Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Cid Ad popup Help
   
BullGuard Antivirus Forum > General Security > Spyware > Cid Ad popup Help  
Forum Quick Jump
 
New Topic Post reply to : Cid Ad popup Help Printable version of : Cid Ad popup Help
[ << Previous Thread | Next Thread >> ]

pestilence
New Member


Date Joined Jun 2007
Total Posts : 29
 
   Posted 7-28-2008 1:39 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
Hello:

I seem to be infected with What I think is adware. I keep getting popup ad's that have Cid up in the left hand corner of the ad. I would appreciate any help you can give to remove this problem. Thanks in advance for your help. here are the 2 logs requested and I ran the programs that you listed in before you post.


ComboFix 08-07-27.3 - marty 2008-07-27 20:16:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.630 [GMT -4:00]
Running from: C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\macromedia\Flash Player\#SharedObjects\ZACD8FNS\interclick.com
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\macromedia\Flash Player\#SharedObjects\ZACD8FNS\interclick.com\ud.sol
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Cheyanne\Application Data\macromedia\Flash Player\#SharedObjects\F7X7TERX\interclick.com
C:\Documents and Settings\Cheyanne\Application Data\macromedia\Flash Player\#SharedObjects\F7X7TERX\interclick.com\ud.sol
C:\Documents and Settings\Cheyanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Cheyanne\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\.#
C:\WINDOWS\system32\BAZLib.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 )))))))))))))))))))))))))))))))
.

2008-07-27 20:17 . 2008-07-27 20:17 <DIR> d-------- C:\WINDOWS\LastGood
2008-07-27 17:02 . 2008-07-27 17:02 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Logitech
2008-07-26 19:32 . 2008-07-26 19:32 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Logitech
2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\WINDOWS\Performance
2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Corporation
2008-07-26 16:36 . 2008-07-26 16:36 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Logitech
2008-07-26 16:35 . 2008-05-02 02:38 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll
2008-07-26 16:35 . 2008-05-02 02:39 170,512 --a------ C:\WINDOWS\system32\kemutb.dll
2008-07-26 16:35 . 2008-05-02 02:39 145,936 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-07-26 16:35 . 2008-05-02 02:40 117,264 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-07-26 16:35 . 2008-05-02 02:40 84,496 --a------ C:\WINDOWS\system32\KemXML.dll
2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\InstallShield
2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech
2008-07-25 08:16 . 2008-07-25 08:46 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-07-25 08:14 . 2008-07-25 08:13 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-25 08:13 . 2008-07-25 08:14 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\.housecall6.6
2008-07-23 16:35 . 2008-07-23 16:35 <DIR> d-------- C:\Program Files\Enc bind
2008-07-21 19:29 . 2008-07-21 19:29 <DIR> d-------- C:\Program Files\Disney
2008-07-21 07:45 . 2008-07-21 07:45 130,208 -r------- C:\WINDOWS\bwUnin-8.1.1.87-8876480SL.exe
2008-07-21 06:41 . 2008-07-21 06:53 <DIR> d-------- C:\NoLopBackups
2008-07-16 07:45 . 2008-07-16 07:45 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-07-16 07:44 . 2008-07-16 07:44 <DIR> d-------- C:\Program Files\dizzler
2008-07-06 11:49 . 2008-07-06 11:50 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\SecondLife
2008-07-05 16:18 . 2008-07-05 16:18 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\SUPERAntiSpyware.com
2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-07-05 15:13 . 2008-07-05 15:13 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com
2008-07-04 22:55 . 2008-07-04 22:55 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\MySpace
2008-07-03 17:02 . 2008-07-03 17:02 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Yahoo!
2008-07-03 16:57 . 2008-07-03 16:57 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\MySpace
2008-07-03 12:23 . 2008-07-03 12:23 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Yahoo!
2008-07-02 12:30 . 2008-07-02 12:30 268 --ah----- C:\sqmdata02.sqm
2008-07-02 12:30 . 2008-07-02 12:30 244 --ah----- C:\sqmnoopt02.sqm
2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmnoopt03.sqm
2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmdata03.sqm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-27 21:00 --------- d-----w C:\Program Files\VideoLAN
2008-07-27 20:57 --------- d-----w C:\Program Files\LimeWire
2008-07-27 20:38 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\LimeWire
2008-07-27 05:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-07-26 20:35 --------- d-----w C:\Program Files\Common Files\Logishrd
2008-07-26 20:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-26 20:34 --------- d-----w C:\Program Files\Logitech
2008-07-23 20:36 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind
2008-07-23 20:36 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping
2008-07-22 23:53 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind
2008-07-20 21:01 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-20 21:01 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-07-20 03:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-07-17 01:58 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\LimeWire
2008-07-06 20:42 --------- d-----w C:\Documents and Settings\Cree\Application Data\LimeWire
2008-07-03 20:17 --------- d-----w C:\Program Files\MySpace
2008-07-03 00:37 --------- d-----w C:\Program Files\Call of Duty Game of the Year Edition
2008-07-02 18:00 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Yahoo!
2008-06-27 23:30 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\MySpace
2008-06-27 17:16 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\MySpace
2008-06-26 17:19 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MySpace
2008-06-26 00:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Viewpoint
2008-06-25 21:54 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Yahoo!
2008-06-24 12:17 --------- d--h--r C:\Documents and Settings\All Users.WINDOWS\Application Data\yahoo!
2008-06-24 12:17 --------- d-----w C:\Program Files\Yahoo!
2008-06-24 11:44 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Yahoo!
2008-06-24 11:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-06-24 11:25 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Enc bind
2008-06-22 16:45 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak
2008-06-22 07:54 --------- d-----w C:\Program Files\Common Files\EasyInfo
2008-06-22 06:39 --------- d-----w C:\Documents and Settings\Cree\Application Data\SecondLife
2008-06-22 00:20 --------- d-----w C:\Documents and Settings\Cree\Application Data\Enc bind
2008-06-21 13:52 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\acccore
2008-06-19 02:54 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL OCP
2008-06-19 02:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\acccore
2008-06-19 02:52 --------- d-----w C:\Program Files\AIM6
2008-06-19 02:51 --------- d-----w C:\Program Files\Viewpoint
2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL
2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
2008-06-18 14:21 --------- d-----w C:\Program Files\MSN Messenger
2008-06-18 14:20 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller
2008-06-18 04:22 --------- d-----w C:\Program Files\Norton Security Scan
2008-06-18 04:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
2008-06-18 04:13 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MSN6
2008-06-18 04:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\MSN6
2008-06-18 03:59 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-12 11:50 --------- d-----w C:\Program Files\LG Drivers
2008-06-10 11:35 --------- d-----w C:\Program Files\SecondLife
2008-06-10 11:31 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SecondLife
2008-06-10 11:14 --------- d-----w C:\Documents and Settings\Marty\Application Data\LimeWire
2008-06-10 11:08 --------- d-----w C:\Program Files\iolo
2008-06-09 11:07 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-07 01:15 --------- d-----w C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Enc bind
2008-06-05 23:23 --------- d-----w C:\Program Files\EA SPORTS
2008-06-05 23:04 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-06-05 23:03 --------- d-----w C:\Program Files\Lavasoft
2008-06-05 23:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-05 10:29 --------- d-----w C:\Program Files\Doom 3
2008-06-05 06:34 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\IGN_DLM
2008-06-05 00:44 --------- d-----w C:\Program Files\GTA San Andreas
2008-06-04 22:44 --------- d-----w C:\Program Files\Electronic Arts
2008-06-04 22:25 --------- d-----w C:\Program Files\AGEIA Technologies
2008-06-04 22:04 --------- d-----w C:\Program Files\Ubisoft
2008-06-04 21:51 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-06-03 23:04 --------- d-----w C:\Program Files\EA GAMES
2008-06-02 00:36 --------- d-----w C:\Program Files\Rockstar Games
2008-06-02 00:23 22,328 ----a-w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\PnkBstrK.sys
2008-06-02 00:10 --------- d-----w C:\Program Files\Activision
2008-06-01 23:41 --------- d-----w C:\Program Files\Valve
2008-06-01 23:35 --------- d-----w C:\Program Files\BitPim
2008-06-01 19:47 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com
2008-06-01 19:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-06-01 19:35 --------- d-----w C:\Program Files\Download Manager
2008-06-01 18:33 --------- d-----w C:\Program Files\CDex_150
2008-06-01 18:29 --------- d-----w C:\Program Files\Ahead
2008-06-01 18:25 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-01 18:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Ahead
2008-06-01 18:14 --------- d-----w C:\Program Files\BitDownload
2008-06-01 16:59 --------- d-----w C:\Program Files\Java
2008-06-01 16:45 --------- d-----w C:\Program Files\Google
2008-06-01 15:50 --------- d-----w C:\Program Files\Speeditup Free
2008-06-01 15:07 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\LogiShrd
2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-05-31 19:38 --------- d-----w C:\Program Files\McAfee
2008-05-31 19:02 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-05-31 19:02 405,504 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-05-31 18:13 --------- d-----w C:\Program Files\Common Files\McAfee
2008-05-31 16:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
2008-05-30 18:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll
2008-05-30 18:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll
2008-05-30 18:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll
2008-05-30 18:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll
2008-05-30 18:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll
2008-05-30 18:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll
2008-05-30 18:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-06-02 16:56 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-04 20:08 68856]
"loud new"="C:\DOCUME~1\MARTY~1.MAR\APPLIC~1\ENCBIN~1\MOVEDEAFKNOB.exe" [2008-07-22 19:49 543744]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-04 17:51 1506544]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 12:38 557056]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-12 16:47 50528]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"CHIN PING PHONE PILE"="C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe" [2008-07-27 20:15 8232960]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"P17Helper"="P17.dll" [2006-03-17 16:11 81408 C:\WINDOWS\system32\P17.dll]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-07-26 16:37:32 91440]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-07-26 16:35:12 805392]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon]
--a------ 2007-12-13 17:43 2051096 C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LGDCore]
--a------ 2007-12-13 17:57 2095640 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2008-04-17 19:27 9117696 C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
--a------ 2008-01-10 12:41 223984 C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Download Manager\\DLM.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"=
"C:\\UT2004\\System\\UT2004.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
R3 p17filt;p17filt;C:\WINDOWS\system32\drivers\p17filt.sys [2006-03-20 18:34]

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-07-28 C:\WINDOWS\Tasks\B2EAE3CC963D942C.job
- c:\docume~1\marty~1.mar\applic~1\encbin~1\StupidSeekFork.exe [2008-07-22 19:52]

2008-07-28 C:\WINDOWS\Tasks\BE347C309DB3EF90.job
- c:\docume~1\cheyan~1.mar\applic~1\encbin~1\StupidSeekFork.exe [2008-07-23 16:36]

2008-06-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2008-07-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2008-07-27 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2008-01-09 04:08]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-SpeedItUpEX - C:\Program Files\Speeditup Free\SpeedItUp.exe
HKCU-Run-Performance Center - C:\Program Files\Ascentive\Performance Center\APCMain.exe
MSConfigStartUp-Bits peak locks body - C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak\open fast.exe
MSConfigStartUp-CHIN PING PHONE PILE - C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Chin Internet.exe
MSConfigStartUp-SpybotSD TeaTimer - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.iesearch.com/
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
R0 -: HKLM-Main,Search Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
O8 -: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKfox000
O9 -: {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk
O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-27 20:20:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-27 20:22:28
ComboFix-quarantined-files.txt 2008-07-28 00:21:47
ComboFix2.txt 2008-05-08 00:25:45

Pre-Run: 73,593,053,184 bytes free
Post-Run: 74,227,306,496 bytes free

287 --- E O F --- 2008-07-28 00:16:05


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:31:53 PM, on 7/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iesearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [CHIN PING PHONE PILE] C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [loud new] C:\DOCUME~1\MARTY~1.MAR\APPLIC~1\ENCBIN~1\MOVEDEAFKNOB.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKfox000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15034/CTPID.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 9372 bytes
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 7-28-2008 6:58 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
Hello smile
 
 
If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (normally C:), and launch from there.

 
Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.


Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
Double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, normally  C:\rapport.txt

+++++++++++++++++++++++++++++++++++++++++++++++++++++++
process.exe is detected by some antivirus programs as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
 
 
 
Please download Malwarebytes' Anti-Malware:
 
 to your desktop.
 
Double-click mbam-setup.exe and follow the prompts to install the program.
                     
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch

Malwarebytes' Anti-Malware, then click Finish.
                     
If an update is found, it will download and install the latest version.
                     
Once the program has loaded, select Perform full scan, then click Scan.
                     
When the scan is complete, click OK, then Show Results to view the results.
 
Be sure that everything is checked, and click Remove Selected.
 
When completed, a log will open in Notepad. Please save it to a convenient location.
 
 
Copy and Paste that log into your next reply, along with  C:\rapport.txt, a fresh combofix log
 
 
NB: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

pestilence
New Member


Date Joined Jun 2007
Total Posts : 29
 
   Posted 7-28-2008 8:39 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
Ok I think I have everything here are the 3 logs you asked for.


log #1
SmitFraudFix v2.331

Scan done at 2:22:21.18, Mon 07/28/2008
Run from C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{61F6805E-CB19-4CB6-B662-2D6DBF5EAFE8}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{61F6805E-CB19-4CB6-B662-2D6DBF5EAFE8}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{61F6805E-CB19-4CB6-B662-2D6DBF5EAFE8}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

log #2
Malwarebytes' Anti-Malware 1.23
Database version: 1000
Windows 5.1.2600 Service Pack 3

3:25:23 AM 7/28/2008
mbam-log-7-28-2008 (03-25-23).txt

Scan type: Full Scan (C:\|)
Objects scanned: 135412
Time elapsed: 51 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{BB16CA66-0E52-4412-8FFE-2304B998A88A}\RP131\A0018636.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.

log #3
ComboFix 08-07-27.3 - marty 2008-07-28 3:26:51.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.534 [GMT -4:00]
Running from: C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\ComboFix.exe
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 )))))))))))))))))))))))))))))))
.

2008-07-28 03:01 . 2008-07-28 03:01 <DIR> d-------- C:\WINDOWS\LastGood
2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Malwarebytes
2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-07-28 02:29 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-28 02:29 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-28 02:22 . 2008-07-28 02:22 2,106 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-27 17:02 . 2008-07-27 17:02 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Logitech
2008-07-26 19:32 . 2008-07-26 19:32 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Logitech
2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\WINDOWS\Performance
2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Corporation
2008-07-26 16:36 . 2008-07-26 16:36 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Logitech
2008-07-26 16:35 . 2008-05-02 02:38 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll
2008-07-26 16:35 . 2008-05-02 02:39 170,512 --a------ C:\WINDOWS\system32\kemutb.dll
2008-07-26 16:35 . 2008-05-02 02:39 145,936 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-07-26 16:35 . 2008-05-02 02:40 117,264 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-07-26 16:35 . 2008-05-02 02:40 84,496 --a------ C:\WINDOWS\system32\KemXML.dll
2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\InstallShield
2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech
2008-07-25 08:16 . 2008-07-25 08:46 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-07-25 08:14 . 2008-07-25 08:13 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-25 08:13 . 2008-07-25 08:14 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\.housecall6.6
2008-07-23 16:35 . 2008-07-23 16:35 <DIR> d-------- C:\Program Files\Enc bind
2008-07-21 19:29 . 2008-07-21 19:29 <DIR> d-------- C:\Program Files\Disney
2008-07-21 07:45 . 2008-07-21 07:45 130,208 -r------- C:\WINDOWS\bwUnin-8.1.1.87-8876480SL.exe
2008-07-21 06:41 . 2008-07-21 06:53 <DIR> d-------- C:\NoLopBackups
2008-07-16 07:45 . 2008-07-16 07:45 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-07-16 07:44 . 2008-07-16 07:44 <DIR> d-------- C:\Program Files\dizzler
2008-07-06 11:49 . 2008-07-06 11:50 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\SecondLife
2008-07-05 16:18 . 2008-07-05 16:18 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\SUPERAntiSpyware.com
2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-07-05 15:13 . 2008-07-05 15:13 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com
2008-07-04 22:55 . 2008-07-04 22:55 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\MySpace
2008-07-03 17:02 . 2008-07-03 17:02 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Yahoo!
2008-07-03 16:57 . 2008-07-03 16:57 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\MySpace
2008-07-03 12:23 . 2008-07-03 12:23 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Yahoo!
2008-07-02 12:30 . 2008-07-02 12:30 268 --ah----- C:\sqmdata02.sqm
2008-07-02 12:30 . 2008-07-02 12:30 244 --ah----- C:\sqmnoopt02.sqm
2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmnoopt03.sqm
2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmdata03.sqm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-28 06:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-07-27 21:00 --------- d-----w C:\Program Files\VideoLAN
2008-07-27 20:57 --------- d-----w C:\Program Files\LimeWire
2008-07-27 20:38 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\LimeWire
2008-07-26 20:35 --------- d-----w C:\Program Files\Common Files\Logishrd
2008-07-26 20:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-26 20:34 --------- d-----w C:\Program Files\Logitech
2008-07-23 20:36 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind
2008-07-23 20:36 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping
2008-07-22 23:53 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind
2008-07-20 21:01 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-20 21:01 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-07-20 03:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-07-17 01:58 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\LimeWire
2008-07-06 20:42 --------- d-----w C:\Documents and Settings\Cree\Application Data\LimeWire
2008-07-03 20:17 --------- d-----w C:\Program Files\MySpace
2008-07-03 00:37 --------- d-----w C:\Program Files\Call of Duty Game of the Year Edition
2008-07-02 18:00 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Yahoo!
2008-06-27 23:30 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\MySpace
2008-06-27 17:16 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\MySpace
2008-06-26 17:19 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MySpace
2008-06-26 00:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Viewpoint
2008-06-25 21:54 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Yahoo!
2008-06-24 12:17 --------- d--h--r C:\Documents and Settings\All Users.WINDOWS\Application Data\yahoo!
2008-06-24 12:17 --------- d-----w C:\Program Files\Yahoo!
2008-06-24 11:44 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Yahoo!
2008-06-24 11:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-06-24 11:25 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Enc bind
2008-06-22 16:45 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak
2008-06-22 07:54 --------- d-----w C:\Program Files\Common Files\EasyInfo
2008-06-22 06:39 --------- d-----w C:\Documents and Settings\Cree\Application Data\SecondLife
2008-06-22 00:20 --------- d-----w C:\Documents and Settings\Cree\Application Data\Enc bind
2008-06-21 13:52 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\acccore
2008-06-19 02:54 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL OCP
2008-06-19 02:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\acccore
2008-06-19 02:52 --------- d-----w C:\Program Files\AIM6
2008-06-19 02:51 --------- d-----w C:\Program Files\Viewpoint
2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL
2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
2008-06-18 14:21 --------- d-----w C:\Program Files\MSN Messenger
2008-06-18 14:20 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller
2008-06-18 04:22 --------- d-----w C:\Program Files\Norton Security Scan
2008-06-18 04:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
2008-06-18 04:13 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MSN6
2008-06-18 04:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\MSN6
2008-06-18 03:59 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-12 11:50 --------- d-----w C:\Program Files\LG Drivers
2008-06-10 11:35 --------- d-----w C:\Program Files\SecondLife
2008-06-10 11:31 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SecondLife
2008-06-10 11:14 --------- d-----w C:\Documents and Settings\Marty\Application Data\LimeWire
2008-06-10 11:08 --------- d-----w C:\Program Files\iolo
2008-06-09 11:07 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-07 01:15 --------- d-----w C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Enc bind
2008-06-05 23:23 --------- d-----w C:\Program Files\EA SPORTS
2008-06-05 23:04 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-06-05 23:03 --------- d-----w C:\Program Files\Lavasoft
2008-06-05 23:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-05 10:29 --------- d-----w C:\Program Files\Doom 3
2008-06-05 06:34 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\IGN_DLM
2008-06-05 00:44 --------- d-----w C:\Program Files\GTA San Andreas
2008-06-04 22:44 --------- d-----w C:\Program Files\Electronic Arts
2008-06-04 22:25 --------- d-----w C:\Program Files\AGEIA Technologies
2008-06-04 22:04 --------- d-----w C:\Program Files\Ubisoft
2008-06-04 21:51 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-06-03 23:04 --------- d-----w C:\Program Files\EA GAMES
2008-06-02 00:36 --------- d-----w C:\Program Files\Rockstar Games
2008-06-02 00:23 22,328 ----a-w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\PnkBstrK.sys
2008-06-02 00:10 --------- d-----w C:\Program Files\Activision
2008-06-01 23:41 --------- d-----w C:\Program Files\Valve
2008-06-01 23:35 --------- d-----w C:\Program Files\BitPim
2008-06-01 19:47 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com
2008-06-01 19:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-06-01 19:35 --------- d-----w C:\Program Files\Download Manager
2008-06-01 18:33 --------- d-----w C:\Program Files\CDex_150
2008-06-01 18:29 --------- d-----w C:\Program Files\Ahead
2008-06-01 18:25 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-01 18:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Ahead
2008-06-01 18:14 --------- d-----w C:\Program Files\BitDownload
2008-06-01 16:59 --------- d-----w C:\Program Files\Java
2008-06-01 16:45 --------- d-----w C:\Program Files\Google
2008-06-01 15:50 --------- d-----w C:\Program Files\Speeditup Free
2008-06-01 15:07 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\LogiShrd
2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-05-31 19:38 --------- d-----w C:\Program Files\McAfee
2008-05-31 19:02 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-05-31 19:02 405,504 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-05-31 18:13 --------- d-----w C:\Program Files\Common Files\McAfee
2008-05-31 16:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
2008-05-30 18:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll
2008-05-30 18:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll
2008-05-30 18:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll
2008-05-30 18:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll
2008-05-30 18:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll
2008-05-30 18:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll
2008-05-30 18:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
.

((((((((((((((((((((((((((((( snapshot@2008-07-27_20.21.26.43 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-27 20:33:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-07-28 05:25:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-07-27 20:33:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-28 05:25:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-07-27 20:33:39 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-28 05:25:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-06-02 16:56 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-04 20:08 68856]
"loud new"="C:\DOCUME~1\MARTY~1.MAR\APPLIC~1\ENCBIN~1\MOVEDEAFKNOB.exe" [2008-07-22 19:49 543744]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-04 17:51 1506544]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 12:38 557056]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-12 16:47 50528]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"CHIN PING PHONE PILE"="C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe" [2008-07-28 02:30 8284672]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"P17Helper"="P17.dll" [2006-03-17 16:11 81408 C:\WINDOWS\system32\P17.dll]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-07-26 16:37:32 91440]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-07-26 16:35:12 805392]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon]
--a------ 2007-12-13 17:43 2051096 C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LGDCore]
--a------ 2007-12-13 17:57 2095640 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2008-04-17 19:27 9117696 C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
--a------ 2008-01-10 12:41 223984 C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Download Manager\\DLM.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"=
"C:\\UT2004\\System\\UT2004.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
R3 p17filt;p17filt;C:\WINDOWS\system32\drivers\p17filt.sys [2006-03-20 18:34]
.
Contents of the 'Scheduled Tasks' folder

2008-07-28 C:\WINDOWS\Tasks\B2EAE3CC963D942C.job
- c:\docume~1\marty~1.mar\applic~1\encbin~1\StupidSeekFork.exe [2008-07-22 19:52]

2008-07-28 C:\WINDOWS\Tasks\BE347C309DB3EF90.job
- c:\docume~1\cheyan~1.mar\applic~1\encbin~1\StupidSeekFork.exe [2008-07-23 16:36]

2008-07-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2008-07-27 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2008-01-09 04:08]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.iesearch.com/
O8 -: &Search
O9 -: {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk
O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-28 03:29:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-28 3:31:04
ComboFix-quarantined-files.txt 2008-07-28 07:30:48
ComboFix2.txt 2008-07-28 00:22:28
ComboFix3.txt 2008-05-08 00:25:45

Pre-Run: 74,139,758,592 bytes free
Post-Run: 74,139,471,872 bytes free

277 --- E O F --- 2008-07-28 07:00:54
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 7-28-2008 8:54 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
Open notepad and copy/paste the text in the quote box below into it:
Quote:
-----------------------------------------------------
KILLALL::
 
Snapshot::
 
 
Folder::
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind
C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind
C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Enc bind
C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak
C:\Documents and Settings\Cree\Application Data\Enc bind
C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Enc bind
C:\Program Files\Logitech\Desktop Messenger
 
 
 
 
 
DirLook::
C:\Program Files\BitPim


 
Registry::
R0 -: HKCU-Main,Start Page = hxxp://www.iesearch.com/
O8 -: &Search
O9 -: {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk
O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
 
 
 
----------------------------------------------
 
Save this as CFScript.txt
 
 
At this point, You MUST EXIT ALL BROWSERS NOW before continuing!
Referring to the picture above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system.
It may reboot your system when it finishes. This is normal.
 
 
Post new hijackthis log along with fresh combofix log
 


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

pestilence
New Member


Date Joined Jun 2007
Total Posts : 29
 
   Posted 7-28-2008 9:27 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
ok here we go

log #1
ComboFix 08-07-27.3 - marty 2008-07-28 4:14:01.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.757 [GMT -4:00]
Running from: C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
C:\Documents and Settings\All Users.WINDOWS\Application Data\Noun Love Bits Peak
C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping
C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\TEST BAGS.exe
C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Enc bind
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\0
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\dxersoic.exe
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\jnxemwip.exe
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\Memo Upload Sign Start.exe
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\MOVEDEAFKNOB.exe
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\ohbhewbj.exe
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Enc bind\StupidSeekFork.exe
C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Start Menu\Programs\IMVU\Run IMVU.lnk
C:\Documents and Settings\Cree\Application Data\Enc bind
C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Enc bind
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\0
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\flqvxuqe.exe
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\hvthgfhd.exe
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\lzbxfemk.exe
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\MOVEDEAFKNOB.exe
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\mthgtbuc.exe
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Enc bind\StupidSeekFork.exe
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\macromedia\Flash Player\#SharedObjects\9TQ3Y5F8\interclick.com
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\macromedia\Flash Player\#SharedObjects\9TQ3Y5F8\interclick.com\ud.sol
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Program Files\Logitech\Desktop Messenger
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Install\bwUnin.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Install\LiteInst.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Install\readme.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Install\win2000.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Plugins\Npavi32.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\backweb.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\backweb.tlb
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\BWCHelpr.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\bwfiles.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\bwlang.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\bwsec.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\bwxtext.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\clntutil.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\Cpuinf32.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\ding.wav
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\EN\ClientRc.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\EN\registerRC.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\EN\SpriteRC.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\EN\UninstallRC.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\GAPlugProtocol.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\IAdHide.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\loading.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\pacsupport.js
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\Pre6Import.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\register.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\Restart.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\runner.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\runner.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\Sprite6.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.87-8876480SL\Program\wtsisctd.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\clasid.bak
C:\Program Files\Logitech\Desktop Messenger\8876480\enabled.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\background.gif
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\browser.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\cert.db
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\chandir.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\chandir.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\chn.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\chn.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\DefPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash\1\gen.bif
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash\1\gen.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash\1\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\InfoCenter.GIF
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\InfoCenter.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\main.wkg
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\UpgradePubKey.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\UsrPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWCHelpr-8876480.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWfiles-8876480.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrchs.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrcht.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrdan.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrdeu.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmresp.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrfin.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrfra.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrita.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrjpn.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrkor.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrnld.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrnor.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrptb.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\ldmrsve.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe.appid.8876480
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\SyncExt.dll
C:\Program Files\Logitech\Desktop Messenger\8876480\readme.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\1ed5\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e36\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e36\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e53\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e53\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e54\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3e54\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3ef0\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3ef0\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f17\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f17\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\060SM.ipk
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\action.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\a9a3f18\main.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\405e\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\139MD Welcome Message.ipk
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Close.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Connect.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\logiaction.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\main.bif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\main.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Offer2.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Privacy.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\resources.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Summary.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\11e4f6f3\Teaser.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f5\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\70f8\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\background.gif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\browser.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\cache.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\cert.db
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\chandir.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\chandir.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\chn.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\chn.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\DefPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\GenFlash\1\gen.bif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\GenFlash\1\gen.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\GenFlash\1\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\HostCache.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\InfoCenter.GIF
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\InfoCenter.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\inuse.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\L0000001.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\main.log
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_die.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_die.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_dnd.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_dnd.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_ext.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_ext.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_rcv.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\prs_rcv.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\S0000000.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\S0000001.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\storydb.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\storydb.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\UpgradePubKey.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\UsrPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Beckie\Data\wg1.wkg
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\139MD Welcome Message.ipk
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Close.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Connect.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\logiaction.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\main.bif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\main.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Offer2.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Privacy.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\resources.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Summary.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\11e4f6f3\Teaser.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\UserProf.bak
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da4\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\UserProf.bak
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1da8\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\UserProf.bak
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dab\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e36\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e36\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e53\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e53\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e54\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3e54\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3ef0\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3ef0\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3f17\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\a9a3f17\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\UserProf.bak
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\1dae\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\background.gif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\browser.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\cache.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\cert.db
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\chandir.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\chandir.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\chn.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\chn.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\DefPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\GenFlash\1\gen.bif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\GenFlash\1\gen.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\GenFlash\1\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\HostCache.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\InfoCenter.GIF
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\InfoCenter.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\inuse.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\L0000001.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\main.log
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\player.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_die.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_die.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_dnd.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_dnd.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_ext.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_ext.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_rcv.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\prs_rcv.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\S0000000.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\S0000001.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\storydb.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\storydb.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\test.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\UpgradePubKey.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\UsrPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Data\wg1.wkg
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Misc\Backup\chandir.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cheyanne\Misc\Backup\chandir.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\Stats.tmp
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39d8\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39db\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39db\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39db\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\a9a3e36\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\a9a3e36\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\Stats.tmp
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\39de\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\6d75\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\6d75\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\6d75\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\background.gif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\browser.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\cert.db
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\chandir.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\chandir.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\chn.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\chn.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\DefPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\GenFlash\1\gen.bif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\GenFlash\1\gen.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\GenFlash\1\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\HostCache.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\InfoCenter.GIF
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\InfoCenter.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\inuse.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\L0000001.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\main.log
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_die.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_die.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_dnd.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_dnd.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_ext.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_ext.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_rcv.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\prs_rcv.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\S0000000.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\S0000001.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\storydb.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\storydb.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\UpgradePubKey.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\UsrPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Cree\Data\wg1.wkg
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\DataSets.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e36\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e36\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e53\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e53\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e54\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3e54\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3ef0\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3ef0\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3f17\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\a9a3f17\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\15c0\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\6bc3\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\_bwfindx.zip
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\139MD Welcome Message.ipk
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Close.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Connect.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\logiaction.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\main.bif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\main.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Offer2.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Privacy.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\resources.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Sprite.log
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Summary.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\11e4f6f3\Teaser.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77ed\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\BWEvents.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\chninfo.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\ChnReg.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\segrules.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\77f0\UserProf.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\background.gif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\browser.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\cache.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\cert.db
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\chandir.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\chandir.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\chn.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\chn.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\D0000000.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\DefPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\GenFlash\1\gen.bif
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\GenFlash\1\gen.bis
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\GenFlash\1\info.iad
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\HostCache.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\InfoCenter.GIF
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\InfoCenter.htm
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\inuse.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\L0000001.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\L0000002.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\main.log
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\player.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_die.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_die.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_dnd.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_dnd.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_ext.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_ext.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_rcv.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\prs_rcv.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\S0000000.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\S0000001.FCS
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\storydb.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\storydb.idx
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\UpgradePubKey.txt
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\UsrPrefs.ini
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Data\wg1.wkg
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Misc\Backup\chandir.dat
C:\Program Files\Logitech\Desktop Messenger\8876480\Users\marty\Misc\Backup\chandir.idx

.
((((((((((((((((((((((((( Files Created from 2008-06-28 to 2008-07-28 )))))))))))))))))))))))))))))))
.

2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Malwarebytes
2008-07-28 02:29 . 2008-07-28 02:29 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-07-28 02:29 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-28 02:29 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-28 02:22 . 2008-07-28 02:22 2,106 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-27 17:02 . 2008-07-27 17:02 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Logitech
2008-07-26 19:32 . 2008-07-26 19:32 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Logitech
2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\WINDOWS\Performance
2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-07-26 16:42 . 2008-07-26 16:42 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Corporation
2008-07-26 16:36 . 2008-07-26 16:36 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Logitech
2008-07-26 16:35 . 2008-05-02 02:38 301,656 --a------ C:\WINDOWS\system32\BtCoreIf.dll
2008-07-26 16:35 . 2008-05-02 02:39 170,512 --a------ C:\WINDOWS\system32\kemutb.dll
2008-07-26 16:35 . 2008-05-02 02:39 145,936 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-07-26 16:35 . 2008-05-02 02:40 117,264 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-07-26 16:35 . 2008-05-02 02:40 84,496 --a------ C:\WINDOWS\system32\KemXML.dll
2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\InstallShield
2008-07-26 16:34 . 2008-07-26 16:34 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Logitech
2008-07-25 08:16 . 2008-07-25 08:46 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-07-25 08:14 . 2008-07-25 08:13 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-25 08:13 . 2008-07-25 08:14 <DIR> d-------- C:\Documents and Settings\marty.MARTY-A113CE187\.housecall6.6
2008-07-23 16:35 . 2008-07-23 16:35 <DIR> d-------- C:\Program Files\Enc bind
2008-07-21 19:29 . 2008-07-21 19:29 <DIR> d-------- C:\Program Files\Disney
2008-07-21 07:45 . 2008-07-21 07:45 130,208 -r------- C:\WINDOWS\bwUnin-8.1.1.87-8876480SL.exe
2008-07-21 06:41 . 2008-07-21 06:53 <DIR> d-------- C:\NoLopBackups
2008-07-16 07:45 . 2008-07-16 07:45 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-07-16 07:44 . 2008-07-16 07:44 <DIR> d-------- C:\Program Files\dizzler
2008-07-06 11:49 . 2008-07-06 11:50 <DIR> d-------- C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\SecondLife
2008-07-05 16:18 . 2008-07-05 16:18 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\SUPERAntiSpyware.com
2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-05 16:00 . 2008-07-05 16:51 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-07-05 15:13 . 2008-07-05 15:13 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com
2008-07-04 22:55 . 2008-07-04 22:55 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\MySpace
2008-07-03 17:02 . 2008-07-03 17:02 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\Yahoo!
2008-07-03 16:57 . 2008-07-03 16:57 <DIR> d-------- C:\Documents and Settings\Marley.MARTY-A113CE187\Application Data\MySpace
2008-07-03 12:23 . 2008-07-03 12:23 <DIR> d-------- C:\Documents and Settings\Cree\Application Data\Yahoo!
2008-07-02 12:30 . 2008-07-02 12:30 268 --ah----- C:\sqmdata02.sqm
2008-07-02 12:30 . 2008-07-02 12:30 244 --ah----- C:\sqmnoopt02.sqm
2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmnoopt03.sqm
2008-07-02 12:30 . 2008-07-02 12:30 172 --ah----- C:\sqmdata03.sqm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-28 08:15 --------- d-----w C:\Program Files\Logitech
2008-07-28 06:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-07-27 21:00 --------- d-----w C:\Program Files\VideoLAN
2008-07-27 20:57 --------- d-----w C:\Program Files\LimeWire
2008-07-27 20:38 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\LimeWire
2008-07-26 20:35 --------- d-----w C:\Program Files\Common Files\Logishrd
2008-07-26 20:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-20 21:01 136,888 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-20 21:01 111,928 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-07-20 03:03 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-07-17 01:58 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\LimeWire
2008-07-06 20:42 --------- d-----w C:\Documents and Settings\Cree\Application Data\LimeWire
2008-07-03 20:17 --------- d-----w C:\Program Files\MySpace
2008-07-03 00:37 --------- d-----w C:\Program Files\Call of Duty Game of the Year Edition
2008-07-02 18:00 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\Yahoo!
2008-06-27 23:30 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\MySpace
2008-06-27 17:16 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\MySpace
2008-06-26 17:19 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MySpace
2008-06-26 00:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Viewpoint
2008-06-25 21:54 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\Yahoo!
2008-06-24 12:17 --------- d--h--r C:\Documents and Settings\All Users.WINDOWS\Application Data\yahoo!
2008-06-24 12:17 --------- d-----w C:\Program Files\Yahoo!
2008-06-24 11:44 --------- d-----w C:\Documents and Settings\Beckie.MARTY-A113CE187\Application Data\Yahoo!
2008-06-24 11:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-06-22 07:54 --------- d-----w C:\Program Files\Common Files\EasyInfo
2008-06-22 06:39 --------- d-----w C:\Documents and Settings\Cree\Application Data\SecondLife
2008-06-21 13:52 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\acccore
2008-06-19 02:54 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL OCP
2008-06-19 02:53 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\acccore
2008-06-19 02:52 --------- d-----w C:\Program Files\AIM6
2008-06-19 02:51 --------- d-----w C:\Program Files\Viewpoint
2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Viewpoint
2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL
2008-06-19 02:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\acccore
2008-06-18 14:21 --------- d-----w C:\Program Files\MSN Messenger
2008-06-18 14:20 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller
2008-06-18 04:22 --------- d-----w C:\Program Files\Norton Security Scan
2008-06-18 04:13 --------- d-----w C:\Documents and Settings\Cheyanne.MARTY-A113CE187\Application Data\MSN6
2008-06-18 04:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\MSN6
2008-06-18 03:59 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-12 11:50 --------- d-----w C:\Program Files\LG Drivers
2008-06-10 11:35 --------- d-----w C:\Program Files\SecondLife
2008-06-10 11:31 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SecondLife
2008-06-10 11:14 --------- d-----w C:\Documents and Settings\Marty\Application Data\LimeWire
2008-06-10 11:08 --------- d-----w C:\Program Files\iolo
2008-06-09 11:07 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-05 23:23 --------- d-----w C:\Program Files\EA SPORTS
2008-06-05 23:04 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-06-05 23:03 --------- d-----w C:\Program Files\Lavasoft
2008-06-05 23:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-05 10:29 --------- d-----w C:\Program Files\Doom 3
2008-06-05 06:34 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\IGN_DLM
2008-06-05 00:44 --------- d-----w C:\Program Files\GTA San Andreas
2008-06-04 22:44 --------- d-----w C:\Program Files\Electronic Arts
2008-06-04 22:25 --------- d-----w C:\Program Files\AGEIA Technologies
2008-06-04 22:04 --------- d-----w C:\Program Files\Ubisoft
2008-06-04 21:51 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-06-03 23:04 --------- d-----w C:\Program Files\EA GAMES
2008-06-02 00:36 --------- d-----w C:\Program Files\Rockstar Games
2008-06-02 00:23 22,328 ----a-w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\PnkBstrK.sys
2008-06-02 00:10 --------- d-----w C:\Program Files\Activision
2008-06-01 23:41 --------- d-----w C:\Program Files\Valve
2008-06-01 23:35 --------- d-----w C:\Program Files\BitPim
2008-06-01 19:47 --------- d-----w C:\Documents and Settings\marty.MARTY-A113CE187\Application Data\SUPERAntiSpyware.com
2008-06-01 19:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-06-01 19:35 --------- d-----w C:\Program Files\Download Manager
2008-06-01 18:33 --------- d-----w C:\Program Files\CDex_150
2008-06-01 18:29 --------- d-----w C:\Program Files\Ahead
2008-06-01 18:25 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-01 18:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Ahead
2008-06-01 18:14 --------- d-----w C:\Program Files\BitDownload
2008-06-01 16:59 --------- d-----w C:\Program Files\Java
2008-06-01 16:45 --------- d-----w C:\Program Files\Google
2008-06-01 15:50 --------- d-----w C:\Program Files\Speeditup Free
2008-06-01 15:07 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\LogiShrd
2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-06-01 15:02 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-05-31 19:38 --------- d-----w C:\Program Files\McAfee
2008-05-31 19:02 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-05-31 19:02 405,504 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-05-31 18:13 --------- d-----w C:\Program Files\Common Files\McAfee
2008-05-31 16:47 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
2008-05-30 18:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll
2008-05-30 18:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll
2008-05-30 18:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll
2008-05-30 18:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll
2008-05-30 18:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll
2008-05-30 18:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll
2008-05-30 18:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 21:27 442,368 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-04-29 17:57 208,896 ----a-w C:\WINDOWS\system32\ConTest.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\Program Files\BitPim ----

2008-06-01 19:35 10571 --a------ C:\Program Files\BitPim\unins000.dat
2008-06-01 19:34 691491 --a------ C:\Program Files\BitPim\unins000.exe
2008-01-28 18:08 23552 --a------ C:\Program Files\BitPim\bitpimw.exe
2008-01-28 18:08 19664151 --a------ C:\Program Files\BitPim\library.zip
2008-01-28 18:08 19456 --a------ C:\Program Files\BitPim\bitpim.exe
2008-01-28 18:07 7680 --a------ C:\Program Files\BitPim\jarow.pyd
2008-01-28 17:57 992 --a------ C:\Program Files\BitPim\resources\select_memo.png
2008-01-28 17:57 990 --a------ C:\Program Files\BitPim\resources\select_console.png
2008-01-28 17:57 979 --a------ C:\Program Files\BitPim\resources\cal_regular_style.xy
2008-01-28 17:57 960 --a------ C:\Program Files\BitPim\resources\select_root.png
2008-01-28 17:57 956 --a------ C:\Program Files\BitPim\resources\bitfling.png
2008-01-28 17:57 952 --a------ C:\Program Files\BitPim\resources\select_today.png
2008-01-28 17:57 949 --a------ C:\Program Files\BitPim\resources\add_field.png
2008-01-28 17:57 912 --a------ C:\Program Files\BitPim\resources\select_calls.png
2008-01-28 17:57 900 --a------ C:\Program Files\BitPim\resources\select_image.png
2008-01-28 17:57 891 --a------ C:\Program Files\BitPim\resources\sms.xy
2008-01-28 17:57 888 --a------ C:\Program Files\BitPim\resources\select_message.png
2008-01-28 17:57 860 --a------ C:\Program Files\BitPim\resources\select_phonebook.png
2008-01-28 17:57 831 --a------ C:\Program Files\BitPim\resources\ringer.png
2008-01-28 17:57 810 --a------ C:\Program Files\BitPim\resources\select_todo.png
2008-01-28 17:57 806 --a------ C:\Program Files\BitPim\resources\ranged-slider-start.png
2008-01-28 17:57 776 --a------ C:\Program Files\BitPim\resources\select_ringers.png
2008-01-28 17:57 757 --a------ C:\Program Files\BitPim\resources\ranged-slider-end.png
2008-01-28 17:57 744 --a------ C:\Program Files\BitPim\resources\usb_needdriver.ids
2008-01-28 17:57 723 --a------ C:\Program Files\BitPim\resources\cal_monthly_style.xy
2008-01-28 17:57 713 --a------ C:\Program Files\BitPim\resources\arrow_down.png
2008-01-28 17:57 712 --a------ C:\Program Files\BitPim\resources\memo.xy
2008-01-28 17:57 672 --a------ C:\Program Files\BitPim\resources\arrow_up.png
2008-01-28 17:57 648 --a------ C:\Program Files\BitPim\resources\arrow_left.png
2008-01-28 17:57 630 --a------ C:\Program Files\BitPim\resources\arrow_right.png
2008-01-28 17:57 584 --a------ C:\Program Files\BitPim\resources\bitpim_usb.ids
2008-01-28 17:57 563 --a------ C:\Program Files\BitPim\resources\pbpl-view.xy
2008-01-28 17:57 557 --a------ C:\Program Files\BitPim\resources\phone_root.png
2008-01-28 17:57 523 --a------ C:\Program Files\BitPim\resources\select_log.png
2008-01-28 17:57 523 --a------ C:\Program Files\BitPim\resources\folder_open.png
2008-01-28 17:57 507 --a------ C:\Program Files\BitPim\resources\select_file.png
2008-01-28 17:57 498 --a------ C:\Program Files\BitPim\resources\folder.png
2008-01-28 17:57 48958 --a------ C:\Program Files\BitPim\resources\splashscreen.jpg
2008-01-28 17:57 456 --a------ C:\Program Files\BitPim\resources\mozilla.pdc
2008-01-28 17:57 4507 --a------ C:\Program Files\BitPim\resources\wallpaper.png
2008-01-28 17:57 4291 --a------ C:\Program Files\BitPim\resources\bitpim.css
2008-01-28 17:57 3833 --a------ C:\Program Files\BitPim\resources\pblayout.xy
2008-01-28 17:57 3621 --a------ C:\Program Files\BitPim\resources\styles.xy
2008-01-28 17:57 3017406 --a------ C:\Program Files\BitPim\resources\bitpim.chm
2008-01-28 17:57 290 --a------ C:\Program Files\BitPim\resources\data_history.png
2008-01-28 17:57 270 --a------ C:\Program Files\BitPim\resources\ranged-slider-current.png
2008-01-28 17:57 241 --a------ C:\Program Files\BitPim\resources\palm.pdc
2008-01-28 17:57 23 --a------ C:\Program Files\BitPim\resources\pbps-colourful.xy
2008-01-28 17:57 2238 --a------ C:\Program Files\BitPim\resources\bitpim.ico
2008-01-28 17:57 2216 --a------ C:\Program Files\BitPim\resources\editsettings.png
2008-01-28 17:57 2202 --a------ C:\Program Files\BitPim\resources\zerolen.wav
2008-01-28 17:57 2097 --a------ C:\Program Files\BitPim\resources\editdetect.png
2008-01-28 17:57 2091 --a------ C:\Program Files\BitPim\resources\autosyncexecute.png
2008-01-28 17:57 207 --a------ C:\Program Files\BitPim\resources\media_list_view.png
2008-01-28 17:57 194 --a------ C:\Program Files\BitPim\resources\media_thumb_view.png
2008-01-28 17:57 1773 --a------ C:\Program Files\BitPim\resources\unknown.png
2008-01-28 17:57 153934 --a------ C:\Program Files\BitPim\resources\usb.ids
2008-01-28 17:57 1384 --a------ C:\Program Files\BitPim\resources\datagetphone.png
2008-01-28 17:57 1378 --a------ C:\Program Files\BitPim\resources\delete_sms.png
2008-01-28 17:57 1359 --a------ C:\Program Files\BitPim\resources\add_sms.png
2008-01-28 17:57 1343 --a------ C:\Program Files\BitPim\resources\select_video.png
2008-01-28 17:57 1335 --a------ C:\Program Files\BitPim\resources\delete_memo.png
2008-01-28 17:57 1328 --a------ C:\Program Files\BitPim\resources\datasendphone.png
2008-01-28 17:57 1314 --a------ C:\Program Files\BitPim\resources\add_memo.png
2008-01-28 17:57 1276 --a------ C:\Program Files\BitPim\resources\select_media.png
2008-01-28 17:57 1256 --a------ C:\Program Files\BitPim\resources\select_wallpaper.png
2008-01-28 17:57 1256 --a------ C:\Program Files\BitPim\resources\select_camera.png
2008-01-28 17:57 1233 --a------ C:\Program Files\BitPim\resources\select_sms.png
2008-01-28 17:57 122542 --a------ C:\Program Files\BitPim\resources\wallpaper-watermark.png
2008-01-28 17:57 1225 --a------ C:\Program Files\BitPim\resources\delete_ringer.png
2008-01-28 17:57 1205 --a------ C:\Program Files\BitPim\resources\delete_picture.png
2008-01-28 17:57 1203 --a------ C:\Program Files\BitPim\resources\add_ringer.png
2008-01-28 17:57 12026 --a------ C:\Program Files\BitPim\resources\ringtone-watermark.png
2008-01-28 17:57 1193 --a------ C:\Program Files\BitPim\resources\add_picture.png
2008-01-28 17:57 1160 --a------ C:\Program Files\BitPim\resources\editphoneinfo.png
2008-01-28 17:57 1158 --a------ C:\Program Files\BitPim\resources\delete_contact.png
2008-01-28 17:57 1148 --a------ C:\Program Files\BitPim\resources\delete_todo.png
2008-01-28 17:57 1133 --a------ C:\Program Files\BitPim\resources\add_todo.png
2008-01-28 17:57 1130 --a------ C:\Program Files\BitPim\resources\add_contact.png
2008-01-28 17:57 1119 --a------ C:\Program Files\BitPim\resources\cal_regular.xy
2008-01-28 17:57 1108 --a------ C:\Program Files\BitPim\resources\delete_field.png
2008-01-28 17:57 1098 --a------ C:\Program Files\BitPim\resources\helphelp.png
2008-01-28 17:57 1092 --a------ C:\Program Files\BitPim\resources\select_playlist.png
2008-01-28 17:57 1090 --a------ C:\Program Files\BitPim\resources\select_protocol.png
2008-01-28 17:57 1081 --a------ C:\Program Files\BitPim\resources\cal_monthly.xy
2008-01-28 17:57 1054 --a------ C:\Program Files\BitPim\resources\select_calendar.png
2008-01-28 17:57 1044 --a------ C:\Program Files\BitPim\resources\private.png
2008-01-28 17:57 104 --a------ C:\Program Files\BitPim\resources\pbps-ledger.xy
2008-01-28 17:57 1013 --a------ C:\Program Files\BitPim\resources\select_sounds.png
2008-01-28 17:57 1011 --a------ C:\Program Files\BitPim\resources\select_call_history.png
2008-01-28 17:50 70656 --a------ C:\Program Files\BitPim\helpers\zlib1.dll
2008-01-28 17:50 525680 --a------ C:\Program Files\BitPim\helpers\bmp2avi.exe
2008-01-28 17:50 48 --a------ C:\Program Files\BitPim\bitpim.url
2008-01-28 17:50 33792 --a------ C:\Program Files\BitPim\helpers\pnmtopng.exe
2008-01-28 17:50 25088 --a------ C:\Program Files\BitPim\helpers\pngtopnm.exe
2008-01-28 17:50 21504 --a------ C:\Program Files\BitPim\helpers\ppmquant.exe
2008-01-28 17:50 206627 --a------ C:\Program Files\BitPim\helpers\libpng12.dll
2008-01-28 17:50 1690112 --a------ C:\Program Files\BitPim\helpers\ffmpeg.exe
2008-01-28 17:50 156672 --a------ C:\Program Files\BitPim\helpers\libnetpbm10.dll
2008-01-15 09:26 591872 --a------ C:\Program Files\BitPim\apsw.pyd
2007-11-29 17:37 339968 --a------ C:\Program Files\BitPim\_gizmos.pyd
2007-11-29 17:36 454656 --a------ C:\Program Files\BitPim\_stc.pyd
2007-11-29 17:33 94208 --a------ C:\Program Files\BitPim\_calendar.pyd
2007-11-29 17:33 663552 --a------ C:\Program Files\BitPim\_misc_.pyd
2007-11-29 17:33 389120 --a------ C:\Program Files\BitPim\_grid.pyd
2007-11-29 17:33 339968 --a------ C:\Program Files\BitPim\_html.pyd
2007-11-29 17:33 114688 --a------ C:\Program Files\BitPim\_wizard.pyd
2007-11-29 17:31 909312 --a------ C:\Program Files\BitPim\_controls_.pyd
2007-11-29 17:30 720896 --a------ C:\Program Files\BitPim\_gdi_.pyd
2007-11-29 17:30 647168 --a------ C:\Program Files\BitPim\_windows_.pyd
2007-11-29 17:29 962560 --a------ C:\Program Files\BitPim\_core_.pyd
2007-11-29 17:16 532480 --a------ C:\Program Files\BitPim\wxmsw28uh_stc_vc.dll
2007-11-29 17:16 151552 --a------ C:\Program Files\BitPim\wxmsw28uh_gizmos_vc.dll
2007-11-29 17:14 708608 --a------ C:\Program Files\BitPim\wxmsw28uh_adv_vc.dll
2007-11-29 17:14 483328 --a------ C:\Program Files\BitPim\wxmsw28uh_html_vc.dll
2007-11-29 17:14 3166208 --a------ C:\Program Files\BitPim\wxmsw28uh_core_vc.dll
2007-11-29 17:12 135168 --a------ C:\Program Files\BitPim\wxbase28uh_net_vc.dll
2007-11-29 17:12 1327104 --a------ C:\Program Files\BitPim\wxbase28uh_vc.dll
2007-08-10 22:47 27136 --a------ C:\Program Files\BitPim\AES.pyd
2007-08-10 22:47 19456 --a------ C:\Program Files\BitPim\DES3.pyd
2007-08-10 22:47 18944 --a------ C:\Program Files\BitPim\Blowfish.pyd
2007-04-18 07:52 753664 --a------ C:\Program Files\BitPim\_bsddb.pyd
2007-04-18 07:52 655360 --a------ C:\Program Files\BitPim\_ssl.pyd
2007-04-18 07:52 53248 --a------ C:\Program Files\BitPim\_socket.pyd
2007-04-18 07:52 323584 --a------ C:\Program Files\BitPim\_hashlib.pyd
2007-04-18 07:51 81920 --a------ C:\Program Files\BitPim\_ctypes.pyd
2007-04-18 07:51 77824 --a------ C:\Program Files\BitPim\bz2.pyd
2007-04-18 07:51 7680 --a------ C:\Program Files\BitPim\select.pyd
2007-04-18 07:51 475136 --a------ C:\Program Files\BitPim\unicodedata.pyd
2007-04-18 07:51 2113536 --a------ C:\Program Files\BitPim\python25.dll
2007-04-18 07:51 135168 --a------ C:\Program Files\BitPim\pyexpat.pyd
2006-09-22 20:34 651264 --a------ C:\Program Files\BitPim\win32ui.pyd
2006-09-22 20:32 151552 --a------ C:\Program Files\BitPim\shell.pyd
2006-09-22 20:30 327680 --a------ C:\Program Files\BitPim\pythoncom25.dll
2006-09-22 20:28 5632 --a------ C:\Program Files\BitPim\_win32sysloader.pyd
2006-09-22 20:28 34816 --a------ C:\Program Files\BitPim\win32help.pyd
2006-09-22 20:28 12288 --a------ C:\Program Files\BitPim\win32trace.pyd
2006-09-22 20:28 114688 --a------ C:\Program Files\BitPim\win32gui.pyd
2006-09-22 20:19 16896 --a------ C:\Program Files\BitPim\win32pipe.pyd
2006-09-22 20:18 90112 --a------ C:\Program Files\BitPim\win32file.pyd
2006-09-22 20:18 86016 --a------ C:\Program Files\BitPim\win32api.pyd
2006-09-22 20:18 14848 --a------ C:\Program Files\BitPim\win32event.pyd
2006-09-22 20:18 102400 --a------ C:\Program Files\BitPim\pywintypes25.dll
2006-07-11 17:35 348160 --a------ C:\Program Files\BitPim\MSVCR71.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-06-02 16:56 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-04 20:08 68856]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-06-04 17:51 1506544]
"SMSystemAnalyzer"="C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-12-20 12:38 557056]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-12 16:47 50528]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"P17Helper"="P17.dll" [2006-03-17 16:11 81408 C:\WINDOWS\system32\P17.dll]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 03:12 76304 C:\WINDOWS\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 19:27 9117696]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\QooBox\Quarantine\C\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe.vir [2008-07-26 16:37:32 91440]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-07-26 16:35:12 805392]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LCDMon]
--a------ 2007-12-13 17:43 2051096 C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch LGDCore]
--a------ 2007-12-13 17:57 2095640 C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2008-04-17 19:27 9117696 C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
--a------ 2008-01-10 12:41 223984 C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Download Manager\\DLM.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"=
"C:\\UT2004\\System\\UT2004.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 17:38]
R3 p17filt;p17filt;C:\WINDOWS\system32\drivers\p17filt.sys [2006-03-20 18:34]
.
Contents of the 'Scheduled Tasks' folder

2008-07-28 C:\WINDOWS\Tasks\B2EAE3CC963D942C.job
- c:\docume~1\marty~1.mar\applic~1\encbin~1\StupidSeekFork.exe []

2008-07-28 C:\WINDOWS\Tasks\BE347C309DB3EF90.job
- c:\docume~1\cheyan~1.mar\applic~1\encbin~1\StupidSeekFork.exe []

2008-06-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2008-07-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2008-07-27 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2008-01-09 04:08]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-loud new - C:\DOCUME~1\MARTY~1.MAR\APPLIC~1\ENCBIN~1\MOVEDEAFKNOB.exe
HKLM-Run-CHIN PING PHONE PILE - C:\Documents and Settings\All Users.WINDOWS\Application Data\Proxy Long Chin Ping\Road amen.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-28 04:19:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-07-28 4:22:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-28 08:22:49
ComboFix2.txt 2008-07-28 07:31:05
ComboFix3.txt 2008-07-28 00:22:28
ComboFix4.txt 2008-05-08 00:25:45

Pre-Run: 74,096,865,280 bytes free
Post-Run: 74,060,619,776 bytes free

836 --- E O F --- 2008-07-28 07:00:54

log #2
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:24:40, on 7/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\marty.MARTY-A113CE187\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iesearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\QooBox\Quarantine\C\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe.vir
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15034/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 8477 bytes
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 7-28-2008 11:01 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
Looks like you get rid of CID ?


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

pestilence
New Member


Date Joined Jun 2007
Total Posts : 29
 
   Posted 7-28-2008 11:11 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
I have not seen one in a while thank you very much
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 7-28-2008 2:40 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
My pleasure smile
 
 
Please  read Tony Klein's excellent article  about how to prevent against  spyware/hijackers in the future
http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html   
                                  


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

pestilence
New Member


Date Joined Jun 2007
Total Posts : 29
 
   Posted 7-28-2008 9:41 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
Would you by any chance know how to get my clock off military time i don"t think it reset after combofix changed it.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 7-29-2008 7:44 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.


Do NOT post your problem in someone elses thread.
Member of - Alliance of Security Analysis Professionals
Please do NOT PM me any logs. They will be deleted

Back to Top
 

pestilence
New Member


Date Joined Jun 2007
Total Posts : 29
 
   Posted 7-29-2008 8:45 (GMT +1)    Quote: Cid Ad popup HelpAlert an admin about: Cid Ad popup Help
that did it again thanks for the help
Back to Top
 
New Topic Post reply to : Cid Ad popup Help Printable version of : Cid Ad popup Help
 
Forum Information
Currently it is Saturday, November 21, 2009 4:11 PM (GMT +1)
There are a total of 73.034 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 71 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
38 Guest(s), 1 Registered Member(s) are currently online.  Details
DanLasko
5 Latest Threads
Constant scanning andskipped files? (3)21-11-2009 14:33:51 (Dickens)
Cannot install anti-virus softeware or do window updates... need help (17)21-11-2009 13:46:11 (superjesse)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)