:19 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-03-08 01:58 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2007-11-04 16:32 374 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb6334.dat
2007-11-04 14:50 555 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb8467.dat
2007-11-04 14:50 18,432 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb41.dat
2008-03-09 17:38 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-03-09 17:38 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-03-09 17:38 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8AE578E0-6DF5-41E0-869F-F65A32D2F6BD}]
2008-06-30 09:15 26624 --a------ C:\Windows\system32\xmlview.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1892F58-1116-4DEC-92AA-577872EC3D3D}]
2008-06-29 15:20 26624 --a------ C:\Windows\system32\xmlwin.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 00:33 125952]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 00:33 202240]
"cmds"="C:\Users\Calvin\AppData\Local\Temp\mlJCsQIa.dll" [2008-06-30 09:20 320000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 07:22 4907008 C:\Windows\RtHDVCpl.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 09:37 81920]
"dlcqmon.exe"="C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 08:47 292080]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-17 09:07 86016]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-17 09:07 81920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"DLCQCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-15 22:31 106496]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 19:56 202544]
"MSServer"="C:\Windows\system32\wvUNeEtR.dll" [2008-06-30 09:15 24576]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
C:\Users\Mom.Calvin-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [8/24/2007 5:45:42 AM 101784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{ACED1C9F-2718-4512-9F69-F4E28C1F484F}"= C:\Windows\system32\wvUNeEtR.dll [2008-06-30 09:15 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-19 00:33 202240 C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
"Dell DataSafe Scheduler"="C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe_ID0EYTHM"=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
"ECenter"=c:\dell\E-Center\EULALauncher.exe
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C40A1CDE-3524-47EB-AB86-D043632CF06D}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{95A5E1FA-64AB-4ADB-AC4D-3DF2E0B735B6}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9164ED87-D1FE-4206-8496-29DEC6BBB6D0}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{204B31F1-64E0-4F04-B55D-73DE3A458B3F}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{189B5808-CF71-49AB-94CA-02B985EA3914}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{E162012F-98CF-4888-8A39-00328A767F10}C:\\program files\\nexon\\maplestory\\maplestory.exe"= UDP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{2FB30AAD-97FB-4027-8C8D-3FA7FDCF7BFE}C:\\program files\\nexon\\maplestory\\maplestory.exe"= TCP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{A0186F92-7442-4DC0-9CDF-695C1370EE4F}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= UDP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"UDP Query User{FCD1575D-BBD4-4794-AD79-F7C3406AE999}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= TCP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"TCP Query User{4E10DA99-3C04-4667-9F89-F36A44B45368}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= UDP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"UDP Query User{79088905-9F9D-4D68-9C4F-512196042A94}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= TCP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"TCP Query User{C5CBBF51-2752-40A6-A2C0-DC8A40B3B8F6}C:\\users\\calvin\\saved games\\nexon\\newpatcher.exe"= UDP:C:\users\calvin\saved games\nexon\newpatcher.exe:newpatcher.exe
"UDP Query User{BFE9CE8F-1C04-4B88-8B32-CAD967AF13DA}C:\\users\\calvin\\saved games\\nexon\\newpatcher.exe"= TCP:C:\users\calvin\saved games\nexon\newpatcher.exe:newpatcher.exe
"TCP Query User{871E1A48-AEBC-4085-BAED-C787EC6E21F1}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= UDP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"UDP Query User{326FF41C-497D-4D03-8513-22EBAC3AC34A}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= TCP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"TCP Query User{37A6A56D-37BC-40E8-9018-8069A4C66930}C:\\program files\\nexon\\maplestory\\maplestory.exe"= UDP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{A5CF2920-5E05-4607-BCEE-DA15A6B8B0A0}C:\\program files\\nexon\\maplestory\\maplestory.exe"= TCP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{3FE2B734-5BFA-4A80-84A8-87DC826F8C00}C:\\windows\\explorer.exe"= UDP:C:\windows\explorer.exe:Windows Explorer
"UDP Query User{5FD30CFD-6BAB-4702-9497-098A7B9A67B4}C:\\windows\\explorer.exe"= TCP:C:\windows\explorer.exe:Windows Explorer
"{ECEF8CF6-AFE4-4A65-A2EF-8691D9A93C3E}"= UDP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{79C9CF6E-0E9A-41AB-861D-8EAE4CF907B2}"= TCP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"TCP Query User{80CCF7DE-E26B-40A8-836A-638BA1A87700}C:\\nexon\\maplestory\\maplestory.exe"= UDP:C:\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{71B875FE-9E27-418C-A965-496F8303828E}C:\\nexon\\maplestory\\maplestory.exe"= TCP:C:\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{D3C1ECFA-5DAD-42A3-8DAA-1896FE6B3BEA}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{E2A310D1-7EB4-4C86-94ED-A1764FE80CA3}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"{24BECBA1-8C8C-4B02-9916-4EEB02766C48}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{39FBCFD1-2DF2-4251-AF7F-3C3685B06BB7}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{34A08745-C53B-4350-BBF6-B3E8C45B0762}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe:
"UDP Query User{4FA8BA5C-B3B3-4BB2-B2CE-DAED6CF66DFD}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe:
"TCP Query User{A3D3605E-AF3F-46B9-9FDE-230A280E9BFF}C:\\program files\\bitlord\\bitlord.exe"= UDP:C:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{9C1B00E3-FA2A-420B-84D1-86DAE89A54E6}C:\\program files\\bitlord\\bitlord.exe"= TCP:C:\program files\bitlord\bitlord.exe:BitLord
"{341CEB89-AAA7-452B-A8EB-87FBD4C00165}"= UDP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{C4613266-71ED-4679-8A58-AB4071F27743}"= TCP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{2F9D8050-BF84-4A47-B80A-5A51F24B62A2}"= UDP:C:\Nexon\KartRider\KartRider.exe:KartRider
"{6CEB6678-3F6B-49DA-A194-2CAD4CC4998E}"= TCP:C:\Nexon\KartRider\KartRider.exe:KartRider
"{CB551BCF-FF61-435D-A80D-803693620C35}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{BBD75391-A0DC-47C2-9821-47E61C7E212E}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{0AA4CB1A-C026-4777-AB0D-26B0E8C4F83E}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{F12EB92A-1930-47BF-A3FD-728C657F1501}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{D4C3A691-D7F9-44A7-8EFD-B572AA6E55BD}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{E91FAA2D-12B0-43F8-B2DC-D06E76678598}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{916FABEE-914F-4826-B5B6-1F8593C95026}"= UDP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{52987BB2-9EE3-490F-905B-6245E9C27E94}"= TCP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{5FE6955F-A5A9-4AAC-B7F5-7417FD787A4D}"= UDP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{A5A26F7F-557D-4D8C-8F09-CCA1084FC6D8}"= TCP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{8DB4D979-8B52-45D7-9B71-D00095952AF3}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{CD5E6279-511E-4EFF-A1DD-C2ABE970394B}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{57D1B8F0-DC42-498A-AF6A-D23054A5340E}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{28A1A368-8650-4792-9A26-66373E947820}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{A64B97B6-82CE-4781-B074-0FCDB62DEF67}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{7933A23F-CCC4-43AC-8854-891062504CD7}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{F493B459-7CCA-4DDD-9A94-BD312D30BA98}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{55C74632-22F9-4705-AB7B-2B112956FA2B}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{ED28BE93-1FAA-4D8C-A7D1-0257C567F0DD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CAE85B28-FC9A-4AC2-860E-99EFB98BEC6B}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{07C4E20F-9055-41F6-99B7-62625B4681FC}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{625BF72C-6185-4D8F-B800-F26772BBEA96}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{D8802660-2B38-4762-B31B-C502D67C1A4D}C:\\program files\\ea sports\\nhl08\\nhl2008.exe"= UDP:C:\program files\ea sports\nhl08\nhl2008.exe:nhl2008
"UDP Query User{1C0EF8FA-9327-4934-A9CF-0A6C401F6D9B}C:\\program files\\ea sports\\nhl08\\nhl2008.exe"= TCP:C:\program files\ea sports\nhl08\nhl2008.exe:nhl2008
"{BB93A364-29CE-4471-8A8D-0427EE503372}"= UDP:C:\Program Files\EA Sports\EA SPORTS online\SportsWrapper.exe:SportsWrapper
"{0E00767A-9216-4BA8-B36B-F552C1591F1B}"= TCP:C:\Program Files\EA Sports\EA SPORTS online\SportsWrapper.exe:SportsWrapper
"{7FDCC7F9-7C63-4F32-A0FD-967282029470}"= UDP:3703:Adobe Version Cue CS3 Server
"{A54138F7-585B-45C2-B398-2708C437E641}"= UDP:3704:Adobe Version Cue CS3 Server
"{88F3E162-3910-4B5C-81C9-26A4EF828D5F}"= UDP:50900:Adobe Version Cue CS3 Server
"{CF41B43C-48BF-45B6-A844-345E7BD558F2}"= UDP:50901:Adobe Version Cue CS3 Server
"{E9035596-E03B-4100-8521-8ACD9A3F79FD}"= UDP:C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{940BD430-EBCF-4C4B-83D7-C7AF61054A01}"= TCP:C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"TCP Query User{56B436A0-8D6B-47B1-A43B-8253FFB3D7B4}C:\\program files\\safari\\safari.exe"= UDP:C:\program files\safari\safari.exe:Safari Web Browser
"UDP Query User{DE366E98-DB01-4FF2-AEF9-DE26FDD6F8D5}C:\\program files\\safari\\safari.exe"= TCP:C:\program files\safari\safari.exe:Safari Web Browser
"{7CB9E126-78F4-4078-98DA-E1EF3DE97BA1}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{E2E58ED7-B047-4F17-82DF-763541F65E0A}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{59007D0B-3B78-41DA-85DC-CBC43F6857C4}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{18BF8B2B-D746-40D0-8D11-EDF2AA4BC4C5}"= UDP:C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"{4AB10804-DCDD-453A-BD74-EC2F935A9B1F}"= TCP:C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"{F8D65109-5A54-4613-BE57-2860958BD620}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]
R2 AERTFilters;Andrea RT Filters Service;C:\Windows\system32\AERTSrv.exe [2007-12-05 06:17]
R2 dlcq_device;dlcq_device;C:\Windows\system32\dlcqcoms.exe [2006-12-12 01:22]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-10-09 19:56]
R2 UxTuneUp;TuneUp Theme Extension;C:\Windows\System32\svchost.exe [2008-01-19 00:33]
S2 0048261214841454mcinstcleanup;McAfee Application Installer Cleanup (0048261214841454);C:\Windows\TEMP\004826~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 NAL;Nal Service ;C:\Windows\system32\Drivers\iqvw32.sys [2007-03-09 15:04]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 00:36]
S3 ROCKSTAR;ROCKSTAR;C:\Users\Calvin\Desktop\Hack Trainer\ksysdrv.sys [2006-12-20 20:52]
S3 tapvpn;TAP VPN Adapter;C:\Windows\system32\DRIVERS\tapvpn.sys [2008-03-12 19:38]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.exe [2008-06-24 23:23]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{214b9213-29c4-11dd-b075-00e034123456}]
\shell\AutoRun\command - K:\RunGame.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{214b9239-29c4-11dd-b075-00e034123456}]
\shell\AutoRun\command - M:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68df2eb3-5b9f-11dc-aed8-806e6f6e6963}]
\shell\AutoRun\command - E:\setup.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-30 16:00:00 C:\Windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-06-15 16:39:45 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-03-03 16:25:30 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-06-30 16:30:00 C:\Windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-06-29 17:00:46 C:\Windows\Tasks\User_Feed_Synchronization-{2B3DF531-795E-4B8F-852D-F9141689C0CD}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-06-30 16:30:12 C:\Windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-30 09:32:17
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\Windows\system32\winlogon.exe
-> C:\Windows\system32\wvUNeEtR.dll
.
Completion time: 2008-06-30 9:37:47
ComboFix-quarantined-files.txt 2008-06-30 16:36:54
ComboFix2.txt 2008-05-29 23:41:08
ComboFix3.txt 2008-05-14 00:47:57
ComboFix4.txt 2008-05-13 01:49:51
ComboFix5.txt 2008-04-26 15:23:27
Pre-Run: 329,176,338,432 bytes free
Post-Run: 329,152,720,896 bytes free
406 --- E O F --- 2008-06-24 20:36:01



