pestilence New Member Date Joined Jun 2007 Total Posts : 29 Posted 7-28-2008 1:39 (GMT +1) Hello: I seem to be infected with What I think is adware. I keep getting popup ad's that have Cid up in the left hand corner of the ad. I would appreciate any help you can give to remove this problem. Thanks in advance for your help. here are the 2 logs requested and I ran the programs that you listed in before you post. ComboFix 08-07-27.3 - marty 2008-07-27 20:16:53.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.630 [GMT -4:00] Running from: C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\ComboFix.exe * Created a new restore point * Resident AV is activeWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\macromedia\Flash Player\#SharedObjects\ZACD8FNS\interclick.com C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\macromedia\Flash Player\#SharedObjects\ZACD8FNS\interclick.com\ud.sol C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol C:\Documents and Settings\Cheyanne\Application Data\macromedia\Flash Player\#SharedObjects\F7X7TERX\interclick.com C:\Documents and Settings\Cheyanne\Application Data\macromedia\Flash Player\#SharedObjects\F7X7TERX\interclick.com\ud.sol C:\Documents and Settings\Cheyanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com C:\Documents and Settings\Cheyanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\.# C:\WINDOWS\system32\BAZLib.dll . ((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 ))))))))))))))))))))))))))))))) . 2008-07-27 20:17 . 2008-07-27 20:17 <DIR> d-------- C:\WINDOWS\LastGood 2008-07-27 17:02 . 2008-07-27 17:02 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Logitech 2008-07-26 19:32 . 2008-07-26 19:32 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Logitech 2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\WINDOWS\Performance 2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor 2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Corporation 2008-07-26 16:36 . 2008-07-26 16:36 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Logitech 2008-07-26 16:35 . 2008-05-02 02:38 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll 2008-07-26 16:35 . 2008-05-02 02:39 170,512 --a------ C:\WINDOWS\system32\kemutb.dll 2008-07-26 16:35 . 2008-05-02 02:39 145,936 --a------ C:\WINDOWS\system32\KemUtil.dll 2008-07-26 16:35 . 2008-05-02 02:40 117,264 --a------ C:\WINDOWS\system32\KemWnd.dll 2008-07-26 16:35 . 2008-05-02 02:40 84,496 --a------ C:\WINDOWS\system32\KemXML.dll 2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\InstallShield 2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech 2008-07-25 08:16 . 2008-07-25 08:46 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP 2008-07-25 08:14 . 2008-07-25 08:13 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-07-25 08:13 . 2008-07-25 08:14 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\.housecall6.6 2008-07-23 16:35 . 2008-07-23 16:35 <DIR> d-------- C:\Program Files\Enc bind 2008-07-21 19:29 . 2008-07-21 19:29 <DIR> d-------- C:\Program Files\Disney 2008-07-21 07:45 . 2008-07-21 07:45 130,208 -r------- C:\WINDOWS\bwUnin-8.1.1.87-8876480SL.exe 2008-07-21 06:41 . 2008-07-21 06:53 <DIR> d-------- C:\NoLopBackups 2008-07-16 07:45 . 2008-07-16 07:45 <DIR> d-------- C:\Program Files\Common Files\SWF Studio 2008-07-16 07:44 . 2008-07-16 07:44 <DIR> d-------- C:\Program Files\dizzler 2008-07-06 11:49 . 2008-07-06 11:50 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\SecondLife 2008-07-05 16:18 . 2008-07-05 16:18 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\SUPERAntiSpyware.com 2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy 2008-07-05 15:13 . 2008-07-05 15:13 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com 2008-07-04 22:55 . 2008-07-04 22:55 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\MySpace 2008-07-03 17:02 . 2008-07-03 17:02 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Yahoo! 2008-07-03 16:57 . 2008-07-03 16:57 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\MySpace 2008-07-03 12:23 . 2008-07-03 12:23 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Yahoo! 2008-07-02 12:30 . 2008-07-02 12:30 268 --ah----- C:\sqmdata02.sqm 2008-07-02 12:30 . 2008-07-02 12:30 244 --ah----- C:\sqmnoopt02.sqm 2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmnoopt03.sqm 2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmdata03.sqm . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-27 21:00 --------- d-----w C:\Program Files\VideoLAN 2008-07-27 20:57 --------- d-----w C:\Program Files\LimeWire 2008-07-27 20:38 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\LimeWire 2008-07-27 05:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater 2008-07-26 20:35 --------- d-----w C:\Program Files\Common Files\Logishrd 2008-07-26 20:34 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-26 20:34 --------- d-----w C:\Program Files\Logitech 2008-07-23 20:36 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind 2008-07-23 20:36 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping 2008-07-22 23:53 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind 2008-07-20 21:01 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-07-20 21:01 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-07-20 03:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2008-07-17 01:58 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\LimeWire 2008-07-06 20:42 --------- d-----w C:\Documents and Settings\Cree\Application Data\LimeWire 2008-07-03 20:17 --------- d-----w C:\Program Files\MySpace 2008-07-03 00:37 --------- d-----w C:\Program Files\Call of Duty Game of the Year Edition 2008-07-02 18:00 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Yahoo! 2008-06-27 23:30 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\MySpace 2008-06-27 17:16 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\MySpace 2008-06-26 17:19 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MySpace 2008-06-26 00:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Viewpoint 2008-06-25 21:54 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Yahoo! 2008-06-24 12:17 --------- d--h--r C:\Documents and Settings\All Users.WINDOWS\Application Data\yahoo! 2008-06-24 12:17 --------- d-----w C:\Program Files\Yahoo! 2008-06-24 11:44 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Yahoo! 2008-06-24 11:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion 2008-06-24 11:25 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Enc bind 2008-06-22 16:45 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak 2008-06-22 07:54 --------- d-----w C:\Program Files\Common Files\EasyInfo 2008-06-22 06:39 --------- d-----w C:\Documents and Settings\Cree\Application Data\SecondLife 2008-06-22 00:20 --------- d-----w C:\Documents and Settings\Cree\Application Data\Enc bind 2008-06-21 13:52 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\acccore 2008-06-19 02:54 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL OCP 2008-06-19 02:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\acccore 2008-06-19 02:52 --------- d-----w C:\Program Files\AIM6 2008-06-19 02:51 --------- d-----w C:\Program Files\Viewpoint 2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint 2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL 2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore 2008-06-18 14:21 --------- d-----w C:\Program Files\MSN Messenger 2008-06-18 14:20 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller 2008-06-18 04:22 --------- d-----w C:\Program Files\Norton Security Scan 2008-06-18 04:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus! 2008-06-18 04:13 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MSN6 2008-06-18 04:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\MSN6 2008-06-18 03:59 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-06-12 11:50 --------- d-----w C:\Program Files\LG Drivers 2008-06-10 11:35 --------- d-----w C:\Program Files\SecondLife 2008-06-10 11:31 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SecondLife 2008-06-10 11:14 --------- d-----w C:\Documents and Settings\Marty\Application Data\LimeWire 2008-06-10 11:08 --------- d-----w C:\Program Files\iolo 2008-06-09 11:07 --------- d-----w C:\Program Files\Common Files\Adobe 2008-06-07 01:15 --------- d-----w C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Enc bind 2008-06-05 23:23 --------- d-----w C:\Program Files\EA SPORTS 2008-06-05 23:04 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft 2008-06-05 23:03 --------- d-----w C:\Program Files\Lavasoft 2008-06-05 23:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-06-05 10:29 --------- d-----w C:\Program Files\Doom 3 2008-06-05 06:34 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\IGN_DLM 2008-06-05 00:44 --------- d-----w C:\Program Files\GTA San Andreas 2008-06-04 22:44 --------- d-----w C:\Program Files\Electronic Arts 2008-06-04 22:25 --------- d-----w C:\Program Files\AGEIA Technologies 2008-06-04 22:04 --------- d-----w C:\Program Files\Ubisoft 2008-06-04 21:51 --------- d-----w C:\Program Files\SUPERAntiSpyware 2008-06-03 23:04 --------- d-----w C:\Program Files\EA GAMES 2008-06-02 00:36 --------- d-----w C:\Program Files\Rockstar Games 2008-06-02 00:23 22,328 ----a-w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\PnkBstrK.sys 2008-06-02 00:10 --------- d-----w C:\Program Files\Activision 2008-06-01 23:41 --------- d-----w C:\Program Files\Valve 2008-06-01 23:35 --------- d-----w C:\Program Files\BitPim 2008-06-01 19:47 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com 2008-06-01 19:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com 2008-06-01 19:35 --------- d-----w C:\Program Files\Download Manager 2008-06-01 18:33 --------- d-----w C:\Program Files\CDex_150 2008-06-01 18:29 --------- d-----w C:\Program Files\Ahead 2008-06-01 18:25 --------- d-----w C:\Program Files\Common Files\Ahead 2008-06-01 18:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Ahead 2008-06-01 18:14 --------- d-----w C:\Program Files\BitDownload 2008-06-01 16:59 --------- d-----w C:\Program Files\Java 2008-06-01 16:45 --------- d-----w C:\Program Files\Google 2008-06-01 15:50 --------- d-----w C:\Program Files\Speeditup Free 2008-06-01 15:07 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\LogiShrd 2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf 2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2008-05-31 19:38 --------- d-----w C:\Program Files\McAfee 2008-05-31 19:02 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll 2008-05-31 19:02 405,504 ----a-w C:\WINDOWS\system32\wrap_oal.dll 2008-05-31 18:13 --------- d-----w C:\Program Files\Common Files\McAfee 2008-05-31 16:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee 2008-05-30 18:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll 2008-05-30 18:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll 2008-05-30 18:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll 2008-05-30 18:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll 2008-05-30 18:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll 2008-05-30 18:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll 2008-05-30 18:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll 2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe 2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}] 2008-06-02 16:56 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-04 20:08 68856] "loud new"="C:\DOCUME~1\MARTY~1.MAR\APPLIC~1\ENCBIN~1\MOVEDEAFKNOB.exe" [2008-07-22 19:49 543744] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-04 17:51 1506544] "SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 12:38 557056] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-12 16:47 50528] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016] "CHIN PING PHONE PILE"="C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe" [2008-07-27 20:15 8232960] "nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe] "P17Helper"="P17.dll" [2006-03-17 16:11 81408 C:\WINDOWS\system32\P17.dll] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696] C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\ Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-07-26 16:37:32 91440] Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-07-26 16:35:12 805392] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-05-02 02:42 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Logitech SetPoint.lnk] path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech SetPoint.lnk backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon] --a------ 2007-12-13 17:43 2051096 C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LGDCore] --a------ 2007-12-13 17:57 2095640 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM] --a------ 2008-04-17 19:27 9117696 C:\Program Files\MySpace\IM\MySpaceIM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection] --a------ 2008-01-10 12:41 223984 C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\WINDOWS\\system32\\PnkBstrA.exe"= "C:\\WINDOWS\\system32\\PnkBstrB.exe"= "C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"= "C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"= "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "C:\\Program Files\\Download Manager\\DLM.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\AIM6\\aim6.exe"= "C:\\Program Files\\SecondLife\\SLVoice.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "C:\\Program Files\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"= "C:\\UT2004\\System\\UT2004.exe"= "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38] R3 p17filt;p17filt;C:\WINDOWS\system32\drivers\p17filt.sys [2006-03-20 18:34] *Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder 2008-07-28 C:\WINDOWS\Tasks\B2EAE3CC963D942C.job - c:\docume~1\marty~1.mar\applic~1\encbin~1\StupidSeekFork.exe [2008-07-22 19:52] 2008-07-28 C:\WINDOWS\Tasks\BE347C309DB3EF90.job - c:\docume~1\cheyan~1.mar\applic~1\encbin~1\StupidSeekFork.exe [2008-07-23 16:36] 2008-06-15 C:\WINDOWS\Tasks\McDefragTask.job - c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32] 2008-07-01 C:\WINDOWS\Tasks\McQcTask.job - c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32] 2008-07-27 C:\WINDOWS\Tasks\Norton Security Scan.job - C:\Program Files\Norton Security Scan\Nss.exe [2008-01-09 04:08] . - - - - ORPHANS REMOVED - - - - HKCU-Run-SpeedItUpEX - C:\Program Files\Speeditup Free\SpeedItUp.exe HKCU-Run-Performance Center - C:\Program Files\Ascentive\Performance Center\APCMain.exe MSConfigStartUp-Bits peak locks body - C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak\open fast.exe MSConfigStartUp-CHIN PING PHONE PILE - C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Chin Internet.exe MSConfigStartUp-SpybotSD TeaTimer - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.iesearch.com/ R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com R0 -: HKLM-Main,Search Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html O8 -: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKfox000 O9 -: {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-27 20:20:59 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-07-27 20:22:28 ComboFix-quarantined-files.txt 2008-07-28 00:21:47 ComboFix2.txt 2008-05-08 00:25:45 Pre-Run: 73,593,053,184 bytes free Post-Run: 74,227,306,496 bytes free 287 --- E O F --- 2008-07-28 00:16:05 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:31:53 PM, on 7/27/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\Program Files\McAfee\VirusScan\McShield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\MySpace\IM\MySpaceIM.exe C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iesearch.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper O4 - HKLM\..\Run: [CHIN PING PHONE PILE] C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [loud new] C:\DOCUME~1\MARTY~1.MAR\APPLIC~1\ENCBIN~1\MOVEDEAFKNOB.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user') O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKfox000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15034/CTPID.cab O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe -- End of file - 9372 bytes Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16254 Posted 7-28-2008 6:58 (GMT +1) Hello
If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (normally C: ), and launch from there.
Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.
Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
Double-click on SmitfraudFix.exe Select option #2 - Clean by typing 2 and press "Enter " to delete infected files. You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection. The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter". The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply. The report can also be found at the root of the system drive, normally C:\rapport.txt
+++++++++++++++++++++++++++++++++++++++++++++++++++++++
process.exe is detected by some antivirus programs as a "RiskTool". It is not a virus , but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Please download Malwarebytes' Anti-Malware:
to your desktop .
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch
Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform full scan , then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location.
Copy and Paste that log into your next reply, along with C:\rapport.txt, a fresh combofix log
NB : If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Do NOT post your problem in someone elses thread.
Back to Top
pestilence New Member Date Joined Jun 2007 Total Posts : 29 Posted 7-28-2008 8:39 (GMT +1) Ok I think I have everything here are the 3 logs you asked for. log #1 SmitFraudFix v2.331 Scan done at 2:22:21.18, Mon 07/28/2008 Run from C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» VACFix VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix S!Ri's WS2Fix: LSP not Found. »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files »»»»»»»»»»»»»»»»»»»»»»»» IEDFix IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{61F6805E-CB19-4CB6-B662-2D6DBF5EAFE8}: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CS1\Services\Tcpip\..\{61F6805E-CB19-4CB6-B662-2D6DBF5EAFE8}: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CS3\Services\Tcpip\..\{61F6805E-CB19-4CB6-B662-2D6DBF5EAFE8}: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End log #2 Malwarebytes' Anti-Malware 1.23 Database version: 1000 Windows 5.1.2600 Service Pack 3 3:25:23 AM 7/28/2008 mbam-log-7-28-2008 (03-25-23).txt Scan type: Full Scan (C:\|) Objects scanned: 135412 Time elapsed: 51 minute(s), 39 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 11 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\System Volume Information\_restore{BB16CA66-0E52-4412-8FFE-2304B998A88A}\RP131\A0018636.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. log #3 ComboFix 08-07-27.3 - marty 2008-07-28 3:26:51.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.534 [GMT -4:00] Running from: C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\ComboFix.exe * Resident AV is activeWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 ))))))))))))))))))))))))))))))) . 2008-07-28 03:01 . 2008-07-28 03:01 <DIR> d-------- C:\WINDOWS\LastGood 2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Malwarebytes 2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes 2008-07-28 02:29 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-07-28 02:29 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-28 02:22 . 2008-07-28 02:22 2,106 --a------ C:\WINDOWS\system32\tmp.reg 2008-07-27 17:02 . 2008-07-27 17:02 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Logitech 2008-07-26 19:32 . 2008-07-26 19:32 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Logitech 2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\WINDOWS\Performance 2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor 2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Corporation 2008-07-26 16:36 . 2008-07-26 16:36 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Logitech 2008-07-26 16:35 . 2008-05-02 02:38 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll 2008-07-26 16:35 . 2008-05-02 02:39 170,512 --a------ C:\WINDOWS\system32\kemutb.dll 2008-07-26 16:35 . 2008-05-02 02:39 145,936 --a------ C:\WINDOWS\system32\KemUtil.dll 2008-07-26 16:35 . 2008-05-02 02:40 117,264 --a------ C:\WINDOWS\system32\KemWnd.dll 2008-07-26 16:35 . 2008-05-02 02:40 84,496 --a------ C:\WINDOWS\system32\KemXML.dll 2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\InstallShield 2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech 2008-07-25 08:16 . 2008-07-25 08:46 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP 2008-07-25 08:14 . 2008-07-25 08:13 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-07-25 08:13 . 2008-07-25 08:14 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\.housecall6.6 2008-07-23 16:35 . 2008-07-23 16:35 <DIR> d-------- C:\Program Files\Enc bind 2008-07-21 19:29 . 2008-07-21 19:29 <DIR> d-------- C:\Program Files\Disney 2008-07-21 07:45 . 2008-07-21 07:45 130,208 -r------- C:\WINDOWS\bwUnin-8.1.1.87-8876480SL.exe 2008-07-21 06:41 . 2008-07-21 06:53 <DIR> d-------- C:\NoLopBackups 2008-07-16 07:45 . 2008-07-16 07:45 <DIR> d-------- C:\Program Files\Common Files\SWF Studio 2008-07-16 07:44 . 2008-07-16 07:44 <DIR> d-------- C:\Program Files\dizzler 2008-07-06 11:49 . 2008-07-06 11:50 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\SecondLife 2008-07-05 16:18 . 2008-07-05 16:18 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\SUPERAntiSpyware.com 2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy 2008-07-05 15:13 . 2008-07-05 15:13 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com 2008-07-04 22:55 . 2008-07-04 22:55 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\MySpace 2008-07-03 17:02 . 2008-07-03 17:02 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Yahoo! 2008-07-03 16:57 . 2008-07-03 16:57 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\MySpace 2008-07-03 12:23 . 2008-07-03 12:23 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Yahoo! 2008-07-02 12:30 . 2008-07-02 12:30 268 --ah----- C:\sqmdata02.sqm 2008-07-02 12:30 . 2008-07-02 12:30 244 --ah----- C:\sqmnoopt02.sqm 2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmnoopt03.sqm 2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmdata03.sqm . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-28 06:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater 2008-07-27 21:00 --------- d-----w C:\Program Files\VideoLAN 2008-07-27 20:57 --------- d-----w C:\Program Files\LimeWire 2008-07-27 20:38 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\LimeWire 2008-07-26 20:35 --------- d-----w C:\Program Files\Common Files\Logishrd 2008-07-26 20:34 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-26 20:34 --------- d-----w C:\Program Files\Logitech 2008-07-23 20:36 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind 2008-07-23 20:36 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping 2008-07-22 23:53 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind 2008-07-20 21:01 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-07-20 21:01 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-07-20 03:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2008-07-17 01:58 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\LimeWire 2008-07-06 20:42 --------- d-----w C:\Documents and Settings\Cree\Application Data\LimeWire 2008-07-03 20:17 --------- d-----w C:\Program Files\MySpace 2008-07-03 00:37 --------- d-----w C:\Program Files\Call of Duty Game of the Year Edition 2008-07-02 18:00 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Yahoo! 2008-06-27 23:30 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\MySpace 2008-06-27 17:16 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\MySpace 2008-06-26 17:19 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MySpace 2008-06-26 00:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Viewpoint 2008-06-25 21:54 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Yahoo! 2008-06-24 12:17 --------- d--h--r C:\Documents and Settings\All Users.WINDOWS\Application Data\yahoo! 2008-06-24 12:17 --------- d-----w C:\Program Files\Yahoo! 2008-06-24 11:44 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Yahoo! 2008-06-24 11:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion 2008-06-24 11:25 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Enc bind 2008-06-22 16:45 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak 2008-06-22 07:54 --------- d-----w C:\Program Files\Common Files\EasyInfo 2008-06-22 06:39 --------- d-----w C:\Documents and Settings\Cree\Application Data\SecondLife 2008-06-22 00:20 --------- d-----w C:\Documents and Settings\Cree\Application Data\Enc bind 2008-06-21 13:52 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\acccore 2008-06-19 02:54 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL OCP 2008-06-19 02:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\acccore 2008-06-19 02:52 --------- d-----w C:\Program Files\AIM6 2008-06-19 02:51 --------- d-----w C:\Program Files\Viewpoint 2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint 2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL 2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore 2008-06-18 14:21 --------- d-----w C:\Program Files\MSN Messenger 2008-06-18 14:20 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller 2008-06-18 04:22 --------- d-----w C:\Program Files\Norton Security Scan 2008-06-18 04:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus! 2008-06-18 04:13 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MSN6 2008-06-18 04:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\MSN6 2008-06-18 03:59 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-06-12 11:50 --------- d-----w C:\Program Files\LG Drivers 2008-06-10 11:35 --------- d-----w C:\Program Files\SecondLife 2008-06-10 11:31 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SecondLife 2008-06-10 11:14 --------- d-----w C:\Documents and Settings\Marty\Application Data\LimeWire 2008-06-10 11:08 --------- d-----w C:\Program Files\iolo 2008-06-09 11:07 --------- d-----w C:\Program Files\Common Files\Adobe 2008-06-07 01:15 --------- d-----w C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Enc bind 2008-06-05 23:23 --------- d-----w C:\Program Files\EA SPORTS 2008-06-05 23:04 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft 2008-06-05 23:03 --------- d-----w C:\Program Files\Lavasoft 2008-06-05 23:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-06-05 10:29 --------- d-----w C:\Program Files\Doom 3 2008-06-05 06:34 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\IGN_DLM 2008-06-05 00:44 --------- d-----w C:\Program Files\GTA San Andreas 2008-06-04 22:44 --------- d-----w C:\Program Files\Electronic Arts 2008-06-04 22:25 --------- d-----w C:\Program Files\AGEIA Technologies 2008-06-04 22:04 --------- d-----w C:\Program Files\Ubisoft 2008-06-04 21:51 --------- d-----w C:\Program Files\SUPERAntiSpyware 2008-06-03 23:04 --------- d-----w C:\Program Files\EA GAMES 2008-06-02 00:36 --------- d-----w C:\Program Files\Rockstar Games 2008-06-02 00:23 22,328 ----a-w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\PnkBstrK.sys 2008-06-02 00:10 --------- d-----w C:\Program Files\Activision 2008-06-01 23:41 --------- d-----w C:\Program Files\Valve 2008-06-01 23:35 --------- d-----w C:\Program Files\BitPim 2008-06-01 19:47 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com 2008-06-01 19:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com 2008-06-01 19:35 --------- d-----w C:\Program Files\Download Manager 2008-06-01 18:33 --------- d-----w C:\Program Files\CDex_150 2008-06-01 18:29 --------- d-----w C:\Program Files\Ahead 2008-06-01 18:25 --------- d-----w C:\Program Files\Common Files\Ahead 2008-06-01 18:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Ahead 2008-06-01 18:14 --------- d-----w C:\Program Files\BitDownload 2008-06-01 16:59 --------- d-----w C:\Program Files\Java 2008-06-01 16:45 --------- d-----w C:\Program Files\Google 2008-06-01 15:50 --------- d-----w C:\Program Files\Speeditup Free 2008-06-01 15:07 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\LogiShrd 2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf 2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2008-05-31 19:38 --------- d-----w C:\Program Files\McAfee 2008-05-31 19:02 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll 2008-05-31 19:02 405,504 ----a-w C:\WINDOWS\system32\wrap_oal.dll 2008-05-31 18:13 --------- d-----w C:\Program Files\Common Files\McAfee 2008-05-31 16:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee 2008-05-30 18:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll 2008-05-30 18:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll 2008-05-30 18:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll 2008-05-30 18:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll 2008-05-30 18:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll 2008-05-30 18:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll 2008-05-30 18:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll 2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe 2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll . ((((((((((((((((((((((((((((( snapshot@2008-07-27_20.21.26.43 ))))))))))))))))))))))))))))))))))))))))) . - 2008-07-27 20:33:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat + 2008-07-28 05:25:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - 2008-07-27 20:33:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat + 2008-07-28 05:25:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2008-07-27 20:33:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2008-07-28 05:25:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}] 2008-06-02 16:56 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-04 20:08 68856] "loud new"="C:\DOCUME~1\MARTY~1.MAR\APPLIC~1\ENCBIN~1\MOVEDEAFKNOB.exe" [2008-07-22 19:49 543744] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-04 17:51 1506544] "SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 12:38 557056] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-12 16:47 50528] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016] "CHIN PING PHONE PILE"="C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe" [2008-07-28 02:30 8284672] "nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe] "P17Helper"="P17.dll" [2006-03-17 16:11 81408 C:\WINDOWS\system32\P17.dll] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696] C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\ Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-07-26 16:37:32 91440] Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-07-26 16:35:12 805392] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-05-02 02:42 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Logitech SetPoint.lnk] path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech SetPoint.lnk backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon] --a------ 2007-12-13 17:43 2051096 C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LGDCore] --a------ 2007-12-13 17:57 2095640 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM] --a------ 2008-04-17 19:27 9117696 C:\Program Files\MySpace\IM\MySpaceIM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection] --a------ 2008-01-10 12:41 223984 C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\WINDOWS\\system32\\PnkBstrA.exe"= "C:\\WINDOWS\\system32\\PnkBstrB.exe"= "C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"= "C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"= "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "C:\\Program Files\\Download Manager\\DLM.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\AIM6\\aim6.exe"= "C:\\Program Files\\SecondLife\\SLVoice.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "C:\\Program Files\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"= "C:\\UT2004\\System\\UT2004.exe"= "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38] R3 p17filt;p17filt;C:\WINDOWS\system32\drivers\p17filt.sys [2006-03-20 18:34] . Contents of the 'Scheduled Tasks' folder 2008-07-28 C:\WINDOWS\Tasks\B2EAE3CC963D942C.job - c:\docume~1\marty~1.mar\applic~1\encbin~1\StupidSeekFork.exe [2008-07-22 19:52] 2008-07-28 C:\WINDOWS\Tasks\BE347C309DB3EF90.job - c:\docume~1\cheyan~1.mar\applic~1\encbin~1\StupidSeekFork.exe [2008-07-23 16:36] 2008-07-01 C:\WINDOWS\Tasks\McQcTask.job - c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32] 2008-07-27 C:\WINDOWS\Tasks\Norton Security Scan.job - C:\Program Files\Norton Security Scan\Nss.exe [2008-01-09 04:08] . . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.iesearch.com/ O8 -: &Search O9 -: {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-28 03:29:55 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-07-28 3:31:04 ComboFix-quarantined-files.txt 2008-07-28 07:30:48 ComboFix2.txt 2008-07-28 00:22:28 ComboFix3.txt 2008-05-08 00:25:45 Pre-Run: 74,139,758,592 bytes free Post-Run: 74,139,471,872 bytes free 277 --- E O F --- 2008-07-28 07:00:54 Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16254 Posted 7-28-2008 8:54 (GMT +1)
Open notepad and copy/paste the text in the quote box below into it:
Quote:
-----------------------------------------------------
KILLALL::
Snapshot::
Folder::
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind
C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Enc bind
C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak
C:\Documents and Settings\Cree\Application Data\Enc bind
C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Enc bind
C:\Program Files\Logitech\Desktop Messenger
DirLook::
C:\Program Files\BitPim
Registry::
R0 -: HKCU-Main,Start Page = hxxp://www.iesearch.com/ O8 -: &Search O9 -: {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
----------------------------------------------
Save this as CFScript.txt
At this point, You MUST EXIT ALL BROWSERS NOW before continuing!
Referring to the picture above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system.
It may reboot your system when it finishes. This is normal.
Post new hijackthis log along with fresh combofix log
Do NOT post your problem in someone elses thread.
Back to Top
pestilence New Member Date Joined Jun 2007 Total Posts : 29 Posted 7-28-2008 9:27 (GMT +1) ok here we go log #1 ComboFix 08-07-27.3 - marty 2008-07-28 4:14:01.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.757 [GMT -4:00] Running from: C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\CFScript.txt * Created a new restore pointWARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus! C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\TEST BAGS.exe C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Enc bind C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\0 C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\dxersoic.exe C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\jnxemwip.exe C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\Memo Upload Sign Start.exe C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\MOVEDEAFKNOB.exe C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\ohbhewbj.exe C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\StupidSeekFork.exe C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk C:\Documents and Settings\Cree\Application Data\Enc bind C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Enc bind C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\0 C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\flqvxuqe.exe C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\hvthgfhd.exe C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\lzbxfemk.exe C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\MOVEDEAFKNOB.exe C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\mthgtbuc.exe C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\StupidSeekFork.exe C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\macromedia\Flash Player\#SharedObjects\9TQ3Y5F8\interclick.com C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\macromedia\Flash Player\#SharedObjects\9TQ3Y5F8\interclick.com\ud.sol C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol C:\Program Files\Logitech\Desktop Messenger C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Install\bwUnin.exe C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Install\LiteInst.exe C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Install\readme.txt C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Install\win2000.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Plugins\Npavi32.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\backweb.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\backweb.tlb C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\BWCHelpr.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\bwfiles.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\bwlang.ini C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\bwsec.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\bwxtext.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\clntutil.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\Cpuinf32.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\ding.wav C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\EN\ClientRc.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\EN\registerRC.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\EN\SpriteRC.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\EN\UninstallRC.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\GAPlugProtocol.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\IAdHide.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\loading.htm C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\pacsupport.js C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\Pre6Import.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\register.exe C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\Restart.exe C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\runner.dll C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\runner.exe C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\Sprite6.exe C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\wtsisctd.exe C:\Program Files\Logitech\Desktop Messenger\8876480\clasid.bak C:\Program Files\Logitech\Desktop Messenger\8876480\enabled.txt C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\background.gif C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\browser.htm C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\cert.db C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\chandir.dat C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\chandir.idx C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\chn.dat C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\chn.idx C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\DefPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash\1\gen.bif C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash\1\gen.bis C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash\1\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\InfoCenter.GIF C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\InfoCenter.htm C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\main.wkg C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\UpgradePubKey.txt C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\UsrPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWCHelpr-8876480.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWfiles-8876480.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrchs.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrcht.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrdan.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrdeu.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmresp.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrfin.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrfra.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrita.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrjpn.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrkor.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrnld.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrnor.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrptb.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrsve.dll C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe.appid.8876480 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\SyncExt.dll C:\Program Files\Logitech\Desktop Messenger\8876480\readme.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e36\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e36\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e53\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e53\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e54\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e54\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3ef0\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3ef0\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f17\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f17\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\0 60SM.ipk C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\action.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\main.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\139MD Welcome Message.ipk C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Close.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Connect.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\logiaction.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\main.bif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\main.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Offer2.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Privacy.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\resources.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Summary.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Teaser.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\background.gif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\browser.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\cache.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\cert.db C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\chandir.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\chandir.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\chn.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\chn.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\DefPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\GenFlash\1\gen.bif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\GenFlash\1\gen.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\GenFlash\1\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\HostCache.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\InfoCenter.GIF C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\InfoCenter.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\inuse.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\L0000001.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\main.log C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_die.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_die.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_dnd.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_dnd.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_ext.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_ext.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_rcv.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_rcv.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\S0000000.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\S0000001.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\storydb.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\storydb.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\UpgradePubKey.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\UsrPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\wg1.wkg C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\139MD Welcome Message.ipk C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Close.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Connect.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\logiaction.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\main.bif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\main.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Offer2.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Privacy.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\resources.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Summary.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Teaser.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\UserProf.bak C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\UserProf.bak C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\UserProf.bak C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e36\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e36\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e53\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e53\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e54\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e54\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3ef0\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3ef0\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3f17\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3f17\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\UserProf.bak C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\background.gif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\browser.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\cache.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\cert.db C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\chandir.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\chandir.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\chn.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\chn.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\DefPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\GenFlash\1\gen.bif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\GenFlash\1\gen.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\GenFlash\1\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\HostCache.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\InfoCenter.GIF C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\InfoCenter.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\inuse.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\L0000001.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\main.log C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\player.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_die.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_die.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_dnd.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_dnd.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_ext.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_ext.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_rcv.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_rcv.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\S0000000.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\S0000001.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\storydb.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\storydb.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\test.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\UpgradePubKey.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\UsrPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\wg1.wkg C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Misc\Backup\chandir.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Misc\Backup\chandir.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\Stats.tmp C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39db\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39db\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39db\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\a9a3e36\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\a9a3e36\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\Stats.tmp C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\6d75\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\6d75\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\6d75\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\background.gif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\browser.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\cert.db C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\chandir.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\chandir.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\chn.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\chn.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\DefPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\GenFlash\1\gen.bif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\GenFlash\1\gen.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\GenFlash\1\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\HostCache.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\InfoCenter.GIF C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\InfoCenter.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\inuse.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\L0000001.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\main.log C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_die.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_die.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_dnd.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_dnd.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_ext.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_ext.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_rcv.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_rcv.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\S0000000.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\S0000001.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\storydb.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\storydb.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\UpgradePubKey.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\UsrPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\wg1.wkg C:\Program Files\Logitech\Desktop Messenger\8876480\Users\DataSets.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e36\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e36\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e53\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e53\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e54\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e54\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3ef0\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3ef0\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3f17\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3f17\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\_bwfindx.zip C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\139MD Welcome Message.ipk C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Close.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Connect.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\logiaction.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\main.bif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\main.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Offer2.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Privacy.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\resources.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Sprite.log C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Summary.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Teaser.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\BWEvents.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\chninfo.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\ChnReg.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\segrules.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\UserProf.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\background.gif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\browser.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\cache.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\cert.db C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\chandir.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\chandir.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\chn.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\chn.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\D0000000.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\DefPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\GenFlash\1\gen.bif C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\GenFlash\1\gen.bis C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\GenFlash\1\info.iad C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\HostCache.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\InfoCenter.GIF C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\InfoCenter.htm C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\inuse.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\L0000001.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\L0000002.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\main.log C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\player.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_die.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_die.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_dnd.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_dnd.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_ext.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_ext.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_rcv.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_rcv.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\S0000000.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\S0000001.FCS C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\storydb.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\storydb.idx C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\UpgradePubKey.txt C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\UsrPrefs.ini C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\wg1.wkg C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Misc\Backup\chandir.dat C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Misc\Backup\chandir.idx . ((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 ))))))))))))))))))))))))))))))) . 2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Malwarebytes 2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes 2008-07-28 02:29 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2008-07-28 02:29 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-28 02:22 . 2008-07-28 02:22 2,106 --a------ C:\WINDOWS\system32\tmp.reg 2008-07-27 17:02 . 2008-07-27 17:02 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Logitech 2008-07-26 19:32 . 2008-07-26 19:32 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Logitech 2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\WINDOWS\Performance 2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor 2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Corporation 2008-07-26 16:36 . 2008-07-26 16:36 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Logitech 2008-07-26 16:35 . 2008-05-02 02:38 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll 2008-07-26 16:35 . 2008-05-02 02:39 170,512 --a------ C:\WINDOWS\system32\kemutb.dll 2008-07-26 16:35 . 2008-05-02 02:39 145,936 --a------ C:\WINDOWS\system32\KemUtil.dll 2008-07-26 16:35 . 2008-05-02 02:40 117,264 --a------ C:\WINDOWS\system32\KemWnd.dll 2008-07-26 16:35 . 2008-05-02 02:40 84,496 --a------ C:\WINDOWS\system32\KemXML.dll 2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\InstallShield 2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech 2008-07-25 08:16 . 2008-07-25 08:46 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP 2008-07-25 08:14 . 2008-07-25 08:13 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2008-07-25 08:13 . 2008-07-25 08:14 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\.housecall6.6 2008-07-23 16:35 . 2008-07-23 16:35 <DIR> d-------- C:\Program Files\Enc bind 2008-07-21 19:29 . 2008-07-21 19:29 <DIR> d-------- C:\Program Files\Disney 2008-07-21 07:45 . 2008-07-21 07:45 130,208 -r------- C:\WINDOWS\bwUnin-8.1.1.87-8876480SL.exe 2008-07-21 06:41 . 2008-07-21 06:53 <DIR> d-------- C:\NoLopBackups 2008-07-16 07:45 . 2008-07-16 07:45 <DIR> d-------- C:\Program Files\Common Files\SWF Studio 2008-07-16 07:44 . 2008-07-16 07:44 <DIR> d-------- C:\Program Files\dizzler 2008-07-06 11:49 . 2008-07-06 11:50 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\SecondLife 2008-07-05 16:18 . 2008-07-05 16:18 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\SUPERAntiSpyware.com 2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy 2008-07-05 15:13 . 2008-07-05 15:13 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com 2008-07-04 22:55 . 2008-07-04 22:55 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\MySpace 2008-07-03 17:02 . 2008-07-03 17:02 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Yahoo! 2008-07-03 16:57 . 2008-07-03 16:57 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\MySpace 2008-07-03 12:23 . 2008-07-03 12:23 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Yahoo! 2008-07-02 12:30 . 2008-07-02 12:30 268 --ah----- C:\sqmdata02.sqm 2008-07-02 12:30 . 2008-07-02 12:30 244 --ah----- C:\sqmnoopt02.sqm 2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmnoopt03.sqm 2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmdata03.sqm . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-28 08:15 --------- d-----w C:\Program Files\Logitech 2008-07-28 06:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater 2008-07-27 21:00 --------- d-----w C:\Program Files\VideoLAN 2008-07-27 20:57 --------- d-----w C:\Program Files\LimeWire 2008-07-27 20:38 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\LimeWire 2008-07-26 20:35 --------- d-----w C:\Program Files\Common Files\Logishrd 2008-07-26 20:34 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-20 21:01 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-07-20 21:01 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe 2008-07-20 03:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe 2008-07-17 01:58 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\LimeWire 2008-07-06 20:42 --------- d-----w C:\Documents and Settings\Cree\Application Data\LimeWire 2008-07-03 20:17 --------- d-----w C:\Program Files\MySpace 2008-07-03 00:37 --------- d-----w C:\Program Files\Call of Duty Game of the Year Edition 2008-07-02 18:00 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Yahoo! 2008-06-27 23:30 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\MySpace 2008-06-27 17:16 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\MySpace 2008-06-26 17:19 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MySpace 2008-06-26 00:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Viewpoint 2008-06-25 21:54 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Yahoo! 2008-06-24 12:17 --------- d--h--r C:\Documents and Settings\All Users.WINDOWS\Application Data\yahoo! 2008-06-24 12:17 --------- d-----w C:\Program Files\Yahoo! 2008-06-24 11:44 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Yahoo! 2008-06-24 11:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion 2008-06-22 07:54 --------- d-----w C:\Program Files\Common Files\EasyInfo 2008-06-22 06:39 --------- d-----w C:\Documents and Settings\Cree\Application Data\SecondLife 2008-06-21 13:52 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\acccore 2008-06-19 02:54 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL OCP 2008-06-19 02:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\acccore 2008-06-19 02:52 --------- d-----w C:\Program Files\AIM6 2008-06-19 02:51 --------- d-----w C:\Program Files\Viewpoint 2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint 2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL 2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore 2008-06-18 14:21 --------- d-----w C:\Program Files\MSN Messenger 2008-06-18 14:20 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller 2008-06-18 04:22 --------- d-----w C:\Program Files\Norton Security Scan 2008-06-18 04:13 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MSN6 2008-06-18 04:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\MSN6 2008-06-18 03:59 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-06-12 11:50 --------- d-----w C:\Program Files\LG Drivers 2008-06-10 11:35 --------- d-----w C:\Program Files\SecondLife 2008-06-10 11:31 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SecondLife 2008-06-10 11:14 --------- d-----w C:\Documents and Settings\Marty\Application Data\LimeWire 2008-06-10 11:08 --------- d-----w C:\Program Files\iolo 2008-06-09 11:07 --------- d-----w C:\Program Files\Common Files\Adobe 2008-06-05 23:23 --------- d-----w C:\Program Files\EA SPORTS 2008-06-05 23:04 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft 2008-06-05 23:03 --------- d-----w C:\Program Files\Lavasoft 2008-06-05 23:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-06-05 10:29 --------- d-----w C:\Program Files\Doom 3 2008-06-05 06:34 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\IGN_DLM 2008-06-05 00:44 --------- d-----w C:\Program Files\GTA San Andreas 2008-06-04 22:44 --------- d-----w C:\Program Files\Electronic Arts 2008-06-04 22:25 --------- d-----w C:\Program Files\AGEIA Technologies 2008-06-04 22:04 --------- d-----w C:\Program Files\Ubisoft 2008-06-04 21:51 --------- d-----w C:\Program Files\SUPERAntiSpyware 2008-06-03 23:04 --------- d-----w C:\Program Files\EA GAMES 2008-06-02 00:36 --------- d-----w C:\Program Files\Rockstar Games 2008-06-02 00:23 22,328 ----a-w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\PnkBstrK.sys 2008-06-02 00:10 --------- d-----w C:\Program Files\Activision 2008-06-01 23:41 --------- d-----w C:\Program Files\Valve 2008-06-01 23:35 --------- d-----w C:\Program Files\BitPim 2008-06-01 19:47 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com 2008-06-01 19:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com 2008-06-01 19:35 --------- d-----w C:\Program Files\Download Manager 2008-06-01 18:33 --------- d-----w C:\Program Files\CDex_150 2008-06-01 18:29 --------- d-----w C:\Program Files\Ahead 2008-06-01 18:25 --------- d-----w C:\Program Files\Common Files\Ahead 2008-06-01 18:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Ahead 2008-06-01 18:14 --------- d-----w C:\Program Files\BitDownload 2008-06-01 16:59 --------- d-----w C:\Program Files\Java 2008-06-01 16:45 --------- d-----w C:\Program Files\Google 2008-06-01 15:50 --------- d-----w C:\Program Files\Speeditup Free 2008-06-01 15:07 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\LogiShrd 2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf 2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2008-05-31 19:38 --------- d-----w C:\Program Files\McAfee 2008-05-31 19:02 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll 2008-05-31 19:02 405,504 ----a-w C:\WINDOWS\system32\wrap_oal.dll 2008-05-31 18:13 --------- d-----w C:\Program Files\Common Files\McAfee 2008-05-31 16:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee 2008-05-30 18:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll 2008-05-30 18:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll 2008-05-30 18:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll 2008-05-30 18:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll 2008-05-30 18:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll 2008-05-30 18:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll 2008-05-30 18:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll 2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe 2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll 2008-04-30 21:27 442,368 ----a-w C:\WINDOWS\system32\NVUNINST.EXE 2008-04-29 17:57 208,896 ----a-w C:\WINDOWS\system32\ConTest.dll . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ---- Directory of C:\Program Files\BitPim ---- 2008-06-01 19:35 10571 --a------ C:\Program Files\BitPim\unins000.dat 2008-06-01 19:34 691491 --a------ C:\Program Files\BitPim\unins000.exe 2008-01-28 18:08 23552 --a------ C:\Program Files\BitPim\bitpimw.exe 2008-01-28 18:08 19664151 --a------ C:\Program Files\BitPim\library.zip 2008-01-28 18:08 19456 --a------ C:\Program Files\BitPim\bitpim.exe 2008-01-28 18:07 7680 --a------ C:\Program Files\BitPim\jarow.pyd 2008-01-28 17:57 992 --a------ C:\Program Files\BitPim\resources\select_memo.png 2008-01-28 17:57 990 --a------ C:\Program Files\BitPim\resources\select_console.png 2008-01-28 17:57 979 --a------ C:\Program Files\BitPim\resources\cal_regular_style.xy 2008-01-28 17:57 960 --a------ C:\Program Files\BitPim\resources\select_root.png 2008-01-28 17:57 956 --a------ C:\Program Files\BitPim\resources\bitfling.png 2008-01-28 17:57 952 --a------ C:\Program Files\BitPim\resources\select_today.png 2008-01-28 17:57 949 --a------ C:\Program Files\BitPim\resources\add_field.png 2008-01-28 17:57 912 --a------ C:\Program Files\BitPim\resources\select_calls.png 2008-01-28 17:57 900 --a------ C:\Program Files\BitPim\resources\select_image.png 2008-01-28 17:57 891 --a------ C:\Program Files\BitPim\resources\sms.xy 2008-01-28 17:57 888 --a------ C:\Program Files\BitPim\resources\select_message.png 2008-01-28 17:57 860 --a------ C:\Program Files\BitPim\resources\select_phonebook.png 2008-01-28 17:57 831 --a------ C:\Program Files\BitPim\resources\ringer.png 2008-01-28 17:57 810 --a------ C:\Program Files\BitPim\resources\select_todo.png 2008-01-28 17:57 806 --a------ C:\Program Files\BitPim\resources\ranged-slider-start.png 2008-01-28 17:57 776 --a------ C:\Program Files\BitPim\resources\select_ringers.png 2008-01-28 17:57 757 --a------ C:\Program Files\BitPim\resources\ranged-slider-end.png 2008-01-28 17:57 744 --a------ C:\Program Files\BitPim\resources\usb_needdriver.ids 2008-01-28 17:57 723 --a------ C:\Program Files\BitPim\resources\cal_monthly_style.xy 2008-01-28 17:57 713 --a------ C:\Program Files\BitPim\resources\arrow_down.png 2008-01-28 17:57 712 --a------ C:\Program Files\BitPim\resources\memo.xy 2008-01-28 17:57 672 --a------ C:\Program Files\BitPim\resources\arrow_up.png 2008-01-28 17:57 648 --a------ C:\Program Files\BitPim\resources\arrow_left.png 2008-01-28 17:57 630 --a------ C:\Program Files\BitPim\resources\arrow_right.png 2008-01-28 17:57 584 --a------ C:\Program Files\BitPim\resources\bitpim_usb.ids 2008-01-28 17:57 563 --a------ C:\Program Files\BitPim\resources\pbpl-view.xy 2008-01-28 17:57 557 --a------ C:\Program Files\BitPim\resources\phone_root.png 2008-01-28 17:57 523 --a------ C:\Program Files\BitPim\resources\select_log.png 2008-01-28 17:57 523 --a------ C:\Program Files\BitPim\resources\folder_open.png 2008-01-28 17:57 507 --a------ C:\Program Files\BitPim\resources\select_file.png 2008-01-28 17:57 498 --a------ C:\Program Files\BitPim\resources\folder.png 2008-01-28 17:57 48958 --a------ C:\Program Files\BitPim\resources\splashscreen.jpg 2008-01-28 17:57 456 --a------ C:\Program Files\BitPim\resources\mozilla.pdc 2008-01-28 17:57 4507 --a------ C:\Program Files\BitPim\resources\wallpaper.png 2008-01-28 17:57 4291 --a------ C:\Program Files\BitPim\resources\bitpim.css 2008-01-28 17:57 3833 --a------ C:\Program Files\BitPim\resources\pblayout.xy 2008-01-28 17:57 3621 --a------ C:\Program Files\BitPim\resources\styles.xy 2008-01-28 17:57 3017406 --a------ C:\Program Files\BitPim\resources\bitpim.chm 2008-01-28 17:57 290 --a------ C:\Program Files\BitPim\resources\data_history.png 2008-01-28 17:57 270 --a------ C:\Program Files\BitPim\resources\ranged-slider-current.png 2008-01-28 17:57 241 --a------ C:\Program Files\BitPim\resources\palm.pdc 2008-01-28 17:57 23 --a------ C:\Program Files\BitPim\resources\pbps-colourful.xy 2008-01-28 17:57 2238 --a------ C:\Program Files\BitPim\resources\bitpim.ico 2008-01-28 17:57 2216 --a------ C:\Program Files\BitPim\resources\editsettings.png 2008-01-28 17:57 2202 --a------ C:\Program Files\BitPim\resources\zerolen.wav 2008-01-28 17:57 2097 --a------ C:\Program Files\BitPim\resources\editdetect.png 2008-01-28 17:57 2091 --a------ C:\Program Files\BitPim\resources\autosyncexecute.png 2008-01-28 17:57 207 --a------ C:\Program Files\BitPim\resources\media_list_view.png 2008-01-28 17:57 194 --a------ C:\Program Files\BitPim\resources\media_thumb_view.png 2008-01-28 17:57 1773 --a------ C:\Program Files\BitPim\resources\unknown.png 2008-01-28 17:57 153934 --a------ C:\Program Files\BitPim\resources\usb.ids 2008-01-28 17:57 1384 --a------ C:\Program Files\BitPim\resources\datagetphone.png 2008-01-28 17:57 1378 --a------ C:\Program Files\BitPim\resources\delete_sms.png 2008-01-28 17:57 1359 --a------ C:\Program Files\BitPim\resources\add_sms.png 2008-01-28 17:57 1343 --a------ C:\Program Files\BitPim\resources\select_video.png 2008-01-28 17:57 1335 --a------ C:\Program Files\BitPim\resources\delete_memo.png 2008-01-28 17:57 1328 --a------ C:\Program Files\BitPim\resources\datasendphone.png 2008-01-28 17:57 1314 --a------ C:\Program Files\BitPim\resources\add_memo.png 2008-01-28 17:57 1276 --a------ C:\Program Files\BitPim\resources\select_media.png 2008-01-28 17:57 1256 --a------ C:\Program Files\BitPim\resources\select_wallpaper.png 2008-01-28 17:57 1256 --a------ C:\Program Files\BitPim\resources\select_camera.png 2008-01-28 17:57 1233 --a------ C:\Program Files\BitPim\resources\select_sms.png 2008-01-28 17:57 122542 --a------ C:\Program Files\BitPim\resources\wallpaper-watermark.png 2008-01-28 17:57 1225 --a------ C:\Program Files\BitPim\resources\delete_ringer.png 2008-01-28 17:57 1205 --a------ C:\Program Files\BitPim\resources\delete_picture.png 2008-01-28 17:57 1203 --a------ C:\Program Files\BitPim\resources\add_ringer.png 2008-01-28 17:57 12026 --a------ C:\Program Files\BitPim\resources\ringtone-watermark.png 2008-01-28 17:57 1193 --a------ C:\Program Files\BitPim\resources\add_picture.png 2008-01-28 17:57 1160 --a------ C:\Program Files\BitPim\resources\editphoneinfo.png 2008-01-28 17:57 1158 --a------ C:\Program Files\BitPim\resources\delete_contact.png 2008-01-28 17:57 1148 --a------ C:\Program Files\BitPim\resources\delete_todo.png 2008-01-28 17:57 1133 --a------ C:\Program Files\BitPim\resources\add_todo.png 2008-01-28 17:57 1130 --a------ C:\Program Files\BitPim\resources\add_contact.png 2008-01-28 17:57 1119 --a------ C:\Program Files\BitPim\resources\cal_regular.xy 2008-01-28 17:57 1108 --a------ C:\Program Files\BitPim\resources\delete_field.png 2008-01-28 17:57 1098 --a------ C:\Program Files\BitPim\resources\helphelp.png 2008-01-28 17:57 1092 --a------ C:\Program Files\BitPim\resources\select_playlist.png 2008-01-28 17:57 1090 --a------ C:\Program Files\BitPim\resources\select_protocol.png 2008-01-28 17:57 1081 --a------ C:\Program Files\BitPim\resources\cal_monthly.xy 2008-01-28 17:57 1054 --a------ C:\Program Files\BitPim\resources\select_calendar.png 2008-01-28 17:57 1044 --a------ C:\Program Files\BitPim\resources\private.png 2008-01-28 17:57 104 --a------ C:\Program Files\BitPim\resources\pbps-ledger.xy 2008-01-28 17:57 1013 --a------ C:\Program Files\BitPim\resources\select_sounds.png 2008-01-28 17:57 1011 --a------ C:\Program Files\BitPim\resources\select_call_history.png 2008-01-28 17:50 70656 --a------ C:\Program Files\BitPim\helpers\zlib1.dll 2008-01-28 17:50 525680 --a------ C:\Program Files\BitPim\helpers\bmp2avi.exe 2008-01-28 17:50 48 --a------ C:\Program Files\BitPim\bitpim.url 2008-01-28 17:50 33792 --a------ C:\Program Files\BitPim\helpers\pnmtopng.exe 2008-01-28 17:50 25088 --a------ C:\Program Files\BitPim\helpers\pngtopnm.exe 2008-01-28 17:50 21504 --a------ C:\Program Files\BitPim\helpers\ppmquant.exe 2008-01-28 17:50 206627 --a------ C:\Program Files\BitPim\helpers\libpng12.dll 2008-01-28 17:50 1690112 --a------ C:\Program Files\BitPim\helpers\ffmpeg.exe 2008-01-28 17:50 156672 --a------ C:\Program Files\BitPim\helpers\libnetpbm10.dll 2008-01-15 09:26 591872 --a------ C:\Program Files\BitPim\apsw.pyd 2007-11-29 17:37 339968 --a------ C:\Program Files\BitPim\_gizmos.pyd 2007-11-29 17:36 454656 --a------ C:\Program Files\BitPim\_stc.pyd 2007-11-29 17:33 94208 --a------ C:\Program Files\BitPim\_calendar.pyd 2007-11-29 17:33 663552 --a------ C:\Program Files\BitPim\_misc_.pyd 2007-11-29 17:33 389120 --a------ C:\Program Files\BitPim\_grid.pyd 2007-11-29 17:33 339968 --a------ C:\Program Files\BitPim\_html.pyd 2007-11-29 17:33 114688 --a------ C:\Program Files\BitPim\_wizard.pyd 2007-11-29 17:31 909312 --a------ C:\Program Files\BitPim\_controls_.pyd 2007-11-29 17:30 720896 --a------ C:\Program Files\BitPim\_gdi_.pyd 2007-11-29 17:30 647168 --a------ C:\Program Files\BitPim\_windows_.pyd 2007-11-29 17:29 962560 --a------ C:\Program Files\BitPim\_core_.pyd 2007-11-29 17:16 532480 --a------ C:\Program Files\BitPim\wxmsw28uh_stc_vc.dll 2007-11-29 17:16 151552 --a------ C:\Program Files\BitPim\wxmsw28uh_gizmos_vc.dll 2007-11-29 17:14 708608 --a------ C:\Program Files\BitPim\wxmsw28uh_adv_vc.dll 2007-11-29 17:14 483328 --a------ C:\Program Files\BitPim\wxmsw28uh_html_vc.dll 2007-11-29 17:14 3166208 --a------ C:\Program Files\BitPim\wxmsw28uh_core_vc.dll 2007-11-29 17:12 135168 --a------ C:\Program Files\BitPim\wxbase28uh_net_vc.dll 2007-11-29 17:12 1327104 --a------ C:\Program Files\BitPim\wxbase28uh_vc.dll 2007-08-10 22:47 27136 --a------ C:\Program Files\BitPim\AES.pyd 2007-08-10 22:47 19456 --a------ C:\Program Files\BitPim\DES3.pyd 2007-08-10 22:47 18944 --a------ C:\Program Files\BitPim\Blowfish.pyd 2007-04-18 07:52 753664 --a------ C:\Program Files\BitPim\_bsddb.pyd 2007-04-18 07:52 655360 --a------ C:\Program Files\BitPim\_ssl.pyd 2007-04-18 07:52 53248 --a------ C:\Program Files\BitPim\_socket.pyd 2007-04-18 07:52 323584 --a------ C:\Program Files\BitPim\_hashlib.pyd 2007-04-18 07:51 81920 --a------ C:\Program Files\BitPim\_ctypes.pyd 2007-04-18 07:51 77824 --a------ C:\Program Files\BitPim\bz2.pyd 2007-04-18 07:51 7680 --a------ C:\Program Files\BitPim\select.pyd 2007-04-18 07:51 475136 --a------ C:\Program Files\BitPim\unicodedata.pyd 2007-04-18 07:51 2113536 --a------ C:\Program Files\BitPim\python25.dll 2007-04-18 07:51 135168 --a------ C:\Program Files\BitPim\pyexpat.pyd 2006-09-22 20:34 651264 --a------ C:\Program Files\BitPim\win32ui.pyd 2006-09-22 20:32 151552 --a------ C:\Program Files\BitPim\shell.pyd 2006-09-22 20:30 327680 --a------ C:\Program Files\BitPim\pythoncom25.dll 2006-09-22 20:28 5632 --a------ C:\Program Files\BitPim\_win32sysloader.pyd 2006-09-22 20:28 34816 --a------ C:\Program Files\BitPim\win32help.pyd 2006-09-22 20:28 12288 --a------ C:\Program Files\BitPim\win32trace.pyd 2006-09-22 20:28 114688 --a------ C:\Program Files\BitPim\win32gui.pyd 2006-09-22 20:19 16896 --a------ C:\Program Files\BitPim\win32pipe.pyd 2006-09-22 20:18 90112 --a------ C:\Program Files\BitPim\win32file.pyd 2006-09-22 20:18 86016 --a------ C:\Program Files\BitPim\win32api.pyd 2006-09-22 20:18 14848 --a------ C:\Program Files\BitPim\win32event.pyd 2006-09-22 20:18 102400 --a------ C:\Program Files\BitPim\pywintypes25.dll 2006-07-11 17:35 348160 --a------ C:\Program Files\BitPim\MSVCR71.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}] 2008-06-02 16:56 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-04 20:08 68856] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-04 17:51 1506544] "SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 12:38 557056] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-12 16:47 50528] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016] "nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe] "P17Helper"="P17.dll" [2006-03-17 16:11 81408 C:\WINDOWS\system32\P17.dll] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696] C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\ Logitech Desktop Messenger.lnk - C:\QooBox\Quarantine\C\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe.vir [2008-07-26 16:37:32 91440] Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-07-26 16:35:12 805392] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2008-05-02 02:42 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Logitech SetPoint.lnk] path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech SetPoint.lnk backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon] --a------ 2007-12-13 17:43 2051096 C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LGDCore] --a------ 2007-12-13 17:57 2095640 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM] --a------ 2008-04-17 19:27 9117696 C:\Program Files\MySpace\IM\MySpaceIM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection] --a------ 2008-01-10 12:41 223984 C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\WINDOWS\\system32\\PnkBstrA.exe"= "C:\\WINDOWS\\system32\\PnkBstrB.exe"= "C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"= "C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"= "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "C:\\Program Files\\Download Manager\\DLM.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\AIM6\\aim6.exe"= "C:\\Program Files\\SecondLife\\SLVoice.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "C:\\Program Files\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"= "C:\\UT2004\\System\\UT2004.exe"= "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38] R3 p17filt;p17filt;C:\WINDOWS\system32\drivers\p17filt.sys [2006-03-20 18:34] . Contents of the 'Scheduled Tasks' folder 2008-07-28 C:\WINDOWS\Tasks\B2EAE3CC963D942C.job - c:\docume~1\marty~1.mar\applic~1\encbin~1\StupidSeekFork.exe [] 2008-07-28 C:\WINDOWS\Tasks\BE347C309DB3EF90.job - c:\docume~1\cheyan~1.mar\applic~1\encbin~1\StupidSeekFork.exe [] 2008-06-15 C:\WINDOWS\Tasks\McDefragTask.job - c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32] 2008-07-01 C:\WINDOWS\Tasks\McQcTask.job - c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32] 2008-07-27 C:\WINDOWS\Tasks\Norton Security Scan.job - C:\Program Files\Norton Security Scan\Nss.exe [2008-01-09 04:08] . - - - - ORPHANS REMOVED - - - - HKCU-Run-loud new - C:\DOCUME~1\MARTY~1.MAR\APPLIC~1\ENCBIN~1\MOVEDEAFKNOB.exe HKLM-Run-CHIN PING PHONE PILE - C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-28 04:19:04 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe C:\Program Files\McAfee\MPF\MpfSrv.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe C:\Program Files\AIM6\aolsoftware.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\WINDOWS\system32\verclsid.exe . ************************************************************************** . Completion time: 2008-07-28 4:22:55 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-28 08:22:49 ComboFix2.txt 2008-07-28 07:31:05 ComboFix3.txt 2008-07-28 00:22:28 ComboFix4.txt 2008-05-08 00:25:45 Pre-Run: 74,096,865,280 bytes free Post-Run: 74,060,619,776 bytes free 836 --- E O F --- 2008-07-28 07:00:54 log #2 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 04:24:40, on 7/28/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\Program Files\McAfee\VirusScan\McShield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\MySpace\IM\MySpaceIM.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\MySpace\IM\MySpaceIM.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iesearch.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user') O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\QooBox\Quarantine\C\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe.vir O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15034/CTPID.cab O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe -- End of file - 8477 bytes Back to Top
pestilence New Member Date Joined Jun 2007 Total Posts : 29 Posted 7-28-2008 11:11 (GMT +1) I have not seen one in a while thank you very much Back to Top
Touch Forum Moderator Date Joined Jun 2004 Total Posts : 16254 Posted 7-28-2008 2:40 (GMT +1) My pleasure
Please read Tony Klein's excellent article about how to prevent against spyware/hijackers in the future
http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html
Do NOT post your problem in someone elses thread.
Back to Top
pestilence New Member Date Joined Jun 2007 Total Posts : 29 Posted 7-28-2008 9:41 (GMT +1) Would you by any chance know how to get my clock off military time i don"t think it reset after combofix changed it. Back to Top
pestilence New Member Date Joined Jun 2007 Total Posts : 29 Posted 7-29-2008 8:45 (GMT +1)
Forum Information Currently it is Saturday, November 07, 2009 8:30 PM (GMT +1) There are a total of 72.700 posts in 17.060 threads. In the last 3 days there were 10 new threads and 50 reply posts. View Active Threads Who's Online This forum has 30250 registered members. Please welcome our newest member, iyshwarya iyer . 35 Guest(s), 0 Registered Member(s) are currently online. Details 5 Latest Threads