It is currently Tue Sep 01, 2026 3:02 pm


SOS... What's wrong?

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

SOS... What's wrong?

Postby cc481613 » Fri Apr 25, 2008 5:16 am

Okay... yesterday, I was browsing the web when I accidentally clicked on a pop-up (I was clicking on a link but the pop-up cam up just before I clicked). A few seconds later, Spybot S&D started spamming me with messages about changes in registry, etc. I clicked "deny change" for everything, but then it just kept on popping up. Then, after about a minute or so, my computer went poof and shut down randomly. I restarted it, and now once I log in, Spybot S&D spams me all over again. Just in case you need it, here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:07:08 PM, on 24/04/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Program Files\McAfee\MSK\mskagent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\Calvin\Desktop\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/?lang=en-CA
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Calvin
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: BeSideit IE Helper - {89CBB8EA-FA02-4f61-B997-0247E69F002B} - C:\Program Files\QdrDrive\QdrDrive15.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\{0150f981-1470-f2da-2b06-d4309fa24d9d}.dll" DllInit
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-U ... E_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: dlcq_device - - C:\Windows\system32\dlcqcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: PsExec (PSEXESVC) - Sysinternals - C:\Windows\PSEXESVC.EXE
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 10752 bytes


Please help me... thanks!
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: SOS... What's wrong?

Postby Gecko » Fri Apr 25, 2008 12:28 pm

cc481613,

Please download to your desktop.

Double click combofix.exe and follow the prompts.

When it's done running it will produce a log for you. Please post that log in your next reply.

Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: SOS... What's wrong?

Postby cc481613 » Fri Apr 25, 2008 1:23 pm

OKay... heres the log:

ComboFix 08-04-22.5 - Calvin 2008-04-25 5:08:44.3 - NTFSx86
Running from: C:\Users\Calvin\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QdrDrive15.dll
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\Reference Assemblies\dagupax66225.dll
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Speed Monitor
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Users\Calvin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Speed Monitor
C:\Users\Calvin\AppData\Roaming\WeatherDPA
C:\Windows\system32\msnav32.ax

.
((((((((((((((((((((((((( Files Created from 2008-03-25 to 2008-04-25 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-25 12:15 --------- d-----w C:\Program Files\Reference Assemblies
2008-04-25 12:02 --------- d-----w C:\Program Files\Dl_cats
2008-04-25 12:01 --------- d-----w C:\Program Files\McAfee
2008-04-25 03:17 63,925 ----a-w C:\Windows\System32\{0150f981-1470-f2da-2b06-d4309fa24d9d}.dll-uninst.exe
2008-04-25 03:17 49,152 ----a-w C:\Windows\one11111.exe
2008-04-25 03:17 399,943 ----a-w C:\Windows\four444444.exe
2008-04-25 03:17 266,607 ----a-w C:\Windows\two222222.exe
2008-04-25 03:17 136,627 ----a-w C:\Windows\LOT66225.exe
2008-04-25 03:17 --------- d-----w C:\Program Files\VnrPack
2008-04-25 03:11 --------- d---a-w C:\Users\Calvin\AppData\Roaming\LimeWire
2008-04-24 01:16 --------- d-----w C:\Program Files\Nexon
2008-04-22 23:22 --------- d-----w C:\Program Files\7-Zip
2008-04-22 07:52 --------- d-----w C:\Program Files\Actual Drawing
2008-04-22 07:48 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Web Page Maker V2
2008-04-22 07:48 --------- d-----w C:\Program Files\Yahoo!
2008-04-22 07:43 --------- d-----w C:\Program Files\Game Optimizer Pro
2008-04-22 06:18 --------- d-----w C:\Program Files\i.Hex
2008-04-22 03:38 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-04-22 03:38 --------- d-----w C:\Program Files\Windows Live Favorites
2008-04-22 03:37 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-04-22 03:23 --------- d-----w C:\Program Files\Safari
2008-04-22 03:20 --------- d-----w C:\Program Files\Apple Software Update
2008-04-21 00:38 --------- d-----w C:\Program Files\LeechGet 2007
2008-04-20 17:09 --------- d-----w C:\Program Files\Windows Live
2008-04-20 17:02 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Orbit
2008-04-16 05:57 --------- d-----w C:\Program Files\Cloudbrain
2008-04-16 04:19 --------- d-----w C:\Program Files\Macromedia
2008-04-16 04:19 --------- d-----w C:\Program Files\Common Files\Macromedia Shared
2008-04-16 04:15 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-04-15 03:10 --------- d-----w C:\Program Files\LimeWire
2008-04-15 01:39 --------- d-----w C:\Program Files\Java
2008-04-13 17:07 --------- d-----w C:\Program Files\Virtual Mechanics
2008-04-11 08:12 --------- d-----w C:\Program Files\UFile 2007
2008-04-09 02:06 --------- d-----w C:\Program Files\Windows Mail
2008-04-09 00:08 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-03 05:31 --------- d-----w C:\Program Files\iTunes
2008-04-03 05:31 --------- d-----w C:\Program Files\iPod
2008-04-03 05:30 --------- d-----w C:\Program Files\QuickTime
2008-03-31 18:05 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-31 16:07 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Apple Computer
2008-03-31 05:01 691,545 ----a-w C:\Windows\unins000.exe
2008-03-27 15:24 --------- d---a-w C:\Users\Calvin\AppData\Roaming\gtk-2.0
2008-03-27 02:13 --------- d---a-w C:\Users\Calvin\AppData\Roaming\ZoomBrowser EX
2008-03-27 02:12 --------- d---a-w C:\Users\Calvin\AppData\Roaming\CameraWindowDC
2008-03-26 15:55 --------- d---a-w C:\Users\Calvin\AppData\Roaming\SystemRequirementsLab
2008-03-26 15:55 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-03-15 17:30 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Canon
2008-03-15 17:24 --------- d---a-w C:\Users\Calvin\AppData\Roaming\CANON INC
2008-03-14 05:18 --------- d-----w C:\Program Files\DVDVideoSoft
2008-03-13 04:55 --------- d-----w C:\Program Files\Canon
2008-03-13 04:52 --------- d-----w C:\Program Files\Common Files\Canon
2008-03-13 02:38 27,136 ----a-w C:\Windows\system32\drivers\tapvpn.sys
2008-03-09 17:23 --------- d-----w C:\Program Files\ICEOWS
2008-03-09 17:14 --------- d-----w C:\Program Files\NCH Swift Sound
2008-03-09 17:11 --------- d-----w C:\Users\Mom\AppData\Roaming\NCH Swift Sound
2008-03-09 01:45 21,764 ----a-w C:\Windows\System32\CoreAAC-uninstall.exe
2008-03-05 13:55 --------- d-----w C:\Program Files\GIMP-2.0
2008-03-05 12:29 --------- d---a-w C:\Users\Calvin\AppData\Roaming\InfraRecorder
2008-03-04 04:51 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-03 16:25 --------- d-----w C:\Program Files\Avast4
2008-03-03 14:42 --------- d-----w C:\Users\Calvin\AppData\Roaming\NCH Swift Sound
2008-03-03 14:42 --------- d-----w C:\Program Files\Common Files\McAfee
2008-03-03 14:41 --------- d-----w C:\Program Files\McAfee.com
2008-03-01 08:15 --------- d-----w C:\Program Files\CCleaner
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-27 04:12 --------- d-----w C:\Program Files\Dell Photo AIO Printer 966
2008-02-25 07:32 --------- d---a-w C:\Users\Calvin\AppData\Roaming\ErrorSmart
2008-02-25 07:24 --------- d-----w C:\Program Files\Eusing Free Registry Cleaner
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
2008-02-13 09:39 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-13 09:36 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-13 09:36 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-13 09:35 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 09:35 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 09:35 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-13 09:35 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-13 09:35 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-13 09:35 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-13 09:35 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 09:35 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 09:35 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-13 09:35 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-01-29 19:02 107,368 ----a-w C:\Windows\System32\GEARAspi.dll
2008-01-25 11:46 2,158,592 ----a-w C:\Windows\System32\RtkAPO.dll
2007-11-04 16:32 374 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb6334.dat
2007-11-04 14:50 555 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb8467.dat
2007-11-04 14:50 18,432 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb41.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89CBB8EA-FA02-4f61-B997-0247E69F002B}]
C:\Program Files\QdrDrive\QdrDrive15.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 05:35 125440]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-08 18:56 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 19:56 202544]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 05:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-05 11:57 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 07:22 4907008 C:\Windows\RtHDVCpl.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 09:37 81920]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 09:22 221184]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 19:57 16384]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 03:20 17920]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-17 09:07 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-17 09:07 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-17 09:07 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"dlcqmon.exe"="C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 08:47 292080]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 966\memcard.exe" [2007-06-29 08:48 304368]
"DLCQCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-15 22:31 106496]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 18:30 152144]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Dell DataSafe Scheduler"="C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C40A1CDE-3524-47EB-AB86-D043632CF06D}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{95A5E1FA-64AB-4ADB-AC4D-3DF2E0B735B6}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9164ED87-D1FE-4206-8496-29DEC6BBB6D0}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{204B31F1-64E0-4F04-B55D-73DE3A458B3F}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{189B5808-CF71-49AB-94CA-02B985EA3914}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{E162012F-98CF-4888-8A39-00328A767F10}C:\\program files\\nexon\\maplestory\\maplestory.exe"= UDP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{2FB30AAD-97FB-4027-8C8D-3FA7FDCF7BFE}C:\\program files\\nexon\\maplestory\\maplestory.exe"= TCP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{A0186F92-7442-4DC0-9CDF-695C1370EE4F}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= UDP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"UDP Query User{FCD1575D-BBD4-4794-AD79-F7C3406AE999}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= TCP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"TCP Query User{FF2B4B4D-1D13-48E6-8991-58A7FA801092}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= UDP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"UDP Query User{0B2E0060-86A4-484A-AB2C-D90157F44379}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= TCP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"TCP Query User{4E10DA99-3C04-4667-9F89-F36A44B45368}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= UDP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"UDP Query User{79088905-9F9D-4D68-9C4F-512196042A94}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= TCP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"TCP Query User{C5CBBF51-2752-40A6-A2C0-DC8A40B3B8F6}C:\\users\\calvin\\saved games\\nexon\\newpatcher.exe"= UDP:C:\users\calvin\saved games\nexon\newpatcher.exe:newpatcher.exe
"UDP Query User{BFE9CE8F-1C04-4B88-8B32-CAD967AF13DA}C:\\users\\calvin\\saved games\\nexon\\newpatcher.exe"= TCP:C:\users\calvin\saved games\nexon\newpatcher.exe:newpatcher.exe
"TCP Query User{4513D3DC-A943-4252-BE51-253D2AEA4C5F}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= UDP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"UDP Query User{D4241B12-00EC-4E4D-A39C-7C2807C78F17}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= TCP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"TCP Query User{871E1A48-AEBC-4085-BAED-C787EC6E21F1}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= UDP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"UDP Query User{326FF41C-497D-4D03-8513-22EBAC3AC34A}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= TCP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"TCP Query User{37A6A56D-37BC-40E8-9018-8069A4C66930}C:\\program files\\nexon\\maplestory\\maplestory.exe"= UDP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{A5CF2920-5E05-4607-BCEE-DA15A6B8B0A0}C:\\program files\\nexon\\maplestory\\maplestory.exe"= TCP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{82CCA1D9-95CC-4545-8AE2-8C097F9A4A13}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= UDP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"UDP Query User{2DFC44B5-C6FC-4455-9F08-9713F4536A64}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= TCP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"TCP Query User{3FE2B734-5BFA-4A80-84A8-87DC826F8C00}C:\\windows\\explorer.exe"= UDP:C:\windows\explorer.exe:Windows Explorer
"UDP Query User{5FD30CFD-6BAB-4702-9497-098A7B9A67B4}C:\\windows\\explorer.exe"= TCP:C:\windows\explorer.exe:Windows Explorer
"{400D87FB-D104-4A48-8208-178B985E4A11}"= UDP:C:\Windows\System32\rlvknlg.exe:rlvknlg.exe
"{EC8BCD7F-E649-4D37-A950-57E4B152804C}"= TCP:C:\Windows\System32\rlvknlg.exe:rlvknlg.exe
"{ECEF8CF6-AFE4-4A65-A2EF-8691D9A93C3E}"= UDP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{79C9CF6E-0E9A-41AB-861D-8EAE4CF907B2}"= TCP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"TCP Query User{489E40BC-53D2-44A4-A423-82B499B8D9BB}C:\\nexon\\maplestory\\maplestory.exe"= UDP:C:\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{0B733464-F515-4AA6-8220-F374B7E1341C}C:\\nexon\\maplestory\\maplestory.exe"= TCP:C:\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{80CCF7DE-E26B-40A8-836A-638BA1A87700}C:\\nexon\\maplestory\\maplestory.exe"= UDP:C:\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{71B875FE-9E27-418C-A965-496F8303828E}C:\\nexon\\maplestory\\maplestory.exe"= TCP:C:\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{D3C1ECFA-5DAD-42A3-8DAA-1896FE6B3BEA}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{E2A310D1-7EB4-4C86-94ED-A1764FE80CA3}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"{24BECBA1-8C8C-4B02-9916-4EEB02766C48}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{39FBCFD1-2DF2-4251-AF7F-3C3685B06BB7}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{34A08745-C53B-4350-BBF6-B3E8C45B0762}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe:
"UDP Query User{4FA8BA5C-B3B3-4BB2-B2CE-DAED6CF66DFD}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe:
"TCP Query User{A3D3605E-AF3F-46B9-9FDE-230A280E9BFF}C:\\program files\\bitlord\\bitlord.exe"= UDP:C:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{9C1B00E3-FA2A-420B-84D1-86DAE89A54E6}C:\\program files\\bitlord\\bitlord.exe"= TCP:C:\program files\bitlord\bitlord.exe:BitLord
"{341CEB89-AAA7-452B-A8EB-87FBD4C00165}"= UDP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{C4613266-71ED-4679-8A58-AB4071F27743}"= TCP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{2F9D8050-BF84-4A47-B80A-5A51F24B62A2}"= UDP:C:\Nexon\KartRider\KartRider.exe:KartRider
"{6CEB6678-3F6B-49DA-A194-2CAD4CC4998E}"= TCP:C:\Nexon\KartRider\KartRider.exe:KartRider
"{CB551BCF-FF61-435D-A80D-803693620C35}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{BBD75391-A0DC-47C2-9821-47E61C7E212E}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{0AA4CB1A-C026-4777-AB0D-26B0E8C4F83E}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{F12EB92A-1930-47BF-A3FD-728C657F1501}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{D4C3A691-D7F9-44A7-8EFD-B572AA6E55BD}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{E91FAA2D-12B0-43F8-B2DC-D06E76678598}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{916FABEE-914F-4826-B5B6-1F8593C95026}"= UDP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{52987BB2-9EE3-490F-905B-6245E9C27E94}"= TCP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"TCP Query User{2403A6DE-64D6-49C2-80EE-2D943E9CF91F}C:\\program files\\nexon\\maplestory\\gglessv51.exe"= UDP:C:\program files\nexon\maplestory\gglessv51.exe:MapleStory
"UDP Query User{D758F7CB-2751-4782-913A-F24C56E7ABD7}C:\\program files\\nexon\\maplestory\\gglessv51.exe"= TCP:C:\program files\nexon\maplestory\gglessv51.exe:MapleStory
"{5FE6955F-A5A9-4AAC-B7F5-7417FD787A4D}"= UDP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{A5A26F7F-557D-4D8C-8F09-CCA1084FC6D8}"= TCP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{8DB4D979-8B52-45D7-9B71-D00095952AF3}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{CD5E6279-511E-4EFF-A1DD-C2ABE970394B}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{57D1B8F0-DC42-498A-AF6A-D23054A5340E}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{28A1A368-8650-4792-9A26-66373E947820}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{A64B97B6-82CE-4781-B074-0FCDB62DEF67}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{7933A23F-CCC4-43AC-8854-891062504CD7}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"TCP Query User{3094D4F0-4A74-43D8-ADF8-385FDCA2125F}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{60FEC39C-576F-4CDB-8894-596E013E17D4}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"{D04AA1E0-2354-47A4-B03E-34F8302D4128}"= UDP:C:\Program Files\Grisoft\AVG7\avgcc.exe:AVG Control Center
"{DC2D4B90-FE0D-4508-B2AD-7FCD89315EB7}"= TCP:C:\Program Files\Grisoft\AVG7\avgcc.exe:AVG Control Center
"{60ED4348-1C81-48CC-86E6-9E278D53F6AE}"= UDP:C:\Program Files\Grisoft\AVG7\avgw.exe:AVG Test Center
"{CE4889C6-655B-41E5-9634-A9D4F1D861DF}"= TCP:C:\Program Files\Grisoft\AVG7\avgw.exe:AVG Test Center
"{E7093309-45D0-4BDF-AB60-345CD913DD04}"= UDP:C:\Program Files\Grisoft\AVG7\avgvv.exe:AVG Virus Vault
"{08FA98A6-AD7B-4967-8CC5-1725C7A60C25}"= TCP:C:\Program Files\Grisoft\AVG7\avgvv.exe:AVG Virus Vault
"{77A37B42-5889-4A26-9C5B-D8495F8BB946}"= UDP:C:\Program Files\Avast4\ashAvast.exe:avast! Antivirus
"{3E72381B-CED5-431E-803F-43BB4EC16E40}"= TCP:C:\Program Files\Avast4\ashAvast.exe:avast! Antivirus
"{F493B459-7CCA-4DDD-9A94-BD312D30BA98}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{55C74632-22F9-4705-AB7B-2B112956FA2B}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{ED28BE93-1FAA-4D8C-A7D1-0257C567F0DD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{305C2301-1CC4-4397-93CE-DC6BDF9963D5}C:\\program files\\nexon\\maplestory\\ggless52.exe"= UDP:C:\program files\nexon\maplestory\ggless52.exe:MapleStory
"UDP Query User{308608BB-9CB5-4086-B67C-C9BC9AAEB86F}C:\\program files\\nexon\\maplestory\\ggless52.exe"= TCP:C:\program files\nexon\maplestory\ggless52.exe:MapleStory
"{D2745287-EEDB-4836-AA2F-CCBE52746944}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{9242175C-A073-468A-959F-1A20FD1F204E}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{435E572C-6B71-4895-AF14-A2319EA2A03C}C:\\program files\\orbitdownloader\\orbitnet.exe"= UDP:C:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader
"UDP Query User{E37796CC-BDBE-4B98-BA19-7623E2E52319}C:\\program files\\orbitdownloader\\orbitnet.exe"= TCP:C:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]
R2 AERTFilters;Andrea RT Filters Service;C:\Windows\system32\AERTSrv.exe [2007-12-05 06:17]
R2 dlcq_device;dlcq_device;C:\Windows\system32\dlcqcoms.exe [2006-12-12 01:22]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-10-09 19:56]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 00:30]
S3 NAL;Nal Service ;C:\Windows\system32\Drivers\iqvw32.sys [2007-03-09 15:04]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 00:36]
S3 tapvpn;TAP VPN Adapter;C:\Windows\system32\DRIVERS\tapvpn.sys [2008-03-12 19:38]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\AutoRun\command - K:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d670c13-8f53-11dc-bc1e-001aa090d113}]
\shell\AutoRun\command - K:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68df2eb3-5b9f-11dc-aed8-806e6f6e6963}]
\shell\AutoRun\command - E:\Setup.EXE

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-03-03 16:25:30 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-03-03 16:25:30 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-04-22 03:00:02 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Calvin.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-04-25 12:15:02 C:\Windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-04-25 12:06:21 C:\Windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-25 05:15:38
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-25 5:16:43
ComboFix-quarantined-files.txt 2008-04-25 12:16:32

The system cannot find message text for message number 0x2379 in the message file for Application.
The system cannot find message text for message number 0x2379 in the message file for Application.

314 --- E O F --- 2008-04-24 22:23:36
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: SOS... What's wrong?

Postby Gecko » Fri Apr 25, 2008 6:27 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: SOS... What's wrong?

Postby cc481613 » Sat Apr 26, 2008 4:27 pm

ComboFix 08-04-22.5 - Calvin 2008-04-26 8:19:58.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2157 [GMT -7:00]
Running from: C:\Users\Calvin\Desktop\ComboFix.exe
Command switches used :: C:\Users\Calvin\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


FILE ::
C:\Windows\four444444.exe
C:\Windows\LOT66225.exe
C:\Windows\one11111.exe
C:\Windows\System32\{0150f981-1470-f2da-2b06-d4309fa24d9d}.dll-uninst.exe
C:\Windows\two222222.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\VnrPack
C:\Program Files\VnrPack\dicts.gz
C:\Program Files\VnrPack\trgts.gz
C:\Program Files\VnrPack\VnrPack15.exe
C:\Windows\four444444.exe
C:\Windows\LOT66225.exe
C:\Windows\one11111.exe
C:\Windows\System32\{0150f981-1470-f2da-2b06-d4309fa24d9d}.dll-uninst.exe
C:\Windows\two222222.exe

.
((((((((((((((((((((((((( Files Created from 2008-03-26 to 2008-04-26 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-26 14:38 --------- d-----w C:\Program Files\McAfee
2008-04-26 14:37 --------- d-----w C:\Program Files\Dl_cats
2008-04-25 12:32 --------- d-----w C:\Program Files\Safari
2008-04-25 12:31 --------- d-----w C:\Program Files\Bonjour
2008-04-25 12:15 --------- d-----w C:\Program Files\Reference Assemblies
2008-04-25 03:11 --------- d---a-w C:\Users\Calvin\AppData\Roaming\LimeWire
2008-04-24 01:16 --------- d-----w C:\Program Files\Nexon
2008-04-22 23:22 --------- d-----w C:\Program Files\7-Zip
2008-04-22 07:52 --------- d-----w C:\Program Files\Actual Drawing
2008-04-22 07:48 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Web Page Maker V2
2008-04-22 07:48 --------- d-----w C:\Program Files\Yahoo!
2008-04-22 07:43 --------- d-----w C:\Program Files\Game Optimizer Pro
2008-04-22 06:18 --------- d-----w C:\Program Files\i.Hex
2008-04-22 03:38 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-04-22 03:38 --------- d-----w C:\Program Files\Windows Live Favorites
2008-04-22 03:37 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-04-22 03:20 --------- d-----w C:\Program Files\Apple Software Update
2008-04-21 00:38 --------- d-----w C:\Program Files\LeechGet 2007
2008-04-20 17:09 --------- d-----w C:\Program Files\Windows Live
2008-04-20 17:02 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Orbit
2008-04-16 05:57 --------- d-----w C:\Program Files\Cloudbrain
2008-04-16 04:19 --------- d-----w C:\Program Files\Macromedia
2008-04-16 04:19 --------- d-----w C:\Program Files\Common Files\Macromedia Shared
2008-04-16 04:15 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-04-15 03:10 --------- d-----w C:\Program Files\LimeWire
2008-04-15 01:39 --------- d-----w C:\Program Files\Java
2008-04-13 17:07 --------- d-----w C:\Program Files\Virtual Mechanics
2008-04-11 08:12 --------- d-----w C:\Program Files\UFile 2007
2008-04-09 02:06 --------- d-----w C:\Program Files\Windows Mail
2008-04-09 00:08 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-03 05:31 --------- d-----w C:\Program Files\iTunes
2008-04-03 05:31 --------- d-----w C:\Program Files\iPod
2008-04-03 05:30 --------- d-----w C:\Program Files\QuickTime
2008-03-31 18:05 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-31 16:07 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Apple Computer
2008-03-31 05:01 691,545 ----a-w C:\Windows\unins000.exe
2008-03-27 15:24 --------- d---a-w C:\Users\Calvin\AppData\Roaming\gtk-2.0
2008-03-27 02:13 --------- d---a-w C:\Users\Calvin\AppData\Roaming\ZoomBrowser EX
2008-03-27 02:12 --------- d---a-w C:\Users\Calvin\AppData\Roaming\CameraWindowDC
2008-03-26 15:55 --------- d---a-w C:\Users\Calvin\AppData\Roaming\SystemRequirementsLab
2008-03-26 15:55 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-03-15 17:30 --------- d---a-w C:\Users\Calvin\AppData\Roaming\Canon
2008-03-15 17:24 --------- d---a-w C:\Users\Calvin\AppData\Roaming\CANON INC
2008-03-14 05:18 --------- d-----w C:\Program Files\DVDVideoSoft
2008-03-13 04:55 --------- d-----w C:\Program Files\Canon
2008-03-13 04:52 --------- d-----w C:\Program Files\Common Files\Canon
2008-03-13 02:38 27,136 ----a-w C:\Windows\system32\drivers\tapvpn.sys
2008-03-09 17:23 --------- d-----w C:\Program Files\ICEOWS
2008-03-09 17:14 --------- d-----w C:\Program Files\NCH Swift Sound
2008-03-09 17:11 --------- d-----w C:\Users\Mom\AppData\Roaming\NCH Swift Sound
2008-03-09 01:45 21,764 ----a-w C:\Windows\System32\CoreAAC-uninstall.exe
2008-03-05 13:55 --------- d-----w C:\Program Files\GIMP-2.0
2008-03-05 12:29 --------- d---a-w C:\Users\Calvin\AppData\Roaming\InfraRecorder
2008-03-04 04:51 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-03 16:25 --------- d-----w C:\Program Files\Avast4
2008-03-03 14:42 --------- d-----w C:\Users\Calvin\AppData\Roaming\NCH Swift Sound
2008-03-03 14:42 --------- d-----w C:\Program Files\Common Files\McAfee
2008-03-03 14:41 --------- d-----w C:\Program Files\McAfee.com
2008-03-01 08:15 --------- d-----w C:\Program Files\CCleaner
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-27 04:12 --------- d-----w C:\Program Files\Dell Photo AIO Printer 966
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
2008-02-13 09:39 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-13 09:36 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-13 09:36 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-13 09:35 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 09:35 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 09:35 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-13 09:35 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-13 09:35 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-13 09:35 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-13 09:35 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 09:35 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 09:35 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-13 09:35 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-01-29 19:02 107,368 ----a-w C:\Windows\System32\GEARAspi.dll
2007-11-04 16:32 374 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb6334.dat
2007-11-04 14:50 555 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb8467.dat
2007-11-04 14:50 18,432 ----a-w C:\Users\Calvin\AppData\Roaming\internaldb41.dat
2007-09-22 16:22 174 --sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((( snapshot@2008-04-25_ 5.16.07.91 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-25 12:01:36 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-26 14:36:58 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-04-22 03:23:37 307,200 ----a-r C:\Windows\Installer\{40589552-3892-409E-B92C-9F5032A4B2F0}\SafariIco.exe
+ 2008-04-25 12:32:49 307,200 ----a-r C:\Windows\Installer\{40589552-3892-409E-B92C-9F5032A4B2F0}\SafariIco.exe
+ 2008-04-25 12:31:56 86,016 ----a-r C:\Windows\Installer\{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}\PrntWzrdIco.exe
- 2008-04-25 12:01:37 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-04-26 14:36:59 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-04-25 12:01:37 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-04-26 14:36:59 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-04-25 12:06:59 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-04-26 14:52:03 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-04-25 12:03:55 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-04-26 14:39:04 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-04-25 12:06:59 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-04-26 15:19:30 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-04-25 12:15:19 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-26 15:22:20 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-04-25 12:02:33 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-26 14:37:33 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-04-25 12:02:33 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-26 14:37:33 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-25 12:02:33 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-04-26 14:37:33 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-07-24 22:17:08 81,920 ----a-w C:\Windows\System32\dns-sd.exe
+ 2007-07-24 22:17:08 61,440 ----a-w C:\Windows\System32\dnssd.dll
+ 2007-07-24 22:17:08 65,536 ----a-w C:\Windows\System32\jdns_sd.dll
- 2008-04-25 12:03:33 16,766 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1790924192-2944971578-4197939686-1000_UserData.bin
+ 2008-04-26 14:39:18 16,766 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1790924192-2944971578-4197939686-1000_UserData.bin
- 2008-04-23 16:44:46 6,490 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1790924192-2944971578-4197939686-1001_UserData.bin
+ 2008-04-26 01:07:03 6,566 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1790924192-2944971578-4197939686-1001_UserData.bin
- 2008-04-25 12:03:33 72,306 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-26 14:39:17 72,456 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-04-25 10:46:53 64,224 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-26 14:39:07 64,240 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 05:35 125440]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-08 18:56 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 19:56 202544]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 05:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-05 11:57 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 07:22 4907008 C:\Windows\RtHDVCpl.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 09:37 81920]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 09:22 221184]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 19:57 16384]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 03:20 17920]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-17 09:07 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-17 09:07 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-17 09:07 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"dlcqmon.exe"="C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe" [2007-06-29 08:47 292080]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 966\memcard.exe" [2007-06-29 08:48 304368]
"DLCQCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-15 22:31 106496]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 18:30 152144]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Dell DataSafe Scheduler"="C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C40A1CDE-3524-47EB-AB86-D043632CF06D}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{95A5E1FA-64AB-4ADB-AC4D-3DF2E0B735B6}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9164ED87-D1FE-4206-8496-29DEC6BBB6D0}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{204B31F1-64E0-4F04-B55D-73DE3A458B3F}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{189B5808-CF71-49AB-94CA-02B985EA3914}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{E162012F-98CF-4888-8A39-00328A767F10}C:\\program files\\nexon\\maplestory\\maplestory.exe"= UDP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{2FB30AAD-97FB-4027-8C8D-3FA7FDCF7BFE}C:\\program files\\nexon\\maplestory\\maplestory.exe"= TCP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{A0186F92-7442-4DC0-9CDF-695C1370EE4F}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= UDP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"UDP Query User{FCD1575D-BBD4-4794-AD79-F7C3406AE999}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= TCP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"TCP Query User{FF2B4B4D-1D13-48E6-8991-58A7FA801092}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= UDP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"UDP Query User{0B2E0060-86A4-484A-AB2C-D90157F44379}C:\\users\\calvin\\saved games\\nexon\\maplestory.exe"= TCP:C:\users\calvin\saved games\nexon\maplestory.exe:maplestory.exe
"TCP Query User{4E10DA99-3C04-4667-9F89-F36A44B45368}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= UDP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"UDP Query User{79088905-9F9D-4D68-9C4F-512196042A94}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= TCP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"TCP Query User{C5CBBF51-2752-40A6-A2C0-DC8A40B3B8F6}C:\\users\\calvin\\saved games\\nexon\\newpatcher.exe"= UDP:C:\users\calvin\saved games\nexon\newpatcher.exe:newpatcher.exe
"UDP Query User{BFE9CE8F-1C04-4B88-8B32-CAD967AF13DA}C:\\users\\calvin\\saved games\\nexon\\newpatcher.exe"= TCP:C:\users\calvin\saved games\nexon\newpatcher.exe:newpatcher.exe
"TCP Query User{4513D3DC-A943-4252-BE51-253D2AEA4C5F}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= UDP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"UDP Query User{D4241B12-00EC-4E4D-A39C-7C2807C78F17}C:\\users\\calvin\\saved games\\nexon\\patcher.exe"= TCP:C:\users\calvin\saved games\nexon\patcher.exe:patcher.exe
"TCP Query User{871E1A48-AEBC-4085-BAED-C787EC6E21F1}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= UDP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"UDP Query User{326FF41C-497D-4D03-8513-22EBAC3AC34A}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= TCP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"TCP Query User{37A6A56D-37BC-40E8-9018-8069A4C66930}C:\\program files\\nexon\\maplestory\\maplestory.exe"= UDP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{A5CF2920-5E05-4607-BCEE-DA15A6B8B0A0}C:\\program files\\nexon\\maplestory\\maplestory.exe"= TCP:C:\program files\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{82CCA1D9-95CC-4545-8AE2-8C097F9A4A13}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= UDP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"UDP Query User{2DFC44B5-C6FC-4455-9F08-9713F4536A64}C:\\users\\calvin\\appdata\\roaming\\u3\\0000187b85732e4e\\0de4f643-c398-46ec-9339-2362f2311932\\exec\\skype.exe"= TCP:C:\users\calvin\appdata\roaming\u3\0000187b85732e4e\0de4f643-c398-46ec-9339-2362f2311932\exec\skype.exe:skype.exe
"TCP Query User{3FE2B734-5BFA-4A80-84A8-87DC826F8C00}C:\\windows\\explorer.exe"= UDP:C:\windows\explorer.exe:Windows Explorer
"UDP Query User{5FD30CFD-6BAB-4702-9497-098A7B9A67B4}C:\\windows\\explorer.exe"= TCP:C:\windows\explorer.exe:Windows Explorer
"{400D87FB-D104-4A48-8208-178B985E4A11}"= UDP:C:\Windows\System32\rlvknlg.exe:rlvknlg.exe
"{EC8BCD7F-E649-4D37-A950-57E4B152804C}"= TCP:C:\Windows\System32\rlvknlg.exe:rlvknlg.exe
"{ECEF8CF6-AFE4-4A65-A2EF-8691D9A93C3E}"= UDP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{79C9CF6E-0E9A-41AB-861D-8EAE4CF907B2}"= TCP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"TCP Query User{489E40BC-53D2-44A4-A423-82B499B8D9BB}C:\\nexon\\maplestory\\maplestory.exe"= UDP:C:\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{0B733464-F515-4AA6-8220-F374B7E1341C}C:\\nexon\\maplestory\\maplestory.exe"= TCP:C:\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{80CCF7DE-E26B-40A8-836A-638BA1A87700}C:\\nexon\\maplestory\\maplestory.exe"= UDP:C:\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{71B875FE-9E27-418C-A965-496F8303828E}C:\\nexon\\maplestory\\maplestory.exe"= TCP:C:\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{D3C1ECFA-5DAD-42A3-8DAA-1896FE6B3BEA}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{E2A310D1-7EB4-4C86-94ED-A1764FE80CA3}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"{24BECBA1-8C8C-4B02-9916-4EEB02766C48}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{39FBCFD1-2DF2-4251-AF7F-3C3685B06BB7}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{34A08745-C53B-4350-BBF6-B3E8C45B0762}C:\\program files\\bitlord2\\bitlord.exe"= UDP:C:\program files\bitlord2\bitlord.exe:
"UDP Query User{4FA8BA5C-B3B3-4BB2-B2CE-DAED6CF66DFD}C:\\program files\\bitlord2\\bitlord.exe"= TCP:C:\program files\bitlord2\bitlord.exe:
"TCP Query User{A3D3605E-AF3F-46B9-9FDE-230A280E9BFF}C:\\program files\\bitlord\\bitlord.exe"= UDP:C:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{9C1B00E3-FA2A-420B-84D1-86DAE89A54E6}C:\\program files\\bitlord\\bitlord.exe"= TCP:C:\program files\bitlord\bitlord.exe:BitLord
"{341CEB89-AAA7-452B-A8EB-87FBD4C00165}"= UDP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{C4613266-71ED-4679-8A58-AB4071F27743}"= TCP:C:\ProgramData\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{2F9D8050-BF84-4A47-B80A-5A51F24B62A2}"= UDP:C:\Nexon\KartRider\KartRider.exe:KartRider
"{6CEB6678-3F6B-49DA-A194-2CAD4CC4998E}"= TCP:C:\Nexon\KartRider\KartRider.exe:KartRider
"{CB551BCF-FF61-435D-A80D-803693620C35}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{BBD75391-A0DC-47C2-9821-47E61C7E212E}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{0AA4CB1A-C026-4777-AB0D-26B0E8C4F83E}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{F12EB92A-1930-47BF-A3FD-728C657F1501}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{D4C3A691-D7F9-44A7-8EFD-B572AA6E55BD}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{E91FAA2D-12B0-43F8-B2DC-D06E76678598}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{916FABEE-914F-4826-B5B6-1F8593C95026}"= UDP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{52987BB2-9EE3-490F-905B-6245E9C27E94}"= TCP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"TCP Query User{2403A6DE-64D6-49C2-80EE-2D943E9CF91F}C:\\program files\\nexon\\maplestory\\gglessv51.exe"= UDP:C:\program files\nexon\maplestory\gglessv51.exe:MapleStory
"UDP Query User{D758F7CB-2751-4782-913A-F24C56E7ABD7}C:\\program files\\nexon\\maplestory\\gglessv51.exe"= TCP:C:\program files\nexon\maplestory\gglessv51.exe:MapleStory
"{5FE6955F-A5A9-4AAC-B7F5-7417FD787A4D}"= UDP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{A5A26F7F-557D-4D8C-8F09-CCA1084FC6D8}"= TCP:C:\Windows\System32\dlcqcoms.exe:Dell Communications System
"{8DB4D979-8B52-45D7-9B71-D00095952AF3}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{CD5E6279-511E-4EFF-A1DD-C2ABE970394B}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe:Device Monitor
"{57D1B8F0-DC42-498A-AF6A-D23054A5340E}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{28A1A368-8650-4792-9A26-66373E947820}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\DLCQaiox.exe:All In One Center
"{A64B97B6-82CE-4781-B074-0FCDB62DEF67}"= UDP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"{7933A23F-CCC4-43AC-8854-891062504CD7}"= TCP:C:\Program Files\Dell Photo AIO Printer 966\memcard.exe:Memory Card Manager
"TCP Query User{3094D4F0-4A74-43D8-ADF8-385FDCA2125F}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{60FEC39C-576F-4CDB-8894-596E013E17D4}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"{D04AA1E0-2354-47A4-B03E-34F8302D4128}"= UDP:C:\Program Files\Grisoft\AVG7\avgcc.exe:AVG Control Center
"{DC2D4B90-FE0D-4508-B2AD-7FCD89315EB7}"= TCP:C:\Program Files\Grisoft\AVG7\avgcc.exe:AVG Control Center
"{60ED4348-1C81-48CC-86E6-9E278D53F6AE}"= UDP:C:\Program Files\Grisoft\AVG7\avgw.exe:AVG Test Center
"{CE4889C6-655B-41E5-9634-A9D4F1D861DF}"= TCP:C:\Program Files\Grisoft\AVG7\avgw.exe:AVG Test Center
"{E7093309-45D0-4BDF-AB60-345CD913DD04}"= UDP:C:\Program Files\Grisoft\AVG7\avgvv.exe:AVG Virus Vault
"{08FA98A6-AD7B-4967-8CC5-1725C7A60C25}"= TCP:C:\Program Files\Grisoft\AVG7\avgvv.exe:AVG Virus Vault
"{77A37B42-5889-4A26-9C5B-D8495F8BB946}"= UDP:C:\Program Files\Avast4\ashAvast.exe:avast! Antivirus
"{3E72381B-CED5-431E-803F-43BB4EC16E40}"= TCP:C:\Program Files\Avast4\ashAvast.exe:avast! Antivirus
"{F493B459-7CCA-4DDD-9A94-BD312D30BA98}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{55C74632-22F9-4705-AB7B-2B112956FA2B}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{ED28BE93-1FAA-4D8C-A7D1-0257C567F0DD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{305C2301-1CC4-4397-93CE-DC6BDF9963D5}C:\\program files\\nexon\\maplestory\\ggless52.exe"= UDP:C:\program files\nexon\maplestory\ggless52.exe:MapleStory
"UDP Query User{308608BB-9CB5-4086-B67C-C9BC9AAEB86F}C:\\program files\\nexon\\maplestory\\ggless52.exe"= TCP:C:\program files\nexon\maplestory\ggless52.exe:MapleStory
"{D2745287-EEDB-4836-AA2F-CCBE52746944}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{9242175C-A073-468A-959F-1A20FD1F204E}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{435E572C-6B71-4895-AF14-A2319EA2A03C}C:\\program files\\orbitdownloader\\orbitnet.exe"= UDP:C:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader
"UDP Query User{E37796CC-BDBE-4B98-BA19-7623E2E52319}C:\\program files\\orbitdownloader\\orbitnet.exe"= TCP:C:\program files\orbitdownloader\orbitnet.exe:P2P service of Orbit Downloader
"{CAE85B28-FC9A-4AC2-860E-99EFB98BEC6B}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{07C4E20F-9055-41F6-99B7-62625B4681FC}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]
R2 AERTFilters;Andrea RT Filters Service;C:\Windows\system32\AERTSrv.exe [2007-12-05 06:17]
R2 dlcq_device;dlcq_device;C:\Windows\system32\dlcqcoms.exe [2006-12-12 01:22]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-10-09 19:56]
S2 0000291209220743mcinstcleanup;McAfee Application Installer Cleanup (0000291209220743);C:\Windows\TEMP\000029~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 00:30]
S3 NAL;Nal Service ;C:\Windows\system32\Drivers\iqvw32.sys [2007-03-09 15:04]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 00:36]
S3 tapvpn;TAP VPN Adapter;C:\Windows\system32\DRIVERS\tapvpn.sys [2008-03-12 19:38]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\AutoRun\command - K:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3d670c13-8f53-11dc-bc1e-001aa090d113}]
\shell\AutoRun\command - K:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68df2eb3-5b9f-11dc-aed8-806e6f6e6963}]
\shell\AutoRun\command - E:\Setup.EXE

.
Contents of the 'Scheduled Tasks' folder
"2008-03-03 16:25:30 C:\Windows\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-03-03 16:25:30 C:\Windows\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-04-22 03:00:02 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Calvin.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-04-26 01:05:27 C:\Windows\Tasks\User_Feed_Synchronization-{0FC40BB8-6DE1-4C3A-BFFC-6DC12BF1D332}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-04-26 14:38:46 C:\Windows\Tasks\User_Feed_Synchronization-{893D5EE2-FA10-4615-B039-239B29105AB9}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-26 08:22:34
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-26 8:23:25
ComboFix-quarantined-files.txt 2008-04-26 15:23:16
ComboFix2.txt 2008-04-25 12:16:47

The system cannot find message text for message number 0x2379 in the message file for Application.
The system cannot find message text for message number 0x2379 in the message file for Application.

349 --- E O F --- 2008-04-24 22:23:36



Here it is :classic:
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: SOS... What's wrong?

Postby Gecko » Sun Apr 27, 2008 11:55 am

cc481613,
Things are looking better
Can you please post a new Hijackthis log.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: SOS... What's wrong?

Postby cc481613 » Sun Apr 27, 2008 3:52 pm

cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top

Re: SOS... What's wrong?

Postby Gecko » Mon Apr 28, 2008 11:26 am

cc481613,

Your log is clean :)
How is it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: SOS... What's wrong?

Postby cc481613 » Tue Apr 29, 2008 3:52 am

It's still somewhat slower than before... but hey, at least the baddies are gone!
cc481613
Geek
Geek
 
Posts: 60
Joined: Tue Jan 08, 2008 9:21 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron