It is currently Tue Sep 01, 2026 3:04 pm


Some type of malware screwing up IE

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Some type of malware screwing up IE

Postby cc481613 » Mon Jun 30, 2008 3:52 am

I don't know how this happened, but it sure is wreaking havoc with Internet Explorer. It redirects every link to a page saying that my Internet connection is insecure, etc. It doesn't let me browse, whenever I go to a new URL, a pop -up stops me, saying that a Trojan has corrupted system files and I need to go to this link to stop it. Knowing better, I didn't click it. However, this problem still isn't getting any better. Luckily for me, I have an alternate browser I usually use. Nevertheless, could you please check this log? It gets really annoying after a while.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:47:14 PM, on 29/06/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Safari\Safari.exe
C:\Users\Calvin\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/?lang=en-CA
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:\PROGRA~1\SPEEDB~1\vaproxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Spybot-S&D IE Protection - {B1892F58-1116-4DEC-92AA-577872EC3D3D} - C:\Windows\system32\xmlwin.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v ... b56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe

--
End of file - 9654 bytes





EDIT: Now, explorer.exe is closing and not restarting, unless I start is from Task Manager. However, it still closes within the first 10 seconds after I open it. Knowing that I will need a ComboFix log, here it is:


ComboFix 08-06-20.4 - Calvin 2008-06-30 9:27:27.10 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1995 [GMT -7:00]
Running from: C:\Users\Calvin\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((( Files Created from 2008-05-28 to 2008-06-30 )))))))))))))))))))))))))))))))
.

2008-06-30 09:15 . 2008-06-30 09:15 26,624 --a------ C:\Windows\System32\xmlview.dll
2008-06-30 09:15 . 2008-06-30 09:15 24,576 --a------ C:\Windows\System32\wvUNeEtR.dll
2008-06-30 08:55 . 2008-06-30 09:02 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-06-30 08:55 . 2008-06-30 09:02 <DIR> d-------- C:\ProgramData\Lavasoft
2008-06-30 08:55 . 2008-06-30 08:55 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-29 15:21 . 2008-06-29 15:22 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\VMware
2008-06-29 15:20 . 2008-06-29 15:20 26,624 --a------ C:\Windows\System32\xmlwin.dll
2008-06-29 15:10 . 2008-05-16 00:51 50,992 --a------ C:\Windows\System32\vmnetbridge.dll
2008-06-29 15:09 . 2008-06-29 15:09 1,024 --a------ C:\.rnd
2008-06-29 15:08 . 2008-06-29 15:28 <DIR> d-------- C:\Program Files\VMware
2008-06-26 13:59 . 2008-06-26 14:24 <DIR> d-------- C:\Program Files\Opera
2008-06-25 15:40 . 2008-06-29 17:23 <DIR> d-------- C:\Program Files\Free Download Manager
2008-06-25 15:31 . 2008-06-25 15:31 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-06-25 09:47 . 2008-06-25 09:47 <DIR> d-------- C:\Program Files\Freeze.com
2008-06-25 09:39 . 2008-06-25 09:39 <DIR> d-------- C:\Program Files\Xio
2008-06-25 09:38 . 2008-06-25 09:38 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\Xion
2008-06-24 23:23 . 2008-06-24 23:23 354,560 --a------ C:\Windows\System32\TuneUpDefragService.exe
2008-06-24 23:21 . 2008-04-04 14:51 28,416 --a------ C:\Windows\System32\uxtuneup.dll
2008-06-24 23:21 . 2008-04-04 14:51 16,640 --a------ C:\Windows\System32\authuitu.dll
2008-06-24 23:20 . 2008-06-29 18:21 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-06-24 23:19 . 2008-06-30 08:54 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-23 12:45 . 2008-06-23 12:45 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\TuneUp Software
2008-06-23 12:45 . 2008-06-23 12:45 <DIR> d-------- C:\Users\All Users\TuneUp Software
2008-06-23 12:45 . 2008-06-23 12:45 <DIR> d-------- C:\ProgramData\TuneUp Software
2008-06-23 12:38 . 2008-06-23 12:38 28,812,800 --a------ C:\Windows\System32\imageres.dll
2008-06-23 12:30 . 2008-06-23 12:30 <DIR> d-------- C:\Program Files\Stardock
2008-06-23 08:20 . 2008-06-23 08:20 <DIR> d-------- C:\Users\All Users\Stardock
2008-06-23 08:20 . 2008-06-23 08:20 <DIR> d-------- C:\ProgramData\Stardock
2008-06-23 08:19 . 2007-06-05 11:26 567,040 --a------ C:\Windows\System32\wbocx.ocx
2008-06-23 08:19 . 2007-06-05 11:26 56,496 --a------ C:\Windows\System32\wbhelp2.dll
2008-06-22 09:23 . 2008-06-22 09:23 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\Sibelius Software
2008-06-22 08:49 . 2008-06-22 08:56 <DIR> d-------- C:\Program Files\Unlocker
2008-06-22 02:18 . 2006-03-03 08:07 143,360 --a------ C:\Windows\System32\dunzip32.dll
2008-06-21 19:11 . 2008-06-21 19:11 50 --a------ C:\Windows\MegaManager.INI
2008-06-17 16:52 . 2008-06-28 10:46 <DIR> d-------- C:\Program Files\PokerStars
2008-06-16 07:47 . 2008-06-16 07:47 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-06-15 11:20 . 2008-06-15 11:20 <DIR> d-------- C:\Program Files\iPod
2008-06-14 08:39 . 2008-06-14 08:39 <DIR> d--h----- C:\Windows\msdownld.tmp
2008-06-12 17:46 . 2008-06-29 18:44 <DIR> d-------- C:\Users\Mom.Calvin-PC\AppData\Roaming\Apple Computer
2008-06-10 19:50 . 2008-04-22 21:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-06-10 19:50 . 2008-04-22 21:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-06-10 19:50 . 2008-04-22 21:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-10 19:50 . 2008-04-22 21:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-10 17:35 . 2008-05-09 20:35 885,248 --a------ C:\Windows\System32\RacEngn.dll
2008-06-10 17:35 . 2008-05-09 15:22 9,127 --a------ C:\Windows\System32\RacUR.xml
2008-06-10 17:35 . 2008-05-09 15:22 153 --a------ C:\Windows\System32\RacUREx.xml
2008-06-10 17:34 . 2008-04-24 19:12 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-06-10 17:34 . 2008-04-26 01:08 1,314,816 --a------ C:\Windows\System32\quartz.dll
2008-06-10 17:34 . 2008-04-24 21:35 826,880 --a------ C:\Windows\System32\wininet.dll
2008-06-10 17:34 . 2008-05-09 18:33 113,664 --a------ C:\Windows\System32\drivers\rmcast.sys
2008-06-08 21:53 . 2008-06-08 21:58 <DIR> d-------- C:\Users\All Users\PrevxCSI
2008-06-08 21:53 . 2008-06-08 21:58 <DIR> d-------- C:\ProgramData\PrevxCSI
2008-06-08 16:50 . 2008-06-08 16:50 32 --a------ C:\Windows\hip
2008-06-06 06:25 . 2008-06-06 06:25 <DIR> d-------- C:\Users\All Users\Microsoft Corporation
2008-06-06 06:25 . 2008-06-06 06:25 <DIR> d-------- C:\ProgramData\Microsoft Corporation
2008-06-04 23:11 . 2008-06-04 23:11 <DIR> d-------- C:\Users\All Users\PopCap
2008-06-04 23:11 . 2008-06-04 23:11 <DIR> d-------- C:\ProgramData\PopCap
2008-06-03 06:34 . 2008-06-03 06:35 <DIR> d-ahs---- C:\Users\Calvin\!
2008-06-01 09:29 . 2008-06-01 09:29 <DIR> d-------- C:\Users\Mom.Calvin-PC\AppData\Roaming\Roxio
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Videos
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Searches
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Saved Games
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Pictures
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Music
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Links
2008-06-01 09:28 . 2008-06-20 17:49 <DIR> dr------- C:\Users\Mom.Calvin-PC\Downloads
2008-06-01 09:28 . 2008-06-14 18:34 <DIR> dr------- C:\Users\Mom.Calvin-PC\Documents
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> dr------- C:\Users\Mom.Calvin-PC\Contacts
2008-06-01 09:28 . 2006-11-02 05:37 <DIR> d-------- C:\Users\Mom.Calvin-PC\AppData\Roaming\Media Center Programs
2008-06-01 09:28 . 2008-06-04 22:08 <DIR> d--h----- C:\Users\Mom.Calvin-PC\AppData\Roaming\GTek
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> d--h----- C:\Users\Mom.Calvin-PC\AppData
2008-06-01 09:28 . 2008-06-01 09:28 <DIR> d-------- C:\Users\Mom.Calvin-PC
2008-05-31 10:22 . 2008-05-31 10:22 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-05-27 16:41 . 2008-03-07 19:08 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-27 16:41 . 2008-03-07 21:21 1,695,744 --a------ C:\Windows\System32\gameux.dll
2008-05-27 10:50 . 2008-05-27 10:50 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 --a------ C:\Windows\System32\QuickTime.qts
2008-05-24 15:57 . 2008-05-25 07:44 <DIR> d-------- C:\Program Files\EA GAMES
2008-05-24 15:57 . 2004-08-18 02:17 442,368 -ra------ C:\Windows\System32\vp6vfw.dll
2008-05-24 10:38 . 2008-05-24 10:38 717,296 --a------ C:\Windows\System32\drivers\sptd.sys
2008-05-24 10:37 . 2008-05-24 10:37 <DIR> d-a------ C:\Users\Calvin\AppData\Roaming\DAEMON Tools
2008-05-22 19:19 . 2008-05-22 19:19 <DIR> d-------- C:\PerfLogs
2008-05-22 17:18 . 2008-01-19 00:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-05-22 17:17 . 2008-01-19 00:33 8,139,264 --a------ C:\Windows\System32\ssBranded.scr
2008-05-22 17:16 . 2008-01-19 00:36 2,588,160 --a------ C:\Windows\System32\UIHub.dll
2008-05-22 17:15 . 2008-01-19 00:34 6,103,040 --a------ C:\Windows\System32\chtbrkr.dll
2008-05-22 17:14 . 2008-06-27 11:08 8,372,224 --a------ C:\Windows\System32\wmploc.dll
2008-05-22 17:13 . 2008-01-19 00:33 599,552 --a------ C:\Windows\System32\vsp1cln.exe
2008-05-22 17:13 . 2008-01-05 04:31 145,455 --a------ C:\Windows\System32\perfmon.msc
2008-05-22 17:13 . 2008-01-05 04:31 3 --a------ C:\Windows\System32\drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf
2008-05-22 17:12 . 2008-01-19 00:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-05-22 17:12 . 2008-01-19 00:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-05-22 17:12 . 2008-01-19 00:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-05-22 17:12 . 2008-01-19 00:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-05-22 17:12 . 2008-01-19 00:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-05-22 17:12 . 2008-01-19 00:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-05-22 17:12 . 2008-01-19 00:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-05-22 17:12 . 2008-01-19 00:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-05-22 17:11 . 2008-01-19 00:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-05-18 18:07 . 2008-05-18 18:07 671 --a------ C:\Windows\System32\newaddies.xtc
2008-05-18 18:03 . 2008-05-31 12:37 <DIR> d--h----- C:\Users\~Administrator~\AppData
2008-05-18 18:03 . 2008-05-31 12:37 <DIR> d-------- C:\Users\~Administrator~
2008-05-18 11:19 . 2008-06-29 17:54 <DIR> d-------- C:\Program Files\Eusing Free Registry Cleaner
2008-05-17 21:13 . 2008-05-17 21:17 <DIR> d-------- C:\Program Files\GRETECH
2008-05-17 08:03 . 2008-06-04 22:48 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\Windows\System32\lsdelete.exe
2008-05-16 07:48 . 2008-05-16 07:54 <DIR> d-------- C:\Program Files\ShellExView
2008-05-16 07:48 . 2008-05-16 07:48 39,424 --a------ C:\Windows\zipinst.exe
2008-05-15 18:33 . 2008-05-15 18:45 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-05-15 17:29 . 2008-06-03 23:19 <DIR> d-------- C:\DVDVideoSoft
2008-05-15 00:16 . 2008-05-15 00:16 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2008-05-13 00:07 . 2008-05-13 00:07 524,288 --ahs---- C:\ntuser.dat{c39279b4-208c-11dd-8355-00e034123456}.TMContainer00000000000000000002.regtrans-ms
2008-05-13 00:07 . 2008-06-29 15:51 524,288 --ahs---- C:\ntuser.dat{c39279b4-208c-11dd-8355-00e034123456}.TMContainer00000000000000000001.regtrans-ms
2008-05-13 00:07 . 2008-05-13 00:07 524,288 --ahs---- C:\ntuser.dat{c39279b0-208c-11dd-8355-00e034123456}.TMContainer00000000000000000002.regtrans-ms
2008-05-13 00:07 . 2008-05-13 00:07 524,288 --ahs---- C:\ntuser.dat{c39279b0-208c-11dd-8355-00e034123456}.TMContainer00000000000000000001.regtrans-ms
2008-05-13 00:07 . 2008-06-29 15:23 262,144 --a------ C:\ntuser.dat
2008-05-13 00:07 . 2008-06-29 15:51 65,536 --ahs---- C:\ntuser.dat{c39279b4-208c-11dd-8355-00e034123456}.TM.blf
2008-05-13 00:07 . 2008-05-13 00:07 65,536 --ahs---- C:\ntuser.dat{c39279b0-208c-11dd-8355-00e034123456}.TM.blf
2008-05-13 00:07 . 2008-06-29 15:23 5,120 --ah----- C:\ntuser.dat.LOG1
2008-05-13 00:07 . 2008-05-13 00:07 0 --ah----- C:\ntuser.dat.LOG2
2008-05-11 15:31 . 2008-05-11 15:31 <DIR> d-------- C:\NVIDIA
2008-05-11 12:59 . 2008-05-11 12:59 <DIR> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-05-11 12:55 . 2007-02-20 16:04 2,463,976 --a------ C:\Windows\System32\NPSWF32.dll
2008-05-11 12:55 . 2007-02-20 16:04 190,696 --a------ C:\Windows\System32\NPSWF32_FlashUtil.exe
2008-05-11 09:19 . 2008-05-11 11:53 <DIR> d-------- C:\Users\Calvin\AppData\Roaming\Download Manager

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-30 16:07 --------- d---a-w C:\Users\Calvin\AppData\Roaming\LimeWire
2008-06-30 15:57 --------- d-----w C:\Program Files\McAfee
2008-06-30 15:51 --------- d-----w C:\Program Files\Dl_cats
2008-06-30 00:55 --------- d-----w C:\Program Files\Bonjour
2008-06-27 18:08 615,424 ----a-w C:\Windows\System32\themeui.dll
2008-06-27 18:08 240,128 ----a-w C:\Windows\System32\uxtheme.dll
2008-06-27 18:08 2,140,672 ----a-w C:\Windows\System32\authui.dll
2008-06-27 18:08 1,991,680 ----a-w C:\Windows\System32\oobefldr.dll
2008-06-25 22:27 --------- d---a-w C:\ProgramData\TEMP
2008-06-23 19:40 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-06-22 14:10 --------- d-----w C:\Program Files\Common Files\McAfee
2008-06-22 02:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 18:53 --------- d-----w C:\Program Files\Nexon
2008-06-18 22:18 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-15 18:20 --------- d-----w C:\Program Files\iTunes
2008-06-15 18:03 --------- d-----w C:\Program Files\QuickTime
2008-06-11 02:39 --------- d-----w C:\Program Files\Windows Mail
2008-06-04 00:12 --------- d-----w C:\Program Files\LimeWire
2008-05-31 18:31 --------- d---a-w C:\Users\Calvin\AppData\Roaming\U3
2008-05-25 04:34 --------- d-----w C:\ProgramData\Roxio
2008-05-23 03:26 --------- d-----w C:\ProgramData\NVIDIA
2008-05-23 02:33 174 --sha-w C:\Program Files\desktop.ini
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Sidebar
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Journal
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Defender
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Collaboration
2008-05-23 02:22 --------- d-----w C:\Program Files\Windows Calendar
2008-05-23 01:28 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-05-23 01:28 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-05-15 02:01 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-15 01:13 --------- d-----w C:\Program Files\Java
2008-05-14 00:05 --------- d-----w C:\Program Files\SoundSpectrum
2008-05-11 22:31 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-11 19:47 --------- d-----w C:\Program Files\Macromedia
2008-05-11 19:47 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-05-01 02:14 --------- d-----w C:\Program Files\CCleaner
2008-05-01 02:10 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Crystal Art Software
2008-04-30 06:14 --------- d-----w C:\Program Files\Dell DataSafe Online
2008-04-29 18:20 15,648 ----a-w C:\Windows\system32\drivers\NSDriver.sys
2008-04-29 18:19 15,648 ----a-w C:\Windows\system32\drivers\Awrtrd.sys
2008-04-29 18:19 12,960 ----a-w C:\Windows\system32\drivers\Awrtpd.sys
2008-04-29 05:27 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Astro Gemini Software
2008-04-29 02:54 --------- d-----w C:\Program Files\Windows Live
2008-04-29 02:46 --------- d-----w C:\ProgramData\WLInstaller
2008-04-28 00:17 --------- d-----w C:\Users\Calvin\AppData\Roaming\Hamachi
2008-04-28 00:10 25,280 ----a-w C:\Windows\system32\drivers\hamachi.sys
2008-03-31 05:01 691,545 ----a-w C:\Windows\unins000.exe
2008-03-09 01:45 21,764 ----a-w C:\Windows\System32\CoreAAC-uninstall.exe
2008-03-08 04:19 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-08 04:19 458,752 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-03-08 04:19 2,153,984 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-03-08 04:19 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-03-08 01:58 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2007-11-04 16:32 374 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb6334.dat
2007-11-04 14:50 555 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb8467.dat
2007-11-04 14:50 18,432 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb41.dat
2008-03-09 17:38 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-03-09 17:38 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-03-09 17:38 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8AE578E0-6DF5-41E0-869F-F65A32D2F6BD}]
2008-06-30 09:15 26624 --a------ C:\Windows\system32\xmlview.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1892F58-1116-4DEC-92AA-577872EC3D3D}]
2008-06-29 15:20 26624 --a------ C:\Windows\system32\xmlwin.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 00:33 125952]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 00:33 202240]
"cmds"="C:\Users\Calvin\AppData\Local\Temp\mlJCsQIa.dll" [2008-06-30 09:20 320000]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 07:22 4907008 C:\Windows\RtHDVCpl.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 09:37 81920]
"dlcqmon.exe"="C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 08:47 292080]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-17 09:07 86016]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-17 09:07 81920]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"DLCQCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-15 22:31 106496]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 19:56 202544]
"MSServer"="C:\Windows\system32\wvUNeEtR.dll" [2008-06-30 09:15 24576]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

C:\Users\Mom.Calvin-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [8/24/2007 5:45:42 AM 101784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{ACED1C9F-2718-4512-9F69-F4E28C1F484F}"= C:\Windows\system32\wvUNeEtR.dll [2008-06-30 09:15 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-19 00:33 202240 C:\Program Files\Windows Media Player\WMPNSCFG.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
"Dell DataSafe Scheduler"="C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe_ID0EYTHM"=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
"ECenter"=c:\dell\E-Center\EULALauncher.exe
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C40A1CDE-3524-47EB-AB86-D043632CF06D}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{95A5E1FA-64AB-4ADB-AC4D-3DF2E0B735B6}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9164ED87-D1FE-4206-8496-29DEC6BBB6D0}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{204B31F1-64E0-4F04-B55D-73DE3A458B3F}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{189B5808-CF71-49AB-94CA-02B985EA3914}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{E162012F-98CF-4888-8A39-00328A767F10}C:\\program files\\nexon\\maplestory\\maplestory.exe"= UDP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{2FB30AAD-97FB-4027-8C8D-3FA7FDCF7BFE}C:\\program files\\nexon\\maplestory\\maplestory.exe"= TCP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{A0186F92-7442-4DC0-9CDF-695C1370EE4F}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= UDP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"UDP Query User{FCD1575D-BBD4-4794-AD79-F7C3406AE999}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= TCP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"TCP Query User{4E10DA99-3C04-4667-9F89-F36A44B45368}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= UDP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"UDP Query User{79088905-9F9D-4D68-9C4F-512196042A94}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= TCP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"TCP Query User{C5CBBF51-2752-40A6-A2C0-DC8A40B3B8F6}C:\\users\\calvin\\saved games\\nexon\\newpatcher.exe"= UDP:C:\users\calvin\saved games\nexon\newpatcher.exe:newpatcher.exe
"UDP Query User{BFE9CE8F-1C04-4B88-8B32-CAD967AF13DA}C:\\users\\calvin\\saved games\\nexon\\newpatcher.exe"= TCP:C:\users\calvin\saved games\nexon\newpatcher.exe:newpatcher.exe
"TCP Query User{871E1A48-AEBC-4085-BAED-C787EC6E21F1}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= UDP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"UDP Query User{326FF41C-497D-4D03-8513-22EBAC3AC34A}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= TCP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"TCP Query User{37A6A56D-37BC-40E8-9018-8069A4C66930}C:\\program files\\nexon\\maplestory\\maplestory.exe"= UDP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{A5CF2920-5E05-4607-BCEE-DA15A6B8B0A0}C:\\program files\\nexon\\maplestory\\maplestory.exe"= TCP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{3FE2B734-5BFA-4A80-84A8-87DC826F8C00}C:\\windows\\explorer.exe"= UDP:C:\windows\explorer.exe:Windows Explorer
"UDP Query User{5FD30CFD-6BAB-4702-9497-098A7B9A67B4}C:\\windows\\explorer.exe"= TCP:C:\windows\explorer.exe:Windows Explorer
"{ECEF8CF6-AFE4-4A65-A2EF-8691D9A93C3E}"= UDP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{79C9CF6E-0E9A-41AB-861D-8EAE4CF907B2}"= TCP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"TCP Query User{80CCF7DE-E26B-40A8-836A-638BA1A87700}C:\\nexon\\maplestory\\maplestory.exe"= UDP:C:\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{71B875FE-9E27-418C-A965-496F8303828E}C:\\nexon\\maplestory\\maplestory.exe"= TCP:C:\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{D3C1ECFA-5DAD-42A3-8DAA-1896FE6B3BEA}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{E2A310D1-7EB4-4C86-94ED-A1764FE80CA3}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"{24BECBA1-8C8C-4B02-9916-4EEB02766C48}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{39FBCFD1-2DF2-4251-AF7F-3C3685B06BB7}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{34A08745-C53B-4350-BBF6-B3E8C45B0762}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe:
"UDP Query User{4FA8BA5C-B3B3-4BB2-B2CE-DAED6CF66DFD}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe:
"TCP Query User{A3D3605E-AF3F-46B9-9FDE-230A280E9BFF}C:\\program files\\bitlord\\bitlord.exe"= UDP:C:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{9C1B00E3-FA2A-420B-84D1-86DAE89A54E6}C:\\program files\\bitlord\\bitlord.exe"= TCP:C:\program files\bitlord\bitlord.exe:BitLord
"{341CEB89-AAA7-452B-A8EB-87FBD4C00165}"= UDP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{C4613266-71ED-4679-8A58-AB4071F27743}"= TCP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{2F9D8050-BF84-4A47-B80A-5A51F24B62A2}"= UDP:C:\Nexon\KartRider\KartRider.exe:KartRider
"{6CEB6678-3F6B-49DA-A194-2CAD4CC4998E}"= TCP:C:\Nexon\KartRider\KartRider.exe:KartRider
"{CB551BCF-FF61-435D-A80D-803693620C35}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{BBD75391-A0DC-47C2-9821-47E61C7E212E}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{0AA4CB1A-C026-4777-AB0D-26B0E8C4F83E}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{F12EB92A-1930-47BF-A3FD-728C657F1501}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{D4C3A691-D7F9-44A7-8EFD-B572AA6E55BD}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{E91FAA2D-12B0-43F8-B2DC-D06E76678598}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{916FABEE-914F-4826-B5B6-1F8593C95026}"= UDP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{52987BB2-9EE3-490F-905B-6245E9C27E94}"= TCP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{5FE6955F-A5A9-4AAC-B7F5-7417FD787A4D}"= UDP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{A5A26F7F-557D-4D8C-8F09-CCA1084FC6D8}"= TCP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{8DB4D979-8B52-45D7-9B71-D00095952AF3}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{CD5E6279-511E-4EFF-A1DD-C2ABE970394B}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{57D1B8F0-DC42-498A-AF6A-D23054A5340E}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{28A1A368-8650-4792-9A26-66373E947820}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{A64B97B6-82CE-4781-B074-0FCDB62DEF67}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{7933A23F-CCC4-43AC-8854-891062504CD7}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{F493B459-7CCA-4DDD-9A94-BD312D30BA98}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{55C74632-22F9-4705-AB7B-2B112956FA2B}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{ED28BE93-1FAA-4D8C-A7D1-0257C567F0DD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CAE85B28-FC9A-4AC2-860E-99EFB98BEC6B}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{07C4E20F-9055-41F6-99B7-62625B4681FC}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{625BF72C-6185-4D8F-B800-F26772BBEA96}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{D8802660-2B38-4762-B31B-C502D67C1A4D}C:\\program files\\ea sports\\nhl08\\nhl2008.exe"= UDP:C:\program files\ea sports\nhl08\nhl2008.exe:nhl2008
"UDP Query User{1C0EF8FA-9327-4934-A9CF-0A6C401F6D9B}C:\\program files\\ea sports\\nhl08\\nhl2008.exe"= TCP:C:\program files\ea sports\nhl08\nhl2008.exe:nhl2008
"{BB93A364-29CE-4471-8A8D-0427EE503372}"= UDP:C:\Program Files\EA Sports\EA SPORTS online\SportsWrapper.exe:SportsWrapper
"{0E00767A-9216-4BA8-B36B-F552C1591F1B}"= TCP:C:\Program Files\EA Sports\EA SPORTS online\SportsWrapper.exe:SportsWrapper
"{7FDCC7F9-7C63-4F32-A0FD-967282029470}"= UDP:3703:Adobe Version Cue CS3 Server
"{A54138F7-585B-45C2-B398-2708C437E641}"= UDP:3704:Adobe Version Cue CS3 Server
"{88F3E162-3910-4B5C-81C9-26A4EF828D5F}"= UDP:50900:Adobe Version Cue CS3 Server
"{CF41B43C-48BF-45B6-A844-345E7BD558F2}"= UDP:50901:Adobe Version Cue CS3 Server
"{E9035596-E03B-4100-8521-8ACD9A3F79FD}"= UDP:C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"{940BD430-EBCF-4C4B-83D7-C7AF61054A01}"= TCP:C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server
"TCP Query User{56B436A0-8D6B-47B1-A43B-8253FFB3D7B4}C:\\program files\\safari\\safari.exe"= UDP:C:\program files\safari\safari.exe:Safari Web Browser
"UDP Query User{DE366E98-DB01-4FF2-AEF9-DE26FDD6F8D5}C:\\program files\\safari\\safari.exe"= TCP:C:\program files\safari\safari.exe:Safari Web Browser
"{7CB9E126-78F4-4078-98DA-E1EF3DE97BA1}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{E2E58ED7-B047-4F17-82DF-763541F65E0A}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{59007D0B-3B78-41DA-85DC-CBC43F6857C4}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{18BF8B2B-D746-40D0-8D11-EDF2AA4BC4C5}"= UDP:C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"{4AB10804-DCDD-453A-BD74-EC2F935A9B1F}"= TCP:C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"{F8D65109-5A54-4613-BE57-2860958BD620}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]
R2 AERTFilters;Andrea RT Filters Service;C:\Windows\system32\AERTSrv.exe [2007-12-05 06:17]
R2 dlcq_device;dlcq_device;C:\Windows\system32\dlcqcoms.exe [2006-12-12 01:22]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-10-09 19:56]
R2 UxTuneUp;TuneUp Theme Extension;C:\Windows\System32\svchost.exe [2008-01-19 00:33]
S2 0048261214841454mcinstcleanup;McAfee Application Installer Cleanup (0048261214841454);C:\Windows\TEMP\004826~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 NAL;Nal Service ;C:\Windows\system32\Drivers\iqvw32.sys [2007-03-09 15:04]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 00:36]
S3 ROCKSTAR;ROCKSTAR;C:\Users\Calvin\Desktop\Hack Trainer\ksysdrv.sys [2006-12-20 20:52]
S3 tapvpn;TAP VPN Adapter;C:\Windows\system32\DRIVERS\tapvpn.sys [2008-03-12 19:38]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.exe [2008-06-24 23:23]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{214b9213-29c4-11dd-b075-00e034123456}]
\shell\AutoRun\command - K:\RunGame.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{214b9239-29c4-11dd-b075-00e034123456}]
\shell\AutoRun\command - M:\Autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68df2eb3-5b9f-11dc-aed8-806e6f6e6963}]
\shell\AutoRun\command - E:\setup.exe

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-30 16:00:00 C:\Windows\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-06-15 16:39:45 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-03-03 16:25:30 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-06-30 16:30:00 C:\Windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-06-29 17:00:46 C:\Windows\Tasks\User_Feed_Synchronization-{2B3DF531-795E-4B8F-852D-F9141689C0CD}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-06-30 16:30:12 C:\Windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-30 09:32:17
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\Windows\system32\winlogon.exe
-> C:\Windows\system32\wvUNeEtR.dll
.
Completion time: 2008-06-30 9:37:47
ComboFix-quarantined-files.txt 2008-06-30 16:36:54
ComboFix2.txt 2008-05-29 23:41:08
ComboFix3.txt 2008-05-14 00:47:57
ComboFix4.txt 2008-05-13 01:49:51
ComboFix5.txt 2008-04-26 15:23:27

Pre-Run: 329,176,338,432 bytes free
Post-Run: 329,152,720,896 bytes free

406 --- E O F --- 2008-06-24 20:36:01
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: Some type of malware screwing up IE

Postby Gecko » Tue Jul 01, 2008 11:34 am

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Some type of malware screwing up IE

Postby cc481613 » Tue Jul 01, 2008 4:17 pm

I did a System Restore before you posted and the problem is fixed... However, is it gone for good? Or should I restore back to normal and fix it the ComboFix way?
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: Some type of malware screwing up IE

Postby tier1ip » Sat Nov 29, 2008 5:08 pm

The system restore should have fixed your problem; however, I recommend you take a look at the root of your problem -- how did you obtain the issue? Perhaps you should look into removing file sharing programs. Also, try downloading, updating, and scanning for malware with Spybot Search & Destroy on a regular basis. Another process I would try is do a house call free scan from trend micro to see if mcafee is missing anything.
tier1ip
Newbie
Newbie
 
Posts: 4
Joined: Sat Nov 29, 2008 6:29 am
Location: Fort Worth, TX

Thanks given:0
Thanks received:0
Top

Re: Some type of malware screwing up IE

Postby Axelation » Wed Dec 03, 2008 5:23 am

Download MalwareBytes Malware Remover, It's free and does a pretty good job with things like that. Even though you fixed it, I would have it available just in case. Problems like that seem to be becoming more an more frequent. Also check out SuperAntiSpyware. It also helps for things like that.
"You don't know it yet, but.......You are sharing your secrets....One packet at a time."
User avatar
Axelation
Senior Geek
Senior Geek
 
Posts: 133
Joined: Fri Aug 06, 2004 1:00 am
Location: Texas

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron