We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Web Hijack Need Help

13»

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    95 ~ ive no clue what your saying to me at all

    Ive gone through your combifix log. Ive found 'some' items which need removing and even highlighted them in red and given you complete instructions as to HOW to remove them
    :idea:
  • i no and i have done that what im trying to say is i can send all of the log so what bit do u want
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Then SPLIT IT INTO SECTIONS
    :idea:
  • Fix 09-12-06.A3 - Curtis 26/11/2009 17:40.2.2 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1466 [GMT 0:00]
    Running from: c:\documents and settings\Curtis\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Curtis\Desktop\CFScript.txt
    AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    * Resident AV is active

    FILE ::
    "c:\windows\Owakuteroyowu.bin"
    "c:\windows\system32\MFC71CHS.DLL"
    "c:\windows\system32\MFC71CHT.DLL"
    "c:\windows\system32\MFC71DEU.DLL"
    "c:\windows\system32\MFC71ENU.DLL"
    "c:\windows\system32\MFC71ESP.DLL"
    "c:\windows\system32\MFC71ITA.DLL"
    "c:\windows\system32\MFC71KOR.DLL"
    "c:\windows\Ukovuresiqa.dat"
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    c:\program files\Save Tube Video Company\SaveTubeVideo\MiNBho.dll
    c:\program files\Save Tube Video Company\SaveTubeVideo\SaVEtubevideo.dll
    c:\windows\Owakuteroyowu.bin
    c:\windows\system32\MFC71CHS.DLL
    c:\windows\system32\MFC71CHT.DLL
    c:\windows\system32\MFC71DEU.DLL
    c:\windows\system32\MFC71ENU.DLL
    c:\windows\system32\MFC71ESP.DLL
    c:\windows\system32\MFC71ITA.DLL
    c:\windows\system32\MFC71KOR.DLL
    c:\windows\Ukovuresiqa.dat
    .
    ((((((((((((((((((((((((( Files Created from 2009-10-26 to 2009-11-26 )))))))))))))))))))))))))))))))
    .
    2009-11-26 17:35 . 2009-11-26 17:32 389120 ----a-w- c:\windows\system32\CF32526.exe
    2009-11-26 17:00 . 2009-11-26 17:02
    d
    w- C:\sUBs
    2009-11-26 16:42 . 2009-11-26 16:42
    d
    w- c:\documents and settings\Curtis\Application Data\StarBurn
    2009-11-26 16:42 . 2009-11-26 16:42
    d
    w- c:\program files\Save Tube Video Company
    2009-11-26 16:41 . 2009-11-26 16:41 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
    2009-11-26 16:41 . 2009-03-02 14:00 95592 ----a-w- c:\windows\system32\drivers\StarPortLite.sys
    2009-11-26 16:11 . 2009-11-26 16:11
    d
    w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
    2009-11-25 22:57 . 2009-11-25 22:57
    d
    w- c:\program files\RocketDock
    2009-11-25 21:32 . 2009-11-25 21:32
    d
    w- c:\program files\CCleaner
    2009-11-25 21:30 . 2009-11-25 21:30
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\Threat Expert
    2009-11-25 17:58 . 2009-11-25 21:46
    d
    w- c:\program files\Malwarebytes' Anti-Malware
    2009-11-25 12:27 . 2009-11-25 12:27
    d
    w- c:\program files\Common Files\DivX Shared
    2009-11-25 12:22 . 2009-11-11 14:50 311296 ----a-w- c:\windows\system32\TubeFinder.exe
    2009-11-25 12:22 . 2009-06-19 18:51 9728 ----a-w- c:\windows\system32\PCCLPFR.DLL
    2009-11-25 12:22 . 2009-06-19 18:51 32768 ----a-w- c:\windows\system32\CMDLGFR.DLL
    2009-11-25 12:22 . 2009-06-19 18:51 141312 ----a-w- c:\windows\system32\MSCMCFR.DLL
    2009-11-25 12:22 . 2009-06-19 18:51 119568 ----a-w- c:\windows\system32\VB6FR.DLL
    2009-11-25 12:22 . 2009-06-19 18:51 101888 ----a-w- c:\windows\system32\VB6STKIT.DLL
    2009-11-25 12:22 . 2009-11-26 16:18
    d
    w- c:\documents and settings\Curtis\Application Data\FreeFLVConverter
    2009-11-25 12:22 . 2009-11-25 12:22
    d
    w- c:\program files\Free FLV Converter
    2009-11-25 11:53 . 2009-11-25 11:54
    d
    w- c:\documents and settings\Curtis\Application Data\Download Manager
    2009-11-24 12:31 . 2008-04-14 00:16 37888 -c--a-w- c:\windows\system32\dllcache\bthmodem.sys
    2009-11-24 12:31 . 2008-04-14 00:16 37888 ----a-w- c:\windows\system32\drivers\bthmodem.sys
    2009-11-23 23:54 . 2009-11-24 00:27
    d
    w- c:\program files\Browser Hijack Recover
    2009-11-23 23:28 . 2009-11-23 23:28
    d
    w- c:\documents and settings\All Users\Application Data\XoftSpySE
    2009-11-23 18:10 . 2009-11-02 20:42 195456
    w- c:\windows\system32\MpSigStub.exe
    2009-11-23 15:44 . 2009-11-26 16:26
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\Temp
    2009-11-21 22:45 . 2009-11-25 19:42
    d
    w- c:\program files\Secure PC Solutions
    2009-11-21 20:41 . 2009-11-21 20:41 1962544 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
    2009-11-21 20:41 . 2009-11-21 20:41
    d
    w- c:\program files\NOS
    2009-11-21 19:12 . 2009-11-21 19:12
    d
    w- c:\windows\system32\URTTEMP
    2009-11-21 19:11 . 2009-11-21 19:11
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\Identities
    2009-11-21 19:01 . 2009-11-21 19:01
    d
    w- c:\windows\system32\wbem\Repository
    2009-11-21 19:00 . 2009-11-21 19:00
    d
    w- c:\program files\LG PC Suite 2
    2009-11-21 18:33 . 2009-11-25 22:53
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\Google
    2009-11-21 18:32 . 2009-11-21 22:42
    d
    w- c:\program files\Google
    2009-11-21 08:22 . 2009-11-21 08:22
    d
    w- c:\documents and settings\LocalService\Application Data\McAfee
    2009-11-20 19:16 . 2009-11-20 19:16
    d
    w- c:\program files\Trend Micro
    2009-11-19 17:18 . 2009-11-20 18:10
    d
    w- C:\Downloads
    2009-11-19 17:17 . 2009-11-19 17:17 1032192 ----a-w- c:\documents and settings\Curtis\Application Data\Mozilla\Firefox\Profiles\8qmlj9hg.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}-trash\components\IBitCometExtension.dll
    2009-11-19 17:17 . 2009-11-20 19:32
    d
    w- c:\program files\BitComet
    2009-11-19 15:46 . 2009-11-19 15:46
    d
    w- c:\documents and settings\Curtis\Application Data\InfraRecorder
    2009-11-19 15:37 . 2009-11-19 15:37
    d
    w- c:\documents and settings\Curtis\Application Data\Ashampoo
    2009-11-19 15:36 . 2009-11-19 15:36
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\ashampoo
    2009-11-19 15:36 . 2009-11-19 15:36
    d
    w- c:\documents and settings\All Users\Application Data\ashampoo
    2009-11-19 15:28 . 2009-11-20 20:13
    d
    w- c:\program files\Spybot - Search & Destroy
    2009-11-19 15:28 . 2009-11-20 20:13
    d
    w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-11-19 14:34 . 2009-11-19 14:34
    d
    w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
    2009-11-18 23:50 . 2009-11-18 23:50 0 ----a-w- c:\windows\nsreg.dat
    2009-11-18 23:50 . 2009-11-18 23:50
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\Mozilla
    2009-11-18 16:00 . 2009-11-25 11:31
    d
    w- c:\program files\WinFF
    2009-11-18 11:09 . 2009-11-18 11:09
    d
    w- c:\documents and settings\Curtis\Application Data\Malwarebytes
    2009-11-18 11:08 . 2009-11-18 11:08
    d
    w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-11-17 20:48 . 2009-11-18 20:18
    d
    w- c:\program files\ffdshow
    2009-11-17 20:38 . 2009-11-17 20:38
    d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
    2009-11-17 19:20 . 2009-11-18 20:18
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\Spotify
    2009-11-17 19:20 . 2009-11-17 19:24
    d
    w- c:\documents and settings\Curtis\Application Data\Spotify
    2009-11-17 18:43 . 2009-11-17 18:43
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\Nero
    2009-11-17 11:07 . 2009-11-18 20:18
    d
    w- c:\program files\Windows Media Connect 2
    2009-11-13 19:47 . 2005-07-19 17:31 53248 ----a-r- c:\windows\system32\InstMed.exe
    2009-11-13 19:47 . 2005-05-27 09:36 372736 ----a-w- c:\windows\system32\LVUI2RC.dll
    2009-11-13 19:47 . 2005-05-27 09:31 22016 ----a-w- c:\windows\system32\drivers\LVUSBSta.sys
    2009-11-13 19:47 . 2005-05-27 09:29 204800 ----a-w- c:\windows\system32\LVUI2.dll
    2009-11-13 19:47 . 2004-02-14 10:53 110592 ----a-w- c:\windows\system32\lvcoinst.dll
    2009-11-13 19:47 . 2005-05-27 09:26 204800 ----a-w- c:\windows\system32\LVCodec2.dll
    2009-11-13 19:47 . 2004-02-14 10:55 471712 ----a-w- c:\windows\system32\drivers\lvcd.sys
    2009-11-12 19:32 . 2009-11-12 19:32
    d
    w- c:\documents and settings\Curtis\Application Data\DivX
    2009-11-10 15:33 . 2009-11-10 15:33
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\Rockstar Games
    2009-11-10 14:47 . 2009-11-10 14:47
    d
    w- C:\5c3fd0401f3efb8b31f504b9d4
    2009-11-10 14:14 . 2009-09-04 17:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
    2009-11-10 14:14 . 2009-09-04 17:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
    2009-11-10 13:59 . 2009-11-10 13:59
    d--h--r- c:\documents and settings\Curtis\Application Data\SecuROM
    2009-11-10 13:52 . 2008-05-30 14:19 507400 ----a-w- c:\windows\system32\XAudio2_1.dll
    2009-11-10 13:52 . 2008-05-30 14:18 238088 ----a-w- c:\windows\system32\xactengine3_1.dll
    2009-11-10 13:52 . 2008-05-30 14:17 65032 ----a-w- c:\windows\system32\XAPOFX1_0.dll
    2009-11-10 13:52 . 2008-05-30 14:17 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll
    2009-11-10 13:52 . 2008-05-30 14:11 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
    2009-11-10 13:52 . 2008-05-30 14:11 1491992 ----a-w- c:\windows\system32\D3DCompiler_38.dll
    2009-11-10 13:52 . 2008-05-30 14:11 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll
    2009-11-10 13:52 . 2008-03-05 16:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
    2009-11-10 13:52 . 2008-03-05 16:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll
    2009-11-10 13:52 . 2008-03-05 16:00 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll
    2009-11-10 13:50 . 2009-11-10 13:51
    d
    w- c:\windows\system32\drivers\umdf
    2009-11-10 13:49 . 2008-03-05 15:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
    2009-11-10 13:49 . 2008-03-05 15:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
    2009-11-10 13:49 . 2008-02-05 23:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
    2009-11-10 13:49 . 2007-04-04 18:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
    2009-11-10 13:10 . 2009-11-10 13:10
    d
    w- c:\program files\MSBuild
    2009-11-10 13:04 . 2009-11-10 14:49
    d
    w- c:\windows\system32\XPSViewer
    2009-11-10 13:03 . 2009-11-10 13:03
    d
    w- c:\program files\Reference Assemblies
    2009-11-10 13:03 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
    2009-11-10 13:03 . 2006-06-29 13:07 14048
    w- c:\windows\system32\spmsg2.dll
    2009-11-10 12:59 . 2009-11-10 13:05
    d
    w- C:\4d82ea16ddf541d31e61337e6534
    2009-11-10 12:58 . 2009-11-10 15:24
    d
    w- c:\program files\Rockstar Games
    2009-11-09 20:43 . 2009-11-09 20:43
    d
    w- c:\program files\NCH Software
    2009-11-09 20:42 . 2009-11-09 20:42
    d
    w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
    2009-11-09 20:42 . 2009-11-09 20:42
    d
    w- c:\documents and settings\Curtis\Application Data\NCH Swift Sound
    2009-11-09 20:39 . 2009-11-09 22:51
    d
    w- c:\program files\Mp3DoctorPRO
    2009-11-09 16:02 . 2009-11-09 16:02
    d
    w- c:\program files\MSXML 4.0
    2009-11-08 10:25 . 2009-11-08 10:25
    d
    w- c:\program files\Microsoft Office Outlook Connector
    2009-11-08 10:09 . 2009-11-08 10:09
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\Ahead
    2009-11-08 00:38 . 2009-11-08 00:38
    d
    w- c:\documents and settings\Curtis\Application Data\Nero
    2009-11-08 00:34 . 2009-11-08 10:00
    d
    w- c:\program files\Nero
    2009-11-08 00:34 . 2009-11-18 10:27
    d
    w- c:\documents and settings\All Users\Application Data\Nero
    2009-11-08 00:34 . 2009-11-18 10:27
    d
    w- c:\program files\Common Files\Nero
    2009-11-07 21:26 . 2009-11-07 21:26
    d
    w- c:\program files\Common Files\InterVideo
    2009-11-07 21:25 . 2009-11-25 12:27
    d
    w- c:\program files\DivX
    2009-11-07 21:25 . 2009-11-08 10:09
    d
    w- c:\program files\Common Files\LightScribe
    2009-11-07 21:23 . 2009-11-07 21:36
    d
    w- c:\documents and settings\All Users\Application Data\Ulead Systems
    2009-11-07 21:22 . 2005-05-26 15:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
    2009-11-07 11:25 . 2009-11-07 11:39
    d
    w- c:\program files\VirtualDJ
    2009-11-05 18:32 . 2009-11-05 18:32
    d
    w- c:\program files\iPod
    2009-11-05 18:32 . 2009-11-05 18:33
    d
    w- c:\program files\iTunes
    2009-11-05 18:29 . 2009-08-28 19:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
    2009-11-05 18:29 . 2009-08-28 19:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
    2009-11-05 18:22 . 2009-11-05 18:22 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
    2009-11-04 15:46 . 2009-11-04 15:49 152576 ----a-w- c:\documents and settings\Curtis\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
    2009-11-03 18:08 . 2003-01-10 10:56 30921 ----a-w- c:\windows\system32\drivers\SQCaptur.sys
    2009-11-03 18:08 . 2003-01-10 09:30 25449 ----a-w- c:\windows\system32\drivers\SQCamD.sys
    2009-11-01 15:05 . 2005-03-09 20:50 46592 ----a-w- c:\windows\system32\libusb0.dll
    2009-11-01 15:05 . 2005-03-09 20:50 33792 ----a-w- c:\windows\system32\drivers\libusb0.sys
    2009-10-31 16:47 . 2009-11-18 20:09
    d
    w- c:\documents and settings\Curtis\Local Settings\Application Data\WMTools Downloaded Files
    2009-10-31 14:26 . 2003-03-18 21:44 49152 ----a-w- c:\windows\system32\MFC71JPN.DLL
    2009-10-31 14:26 . 2009-10-31 14:32
    d
    w- c:\program files\Logitech
    2009-10-31 12:32 . 2003-10-15 17:52 307200 ----a-r- c:\windows\vidcap32.exe
  • (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-11-26 00:20 . 2009-10-25 20:59
    d
    w- c:\program files\Common Files\Adobe
    2009-11-24 09:32 . 2008-04-14 12:00 96512
    w- c:\windows\system32\drivers\atapi.sys
    2009-11-21 17:26 . 2009-10-25 20:18
    d--h--w- c:\program files\InstallShield Installation Information
    2009-11-21 08:15 . 2009-10-27 16:19
    d
    w- c:\program files\McAfee
    2009-11-10 17:09 . 2009-10-25 21:21 47800 ----a-w- c:\documents and settings\Manager\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-11-08 10:24 . 2009-10-25 21:20
    d
    w- c:\program files\MSECache
    2009-11-07 20:06 . 2009-10-25 20:27
    d
    w- c:\program files\Common Files\Adaptec Shared
    2009-11-05 18:32 . 2009-10-28 23:24
    d
    w- c:\program files\Common Files\Apple
    2009-10-30 09:35 . 2009-10-27 16:23
    d
    w- c:\documents and settings\All Users\Application Data\SiteAdvisor
    2009-10-29 21:53 . 2009-10-27 16:16
    d
    w- c:\documents and settings\All Users\Application Data\McAfee
    2009-10-29 13:10 . 2009-10-28 23:24
    d
    w- c:\documents and settings\All Users\Application Data\Apple
    2009-10-28 23:31 . 2009-10-25 19:52 87263 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
    2009-10-27 16:20 . 2009-10-27 16:19
    d
    w- c:\program files\Common Files\McAfee
    2009-10-27 16:20 . 2009-10-27 16:20
    d
    w- c:\program files\McAfee.com
    2009-10-25 21:21 . 2009-10-25 21:21
    d
    w- c:\documents and settings\All Users\Application Data\CyberLink
    2009-10-25 21:08 . 2009-10-25 21:08
    d
    w- c:\program files\Microsoft.NET
    2009-10-25 21:08 . 2009-10-25 21:08
    d
    w- c:\program files\Microsoft ActiveSync
    2009-10-25 21:00 . 2009-10-25 21:00
    d
    w- c:\program files\Common Files\Adobe AIR
    2009-10-25 20:57 . 2009-11-15 09:43
    d
    w- c:\documents and settings\Administrator\Application Data\U3
    2009-10-25 20:57 . 2009-10-25 21:27
    d
    w- c:\documents and settings\Curtis\Application Data\U3
    2009-10-25 20:57 . 2009-10-25 20:56
    d
    w- c:\documents and settings\Manager\Application Data\U3
    2009-10-25 20:27 . 2009-10-25 20:27 57344 ----a-w- c:\windows\uneng.exe
    2009-10-25 20:27 . 2009-10-25 20:17
    d
    w- c:\program files\Common Files\InstallShield
    2009-10-25 20:25 . 2009-10-25 20:24
    d
    w- c:\program files\Canon
    2009-10-25 20:24 . 2009-10-25 20:24
    d
    w- c:\program files\Common Files\Canon
    2009-10-25 20:23 . 2009-11-15 09:43
    d
    w- c:\documents and settings\Administrator\Application Data\CyberLink
    2009-10-25 20:23 . 2009-10-25 21:27
    d
    w- c:\documents and settings\Curtis\Application Data\CyberLink
    2009-10-25 20:23 . 2009-10-25 20:23
    d
    w- c:\documents and settings\Manager\Application Data\CyberLink
    2009-10-25 20:22 . 2009-10-25 20:22
    d
    w- c:\documents and settings\All Users\Application Data\Dell
    2009-10-25 20:22 . 2009-10-25 20:22
    d
    w- c:\program files\CyberLink
    2009-10-25 20:20 . 2009-10-25 20:20
    d
    w- c:\program files\Broadcom
    2009-10-25 20:18 . 2009-10-25 20:18
    d
    w- c:\program files\Analog Devices
    2009-10-25 20:14 . 2009-10-25 20:14
    d
    w- c:\program files\Intel
    2009-10-25 20:12 . 2009-10-25 20:12
    d
    w- c:\program files\Dell
    2009-10-25 20:10 . 2009-10-25 20:10 552 ----a-w- c:\windows\system32\d3d8caps.dat
    2009-10-25 19:53 . 2009-10-25 19:53
    d
    w- c:\program files\microsoft frontpage
    2009-10-25 19:49 . 2009-10-25 19:49 21640 ----a-w- c:\windows\system32\emptyregdb.dat
    2009-09-16 10:22 . 2009-10-27 16:20 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
    2009-09-16 10:22 . 2009-10-27 16:20 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
    2009-09-16 10:22 . 2009-10-27 16:20 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
    2009-09-16 10:22 . 2009-10-27 16:20 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
    2009-09-16 10:22 . 2009-10-27 16:20 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
    2009-09-11 14:18 . 2008-04-14 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-04 21:03 . 2008-04-14 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-08-29 08:08 . 2008-04-14 12:00 916480
    w- c:\windows\system32\wininet.dll
    .
    ((((((((((((((((((((((((((((( SnapShot@2009-11-25_20.21.21 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-11-26 17:37 . 2009-11-26 17:37 16384 c:\windows\Temp\Perflib_Perfdata_768.dat
    + 2009-10-25 19:55 . 2009-11-26 15:26 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    - 2009-10-25 19:55 . 2009-11-25 16:09 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    - 2009-10-25 19:55 . 2009-11-25 16:09 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    + 2009-10-25 19:55 . 2009-11-26 15:26 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    - 2009-11-17 20:38 . 2009-11-25 16:09 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
    + 2009-11-17 20:38 . 2009-11-26 15:26 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
    - 2009-10-25 19:55 . 2009-11-25 16:09 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2009-11-25 20:59 . 2009-11-26 15:26 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2009-07-12 00:02 . 2009-07-12 00:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
    + 2009-08-03 15:07 . 2009-08-03 15:07 230768 c:\windows\system32\OGAEXEC.exe
    + 2009-08-03 15:07 . 2009-08-03 15:07 403816 c:\windows\system32\OGACheckControl.dll
    + 2009-08-03 15:07 . 2009-08-03 15:07 322928 c:\windows\system32\OGAAddin.dll
    + 2009-11-25 21:41 . 2009-11-25 21:41 195584 c:\windows\Installer\57a228.msi
    + 2009-11-25 22:21 . 2009-11-25 22:21 119296 c:\windows\Installer\10284e.msi
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Google Update"="c:\documents and settings\Curtis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-25 135664]
    "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-11 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-11 166424]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-05-08 1015808]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
    "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-9-15 503869]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
    backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
    [HKLM\~\startupfolder\C:^Documents and Settings^Curtis^Start Menu^Programs^Startup^FrostWire On Startup.lnk]
    path=c:\documents and settings\Curtis\Start Menu\Programs\Startup\FrostWire On Startup.lnk
    backup=c:\windows\pss\FrostWire On Startup.lnkStartup
    [HKLM\~\startupfolder\C:^Documents and Settings^Curtis^Start Menu^Programs^Startup^Shortcut to Nobar.lnk]
    path=c:\documents and settings\Curtis\Start Menu\Programs\Startup\Shortcut to Nobar.lnk
    backup=c:\windows\pss\Shortcut to Nobar.lnkStartup
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2009-10-28 20:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
    2007-09-17 11:56 124200
    w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2009-09-05 01:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "ose"=3 (0x3)
    "MSK80Service"=2 (0x2)
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\FrostWire\\FrostWire.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Save Tube Video Company\\SaveTubeVideo\\downloader.exe"=
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "43594:TCP"= 43594:TCP:gasscape
    "25188:TCP"= 25188:TCP:BitComet 25188 TCP
    "25188:UDP"= 25188:UDP:BitComet 25188 UDP
    R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [26/11/2009 16:41 95592]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [29/10/2009 21:53 93320]
    R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\Ralink\Common\RalinkRegistryWriter.exe [29/10/2009 12:55 75040]
    S0 cerc6;cerc6; [x]
    S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26/11/2009 16:41 721904]
    S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [01/11/2009 15:05 33792]
    S3 RAPIProtocol;Ralink RAPI Protocol Driver;c:\windows\system32\drivers\RAPIProtocol.sys [28/10/2009 22:00 16512]
    S3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\DRIVERS\xpadfl02.sys --> c:\windows\system32\DRIVERS\xpadfl02.sys [?]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    getPlusHelper REG_MULTI_SZ getPlusHelper
  • is that ok ?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Im off to work now

    Ill check again when I can

    If you wish to have another scan (I would recommend you do) ~
    Download and run the FREE version of DR WEB
    http://www.freedrweb.com/download+cureit/gr/
    Turn your anti virus OFF
    It will auto QUICK scan
    After that set to scan the WHOLE computer and press the 'play' icon
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.