1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Remotely Controlled, apps and all - how to find their software??

Discussion in 'Malware and Virus Removal Archive' started by Gail22, 2009/03/01.

  1. 2009/03/01
    Gail22

    Gail22 Inactive Thread Starter

    Joined:
    2004/10/18
    Messages:
    51
    Likes Received:
    0
    Hi,

    As I said in the wrong forum (because I'm having so many different problems, but most of them probably lead back to the criminal activity I cannot yet prove to the police), I think my computer is being remotely, and wirelessly, controlled overnights, between usually midnight and 6 or 7 AM. I've noticed my web cam software either shut off (from my password protected user account), or hours of video capture deleted, then resumed. I've noticed applications having been completely uninstalled. And I only find out the next day, because it was all done overnight.

    I know the criminal has actually been in the apartment on a few occasions, but I was never able to get the proof with my web cam surveillance software. But this means that s/he had the opportunity to install remote-control software on my computer before I wised up and finally password protected my account, which was a useless effort by then (since in all likelihood, there was also a keylogger installed - one of the antivirus apps reported it).

    I am extremely careful with my computer and do regular malware scans with various apps, and only ever find tracking cookies.

    Is there any way at all that I could find any "remote control" software, such as the sort Dell uses in order to connect remotely? It could mean I'd be able to finally bring this nightmare to the police.

    The logs from the little app Arie told me to download and run are below - thank you very much for any help.

    Gail


    (Here is the Attach.txt log, which I'm pretty sure the rules said could be posted in the post body, and not as only an attachment.)

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-02-01.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume2
    Install Date: 2/9/2009 10:49:55 AM
    System Uptime: 3/1/2009 5:23:22 AM (2 hours ago)

    Motherboard: Dell Inc. | | 0JC474
    Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2794/800mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 69 GiB total, 18.358 GiB free.
    D: is FIXED (NTFS) - 76 GiB total, 3.182 GiB free.
    E: is Removable
    G: is CDROM ()
    H: is CDROM ()
    P: is FIXED (NTFS) - 107 GiB total, 1.495 GiB free.
    Q: is FIXED (NTFS) - 191 GiB total, 0.312 GiB free.

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP11: 2/9/2009 5:55:11 PM - Software Distribution Service 3.0
    RP12: 2/9/2009 6:07:19 PM - Software Distribution Service 3.0
    RP13: 2/9/2009 6:37:36 PM - Installed Norton PartitionMagic
    RP14: 2/10/2009 3:53:58 PM - Installed Webcam 2200
    RP15: 2/10/2009 3:58:35 PM - Installed Microsoft Office Basic Edition 2003
    RP16: 2/10/2009 5:23:04 PM - Installed PhotoStudio
    RP17: 2/10/2009 5:24:04 PM - Installed OmniPage SE
    RP18: 2/10/2009 6:32:18 PM - Installed WebCam Companion
    RP19: 2/10/2009 6:51:41 PM - Installed SUPERAntiSpyware Free Edition
    RP20: 2/11/2009 2:30:39 AM - Installed Sygate Personal Firewall
    RP21: 2/12/2009 2:41:12 AM - System Checkpoint
    RP22: 2/12/2009 3:23:22 PM - Software Distribution Service 3.0
    RP23: 2/13/2009 3:29:14 PM - System Checkpoint
    RP24: 2/13/2009 10:08:56 PM - Software Distribution Service 3.0
    RP25: 2/14/2009 6:20:40 AM - Software Distribution Service 3.0
    RP26: 2/15/2009 6:21:32 AM - System Checkpoint
    RP27: 2/16/2009 9:35:10 AM - System Checkpoint
    RP28: 2/17/2009 2:49:14 PM - System Checkpoint
    RP29: 2/18/2009 4:00:11 PM - System Checkpoint
    RP30: 2/19/2009 4:13:26 PM - System Checkpoint
    RP31: 2/20/2009 4:19:41 PM - System Checkpoint
    RP32: 2/21/2009 7:41:30 PM - System Checkpoint
    RP33: 2/22/2009 2:45:24 PM - Installed WebCam Companion
    RP34: 2/22/2009 3:45:43 PM - Installed Adobe Reader 9.
    RP35: 2/23/2009 5:16:49 PM - System Checkpoint
    RP36: 2/24/2009 6:25:43 PM - Installed DirectX
    RP37: 2/24/2009 6:31:23 PM - Removed Webcam 2200
    RP38: 2/24/2009 6:38:30 PM - Installed Webcam 2200
    RP39: 2/24/2009 6:42:52 PM - Removed Webcam 2200
    RP40: 2/24/2009 6:44:31 PM - Installed Webcam 2200
    RP41: 2/24/2009 6:56:30 PM - Software Distribution Service 3.0
    RP42: 2/25/2009 2:58:35 PM - Restore Operation
    RP43: 2/25/2009 3:03:57 PM - Restore Operation
    RP44: 2/25/2009 3:06:49 PM - Restore Operation
    RP45: 2/25/2009 4:23:13 PM - Software Distribution Service 3.0
    RP46: 2/26/2009 6:04:46 PM - System Checkpoint
    RP47: 2/27/2009 7:45:26 PM - System Checkpoint
    RP48: 3/1/2009 3:26:25 AM - ComboFix created restore point
    RP49: 3/1/2009 5:09:49 AM - Software Distribution Service 3.0

    ==== Installed Programs ======================

    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9
    ArcSoft PhotoStudio 5.5
    ArcSoft WebCam Companion 2
    AstroWin v3.61
    avast! Antivirus
    Canon MP Navigator 2.0
    Canon MP450
    Canon Utilities Easy-PhotoPrint
    Canon Utilities Easy-PhotoPrint EX
    CCleaner (remove only)
    ChronosXP 3.4
    Conexant D850 56K V.9x DFVc Modem
    Dell Resource CD
    Easy-WebPrint
    Forté Agent
    GoToAssist 8.0.0.514
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    HouseCall 6.6
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) PRO Network Connections Drivers
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 11
    Macromedia Flash Player 8
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Office Basic Edition 2003
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Modem Helper
    Mozilla Firefox (3.0.6)
    MXpie Patch for WinMX Network/WPNP 3.6.3.6
    Nero Media Player
    Nero OEM
    NewsBin for Giganews
    Norton PartitionMagic
    Norton PartitionMagic 8.0
    OmniPage SE 2.0
    PeerGuardian 2.0
    Pie Auto Updater 1.0
    QuickPar 0.9
    SeaMonkey (1.1.14)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    SigmaTel Audio
    Spyware Doctor 6.0
    SpywareBlaster 4.1
    SUPERAntiSpyware Free Edition
    Sygate Personal Firewall
    Update for Windows XP (KB898461)
    Update for Windows XP (KB943729)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    VideoLAN VLC media player 0.8.6f
    WebFldrs XP
    Winamp (remove only)
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Media Format 11 runtime
    Windows Media Player 11
    Winmx Community 1
    WinRAR archiver

    ==== Event Viewer Messages From Past Week ========

    2/25/2009 6:39:36 PM, error: Service Control Manager [7000] - The SASDIFSV service failed to start due to the following error: Cannot create a file when that file already exists.
    2/25/2009 2:59:48 PM, error: System Error [1003] - Error code 0000007f, parameter1 00000000, parameter2 00000000, parameter3 00000000, parameter4 00000000.
    2/26/2009 11:05:23 AM, error: Service Control Manager [7000] - The SABProcEnum service failed to start due to the following error: The system cannot find the file specified.
    2/28/2009 5:53:30 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    2/28/2009 5:54:47 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSP Fips intelppm SASDIFSV SASKUTIL
    2/28/2009 8:21:06 PM, error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
    3/1/2009 5:03:48 AM, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
    3/1/2009 5:04:36 AM, error: System Error [1003] - Error code 00000019, parameter1 00000020, parameter2 f81b8bd8, parameter3 f81b8c50, parameter4 8c0fc085.

    ==== End Of File ===========================

    And here is the DDS.txt


    DDS (Ver_09-02-01.01) - NTFSx86
    Run by Sparx at 7:08:35.35 on Sun 03/01/2009
    Internet Explorer: 6.0.2900.5512
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.248 [GMT -6:00]

    AV: avast! antivirus 4.8.1335 [VPS 090228-0] *On-access scanning enabled* (Updated)
    FW: Sygate Personal Firewall *enabled*

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\Program Files\Sygate\SPF\smc.exe
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxpers.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\PixArt\PAC7302\Monitor.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Sparx\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.com/
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - c:\program files\canon\easy-webprint\EWPBrowseLoader.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
    mRun: [igfxtray] c:\windows\system32\igfxtray.exe
    mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
    mRun: [igfxpers] c:\windows\system32\igfxpers.exe
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe
    mRun: [SmcService] c:\progra~1\sygate\spf\smc.exe -startgui
    mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Toolband.dll/RC_AddToList.html
    IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_HSPrint.html
    IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Toolband.dll/RC_Preview.html
    IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_Print.html
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -

    hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1234222078515
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} -

    hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1234583740312
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
    DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
    Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
    Notify: igfxcui - igfxdev.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\sparx\applic~1\mozilla\firefox\profiles\tjlxadzj.default\

    ============= SERVICES / DRIVERS ===============

    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-2-26 130424]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-2-10 114768]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-1-15 8944]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-1-15 55024]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-2-10 20560]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-2-10 138680]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-2-10 254040]
    R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-2-10 352920]
    R3 PAC7302;PAC7302 VGA USB Camera;c:\windows\system32\drivers\PAC7302.SYS [2009-2-10 457856]
    S0 cerc6;cerc6; [x]
    S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-1-15 7408]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-2-26 348752]
    S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-2-26 1095560]
    S4 vsdatant;vsdatant; [x]

    =============== Created Last 30 ================

    2009-03-01 03:53 60,611 a------- C:\MGlogs.zip
    2009-03-01 03:53 <DIR> --d----- C:\MGtools
    2009-03-01 03:26 161,792 a------- c:\windows\SWREG.exe
    2009-03-01 03:26 98,816 a------- c:\windows\sed.exe
    2009-03-01 03:26 <DIR> --d----- C:\ComboFix
    2009-03-01 02:46 <DIR> --d----- c:\docume~1\sparx\applic~1\Malwarebytes
    2009-03-01 02:46 15,504 a------- c:\windows\system32\drivers\mbam.sys
    2009-03-01 02:46 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-03-01 02:46 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-03-01 02:46 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-03-01 02:03 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
    2009-03-01 01:53 1,337,489 a------- C:\MGtools.exe
    2009-03-01 01:34 <DIR> --d----- c:\program files\CCleaner
    2009-02-26 11:43 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
    2009-02-26 11:43 130,424 a------- c:\windows\system32\drivers\PCTCore.sys
    2009-02-26 11:43 73,840 a------- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-02-26 11:43 64,392 a------- c:\windows\system32\drivers\pctplsg.sys
    2009-02-26 11:43 <DIR> --d----- c:\program files\common files\PC Tools
    2009-02-26 11:43 <DIR> --d----- c:\program files\Spyware Doctor
    2009-02-26 11:43 <DIR> --d----- c:\docume~1\sparx\applic~1\PC Tools
    2009-02-26 11:43 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools
    2009-02-26 11:18 <DIR> --d----- c:\docume~1\sparx\applic~1\HouseCall 6.6
    2009-02-25 17:44 61,224 a------- c:\documents and settings\sparx\GoToAssistDownloadHelper.exe
    2009-02-25 16:05 33,792 ac------ c:\windows\system32\dllcache\lmmib2.dll
    2009-02-25 16:05 33,792 a------- c:\windows\system32\lmmib2.dll
    2009-02-25 15:07 <DIR> --d----- c:\windows\PixArt
    2009-02-25 15:07 <DIR> --d----- c:\program files\Winmx
    2009-02-25 15:07 <DIR> --d----- c:\program files\PieAutoUpdater
    2009-02-25 15:07 <DIR> --d----- c:\program files\MXpie Patch
    2009-02-25 14:43 11,776 a------- c:\windows\system32\miniime.tpl
    2009-02-24 18:47 <DIR> --d----- c:\windows\PixArt(2)
    2009-02-24 18:33 <DIR> --d----- c:\windows\system32\NtmsData
    2009-02-24 18:22 <DIR> --d----- c:\windows\Logs
    2009-02-24 02:20 <DIR> --d----- c:\program files\PeerGuardian2
    2009-02-15 03:56 132 a------- c:\windows\winamp.ini
    2009-02-15 03:05 118,784 a------- c:\windows\SeaMonkeyUninstall.exe
    2009-02-15 03:05 118,784 a------- c:\windows\GREUninstall.exe
    2009-02-15 03:05 8,653 a------- c:\windows\mozver.dat
    2009-02-15 03:05 <DIR> --d----- c:\program files\mozilla.org
    2009-02-15 02:41 <DIR> --d----- c:\program files\Netscape
    2009-02-15 02:20 <DIR> --d----- C:\Copy of ASTROWORKS
    2009-02-14 01:58 268,648 a------- c:\windows\system32\mucltui.dll
    2009-02-14 01:58 27,496 a------- c:\windows\system32\mucltui.dll.mui
    2009-02-13 13:03 6 a------- c:\windows\WS_FTP.EXT
    2009-02-13 13:03 0 a------- c:\windows\WS_FTP.CNV
    2009-02-13 12:57 <DIR> --d----- C:\WS_FTP
    2009-02-13 12:56 <DIR> --d----- c:\program files\ws_ftp
    2009-02-12 15:42 132,880 a------- c:\windows\system32\msinet.ocx
    2009-02-12 15:10 2,444,830 a------- C:\samsunga740.pdf
    2009-02-12 15:02 <DIR> --d----- C:\Astro E-Books
    2009-02-12 14:58 <DIR> --d----- C:\Pictures
    2009-02-12 14:34 <DIR> --d----- C:\music recent
    2009-02-12 13:30 <DIR> --d----- C:\C - To Archive
    2009-02-11 05:57 <DIR> --d-h--- c:\windows\system32\GroupPolicy
    2009-02-11 04:28 <DIR> --d----- c:\program files\ChronosXP
    2009-02-11 04:22 260,880 a------- c:\windows\system32\Msflxgrd.ocx
    2009-02-11 04:22 212,240 a------- c:\windows\system32\Richtx32.ocx
    2009-02-11 04:22 158,992 a------- c:\windows\system32\Comct232.ocx
    2009-02-11 04:22 152,848 a------- c:\windows\system32\Comdlg32.ocx
    2009-02-11 04:22 <DIR> --d----- c:\program files\AstroWin
    2009-02-11 04:05 <DIR> --d----- c:\program files\QuickPar
    2009-02-11 03:46 116 a------- c:\windows\NeroDigital.ini
    2009-02-11 03:43 <DIR> --d----- C:\Gnews download
    2009-02-11 02:34 <DIR> --d----- c:\windows\pss
    2009-02-11 02:30 14,568 a------- c:\windows\system32\drivers\wg6n.sys
    2009-02-11 02:30 14,568 a------- c:\windows\system32\drivers\wg5n.sys
    2009-02-11 02:30 14,568 a------- c:\windows\system32\drivers\wg4n.sys
    2009-02-11 02:30 60,496 a------- c:\windows\system32\drivers\Teefer.sys
    2009-02-11 02:30 21,075 a------- c:\windows\system32\drivers\wpsdrvnt.sys
    2009-02-11 02:30 14,568 a------- c:\windows\system32\drivers\wg3n.sys
    2009-02-11 02:30 83,096 a------- c:\windows\system32\SSSensor.dll
    2009-02-11 02:30 <DIR> --d----- c:\program files\Sygate
    2009-02-10 21:41 5,504 ac------ c:\windows\system32\dllcache\mstee.sys
    2009-02-10 21:41 5,504 a------- c:\windows\system32\drivers\MSTEE.sys
    2009-02-10 21:41 10,880 ac------ c:\windows\system32\dllcache\ndisip.sys
    2009-02-10 21:41 10,880 a------- c:\windows\system32\drivers\NdisIP.sys
    2009-02-10 21:41 15,232 ac------ c:\windows\system32\dllcache\streamip.sys
    2009-02-10 21:41 15,232 a------- c:\windows\system32\drivers\StreamIP.sys
    2009-02-10 21:41 16,384 ac------ c:\windows\system32\dllcache\ipsink.ax
    2009-02-10 21:41 16,384 a------- c:\windows\system32\ipsink.ax
    2009-02-10 21:41 11,136 ac------ c:\windows\system32\dllcache\slip.sys
    2009-02-10 21:41 11,136 a------- c:\windows\system32\drivers\SLIP.sys
    2009-02-10 19:56 <DIR> --d----- c:\program files\NewsBinGN
    2009-02-10 19:56 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NewsBin
    2009-02-10 19:39 <DIR> --d----- c:\program files\Agent
    2009-02-10 18:51 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
    2009-02-10 18:51 <DIR> --d----- c:\program files\SUPERAntiSpyware
    2009-02-10 18:51 <DIR> --d----- c:\docume~1\sparx\applic~1\SUPERAntiSpyware.com
    2009-02-10 18:51 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
    2009-02-10 18:47 <DIR> --d----- c:\program files\VideoLAN
    2009-02-10 18:33 <DIR> --d----- c:\program files\SpywareBlaster
    2009-02-10 18:32 1,645,320 a------- c:\windows\system32\gdiplus.dll
    2009-02-10 17:55 195,072 a------- c:\windows\system32\CNCC450.DLL
    2009-02-10 17:55 139,264 a------- c:\windows\system32\CNCL450.DLL
    2009-02-10 17:55 37,888 a------- c:\windows\system32\CNCI450.DLL
    2009-02-10 17:35 198,656 a------- c:\windows\system32\CNMLM7I.DLL
    2009-02-10 17:35 8,704 a------- c:\windows\system32\CNMVS7I.DLL
    2009-02-10 17:35 25,856 ac------ c:\windows\system32\dllcache\usbprint.sys
    2009-02-10 17:35 25,856 a------- c:\windows\system32\drivers\usbprint.sys
    2009-02-10 17:35 15,104 ac------ c:\windows\system32\dllcache\usbscan.sys
    2009-02-10 17:35 15,104 a------- c:\windows\system32\drivers\usbscan.sys
    2009-02-10 17:35 32,128 ac------ c:\windows\system32\dllcache\usbccgp.sys
    2009-02-10 17:35 32,128 a------- c:\windows\system32\drivers\usbccgp.sys
    2009-02-10 17:24 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SSScanWizard
    2009-02-10 17:24 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SSScanAppDataDir
    2009-02-10 17:24 532 a------- c:\windows\MAXLINK.INI
    2009-02-10 17:24 <DIR> --d----- c:\program files\ScanSoft
    2009-02-10 17:24 <DIR> --d----- c:\program files\common files\ScanSoft Shared
    2009-02-10 17:23 212,480 a------- c:\windows\PCDLIB32.DLL
    2009-02-10 17:22 306,688 a------- c:\windows\IsUninst.exe
    2009-02-10 17:21 <DIR> --d----- c:\windows\StartHtmico
    2009-02-10 17:21 106,496 a------- c:\windows\system32\cncisco.dll
    2009-02-10 17:20 <DIR> --d----- c:\program files\Canon
    2009-02-10 17:10 127,488 -------- c:\windows\system32\drivers\imagesrv.sys
    2009-02-10 17:10 5,888 -------- c:\windows\system32\drivers\imagedrv.sys
    2009-02-10 17:10 106,496 a------- c:\windows\system32\TwnLib20.dll
    2009-02-10 17:10 364,544 -------- c:\windows\system32\TwnLib4.dll
    2009-02-10 17:10 476,320 -------- c:\windows\system32\ImagXpr7.dll
    2009-02-10 17:10 471,040 -------- c:\windows\system32\ImagXRA7.dll
    2009-02-10 17:10 262,144 -------- c:\windows\system32\ImagXR7.dll
    2009-02-10 17:10 1,568,768 -------- c:\windows\system32\ImagX7.dll
    2009-02-10 16:15 1,794,048 -------- c:\windows\UNNMP.exe
    2009-02-10 16:15 50,779 -------- c:\windows\UNNMP.cfg
    2009-02-10 16:13 38,912 a----r-- c:\windows\system32\picn20.dll
    2009-02-10 16:13 569,344 a----r-- c:\windows\system32\imagr5.dll
    2009-02-10 16:13 544,768 a----r-- c:\windows\system32\imagx5.dll
    2009-02-10 16:13 283,920 a----r-- c:\windows\system32\ImagXpr5.dll
    2009-02-10 16:13 155,648 a------- c:\windows\system32\NeroCheck.exe
    2009-02-10 15:59 376 a------- c:\windows\ODBC.INI
    2009-02-10 15:59 28,040 a------- c:\windows\system32\mdimon.dll
    2009-02-10 15:59 <DIR> --d----- c:\program files\Microsoft ActiveSync
    2009-02-10 15:59 <DIR> --d----- c:\windows\SHELLNEW
    2009-02-10 15:53 457,856 a------- c:\windows\system32\drivers\PAC7302.SYS
    2009-02-10 15:53 129,024 a------- c:\windows\system32\SP7302.AX
    2009-02-10 15:53 6,656 a------- c:\windows\system32\CoInst.dll
    2009-02-10 15:53 566 a------- c:\windows\system32\SP7302.INI
    2009-02-10 14:39 <DIR> --d----- c:\windows\LMI3.tmp
    2009-02-10 12:28 <DIR> --d----- c:\windows\LMI1.tmp
    2009-02-09 18:39 <DIR> --d----- c:\program files\Symantec
    2009-02-09 18:29 26,368 ac------ c:\windows\system32\dllcache\usbstor.sys
    2009-02-09 18:00 <DIR> --d----- c:\windows\system32\XPSViewer
    2009-02-09 18:00 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll
    2009-02-09 18:00 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
    2009-02-09 18:00 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll
    2009-02-09 18:00 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
    2009-02-09 18:00 <DIR> --d----- C:\4a65553d094536c40e4e9d
    2009-02-09 18:00 1,676,288 -------- c:\windows\system32\xpssvcs.dll
    2009-02-09 18:00 575,488 -------- c:\windows\system32\xpsshhdr.dll
    2009-02-09 18:00 117,760 -------- c:\windows\system32\prntvpt.dll
    2009-02-09 17:57 221,184 a------- c:\windows\system32\wmpns.dll
    2009-02-09 17:57 <DIR> --d----- c:\program files\Windows Media Connect 2
    2009-02-09 17:56 <DIR> --d----- c:\windows\system32\LogFiles
    2009-02-09 17:55 <DIR> --d----- c:\windows\system32\URTTemp
    2009-02-09 17:33 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
    2009-02-09 17:33 2,189,184 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
    2009-02-09 17:33 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
    2009-02-09 17:33 2,066,048 -c------ c:\windows\system32\dllcache\ntkrnlpa.exe
    2009-02-09 17:33 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
    2009-02-09 17:32 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
    2009-02-09 17:32 272,128 -------- c:\windows\system32\drivers\bthport.sys
    2009-02-09 17:30 26,488 a------- c:\windows\system32\spupdsvc.exe
    2009-02-09 17:30 <DIR> --d----- c:\windows\system32\PreInstall
    2009-02-09 17:30 <DIR> --d-h--- c:\windows\$hf_mig$
    2009-02-09 17:29 410,984 a------- c:\windows\system32\deploytk.dll
    2009-02-09 17:29 73,728 a------- c:\windows\system32\javacpl.cpl
    2009-02-09 17:28 23,576 a------- c:\windows\system32\wuapi.dll.mui
    2009-02-09 17:28 <DIR> --d----- c:\windows\system32\SoftwareDistribution
    2009-02-09 17:27 <DIR> --ds---- c:\documents and settings\sparx\UserData
    2009-02-09 17:26 135,168 a------- c:\windows\system32\igfxres.dll
    2009-02-09 17:25 <DIR> --d----- c:\program files\Modem Helper
    2009-02-09 17:23 5 a------- c:\windows\system32\drivers\DELL_DIM_3100.MRK
    2009-02-09 17:23 5 a------- c:\windows\system32\drivers\1028_DELL_DIM_3100.MRK
    2009-02-09 17:21 6,272 ac------ c:\windows\system32\dllcache\splitter.sys
    2009-02-09 17:21 <DIR> --d----- c:\program files\SigmaTel
    2009-02-09 17:20 4,992 ac------ c:\windows\system32\dllcache\mspqm.sys
    2009-02-09 17:20 <DIR> --d----- c:\program files\CONEXANT
    2009-02-09 17:17 <DIR> --d----- c:\windows\system32\ReinstallBackups
    2009-02-09 17:16 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Citrix
    2009-02-09 17:16 <DIR> --d----- c:\program files\Citrix
    2009-02-09 14:13 1,902 -------- c:\windows\system32\SetupBD.din
    2009-02-09 14:12 155,648 ac------ c:\windows\system32\dllcache\e100b325.sys
    2009-02-09 14:12 155,648 a------- c:\windows\system32\drivers\e100b325.sys
    2009-02-09 14:12 126,976 a------- c:\windows\system32\Prounstl.exe
    2009-02-09 14:12 19,456 a------- c:\windows\system32\IntelNic.dll
    2009-02-09 14:12 5,110 a------- c:\windows\system32\e100b325.din
    2009-02-09 14:12 <DIR> --d----- C:\drvrtmp
    2009-02-09 11:49 <DIR> --d----- c:\windows\system32\vmm32
    2009-02-09 11:49 <DIR> --d----- c:\program files\Dell
    2009-02-09 11:41 <DIR> --d----- c:\documents and settings\Sparx
    2009-02-09 11:37 <DIR> --ds---- c:\windows\system32\Microsoft
    2009-02-09 10:50 8,192 a------- c:\windows\REGLOCS.OLD
    2009-02-09 10:48 6,144 ac------ c:\windows\system32\dllcache\kbdax2.dll
    2009-02-09 10:47 290,816 ac------ c:\windows\system32\dllcache\adsiis51.dll
    2009-02-09 10:46 <DIR> --dsh--- c:\documents and settings\all users\DRM
    2009-02-09 10:46 488 a---hr-- c:\windows\system32\WindowsLogon.manifest
    2009-02-09 10:46 488 a---hr-- c:\windows\system32\logonui.exe.manifest
    2009-02-09 10:46 <DIR> --ds---- c:\windows\Downloaded Program Files
    2009-02-09 10:46 <DIR> --d--r-- c:\windows\Offline Web Pages
    2009-02-09 10:46 749 a---hr-- c:\windows\WindowsShell.Manifest
    2009-02-09 10:46 749 a---hr-- c:\windows\system32\wuaucpl.cpl.manifest
    2009-02-09 10:46 749 a---hr-- c:\windows\system32\sapi.cpl.manifest
    2009-02-09 10:46 749 a---hr-- c:\windows\system32\nwc.cpl.manifest
    2009-02-09 10:46 749 a---hr-- c:\windows\system32\ncpa.cpl.manifest
    2009-02-09 10:46 749 a---hr-- c:\windows\system32\cdplayer.exe.manifest
    2009-02-09 10:46 <DIR> --d-h--- c:\program files\WindowsUpdate
    2009-02-09 10:46 4,399,505 ac------ c:\windows\system32\dllcache\nls302en.lex
    2009-02-09 10:45 <DIR> --d----- c:\program files\common files\MSSoap
    2009-02-09 10:44 <DIR> --d----- c:\program files\Online Services
    2009-02-09 10:44 <DIR> --d----- c:\program files\Messenger
    2009-02-09 10:44 <DIR> --d----- c:\program files\MSN Gaming Zone
    2009-02-09 10:43 <DIR> --d----- c:\program files\Windows NT
    2009-02-09 04:38 <DIR> --d----- c:\program files\common files\ODBC
    2009-02-09 04:38 <DIR> --d----- c:\program files\common files\SpeechEngines
    2009-02-09 04:38 <DIR> --d--r-- c:\documents and settings\all users\Documents

    ==================== Find3M ====================

    2009-02-09 11:54 87,263 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
    2009-02-09 10:44 21,640 a------- c:\windows\system32\emptyregdb.dat

    ============= FINISH: 7:09:03.20 ===============
     
  2. 2009/03/01
    Gail22

    Gail22 Inactive Thread Starter

    Joined:
    2004/10/18
    Messages:
    51
    Likes Received:
    0
    I got a few clues on how to try to dismantle remote control of my computer from existing questions at forums.majorgeeks.com but it still does not tell me how to get my user name into Task Manager.
     

  3. to hide this advert.

  4. 2009/03/01
    rsinfo

    rsinfo SuperGeek Alumni

    Joined:
    2005/12/25
    Messages:
    4,076
    Likes Received:
    178
    You should run chkdsk /f on C: before proceeding any further.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.