Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Google redirect malware

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Google redirect malware

Unread postby rsund » June 3rd, 2009, 11:00 pm

When trying to access microsoft update site I am redirected to the google search page.
Here is the log from hijackthis.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:38:11 PM, on 6/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\SM1BG.EXE
C:\Program Files\ContentWatch\Internet Protection\cwtray.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/?cid=NET_mmhpset
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [cwcptray] C:\Program Files\ContentWatch\Internet Protection\cwtray.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O15 - Trusted Zone: http://*.netcampus.fujitsu.com
O15 - Trusted Zone: http://*.napster.com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLa ... uncher.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://secure.dmr.com/postauthI/epi.cab
O16 - DPF: {84B7AC1D-9AD1-474F-B6B0-FE1641DBFDFA} - http://contentpurity.net/xp/ScanFile.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/ ... leId=29223
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - https://www.contentwatch.com/audit/incl ... ontrol.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://fc.webex.com/client/v_mywebex-t ... eatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://sslvpn.consulting-fujitsu.com/d ... tupSP1.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/ins ... downde.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0BFC6C09-81C0-43A3-B888-CC26A1FE4606}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CCS\Services\Tcpip\..\{338F5B52-8863-4497-8D2F-83BEA9FE3C2C}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS1\Services\Tcpip\..\{0BFC6C09-81C0-43A3-B888-CC26A1FE4606}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS2\Services\Tcpip\..\{0BFC6C09-81C0-43A3-B888-CC26A1FE4606}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.205,85.255.112.202
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ContentWatch (CwAltaService20) - ContentWatch, Inc. - C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Security Activity Dashboard Service - Trend Micro Inc. - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 13541 bytes
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm
Advertisement
Register to Remove

Re: Google redirect malware

Unread postby MWR 3 day Mod » June 6th, 2009, 11:36 pm

Hi,

We are sorry to see your topic is over three days old and no one has yet been able to respond and offer help.

If you still require assistance, please post a link to your topic in our Waiting for help with malware removal? forum, and our staff will make an effort to assist you as promptly as possible. Only post a LINK to this topic, DO NOT post your DDS log!

Please do not reply to this topic.

If you haven't posted within two days in the "Waiting for help with malware removal?" forum, we will assume you have been able to get assistance in other ways and this topic will be closed.
MWR 3 day Mod
MRU Undergrad
MRU Undergrad
 
Posts: 2534
Joined: April 4th, 2008, 8:40 am

Re: Google redirect malware

Unread postby Dakeyras » June 8th, 2009, 7:57 am

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Hi rsund and welcome to Malware Removal :)

Please note I will not be able to do anything with this until 6/15.
I will take this into account and if you have not responded by this time this topic will be closed.

I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:

  • I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine!.
  • The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Refrain from running self fixes as this will hinder the malware removal process.
  • It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.

Next:

Please download Rooter.exe to your desktop.

  • Then double-click it to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt.
  • Post the contents of Rooter.txt in your next reply.

Next:

Now lets carry out a more in-depth scan of your computer shall we as follows:

  • Please download Random's System Information Tool by random/random from here and save it to your desktop.
Make sure that RSIT.exe is on the your Desktop before running the application.
  • Double click on RSIT.exe and to start RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open:
    • log.txt will be opened maximized.
    • info.txt will be opened minimized.
  • Please post the contents of both log.txt and info.txt.

When completed the above, please post back the following in the order asked for:

  • How is you computer performing now, any other symptoms and or problems encountered?
  • Rooter Log.
  • Both RSIT logs. <-- Post them individually please, IE: one Log per post/reply.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8804
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Google redirect malware

Unread postby rsund » June 14th, 2009, 9:40 pm

Computer is still experiencing the issue - trying to access microsoft updates redirects to google. Also still cannot download antivirus updates.

Rooter file is as follows:
Rooter.exe (v1.0) by Eric_71
¨
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
32_bits - x86 Family 15 Model 4 Stepping 1, GenuineIntel
¨
A:\ [Removable]
C:\ [Fixed-NTFS] .. ( Total:146 Go - Free:75 Go )
D:\ [CD_Rom]
¨
Scan : 20:26.30
Path : C:\Documents and Settings\Richard Sund\Desktop\Rooter.exe
User : Richard Sund ( Administrator -> YES )
¨
----------------------\\ Processes
¨
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (500)
______ \??\C:\WINDOWS\system32\csrss.exe (552)
______ \??\C:\WINDOWS\system32\winlogon.exe (576)
______ C:\WINDOWS\system32\services.exe (616)
______ C:\WINDOWS\system32\lsass.exe (632)
______ C:\WINDOWS\system32\svchost.exe (896)
______ C:\WINDOWS\system32\svchost.exe (964)
______ C:\Program Files\Windows Defender\MsMpEng.exe (1560)
______ C:\WINDOWS\System32\svchost.exe (1600)
______ C:\WINDOWS\system32\svchost.exe (1640)
______ C:\WINDOWS\system32\svchost.exe (1700)
______ C:\WINDOWS\system32\svchost.exe (1948)
______ C:\WINDOWS\system32\LEXBCES.EXE (1056)
______ C:\WINDOWS\system32\spoolsv.exe (1088)
______ C:\WINDOWS\system32\LEXPPS.EXE (1100)
______ C:\WINDOWS\system32\svchost.exe (1248)
______ C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe (1276)
______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (1764)
______ C:\Program Files\Bonjour\mDNSResponder.exe (1784)
______ C:\WINDOWS\system32\CTsvcCDA.EXE (1864)
______ C:\WINDOWS\system32\crypserv.exe (1892)
______ C:\Program Files\Java\jre6\bin\jqs.exe (2000)
______ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (2044)
______ C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (204)
______ C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (324)
______ C:\WINDOWS\system32\svchost.exe (556)
______ C:\Program Files\Trend Micro\Internet Security\TmPfw.exe (1216)
______ C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (1404)
______ C:\Program Files\Viewpoint\Common\ViewpointService.exe (1492)
______ C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe (3380)
______ C:\WINDOWS\Explorer.EXE (4076)
______ C:\WINDOWS\system32\wbem\wmiprvse.exe (788)
______ C:\Program Files\Java\jre6\bin\jusched.exe (2120)
______ C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (2200)
______ C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (2260)
______ C:\WINDOWS\SM1BG.EXE (2316)
______ C:\Program Files\ContentWatch\Internet Protection\cwtray.exe (2544)
______ C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (2928)
______ C:\WINDOWS\System32\alg.exe (2952)
______ C:\WINDOWS\system32\ctfmon.exe (2980)
______ C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (3056)
______ C:\WINDOWS\system32\wbem\unsecapp.exe (3064)
______ C:\WINDOWS\system32\wscntfy.exe (3668)
______ C:\WINDOWS\System32\svchost.exe (3220)
______ C:\Program Files\Internet Explorer\iexplore.exe (2572)
______ C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe (1164)
______ C:\Program Files\Internet Explorer\iexplore.exe (2420)
______ C:\Documents and Settings\Richard Sund\Desktop\Rooter.exe (2580)
¨
----------------------\\ Device\Harddisk0\
¨
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
¨
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:65769984)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:65802240 | Length:156798512640)
\Device\Harddisk0\Partition3 (Start_Offset:156864314880 | Length:3133831680)
¨
----------------------\\ Scheduled Tasks
¨
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
C:\WINDOWS\Tasks\DESKTOP.INI
C:\WINDOWS\Tasks\MP Scheduled Scan.job
C:\WINDOWS\Tasks\SA.DAT
¨
----------------------\\ Registry
¨
¨
----------------------\\ Files & Folders
¨
----------------------\\ Scan completed at 20:26.47
¨
C:\Rooter$\Rooter_1.txt - (14/06/2009 | 20:26.47)
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm

Re: Google redirect malware

Unread postby rsund » June 14th, 2009, 9:41 pm

Here is the RSIT info file

info.txt logfile of random's system information tool 1.06 2009-06-14 20:28:38

======Uninstall list======

Sansa Media Converter-->"C:\Program Files\InstallShield Installation Information\{FC053571-8507-44E4-8B6D-AACEAB8CA57C}\setup.exe" --u:{FC053571-8507-44E4-8B6D-AACEAB8CA57C}
-->"C:\Program Files\Creative\SBAudigy2ZS\Program\Ctzapxx.EXE" /W /U /S
-->C:\WINDOWS\IsUninst.exe -f"c:\documents and settings\all users\desktop\Uninst.isu"
-->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
-->C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
-->C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
-->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{169F8893-C1C5-4847-972C-EA1E008112AC}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{169F8893-C1C5-4847-972C-EA1E008112AC}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{236FADD8-58FD-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{236FADD8-58FD-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{435E969D-867E-4364-8E74-3DC8A69C5BDB}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67AEFC4C-69E4-11D7-85F4-00E018013273}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7201B853-5833-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7201B853-5833-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{72A810B1-EE62-455A-A086-E1C9FEDE7F29}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{72A810B1-EE62-455A-A086-E1C9FEDE7F29}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7A900EAB-DA37-4554-AF19-9C337476D05D}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9154ED7C-926E-49CC-B677-0CF3C5267457}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9154ED7C-926E-49CC-B677-0CF3C5267457}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A4D2983-4662-4387-BE3D-4CFC2FA9C100}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A4D2983-4662-4387-BE3D-4CFC2FA9C100}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC157741-3285-4D6A-B934-9174587A3493}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC157741-3285-4D6A-B934-9174587A3493}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3549608-69D3-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3549608-69D3-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C6866B7D-ACFD-4C49-B77B-3B2F8CF54B96}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE6699B3-E5AD-4E59-8F2B-207DF630670C}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD851F7E-F887-405D-9E1C-488811113EF3}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD851F7E-F887-405D-9E1C-488811113EF3}\setup.exe" -l0x9 /remove
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
AIM 6-->C:\Program Files\AIM6\uninst.exe
AOL Instant Messenger-->C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ArcSoft Software Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EE7C3A14-1D20-49F6-B903-491561076F0F}\SETUP.EXE" -l0x9
ATI Control Panel-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Banctec Service Agreement-->MsiExec.exe /X{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
CardRd81-->MsiExec.exe /I{54C8FE84-89C4-40E8-976C-439EB0729BD6}
CCScore-->MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
Citrix ICA Web Client 6.30.1050-->C:\PROGRA~1\Citrix\icaweb32\UNWISE.EXE C:\PROGRA~1\Citrix\icaweb32\INSTALL.LOG
Comcast High-Speed Internet Install Wizard-->C:\Program Files\support.com\uninstall\chsi_uninstaller.exe
Conexant D850 56K V.9x DFVc Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1\HXFSETUP.EXE -U -Idel200fk.inf
ContentCleanup 2.5-->"C:\Program Files\ContentWatch\Internet Protection\ContentCleanup\unins000.exe"
CR2-->MsiExec.exe /I{432C3720-37BF-4BD7-8E49-F38E090246D0}
Creative MediaSource-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\setup.exe" -l0x9 /remove
Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
CutePDF Writer 2.7-->C:\Program Files\Acro Software\CutePDF Writer\uninscpw.exe
CutList Plus-->MsiExec.exe /X{236AED25-0A8B-4F95-A86B-5C394291A9F3}
Cypress USB Mass Storage Driver Installation-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E0695EE-ED29-4D96-BD77-2A9A17EDF0D6}\Setup.exe" -l0x9 NotFirstInstall
Dell Digital Jukebox Driver-->C:\Program Files\Dell\Digital Jukebox Drivers\DrvUnins.exe /s
Dell Driver Reset Tool-->MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
Dell Media Experience Update-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CDE4CC8B-134B-421E-943C-90799E56F664}\setup.exe" -l0x9 -L0x9 /SMAINT
Dell Media Experience-->MsiExec.exe /I{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}
Dell Support 5.0.0 (630)-->rundll32 C:\PROGRA~1\DELLSU~1\AUInst.dll,ExUninstall
Digital Line Detect-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
ESSBrwr-->MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
ESSCDBK-->MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
ESScore-->MsiExec.exe /I{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}
ESSCT-->MsiExec.exe /I{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}
ESSEMAIL-->MsiExec.exe /I{FEDE2483-87B7-44C1-A5BB-D75AEB8B6340}
ESSgui-->MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
ESShelp-->MsiExec.exe /I{87843A41-7808-4F2E-B13F-25C1E67CF2FD}
ESSini-->MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
ESSPCD-->MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
ESSPDock-->MsiExec.exe /I{FCDB1C92-03C6-4C76-8625-371224256091}
ESSSONIC-->MsiExec.exe /I{4F677FC7-7AA8-412B-A957-F13CBE1C7331}
ESSTOOLS-->MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589}
ESSTUTOR-->MsiExec.exe /I{CA60320D-6A16-49C8-A34F-84EEF4799567}
ESSvpaht-->MsiExec.exe /I{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}
ESSvpot-->MsiExec.exe /I{48C82F7A-F100-4DAB-A310-8E18BF2159E1}
FileOpen Plug-in for Adobe Acrobat® and Acrobat Reader®-->MsiExec.exe /X{AE6C085B-3F64-4383-BBD5-E8FE4F1DA514}
Forms Wizard-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FCDE0800-64C1-4D63-AD6D-8B70442BB802}\Setup.exe" -l0x9
Free Mp3 Wma Converter V 1.6.2-->"C:\Program Files\Free Audio Pack\unins000.exe"
Free WMA to MP3 Converter 1.16-->"C:\Program Files\Free WMA to MP3 Converter\unins000.exe"
G5a922EN-->MsiExec.exe /X{A3E77D20-647C-40E2-B69B-C120D4D58190}
Garmin Communicator Plugin-->MsiExec.exe /X{F6970FBD-809A-4C51-BAB3-D94A04C6C8E7}
Garmin WebUpdater-->MsiExec.exe /X{366FFC89-C800-4366-B903-B9C4314109A5}
Google Earth-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly
Google SketchUp 7-->MsiExec.exe /I{BEF106F8-2689-4530-925A-E1117836E8CD}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HLPIndex-->MsiExec.exe /I{38441BE7-79B0-42B8-8297-833704F949FE}
HLPPDOCK-->MsiExec.exe /I{154508C0-07C5-4659-A7A0-E49968750D21}
HLPSFO-->MsiExec.exe /I{8DD94CA3-BCD2-49C0-B537-F3B5D95FF0C8}
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Intel(R) PRO Network Adapters and Drivers-->Prounstl.exe
Intel(R) PROSet for Wired Connections-->MsiExec.exe /I{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}
Internet Explorer Default Page-->MsiExec.exe /I{35BDEFF1-A610-4956-A00D-15453C116395}
iriver Firmware Updater (remove only)-->"C:\Program Files\iriver\iriver Firmware Updater\uninstall.exe"
iRiver Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1F1F35A7-8EA0-43B5-AEAF-B0B9AB1BEF97}\Setup.exe" -l0x9
iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
Jasc Paint Shop Photo Album-->MsiExec.exe /I{CC000127-5E5D-4A1C-90CB-EEAAAC1E3AC0}
Jasc Paint Shop Pro 8 Dell Edition-->MsiExec.exe /I{81A34902-9D0B-4920-A25C-4CDC5D14B328}
Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
Java 2 Runtime Environment, SE v1.4.2_06-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142060}
Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Juniper Networks Secure Application Manager-->C:\Program Files\Juniper Networks\Secure Application Manager\UninstallSAM.exe
Kodak EasyShare software-->C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140011_d1e7477\Setup.exe /APR-REMOVE
KSU-->MsiExec.exe /I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}
Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
Lexmark Z700-P700 Series-->C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBLUN5C.EXE -dLexmark Z700-P700 Series
Lotus Notes 6.5.4-->MsiExec.exe /I{6B2764B1-F062-4481-94FD-58B1C211C448}
Macromedia Flash Player-->MsiExec.exe /X{0456ebd7-5f67-4ab6-852e-63781e3f389c}
Macromedia Shockwave Player-->C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\Install.log
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
MDL Chime/Chime Pro for Internet Explorer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{46761278-BF32-4008-833B-93487FF0A06E}\setup.exe" -l0x9 -uninst -removeonly
Memorex exPressit Label Design Studio-->C:\WINDOWS\mvuninst\App1\mvuninst.exe "Memorex exPressit Label Design Studio"
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Money 5.0-->C:\Program Files\Microsoft Money\setup\setup.exe
Microsoft Office 2000 Disc 2-->MsiExec.exe /I{00040409-78E1-11D2-B60F-006097C998E7}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Small Business 2007 Trial-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall SMALLBUSINESSR /dll OSETUP.DLL
Microsoft Office Small Business 2007-->MsiExec.exe /X{91120000-00CA-0000-0000-0000000FF1CE}
Microsoft Office Standard Edition 2003-->MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Plus! Digital Media Edition Installer-->MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
Microsoft Plus! Photo Story 2 LE-->MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
Microsoft Project 2000-->MsiExec.exe /I{2DFE1608-BDCA-11D1-B7AE-00C04FB92F3D}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Modem Helper-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanel
MoviesPlay-->"C:\Program Files\MoviesPlay\Uninstall.exe"
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Musicmatch for Windows Media Player-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E93E5EF6-D361-481E-849D-F16EF5C78EBC}\setup.exe" -l0x9 remove
Musicmatch® Jukebox-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}\setup.exe" -l0x9 -uninst
Napster 3.5 MP3 Encoder-->MsiExec.exe /X{708F9BEF-2B8C-421D-813E-8CA9EA29B1B8}
Napster Burn Engine-->MsiExec.exe /I{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}
Napster-->C:\Program Files\InstallShield Installation Information\{BBBCAE4B-B416-4182-A6F2-438180894A81}\setup.exe -runfromtemp -l0x0009 -removeonly
Net Nanny Parental Controls 5.6-->"C:\Program Files\ContentWatch\Internet Protection\ContentProtect\Home\unins000.exe"
NetWaiting-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe" -l0x9 ControlPanelAnyText
Network Stumbler 0.4.0 (remove only)-->"C:\Program Files\Network Stumbler\uninst.exe"
Nikon Message Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\Setup.exe" -l0x9 UNINSTALL
Nortel Networks Contivity VPN Client-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF964A78-078C-11D1-B7A7-0000C0134CE6}\setup.exe" Uninstall
Notifier-->MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}
OfotoXMI-->MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
OpenMG Limited Patch 4.1-05-13-31-01-->C:\Program Files\Common Files\Sony Shared\OpenMG\HotFixes\HotFix4.1-05-13-31-01\HotFixSetup\setup.exe /u
OpenMG Secure Module 4.1.00-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{2F151B50-B434-4838-B51D-70442EBA093E} UNINSTALL
OTtBP-->MsiExec.exe /I{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}
OTtBPSDK-->MsiExec.exe /I{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}
PassAlong Software-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AC4732F4-665D-4E6B-8E50-74D6B6FBE5A9}\setup.exe" -l0x9
Photo Click-->MsiExec.exe /I{6E179C77-7335-458D-9537-4F4EAC0181ED}
PictureProject-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF3999BE-1A7B-4738-88AA-97BF14094A4A}\setup.exe" -l0x9 UNINSTALL
PixiePack Codec Pack-->MsiExec.exe /I{61E3FE32-07B9-4563-A3E0-2DE2D620FE10}
PM FASTrack® 5.1-->C:\Program Files\PM FASTrack®\uninst.exe
PMP-->"C:\Program Files\CertGear\PMP\UninstallerData\Uninstall PMP.exe"
Pocket Tanks 1.00b-->"C:\Program Files\Pocket Tanks\unins000.exe"
PowerArchiver 2007-->MsiExec.exe /I{D0F210C9-64C5-41C6-8882-A111C6C49911}
PowerDVD 5.3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
RealPlayer Basic-->C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
SanDisk TransferMate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{601C6E14-DF1E-4113-A8C8-F9DB90CB0D88}\Setup.exe" -l0x9
Sansa Updater-->C:\Program Files\InstallShield Installation Information\{E2D7E05E-C8C7-45F4-8D89-D6696075E0B7}\setup.exe -runfromtemp -l0x0009 -removeonly
Scholastic's I SPY Treasure Hunt-->C:\PROGRA~1\SCHOLA~1\ISPYTR~1\UNWISE.EXE C:\PROGRA~1\SCHOLA~1\ISPYTR~1\INSTALL.LOG
Security Update for Step By Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Security Update for Windows XP (KB963027)-->"C:\WINDOWS\$NtUninstallKB963027$\spuninst\spuninst.exe"
SFR-->MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B}
SHASTA-->MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237}
SKIN0001-->MsiExec.exe /I{FDF9943A-3D5C-46B3-9679-586BD237DDEE}
SKINXSDK-->MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}
Sonic MyDVD-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
Sonic RecordNow! Plus-->MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Sonic Update Manager-->MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
SonicStage 3.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A0EB195B-5876-48E6-879D-33D4B2102610}\setup.exe" -l0x9 UNINSTALL -removeonly
Sound Blaster Audigy 2 ZS-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E2514D9-DC24-4634-B348-61F3EF0F1628}\setup.exe" -l0x9
Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
Super DX-Ball v1.00-->"C:\Program Files\Super DX-Ball\unins000.exe"
TI Connect 1.6-->MsiExec.exe /I{A8B94669-8654-4126-BD28-D0D2412CDED6}
Trend Micro Internet Security Pro-->C:\Program Files\Trend Micro\Internet Security\remove.exe
Trend Micro Internet Security Pro-->MsiExec.exe /X{40E12A55-C504-4223-AFAC-7672DBF1ACDE}
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
USB Storage Adapter FX (SM1)-->SM1UN.EXE SM1FX_AT
Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
VPRINTOL-->MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
WebCyberCoach 3.2 Dell-->"C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exe" "WebCyberCoach ext\wtrb" /inf "engine.inf,RealUninstallSection,,4" /infcfg "enginecf.inf,RealUninstallSection,,4"
WebEx-->C:\WINDOWS\DOWNLO~1\atcliun.exe
Wheel Of Fortune-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Hasbro Interactive\Wheel Of Fortune\Uninst.isu"
WildTangent Web Driver-->C:\Program Files\WildTangent\Apps\CDA\CDAUninstall.exe
Windows Defender-->MsiExec.exe /I{A06275F4-324B-4E85-95E6-87B2CD729401}
Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Format SDK Hotfix - KB891122-->"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
Windows Media Player 10-->MsiExec.exe /I{33BB4982-DC52-4886-A03B-F4C5C80BEE89}
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WIRELESS-->MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F}
WordPerfect Office 12-->MsiExec.exe /I{AF19F291-F22F-4798-9662-525305AE9E48}
Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe
YahooPoolAimer-->MsiExec.exe /I{2E8A57F3-E29E-4EFF-ADEE-183B28C9D111}

======Security center information======

AV: Trend Micro Internet Security Pro (outdated)
FW: Trend Micro Personal Firewall

======System event log======

Computer Name: FAMILYROOM
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 75181
Source Name: W32Time
Time Written: 20090524081808.000000-300
Event Type: warning
User:

Computer Name: FAMILYROOM
Event Code: 16
Message: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.

Record Number: 75180
Source Name: Windows Update Agent
Time Written: 20090524042535.000000-300
Event Type: error
User:

Computer Name: FAMILYROOM
Event Code: 7000
Message: The Nortel Extranet Access Protocol service failed to start due to the following error:
The system cannot find the file specified.


Record Number: 75162
Source Name: Service Control Manager
Time Written: 20090523183840.000000-300
Event Type: error
User:

Computer Name: FAMILYROOM
Event Code: 23
Message: Printer Dell Photo AIO Printer 922 failed to initialize because a suitable Dell Photo AIO Printer 922 driver could not be found.

Record Number: 75161
Source Name: Print
Time Written: 20090523183829.000000-300
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: FAMILYROOM
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 75158
Source Name: W32Time
Time Written: 20090523054254.000000-300
Event Type: warning
User:

=====Application event log=====

Computer Name: FAMILYROOM
Event Code: 1524
Message: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.



Record Number: 12
Source Name: Userenv
Time Written: 20080710030623.000000-300
Event Type: warning
User: FAMILYROOM\Mollie & Rich

Computer Name: FAMILYROOM
Event Code: 1002
Message: Hanging application wmplayer.exe, version 11.0.5721.5145, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Record Number: 11
Source Name: Application Hang
Time Written: 20080709171731.000000-300
Event Type: error
User:

Computer Name: FAMILYROOM
Event Code: 1517
Message: Windows saved user FAMILYROOM\Rebecca registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 7
Source Name: Userenv
Time Written: 20080702215733.000000-300
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: FAMILYROOM
Event Code: 1524
Message: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.



Record Number: 6
Source Name: Userenv
Time Written: 20080702215732.000000-300
Event Type: warning
User: FAMILYROOM\Rebecca

Computer Name: FAMILYROOM
Event Code: 1002
Message: Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Record Number: 5
Source Name: Application Hang
Time Written: 20080702180428.000000-300
Event Type: error
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\PROGRA~1\COMMON~1\SONICS~1\;C:\Program Files\Common Files\Sonic Shared;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
"PROCESSOR_REVISION"=0401
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"CWHOME"=C:\Program Files\ContentWatch
"CWALTAHOME"=C:\Program Files\ContentWatch
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

-----------------EOF-----------------
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm

Re: Google redirect malware

Unread postby rsund » June 14th, 2009, 9:46 pm

And here is the RSIT log file:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Richard Sund at 2009-06-14 20:28:30
Microsoft Windows XP Professional Service Pack 3
System drive C: has 77 GB (52%) free of 150 GB
Total RAM: 1022 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:28:35 PM, on 6/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\SM1BG.EXE
C:\Program Files\ContentWatch\Internet Protection\cwtray.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Richard Sund\Desktop\Rooter.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Richard Sund\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Richard Sund.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/?cid=NET_mmhpset
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [cwcptray] C:\Program Files\ContentWatch\Internet Protection\cwtray.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
O4 - HKUS\S-1-5-19\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O15 - Trusted Zone: http://*.netcampus.fujitsu.com
O15 - Trusted Zone: http://*.napster.com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLa ... uncher.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://secure.dmr.com/postauthI/epi.cab
O16 - DPF: {84B7AC1D-9AD1-474F-B6B0-FE1641DBFDFA} - http://contentpurity.net/xp/ScanFile.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/ ... leId=29223
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - https://www.contentwatch.com/audit/incl ... ontrol.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://fc.webex.com/client/v_mywebex-t ... eatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://sslvpn.consulting-fujitsu.com/d ... tupSP1.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/ins ... downde.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0BFC6C09-81C0-43A3-B888-CC26A1FE4606}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CCS\Services\Tcpip\..\{338F5B52-8863-4497-8D2F-83BEA9FE3C2C}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS1\Services\Tcpip\..\{0BFC6C09-81C0-43A3-B888-CC26A1FE4606}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS2\Services\Tcpip\..\{0BFC6C09-81C0-43A3-B888-CC26A1FE4606}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.205,85.255.112.202
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ContentWatch (CwAltaService20) - ContentWatch, Inc. - C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Security Activity Dashboard Service - Trend Micro Inc. - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 13808 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43C6D902-A1C5-45c9-91F6-FD9E90337E18}]
TSToolbarBHO - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll [2009-02-12 144720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-05-31 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-05-31 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BA52B914-B692-46c4-B683-905236F6F655}
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]
{CCAC5586-44D7-4c43-B64A-F042461A97D2} - Trend Micro Toolbar - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll [2009-02-12 144720]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-05-31 148888]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-08-25 339968]
"CTSysVol"=C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe [2003-09-17 57344]
"CTDVDDET"=C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE [2003-06-18 45056]
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"SM1BG"=C:\WINDOWS\SM1BG.EXE [2003-08-27 94208]
"cwcptray"=C:\Program Files\ContentWatch\Internet Protection\cwtray.exe [2009-05-21 352576]
"UfSeAgnt.exe"=C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [2009-03-31 995528]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-11-04 413696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"OE"=C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe [2009-02-07 497008]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
C:\WINDOWS\system32\CTHELPER.EXE [2004-03-11 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [2004-08-23 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe [2005-03-15 53248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-11-04 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe [2004-12-14 26112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe [2007-05-02 55368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe [2005-01-24 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [2004-01-07 110592]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
C:\PROGRA~1\DIGITA~1\DLG.exe [2003-10-29 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor.lnk]
C:\PROGRA~1\SanDisk\SANDIS~1\SDMONI~1.EXE [2006-01-05 114688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"As32Svc"=2
"SSScsiSV"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\CwWLEvent]
C:\Program Files\ContentWatch\Internet Protection\common\cwplc001.dll [2007-04-24 884736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"AllowLegacyWebView"=
"AllowUnhashedWebView"=
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Disabled:AOL Instant Messenger"
"C:\Program Files\Nortel Networks\Extranet.exe"="C:\Program Files\Nortel Networks\Extranet.exe:*:Enabled:Contivity VPN Client"
"C:\Program Files\IncrediMail\bin\IMApp.exe"="C:\Program Files\IncrediMail\bin\IMApp.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"="C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Disabled:Internet Explorer"
"C:\Program Files\Edutils\acted3.exe"="C:\Program Files\Edutils\acted3.exe:*:Enabled:acted3"
"C:\Documents and Settings\All Users\Documents\FrostWire\FrostWire.exe"="C:\Documents and Settings\All Users\Documents\FrostWire\FrostWire.exe:*:Disabled:FrostWire"
"C:\Documents and Settings\All Users\Documents\Soulseek\slsk.exe"="C:\Documents and Settings\All Users\Documents\Soulseek\slsk.exe:*:Disabled:SoulSeek"
"C:\Documents and Settings\All Users\Documents\Ares\Ares.exe"="C:\Documents and Settings\All Users\Documents\Ares\Ares.exe:*:Disabled:Ares p2p for windows"
"F:\Documents\Downloads\Ares.exe"="F:\Documents\Downloads\Ares.exe:*:Disabled:Ares p2p for windows"
"C:\Brians programs\Ares\Ares.exe"="C:\Brians programs\Ares\Ares.exe:*:Disabled:Ares p2p for windows"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\AIM6\aim6.exe"="C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM"
"C:\Documents and Settings\All Users\Documents\Ares2\Ares.exe"="C:\Documents and Settings\All Users\Documents\Ares2\Ares.exe:*:Disabled:Ares p2p for windows"
"C:\Program Files\Java\jre1.6.0_03\bin\javaw.exe"="C:\Program Files\Java\jre1.6.0_03\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary"
"C:\WINDOWS\SYSTEM32\javaw.exe"="C:\WINDOWS\SYSTEM32\javaw.exe:*:Disabled:Java(TM) Platform SE binary"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Documents and Settings\All Users\Documents\Trilix\Trilix.exe"="C:\Documents and Settings\All Users\Documents\Trilix\Trilix.exe:*:Disabled:Trilix"
"C:\WINDOWS\SYSTEM32\LEXPPS.EXE"="C:\WINDOWS\SYSTEM32\LEXPPS.EXE:*:Enabled:LEXPPS.EXE"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Documents and Settings\Mollie & Rich\Desktop\utorrent.exe"="C:\Documents and Settings\Mollie & Rich\Desktop\utorrent.exe:*:Disabled:µTorrent"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5e4ea0ad-9830-11db-b65d-00111186b090}]
shell\AutoRun\command - E:\LaunchU3.exe -a


======File associations======

.scr - open - "C:\Program Files\Internet Explorer\Iexplore.exe" %1

======List of files/folders created in the last 3 months======

2009-06-14 20:28:30 ----D---- C:\rsit
2009-06-14 20:26:47 ----D---- C:\Rooter$
2009-06-06 06:12:43 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-06 06:12:43 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-06-04 17:04:35 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-05-31 08:16:52 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-05-30 12:49:14 ----D---- C:\Documents and Settings\All Users\Application Data\Azureus
2009-05-26 19:32:08 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-05-25 07:24:14 ----D---- C:\Documents and Settings\Richard Sund\Application Data\FileOpen
2009-05-21 20:40:56 ----A---- C:\WINDOWS\system32\wxcode_msw28u_wxjson_CW.dll
2009-05-21 20:40:55 ----A---- C:\WINDOWS\system32\wxcode_msw28u_wxcurl_CW.dll
2009-05-17 08:55:59 ----D---- C:\Program Files\MoviesPlay
2009-05-05 22:06:07 ----A---- C:\CKINFO.TXT
2009-05-05 22:05:57 ----A---- C:\WINDOWS\Crypkey.ini
2009-05-05 22:05:55 ----SHD---- C:\WINDOWS\ftpcache
2009-05-05 22:05:53 ----A---- C:\WINDOWS\system32\Crypserv.exe
2009-05-05 22:05:53 ----A---- C:\WINDOWS\Setup_ck.dll
2009-05-05 22:05:53 ----A---- C:\WINDOWS\Ckrfresh.exe
2009-05-05 22:05:53 ----A---- C:\WINDOWS\Ckconfig.exe
2009-05-05 22:05:52 ----RA---- C:\WINDOWS\Setup_ck.exe
2009-05-05 22:05:47 ----D---- C:\Program Files\PM FASTrack®
2009-05-05 06:26:01 ----HD---- C:\Program Files\Zero G Registry
2009-05-05 06:26:01 ----D---- C:\Program Files\CertGear
2009-04-22 08:34:24 ----D---- C:\Program Files\Juniper Networks
2009-04-21 03:04:27 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-04-21 03:04:17 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-04-21 03:01:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-04-21 03:01:38 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-04-21 03:01:27 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-04-21 03:01:11 ----HDC---- C:\WINDOWS\$NtUninstallKB963027$
2009-04-21 03:00:54 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-04-20 07:26:53 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-04-05 19:48:39 ----D---- C:\WINDOWS\system32\Service
2009-03-20 07:47:08 ----D---- C:\Log
2009-03-17 05:31:46 ----D---- C:\Program Files\GPLGS

======List of files/folders modified in the last 3 months======

2009-06-14 20:26:16 ----D---- C:\WINDOWS\Prefetch
2009-06-14 20:19:38 ----SD---- C:\WINDOWS\Tasks
2009-06-14 20:17:53 ----D---- C:\WINDOWS\Temp
2009-06-14 20:17:04 ----A---- C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt
2009-06-14 20:16:35 ----SHD---- C:\WINDOWS\CSC
2009-06-06 11:25:50 ----D---- C:\WINDOWS\system32\CatRoot2
2009-06-06 06:12:44 ----D---- C:\WINDOWS\system32\DRIVERS
2009-06-06 06:12:43 ----RD---- C:\Program Files
2009-06-06 05:54:44 ----A---- C:\WINDOWS\ntbtlog.txt
2009-06-06 05:42:02 ----SHD---- C:\WINDOWS\Installer
2009-06-05 06:56:24 ----D---- C:\WINDOWS\SYSTEM32
2009-06-05 05:53:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-06-04 17:16:03 ----D---- C:\Program Files\Common Files
2009-06-04 09:38:16 ----D---- C:\WINDOWS
2009-06-04 08:04:55 ----A---- C:\WINDOWS\IE4 Error Log.txt
2009-06-04 07:55:02 ----D---- C:\Program Files\Internet Explorer
2009-06-04 06:22:50 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-06-03 21:31:07 ----D---- C:\Program Files\Trend Micro
2009-06-03 20:52:41 ----HD---- C:\WINDOWS\INF
2009-06-03 20:52:37 ----HD---- C:\Program Files\InstallShield Installation Information
2009-05-31 08:16:42 ----A---- C:\WINDOWS\system32\javaws.exe
2009-05-31 08:16:42 ----A---- C:\WINDOWS\system32\javaw.exe
2009-05-31 08:16:42 ----A---- C:\WINDOWS\system32\java.exe
2009-05-31 08:16:40 ----D---- C:\Program Files\Java
2009-05-26 19:36:54 ----D---- C:\WINDOWS\system32\CONFIG
2009-05-26 19:36:14 ----D---- C:\Program Files\Microsoft Works
2009-05-26 19:36:07 ----D---- C:\WINDOWS\WinSxS
2009-05-26 19:35:50 ----D---- C:\Program Files\Microsoft Office
2009-05-26 19:35:44 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-05-26 19:35:41 ----D---- C:\WINDOWS\ShellNew
2009-05-26 19:35:21 ----RSD---- C:\WINDOWS\Fonts
2009-05-21 20:38:23 ----A---- C:\WINDOWS\system32\wxmsw28u_xrc_vc_CW.dll
2009-05-21 20:38:23 ----A---- C:\WINDOWS\system32\wxmsw28u_media_vc_CW.dll
2009-05-21 20:38:23 ----A---- C:\WINDOWS\system32\wxmsw28u_html_vc_CW.dll
2009-05-21 20:38:23 ----A---- C:\WINDOWS\system32\wxmsw28u_core_vc_CW.dll
2009-05-21 20:38:23 ----A---- C:\WINDOWS\system32\wxmsw28u_adv_vc_CW.dll
2009-05-21 20:38:23 ----A---- C:\WINDOWS\system32\wxbase28u_xml_vc_CW.dll
2009-05-21 20:38:23 ----A---- C:\WINDOWS\system32\wxbase28u_vc_CW.dll
2009-05-21 20:38:22 ----A---- C:\WINDOWS\system32\wxIE.dll
2009-05-21 20:38:22 ----A---- C:\WINDOWS\system32\wxbase28u_net_vc_CW.dll
2009-05-21 20:38:22 ----A---- C:\WINDOWS\system32\libxml2_CW.dll
2009-05-21 20:38:22 ----A---- C:\WINDOWS\system32\libexpat.dll
2009-05-21 20:38:22 ----A---- C:\WINDOWS\system32\AltaRecovery.exe
2009-05-21 20:38:21 ----A---- C:\WINDOWS\system32\cwalsp.dll
2009-05-17 20:22:28 ----A---- C:\WINDOWS\WIN.INI
2009-05-17 08:55:57 ----SHD---- C:\RECYCLER
2009-05-07 00:16:30 ----A---- C:\WINDOWS\system32\MRT.exe
2009-05-04 05:28:11 ----D---- C:\WINDOWS\system32\CatRoot
2009-05-04 05:28:01 ----RSHD---- C:\WINDOWS\system32\DLLCACHE
2009-04-22 08:34:27 ----D---- C:\Documents and Settings\Richard Sund\Application Data\Juniper Networks
2009-04-21 03:15:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-21 03:11:14 ----D---- C:\WINDOWS\system32\WBEM
2009-04-21 03:11:14 ----D---- C:\WINDOWS\AppPatch
2009-04-21 03:04:22 ----A---- C:\WINDOWS\imsins.BAK
2009-04-21 03:01:48 ----HD---- C:\WINDOWS\$hf_mig$
2009-04-07 20:17:57 ----D---- C:\Brians programs
2009-04-07 05:24:17 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-04-07 05:24:16 ----D---- C:\Program Files\NOS
2009-03-31 05:39:22 ----D---- C:\Documents and Settings\All Users\Application Data\NETg
2009-03-29 19:41:33 ----A---- C:\WINDOWS\lexstat.ini
2009-03-21 09:06:58 ----A---- C:\WINDOWS\system32\kernel32.dll
2009-03-17 05:28:08 ----D---- C:\WINDOWS\system32\FxsTmp

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2007-06-20 9072]
R1 DcCam;Kodak Camera Proxy; C:\WINDOWS\system32\DRIVERS\DcCam.sys [2005-06-16 37150]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 NEOFLTR_600_13073;Juniper Networks TDI Filter Driver (NEOFLTR_600_13073); \??\C:\WINDOWS\system32\Drivers\NEOFLTR_600_13073.SYS []
R1 NetworkX;NetworkX; C:\WINDOWS\system32\ckldrv.sys [2006-01-09 31846]
R1 omci;OMCI WDM Device Driver; C:\WINDOWS\system32\DRIVERS\omci.sys [2002-11-08 17217]
R1 tmtdi;Trend Micro TDI Driver; C:\WINDOWS\system32\DRIVERS\tmtdi.sys [2009-03-03 80400]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 ASCTRM;ASCTRM; C:\WINDOWS\system32\drivers\ASCTRM.sys [2004-12-14 8552]
R2 DCFS2K;Kodak DCFS2K Driver; C:\WINDOWS\system32\drivers\dcfs2k.sys [2005-03-31 38673]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R2 tmpreflt;tmpreflt; C:\WINDOWS\system32\DRIVERS\tmpreflt.sys [2009-03-05 36368]
R2 tmxpflt;tmxpflt; C:\WINDOWS\system32\DRIVERS\tmxpflt.sys [2009-03-05 205328]
R2 vsapint;vsapint; C:\WINDOWS\system32\DRIVERS\vsapint.sys [2009-03-05 1195512]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2004-08-25 787456]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys [2004-07-13 645360]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2004-08-06 366384]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys [2004-07-13 6096]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys [2004-07-13 130288]
R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2004-02-10 154112]
R3 Eacfilt;Eacfilt Miniport; C:\WINDOWS\system32\DRIVERS\eacfilt.sys [2003-03-28 9433]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys [2004-07-13 145488]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\System32\drivers\ha10kx2k.sys [2004-08-12 904752]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\System32\drivers\ha10kx2k.sys [2004-08-12 904752]
R3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\System32\drivers\hap16v2k.sys [2004-07-13 148432]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-11-17 1042432]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2003-11-17 212224]
R3 IPSECSHM;Nortel IPSECSHM Adapter; C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2003-03-28 115008]
R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2005-09-20 10368]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2004-07-13 178672]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
R3 tmcfw;Trend Micro Common Firewall Service; C:\WINDOWS\system32\DRIVERS\TM_CFW.sys [2009-03-03 335376]
R3 TMPassthruMP;TMPassthruMP; C:\WINDOWS\system32\DRIVERS\TMPassthru.sys [2008-03-02 206608]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-11-17 680704]
S1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2007-06-20 9200]
S1 Exportit;Exportit; C:\WINDOWS\system32\DRIVERS\exportit.sys [2005-03-31 152081]
S2 IPSECEXT;Nortel Extranet Access Protocol; C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys [2003-03-28 115008]
S2 tmactmon;tmactmon; \??\C:\WINDOWS\system32\drivers\tmactmon.sys []
S2 tmevtmgr;tmevtmgr; \??\C:\WINDOWS\system32\drivers\tmevtmgr.sys []
S3 bvrp_pci;bvrp_pci; C:\WINDOWS\system32\drivers\bvrp_pci.sys []
S3 CO_Mon;CO_Mon; \??\C:\WINDOWS\system32\Drivers\CO_Mon.sys []
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\System32\drivers\ctdvda2k.sys [2003-11-12 333600]
S3 DcFpoint;DcFpoint; C:\WINDOWS\system32\DRIVERS\DcFpoint.sys [2005-03-31 61564]
S3 DcLps;Legacy Polling Service; C:\WINDOWS\system32\DRIVERS\DcLps.sys [2005-03-31 8022]
S3 DcPTP;dcptp; C:\WINDOWS\system32\DRIVERS\DcPTP.sys [2005-03-31 70262]
S3 neokdss;neokdss; C:\WINDOWS\system32\Drivers\neokdss.sys []
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 tbhsd;Tunebite High-Speed Dubbing; C:\WINDOWS\system32\drivers\tbhsd.sys [2008-02-20 27936]
S3 TIEHDUSB;TIEHDUSB; C:\WINDOWS\system32\drivers\tiehdusb.sys [2006-02-03 49536]
S3 TMPassthru;Trend Micro Passthru Ndis Service; C:\WINDOWS\system32\DRIVERS\TMPassthru.sys [2008-03-02 206608]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys []
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.EXE [1999-12-13 44032]
R2 Crypkey License;Crypkey License; C:\WINDOWS\system32\crypserv.exe [2006-01-28 69632]
R2 CwAltaService20;ContentWatch; C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe [2009-05-21 1288512]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-05-31 152984]
R2 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2003-08-29 307200]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 Security Activity Dashboard Service;Security Activity Dashboard Service; C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [2008-08-14 181584]
R2 SfCtlCom;Trend Micro Central Control Component; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [2009-03-31 711248]
R2 TmPfw;Trend Micro Personal Firewall; C:\Program Files\Trend Micro\Internet Security\TmPfw.exe [2009-03-31 497008]
R2 TmProxy;Trend Micro Proxy Service; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [2009-03-31 677128]
R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2004-08-25 389120]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S2 TMBMServer;Trend Micro Unauthorized Change Prevention Service; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [2009-03-03 341256]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
S3 KodakCCS;Kodak Camera Connection Software; C:\WINDOWS\system32\drivers\KodakCCS.exe [2005-03-30 411920]
S3 MSCSPTISRV;MSCSPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [2005-01-26 53337]
S3 NetSvc;Intel NCS NetService; C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe [2003-12-17 143360]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [2005-01-26 53337]
S3 SPTISRV;Sony SPTI Service; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [2005-01-26 69718]
S3 SSScsiSV;SonicStage SCSI Service; C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe [2005-01-24 69632]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm

Re: Google redirect malware

Unread postby Dakeyras » June 15th, 2009, 7:15 am

Hi :)

Viewpoint Software Advice:

This is just to make you aware of the nature of the aforementioned applications. Though not exactly classed as malware they do have some undersirible characteristics. However there is not point uninstalling any of them, as the AIM 6 application you have installed, next time used will download/install the aforementioned again with out your knowledge. Isn't that nice of AOL and their applications :banghead:

Next:

Now please go to Start >> Control Panel >> Add/Remove Programs and remove the following (if present):

Adobe Reader 8.1.3 <-- out of date versions pose a security risk, we will update this in due course.
J2SE Runtime Environment 5.0 Update 2
Java 2 Runtime Environment, SE v1.4.2_03
Java 2 Runtime Environment, SE v1.4.2_06

Java(TM) 6 Update 2
Java(TM) 6 Update 3
Java(TM) 6 Update 7 <-- Having out of date versions installed pose a security risk.
WildTangent Web Driver
Windows Defender <-- Optional Removal, this application is not particularly effective at all.

Note: Take extra care in answering questions posed by any Uninstaller. Some questions may be worded to deceive you into keeping the program.

Next:

Please re-open HiJackThis and select Scan. Check the boxes next to all the entries listed below (if present):

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLa ... uncher.cab
O16 - DPF: {84B7AC1D-9AD1-474F-B6B0-FE1641DBFDFA} - http://contentpurity.net/xp/ScanFile.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{0BFC6C09-81C0-43A3-B888-CC26A1FE4606}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CCS\Services\Tcpip\..\{338F5B52-8863-4497-8D2F-83BEA9FE3C2C}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS1\Services\Tcpip\..\{0BFC6C09-81C0-43A3-B888-CC26A1FE4606}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CS2\Services\Tcpip\..\{0BFC6C09-81C0-43A3-B888-CC26A1FE4606}: NameServer = 85.255.112.205,85.255.112.202
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.205,85.255.112.202


Now click on Fix Checked. Close HiJackThis. Then Reboot(restart) your computer.

Next:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs can be read here
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Image

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Image

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use. ComboFix SHOULD NOT be used unless requested by a forum helper


Repair File Extensions:

Download SREng(System Repair Engineer)

  • Extract it to Desktop and double click SREng.exe to run it
  • Select System Repair from the left pane.
  • Click on File Association
  • Select all entries that has an Error status click [Repair]
  • Refer to this image for an example:

    Image
  • In your case, it would be .scr
  • Close SREng now.

When completed the above, please post back the following:

  • How is you computer performing now? Any problems encountered and or any further symptoms?
  • ComboFix Log.
  • A new HijackThis Log.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8804
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Google redirect malware

Unread postby rsund » June 15th, 2009, 10:56 pm

1) I am able to access Windows Updates and Trend Micro updates successfully. However now when computer reboots I get an error message about an error in winlogin.exe.

2) Combo Fix Log

ComboFix 09-06-15.04 - Richard Sund 06/15/2009 21:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.569 [GMT -5:00]
Running from: c:\documents and settings\Richard Sund\Desktop\ComboFix.exe
AV: Trend Micro Internet Security Pro *On-access scanning disabled* (Outdated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\documents\setup.exe
c:\documents and settings\Mollie & Rich\Application Data\Macromedia\Common\03d6c04a1.dll
c:\documents and settings\Mollie & Rich\Local Settings\Temporary Internet Files\head_firmware.inf
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\gxvxcayvhcwxghbqxkabugtltvffsdrjamuov.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxccwluomonqnknlvpfgihlydxxrlltqjlj.dll
c:\windows\system32\kdfinj.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_GXVXCSERV.SYS


((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.

2009-06-15 01:28 . 2009-06-15 01:28 -------- d-----w- C:\rsit
2009-06-15 01:26 . 2009-06-15 01:27 -------- d-----w- C:\Rooter$
2009-06-06 11:12 . 2009-05-26 18:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-06 11:12 . 2009-06-06 11:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-06 11:12 . 2009-06-06 11:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-06 11:12 . 2009-05-26 18:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-04 22:04 . 2009-06-04 22:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-04 12:50 . 2007-08-02 03:47 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-06-04 01:52 . 2008-03-02 08:28 206608 ----a-w- c:\windows\system32\drivers\TMPassthru.sys
2009-05-31 13:16 . 2009-05-31 13:16 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-31 13:16 . 2009-05-31 13:16 152576 ----a-w- c:\documents and settings\Richard Sund\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-30 17:49 . 2009-05-30 17:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-05-30 17:49 . 2009-05-31 20:51 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\Azureus
2009-05-29 10:05 . 2009-05-29 10:05 -------- d-----w- c:\documents and settings\Mollie & Rich\Local Settings\Application Data\Microsoft Help
2009-05-28 10:12 . 2009-05-28 10:12 56832 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Computer_Associates_International.dll
2009-05-28 10:12 . 2009-05-28 10:12 46080 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Grisoft.dll
2009-05-28 10:12 . 2009-05-28 10:12 33280 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\ALWIL.dll
2009-05-28 10:12 . 2009-05-28 10:12 38912 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Eset.dll
2009-05-28 10:12 . 2009-05-28 10:12 29184 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\MicrosoftAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 76288 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\McAfeeAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 96256 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\NortonAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 29184 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Zone_Labs.dll
2009-05-28 10:12 . 2009-05-28 10:12 31232 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Check_PointAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 72192 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\TrendMicroAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 82030 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\policy_68\hcifpfw.dll
2009-05-27 00:33 . 2009-05-27 00:33 -------- d-----w- c:\documents and settings\Richard Sund\Local Settings\Application Data\Microsoft Help
2009-05-27 00:32 . 2009-05-29 10:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-27 00:21 . 2009-05-27 00:28 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\GetRightToGo
2009-05-25 12:24 . 2009-05-25 12:24 -------- d-----w- c:\documents and settings\Richard Sund\Application Data\FileOpen
2009-05-22 01:40 . 2009-05-22 01:38 81920 ----a-w- c:\windows\system32\wxcode_msw28u_wxjson_CW.dll
2009-05-22 01:40 . 2009-05-22 01:38 991232 ----a-w- c:\windows\system32\wxcode_msw28u_wxcurl_CW.dll
2009-05-17 13:55 . 2009-05-17 13:55 -------- d-----w- c:\program files\MoviesPlay

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 01:59 . 2004-12-15 01:26 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000003-00000000-00000000-00001102-00000004-20061102}.dat
2009-06-16 01:59 . 2004-12-15 01:26 384 ----a-w- c:\windows\system32\DVCState-{00000003-00000000-00000000-00001102-00000004-20061102}.dat
2009-06-16 01:36 . 2004-12-15 01:24 -------- d-----w- c:\program files\Java
2009-06-15 17:26 . 2007-09-28 21:58 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\U3
2009-06-08 11:28 . 2009-06-02 00:46 664 ----a-w- c:\documents and settings\Mollie & Rich\Local Settings\Application Data\d3d9caps.tmp
2009-06-05 11:56 . 2008-06-01 12:23 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-04 02:31 . 2004-12-18 05:48 -------- d-----w- c:\program files\Trend Micro
2009-06-04 01:52 . 2004-12-15 01:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-31 19:53 . 2004-12-18 05:51 120832 ----a-w- c:\documents and settings\Richard Sund\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-30 20:25 . 2008-10-23 22:59 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\uTorrent
2009-05-30 17:49 . 2004-12-18 21:25 120832 ----a-w- c:\documents and settings\Mollie & Rich\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-28 10:12 . 2007-07-28 10:50 49951 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\uninstall.exe
2009-05-28 10:12 . 2007-07-28 10:50 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks
2009-05-27 00:36 . 2004-12-18 04:38 -------- d-----w- c:\program files\Microsoft Works
2009-05-18 01:22 . 2009-05-06 03:05 -------- d-----w- c:\program files\PM FASTrack®
2009-05-11 23:46 . 2009-05-11 23:46 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\GARMIN
2009-05-06 03:06 . 2009-05-06 03:06 4 ----a-w- c:\windows\vx86036.dat
2009-05-05 11:26 . 2009-05-05 11:26 -------- d--h--w- c:\program files\Zero G Registry
2009-05-05 11:26 . 2009-05-05 11:26 -------- d-----w- c:\program files\CertGear
2009-04-22 13:34 . 2007-06-18 10:21 -------- d-----w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks
2009-04-22 13:34 . 2009-04-22 13:34 -------- d-----w- c:\program files\Juniper Networks
2009-04-22 13:34 . 2009-04-22 13:34 57856 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Computer_Associates_International.dll
2009-04-22 13:34 . 2009-04-22 13:34 46080 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Grisoft.dll
2009-04-22 13:34 . 2009-04-22 13:34 32768 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\ALWIL.dll
2009-04-22 13:34 . 2009-04-22 13:34 41472 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Eset.dll
2009-04-22 13:34 . 2009-04-22 13:34 29184 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\MicrosoftAV.dll
2009-04-22 13:34 . 2009-04-22 13:34 76288 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\McAfeeAV.dll
2009-04-22 13:34 . 2009-04-22 13:34 94720 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\NortonAV.dll
2009-04-22 13:34 . 2009-04-22 13:34 29184 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Zone_Labs.dll
2009-04-22 13:34 . 2009-04-22 13:34 31232 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Check_PointAV.dll
2009-04-22 13:34 . 2008-05-23 15:36 70656 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\TrendMicroAV.dll
2009-04-02 23:08 . 2008-12-21 12:59 50192 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2009-04-02 23:08 . 2008-12-21 13:00 50192 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2009-04-01 08:47 . 2009-04-01 08:47 88064 ------w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\CAntiVirusCOM.dll
2009-04-01 08:47 . 2009-04-01 08:47 32768 ------w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\OPSWATProcessesScanner.dll
2009-04-01 08:47 . 2009-04-01 08:47 20992 ------w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AVManager.dll
2009-04-01 08:47 . 2009-04-01 08:47 146944 ------w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\OPSWATAVCommon.dll
2009-03-29 19:04 . 2008-02-24 17:35 163840 ----a-w- c:\documents and settings\Emily\Application Data\Mozilla\Firefox\Profiles\76ccqagn.default\FlashGot.exe
2004-12-31 01:52 . 2004-12-31 01:52 632723 ----a-w- c:\program files\wgr614v4_v5_0_02.img
2003-08-27 20:19 . 2004-12-25 15:33 36963 ----a-r- c:\program files\Common Files\SM1updtr.dll
2007-07-26 21:01 . 2008-03-12 02:24 114688 ----a-w- c:\program files\internet explorer\plugins\ChimeShim.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-02-07 497008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"SM1BG"="c:\windows\SM1BG.EXE" [2003-08-27 94208]
"cwcptray"="c:\program files\ContentWatch\Internet Protection\cwtray.exe" [2009-05-22 352576]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-31 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-02-07 497008]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\SYSTEM32\narrator.exe [2008-04-14 53760]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\CwWLEvent]
2007-04-25 03:56 884736 ----a-w- c:\program files\ContentWatch\Internet Protection\common\cwplc001.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor.lnk
backup=c:\windows\pss\Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"As32Svc"=2 (0x2)
"SSScsiSV"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Nortel Networks\\Extranet.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Edutils\\acted3.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\FrostWire\\FrostWire.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\SYSTEM32\\javaw.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 NEOFLTR_600_13073;Juniper Networks TDI Filter Driver (NEOFLTR_600_13073);c:\windows\SYSTEM32\DRIVERS\NEOFLTR_600_13073.sys [4/30/2008 2:54 PM 64160]
R2 CwAltaService20;ContentWatch;c:\program files\ContentWatch\Internet Protection\cwsvc.exe [6/16/2007 6:21 AM 1288512]
R2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [2/7/2009 6:09 AM 181584]
R2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [12/21/2008 8:00 AM 497008]
R2 tmpreflt;tmpreflt;c:\windows\SYSTEM32\DRIVERS\tmpreflt.sys [12/21/2008 7:51 AM 36368]
R2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [12/21/2008 8:00 AM 677128]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/8/2008 8:21 PM 24652]
R3 Eacfilt;Eacfilt Miniport;c:\windows\SYSTEM32\DRIVERS\eacfilt.sys [2/1/2007 10:04 PM 9433]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\SYSTEM32\DRIVERS\TM_CFW.sys [12/21/2008 7:51 AM 335376]
R3 TMPassthruMP;TMPassthruMP;c:\windows\SYSTEM32\DRIVERS\TMPassthru.sys [6/3/2009 8:52 PM 206608]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\SYSTEM32\DRIVERS\ipsecw2k.sys [2/1/2007 10:04 PM 115008]
S2 tmevtmgr;tmevtmgr;c:\windows\SYSTEM32\DRIVERS\tmevtmgr.sys [12/21/2008 8:00 AM 50192]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\SYSTEM32\DRIVERS\TMPassthru.sys [6/3/2009 8:52 PM 206608]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{61E3FE32-07B9-4563-A3E0-2DE2D620FE10}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder

2009-06-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/?cid=NET_mmhpset
mDefault_Page_URL = hxxp://www.dell4me.com/myway
mStart Page = hxxp://www.comcast.net/
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\cwalsp.dll
Trusted Zone: fujitsu.com\*.netcampus
Trusted Zone: napster.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-15 21:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3121708411-1105498553-3547664071-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-06-16 21:18
ComboFix-quarantined-files.txt 2009-06-16 02:18

Pre-Run: 81,226,838,016 bytes free
Post-Run: 87,652,212,736 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

217 --- E O F --- 2009-05-15 03:48

3) Hijack this log will follow in next post
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm

Re: Google redirect malware

Unread postby rsund » June 15th, 2009, 10:57 pm

Hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:52:00 PM, on 6/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\SM1BG.EXE
C:\Program Files\ContentWatch\Internet Protection\cwtray.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/?cid=NET_mmhpset
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [cwcptray] C:\Program Files\ContentWatch\Internet Protection\cwtray.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O15 - Trusted Zone: http://*.netcampus.fujitsu.com
O15 - Trusted Zone: http://*.napster.com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://secure.dmr.com/postauthI/epi.cab
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - https://www.contentwatch.com/audit/incl ... ontrol.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://fc.webex.com/client/v_mywebex-t ... eatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://sslvpn.consulting-fujitsu.com/d ... tupSP1.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/ins ... downde.cab
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ContentWatch (CwAltaService20) - ContentWatch, Inc. - C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Security Activity Dashboard Service - Trend Micro Inc. - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 12354 bytes
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm

Re: Google redirect malware

Unread postby Dakeyras » June 16th, 2009, 7:07 am

Hi :)

I am able to access Windows Updates and Trend Micro updates successfully.
Good to know.

However now when computer reboots I get an error message about an error in winlogin.exe.
Hmm not seeing anything in the logs to account for this are you sure you do mean Winlogin and not Winlogon? We can check this out however.

DelDomains:

  • Right click Here and select Save Targat As... to download WinHelp2002's DelDomains.inf.
  • Please save the file to the desktop.
  • To run the inf file right click on it and select Install.

Custom ComboFix-Script:

A word of warning: Please do not run ComboFix on your own. This tool is not a toy and not for everyday use.

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    Code: Select all
    File::
    c:\windows\system32\wxcode_msw28u_wxjson_CW.dll
    c:\windows\system32\wxcode_msw28u_wxcurl_CW.dll
    c:\windows\system32\DVCStateBkp-{00000003-00000000-00000000-00001102-00000004-20061102}.dat
    c:\windows\system32\DVCState-{00000003-00000000-00000000-00001102-00000004-20061102}.dat
    c:\documents and settings\Mollie & Rich\Local Settings\Application Data\d3d9caps.tmp
    
    Folder::
    c:\documents and settings\All Users\Application Data\Azureus
    c:\documents and settings\Mollie & Rich\Application Data\uTorrent
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "UserFaultCheck"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "As32Svc"=-
    "SSScsiSV"=-
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Documents and Settings\\All Users\\Documents\\FrostWire\\FrostWire.exe"=-
    "c:\\Documents and Settings\\All Users\\Documents\\Soulseek\\slsk.exe"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    [-HKEY_CLASSES_ROOT\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{BA52B914-B692-46c4-B683-905236F6F655}"=-
    [-HKEY_CLASSES_ROOT\CLSID\{BA52B914-B692-46c4-B683-905236F6F655}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    Image

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Malwarebytes Anti-Malware:

  • Launch the application, Check for Updates >> Perform a Quick Scan
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

F-Secure Blacklight:

Please download Blacklight from here to your desktop.

or

Link to it from the ftp site: ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe
and save it to your desktop from there.

Go to Start-->Run, copy in the following text, and press Enter:
"%userprofile%\desktop\fsbl.exe" /expert
Accept the license agreement.
Click > scan, wait for it to finish, then click Close

There will be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).
Copy and paste the contents of this log into your next reply.

When completed the above, please post back the following:

  • How is you computer performing now? Any problems encountered and or any further symptoms?
  • ComboFix Log.
  • Malwarebytes Anti-Malware Log.
  • Blacklight Log.
  • A new HijackThis Log.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8804
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Google redirect malware

Unread postby rsund » June 16th, 2009, 8:24 pm

You are correct the error is related to Winlogon.exe

The error is still occurring.

Combofix log follows:
ComboFix 09-06-16.01 - Richard Sund 06/16/2009 18:17.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.540 [GMT -5:00]
Running from: c:\documents and settings\Richard Sund\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Richard Sund\Desktop\CFScript.txt
AV: Trend Micro Internet Security Pro *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}

FILE ::
"c:\documents and settings\Mollie & Rich\Local Settings\Application Data\d3d9caps.tmp"
"c:\windows\system32\DVCState-{00000003-00000000-00000000-00001102-00000004-20061102}.dat"
"c:\windows\system32\DVCStateBkp-{00000003-00000000-00000000-00001102-00000004-20061102}.dat"
"c:\windows\system32\wxcode_msw28u_wxcurl_CW.dll"
"c:\windows\system32\wxcode_msw28u_wxjson_CW.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Azureus
c:\documents and settings\Mollie & Rich\Application Data\uTorrent
c:\documents and settings\Mollie & Rich\Desktop\STOPzilla_Setup.exe
c:\documents and settings\All Users\Application Data\Azureus\azCID.txt
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\Adobe CS3 Photoshop Extended and Illustrator - All Cracked.1.torrent
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\Adobe CS3 Photoshop Extended and Illustrator - All Cracked.torrent
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\dht.dat
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\Photoshop CS2.zip.torrent
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\resume.dat
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\rss.dat
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\settings.dat
c:\documents and settings\Mollie & Rich\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Mollie & Rich\Local Settings\Application Data\d3d9caps.tmp
c:\windows\system32\DVCState-{00000003-00000000-00000000-00001102-00000004-20061102}.dat
c:\windows\system32\DVCStateBkp-{00000003-00000000-00000000-00001102-00000004-20061102}.dat
c:\windows\system32\wxcode_msw28u_wxcurl_CW.dll
c:\windows\system32\wxcode_msw28u_wxjson_CW.dll

.
((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.

2009-06-16 23:26 . 2009-06-16 23:26 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000003-00000000-00000000-00001102-00000004-20061102}.dat
2009-06-16 23:26 . 2009-06-16 23:26 384 ----a-w- c:\windows\system32\DVCState-{00000003-00000000-00000000-00001102-00000004-20061102}.dat
2009-06-16 21:19 . 2008-10-16 19:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-06-16 10:31 . 2009-06-16 10:31 -------- d-----w- c:\documents and settings\Richard Sund\Application Data\Malwarebytes
2009-06-15 01:28 . 2009-06-15 01:28 -------- d-----w- C:\rsit
2009-06-15 01:26 . 2009-06-15 01:27 -------- d-----w- C:\Rooter$
2009-06-06 11:12 . 2009-05-26 18:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-06 11:12 . 2009-06-06 11:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-06 11:12 . 2009-06-06 11:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-06 11:12 . 2009-05-26 18:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-04 22:04 . 2009-06-04 22:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-04 12:50 . 2009-04-02 23:08 153104 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-06-04 01:52 . 2008-03-02 08:28 206608 ----a-w- c:\windows\system32\drivers\TMPassthru.sys
2009-05-31 13:16 . 2009-05-31 13:16 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-31 13:16 . 2009-05-31 13:16 152576 ----a-w- c:\documents and settings\Richard Sund\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-30 17:49 . 2009-05-31 20:51 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\Azureus
2009-05-29 10:05 . 2009-05-29 10:05 -------- d-----w- c:\documents and settings\Mollie & Rich\Local Settings\Application Data\Microsoft Help
2009-05-28 10:12 . 2009-05-28 10:12 56832 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Computer_Associates_International.dll
2009-05-28 10:12 . 2009-05-28 10:12 46080 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Grisoft.dll
2009-05-28 10:12 . 2009-05-28 10:12 33280 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\ALWIL.dll
2009-05-28 10:12 . 2009-05-28 10:12 38912 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Eset.dll
2009-05-28 10:12 . 2009-05-28 10:12 29184 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\MicrosoftAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 76288 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\McAfeeAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 96256 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\NortonAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 29184 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Zone_Labs.dll
2009-05-28 10:12 . 2009-05-28 10:12 31232 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\Check_PointAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 72192 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AV\TrendMicroAV.dll
2009-05-28 10:12 . 2009-05-28 10:12 82030 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\policy_68\hcifpfw.dll
2009-05-27 00:33 . 2009-05-27 00:33 -------- d-----w- c:\documents and settings\Richard Sund\Local Settings\Application Data\Microsoft Help
2009-05-27 00:32 . 2009-06-16 10:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-27 00:21 . 2009-05-27 00:28 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\GetRightToGo
2009-05-25 12:24 . 2009-05-25 12:24 -------- d-----w- c:\documents and settings\Richard Sund\Application Data\FileOpen

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 10:29 . 2004-12-18 04:38 -------- d-----w- c:\program files\Microsoft Works
2009-06-16 01:36 . 2004-12-15 01:24 -------- d-----w- c:\program files\Java
2009-06-15 17:26 . 2007-09-28 21:58 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\U3
2009-06-05 11:56 . 2008-06-01 12:23 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-04 02:31 . 2004-12-18 05:48 -------- d-----w- c:\program files\Trend Micro
2009-06-04 01:52 . 2004-12-15 01:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-31 19:53 . 2004-12-18 05:51 120832 ----a-w- c:\documents and settings\Richard Sund\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-30 17:49 . 2004-12-18 21:25 120832 ----a-w- c:\documents and settings\Mollie & Rich\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-28 10:12 . 2007-07-28 10:50 49951 ----a-w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\uninstall.exe
2009-05-28 10:12 . 2007-07-28 10:50 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks
2009-05-18 01:22 . 2009-05-06 03:05 -------- d-----w- c:\program files\PM FASTrack®
2009-05-17 13:55 . 2009-05-17 13:55 -------- d-----w- c:\program files\MoviesPlay
2009-05-11 23:46 . 2009-05-11 23:46 -------- d-----w- c:\documents and settings\Mollie & Rich\Application Data\GARMIN
2009-05-07 15:32 . 2004-08-04 11:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 03:06 . 2009-05-06 03:06 4 ----a-w- c:\windows\vx86036.dat
2009-05-05 11:26 . 2009-05-05 11:26 -------- d--h--w- c:\program files\Zero G Registry
2009-05-05 11:26 . 2009-05-05 11:26 -------- d-----w- c:\program files\CertGear
2009-04-29 04:46 . 2004-08-04 11:00 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2004-08-04 11:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-22 13:34 . 2007-06-18 10:21 -------- d-----w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks
2009-04-22 13:34 . 2009-04-22 13:34 -------- d-----w- c:\program files\Juniper Networks
2009-04-22 13:34 . 2009-04-22 13:34 57856 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Computer_Associates_International.dll
2009-04-22 13:34 . 2009-04-22 13:34 46080 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Grisoft.dll
2009-04-22 13:34 . 2009-04-22 13:34 32768 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\ALWIL.dll
2009-04-22 13:34 . 2009-04-22 13:34 41472 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Eset.dll
2009-04-22 13:34 . 2009-04-22 13:34 29184 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\MicrosoftAV.dll
2009-04-22 13:34 . 2009-04-22 13:34 76288 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\McAfeeAV.dll
2009-04-22 13:34 . 2009-04-22 13:34 94720 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\NortonAV.dll
2009-04-22 13:34 . 2009-04-22 13:34 29184 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Zone_Labs.dll
2009-04-22 13:34 . 2009-04-22 13:34 31232 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\Check_PointAV.dll
2009-04-22 13:34 . 2008-05-23 15:36 70656 ----a-w- c:\documents and settings\Richard Sund\Application Data\Juniper Networks\Host Checker\AV\TrendMicroAV.dll
2009-04-17 12:26 . 2004-08-04 11:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 11:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-02 23:08 . 2008-12-21 12:59 50192 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2009-04-02 23:08 . 2008-12-21 13:00 50192 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2009-04-01 08:47 . 2009-04-01 08:47 88064 ------w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\CAntiVirusCOM.dll
2009-04-01 08:47 . 2009-04-01 08:47 32768 ------w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\OPSWATProcessesScanner.dll
2009-04-01 08:47 . 2009-04-01 08:47 20992 ------w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\AVManager.dll
2009-04-01 08:47 . 2009-04-01 08:47 146944 ------w- c:\documents and settings\Mollie & Rich\Application Data\Juniper Networks\Host Checker\OPSWATAVCommon.dll
2009-03-29 19:04 . 2008-02-24 17:35 163840 ----a-w- c:\documents and settings\Emily\Application Data\Mozilla\Firefox\Profiles\76ccqagn.default\FlashGot.exe
2004-12-31 01:52 . 2004-12-31 01:52 632723 ----a-w- c:\program files\wgr614v4_v5_0_02.img
2003-08-27 20:19 . 2004-12-25 15:33 36963 ----a-r- c:\program files\Common Files\SM1updtr.dll
2007-07-26 21:01 . 2008-03-12 02:24 114688 ----a-w- c:\program files\internet explorer\plugins\ChimeShim.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-16_02.16.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-16 23:06 . 2009-06-16 23:06 16384 c:\windows\Temp\Perflib_Perfdata_728.dat
+ 2009-06-16 23:28 . 2009-06-16 23:28 16384 c:\windows\Temp\Perflib_Perfdata_6dc.dat
+ 2004-12-18 04:39 . 2007-04-09 18:23 28552 c:\windows\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll
+ 2004-12-18 04:39 . 2007-04-09 18:23 46472 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\mdiui.dll
+ 2004-12-18 04:39 . 2007-04-09 18:23 46472 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\mdiui.dll
- 2007-01-28 18:42 . 2007-11-30 12:39 17272 c:\windows\SYSTEM32\spmsg.dll
+ 2007-01-28 18:42 . 2008-07-09 07:38 17272 c:\windows\SYSTEM32\spmsg.dll
+ 2004-12-18 04:39 . 2007-04-09 18:23 28040 c:\windows\SYSTEM32\mdimon.dll
+ 2009-02-20 08:10 . 2009-04-29 04:46 81920 c:\windows\SYSTEM32\DLLCACHE\ieencode.dll
- 2009-02-20 08:10 . 2009-02-20 08:10 81920 c:\windows\SYSTEM32\DLLCACHE\ieencode.dll
+ 2009-06-16 21:19 . 2009-06-16 21:44 16756 c:\windows\SoftwareDistribution\EventCache\{2F0301D5-0B29-41E5-982F-A58A369B0FF7}.bin
- 2004-12-18 04:39 . 2009-05-30 18:30 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2004-12-18 04:39 . 2009-05-30 18:30 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2004-12-18 04:39 . 2009-05-30 18:30 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2004-12-18 04:39 . 2009-05-30 18:30 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2009-05-27 00:37 . 2009-05-29 10:05 35088 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-05-27 00:37 . 2009-06-16 10:30 35088 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-05-27 00:37 . 2009-06-16 10:30 18704 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-05-27 00:37 . 2009-05-29 10:05 18704 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-05-27 00:37 . 2009-05-29 10:05 20240 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-05-27 00:37 . 2009-06-16 10:30 20240 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\cagicon.exe
+ 2001-06-05 14:13 . 2001-06-05 14:13 40972 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OCRVC.DAT
+ 2001-10-23 06:13 . 2001-10-23 06:13 53260 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\OCRHC.DAT
+ 2001-06-05 14:13 . 2001-06-05 14:13 65536 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\LOOKUP.DAT
+ 2001-06-05 14:13 . 2001-06-05 14:13 18844 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\JFONT.DAT
+ 2001-06-05 14:13 . 2001-06-05 14:13 34168 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\ENGIDX.DAT
+ 2003-01-17 20:03 . 2003-01-17 20:03 59466 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\XSCAN32.DAT
+ 2004-12-18 04:38 . 2004-12-18 04:38 64088 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\VBIDEPIA.DLL
+ 2003-07-15 04:57 . 2003-07-15 04:57 59960 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\UNBIND.EXE
+ 2002-10-07 15:49 . 2002-10-07 15:49 81983 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TWRECS.DLL
+ 2003-07-15 05:00 . 2003-07-15 05:00 99904 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TRANSMGR.DLL
+ 2003-07-15 04:57 . 2003-07-15 04:57 58944 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
+ 2003-07-15 04:44 . 2003-07-15 04:44 66616 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\SENDTO.DLL
+ 2002-10-07 15:49 . 2002-10-07 15:49 81984 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\REVERSE.DLL
+ 2003-07-15 04:57 . 2003-07-15 04:57 40512 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
+ 2003-05-09 03:54 . 2003-05-09 03:54 77824 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
+ 2003-07-15 04:42 . 2003-07-15 04:42 37432 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\RECALL.DLL
+ 2003-07-15 09:18 . 2003-07-15 09:18 93752 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
+ 2003-07-15 04:43 . 2003-07-15 04:43 49208 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OUTLWAB.DLL
+ 2003-07-15 04:43 . 2003-07-15 04:43 64056 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OUTLRPC.DLL
+ 2003-07-15 04:44 . 2003-07-15 04:44 88128 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OUTLMIME.DLL
+ 2004-12-18 04:38 . 2004-12-18 04:38 35448 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OLCTLPIA.DLL
+ 2003-07-15 09:14 . 2003-07-15 09:14 27192 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
+ 2003-07-15 04:56 . 2003-07-15 04:56 13888 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
+ 2003-07-15 04:57 . 2003-07-15 04:57 56888 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\NAME.DLL
+ 2004-12-18 04:38 . 2004-12-18 04:38 20080 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSTAGPIA.DLL
+ 2003-07-15 04:52 . 2003-07-15 04:52 41528 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
+ 2003-06-18 23:31 . 2003-06-18 23:31 16384 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
+ 2003-07-15 04:45 . 2003-07-15 04:45 39488 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
+ 2003-07-15 04:45 . 2003-07-15 04:45 55360 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
+ 2003-07-15 04:46 . 2003-07-15 04:46 42040 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
+ 2003-07-15 04:53 . 2003-07-15 04:53 39488 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSOSVFBR.DLL
+ 2003-07-15 04:53 . 2003-07-15 04:53 55872 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSOSVABW.DLL
+ 2003-07-15 04:52 . 2003-07-15 04:52 28224 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSOSTYLE.DLL
+ 2003-07-15 04:56 . 2003-07-15 04:56 54328 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSOMSE.DLL
+ 2003-07-15 04:52 . 2003-07-15 04:52 55360 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSOHTMED.EXE
+ 2003-07-15 04:52 . 2003-07-15 04:52 27704 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSODCW.DLL
+ 2003-07-15 04:52 . 2003-07-15 04:52 17464 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSMH.DLL
+ 2003-07-15 04:51 . 2003-07-15 04:51 87104 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSENCODE.DLL
+ 2003-07-15 04:56 . 2003-07-15 04:56 40504 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSE7.EXE
+ 2003-07-15 04:41 . 2003-07-15 04:41 13368 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\FINDER.EXE
+ 2003-07-15 04:57 . 2003-07-15 04:57 98360 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\DSSM.EXE
+ 2003-07-15 04:56 . 2003-07-15 04:56 14904 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\DSITF.DLL
+ 2003-07-26 00:57 . 2003-07-26 00:57 75832 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\DLGSETP.DLL
+ 2003-07-15 09:18 . 2003-07-15 09:18 47160 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\DFUICOM.EXE
+ 2003-07-15 04:53 . 2003-07-15 04:53 46144 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\BLNMGRPS.DLL
+ 2003-07-15 04:53 . 2003-07-15 04:53 60984 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\BLNMGR.DLL
+ 2003-07-15 04:53 . 2003-07-15 04:53 94768 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\AW.DLL
+ 2003-07-15 04:57 . 2003-07-15 04:57 38968 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\AUTHZAX.DLL
+ 2003-07-15 04:43 . 2003-07-15 04:43 87616 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\ADDRPARS.DLL
+ 1999-11-25 00:40 . 1999-11-25 00:40 40960 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.6425\VBAME.DLL
+ 1998-08-09 17:07 . 1998-08-09 17:07 86016 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.6425\MSADDNDR.DLL
+ 2006-10-27 02:17 . 2006-10-27 02:17 11072 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\XLCALL32.DLL
+ 2006-10-27 02:13 . 2006-10-27 02:13 72472 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\XL12CNVP.DLL
+ 2006-10-27 20:11 . 2006-10-27 20:11 21264 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\WRD12EXE.EXE
+ 2009-05-27 00:36 . 2009-05-27 00:36 12096 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\WORDPOL.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 12080 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\VBIDEPOL.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 64288 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\VBIDEPIA.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 15672 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\SMARTTAGINSTALL.EXE
+ 2006-10-27 00:49 . 2006-10-27 00:49 34104 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\SETLANG.EXE
+ 2006-10-27 01:12 . 2006-10-27 01:12 40424 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\REFIEBAR.DLL
+ 2006-10-27 02:13 . 2006-10-27 02:13 38168 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\REFEDIT.DLL
+ 2006-10-27 01:09 . 2006-10-27 01:09 48448 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PUBTRAP.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 12112 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PPTPOL.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 46936 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OSETUPPS.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 18760 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OPHPROXY.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 16728 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OMUOPTINPS.DLL
+ 2006-10-27 01:00 . 2006-10-27 01:00 23392 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OISCTRL.DLL
+ 2006-10-27 20:11 . 2006-10-27 20:11 54680 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OFFRHD.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 11544 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OFFICEPL.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 65824 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\NAME.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 12104 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSTAGPOL.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 20280 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSTAGPIA.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 43832 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSSH.DLL
+ 2006-10-27 20:26 . 2006-10-27 20:26 35152 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSOSTYLE.DLL
+ 2006-10-27 00:52 . 2006-10-27 00:52 66368 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSOMSE.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 67896 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSOHTMED.EXE
+ 2006-10-27 20:01 . 2006-10-27 20:01 76088 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSOHEV.DLL
+ 2006-10-27 02:13 . 2006-10-27 02:13 26936 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSOEURO.DLL
+ 2006-10-27 00:48 . 2006-10-27 00:48 14664 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSOCFU.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 19768 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSMH.DLL
+ 2006-10-27 00:52 . 2006-10-27 00:52 48424 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSE7.EXE
+ 2006-10-27 01:12 . 2006-10-27 01:12 89400 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\METCONV.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 12096 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\GRAPHPOL.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 12096 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\EXCELPOL.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 53576 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\AUTHZAX.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 56120 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACERCLR.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 15160 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEODTXT.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 15160 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEODPDX.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 15160 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEODEXL.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 15160 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEODDBS.DLL
+ 2006-10-27 20:00 . 2006-10-27 20:00 47976 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEERR.DLL
+ 2009-06-16 10:29 . 2009-06-16 10:29 10576 c:\windows\ASSEMBLY\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
+ 2009-06-16 10:29 . 2009-06-16 10:29 11112 c:\windows\ASSEMBLY\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2009-06-16 10:30 . 2009-06-16 10:30 11128 c:\windows\ASSEMBLY\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2009-06-16 10:29 . 2009-06-16 10:29 11136 c:\windows\ASSEMBLY\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2009-06-16 10:30 . 2009-06-16 10:30 11152 c:\windows\ASSEMBLY\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2009-06-16 10:29 . 2009-06-16 10:29 11128 c:\windows\ASSEMBLY\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2009-06-16 10:29 . 2009-06-16 10:29 11144 c:\windows\ASSEMBLY\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2009-06-16 10:29 . 2009-06-16 10:29 63336 c:\windows\ASSEMBLY\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-06-16 10:21 . 2009-06-16 10:21 66936 c:\windows\ASSEMBLY\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-06-16 10:29 . 2009-06-16 10:29 19320 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-06-16 10:22 . 2009-06-16 10:22 22928 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.SmartTag\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-06-16 10:22 . 2009-06-16 10:22 38304 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.OutlookViewCtl\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.OutlookViewCtl.dll
- 2004-12-18 04:39 . 2009-05-30 18:30 4096 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 4096 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2003-06-18 23:31 . 2003-06-18 23:31 6144 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OCRPS.DLL
+ 2004-08-04 11:00 . 2009-04-29 04:46 620032 c:\windows\SYSTEM32\urlmon.dll
+ 2004-12-18 04:39 . 2007-04-09 18:24 758664 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\mdigraph.dll
+ 2004-12-18 04:39 . 2007-04-09 18:24 758664 c:\windows\SYSTEM32\SPOOL\DRIVERS\W32X86\3\mdigraph.dll
+ 2008-10-16 19:07 . 2008-10-16 19:07 208744 c:\windows\SYSTEM32\muweb.dll
+ 2004-08-11 23:20 . 2009-06-16 11:18 423024 c:\windows\SYSTEM32\FNTCACHE.DAT
- 2004-08-11 23:20 . 2009-05-30 19:59 423024 c:\windows\SYSTEM32\FNTCACHE.DAT
+ 2008-04-21 06:44 . 2009-04-29 04:46 666624 c:\windows\SYSTEM32\DLLCACHE\wininet.dll
+ 2008-06-26 08:15 . 2009-04-29 04:46 620032 c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
+ 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\SYSTEM32\DLLCACHE\rpcrt4.dll
+ 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\SYSTEM32\DLLCACHE\localspl.dll
+ 2009-06-16 23:15 . 2009-06-16 23:15 389120 c:\windows\SYSTEM32\CF662.exe
- 2004-12-18 04:39 . 2009-05-30 18:30 409600 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 409600 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2004-12-18 04:39 . 2009-05-30 18:30 286720 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 286720 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2004-12-18 04:39 . 2009-05-30 18:30 249856 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 249856 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 794624 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2004-12-18 04:39 . 2009-05-30 18:30 794624 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2004-12-18 04:39 . 2009-06-16 10:24 135168 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2004-12-18 04:39 . 2009-05-30 18:30 135168 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-05-27 00:37 . 2009-06-16 10:30 888080 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-05-27 00:37 . 2009-05-29 10:05 888080 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-05-27 00:37 . 2009-05-29 10:05 272648 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-05-27 00:37 . 2009-06-16 10:30 272648 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\pubs.exe
- 2009-05-27 00:37 . 2009-05-29 10:05 922384 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-05-27 00:37 . 2009-06-16 10:30 922384 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\pptico.exe
- 2009-05-27 00:37 . 2009-05-29 10:05 845584 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-05-27 00:37 . 2009-06-16 10:30 845584 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-05-27 00:37 . 2009-06-16 10:30 217864 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\misc.exe
- 2009-05-27 00:37 . 2009-05-29 10:05 217864 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\misc.exe
+ 2009-06-16 10:25 . 2009-06-16 10:25 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2009-05-29 10:04 . 2009-05-29 10:04 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2005-05-04 05:06 . 2005-05-04 05:06 199408 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSMDUN80.DLL
+ 2005-05-04 05:06 . 2005-05-04 05:06 465640 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSDMENG.DLL
+ 2001-06-05 14:13 . 2001-06-05 14:13 289926 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\ENGDIC.DAT
+ 2004-12-18 04:38 . 2004-12-18 04:38 662120 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\WORDPIA.DLL
+ 2002-10-07 15:51 . 2002-10-07 15:51 221252 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TWSTRUCT.DLL
+ 2002-10-07 15:50 . 2002-10-07 15:50 118847 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TWRECE.DLL
+ 2002-10-07 15:51 . 2002-10-07 15:51 102467 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TWORIENT.DLL
+ 2002-10-07 15:51 . 2002-10-07 15:51 147520 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TWLAY32.DLL
+ 2002-10-07 15:51 . 2002-10-07 15:51 180289 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TWCUTLIN.DLL
+ 2002-10-07 15:50 . 2002-10-07 15:50 241729 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TWCUTCHR.DLL
+ 2002-10-07 15:53 . 2002-10-07 15:53 106561 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\THOCRAPI.DLL
+ 2003-07-15 04:57 . 2003-07-15 04:57 349248 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\SELFCERT.EXE
+ 2003-07-21 17:46 . 2003-07-21 17:46 390712 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\RTFHTML.DLL
+ 2002-10-07 16:11 . 2002-10-07 16:11 167997 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\PSOM.DLL
+ 2004-12-18 04:38 . 2004-12-18 04:38 223856 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\PPTPIA.DLL
+ 2003-07-15 09:18 . 2003-07-15 09:18 430136 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\PP4X322.DLL
+ 2004-12-18 04:38 . 2004-12-18 04:38 461416 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OWC11PIA.DLL
+ 2004-12-18 04:38 . 2004-12-18 04:38 408176 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OUTLPIA.DLL
+ 2003-07-15 04:44 . 2003-07-15 04:44 102968 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OUTLCTL.DLL
+ 2003-07-15 09:14 . 2003-07-15 09:14 242240 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OISGRAPH.DLL
+ 2003-07-15 09:14 . 2003-07-15 09:14 283696 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OIS.EXE
+ 2004-12-18 04:38 . 2004-12-18 04:38 223800 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OFFICE.DLL
+ 2003-07-15 05:00 . 2003-07-15 05:00 145984 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSWEBCAP.DLL
+ 2003-07-15 05:02 . 2003-07-15 05:02 637496 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSQRY32.EXE
+ 2003-06-19 22:05 . 2003-06-19 22:05 364648 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSPVIEW.EXE
+ 2003-06-19 22:05 . 2003-06-19 22:05 128104 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSPSCAN.EXE
+ 2003-06-18 23:31 . 2003-06-18 23:31 788480 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSPFILT.DLL
+ 2003-07-15 04:57 . 2003-07-15 04:57 120888 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSOAUTH.DLL
+ 2003-07-15 04:58 . 2003-07-15 04:58 230968 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSCDM.DLL
+ 2003-07-15 04:46 . 2003-07-15 04:46 176696 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MIMEDIR.DLL
+ 2003-06-18 23:31 . 2003-06-18 23:31 443904 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MDIVWCTL.DLL
+ 2003-06-18 23:31 . 2003-06-18 23:31 252928 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MDIINK.DLL
+ 2003-07-24 04:32 . 2003-07-24 04:32 121400 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\IMPMAIL.DLL
+ 2004-12-18 04:38 . 2004-12-18 04:38 141928 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\GRAPHPIA.DLL
+ 2002-10-07 15:49 . 2002-10-07 15:49 192573 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\FORM.DLL
+ 2000-05-24 04:45 . 2000-05-24 04:45 118784 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.6425\MSSTDFMT.DLL
+ 2006-10-27 01:49 . 2006-10-27 01:49 509200 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\WRD12CVR.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 781104 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\WORDPIA.DLL
+ 2006-10-27 20:23 . 2006-10-27 20:23 347432 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\WINWORD.EXE
+ 2006-10-27 01:06 . 2006-10-27 01:06 439600 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\SETUP.EXE
+ 2006-10-27 01:13 . 2006-10-27 01:13 503624 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\SELFCERT.EXE
+ 2006-10-27 01:09 . 2006-10-27 01:09 590144 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PUBCONV.DLL
+ 2006-10-27 20:04 . 2006-10-27 20:04 624456 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PTXT9.DLL
+ 2006-10-27 01:09 . 2006-10-27 01:09 136008 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PRTF9.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 248632 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PPTPIA.DLL
+ 2006-10-27 02:07 . 2006-10-27 02:07 368968 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PPSLAX.DLL
+ 2006-10-27 20:04 . 2006-10-27 20:04 465200 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\POWERPNT.EXE
+ 2006-10-27 02:30 . 2006-10-27 02:30 482088 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PORTCONN.DLL
+ 2006-07-26 23:53 . 2006-07-26 23:53 459080 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OUTLFLTR.DLL
+ 2006-10-27 01:00 . 2006-10-27 01:00 285008 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OISGRAPH.DLL
+ 2006-10-27 01:00 . 2006-10-27 01:00 998208 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OISAPP.DLL
+ 2006-10-27 01:00 . 2006-10-27 01:00 274744 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OIS.EXE
+ 2006-10-20 13:37 . 2006-10-20 13:37 637744 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OGALEGIT.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 416544 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OFFICE.DLL
+ 2006-10-27 01:06 . 2006-10-27 01:06 232816 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ODEPLOY.EXE
+ 2006-10-27 00:55 . 2006-10-27 00:55 538904 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSTORES.DLL
+ 2006-10-27 00:55 . 2006-10-27 00:55 145688 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSTORE.EXE
+ 2006-10-27 00:55 . 2006-10-27 00:55 832800 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSTORDB.EXE
+ 2006-10-26 18:56 . 2006-10-26 18:56 505136 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSSOAP30.DLL
+ 2006-10-27 00:50 . 2006-10-27 00:50 672024 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSQRY32.EXE
+ 2006-10-26 19:47 . 2006-10-26 19:47 727840 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSPROOF6.DLL
+ 2006-10-26 18:56 . 2006-10-26 18:56 436520 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSORUN.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 428816 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSODCW.DLL
+ 2006-10-27 19:59 . 2006-10-27 19:59 161080 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSOCF.DLL
+ 2006-10-26 18:58 . 2006-10-26 18:58 117552 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSCONV97.DLL
+ 2006-10-27 20:04 . 2006-10-27 20:04 497504 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MORPH9.DLL
+ 2006-10-27 00:52 . 2006-10-27 00:52 460616 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MODHELP.DLL
+ 2006-10-27 00:55 . 2006-10-27 00:55 828704 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MEDCAT.DLL
+ 2006-10-27 01:00 . 2006-10-27 01:00 178488 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\IETAG.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 173328 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\IEAWSDC.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 150320 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\GRAPHPIA.DLL
+ 2006-10-27 20:09 . 2006-10-27 20:09 983376 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\FPWEC.DLL
+ 2006-10-27 00:48 . 2006-10-27 00:48 434528 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\DWTRIG20.EXE
+ 2006-10-27 00:48 . 2006-10-27 00:48 439568 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\DWDCW20.DLL
+ 2006-10-27 01:12 . 2006-10-27 01:12 106824 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\DSSM.EXE
+ 2006-10-27 01:12 . 2006-10-27 01:12 189760 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\CONTACTPICKER.DLL
+ 2006-10-27 00:59 . 2006-10-27 00:59 205616 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\CLVIEW.EXE
+ 2006-10-27 20:41 . 2006-10-27 20:41 399640 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\CDLMSO.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 371568 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEXBE.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 224104 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACETXT.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 551800 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEREP.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 289648 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACER3X.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 260976 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACER2X.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 392048 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEPDE.DLL
+ 2006-10-27 20:00 . 2006-10-27 20:00 387960 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEOLEDB.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 279352 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEODBC.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 207736 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACELTS.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 629616 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEEXCL.DLL
+ 2006-10-27 01:13 . 2006-10-27 01:13 338800 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEEXCH.DLL
+ 2006-10-27 20:00 . 2006-10-27 20:00 191360 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEES.DLL
+ 2006-10-27 20:00 . 2006-10-27 20:00 576376 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACEDAO.DLL
+ 2006-10-27 00:49 . 2006-10-27 00:49 970528 c:\windows\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSONSEXT.DLL
+ 2009-06-16 10:29 . 2009-06-16 10:29 423784 c:\windows\ASSEMBLY\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-06-16 10:21 . 2009-06-16 10:21 226656 c:\windows\ASSEMBLY\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-06-16 10:29 . 2009-06-16 10:29 870256 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2009-06-16 10:22 . 2009-06-16 10:22 664968 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.Word\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2009-06-16 10:30 . 2009-06-16 10:30 350064 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2009-06-16 10:22 . 2009-06-16 10:22 226712 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.PowerPoint\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2009-06-16 10:22 . 2009-06-16 10:22 464272 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.Owc11\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Owc11.dll
+ 2009-06-16 10:22 . 2009-06-16 10:22 411024 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.Outlook\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll
+ 2009-06-16 10:29 . 2009-06-16 10:29 149352 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2009-06-16 10:21 . 2009-06-16 10:21 144784 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.Graph\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
- 2004-08-04 11:00 . 2009-03-02 23:04 1499136 c:\windows\SYSTEM32\shdocvw.dll
+ 2004-08-04 11:00 . 2009-04-29 04:46 1499136 c:\windows\SYSTEM32\shdocvw.dll
+ 2004-08-04 11:00 . 2009-04-29 04:46 3068928 c:\windows\SYSTEM32\mshtml.dll
+ 2008-11-21 04:06 . 2008-11-21 04:06 1194848 c:\windows\SYSTEM32\FM20.DLL
+ 2008-10-15 01:23 . 2009-04-17 12:26 1847168 c:\windows\SYSTEM32\DLLCACHE\win32k.sys
- 2008-06-26 08:15 . 2009-03-02 23:04 1499136 c:\windows\SYSTEM32\DLLCACHE\shdocvw.dll
+ 2008-06-26 08:15 . 2009-04-29 04:46 1499136 c:\windows\SYSTEM32\DLLCACHE\shdocvw.dll
+ 2008-04-21 06:44 . 2009-04-29 04:46 3068928 c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
+ 2009-05-27 00:37 . 2009-06-16 10:30 1172240 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-05-27 00:37 . 2009-05-29 10:05 1172240 c:\windows\Installer\{91120000-00CA-0000-0000-0000000FF1CE}\xlicons.exe
+ 2006-09-27 02:01 . 2006-09-27 02:01 2113536 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSOLAP80.DLL
+ 2005-05-04 05:06 . 2005-05-04 05:06 1411816 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSDMINE.DLL
+ 2003-04-30 17:52 . 2003-04-30 17:52 1581120 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\XPAGE3C.DLL
+ 2002-10-07 16:03 . 2002-10-07 16:03 1794113 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\XIMAGE3B.DLL
+ 2003-08-03 16:52 . 2003-08-03 16:52 2808376 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\STSLIST.DLL
+ 2003-07-15 05:05 . 2003-07-15 05:05 1054264 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\OMFC.DLL
+ 2003-06-18 23:31 . 2003-06-18 23:31 1033216 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\MSPCORE.DLL
+ 2004-12-18 04:38 . 2004-12-18 04:38 1100392 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\EXCELPIA.DLL
+ 2006-10-27 20:11 . 2006-10-27 20:11 4235560 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\WRD12CNV.DLL
+ 2006-10-27 03:58 . 2006-10-27 03:58 3732792 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\VVIEWER.DLL
+ 2006-10-27 04:00 . 2006-10-27 04:00 1841984 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\VVIEWDWG.DLL
+ 2006-10-27 19:57 . 2006-10-27 19:57 2330968 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\STSLIST.DLL
+ 2006-10-27 00:52 . 2006-10-27 00:52 2012480 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PPTVIEW.EXE
+ 2006-10-27 20:04 . 2006-10-27 20:04 7980848 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\PPCORE.DLL
+ 2006-09-15 21:25 . 2006-09-15 21:25 3611416 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT
+ 2006-10-27 01:07 . 2006-10-27 01:07 6536992 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OSETUP.DLL
+ 2006-10-27 20:18 . 2006-10-27 20:18 1658152 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OGL.DLL
+ 2006-10-27 01:14 . 2006-10-27 01:14 7033152 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OFFOWC.DLL
+ 2006-10-27 01:42 . 2006-10-27 01:42 8423224 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OARTCONV.DLL
+ 2006-10-26 19:47 . 2006-10-26 19:47 1512304 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\NLSD0000.DLL
+ 2006-10-27 20:04 . 2006-10-27 20:04 9581360 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSPUB.EXE
+ 2006-10-27 01:00 . 2006-10-27 01:00 6635320 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSORES.DLL
+ 2006-10-27 20:10 . 2006-10-27 20:10 5281592 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\IPEDITOR.DLL
+ 2006-10-27 01:02 . 2006-10-27 01:02 2526520 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\GRAPH.EXE
+ 2006-10-27 00:21 . 2006-10-27 00:21 1682232 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\FPSRVUTL.DLL
+ 2009-05-27 00:35 . 2009-05-27 00:35 1276720 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\EXCELPIA.DLL
+ 2006-10-27 20:00 . 2006-10-27 20:00 1751904 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\ACECORE.DLL
+ 2006-10-27 00:49 . 2006-10-27 00:49 1011488 c:\windows\Installer\$PatchCache$\Managed\00002109010090400000000000F01FEC\12.0.4518\MSDAIPP.DLL
+ 2009-06-16 10:29 . 2009-06-16 10:29 1279848 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2009-06-16 10:22 . 2009-06-16 10:22 1103248 c:\windows\ASSEMBLY\GAC\Microsoft.Office.Interop.Excel\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2005-05-11 08:00 . 2009-06-01 14:51 23635392 c:\windows\SYSTEM32\MRT.exe
+ 2006-10-27 02:13 . 2006-10-27 02:13 14674216 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\XL12CNV.EXE
+ 2006-10-27 20:23 . 2006-10-27 20:23 17483560 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\WWLIB.DLL
+ 2006-10-27 20:14 . 2006-10-27 20:14 14151456 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\OART.DLL
+ 2006-10-27 20:26 . 2006-10-27 20:26 16870712 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\MSO.DLL
+ 2006-10-27 20:07 . 2006-10-27 20:07 17891112 c:\windows\Installer\$PatchCache$\Managed\00002119AC0000000000000000F01FEC\12.0.4518\EXCEL.EXE
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-02-07 497008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"SM1BG"="c:\windows\SM1BG.EXE" [2003-08-27 94208]
"cwcptray"="c:\program files\ContentWatch\Internet Protection\cwtray.exe" [2009-05-22 352576]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-31 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-02-07 497008]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\SYSTEM32\narrator.exe [2008-04-14 53760]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\CwWLEvent]
2007-04-25 03:56 884736 ----a-w- c:\program files\ContentWatch\Internet Protection\common\cwplc001.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor.lnk
backup=c:\windows\pss\Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Nortel Networks\\Extranet.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Edutils\\acted3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\SYSTEM32\\javaw.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 NEOFLTR_600_13073;Juniper Networks TDI Filter Driver (NEOFLTR_600_13073);c:\windows\SYSTEM32\DRIVERS\NEOFLTR_600_13073.sys [4/30/2008 2:54 PM 64160]
R2 CwAltaService20;ContentWatch;c:\program files\ContentWatch\Internet Protection\cwsvc.exe [6/16/2007 6:21 AM 1288512]
R2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [2/7/2009 6:09 AM 181584]
R2 tmpreflt;tmpreflt;c:\windows\SYSTEM32\DRIVERS\tmpreflt.sys [12/21/2008 7:51 AM 36368]
R2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [12/21/2008 8:00 AM 677128]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/8/2008 8:21 PM 24652]
R3 Eacfilt;Eacfilt Miniport;c:\windows\SYSTEM32\DRIVERS\eacfilt.sys [2/1/2007 10:04 PM 9433]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\SYSTEM32\DRIVERS\TM_CFW.sys [12/21/2008 7:51 AM 335376]
R3 TMPassthruMP;TMPassthruMP;c:\windows\SYSTEM32\DRIVERS\TMPassthru.sys [6/3/2009 8:52 PM 206608]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\SYSTEM32\DRIVERS\ipsecw2k.sys [2/1/2007 10:04 PM 115008]
S2 tmevtmgr;tmevtmgr;c:\windows\SYSTEM32\DRIVERS\tmevtmgr.sys [12/21/2008 8:00 AM 50192]
S2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [12/21/2008 8:00 AM 497008]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\SYSTEM32\DRIVERS\TMPassthru.sys [6/3/2009 8:52 PM 206608]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{61E3FE32-07B9-4563-A3E0-2DE2D620FE10}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder

2009-06-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/?cid=NET_mmhpset
mStart Page = hxxp://www.comcast.net/
mWindow Title = Microsoft Internet Explorer presented by Comcast
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\cwalsp.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 18:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3121708411-1105498553-3547664071-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2240)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\LEXBCES.EXE
c:\windows\SYSTEM32\LEXPPS.EXE
c:\program files\Trend Micro\BM\TMBMSRV.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\SYSTEM32\CTSVCCDA.EXE
c:\windows\SYSTEM32\Crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Trend Micro\Internet Security\SfCtlCom.exe
c:\program files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
c:\windows\SYSTEM32\CF662.exe
c:\program files\Trend Micro\TrendSecure\TSCFCommander.exe
c:\program files\Trend Micro\Internet Security\UfUpdUi.exe
.
**************************************************************************
.
Completion time: 2009-06-16 18:34 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-16 23:33
ComboFix2.txt 2009-06-16 02:18

Pre-Run: 85,781,630,976 bytes free
Post-Run: 86,068,936,704 bytes free

562 --- E O F --- 2009-06-16 02:51
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm

Re: Google redirect malware

Unread postby rsund » June 16th, 2009, 8:26 pm

Malwarebytes anti-malware log and blacklight log

Malwarebytes' Anti-Malware 1.37
Database version: 2182
Windows 5.1.2600 Service Pack 3

6/16/2009 6:43:33 PM
mbam-log-2009-06-16 (18-43-33).txt

Scan type: Quick Scan
Objects scanned: 114123
Time elapsed: 4 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 5
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MoviesPlay (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MoviesPlay (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\Richard Sund\Start Menu\Programs\MoviesPlay (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Program Files\MoviesPlay (Trojan.DNSChanger) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
c:\documents and settings\richard sund\start menu\Programs\moviesplay\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
c:\program files\moviesplay\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.


BLACKLIGHT LOG

06/16/09 19:04:40 [Info]: BlackLight Engine 2.2.1092 initialized
06/16/09 19:04:40 [Info]: OS: 5.1 build 2600 (Service Pack 3)
06/16/09 19:04:43 [Note]: 7019 4
06/16/09 19:04:43 [Note]: 7005 0
06/16/09 19:04:47 [Note]: 7006 0
06/16/09 19:04:47 [Note]: 7022 0
06/16/09 19:04:47 [Note]: 7011 1408
06/16/09 19:04:47 [Note]: 7035 0
06/16/09 19:04:49 [Note]: 7026 0
06/16/09 19:04:51 [Note]: 7026 0
06/16/09 19:04:51 [Note]: FSRAW library version 1.7.1024
06/16/09 19:15:30 [Note]: 7007 0
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm

Re: Google redirect malware

Unread postby rsund » June 16th, 2009, 8:27 pm

Hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:16:00 PM, on 6/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/?cid=NET_mmhpset
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
O4 - HKUS\S-1-5-18\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [OE] C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://secure.dmr.com/postauthI/epi.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 5126862890
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - https://www.contentwatch.com/audit/incl ... ontrol.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://fc.webex.com/client/v_mywebex-t ... eatgpc.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://sslvpn.consulting-fujitsu.com/d ... tupSP1.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/ins ... downde.cab
O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Security Activity Dashboard Service - Trend Micro Inc. - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 11849 bytes
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm

Re: Google redirect malware

Unread postby Dakeyras » June 16th, 2009, 11:49 pm

Hi :)

You are correct the error is related to Winlogon.exe

The error is still occurring.
OK this important file has either been infected by malware and or damaged, so with this in mind I think it prudent to check it out.

Upload a Suspicious File:

There is a file I would like to be checked, please carry out the following:

Note: Internet Explorer is the browser to use for best results.

  • Please go to VirSCAN.org free on-line scan service.
  • Copy and paste the following file path into the "Suspicious files to scan" box at the top of the page:

    C:\Windows\System32\Winlogon.exe

  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply. (Ctrl & V)
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8804
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Google redirect malware

Unread postby rsund » June 17th, 2009, 6:41 am

Here is the result
VirSCAN.org Scanned Report :
Scanned time : 2009/06/15 00:43:55 (CDT)
Scanner results: All Scanners reported not find malware!
File Name : winlogon.exe
File Size : 507904 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : ed0ef0a136dec83df69f04118870003e
SHA1 : f77a7cd78877527023ebfb35e83b75ef59d3df07
Online report : http://virscan.org/report/be3c94d67caed ... e478b.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090614213204 2009-06-14 2.23 -
AhnLab V3 2009.06.15.00 2009.06.15 2009-06-15 0.74 -
AntiVir 8.2.0.187 7.1.4.90 2009-06-14 0.46 -
Antiy 2.0.18 20090614.2538226 2009-06-14 0.14 -
Arcavir 2009 200906141032 2009-06-14 0.01 -
Authentium 5.1.1 200906141749 2009-06-14 1.14 -
AVAST! 4.7.4 090614-0 2009-06-14 0.03 -
AVG 8.5.286 270.12.69/2176 2009-06-15 3.32 -
BitDefender 7.81008.3348620 7.25989 2009-06-15 3.00 -
CA (VET) 9.0.0.143 31.6.6555 2009-06-13 3.27 -
ClamAV 0.95.1 9465 2009-06-14 0.09 -
Comodo 3.9 1332 2009-06-15 0.78 -
CP Secure 1.1.0.715 2009.06.15 2009-06-15 10.31 -
Dr.Web 4.44.0.9170 2009.06.15 2009-06-15 4.76 -
F-Prot 4.4.4.56 20090614 2009-06-14 1.11 -
F-Secure 5.51.6100 2009.06.15.03 2009-06-15 0.10 -
Fortinet 2.81-3.117 10.499 2009-06-14 0.31 -
GData 19.5844/19.364 20090615 2009-06-15 3.98 -
ViRobot 20090613 2009.06.13 2009-06-13 0.43 -
Ikarus T3.1.01.59 2009.06.14.72867 2009-06-14 3.32 -
JiangMin 11.0.706 2009.06.14 2009-06-14 2.28 -
Kaspersky 5.5.10 2009.06.15 2009-06-15 0.09 -
KingSoft 2009.2.5.15 2009.6.15.10 2009-06-15 0.54 -
McAfee 5.3.00 5646 2009-06-14 3.18 -
Microsoft 1.4701 2009.06.15 2009-06-15 8.20 -
mks_vir 2.01 2009.06.15 2009-06-15 3.24 -
Norman 6.01.09 6.01.00 2009-06-12 4.01 -
Panda 9.05.01 2009.06.14 2009-06-14 1.79 -
Trend Micro 8.700-1004 6.194.02 2009-06-14 0.03 -
Quick Heal 10.00 2009.06.15 2009-06-15 1.40 -
Rising 20.0 21.34.00.00 2009-06-15 0.79 -
Sophos 2.87.1 4.42 2009-06-15 2.46 -
Sunbelt 5187 5187 2009-06-13 1.03 -
Symantec 1.3.0.24 20090614.004 2009-06-14 0.06 -
nProtect 20090614.01 4248987 2009-06-14 7.50 -
The Hacker 6.3.4.3 v00345 2009-06-12 2.50 -
VBA32 3.12.10.7 20090614.1156 2009-06-14 2.30 -
VirusBuster 4.5.11.10 10.107.13/1629186 2009-06-14 2.14 -
rsund
Regular Member
 
Posts: 17
Joined: June 3rd, 2009, 10:55 pm
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 304 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware