1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive mouse clicks audible

Discussion in 'Malware and Virus Removal Archive' started by dogday, 2010/11/02.

Thread Status:
Not open for further replies.
  1. 2010/11/02
    dogday

    dogday Inactive Thread Starter

    Joined:
    2010/11/02
    Messages:
    1
    Likes Received:
    0
    [Inactive] mouse clicks audible

    I heard two-three dozen mouse clicks during last night's session, in the span of ten minutes. I had received an email from an acquaitance who bragged he could read my internet activity, and gain access to my history for passwords and banking transactions, with the software he had loaded two days previous. Although I ignore this individual, he persists. He claims he can do this simply by having my IP address. I have downloaded the DDS scan from this morning as follows. Thank you for your assistance:




    DDS (Ver_10-10-21.02) - NTFSx86
    Run by daveco at 9:31:28.17 on Tue 11/02/2010
    Internet Explorer: 8.0.6001.18975
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6002.2.1252.1.1033.18.2815.1371 [GMT -4:00]

    SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\System32\ZoneLabs\vsmon.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
    C:\Program Files\IObit\IObit Security 360\IS360srv.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Microsoft LifeCam\MSCamS32.exe
    C:\Program Files\Ralink\Common\RaRegistry.exe
    C:\Program Files\Realtek\RTL8187 Wireless LAN Utility\RtlService.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\System32\mobsync.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\IObit\IObit Security 360\is360tray.exe
    C:\Program Files\Web Accelerator\slipcore.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\BlazeVideo\BlazeDTV 2.5\MediaDetector.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
    C:\Program Files\Web Accelerator\slipgui.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\MSN Toolbar\Platform\6.3.2322.0\mswinext.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil10k_ActiveX.exe
    C:\Program Files\IObit\IObit Security 360\is360.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\daveco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2FX9YN1H\dds[1].pif
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://us.mg2.mail.yahoo.com/dc/launch?sysreq=ignore
    uSEARCH PAGE = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8
    uWindow Title = Windows Internet Explorer provided by Yahoo!
    mStart Page = hxxp://www.natisp.com/start
    mDefault_Page_URL = hxxp://www.natisp.com/start
    uInternet Settings,ProxyServer = http=127.0.0.1:5403
    uInternet Settings,ProxyOverride =

    <local>;127.0.0.1:5403;*update.microsoft.com;*windowsupdate.com;download.microsoft.com;codecs.microsoft.com;activex.microsoft.com;liveupdate.symantecliveupdate.com;liv

    eupdate.symantec.com;download.mcafee.com;*.phobos.apple.com;update.adobe.com;localhost;localhost;www.007guard.com;007guard.com;008i.com;www.008k.com;008k.com;www.00hq.

    com;00hq.com;010402.com;www.032439.com;032439.com;www.0scan...w.1001namen.com;1001namen.com;100888290cs.com

    ;www.100888290cs.com;100sexlinks.com...m;www.10sek.com;www.1-2005-search.com;1-2005-

    search.com;123haustiereundmehr.com;www.123haustiereundmehr.com;123movi...;www.123simsen.com;123topsearch.com;www.123to

    psearch.com;125sms.co.uk;www.125sms.co.uk;125sms.com;www.125...info;www.1337crew.info;www.1337-crew.to;1337-

    crew.to;136136.net;www.136136.net;150freesms.de;www.150freesms.de;163ns.com;www.163ns.com;171203.com;17-

    plus.com;1800searchonline.com;www.1800searchonline.com;www.180sea...www.180solutions.com;www.181.365soft.info;181

    .365soft.info;1987324.com;www.1987324.com;1-domains-registrations.com
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
    uURLSearchHooks: H - No File
    mURLSearchHooks: H - No File
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    BHO: Yahooo Search Protection: {25bc7718-0bfa-40ea-b381-4b2d9732d686} - c:\program files\yahoo!\search protection\ysp.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\windows\system32\ActiveToolBand.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Prefetch: {a66aa08a-9bf0-4e87-99e6-6972731d6b99} - c:\program files\web accelerator\Prefetch.dll
    BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
    TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
    TB: @c:\program files\msn toolbar\platform\6.3.2322.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\6.3.2322.0

    \npwinext.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
    uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
    uRun: [Internet Explorer] "c:\program files\internet explorer\iexplore.exe "
    uRun: [BlazeServoTool] "c:\program files\blazevideo\blazedtv 2.5\MediaDetector.exe "
    uRun: [Sidebar] "c:\program files\windows sidebar\sidebar.exe" /autoRun
    uRun: [Internet Explorer797] "c:\program files\internet explorer\iexplore.exe "
    uRun: [RunSpySweeperScheduleAtStartup] "c:\windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{2CF1C9E0-3938-4D95-8C8F-6F6AE934E7B3}
    uRun: [SpybotSD TeaTimer] "c:\program files\spybot - search & destroy\TeaTimer.exe "
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [SmartRAM] "c:\program files\iobit\advanced systemcare 3\Sup_SmartRAM.exe" /m
    mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
    mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
    mRun: [RtHDVCpl] RtHDVCpl.exe
    mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
    mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe "
    mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [IObit Security 360] "c:\program files\iobit\iobit security 360\IS360tray.exe" /autostart
    mRun: [SlipStream] "c:\program files\web accelerator\slipcore.exe "
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\1dialw~1.lnk - c:\program files\web accelerator\slipgui.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\ralink~1.lnk - c:\program files\ralink\common\RaUI.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Show All Original Images - c:\program files\web accelerator\gui_resource.dll/327
    IE: Show Original Image - c:\program files\web accelerator\gui_resource.dll/328
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
    TCP: {613694F3-98F8-4B40-BCBB-210DB43BB654} = 64.136.173.5 64.136.164.77
    mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet

    explorer\clrtour.inf,DefaultInstall.ResetTour,,12
    Hosts: 127.0.0.1 www.spywareinfo.com

    ============= SERVICES / DRIVERS ===============

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-6-6 64288]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-8-28 165584]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-8-28 17744]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-8-28 50768]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-28 40384]
    R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2010-9-22 312152]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-7-12 1357464]
    R2 RalinkRegistryWriter;Ralink Registry Writer;c:\program files\ralink\common\RaRegistry.exe [2010-9-27 185632]
    R2 RealtekUSB;RealtekUSB;c:\program files\realtek\rtl8187 wireless lan utility\RtlService.exe [2009-12-31 36864]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-8-7 1153368]
    R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2010\TuneUpUtilitiesService32.exe [2010-4-19 1050440]
    R3 AuviUATV;Auvitek Dongle NTSC Capture Device;c:\windows\system32\drivers\AuviUATV.sys [2008-6-25 1071488]
    R3 AuviUDTV;Auvitek Dongle ATSC Capture;c:\windows\system32\drivers\AuviUDTV.sys [2008-6-25 1070464]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-28 40384]
    R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-28 40384]
    R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2010\TuneUpUtilitiesDriver32.sys [2010-2-25 10064]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-12 135664]
    S3 DNIMp50;DNIMp50 NDIS Protocol Driver;c:\windows\system32\drivers\DNIMP50.sys [2006-11-16 21504]
    S3 DNISp50;DNISp50 NDIS Protocol Driver;c:\windows\system32\drivers\DNISP50.sys [2006-11-16 20480]
    S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-4-13 21504]
    S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-26 15008]
    S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [2010-5-20 30576]
    S3 netr28u;RT2870 USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2010-9-27 839456]
    S3 Ph3xIB32;Philips 713x Inbox PCI TV Card;c:\windows\system32\drivers\Ph3xIB32.sys [2007-4-3 1131136]
    S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\rtl8187.sys [2009-12-31 335872]
    S3 RtlProt;RtlProt;c:\windows\system32\drivers\RtlProt.sys [2009-12-31 25896]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]

    =============== Created Last 30 ================

    2010-11-02 10:52:30 6146896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{8754ed43-ba21-426d-94d6-a81639ebd85e}\mpengine.dll
    2010-10-27 14:02:59 1696256 ----a-w- c:\windows\system32\gameux.dll
    2010-10-27 14:02:57 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
    2010-10-27 14:02:56 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
    2010-10-26 13:44:57 420352 ----a-w- c:\windows\system32\vbscript.dll
    2010-10-26 13:39:56 13312 ----a-w- c:\program files\internet explorer\iecompat.dll
    2010-10-25 15:13:36 -------- d--h--w- c:\windows\msdownld.tmp
    2010-10-25 00:54:52 -------- d-----w- c:\program files\MSN Toolbar
    2010-10-25 00:54:28 -------- d-----w- c:\program files\Bing Bar Installer
    2010-10-25 00:53:57 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
    2010-10-25 00:53:57 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
    2010-10-25 00:53:57 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
    2010-10-25 00:53:06 469256 ----a-w- c:\program files\common files\windows live\.cache\f7063e4a1cb73de0f\InstallManager_WLE_WLE.exe
    2010-10-25 00:52:53 15712 ----a-w- c:\program files\common files\windows live\.cache\f41d4f2a1cb73de0d\MeshBetaRemover.exe
    2010-10-25 00:52:52 94040 ----a-w- c:\program files\common files\windows live\.cache\f3754f5a1cb73de0c\DSETUP.dll
    2010-10-25 00:52:52 525656 ----a-w- c:\program files\common files\windows live\.cache\f3754f5a1cb73de0c\DXSETUP.exe
    2010-10-25 00:52:52 1691480 ----a-w- c:\program files\common files\windows live\.cache\f3754f5a1cb73de0c\dsetup32.dll
    2010-10-25 00:52:40 525656 ----a-w- c:\program files\common files\windows live\.cache\eae7d38a1cb73de0b\DXSETUP.exe
    2010-10-25 00:52:39 94040 ----a-w- c:\program files\common files\windows live\.cache\eae7d38a1cb73de0b\DSETUP.dll
    2010-10-25 00:52:39 1691480 ----a-w- c:\program files\common files\windows live\.cache\eae7d38a1cb73de0b\dsetup32.dll
    2010-10-25 00:51:19 -------- d-----w- c:\users\daveco\appdata\local\Windows Live
    2010-10-25 00:46:30 754688 ----a-w- c:\windows\system32\webservices.dll
    2010-10-13 13:59:43 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
    2010-10-13 13:59:42 8147456 ----a-w- c:\windows\system32\wmploc.DLL
    2010-10-13 13:55:48 304128 ----a-w- c:\windows\system32\drivers\srv.sys
    2010-10-13 13:55:48 145408 ----a-w- c:\windows\system32\drivers\srv2.sys
    2010-10-13 13:55:48 125952 ----a-w- c:\windows\system32\srvsvc.dll
    2010-10-13 13:55:48 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
    2010-10-13 13:55:47 17920 ----a-w- c:\windows\system32\netevent.dll
    2010-10-13 13:55:29 954752 ----a-w- c:\windows\system32\mfc40.dll
    2010-10-13 13:55:28 954288 ----a-w- c:\windows\system32\mfc40u.dll
    2010-10-13 13:49:00 274944 ----a-w- c:\windows\system32\schannel.dll
    2010-10-13 13:48:58 339968 ----a-w- c:\program files\windows nt\accessories\wordpad.exe
    2010-10-13 13:48:58 1316864 ----a-w- c:\windows\system32\ole32.dll
    2010-10-13 13:48:19 867328 ----a-w- c:\windows\system32\wmpmde.dll
    2010-10-13 13:48:09 2038272 ----a-w- c:\windows\system32\win32k.sys
    2010-10-13 13:47:59 531968 ----a-w- c:\windows\system32\comctl32.dll
    2010-10-13 13:47:57 157184 ----a-w- c:\windows\system32\t2embed.dll
    2010-10-13 13:47:55 231424 ----a-w- c:\windows\system32\msshsq.dll

    ==================== Find3M ====================

    2010-10-19 15:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
    2010-09-30 14:38:09 9728 ----a-w- c:\windows\system32\rnaph.dll
    2010-09-08 15:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-09-08 15:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2010-09-08 06:01:28 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-09-08 05:57:18 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2010-09-08 05:57:05 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
    2010-09-08 05:56:53 71680 ----a-w- c:\windows\system32\iesetup.dll
    2010-09-08 05:56:53 109056 ----a-w- c:\windows\system32\iesysprep.dll
    2010-09-08 05:04:36 385024 ----a-w- c:\windows\system32\html.iec
    2010-09-08 04:26:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
    2010-09-08 04:25:15 1638912 ----a-w- c:\windows\system32\mshtml.tlb
    2010-09-07 15:12:17 38848 ----a-w- c:\windows\avastSS.scr
    2010-08-26 16:33:06 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
    2010-08-26 16:33:04 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
    2010-08-26 16:33:04 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
    2010-08-26 16:33:04 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
    2010-08-17 14:11:37 128000 ----a-w- c:\windows\system32\spoolsv.exe

    ============= FINISH: 9:32:37.19 ===============
     
  2. 2010/11/02
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    Also need the Attach.txt log
     

  3. to hide this advert.

  4. 2010/11/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Also, disable "word wrap" in Notepad, because your logs are hard to read.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.