You are not connected. Please login or register

Goto page : 1, 2  Next

View previous topic View next topic Go down  Message [Page 1 of 2]

1 Please help me remove Searhcmagnified.com on Sun Feb 07, 2010 12:41 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:27:18 AM, on 2/7/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.southwestsafari.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "https://signin.ebay.com/ws/eBayISAPI.dll?SignIn&co_partnerId=2&pUserId=&siteid=0&pageType=1883&pa1=&i1=&bshowgif=&UsingSSL=0&ru=http%3A%2F%2Fmy.ebay.com%2Fws%2FeBayISAPI.dll%3FMyeBay&pp=&pa2=&errmsg=&runame=&ruparams=&ruproduct=&sid=&favoritenav=&migrateVisitor=1"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\1ao8dlll.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\OWNER\Application Data\Mozilla\Profiles\default\1ao8dlll.slt\prefs.js)
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - .DEFAULT User Startup: Launcher.exe (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &ieSpell Options - res://D:\Program Files D\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://D:\Program Files D\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://D:\Program Files D\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://D:\Program Files D\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files D\ieSpell\iespell.dll (file missing)
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files D\ieSpell\iespell.dll (file missing)
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - D:\Program Files D\ieSpell\iespell.dll (file missing)
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - D:\Program Files D\ieSpell\iespell.dll (file missing)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: UltimateBet - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Documents and Settings\Owner\Start Menu\Programs\UltimateBet\UltimateBet.lnk (HKCU)
O9 - Extra 'Tools' menuitem: UltimateBet - {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Documents and Settings\Owner\Start Menu\Programs\UltimateBet\UltimateBet.lnk (HKCU)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://alancraigmauirealestate.viewnetcam.com/kxhcm10.ocx
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1234214192390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233162206937
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://66.91.147.106:8010/activex/AMC.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 10033 bytes

View user profile

2 Re: Please help me remove Searhcmagnified.com on Sun Feb 07, 2010 1:19 pm

Please download ComboFix from BleepingComputer.com

Alternate link: GeeksToGo.com

Alternate link: Forospyware.com

Rename ComboFix.exe to commy.exe before you save it to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
  • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console


Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

3 ComboFix log. Thank you. on Sun Feb 07, 2010 2:38 pm

ComboFix 10-02-07.02 - Owner 02/07/2010 12:06:23.1.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1722 [GMT -7:00]
Running from: c:\documents and settings\Owner\desktop\commy.exe
Command switches used :: /stepdel
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\NPROTECT\00271018.
c:\recycler\NPROTECT\00271179. 12-17
c:\recycler\NPROTECT\00271180. 12-17
c:\recycler\NPROTECT\00271181. 12-17
c:\recycler\NPROTECT\00271182. 12-17
c:\recycler\NPROTECT\00271184.
c:\recycler\NPROTECT\00271251.
c:\recycler\NPROTECT\00271255.
c:\recycler\NPROTECT\00271261.
c:\recycler\NPROTECT\00271357.
c:\recycler\NPROTECT\00271394.
c:\recycler\NPROTECT\00271395.
c:\recycler\NPROTECT\00271401.
c:\recycler\NPROTECT\00271403.
c:\recycler\NPROTECT\00271407.
c:\recycler\NPROTECT\00271417.
c:\recycler\NPROTECT\00271454.
c:\recycler\NPROTECT\00271614.
c:\recycler\NPROTECT\00271644.
c:\recycler\NPROTECT\00271654.
c:\recycler\NPROTECT\00271659.
c:\recycler\NPROTECT\00271684.
c:\recycler\NPROTECT\00271685.
c:\recycler\NPROTECT\00271721.
c:\recycler\NPROTECT\00271733.
c:\recycler\NPROTECT\00271734.
c:\recycler\NPROTECT\00271744.
c:\recycler\NPROTECT\00271755.
c:\recycler\NPROTECT\00271812.
c:\recycler\NPROTECT\00271837.
c:\recycler\NPROTECT\00271908.
c:\recycler\NPROTECT\00271925.
c:\recycler\NPROTECT\00271936.
c:\recycler\NPROTECT\00271956.
c:\recycler\NPROTECT\00271958.
c:\recycler\NPROTECT\00271994.
c:\recycler\NPROTECT\00272045.
c:\recycler\NPROTECT\00272126.
c:\recycler\NPROTECT\00272135.
c:\recycler\NPROTECT\00272142.
c:\recycler\NPROTECT\00272175.
c:\recycler\NPROTECT\00272188.
c:\recycler\NPROTECT\00272190.
c:\recycler\NPROTECT\00272202.
c:\recycler\NPROTECT\00272210.
c:\recycler\NPROTECT\00272211.
c:\recycler\NPROTECT\00272212.
c:\recycler\NPROTECT\00272213.
c:\recycler\NPROTECT\00272214.
c:\recycler\NPROTECT\00272215.
c:\recycler\NPROTECT\00272217.
c:\recycler\NPROTECT\00272218.
c:\recycler\NPROTECT\00272222.
c:\recycler\NPROTECT\00272226.
c:\recycler\NPROTECT\00272227.
c:\recycler\NPROTECT\00272262.
c:\recycler\NPROTECT\00272298.
c:\recycler\NPROTECT\00272312.
c:\recycler\NPROTECT\00272341.
c:\recycler\NPROTECT\00272383.
c:\recycler\NPROTECT\00272412.
c:\recycler\NPROTECT\00272416.
c:\recycler\NPROTECT\00272418.
c:\windows\AUTOLNCH.REG
c:\windows\system32\Data
C:\LOG.TXT
C:\pcwtest.tmp
c:\recycler\NPROTECT . . . . failed to delete
c:\recycler\NPROTECT\00271018.
c:\recycler\NPROTECT\00271115. 10 Goli
c:\recycler\NPROTECT\00271116. 10 Goli
c:\recycler\NPROTECT\00271177. 10 Wils
c:\recycler\NPROTECT\00271178. 10 Wils
c:\recycler\NPROTECT\00271179. 12-17
c:\recycler\NPROTECT\00271180. 12-17
c:\recycler\NPROTECT\00271181. 12-17
c:\recycler\NPROTECT\00271182. 12-17
c:\recycler\NPROTECT\00271184.
c:\recycler\NPROTECT\00271251.
c:\recycler\NPROTECT\00271255.
c:\recycler\NPROTECT\00271261.
c:\recycler\NPROTECT\00271276. 10, Be
c:\recycler\NPROTECT\00271277. 10, Be
c:\recycler\NPROTECT\00271278. 6-11 (4
c:\recycler\NPROTECT\00271279. 6-11 (4
c:\recycler\NPROTECT\00271357.
c:\recycler\NPROTECT\00271389.prope
c:\recycler\NPROTECT\00271394.
c:\recycler\NPROTECT\00271395.
c:\recycler\NPROTECT\00271401.
c:\recycler\NPROTECT\00271403.
c:\recycler\NPROTECT\00271407.
c:\recycler\NPROTECT\00271417.
c:\recycler\NPROTECT\00271454.
c:\recycler\NPROTECT\00271614.
c:\recycler\NPROTECT\00271644.
c:\recycler\NPROTECT\00271654.
c:\recycler\NPROTECT\00271659.
c:\recycler\NPROTECT\00271684.
c:\recycler\NPROTECT\00271685.
c:\recycler\NPROTECT\00271721.
c:\recycler\NPROTECT\00271733.
c:\recycler\NPROTECT\00271734.
c:\recycler\NPROTECT\00271744.
c:\recycler\NPROTECT\00271755.
c:\recycler\NPROTECT\00271812.
c:\recycler\NPROTECT\00271837.
c:\recycler\NPROTECT\00271841.html
c:\recycler\NPROTECT\00271908.
c:\recycler\NPROTECT\00271925.
c:\recycler\NPROTECT\00271936.
c:\recycler\NPROTECT\00271956.
c:\recycler\NPROTECT\00271958.
c:\recycler\NPROTECT\00271994.
c:\recycler\NPROTECT\00272041. Submiss
c:\recycler\NPROTECT\00272045.
c:\recycler\NPROTECT\00272126.
c:\recycler\NPROTECT\00272131.html
c:\recycler\NPROTECT\00272135.
c:\recycler\NPROTECT\00272142.
c:\recycler\NPROTECT\00272146.html
c:\recycler\NPROTECT\00272147.html
c:\recycler\NPROTECT\00272148.html
c:\recycler\NPROTECT\00272149.html
c:\recycler\NPROTECT\00272150.html
c:\recycler\NPROTECT\00272151.html
c:\recycler\NPROTECT\00272152.html
c:\recycler\NPROTECT\00272153.html
c:\recycler\NPROTECT\00272154.html
c:\recycler\NPROTECT\00272155.html
c:\recycler\NPROTECT\00272156.html
c:\recycler\NPROTECT\00272157.html
c:\recycler\NPROTECT\00272158.html
c:\recycler\NPROTECT\00272159.html
c:\recycler\NPROTECT\00272160.html
c:\recycler\NPROTECT\00272161.html
c:\recycler\NPROTECT\00272162.html
c:\recycler\NPROTECT\00272167.html
c:\recycler\NPROTECT\00272168.html
c:\recycler\NPROTECT\00272169.html
c:\recycler\NPROTECT\00272170.html
c:\recycler\NPROTECT\00272174.html
c:\recycler\NPROTECT\00272175.
c:\recycler\NPROTECT\00272188.
c:\recycler\NPROTECT\00272190.
c:\recycler\NPROTECT\00272202.
c:\recycler\NPROTECT\00272210.
c:\recycler\NPROTECT\00272211.
c:\recycler\NPROTECT\00272212.
c:\recycler\NPROTECT\00272213.
c:\recycler\NPROTECT\00272214.
c:\recycler\NPROTECT\00272215.
c:\recycler\NPROTECT\00272217.
c:\recycler\NPROTECT\00272218.
c:\recycler\NPROTECT\00272222.
c:\recycler\NPROTECT\00272226.
c:\recycler\NPROTECT\00272227.
c:\recycler\NPROTECT\00272262.
c:\recycler\NPROTECT\00272298.
c:\recycler\NPROTECT\00272312.
c:\recycler\NPROTECT\00272341.
c:\recycler\NPROTECT\00272383.
c:\recycler\NPROTECT\00272412.
c:\recycler\NPROTECT\00272416.
c:\recycler\NPROTECT\00272418.
c:\recycler\NPROTECT\00311548
c:\recycler\NPROTECT\00311549
c:\recycler\NPROTECT\00311564.edb
c:\recycler\NPROTECT\00311575.MOZ
c:\recycler\NPROTECT\00311576.MOZ
c:\recycler\NPROTECT\00311577.MOZ
c:\recycler\NPROTECT\00311583.LNK
c:\recycler\NPROTECT\00311584.LNK
c:\recycler\NPROTECT\00311585.DIC
c:\recycler\NPROTECT\00311586.LNK
c:\recycler\NPROTECT\00311587.LNK
c:\recycler\NPROTECT\00311588.LNK
c:\recycler\NPROTECT\00311589.LNK
c:\recycler\NPROTECT\00311693.dat
c:\recycler\NPROTECT\00311695.MOZ
c:\recycler\NPROTECT\00311706.MOZ
c:\recycler\NPROTECT\00311709.edb
c:\recycler\NPROTECT\00311711
c:\recycler\NPROTECT\00311712
c:\recycler\NPROTECT\00311713.lo_
c:\recycler\NPROTECT\00311717.edb
c:\recycler\NPROTECT\00311767.MOZ
c:\recycler\NPROTECT\00311776.JPG
c:\recycler\NPROTECT\00311777.JPG
c:\recycler\NPROTECT\00311778.JPG
c:\recycler\NPROTECT\00311779.JPG
c:\recycler\NPROTECT\00311780.JPG
c:\recycler\NPROTECT\00311781.JPG
c:\recycler\NPROTECT\00311782.JPG
c:\recycler\NPROTECT\00311783.JPG
c:\recycler\NPROTECT\00311784.JPG
c:\recycler\NPROTECT\00311785.JPG
c:\recycler\NPROTECT\00311786.JPG
c:\recycler\NPROTECT\00311787.JPG
c:\recycler\NPROTECT\00311788.JPG
c:\recycler\NPROTECT\00311789.JPG
c:\recycler\NPROTECT\00311790.JPG
c:\recycler\NPROTECT\00311791.JPG
c:\recycler\NPROTECT\00311792.JPG
c:\recycler\NPROTECT\00311793.JPG
c:\recycler\NPROTECT\00311794.JPG
c:\recycler\NPROTECT\00311795.JPG
c:\recycler\NPROTECT\00311796.JPG
c:\recycler\NPROTECT\00311797.JPG
c:\recycler\NPROTECT\00311798.JPG
c:\recycler\NPROTECT\00311799.JPG
c:\recycler\NPROTECT\00311800.JPG
c:\recycler\NPROTECT\00311801.JPG
c:\recycler\NPROTECT\00311802.JPG
c:\recycler\NPROTECT\00311803.JPG
c:\recycler\NPROTECT\00311804.JPG
c:\recycler\NPROTECT\00311805.JPG
c:\recycler\NPROTECT\00311806.JPG
c:\recycler\NPROTECT\00311807.JPG
c:\recycler\NPROTECT\00311808.JPG
c:\recycler\NPROTECT\00311809.JPG
c:\recycler\NPROTECT\00311810.JPG
c:\recycler\NPROTECT\00311811.JPG
c:\recycler\NPROTECT\00311812.JPG
c:\recycler\NPROTECT\00311813.JPG
c:\recycler\NPROTECT\00311814.JPG
c:\recycler\NPROTECT\00311815.JPG
c:\recycler\NPROTECT\00311816.JPG
c:\recycler\NPROTECT\00311817.JPG
c:\recycler\NPROTECT\00311818.JPG
c:\recycler\NPROTECT\00311819.JPG
c:\recycler\NPROTECT\00311820.JPG
c:\recycler\NPROTECT\00311821.JPG
c:\recycler\NPROTECT\00311822.JPG
c:\recycler\NPROTECT\00311823.JPG
c:\recycler\NPROTECT\00311824.JPG
c:\recycler\NPROTECT\00311825.JPG
c:\recycler\NPROTECT\00311826.JPG
c:\recycler\NPROTECT\00311827.JPG
c:\recycler\NPROTECT\00311828.JPG
c:\recycler\NPROTECT\00311829.JPG
c:\recycler\NPROTECT\00311830.JPG
c:\recycler\NPROTECT\00311831.JPG
c:\recycler\NPROTECT\00311832.JPG
c:\recycler\NPROTECT\00311833.JPG
c:\recycler\NPROTECT\00311834.JPG
c:\recycler\NPROTECT\00311835.JPG
c:\recycler\NPROTECT\00311836.JPG
c:\recycler\NPROTECT\00311837.JPG
c:\recycler\NPROTECT\00311838.JPG
c:\recycler\NPROTECT\00311839.JPG
c:\recycler\NPROTECT\00311840.JPG
c:\recycler\NPROTECT\00311841.JPG
c:\recycler\NPROTECT\00311842.JPG
c:\recycler\NPROTECT\00311843.db
c:\recycler\NPROTECT\00311906.THE
c:\recycler\NPROTECT\00311925.gif
c:\recycler\NPROTECT\00311926.jpg
c:\recycler\NPROTECT\00311927.png
c:\recycler\NPROTECT\00311928.gif
c:\recycler\NPROTECT\00311930.THE
c:\recycler\NPROTECT\00311937.dat
c:\recycler\NPROTECT\00311939
c:\recycler\NPROTECT\00311940
c:\recycler\NPROTECT\00311950.MOZ
c:\recycler\NPROTECT\00311952.edb
c:\recycler\NPROTECT\00311955.URL
c:\recycler\NPROTECT\00311957.LNK
c:\recycler\NPROTECT\00311958.LNK
c:\recycler\NPROTECT\00311959.LNK
c:\recycler\NPROTECT\00311960.LNK
c:\recycler\NPROTECT\00311961.LNK
c:\recycler\NPROTECT\00311962.LNK
c:\recycler\NPROTECT\00311963.DIC
c:\recycler\NPROTECT\00311964.LNK
c:\recycler\NPROTECT\00311965.LNK
c:\recycler\NPROTECT\00311966.LNK
c:\recycler\NPROTECT\00311967.LNK
c:\recycler\NPROTECT\00311970.SHD
c:\recycler\NPROTECT\00311971.SPL
c:\recycler\NPROTECT\00311972.doc
c:\recycler\NPROTECT\00311973.doc
c:\recycler\NPROTECT\00311981.URL
c:\recycler\NPROTECT\00311982.LNK
c:\recycler\NPROTECT\00311984.LNK
c:\recycler\NPROTECT\00311985.LNK
c:\recycler\NPROTECT\00311986.LNK
c:\recycler\NPROTECT\00311987.LNK
c:\recycler\NPROTECT\00311988.LNK
c:\recycler\NPROTECT\00311989.LNK
c:\recycler\NPROTECT\00311992.LNK
c:\recycler\NPROTECT\00311993.LNK
c:\recycler\NPROTECT\00311994.SHD
c:\recycler\NPROTECT\00311995.SPL
c:\recycler\NPROTECT\00311997.XML
c:\recycler\NPROTECT\00311999.WMD
c:\recycler\NPROTECT\00312001.doc
c:\recycler\NPROTECT\00312002.doc
c:\recycler\NPROTECT\00312007.LNK
c:\recycler\NPROTECT\00312008.LNK
c:\recycler\NPROTECT\00312009.DIC
c:\recycler\NPROTECT\00312011.LNK
c:\recycler\NPROTECT\00312012.LNK
c:\recycler\NPROTECT\00312013.LNK
c:\recycler\NPROTECT\00312014.LNK
c:\recycler\NPROTECT\00312015.LNK
c:\recycler\NPROTECT\00312016.LNK
c:\recycler\NPROTECT\00312017.LNK
c:\recycler\NPROTECT\00312018.LNK
c:\recycler\NPROTECT\00312019.LNK
c:\recycler\NPROTECT\00312020.LNK
c:\recycler\NPROTECT\00312021.LNK
c:\recycler\NPROTECT\00312022.LNK
c:\recycler\NPROTECT\00312023.LNK
c:\recycler\NPROTECT\00312024.LNK
c:\recycler\NPROTECT\00312025.LNK
c:\recycler\NPROTECT\00312026.LNK
c:\recycler\NPROTECT\00312027.LNK
c:\recycler\NPROTECT\00312028.LNK
c:\recycler\NPROTECT\00312029.LNK
c:\recycler\NPROTECT\00312030.LNK
c:\recycler\NPROTECT\00312031.LNK
c:\recycler\NPROTECT\00312032.LNK
c:\recycler\NPROTECT\00312033.LNK
c:\recycler\NPROTECT\00312034.LNK
c:\recycler\NPROTECT\00312035.LNK
c:\recycler\NPROTECT\00312036.LNK
c:\recycler\NPROTECT\00312037.LNK
c:\recycler\NPROTECT\00312038.LNK
c:\recycler\NPROTECT\00312039.doc
c:\recycler\NPROTECT\00312040.doc
c:\recycler\NPROTECT\00312150.edb
c:\recycler\NPROTECT\00312179.dat
c:\recycler\NPROTECT\00312194.MOZ
c:\recycler\NPROTECT\00312251.MOZ
c:\recycler\NPROTECT\00312257.edb
c:\recycler\NPROTECT\00312264.cab
c:\recycler\NPROTECT\00312276.edb
c:\recycler\NPROTECT\00312277.log
c:\recycler\NPROTECT\00312278.dat
c:\recycler\NPROTECT\00312279.ini
c:\recycler\NPROTECT\00312280.dat
c:\recycler\NPROTECT\00312304.BIN
c:\recycler\NPROTECT\00312306.edb
c:\recycler\NPROTECT\00312334.dat
c:\recycler\NPROTECT\00312335.ini
c:\recycler\NPROTECT\00312337.lo_
c:\recycler\NPROTECT\00312338
c:\recycler\NPROTECT\00312339
c:\recycler\NPROTECT\00312342.edb
c:\recycler\NPROTECT\00312344.SOL
c:\recycler\NPROTECT\00312345.SOL
c:\recycler\NPROTECT\00312346.SOL
c:\recycler\NPROTECT\00312347.SOL
c:\recycler\NPROTECT\00312348.SOL
c:\recycler\NPROTECT\00312349.SOL
c:\recycler\NPROTECT\00312350.SOL
c:\recycler\NPROTECT\00312351.SOL
c:\recycler\NPROTECT\00312352.SOL
c:\recycler\NPROTECT\00312353.SOL
c:\recycler\NPROTECT\00312354.SOL
c:\recycler\NPROTECT\00312355.SOL
c:\recycler\NPROTECT\00312356.SOL
c:\recycler\NPROTECT\00312357.SOL
c:\recycler\NPROTECT\00312358.SOL
c:\recycler\NPROTECT\00312359.SOL
c:\recycler\NPROTECT\00312360.SOL
c:\recycler\NPROTECT\00312362.SOL
c:\recycler\NPROTECT\00312363.SOL
c:\recycler\NPROTECT\00312364.SOL
c:\recycler\NPROTECT\00312365.SOL
c:\recycler\NPROTECT\00312366.SOL
c:\recycler\NPROTECT\00312367.SOL
c:\recycler\NPROTECT\00312368.SOL
c:\recycler\NPROTECT\00312369.SOL
c:\recycler\NPROTECT\00312370.SOL
c:\recycler\NPROTECT\00312371.SOL
c:\recycler\NPROTECT\00312372.SOL
c:\recycler\NPROTECT\00312373.SOL
c:\recycler\NPROTECT\00312376.SOL
c:\recycler\NPROTECT\00312377.SOL
c:\recycler\NPROTECT\00312381.XML
c:\recycler\NPROTECT\00312382.XML
c:\recycler\NPROTECT\00312383.XML
c:\recycler\NPROTECT\00312384.XML
c:\recycler\NPROTECT\00312385.XML
c:\recycler\NPROTECT\00312387
c:\recycler\NPROTECT\00312388
c:\recycler\NPROTECT\00312390.edb
c:\recycler\NPROTECT\00312466.LNK
c:\recycler\NPROTECT\00312467.LNK
c:\recycler\NPROTECT\00312468.DIC
c:\recycler\NPROTECT\00312469.LNK
c:\recycler\NPROTECT\00312470.LNK
c:\recycler\NPROTECT\00312471.LNK
c:\recycler\NPROTECT\00312472.LNK
c:\recycler\NPROTECT\00312473.LNK
c:\recycler\NPROTECT\00312474.LNK
c:\recycler\NPROTECT\00312475.LNK
c:\recycler\NPROTECT\00312476.LNK
c:\recycler\NPROTECT\00312478.LNK
c:\recycler\NPROTECT\00312479.LNK
c:\recycler\NPROTECT\00312480.LNK
c:\recycler\NPROTECT\00312481.LNK
c:\recycler\NPROTECT\00312482.LNK
c:\recycler\NPROTECT\00312483.LNK
c:\recycler\NPROTECT\00312484.LNK
c:\recycler\NPROTECT\00312485.LNK
c:\recycler\NPROTECT\00312486.LNK
c:\recycler\NPROTECT\00312487.LNK
c:\recycler\NPROTECT\00312488.LNK
c:\recycler\NPROTECT\00312489.LNK
c:\recycler\NPROTECT\00312490.LNK
c:\recycler\NPROTECT\00312491.LNK
c:\recycler\NPROTECT\00312492.LNK
c:\recycler\NPROTECT\00312493.LNK
c:\recycler\NPROTECT\00312494.LNK
c:\recycler\NPROTECT\00312495.LNK
c:\recycler\NPROTECT\00312496.LNK
c:\recycler\NPROTECT\00312497.LNK
c:\recycler\NPROTECT\00312498.LNK
c:\recycler\NPROTECT\00312499.LNK
c:\recycler\NPROTECT\00312500.LNK
c:\recycler\NPROTECT\00312501.LNK
c:\recycler\NPROTECT\00312502.LNK
c:\recycler\NPROTECT\00312503.LNK
c:\recycler\NPROTECT\00312504.LNK
c:\recycler\NPROTECT\00312505.LNK
c:\recycler\NPROTECT\00312506.LNK
c:\recycler\NPROTECT\00312507.LNK
c:\recycler\NPROTECT\00312508.LNK
c:\recycler\NPROTECT\00312509.LNK
c:\recycler\NPROTECT\00312510.LNK
c:\recycler\NPROTECT\00312511.LNK
c:\recycler\NPROTECT\00312512.LNK
c:\recycler\NPROTECT\00312513.LNK
c:\recycler\NPROTECT\00312514.LNK
c:\recycler\NPROTECT\00312515.LNK
c:\recycler\NPROTECT\00312516.LNK
c:\recycler\NPROTECT\00312517.LNK
c:\recycler\NPROTECT\00312518.LNK
c:\recycler\NPROTECT\00312519.LNK
c:\recycler\NPROTECT\00312520.LNK
c:\recycler\NPROTECT\00312521.LNK
c:\recycler\NPROTECT\00312522.LNK
c:\recycler\NPROTECT\00312523.LNK
c:\recycler\NPROTECT\00312524.LNK
c:\recycler\NPROTECT\00312525.LNK
c:\recycler\NPROTECT\00312526.doc
c:\recycler\NPROTECT\00312527.doc
c:\recycler\NPROTECT\00312534.cab
c:\recycler\NPROTECT\00312545.dat
c:\recycler\NPROTECT\00312546.ini
c:\recycler\NPROTECT\00312547.dat
c:\recycler\NPROTECT\00312548.edb
c:\recycler\NPROTECT\00312574.BIN
c:\recycler\NPROTECT\00312576.edb
c:\recycler\NPROTECT\00312578
c:\recycler\NPROTECT\00312579
c:\recycler\NPROTECT\00312587.edb
c:\recycler\NPROTECT\00312596.MOZ
c:\recycler\NPROTECT\00312598.SOL
c:\recycler\NPROTECT\00312599.SOL
c:\recycler\NPROTECT\00312600.SOL
c:\recycler\NPROTECT\00312601.SOL
c:\recycler\NPROTECT\00312604.lo_
c:\recycler\NPROTECT\00312611.cab
c:\recycler\NPROTECT\00312620.edb
c:\recycler\NPROTECT\00312633.cab
c:\recycler\NPROTECT\00312642.edb
c:\recycler\NPROTECT\00312646.ini
c:\recycler\NPROTECT\00312648.dat
c:\recycler\NPROTECT\00312668.MOZ
c:\recycler\NPROTECT\00312672.BIN
c:\recycler\NPROTECT\00312674.edb
c:\recycler\NPROTECT\00312700.MOZ
c:\recycler\NPROTECT\00312710.MOZ
c:\recycler\NPROTECT\00312759.sav
c:\recycler\NPROTECT\00312760.sav
c:\recycler\NPROTECT\00312761.sav
c:\recycler\NPROTECT\00312762.sav
c:\recycler\NPROTECT\00312763.sav
c:\recycler\NPROTECT\00312776.sav
c:\recycler\NPROTECT\00312777.sav
c:\recycler\NPROTECT\00312838.edb
c:\recycler\NPROTECT\00312871.LNK
c:\recycler\NPROTECT\00312872.LNK
c:\recycler\NPROTECT\00312873.DIC
c:\recycler\NPROTECT\00312875.LNK
c:\recycler\NPROTECT\00312876.URL
c:\recycler\NPROTECT\00312878.LNK
c:\recycler\NPROTECT\00312879.LNK
c:\recycler\NPROTECT\00312881.LNK
c:\recycler\NPROTECT\00312882.LNK
c:\recycler\NPROTECT\00312884.LNK
c:\recycler\NPROTECT\00312885.URL
c:\recycler\NPROTECT\00312911.MOZ
c:\recycler\NPROTECT\00312914.URL
c:\recycler\NPROTECT\00312915.URL
c:\recycler\NPROTECT\00312916.URL
c:\recycler\NPROTECT\00312917.URL
c:\recycler\NPROTECT\00312918.URL
c:\recycler\NPROTECT\00312919.URL
c:\recycler\NPROTECT\00312920.URL
c:\recycler\NPROTECT\00312921.URL
c:\recycler\NPROTECT\00312922.URL
c:\recycler\NPROTECT\00312923.URL
c:\recycler\NPROTECT\00312924.URL
c:\recycler\NPROTECT\00312925.URL
c:\recycler\NPROTECT\00312926.URL
c:\recycler\NPROTECT\00312972.MOZ
c:\recycler\NPROTECT\00313006.edb
c:\recycler\NPROTECT\00313008
c:\recycler\NPROTECT\00313009
c:\recycler\NPROTECT\00313014.edb
c:\recycler\NPROTECT\00313025.DLL
c:\recycler\NPROTECT\00313026.SYS
c:\recycler\NPROTECT\00313027.SPM
c:\recycler\NPROTECT\00313028.GRD
c:\recycler\NPROTECT\00313029.SIG
c:\recycler\NPROTECT\00313030.INF
c:\recycler\NPROTECT\00313031.CAT
c:\recycler\NPROTECT\00313032.rbs
c:\recycler\NPROTECT\00313033.ipi
c:\recycler\NPROTECT\00313034.msi
c:\recycler\NPROTECT\00313036.rbf
c:\recycler\NPROTECT\00313037.rbf
c:\recycler\NPROTECT\00313038.rbf
c:\recycler\NPROTECT\00313039.rbf
c:\recycler\NPROTECT\00313040.rbf
c:\recycler\NPROTECT\00313041.rbf
c:\recycler\NPROTECT\00313042.rbf
c:\recycler\NPROTECT\00313043.rbf
c:\recycler\NPROTECT\00313044.rbf
c:\recycler\NPROTECT\00313045.rbf
c:\recycler\NPROTECT\00313046.rbs
c:\recycler\NPROTECT\00313047.ipi
c:\recycler\NPROTECT\00313048.msi
c:\recycler\NPROTECT\00313049.rbf
c:\recycler\NPROTECT\00313050.rbf
c:\recycler\NPROTECT\00313051.rbf
c:\recycler\NPROTECT\00313052.rbf
c:\recycler\NPROTECT\00313053.rbf
c:\recycler\NPROTECT\00313054.rbf
c:\recycler\NPROTECT\00313055.rbf
c:\recycler\NPROTECT\00313056.rbf
c:\recycler\NPROTECT\00313057.rbf
c:\recycler\NPROTECT\00313058.rbf
c:\recycler\NPROTECT\00313059.rbf
c:\recycler\NPROTECT\00313060.rbf
c:\recycler\NPROTECT\00313061.rbf
c:\recycler\NPROTECT\00313062.rbf
c:\recycler\NPROTECT\00313063.rbf
c:\recycler\NPROTECT\00313064.rbf
c:\recycler\NPROTECT\00313065.rbf
c:\recycler\NPROTECT\00313066.rbf
c:\recycler\NPROTECT\00313067.rbf
c:\recycler\NPROTECT\00313068.rbf
c:\recycler\NPROTECT\00313069.rbf
c:\recycler\NPROTECT\00313070.rbf
c:\recycler\NPROTECT\00313071.rbf
c:\recycler\NPROTECT\00313072.rbs
c:\recycler\NPROTECT\00313073.ipi
c:\recycler\NPROTECT\00313074.msi
c:\recycler\NPROTECT\00313077.rbf
c:\recycler\NPROTECT\00313078.rbf
c:\recycler\NPROTECT\00313079.rbf
c:\recycler\NPROTECT\00313080.rbf
c:\recycler\NPROTECT\00313081.rbf
c:\recycler\NPROTECT\00313082.rbf
c:\recycler\NPROTECT\00313083.rbf
c:\recycler\NPROTECT\00313084.rbf
c:\recycler\NPROTECT\00313085.rbf
c:\recycler\NPROTECT\00313086.rbs
c:\recycler\NPROTECT\00313087.ipi
c:\recycler\NPROTECT\00313088.msi
c:\recycler\NPROTECT\00313092.rbf
c:\recycler\NPROTECT\00313093.rbf
c:\recycler\NPROTECT\00313094.rbf
c:\recycler\NPROTECT\00313095.rbf
c:\recycler\NPROTECT\00313096.rbf
c:\recycler\NPROTECT\00313097.rbf
c:\recycler\NPROTECT\00313098.rbf
c:\recycler\NPROTECT\00313099.rbf
c:\recycler\NPROTECT\00313100.rbf
c:\recycler\NPROTECT\00313101.rbf
c:\recycler\NPROTECT\00313102.rbf
c:\recycler\NPROTECT\00313103.rbf
c:\recycler\NPROTECT\00313104.rbf
c:\recycler\NPROTECT\00313105.rbf
c:\recycler\NPROTECT\00313106.rbs
c:\recycler\NPROTECT\00313107.ipi
c:\recycler\NPROTECT\00313108.rbf
c:\recycler\NPROTECT\00313109.rbs
c:\recycler\NPROTECT\00313110.ipi
c:\recycler\NPROTECT\00313111.msi
c:\recycler\NPROTECT\00313112.rbs
c:\recycler\NPROTECT\00313113.ipi
c:\recycler\NPROTECT\00313114.msi
c:\recycler\NPROTECT\00313115.rbf
c:\recycler\NPROTECT\00313116.rbf
c:\recycler\NPROTECT\00313117.rbf
c:\recycler\NPROTECT\00313118.rbf
c:\recycler\NPROTECT\00313119.rbs
c:\recycler\NPROTECT\00313120.ipi
c:\recycler\NPROTECT\00313121.msi
c:\recycler\NPROTECT\00313129.rbf
c:\recycler\NPROTECT\00313130.rbf
c:\recycler\NPROTECT\00313131.rbf
c:\recycler\NPROTECT\00313132.rbf
c:\recycler\NPROTECT\00313133.rbf
c:\recycler\NPROTECT\00313134.rbf
c:\recycler\NPROTECT\00313135.rbf
c:\recycler\NPROTECT\00313136.rbf
c:\recycler\NPROTECT\00313137.rbf
c:\recycler\NPROTECT\00313138.rbf
c:\recycler\NPROTECT\00313139.rbf
c:\recycler\NPROTECT\00313140.rbf
c:\recycler\NPROTECT\00313141.rbf
c:\recycler\NPROTECT\00313142.rbf
c:\recycler\NPROTECT\00313143.rbf
c:\recycler\NPROTECT\00313144.rbf
c:\recycler\NPROTECT\00313145.rbf
c:\recycler\NPROTECT\00313146.rbf
c:\recycler\NPROTECT\00313147.rbs
c:\recycler\NPROTECT\00313148.ipi
c:\recycler\NPROTECT\00313149.msi
c:\recycler\NPROTECT\00313151.Dat
c:\recycler\NPROTECT\00313152.rbf
c:\recycler\NPROTECT\00313153.rbf
c:\recycler\NPROTECT\00313154.rbf
c:\recycler\NPROTECT\00313155.rbf
c:\recycler\NPROTECT\00313156.rbf
c:\recycler\NPROTECT\00313157.rbf
c:\recycler\NPROTECT\00313158.rbf
c:\recycler\NPROTECT\00313159.rbf
c:\recycler\NPROTECT\00313160.rbf
c:\recycler\NPROTECT\00313161.rbf
c:\recycler\NPROTECT\00313162.rbf
c:\recycler\NPROTECT\00313163.rbf
c:\recycler\NPROTECT\00313164.rbf
c:\recycler\NPROTECT\00313165.rbf
c:\recycler\NPROTECT\00313166.rbf
c:\recycler\NPROTECT\00313167.rbf
c:\recycler\NPROTECT\00313168.rbs
c:\recycler\NPROTECT\00313169.ipi
c:\recycler\NPROTECT\00313170.msi
c:\recycler\NPROTECT\00313172.rbf
c:\recycler\NPROTECT\00313173.rbf
c:\recycler\NPROTECT\00313174.rbf
c:\recycler\NPROTECT\00313175.rbf
c:\recycler\NPROTECT\00313176.rbf
c:\recycler\NPROTECT\00313177.rbf
c:\recycler\NPROTECT\00313178.rbf
c:\recycler\NPROTECT\00313179.rbf
c:\recycler\NPROTECT\00313180.rbf
c:\recycler\NPROTECT\00313181.rbf
c:\recycler\NPROTECT\00313182.rbf
c:\recycler\NPROTECT\00313183.rbf
c:\recycler\NPROTECT\00313184.rbf
c:\recycler\NPROTECT\00313185.rbf
c:\recycler\NPROTECT\00313186.rbf
c:\recycler\NPROTECT\00313187.rbf
c:\recycler\NPROTECT\00313188.rbf
c:\recycler\NPROTECT\00313189.rbf
c:\recycler\NPROTECT\00313190.rbf
c:\recycler\NPROTECT\00313191.rbf
c:\recycler\NPROTECT\00313192.rbf
c:\recycler\NPROTECT\00313193.rbf
c:\recycler\NPROTECT\00313194.rbf
c:\recycler\NPROTECT\00313195.rbf
c:\recycler\NPROTECT\00313196.rbf
c:\recycler\NPROTECT\00313197.rbf
c:\recycler\NPROTECT\00313198.rbf
c:\recycler\NPROTECT\00313199.rbf
c:\recycler\NPROTECT\00313200.rbf
c:\recycler\NPROTECT\00313201.rbf
c:\recycler\NPROTECT\00313202.rbf
c:\recycler\NPROTECT\00313203.rbf
c:\recycler\NPROTECT\00313204.rbf
c:\recycler\NPROTECT\00313205.rbf
c:\recycler\NPROTECT\00313206.rbf
c:\recycler\NPROTECT\00313207.rbs
c:\recycler\NPROTECT\00313208.ipi
c:\recycler\NPROTECT\00313209.msi
c:\recycler\NPROTECT\00313211.rbs
c:\recycler\NPROTECT\00313212.ipi
c:\recycler\NPROTECT\00313213.msi
c:\recycler\NPROTECT\00313214.EXE
c:\recycler\NPROTECT\00313215.rbs
c:\recycler\NPROTECT\00313216.ipi
c:\recycler\NPROTECT\00313217.msi
c:\recycler\NPROTECT\00313218.msi
c:\recycler\NPROTECT\00313232.DLL
c:\recycler\NPROTECT\00313233.SYS
c:\recycler\NPROTECT\00313234.SPM
c:\recycler\NPROTECT\00313235.GRD
c:\recycler\NPROTECT\00313236.SIG
c:\recycler\NPROTECT\00313237.INF
c:\recycler\NPROTECT\00313238.CAT
c:\recycler\NPROTECT\00313240.lo_
c:\recycler\NPROTECT\00313241.msi
c:\recycler\NPROTECT\00313243.dll
c:\recycler\NPROTECT\00313244.sig
c:\recycler\NPROTECT\00313245.spm
c:\recycler\NPROTECT\00313246.grd
c:\recycler\NPROTECT\00313247.dll
c:\recycler\NPROTECT\00313248.dll
c:\recycler\NPROTECT\00313249.dll
c:\recycler\NPROTECT\00313250.dll
c:\recycler\NPROTECT\00313251.dll
c:\recycler\NPROTECT\00313252.dll
c:\recycler\NPROTECT\00313253.dll
c:\recycler\NPROTECT\00313254.dll
c:\recycler\NPROTECT\00313255.dll
c:\recycler\NPROTECT\00313256.dll
c:\recycler\NPROTECT\00313257.dll
c:\recycler\NPROTECT\00313258.dll
c:\recycler\NPROTECT\00313259.dll
c:\recycler\NPROTECT\00313260.dll
c:\recycler\NPROTECT\00313261.dll
c:\recycler\NPROTECT\00313262.dll
c:\recycler\NPROTECT\00313263.dll
c:\recycler\NPROTECT\00313264.dll
c:\recycler\NPROTECT\00313265.dll
c:\recycler\NPROTECT\00313266.dll
c:\recycler\NPROTECT\00313267.DLL
c:\recycler\NPROTECT\00313268.dll
c:\recycler\NPROTECT\00313269.dll
c:\recycler\NPROTECT\00313270.dll
c:\recycler\NPROTECT\00313271.dll
c:\recycler\NPROTECT\00313272.exe
c:\recycler\NPROTECT\00313273.dll
c:\recycler\NPROTECT\00313274.dll
c:\recycler\NPROTECT\00313275.dll
c:\recycler\NPROTECT\00313276.dll
c:\recycler\NPROTECT\00313277.dll
c:\recycler\NPROTECT\00313278.dll
c:\recycler\NPROTECT\00313279.exe
c:\recycler\NPROTECT\00313280.dll
c:\recycler\NPROTECT\00313281.dll
c:\recycler\NPROTECT\00313282.dll
c:\recycler\NPROTECT\00313283.dll
c:\recycler\NPROTECT\00313284.exe
c:\recycler\NPROTECT\00313285.dll
c:\recycler\NPROTECT\00313286.CHM
c:\recycler\NPROTECT\00313287.exe
c:\recycler\NPROTECT\00313288.dll
c:\recycler\NPROTECT\00313289.exe
c:\recycler\NPROTECT\00313290.dll
c:\recycler\NPROTECT\00313291.dll
c:\recycler\NPROTECT\00313292.rbs
c:\recycler\NPROTECT\00313293.ipi
c:\recycler\NPROTECT\00313294.msi
c:\recycler\NPROTECT\00313300.rbs
c:\recycler\NPROTECT\00313301.ipi
c:\recycler\NPROTECT\00313302.msi
c:\recycler\NPROTECT\00313303.EXE
c:\recycler\NPROTECT\00313308.ORI
c:\recycler\NPROTECT\00313317.JOB
c:\recycler\NPROTECT\00313318.msi
c:\recycler\NPROTECT\00313319.ICO
c:\recycler\NPROTECT\00313320.ico
c:\recycler\NPROTECT\00313321.msi
c:\recycler\NPROTECT\00313322.msi
c:\recycler\NPROTECT\00313323.EXE
c:\recycler\NPROTECT\00313324.ico
c:\recycler\NPROTECT\00313325.ico
c:\recycler\NPROTECT\00313326.exe
c:\recycler\NPROTECT\00313327.EXE
c:\recycler\NPROTECT\00313328.EXE
c:\recycler\NPROTECT\00313329.EXE
c:\recycler\NPROTECT\00313330.txt
c:\recycler\NPROTECT\00313331.LOC
c:\recycler\NPROTECT\00313332.LOC
c:\recycler\NPROTECT\00313333.LOC
c:\recycler\NPROTECT\00313334.txt
c:\recycler\NPROTECT\00313335.loc
c:\recycler\NPROTECT\00313336.loc
c:\recycler\NPROTECT\00313337.TXT
c:\recycler\NPROTECT\00313338.LOC
c:\recycler\NPROTECT\00313339.LOC
c:\recycler\NPROTECT\00313340.LOC
c:\recycler\NPROTECT\00313341.dat
c:\recycler\NPROTECT\00313342.EXE
c:\recycler\NPROTECT\00313343.EXE
c:\recycler\NPROTECT\00313344.EXE
c:\recycler\NPROTECT\00313345.dll
c:\recycler\NPROTECT\00313346.exe
c:\recycler\NPROTECT\00313347.EXE
c:\recycler\NPROTECT\00313348.EXE
c:\recycler\NPROTECT\00313349.dat
c:\recycler\NPROTECT\00313350.INF
c:\recycler\NPROTECT\00313351.dll
c:\recycler\NPROTECT\00313352.DLL
c:\recycler\NPROTECT\00313353.txt
c:\recycler\NPROTECT\00313354.exe
c:\recycler\NPROTECT\00313355.DLL
c:\recycler\NPROTECT\00313356.TXT
c:\recycler\NPROTECT\00313357.DLL
c:\recycler\NPROTECT\00313358.CPL
c:\recycler\NPROTECT\00313359.DLL
c:\recycler\NPROTECT\00313360.DLL
c:\recycler\NPROTECT\00313361.LIV
c:\recycler\NPROTECT\00313362.DLL
c:\recycler\NPROTECT\00313363.LNK
c:\recycler\NPROTECT\00313364.LNK
c:\recycler\NPROTECT\00313365.LNK
c:\recycler\NPROTECT\00313366.LNK
c:\recycler\NPROTECT\00313367.LNK
c:\recycler\NPROTECT\00313368.LNK
c:\recycler\NPROTECT\00313369.LNK
c:\recycler\NPROTECT\00313370.LNK
c:\recycler\NPROTECT\00313371.LNK
c:\recycler\NPROTECT\00313372.LNK
c:\recycler\NPROTECT\00313373.LNK
c:\recycler\NPROTECT\00313374.LNK
c:\recycler\NPROTECT\00313375.LNK
c:\recycler\NPROTECT\00313376.LNK
c:\recycler\NPROTECT\00313377.CHM
c:\recycler\NPROTECT\00313378.chm
c:\recycler\NPROTECT\00313379.dat
c:\recycler\NPROTECT\00313380.GRD
c:\recycler\NPROTECT\00313381.SIG
c:\recycler\NPROTECT\00313382.SPM
c:\recycler\NPROTECT\00313383.GRD
c:\recycler\NPROTECT\00313384.SIG
c:\recycler\NPROTECT\00313385.SPM
c:\recycler\NPROTECT\00313386.LIV
c:\recycler\NPROTECT\00313387.LIV
c:\recycler\NPROTECT\00313388.dll
c:\recycler\NPROTECT\00313389.exe
c:\recycler\NPROTECT\00313390.dll
c:\recycler\NPROTECT\00313391.dll
c:\recycler\NPROTECT\00313392.dll
c:\recycler\NPROTECT\00313393.dll
c:\recycler\NPROTECT\00313394.dll
c:\recycler\NPROTECT\00313395.HLP
c:\recycler\NPROTECT\00313396.dll
c:\recycler\NPROTECT\00313397.dll
c:\recycler\NPROTECT\00313398.dll
c:\recycler\NPROTECT\00313399.dll
c:\recycler\NPROTECT\00313400.dll
c:\recycler\NPROTECT\00313401.dll
c:\recycler\NPROTECT\00313402.exe
c:\recycler\NPROTECT\00313403.EXE
c:\recycler\NPROTECT\00313404.dll
c:\recycler\NPROTECT\00313405.exe
c:\recycler\NPROTECT\00313406.gif
c:\recycler\NPROTECT\00313407.chm
c:\recycler\NPROTECT\00313408.DLL
c:\recycler\NPROTECT\00313409.DLL
c:\recycler\NPROTECT\00313410.SYS
c:\recycler\NPROTECT\00313411.SYS
c:\recycler\NPROTECT\00313412.LNK
c:\recycler\NPROTECT\00313413.dll
c:\recycler\NPROTECT\00313414.dll
c:\recycler\NPROTECT\00313415.DLL
c:\recycler\NPROTECT\00313416.EXE
c:\recycler\NPROTECT\00313417.DLL
c:\recycler\NPROTECT\00313418.DLL
c:\recycler\NPROTECT\00313419.dll
c:\recycler\NPROTECT\00313420.dll
c:\recycler\NPROTECT\00313421.exe
c:\recycler\NPROTECT\00313422.DLL
c:\recycler\NPROTECT\00313423.DLL
c:\recycler\NPROTECT\00313424.DLL
c:\recycler\NPROTECT\00313425.dll
c:\recycler\NPROTECT\00313426.DLL
c:\recycler\NPROTECT\00313427.exe
c:\recycler\NPROTECT\00313428.wav
c:\recycler\NPROTECT\00313429.wav
c:\recycler\NPROTECT\00313430.DLL
c:\recycler\NPROTECT\00313431.dll
c:\recycler\NPROTECT\00313432.dll
c:\recycler\NPROTECT\00313433.DLL
c:\recycler\NPROTECT\00313434.DLL
c:\recycler\NPROTECT\00313435.EXE
c:\recycler\NPROTECT\00313436.HLP
c:\recycler\NPROTECT\00313437.exe
c:\recycler\NPROTECT\00313438.DLL
c:\recycler\NPROTECT\00313439.dll
c:\recycler\NPROTECT\00313440.dll
c:\recycler\NPROTECT\00313441.dll
c:\recycler\NPROTECT\00313442.dll
c:\recycler\NPROTECT\00313443.dll
c:\recycler\NPROTECT\00313444.dll
c:\recycler\NPROTECT\00313445.dll
c:\recycler\NPROTECT\00313446.exe
c:\recycler\NPROTECT\00313447.dll
c:\recycler\NPROTECT\00313448.dll
c:\recycler\NPROTECT\00313449.LIV
c:\recycler\NPROTECT\00313450.DLL
c:\recycler\NPROTECT\00313451.CAT
c:\recycler\NPROTECT\00313452.INF
c:\recycler\NPROTECT\00313453.SYS
c:\recycler\NPROTECT\00313456.edb
c:\recycler\NPROTECT\NPROTECT.LOG
c:\windows\system32\AutoRun.inf
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((( Files Created from 2010-01-07 to 2010-02-07 )))))))))))))))))))))))))))))))
.

2010-02-07 17:25 . 2010-02-07 17:25 -------- d-----w- c:\program files\Trend Micro
2010-02-06 03:24 . 2009-11-12 17:03 59664 --s---w- c:\windows\system32\drivers\TfSysMon.sys
2010-02-06 03:24 . 2009-11-12 17:03 51984 --s---w- c:\windows\system32\drivers\TfFsMon.sys
2010-02-06 03:24 . 2009-11-12 17:03 33552 --s---w- c:\windows\system32\drivers\TfNetMon.sys
2010-02-06 03:21 . 2010-02-06 03:21 -------- d-----w- C:\0932b493950346e6cd5d
2010-02-06 02:45 . 2010-02-06 02:45 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\RapidSolution
2010-02-06 02:45 . 2010-02-06 02:45 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Threat Expert
2010-02-06 01:45 . 2010-02-06 01:45 -------- d-----w- c:\program files\ESET
2010-02-05 03:33 . 2010-02-05 03:33 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Threat Expert
2010-02-05 03:08 . 2010-02-07 19:25 -------- dc--a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-05 03:01 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-02-05 03:01 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-02-05 03:01 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2010-02-05 03:01 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-02-05 03:01 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-02-05 03:00 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-02-05 02:59 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-02-04 20:46 . 2009-08-07 02:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-02-04 20:07 . 2010-02-04 20:07 -------- dc----w- c:\documents and settings\Administrator.DESKTOP\Application Data\Malwarebytes
2010-02-04 20:02 . 2010-02-04 20:02 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-02-04 20:02 . 2010-02-04 20:02 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-03 07:32 . 2010-02-05 03:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-03 07:32 . 2010-02-05 03:24 -------- dc----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-03 07:19 . 2010-02-03 07:19 -------- d-----w- C:\!KillBox

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 18:39 . 2010-02-05 03:09 -------- d-----w- c:\program files\Spyware Doctor
2010-02-07 07:08 . 2010-01-07 00:53 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2010-02-06 03:24 . 2010-02-05 03:09 -------- dc----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-02-05 03:09 . 2010-02-05 03:09 -------- d-----w- c:\program files\Common Files\PC Tools
2010-02-05 03:09 . 2010-02-05 03:09 -------- d-----w- c:\documents and settings\Owner\Application Data\PC Tools
2010-02-03 18:02 . 2008-11-25 22:10 -------- d-----w- c:\program files\Curse
2010-02-03 18:01 . 2009-09-30 21:52 -------- d-----w- c:\program files\Axis Communications
2010-02-03 07:17 . 2008-10-12 04:15 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-03 07:06 . 2008-09-14 15:32 -------- d-----w- c:\program files\HP
2010-01-30 00:30 . 2009-10-12 03:12 -------- d-----w- c:\program files\UltimateBet
2010-01-21 06:23 . 2008-07-14 23:02 -------- d-----w- c:\program files\Rhapsody
2010-01-15 01:40 . 2007-01-18 23:35 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-07 00:45 . 2010-01-07 00:45 -------- d-----w- c:\program files\Impressions Games
2010-01-05 10:00 . 2004-08-04 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-04 12:00 17408 ------w- c:\windows\system32\corpol.dll
2009-12-13 21:15 . 2009-10-04 19:01 -------- d-----w- c:\program files\3DO
2009-11-21 15:51 . 2004-08-04 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-11 07:27 . 2009-08-06 23:55 292120 -c--a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\YouTube.dll
2009-11-10 17:28 . 2010-02-05 03:09 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-11-10 17:28 . 2010-02-05 03:09 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-11-10 17:28 . 2010-02-05 03:09 1640400 ----a-w- c:\windows\PCTBDCore.dll
2009-11-10 17:26 . 2010-02-05 03:09 767952 ----a-w- c:\windows\BDTSupport.dll
2008-01-29 21:15 . 2008-06-16 04:28 28 -c--a-w- c:\program files\wizard.txt
2004-09-10 20:40 . 2004-09-10 20:40 75264 ----a-w- c:\program files\DECCHECK.exe
2004-09-10 20:40 . 2004-09-10 20:40 5970 ----a-w- c:\program files\eula.txt
2008-05-03 02:51 . 2008-05-03 02:49 24 --sh--w- c:\windows\S82CD903D.tmp
2007-07-02 21:29 . 2007-07-02 21:29 32 -csha-w- c:\windows\{0F16EDB4-A16D-4E42-9BE9-CD80AE6C91BD}.dat
2007-07-02 21:27 . 2007-07-02 21:27 32 -csha-w- c:\windows\{1A1AF3A7-D2F5-4F91-AF81-51D8F7BE2E53}.dat
2007-07-02 21:27 . 2007-07-02 21:27 32 -csha-w- c:\windows\{216FEB5C-8984-44BC-83B1-C64EA72A5389}.dat
2007-07-02 21:27 . 2007-07-02 21:27 32 -csha-w- c:\windows\{2236C801-1BAB-466F-86B5-EE1D16D90761}.dat
2008-01-18 07:28 . 2008-01-18 07:28 32 -csha-w- c:\windows\{2B0640E6-62AE-4F2F-9BF5-98D9FB676E27}.dat
2007-07-03 00:22 . 2007-07-03 00:22 32 -csha-w- c:\windows\{4C68B740-B234-4CE1-ABF4-36F03ACBAD9D}.dat
2007-07-02 21:29 . 2007-07-02 21:29 32 -csha-w- c:\windows\{4D7A75C5-EDF6-4D95-AF02-9739226A29EA}.dat
2007-07-02 21:28 . 2007-07-02 21:28 32 -csha-w- c:\windows\{61870425-F2C2-44E0-B417-5287C391DB9D}.dat
2008-01-18 07:26 . 2008-01-18 07:26 32 -csha-w- c:\windows\{9CDC3D43-F805-4ED8-923C-B1E3AFB738EC}.dat
2007-07-03 00:21 . 2007-07-03 00:21 32 -csha-w- c:\windows\{B7142F26-B19B-4492-910F-2CF1F6A81567}.dat
2007-07-03 00:22 . 2007-07-03 00:22 32 -csha-w- c:\windows\{C16D5612-96D8-46A5-9DA5-8AC021115816}.dat
2008-01-18 07:27 . 2008-01-18 07:27 32 -csha-w- c:\windows\{C1FC925B-5EA4-4EEF-9534-2C22CEB5BF38}.dat
2007-07-02 21:25 . 2007-07-02 21:25 32 -csha-w- c:\windows\{FED51F6A-EEF6-407B-9EA5-1234129F03D5}.dat
2007-07-03 00:22 . 2007-07-03 00:22 32 --sha-w- c:\windows\system32\{04F37058-206E-4D55-9B32-8EED05DEBFC8}.dat
2007-07-03 00:21 . 2007-07-03 00:21 32 --sha-w- c:\windows\system32\{13A97F63-E5CC-4BB8-8E86-00E206D8F1E3}.dat
2007-07-03 00:22 . 2007-07-03 00:22 32 --sha-w- c:\windows\system32\{1802357F-F904-4A29-870A-E8EC6E8C43FD}.dat
2007-07-02 21:27 . 2007-07-02 21:27 32 --sha-w- c:\windows\system32\{19DA67BC-5689-48B1-A7EB-38121F15D0BA}.dat
2007-07-02 21:25 . 2007-07-02 21:25 32 --sha-w- c:\windows\system32\{1C72FF99-24ED-4B7F-B669-1408400BCE40}.dat
2008-01-18 07:27 . 2008-01-18 07:27 32 --sha-w- c:\windows\system32\{2D20CCD9-A74B-4EF8-940F-340AFE054133}.dat
2007-07-02 21:29 . 2007-07-02 21:29 32 --sha-w- c:\windows\system32\{68A5E2BA-B30F-4786-A7D0-CB5AAF8D2785}.dat
2008-01-18 07:28 . 2008-01-18 07:28 32 --sha-w- c:\windows\system32\{78ABEB36-E4A8-4A70-B422-F9356C1E1768}.dat
2008-01-18 07:26 . 2008-01-18 07:26 32 --sha-w- c:\windows\system32\{8E7D4F4D-609A-488F-A946-5A8F9ACD95B6}.dat
2007-07-02 21:28 . 2007-07-02 21:28 32 --sha-w- c:\windows\system32\{C09DF030-FBB6-4C27-AF4B-DD9C0D3EB6A6}.dat
2007-07-02 21:27 . 2007-07-02 21:27 32 --sha-w- c:\windows\system32\{C862BD8B-F92F-4561-BF31-8537857BB952}.dat
2007-07-02 21:27 . 2007-07-02 21:27 32 --sha-w- c:\windows\system32\{F29933C1-6452-468D-8B5B-94867E0E0FA5}.dat
2007-07-02 21:29 . 2007-07-02 21:29 32 --sha-w- c:\windows\system32\{F3D8C895-48E0-4C78-951B-3D1DF8933362}.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 23:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-05 81920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-09-30 155648]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-24 1657448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-28 13918208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-28 86016]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
Launcher.exe [2008-5-13 157000]

c:\documents and settings\Administrator.DESKTOP\Start Menu\Programs\Startup\
Launcher.exe [2008-5-13 157000]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-9-7 157000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 15:58 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 09:42 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EZ-DUB Finder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EZ-DUB Finder.lnk
backup=c:\windows\pss\EZ-DUB Finder.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 22:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 08:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
2009-12-11 18:16 2043160 ----a-w- c:\progra~1\AVG\AVG8\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
2002-04-03 08:01 135264 ----a-w- c:\program files\Creative\SBLive\Diagnostics\diagent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-12 04:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2005-09-30 08:46 155648 ----a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 23:07 2260480 ------w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 08:00 90112 -c--a-w- c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Speed Disk service"=2 (0x2)
"usnjsvc"=3 (0x3)
"wuauserv"=2 (0x2)
"PLFlash DeviceIoControl Service"=2 (0x2)
"ose"=3 (0x3)
"LexBceS"=2 (0x2)
"gusvc"=2 (0x2)
"getPlus(R) Helper"=3 (0x3)
"FontCache3.0.0.0"=3 (0x3)
"CiSvc"=3 (0x3)
"iPodService"=3 (0x3)
"UleadBurningHelper"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Netscape\\Netscape\\Netscp.exe"=

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2/4/2010 8:09 PM 207792]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2/5/2010 8:24 PM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2/5/2010 8:24 PM 59664]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/26/2008 12:23 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/26/2008 12:23 PM 108552]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2/4/2010 8:09 PM 233136]
R1 SSHDRV60;SSHDRV60;c:\windows\system32\drivers\SSHDRV60.sys [1/1/2007 1:50 PM 36864]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/4/2008 7:08 AM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/4/2008 7:08 AM 297752]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2/4/2010 8:09 PM 112592]
S3 iMSPQMn;iMSPQMn;\??\c:\docume~1\Owner\LOCALS~1\Temp\iMSPQMn.sys --> c:\docume~1\Owner\LOCALS~1\Temp\iMSPQMn.sys [?]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2/4/2010 8:09 PM 70408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/4/2010 8:09 PM 359624]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2/5/2010 8:24 PM 33552]
S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/24/2009 8:35 PM 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{969B3B70-8765-11D5-9809-0050BACBF861}]
2010-01-05 10:00 124928 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2009-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-25 03:35]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.southwestsafari.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &ieSpell Options - d:\program files d\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - d:\program files d\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://d:\program files d\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://d:\program files d\ieSpell\wikipedia.HTM
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} - hxxp://alancraigmauirealestate.viewnetcam.com/kxhcm10.ocx
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://66.91.147.106:8010/activex/AMC.cab
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-DVDLauncher - d:\program files d\CyberLink\PowerDVD\DVDLauncher.exe
MSConfigStartUp-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
AddRemove-AnyDVD - d:\program files\SlySoft\AnyDVD\AnyDVD-uninst.exe
AddRemove-ieSpell - d:\program files d\ieSpell\uninst.exe
AddRemove-TOPO! - c:\program files\Topo\Uninst.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-07 12:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1715567821-117609710-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(660)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(3572)
c:\windows\system32\WININET.dll
c:\program files\NVIDIA Corporation\nView\nview.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2010-02-07 12:35:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-07 19:34

Pre-Run: 19,611,074,560 bytes free
Post-Run: 19,800,297,472 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 806EA9376064D3D931C47E58554A1AC1

View user profile

4 Re: Please help me remove Searhcmagnified.com on Sun Feb 07, 2010 4:22 pm

Hi again. Please do these steps in order.

1. Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.


2. Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer:

http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial

Post the log from SUPERAntiSpyware when you've accomplished that.

4. Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


5. Post the following in your next reply:
  • MBAM log
  • SAS log
  • ESET log

And, please tell me how your computer is doing.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

5 MBAM log - no threats detected on Mon Feb 08, 2010 3:23 pm

Malwarebytes' Anti-Malware 1.44
Database version: 3704
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/8/2010 8:13:15 AM
mbam-log-2010-02-08 (08-13-15).txt

Scan type: Full Scan (C:\|)
Objects scanned: 245727
Time elapsed: 1 hour(s), 22 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

View user profile

6 Re: Please help me remove Searhcmagnified.com on Mon Feb 08, 2010 4:46 pm

Post the two others when ready.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

7 SuperAntiSpyware log below. on Tue Feb 09, 2010 12:47 am

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/08/2010 at 03:29 PM

Application Version : 4.33.1000

Core Rules Database Version : 4566
Trace Rules Database Version: 2378

Scan type : Complete Scan
Total Scan Time : 01:03:10

Memory items scanned : 395
Memory threats detected : 0
Registry items scanned : 6457
Registry threats detected : 0
File items scanned : 31929
File threats detected : 3

Trojan.Agent/Gen-Nullo[Short]
C:\PROGRAM FILES\NETSCAPE\NETSCAPE\NSLDAP32V50.DLL
C:\PROGRAM FILES\NETSCAPE\NETSCAPE\PLUGINS\NPJPI141_02.DLL
C:\PROGRAM FILES\NETSCAPE\NETSCAPE\PLUGINS\NPVIEWPOINT.DLL

View user profile

8 Re: Please help me remove Searhcmagnified.com on Tue Feb 09, 2010 8:17 am

Please download SpiderKill by DragonMaster Jay and save it to your Desktop.
  • Right-click on SpiderKill.zip and click Extract All. Follow the prompts and read carefully, to save it to your Desktop.
  • Double-click on the SpiderKill folder, and then double-click on SpiderKill.bat and follow all the prompts in the program.
  • Within a minute, it will save its log titled SpiderKill.txt. Please post that in your next reply. You may have to use two or three posts to be able to fit the information in.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

9 ESET log on Tue Feb 09, 2010 12:08 pm

I've run ESET, but I've not been able to find its log.

I've downloaded SpiderKill. Will run it after work. Thank you.

No changes in computer yet.

View user profile

10 ESET log below. on Tue Feb 09, 2010 12:58 pm

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=7.00.6000.16762 (vista_gdr.081013-1507)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=49ef6dfd98bd804cb9e375a87e9d8fa6
# end=stopped
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-02-06 02:13:35
# local_time=2010-02-05 07:13:35 (-0700, US Mountain Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1024 16777175 100 0 43995195 43995195 0 0
# compatibility_mode=2560 16777215 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=5404
# found=0
# cleaned=0
# scan_time=1470
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=49ef6dfd98bd804cb9e375a87e9d8fa6
# end=stopped
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-02-08 08:41:54
# local_time=2010-02-08 01:41:54 (-0700, US Mountain Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 11142 11142 0 0
# compatibility_mode=1024 16777175 100 0 44235299 44235299 0 0
# compatibility_mode=2560 16777175 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=10269
# found=0
# cleaned=0
# scan_time=666
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=49ef6dfd98bd804cb9e375a87e9d8fa6
# end=stopped
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-02-09 05:49:26
# local_time=2010-02-08 10:49:26 (-0700, US Mountain Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 44638 44638 0 0
# compatibility_mode=1024 16777175 100 0 44268795 44268795 0 0
# compatibility_mode=2560 16777175 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=1288
# found=0
# cleaned=0
# scan_time=22
ESETSmartInstaller@High as downloader log:
all ok
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=49ef6dfd98bd804cb9e375a87e9d8fa6
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-02-09 09:08:58
# local_time=2010-02-09 02:08:58 (-0700, US Mountain Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 44730 44730 0 0
# compatibility_mode=1024 16777175 100 0 44268887 44268887 0 0
# compatibility_mode=2560 16777175 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=128111
# found=1
# cleaned=1
# scan_time=11901
C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\1ao8dlll.slt\Mail\pop3.domain-mail-2.com\Trash multiple threats (contained infected files) 00000000000000000000000000000000 C

View user profile

11 Re: Please help me remove Searhcmagnified.com on Tue Feb 09, 2010 1:01 pm

Ok. Post the SpiderKill log when ready.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

12 SpiderKill log below. on Wed Feb 10, 2010 1:33 am

SpiderKill by DragonMaster Jay ( Oct 2009 )


Microsoft Windows XP [Version 5.1.2600]

********************Drivers list********************


Volume in drive C has no label.
Volume Serial Number is 083C-CBFB

Directory of C:\Windows\System32\Drivers

02/08/2010 02:29 AM .
02/08/2010 02:29 AM ..
04/15/2003 10:39 AM 11,319 a302.sys
04/15/2003 10:39 AM 29,239 a303.sys
04/15/2003 10:40 AM 46,647 a304.sys
04/15/2003 10:40 AM 11,831 a305.sys
04/15/2003 10:40 AM 16,439 a306.sys
04/15/2003 10:40 AM 21,559 a307.sys
04/15/2003 10:40 AM 10,807 a308.sys
04/15/2003 10:40 AM 25,655 a309.sys
04/15/2003 10:40 AM 33,335 a310.sys
04/15/2003 10:40 AM 32,823 a311.sys
04/15/2003 10:41 AM 37,431 a313.sys
04/15/2003 10:41 AM 10,807 a314.sys
04/13/2008 11:36 AM 187,776 acpi.sys
08/04/2004 05:00 AM 11,648 acpiec.sys
04/13/2008 05:11 PM 4,255 adv01nt5.dll
04/13/2008 05:11 PM 3,967 adv02nt5.dll
04/13/2008 05:11 PM 3,615 adv05nt5.dll
04/13/2008 05:11 PM 3,647 adv07nt5.dll
04/13/2008 05:11 PM 3,135 adv08nt5.dll
04/13/2008 05:11 PM 3,711 adv09nt5.dll
04/13/2008 05:11 PM 3,775 adv11nt5.dll
04/01/2002 01:15 PM 4,816 aeaudio.sys
04/13/2008 09:39 AM 142,592 aec.sys
08/14/2008 03:04 AM 138,496 afd.sys
04/13/2008 11:36 AM 42,368 agp440.sys
04/13/2008 11:36 AM 44,928 agpcpq.sys
04/13/2008 11:36 AM 42,752 alim1541.sys
04/13/2008 11:36 AM 43,008 amdagp.sys
04/13/2008 11:31 AM 37,376 amdk6.sys
04/13/2008 11:31 AM 37,760 amdk7.sys
12/19/2007 01:05 PM 97,216 AnyDVD.sys
04/13/2008 11:51 AM 60,800 arp1394.sys
08/14/2002 03:03 PM 17,005 ASPI32.SYS
04/13/2008 11:57 AM 14,336 asyncmac.sys
04/13/2008 11:40 AM 96,512 atapi.sys
08/03/2004 10:29 PM 56,623 ati1btxx.sys
08/03/2004 10:29 PM 11,615 ati1mdxx.sys
08/03/2004 10:29 PM 12,047 ati1pdxx.sys
08/03/2004 10:29 PM 30,671 ati1raxx.sys
08/03/2004 10:29 PM 63,663 ati1rvxx.sys
08/03/2004 10:29 PM 26,367 ati1snxx.sys
08/03/2004 10:29 PM 21,343 ati1ttxx.sys
08/03/2004 10:29 PM 36,463 ati1tuxx.sys
08/03/2004 10:29 PM 29,455 ati1xbxx.sys
08/03/2004 10:29 PM 34,735 ati1xsxx.sys
08/03/2004 10:29 PM 327,040 ati2mtaa.sys
08/03/2004 10:29 PM 701,440 ati2mtag.sys
08/03/2004 10:29 PM 57,856 atinbtxx.sys
08/03/2004 10:29 PM 13,824 atinmdxx.sys
08/03/2004 10:29 PM 14,336 atinpdxx.sys
08/03/2004 10:29 PM 52,224 atinraxx.sys
08/03/2004 10:29 PM 104,960 atinrvxx.sys
08/03/2004 10:29 PM 28,672 atinsnxx.sys
08/03/2004 10:29 PM 13,824 atinttxx.sys
08/03/2004 10:29 PM 73,216 atintuxx.sys
08/03/2004 10:29 PM 31,744 atinxbxx.sys
08/03/2004 10:29 PM 63,488 atinxsxx.sys
07/17/2004 11:36 AM 64,352 ativmc20.cod
04/13/2008 11:51 AM 59,904 atmarpc.sys
08/04/2004 05:00 AM 31,360 atmepvc.sys
04/13/2008 11:51 AM 55,808 atmlane.sys
08/04/2004 05:00 AM 352,256 atmuni.sys
04/13/2008 05:11 PM 21,183 atv01nt5.dll
04/13/2008 05:11 PM 11,359 atv02nt5.dll
04/13/2008 05:11 PM 25,471 atv04nt5.dll
04/13/2008 05:11 PM 14,143 atv06nt5.dll
04/13/2008 05:11 PM 17,279 atv10nt5.dll
08/17/2001 06:59 AM 3,072 audstub.sys
02/09/2010 07:23 AM Avg
08/16/2009 08:58 AM 335,240 avgldx86.sys
08/16/2009 08:58 AM 27,784 avgmfx86.sys
05/20/2009 05:17 PM 108,552 avgtdix.sys
05/26/2004 03:18 PM 44,928 bcm4sbxp.sys
08/04/2004 05:00 AM 4,224 beep.sys
04/13/2008 11:53 AM 71,552 bridge.sys
04/13/2008 11:46 AM 17,024 bthenum.sys
04/13/2008 11:46 AM 37,888 bthmodem.sys
04/13/2008 11:51 AM 101,120 bthpan.sys
06/13/2008 04:05 AM 272,128 bthport.sys
04/13/2008 11:46 AM 36,480 bthprint.sys
04/13/2008 11:46 AM 18,944 bthusb.sys
08/04/2004 05:00 AM 13,952 cbidf2k.sys
04/13/2008 11:46 AM 17,024 ccdecode.sys
08/04/2004 05:00 AM 18,688 cdaudio.sys
04/13/2008 12:14 PM 63,744 cdfs.sys
04/13/2008 11:40 AM 62,976 cdrom.sys
03/22/2005 01:49 PM 39,904 cercsr6.sys
04/13/2008 05:11 PM 15,423 ch7xxnt5.dll
08/04/2004 05:00 AM 262,528 cinemst2.sys
04/13/2008 12:16 PM 49,536 classpnp.sys
08/04/2004 05:00 AM 11,776 cpqdap01.sys
04/13/2008 11:31 AM 36,736 crusoe.sys
09/22/2003 08:47 AM 178,672 ctoss2k.sys
09/22/2003 08:48 AM 130,192 ctsfm2k.sys
07/17/2004 10:55 PM 129,045 cxthsfs2.cty
09/06/2005 01:04 PM disdn
04/13/2008 11:40 AM 36,352 disk.sys
04/13/2008 11:40 AM 14,208 diskdump.sys
04/13/2008 11:44 AM 799,744 dmboot.sys
04/13/2008 11:44 AM 153,344 dmio.sys
08/04/2004 05:00 AM 5,888 dmload.sys
04/13/2008 11:45 AM 52,864 dmusic.sys
04/13/2008 11:45 AM 60,160 drmk.sys
04/13/2008 11:45 AM 2,944 drmkaud.sys
08/04/2004 05:00 AM 10,496 dxapi.sys
04/13/2008 11:38 AM 71,168 dxg.sys
08/04/2004 05:00 AM 3,328 dxgthk.sys
01/21/1999 10:31 AM 2,259,070 EAPCI2M.ECW
08/07/2007 12:48 PM 25,160 ElbyCDIO.sys
02/07/2010 12:26 PM etc
04/13/2008 12:14 PM 143,744 fastfat.sys
04/13/2008 11:40 AM 27,392 fdc.sys
04/13/2008 11:33 AM 44,544 fips.sys
04/13/2008 11:40 AM 20,480 flpydisk.sys
04/13/2008 11:32 AM 129,792 fltmgr.sys
08/04/2004 05:00 AM 12,160 fsvga.sys
08/04/2004 05:00 AM 7,936 fs_rec.sys
08/04/2004 05:00 AM 125,056 ftdisk.sys
04/13/2008 11:36 AM 46,464 gagp30kx.sys
04/13/2008 11:45 AM 10,624 gameenum.sys
02/02/2005 01:21 AM 14,408 GEARAspiWDM.sys
08/04/2004 05:00 AM 3,440,660 gm.dls
08/04/2004 05:00 AM 646 gmreadme.txt
04/13/2008 09:36 AM 144,384 hdaudbus.sys
04/13/2008 11:46 AM 25,600 hidbth.sys
04/13/2008 11:45 AM 36,864 hidclass.sys
04/13/2008 11:45 AM 19,200 hidir.sys
04/13/2008 11:45 AM 24,960 hidparse.sys
04/13/2008 11:45 AM 10,368 hidusb.sys
03/07/2007 09:20 PM 49,920 HPZid412.sys
03/07/2007 09:20 PM 16,496 HPZipr12.sys
03/07/2007 09:20 PM 21,568 HPZius12.sys
08/03/2004 10:41 PM 220,032 hsfbs2s2.sys
08/03/2004 10:41 PM 685,056 hsfcxts2.sys
08/03/2004 10:41 PM 1,041,536 hsfdpsp2.sys
10/20/2009 09:20 AM 265,728 http.sys
04/13/2008 12:18 PM 52,480 i8042prt.sys
04/15/2003 10:40 AM 78,752 ialmkchw.sys
10/19/2005 08:59 AM 807,998 ialmnt5.sys
04/15/2003 10:40 AM 113,504 ialmsbw.sys
10/15/2002 12:00 AM 13,891 IdeBusDr.sys
10/15/2002 12:00 AM 101,431 IdeChnDr.sys
04/13/2008 11:40 AM 42,112 imapi.sys
04/13/2008 11:40 AM 5,504 intelide.sys
04/13/2008 11:31 AM 36,352 intelppm.sys
04/13/2008 11:53 AM 36,608 ip6fw.sys
08/04/2004 05:00 AM 32,896 ipfltdrv.sys
04/13/2008 11:57 AM 20,864 ipinip.sys
04/13/2008 11:57 AM 152,832 ipnat.sys
04/13/2008 12:19 PM 75,264 ipsec.sys
04/13/2008 11:54 AM 11,264 irenum.sys
04/13/2008 11:36 AM 37,248 isapnp.sys
04/13/2008 11:39 AM 24,576 kbdclass.sys
04/13/2008 11:39 AM 14,592 kbdhid.sys
04/13/2008 11:45 AM 172,416 kmixer.sys
04/13/2008 12:16 PM 141,056 ks.sys
06/24/2009 04:18 AM 92,928 ksecdd.sys
02/29/2008 03:12 AM 20,240 L8042Kbd.sys
02/29/2008 03:12 AM 63,120 L8042mou.Sys
02/29/2008 03:13 AM 35,344 LHidFilt.Sys
02/29/2008 03:13 AM 36,880 LMouFilt.Sys
02/29/2008 03:13 AM 79,120 LMouKE.Sys
02/29/2008 03:13 AM 28,944 LUsbFilt.sys
01/07/2010 04:07 PM 19,160 mbam.sys
01/07/2010 04:07 PM 38,224 mbamswissarmy.sys
08/04/2004 05:00 AM 7,680 mcd.sys
04/13/2008 11:36 AM 63,744 mf.sys
08/04/2004 05:00 AM 4,224 mnmdd.sys
04/13/2008 12:00 PM 30,080 modem.sys
08/17/2001 01:57 PM 16,128 MODEMCSA.sys
04/13/2008 11:39 AM 23,040 mouclass.sys
08/17/2001 01:48 PM 12,160 mouhid.sys
04/13/2008 11:39 AM 42,368 mountmgr.sys
04/13/2008 11:32 AM 180,608 mrxdav.sys
10/24/2008 04:21 AM 455,296 mrxsmb.sys
04/13/2008 11:32 AM 19,072 msfs.sys
04/13/2008 11:56 AM 35,072 msgpc.sys
04/13/2008 11:39 AM 7,552 mskssrv.sys
04/13/2008 11:39 AM 5,376 mspclock.sys
04/13/2008 11:39 AM 4,992 mspqm.sys
04/13/2008 11:36 AM 15,488 mssmbios.sys
04/13/2008 11:39 AM 5,504 mstee.sys
08/03/2004 10:41 PM 126,686 mtlmnt5.sys
08/03/2004 10:41 PM 1,309,184 mtlstrm.sys
08/03/2004 10:29 PM 452,736 mtxparhm.sys
04/13/2008 12:17 PM 105,344 mup.sys
04/13/2008 11:43 AM 12,672 mutohpen.sys
04/13/2008 11:46 AM 85,248 nabtsfec.sys
04/13/2008 12:20 PM 182,656 ndis.sys
04/13/2008 11:46 AM 10,880 ndisip.sys
04/13/2008 11:57 AM 10,112 ndistapi.sys
04/13/2008 11:55 AM 14,592 ndisuio.sys
04/13/2008 12:20 PM 91,520 ndiswan.sys
04/13/2008 11:57 AM 40,576 ndproxy.sys
04/13/2008 11:56 AM 34,688 netbios.sys
04/13/2008 12:21 PM 162,816 netbt.sys
07/17/2004 11:35 AM 67,866 netwlan5.img
04/13/2008 11:51 AM 61,824 nic1394.sys
08/04/2004 05:00 AM 12,032 nikedrv.sys
04/13/2008 11:53 AM 40,320 nmnt.sys
04/13/2008 11:32 AM 30,848 npfs.sys
04/13/2008 12:15 PM 574,976 ntfs.sys
08/03/2004 10:41 PM 180,360 ntmtlfax.sys
08/04/2004 05:00 AM 2,944 null.sys
09/27/2009 04:12 PM 7,655,872 nv4_mini.sys
03/22/2005 01:49 PM 88,960 NvAtaBus.sys
03/22/2005 01:49 PM 68,992 nvraid.sys
08/04/2004 05:00 AM 12,416 nwlnkflt.sys
08/04/2004 05:00 AM 32,512 nwlnkfwd.sys
04/13/2008 11:56 AM 88,320 nwlnkipx.sys
08/04/2004 05:00 AM 63,232 nwlnknb.sys
08/04/2004 05:00 AM 55,936 nwlnkspx.sys
08/22/2001 08:42 AM 13,632 omci.sys
08/04/2004 05:00 AM 3,456 oprghdlr.sys
07/19/2004 11:57 AM 1,329,920 P16X.sys
04/13/2008 11:31 AM 42,752 p3.sys
04/13/2008 11:40 AM 80,128 parport.sys
04/13/2008 11:40 AM 19,712 partmgr.sys
08/04/2004 05:00 AM 6,784 parvdm.sys
04/13/2008 11:36 AM 68,224 pci.sys
08/17/2001 01:51 PM 3,328 pciide.sys
04/13/2008 11:40 AM 24,960 pciidex.sys
04/13/2008 11:36 AM 120,192 pcmcia.sys
09/15/2009 02:12 AM 7,412 PCTAppEvent.cat
10/06/2009 04:31 PM 87,784 PCTAppEvent.sys
09/16/2009 03:20 AM 7,383 pctcore.cat
11/09/2009 11:20 AM 207,792 PCTCore.sys
09/15/2009 02:01 AM 7,387 pctgntdi.cat
10/30/2009 11:11 AM 233,136 pctgntdi.sys
09/15/2009 06:20 AM 7,383 pctplsg.cat
09/03/2009 09:45 AM 70,408 pctplsg.sys
03/05/2003 12:19 PM 15,840 PFMODNT.SYS
04/13/2008 12:19 PM 146,048 portcls.sys
09/16/2002 05:14 PM 4,228 PQNTDRV.sys
04/13/2008 11:31 AM 35,840 processr.sys
04/13/2008 11:56 AM 69,120 psched.sys
08/04/2004 05:00 AM 17,792 ptilink.sys
03/11/2005 03:28 PM 20,640 pxhelp20.sys
08/04/2004 05:00 AM 8,832 rasacd.sys
04/13/2008 12:19 PM 51,328 rasl2tp.sys
04/13/2008 11:57 AM 41,472 raspppoe.sys
04/13/2008 12:19 PM 48,384 raspptp.sys
08/04/2004 05:00 AM 16,512 raspti.sys
08/04/2004 05:00 AM 34,432 rawwan.sys
04/13/2008 12:28 PM 175,744 rdbss.sys
08/04/2004 05:00 AM 4,224 rdpcdd.sys
04/13/2008 11:32 AM 196,224 rdpdr.sys
04/13/2008 05:13 PM 139,656 rdpwd.sys
08/03/2004 10:41 PM 13,776 recagent.sys
04/13/2008 11:40 AM 57,600 redbook.sys
02/15/2007 05:56 PM 11,984 RegKill.sys
04/13/2008 11:46 AM 59,136 rfcomm.sys
08/04/2004 05:00 AM 12,032 rio8drv.sys
08/04/2004 05:00 AM 12,032 riodrv.sys
05/08/2008 07:02 AM 203,136 rmcast.sys
04/13/2008 11:56 AM 30,592 rndismpx.sys
08/04/2004 05:00 AM 5,888 rootmdm.sys
08/03/2004 10:29 PM 166,912 s3gnbm.sys
04/13/2008 11:40 AM 96,384 scsiport.sys
04/13/2008 11:36 AM 79,232 sdbus.sys
04/13/2008 09:39 AM 20,480 secdrv.sys
04/13/2008 11:40 AM 15,744 serenum.sys
04/13/2008 12:15 PM 64,512 serial.sys
04/13/2008 11:40 AM 11,904 sffdisk.sys
04/13/2008 11:40 AM 10,240 sffp_mmc.sys
04/13/2008 11:40 AM 11,008 sffp_sd.sys
04/13/2008 11:40 AM 11,392 sfloppy.sys
04/13/2008 05:12 PM 3,901 siint5.dll
04/13/2008 11:36 AM 40,960 sisagp.sys
04/13/2008 11:46 AM 11,136 slip.sys
08/03/2004 10:41 PM 129,535 slnt7554.sys
08/03/2004 10:41 PM 404,990 slntamr.sys
08/03/2004 10:41 PM 95,424 slnthal.sys
08/03/2004 10:41 PM 13,240 slwdmsup.sys
04/13/2008 11:36 AM 5,888 smbali.sys
08/04/2004 05:00 AM 14,592 smclib.sys
10/28/2002 11:26 AM 3,744 smsens.sys
02/28/2003 09:17 AM 545,024 smwdm.sys
04/13/2008 11:46 AM 25,344 sonydcam.sys
04/13/2008 11:45 AM 6,272 splitter.sys
04/13/2008 11:36 AM 73,472 sr.sys
12/11/2008 03:57 AM 333,952 srv.sys
01/01/2007 01:50 PM 36,864 SSHDRV60.sys
04/13/2008 11:45 AM 49,408 stream.sys
04/13/2008 11:46 AM 15,232 streamip.sys
04/13/2008 11:39 AM 4,352 swenum.sys
04/13/2008 11:45 AM 56,576 swmidi.sys
01/30/2008 07:35 PM 10,740 SYMEVENT.CAT
01/30/2008 07:35 PM 805 SYMEVENT.INF
07/02/2007 02:38 PM 2,397 symlcbrd.sys
04/13/2008 12:15 PM 60,800 sysaudio.sys
04/13/2008 11:40 AM 14,976 tape.sys
01/23/2009 10:49 AM 37,664 tbhsd.sys
06/20/2008 04:51 AM 361,600 tcpip.sys
06/20/2008 04:08 AM 225,856 tcpip6.sys
04/13/2008 12:00 PM 19,072 tdi.sys
04/13/2008 05:13 PM 12,040 tdpipe.sys
04/13/2008 05:13 PM 21,896 tdtcp.sys
04/13/2008 05:13 PM 40,840 termdd.sys
08/04/2004 05:00 AM 51,712 tosdvd.sys
08/04/2004 05:00 AM 21,376 tsbvcap.sys
04/13/2008 11:56 AM 12,288 tunmp.sys
04/13/2008 11:36 AM 44,672 uagp35.sys
04/13/2008 11:32 AM 66,048 udfs.sys
12/22/2004 01:47 PM 27,392 ULCDRHlp.sys
07/14/2008 03:24 PM UMDF
04/13/2008 11:39 AM 384,768 update.sys
04/13/2008 11:56 AM 12,800 usb8023x.sys
04/13/2008 11:45 AM 60,032 USBAUDIO.sys
04/13/2008 11:45 AM 25,600 usbcamd.sys
04/13/2008 11:45 AM 25,728 usbcamd2.sys
04/13/2008 11:45 AM 32,128 usbccgp.sys
08/04/2004 05:00 AM 4,736 usbd.sys
04/13/2008 11:45 AM 30,208 usbehci.sys
04/13/2008 11:45 AM 59,520 usbhub.sys
04/13/2008 11:45 AM 15,872 usbintel.sys
04/13/2008 11:45 AM 143,872 usbport.sys
04/13/2008 11:47 AM 25,856 usbprint.sys
04/13/2008 11:45 AM 15,104 usbscan.sys
04/13/2008 11:45 AM 26,368 usbstor.sys
04/13/2008 11:45 AM 20,608 usbuhci.sys
04/13/2008 11:46 AM 121,984 usbvideo.sys
11/21/2001 02:09 PM 81,796 V4CB0109.SYS
11/24/2001 07:11 PM 81,924 V4CB010B.SYS
05/07/2002 02:44 AM 81,700 V4CB010F.SYS
05/07/2002 02:44 AM 81,700 V4CB0111.SYS
11/24/2001 07:11 PM 81,924 V4CB0113.SYS
11/24/2001 07:11 PM 81,924 V4CB0115.SYS
05/07/2002 02:44 AM 81,700 V4CB0117.SYS
05/07/2002 02:44 AM 81,700 V4CB0119.SYS
05/07/2002 02:44 AM 81,700 V4CB011B.SYS
05/07/2002 02:44 AM 81,700 V4CB011D.SYS
04/15/2003 10:40 AM 20,533 vch.sys
04/13/2008 05:12 PM 11,325 vchnt5.dll
08/04/2004 05:00 AM 58,112 vdmindvd.sys
04/13/2008 11:44 AM 20,992 vga.sys
04/13/2008 11:36 AM 42,240 viaagp.sys
04/13/2008 11:44 AM 81,664 videoprt.sys
04/13/2008 11:41 AM 52,352 volsnap.sys
04/15/2003 10:39 AM 33,335 wa301a.sys
04/15/2003 10:39 AM 33,335 wa301b.sys
04/13/2008 11:43 AM 14,208 wacompen.sys
08/03/2004 10:29 PM 11,807 wadv07nt.sys
08/03/2004 10:29 PM 11,295 wadv08nt.sys
08/03/2004 10:29 PM 11,871 wadv09nt.sys
08/03/2004 10:29 PM 11,935 wadv11nt.sys
04/13/2008 11:57 AM 34,560 wanarp.sys
08/03/2004 10:29 PM 22,271 watv06nt.sys
08/03/2004 10:29 PM 25,471 watv10nt.sys
11/02/2006 07:22 AM 492,000 wdf01000.sys
11/02/2006 07:22 AM 32,224 wdfldr.sys
04/13/2008 12:17 PM 83,072 wdmaud.sys
08/04/2004 05:00 AM 4,352 wmilib.sys
10/18/2006 08:00 PM 38,528 wpdusb.sys
08/04/2004 05:00 AM 12,032 ws2ifsl.sys
04/13/2008 11:46 AM 19,200 wstcodec.sys
09/28/2006 06:55 PM 77,568 WudfPf.sys
09/28/2006 07:00 PM 82,944 WudfRd.sys
08/28/2007 05:05 PM 55,808 xusb21.sys
355 File(s) 41,354,826 bytes

Directory of C:\Windows\System32\Drivers\Avg

02/09/2010 07:23 AM .
02/09/2010 07:23 AM ..
06/04/2008 05:14 PM 6,061,540 avi7.avg
02/09/2010 07:23 AM 55,322,153 incavi.avm
01/20/2010 08:30 AM 142,495 microavi.avg
10/01/2009 11:16 AM 492,629 miniavi.avg
4 File(s) 62,018,817 bytes

Directory of C:\Windows\System32\Drivers\disdn

09/06/2005 01:04 PM .
09/06/2005 01:04 PM ..
0 File(s) 0 bytes

Directory of C:\Windows\System32\Drivers\etc

02/07/2010 12:26 PM .
02/07/2010 12:26 PM ..
02/07/2010 12:26 PM 27 hosts
08/04/2004 05:00 AM 734 hosts.20100203-105741.backup
07/09/2006 11:44 AM 440 hosts.ics
08/04/2004 05:00 AM 3,683 lmhosts.sam
08/04/2004 05:00 AM 407 networks
08/04/2004 05:00 AM 799 protocol
08/04/2004 05:00 AM 7,116 services
7 File(s) 13,206 bytes

Directory of C:\Windows\System32\Drivers\UMDF

07/14/2008 03:24 PM .
07/14/2008 03:24 PM ..
10/18/2006 09:47 PM 671,232 wpdmtpdr.dll
1 File(s) 671,232 bytes

Total Files Listed:
367 File(s) 104,058,081 bytes
14 Dir(s) 19,583,414,272 bytes free


***********************Hidden Drivers********************
Volume in drive C has no label.
Volume Serial Number is 083C-CBFB

Directory of C:\Windows\System32\Drivers

09/03/2008 09:36 AM 0 MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
09/03/2008 09:36 AM 0 Msft_Kernel_LHidFilt_01005.Wdf
09/03/2008 09:36 AM 0 Msft_Kernel_LMouFilt_01005.Wdf
09/03/2008 09:36 AM 0 Msft_Kernel_LUsbFilt_01005.Wdf
10/07/2008 10:44 PM 0 Msft_Kernel_xusb21_01005.Wdf
5 File(s) 0 bytes
0 Dir(s) 19,583,422,464 bytes free


*********************Processes*******************


PROCESS PID PRIO PATH
smss.exe 572 Normal C:\WINDOWS\System32\smss.exe
csrss.exe 624 Normal C:\WINDOWS\system32\csrss.exe
winlogon.exe 648 High C:\WINDOWS\system32\winlogon.exe
services.exe 692 Normal C:\WINDOWS\system32\services.exe
lsass.exe 712 Normal C:\WINDOWS\system32\lsass.exe
svchost.exe 888 Normal C:\WINDOWS\system32\svchost.exe
svchost.exe 980 Normal C:\WINDOWS\system32\svchost.exe
svchost.exe 1104 Normal C:\WINDOWS\system32\svchost.exe
svchost.exe 1148 Normal C:\WINDOWS\system32\svchost.exe
svchost.exe 1160 Normal C:\WINDOWS\system32\svchost.exe
svchost.exe 1324 Normal C:\WINDOWS\system32\svchost.exe
spoolsv.exe 1376 Normal C:\WINDOWS\system32\spoolsv.exe
avgwdsvc.exe 1720 Normal C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
BDTUpdateService.exe 1732 Normal C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
Explorer.EXE 1820 Normal C:\WINDOWS\Explorer.EXE
svchost.exe 1928 Normal C:\WINDOWS\system32\svchost.exe
avgrsx.exe 1944 Normal C:\PROGRA~1\AVG\AVG8\avgrsx.exe
mdm.exe 1952 Normal C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
avgnsx.exe 1960 Normal C:\PROGRA~1\AVG\AVG8\avgnsx.exe
svchost.exe 1976 Normal C:\WINDOWS\System32\svchost.exe
svchost.exe 2008 Normal C:\WINDOWS\System32\svchost.exe
svchost.exe 160 Normal C:\WINDOWS\system32\svchost.exe
avgemc.exe 288 Normal C:\PROGRA~1\AVG\AVG8\avgemc.exe
avgcsrvx.exe 1080 Normal C:\Program Files\AVG\AVG8\avgcsrvx.exe
RUNDLL32.EXE 1668 Normal C:\WINDOWS\system32\RUNDLL32.EXE
ctfmon.exe 1736 Normal C:\WINDOWS\system32\ctfmon.exe
SUPERAntiSpyware.exe 1688 Normal C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
rundll32.exe 2092 Normal C:\WINDOWS\system32\rundll32.exe
webshots.scr 2236 Normal C:\PROGRA~1\Webshots\webshots.scr
svchost.exe 2784 Normal C:\WINDOWS\System32\svchost.exe
cmd.exe 2072 Normal C:\WINDOWS\system32\cmd.exe
processes.exe 2584 Normal C:\Documents and Settings\Owner\Desktop\SpiderKill\SpiderKill\processes.exe


Module information for 'Explorer.EXE'(1820)
MODULE BASE SIZE PATH
Explorer.EXE 1000000 1044480 C:\WINDOWS\Explorer.EXE 6.00.2900.5512 (xpsp.080413-2105) Windows Explorer
ntdll.dll 7c900000 729088 C:\WINDOWS\system32\ntdll.dll 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234) NT Layer DLL
kernel32.dll 7c800000 1007616 C:\WINDOWS\system32\kernel32.dll 5.1.2600.5781 (xpsp_sp3_gdr.090321-1317) Windows NT BASE API Client DLL
ADVAPI32.dll 77dd0000 634880 C:\WINDOWS\system32\ADVAPI32.dll 5.1.2600.5755 (xpsp_sp3_gdr.090206-1234) Advanced Windows 32 Base API
RPCRT4.dll 77e70000 598016 C:\WINDOWS\system32\RPCRT4.dll 5.1.2600.5795 (xpsp_sp3_gdr.090415-1241) Remote Procedure Call Runtime
Secur32.dll 77fe0000 69632 C:\WINDOWS\system32\Secur32.dll 5.1.2600.5834 (xpsp_sp3_gdr.090624-1305) Security Support Provider Interface
BROWSEUI.dll 75f80000 1036288 C:\WINDOWS\system32\BROWSEUI.dll 6.00.2900.5512 (xpsp.080413-2105) Shell Browser UI Library
GDI32.dll 77f10000 299008 C:\WINDOWS\system32\GDI32.dll 5.1.2600.5698 (xpsp_sp3_gdr.081022-1932) GDI Client DLL
USER32.dll 7e410000 593920 C:\WINDOWS\system32\USER32.dll 5.1.2600.5512 (xpsp.080413-2105) Windows XP USER API Client DLL
msvcrt.dll 77c10000 360448 C:\WINDOWS\system32\msvcrt.dll 7.0.2600.5512 (xpsp.080413-2111) Windows NT CRT DLL
ole32.dll 774e0000 1298432 C:\WINDOWS\system32\ole32.dll 5.1.2600.5512 (xpsp.080413-2108) Microsoft OLE for Windows
SHLWAPI.dll 77f60000 483328 C:\WINDOWS\system32\SHLWAPI.dll 6.00.2900.5512 (xpsp.080413-2105) Shell Light-weight Utility Library
OLEAUT32.dll 77120000 569344 C:\WINDOWS\system32\OLEAUT32.dll 5.1.2600.5512 5.1.2600.5512
SHDOCVW.dll 7e290000 1511424 C:\WINDOWS\system32\SHDOCVW.dll 6.00.2900.5512 (xpsp.080413-2105) Shell Doc Object and Control Library
CRYPT32.dll 77a80000 610304 C:\WINDOWS\system32\CRYPT32.dll 5.131.2600.5512 (xpsp.080413-2113) Crypto API32
MSASN1.dll 77b20000 73728 C:\WINDOWS\system32\MSASN1.dll 5.1.2600.5875 (xpsp_sp3_gdr.090904-1413) ASN.1 Runtime APIs
CRYPTUI.dll 754d0000 524288 C:\WINDOWS\system32\CRYPTUI.dll 5.131.2600.5512 (xpsp.080413-2113) Microsoft Trust UI Provider
NETAPI32.dll 5b860000 348160 C:\WINDOWS\system32\NETAPI32.dll 5.1.2600.5694 (xpsp_sp3_gdr.081015-1312) Net Win32 API DLL
VERSION.dll 77c00000 32768 C:\WINDOWS\system32\VERSION.dll 5.1.2600.5512 (xpsp.080413-2105) Version Checking and File Installation Libraries
WININET.dll 3d930000 856064 C:\WINDOWS\system32\WININET.dll 7.00.6000.16981 (vista_gdr.091215-2244) Internet Extensions for Win32
Normaliz.dll 400000 36864 C:\WINDOWS\system32\Normaliz.dll 6.0.5441.0 (winmain(wmbla).060628-1735) Unicode Normalization DLL
iertutil.dll 3dfd0000 282624 C:\WINDOWS\system32\iertutil.dll 7.00.6000.16981 (vista_gdr.091215-2244) Run time utility for Internet Explorer
WINTRUST.dll 76c30000 188416 C:\WINDOWS\system32\WINTRUST.dll 5.131.2600.5512 (xpsp.080413-2113) Microsoft Trust Verification APIs
IMAGEHLP.dll 76c90000 163840 C:\WINDOWS\system32\IMAGEHLP.dll 5.1.2600.5512 (xpsp.080413-2105) Windows NT Image Helper
WLDAP32.dll 76f60000 180224 C:\WINDOWS\system32\WLDAP32.dll 5.1.2600.5512 (xpsp.080413-2113) Win32 LDAP API DLL
SHELL32.dll 7c9c0000 8482816 C:\WINDOWS\system32\SHELL32.dll 6.00.2900.5622 (xpsp_sp3_gdr.080617-1319) Windows Shell Common Dll
UxTheme.dll 5ad70000 229376 C:\WINDOWS\system32\UxTheme.dll 6.00.2900.5512 (xpsp.080413-2105) Microsoft UxTheme Library
ShimEng.dll 5cb70000 155648 C:\WINDOWS\system32\ShimEng.dll 5.1.2600.5512 (xpsp.080413-2105) Shim Engine DLL
AcGenral.DLL 6f880000 1875968 C:\WINDOWS\AppPatch\AcGenral.DLL 5.1.2600.5512 (xpsp.080413-2105) Windows Compatibility DLL
WINMM.dll 76b40000 184320 C:\WINDOWS\system32\WINMM.dll 5.1.2600.5512 (xpsp.080413-0845) MCI API DLL
MSACM32.dll 77be0000 86016 C:\WINDOWS\system32\MSACM32.dll 5.1.2600.5512 (xpsp.080413-0845) Microsoft ACM Audio Filter
USERENV.dll 769c0000 737280 C:\WINDOWS\system32\USERENV.dll 5.1.2600.5512 (xpsp.080413-2113) Userenv
IMM32.DLL 76390000 118784 C:\WINDOWS\system32\IMM32.DLL 5.1.2600.5512 (xpsp.080413-2105) Windows XP IMM32 API Client DLL
comctl32.dll 773d0000 1060864 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll 6.0 (xpsp.080413-2105) User Experience Controls Library
comctl32.dll 5d090000 630784 C:\WINDOWS\system32\comctl32.dll 5.82 (xpsp.080413-2105) Common Controls Library
msctfime.ime 755c0000 188416 C:\WINDOWS\system32\msctfime.ime 5.1.2600.5512 (xpsp.080413-2105) Microsoft Text Frame Work Service IME
appHelp.dll 77b40000 139264 C:\WINDOWS\system32\appHelp.dll 5.1.2600.5512 (xpsp.080413-2105) Application Compatibility Client Library
CLBCATQ.DLL 76fd0000 520192 C:\WINDOWS\system32\CLBCATQ.DLL 2001.12.4414.700 2001.12.4414.700
COMRes.dll 77050000 806912 C:\WINDOWS\system32\COMRes.dll 2001.12.4414.700 2001.12.4414.700
cscui.dll 77a20000 344064 C:\WINDOWS\System32\cscui.dll 5.1.2600.5512 (xpsp.080413-2105) Client Side Caching UI
CSCDLL.dll 76600000 118784 C:\WINDOWS\System32\CSCDLL.dll 5.1.2600.5512 (xpsp.080413-2111) Offline Network Agent
themeui.dll 5ba60000 462848 C:\WINDOWS\system32\themeui.dll 6.00.2900.5512 (xpsp.080413-2105) Windows Theme API
MSIMG32.dll 76380000 20480 C:\WINDOWS\system32\MSIMG32.dll 5.1.2600.5512 (xpsp.080413-2105) GDIEXT Client DLL
xpsp2res.dll 1100000 2904064 C:\WINDOWS\system32\xpsp2res.dll 5.1.2600.5512 (xpsp.080413-2113) Service Pack 2 Messages
LINKINFO.dll 76980000 32768 C:\WINDOWS\system32\LINKINFO.dll 5.1.2600.5512 (xpsp.080413-2105) Windows Volume Tracking
ntshrui.dll 76990000 151552 C:\WINDOWS\system32\ntshrui.dll 5.1.2600.5512 (xpsp.080413-2105) Shell extensions for sharing
ATL.DLL 76b20000 69632 C:\WINDOWS\system32\ATL.DLL 3.05.2284 ATL Module for Windows XP (Unicode)
SETUPAPI.dll 77920000 995328 C:\WINDOWS\system32\SETUPAPI.dll 5.1.2600.5512 (xpsp.080413-2111) Windows Setup API
ieframe.dll 3e1c0000 6082560 C:\WINDOWS\system32\ieframe.dll 7.00.6000.16981 (vista_gdr.091215-2244) Internet Explorer
PSAPI.DLL 76bf0000 45056 C:\WINDOWS\system32\PSAPI.DLL 5.1.2600.5512 (xpsp.080413-2105) Process Status Helper
WINSTA.dll 76360000 65536 C:\WINDOWS\system32\WINSTA.dll 5.1.2600.5512 (xpsp.080413-2111) Winstation Library
webcheck.dll 42e40000 245760 C:\WINDOWS\system32\webcheck.dll 7.00.6000.16981 (vista_gdr.091215-2244) Web Site Monitor
stobject.dll 76280000 135168 C:\WINDOWS\system32\stobject.dll 5.1.2600.5512 (xpsp.080413-2105) Systray shell service object
BatMeter.dll 74af0000 40960 C:\WINDOWS\system32\BatMeter.dll 6.00.2900.5512 (xpsp.080413-2105) Battery Meter Helper DLL
POWRPROF.dll 74ad0000 32768 C:\WINDOWS\system32\POWRPROF.dll 6.00.2900.5512 (xpsp.080413-2105) Power Profile Helper DLL
WTSAPI32.dll 76f50000 32768 C:\WINDOWS\system32\WTSAPI32.dll 5.1.2600.5512 (xpsp.080413-2111) Windows Terminal Server SDK APIs
urlmon.dll 78130000 1212416 C:\WINDOWS\system32\urlmon.dll 7.00.6000.16981 (vista_gdr.091215-2244) OLE32 Extensions for Win32
WPDShServiceObj.dll 164a0000 143360 C:\WINDOWS\system32\WPDShServiceObj.dll 5.2.5721.5145 (WMP_11.061018-2006) Windows Portable Device Shell Service Object
WINHTTP.dll 4d4f0000 364544 C:\WINDOWS\system32\WINHTTP.dll 5.1.2600.5868 (xpsp_sp3_gdr.090824-1328) Windows HTTP Services
upnpui.dll 5af80000 249856 C:\WINDOWS\system32\upnpui.dll 5.1.2600.5512 (xpsp.080413-0852) UPNP Tray Monitor and Folder
PortableDeviceTypes.dll 109c0000 180224 C:\WINDOWS\system32\PortableDeviceTypes.dll 5.2.5721.5145 (WMP_11.061018-2006) Windows Portable Device (Parameter) Types Component
upnp.dll 76de0000 147456 C:\WINDOWS\system32\upnp.dll 5.1.2600.5512 (xpsp.080413-0852) Universal Plug and Play API
SSDPAPI.dll 74f00000 49152 C:\WINDOWS\system32\SSDPAPI.dll 5.1.2600.5512 (xpsp.080413-0852) SSDP Client API DLL
WS2_32.dll 71ab0000 94208 C:\WINDOWS\system32\WS2_32.dll 5.1.2600.5512 (xpsp.080413-0852) Windows Socket 2.0 32-Bit DLL
WS2HELP.dll 71aa0000 32768 C:\WINDOWS\system32\WS2HELP.dll 5.1.2600.5512 (xpsp.080413-0852) Windows Socket 2.0 Helper for Windows NT
iphlpapi.dll 76d60000 102400 C:\WINDOWS\system32\iphlpapi.dll 5.1.2600.5512 (xpsp.080413-0852) IP Helper API
PortableDeviceApi.dll 10930000 299008 C:\WINDOWS\system32\PortableDeviceApi.dll 5.2.5721.5145 (WMP_11.061018-2006) Windows Portable Device API Components
msi.dll 7d1e0000 2867200 C:\WINDOWS\system32\msi.dll 3.1.4001.5512 Windows Installer
rsaenh.dll 68000000 221184 C:\WINDOWS\system32\rsaenh.dll 5.1.2600.5507 (xpsp.080318-1711) Microsoft Enhanced Cryptographic Provider
MSCTF.dll 74720000 311296 C:\WINDOWS\system32\MSCTF.dll 5.1.2600.5512 (xpsp.080413-2105) MSCTF Server DLL
wdmaud.drv 72d20000 36864 C:\WINDOWS\system32\wdmaud.drv 5.1.2600.5512 (xpsp.080413-2108) WDM Audio driver mapper
msacm32.drv 72d10000 32768 C:\WINDOWS\system32\msacm32.drv 5.1.2600.0 (xpclient.010817-1148) Microsoft Sound Mapper
midimap.dll 77bd0000 28672 C:\WINDOWS\system32\midimap.dll 5.1.2600.5512 (xpsp.080413-0845) Microsoft MIDI Mapper
NETSHELL.dll 76400000 1724416 C:\WINDOWS\system32\NETSHELL.dll 5.1.2600.5512 (xpsp.080413-0852) Network Connections Shell
credui.dll 76c00000 188416 C:\WINDOWS\system32\credui.dll 5.1.2600.5512 (xpsp.080413-2113) Credential Manager User Interface
dot3api.dll 478c0000 40960 C:\WINDOWS\system32\dot3api.dll 5.1.2600.5512 (xpsp.080413-0852) 802.3 Autoconfiguration API
rtutils.dll 76e80000 57344 C:\WINDOWS\system32\rtutils.dll 5.1.2600.5512 (xpsp.080413-0852) Routing Utilities
dot3dlg.dll 736d0000 24576 C:\WINDOWS\system32\dot3dlg.dll 5.1.2600.5512 (xpsp.080413-0852) 802.3 UI Helper
OneX.DLL 5dca0000 163840 C:\WINDOWS\system32\OneX.DLL 5.1.2600.5512 (xpsp.080413-0852) IEEE 802.1X supplicant library
eappcfg.dll 745b0000 139264 C:\WINDOWS\system32\eappcfg.dll 5.1.2600.5512 (xpsp.080413-0852) Eap Peer Config
MSVCP60.dll 76080000 413696 C:\WINDOWS\system32\MSVCP60.dll 6.02.3104.0 Microsoft (R) C++ Runtime Library
eappprxy.dll 5dcd0000 57344 C:\WINDOWS\system32\eappprxy.dll 5.1.2600.5512 (xpsp.080413-0852) Microsoft EAPHost Peer Client DLL
hnetcfg.dll 662b0000 360448 C:\WINDOWS\system32\hnetcfg.dll 5.1.2600.5512 (xpsp.080413-0852) Home Networking Configuration Manager
PCTLsp.dll 10000000 323584 C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll 1, 0, 102, 0 PC Tools Layered Service Provider
mswsock.dll 71a50000 258048 C:\WINDOWS\system32\mswsock.dll 5.1.2600.5625 (xpsp_sp3_gdr.080620-1249) Microsoft Windows Sockets 2.0 Service Provider
wshtcpip.dll 71a90000 32768 C:\WINDOWS\System32\wshtcpip.dll 5.1.2600.5512 (xpsp.080413-0852) Windows Sockets Helper DLL
mslbui.dll 605d0000 36864 C:\WINDOWS\system32\mslbui.dll 5.1.2600.5512 (xpsp.080413-2105) LangageBar Add In
nview.dll 2790000 1658880 C:\Program Files\NVIDIA Corporation\nView\nview.dll
NTMARTA.DLL 77690000 135168 C:\WINDOWS\system32\NTMARTA.DLL 5.1.2600.5512 (xpsp.080413-2113) Windows NT MARTA provider
SAMLIB.dll 71bf0000 77824 C:\WINDOWS\system32\SAMLIB.dll 5.1.2600.5512 (xpsp.080413-2113) SAM Library DLL
SXS.DLL 7e720000 720896 C:\WINDOWS\system32\SXS.DLL 5.1.2600.5512 (xpsp.080413-2111) Fusion 2.5
msxml3.dll 74980000 1191936 C:\WINDOWS\system32\msxml3.dll 8.100.1051.0 MSXML 3.0 SP10
MLANG.dll 75cf0000 593920 C:\WINDOWS\system32\MLANG.dll 6.00.2900.5512 (xpsp.080413-2105) Multi Language Support DLL
MPR.dll 71b20000 73728 C:\WINDOWS\system32\MPR.dll 5.1.2600.5512 (xpsp.080413-0852) Multiple Provider Router DLL
drprov.dll 75f60000 28672 C:\WINDOWS\System32\drprov.dll 5.1.2600.5512 (xpsp.080413-2111) Microsoft Terminal Server Network Provider
ntlanman.dll 71c10000 57344 C:\WINDOWS\System32\ntlanman.dll 5.1.2600.5512 (xpsp.080413-2108) Microsoft® Lan Manager
NETUI0.dll 71cd0000 94208 C:\WINDOWS\System32\NETUI0.dll 5.1.2600.5512 (xpsp.080413-2108) NT LM UI Common Code - GUI Classes
NETUI1.dll 71c90000 262144 C:\WINDOWS\System32\NETUI1.dll 5.1.2600.5512 (xpsp.080413-2108) NT LM UI Common Code - Networking classes
NETRAP.dll 71c80000 28672 C:\WINDOWS\System32\NETRAP.dll 5.1.2600.5512 (xpsp.080413-2113) Net Remote Admin Protocol DLL
davclnt.dll 75f70000 40960 C:\WINDOWS\System32\davclnt.dll 5.1.2600.5512 (xpsp.080413-2111) Web DAV Client DLL
nvwddi.dll d20000 86016 C:\WINDOWS\system32\nvwddi.dll 6.14.11.9107 NVIDIA nView Display Driver Interface Lib, Version 191.07
PDFShell.dll 2c30000 372736 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll 9.3.0.148 PDF Shell Extension
MSVCR80.dll 3cf0000 634880 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll 8.00.50727.3053 Microsoft® C Runtime Library
actxprxy.dll 71d40000 110592 C:\WINDOWS\system32\actxprxy.dll 6.00.2900.5512 (xpsp.080413-2113) ActiveX Interface Marshaling Library
browselc.dll 71600000 73728 C:\WINDOWS\system32\browselc.dll 6.00.2900.5512 (xpsp.080413-2105) Shell Browser UI Library
zipfldr.dll 73380000 356352 C:\WINDOWS\system32\zipfldr.dll 6.00.2900.5512 (xpsp.080413-2105) Compressed (zipped) Folders
gdiplus.dll 4ec50000 1748992 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\gdiplus.dll 5.2.6001.22319 (vistasp1_ldr.081126-1506) Microsoft GDI+
DUSER.dll 6c1b0000 315392 C:\WINDOWS\system32\DUSER.dll 5.1.2600.5512 (xpsp.080413-2105) Windows DirectUser Engine
nvcpl.dll 4380000 14098432 C:\WINDOWS\system32\nvcpl.dll 6.14.11.9107 NVIDIA Display Properties Extension
COMDLG32.dll 763b0000 299008 C:\WINDOWS\system32\COMDLG32.dll 6.00.2900.5512 (xpsp.080413-2105) Common Dialogs DLL
WINSPOOL.DRV 73000000 155648 C:\WINDOWS\system32\WINSPOOL.DRV 5.1.2600.5512 (xpsp.080413-0852) Windows Spooler Driver
OLEACC.dll 74c80000 180224 C:\WINDOWS\system32\OLEACC.dll 4.2.5406.0 (xpclient.010817-1148) Active Accessibility Core Component
nvapi.dll 40e0000 921600 C:\WINDOWS\system32\nvapi.dll 6.14.11.9107 NVIDIA NVAPI Library, Version 191.07
igfxpph.dll 4210000 245760 C:\WINDOWS\system32\igfxpph.dll 3.0.0.4342 igfxpph Module
hccutils.DLL 15f0000 122880 C:\WINDOWS\system32\hccutils.DLL 3.0.0.4342 hccutils Module
igfxres.dll 2a10000 167936 C:\WINDOWS\system32\igfxres.dll 3.0.0.4342 xxxxres Module
igfxsrvc.dll 42b0000 360448 C:\WINDOWS\system32\igfxsrvc.dll 3.0.0.4342 igfxsrvc Module
igfxdev.dll 3950000 147456 C:\WINDOWS\system32\igfxdev.dll 3.0.0.4342 igfxdev Module
nvshell.dll 5200000 471040 C:\Program Files\NVIDIA Corporation\nView\nvshell.dll
sti.dll 73ba0000 77824 C:\WINDOWS\system32\sti.dll 5.1.2600.5512 (xpsp.080413-0852) Still Image Devices client DLL
CFGMGR32.dll 74ae0000 28672 C:\WINDOWS\system32\CFGMGR32.dll 5.1.2600.5512 (xpsp.080413-2111) Configuration Manager Forwarder DLL
mydocs.dll 72410000 106496 C:\WINDOWS\system32\mydocs.dll 6.00.2900.5512 (xpsp.080413-2105) My Documents Folder UI
mbamext.dll 3310000 98304 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll 1, 3, 0, 0 Malwarebytes' Anti-Malware
syncui.dll 74650000 200704 C:\WINDOWS\system32\syncui.dll 5.1.2600.5512 (xpsp.080413-2105) Windows Briefcase
avgse.dll 6c330000 118784 C:\Program Files\AVG\AVG8\avgse.dll 8.5.0.401 AVG Shell Extension
MSVCP80.dll 7c420000 552960 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCP80.dll 8.00.50727.3053 Microsoft® C++ Runtime Library
SASSEH.DLL 5350000 81920 C:\Program Files\SUPERAntiSpyware\SASSEH.DLL 1, 0, 0, 1012 ShellExecuteHook



******************************************
EOF

View user profile

13 Re: Please help me remove Searhcmagnified.com on Wed Feb 10, 2010 9:05 pm

Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile
Malwarebytes' Anti-Malware 1.44
Database version: 3723
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/10/2010 10:46:58 PM
mbam-log-2010-02-10 (22-46-58).txt

Scan type: Quick Scan
Objects scanned: 132878
Time elapsed: 5 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

View user profile

15 Re: Please help me remove Searhcmagnified.com on Thu Feb 11, 2010 4:48 pm

Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE

You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done


To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:

  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.

Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.


==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


..........................................................
DragonMaster Jay
Owner/Administrator/Operator Cheetah-Fast Services
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here
View user profile

View previous topic View next topic Back to top  Message [Page 1 of 2]

Goto page : 1, 2  Next

Permissions in this forum:
You cannot reply to topics in this forum