[ Done ] I've been infected with some sort of virus

  • 11 Replies
  • 3922 Views
*

Offline ryansarda

  • Bronze Member
  • 20
[ Done ] I've been infected with some sort of virus
« on: March 17, 2009, 12:22:10 AM »
I was checking my e-mail and then my computer started all of a sudden spazzing out. It kept opening Internet Explorer windows when I wasn't even on the Internet. It also keeps telling me that I have Spyware Protect 2009 and I need to update it.

Below is a copy of my Hijackthis.exe log:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 2:12:24 AM, on 3/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\sysguard.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis_61608.exe
C:\WINDOWS\svcho.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080522
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=1080522
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO - {C9C42510-9B21-41c1-9DCD-8382A2D07C61} - C:\WINDOWS\system32\iehelper.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [BCROReminder] C:\Program Files\ByteCrusher\RegistryOptimax\BCRO.exe -rem
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [BCROReminder] C:\Program Files\ByteCrusher\RegistryOptimax\BCRO.exe -rem
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [system tool] C:\WINDOWS\sysguard.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader57.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 10413 bytes




I've came here before and some kind soul helped me fix my computer. I never got around to thanking them becauseI had a death in my family the following week and I went away for a while. But if he or she could also help me with this, I'd greatly appreciate it.

Thanks again!!
« Last Edit: March 21, 2009, 05:58:21 AM by bamajim »

*

Offline bamajim

  • Administrator
  • Platinum Member
  • 3116
Re: I've been infected with some sort of virus
« Reply #1 on: March 17, 2009, 01:37:23 PM »
ryansarda

1. Go HERE and download File Lister.

Save it to your Desktop
Rt Click ->> Extract all ->> And extract it to your Desktop
Additional help on extracting zip files can be found HERE
Open the File Lister Folder.
Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
As the program runs, it will appear that nothing is happening.
When the program is fnished it will produce a log for you C:\Files.txt
Copy and paste the contents of that log in your reply.

2008-2010
Rights cannot exist without morals

*

Offline ryansarda

  • Bronze Member
  • 20
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #2 on: March 17, 2009, 09:17:26 PM »
Here's my log. Thanks again for your help!!!







+++++++++++++++++++++++++++++++++
+ File Lister  Version 1.0.7
+
+  By bamajim / bamajim.com
+++++++++++++++++++++++++++++++++

Report ran on --->>>  3/17/2009 11:11:59 PM


====== Running Processes ======

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\WINDOWS\svcho.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\System32\WScript.exe

====== BHO's ======

BHO: (NO NAME) - {02478D38-C3F9-4efb-9B51-7695ECA05670} -

BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

BHO: (NO NAME) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

====== HKLM\~\Run Keys ======

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

[SynTPEnh] = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[IgfxTray] = C:\WINDOWS\system32\igfxtray.exe
[HotKeysCmds] = C:\WINDOWS\system32\hkcmd.exe
[Persistence] = C:\WINDOWS\system32\igfxpers.exe
[Broadcom Wireless Manager UI] = C:\WINDOWS\system32\WLTRAY.exe
[SigmatelSysTrayApp] = stsystra.exe
[KADxMain] = C:\WINDOWS\system32\KADxMain.exe
[Google Desktop Search] = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[dscactivate] = "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
[Adobe Reader Speed Launcher] = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[ccApp] = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
[vptray] = C:\PROGRA~1\SYMANT~1\VPTray.exe
[QuickTime Task] = "C:\Program Files\QuickTime\qttask.exe" -atboottime
[iTunesHelper] = "C:\Program Files\iTunes\iTunesHelper.exe"
[DellSupportCenter] = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
[BCROReminder] = C:\Program Files\ByteCrusher\RegistryOptimax\BCRO.exe -rem
[SunJavaUpdateSched] = "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
[Monitor] = C:\WINDOWS\PixArt\PAC207\Monitor.exe
[LogitechCommunicationsManager] = "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
[LogitechQuickCamRibbon] = "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide

====== HKCU\~\Run Keys ======

[DellSupportCenter] = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
[BCROReminder] = C:\Program Files\ByteCrusher\RegistryOptimax\BCRO.exe -rem
[ctfmon.exe] = C:\WINDOWS\system32\ctfmon.exe
[Skype] = "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======

2/13/2009 12:48:55 PM    152095    32    C:\A0000005.VOC
2/4/2009 1:38:55 PM    1626591    32    C:\A0000158.VOC
2/5/2009 1:43:25 AM    619871    32    C:\A0000161.VOC
3/17/2009 11:11:59 PM    0    32    C:\Files.txt
3/17/2009 6:27:18 AM    621517    C:\WINDOWS\$NtUninstallKB938464-v2$
3/17/2009 6:27:18 AM    621517    C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst
3/17/2009 6:27:07 AM    955768    C:\WINDOWS\$NtUninstallKB958687$
3/17/2009 6:27:07 AM    621944    C:\WINDOWS\$NtUninstallKB958687$\spuninst
3/17/2009 6:26:53 AM    2468248    C:\WINDOWS\$NtUninstallKB958690$
3/17/2009 6:26:53 AM    621848    C:\WINDOWS\$NtUninstallKB958690$\spuninst
3/17/2009 6:26:45 AM    11456152    C:\WINDOWS\$NtUninstallKB959772_WM11$
3/17/2009 6:26:45 AM    621208    C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst
3/17/2009 6:27:22 AM    766398    C:\WINDOWS\$NtUninstallKB960225$
3/17/2009 6:27:22 AM    622014    C:\WINDOWS\$NtUninstallKB960225$\spuninst
3/17/2009 6:27:13 AM    870799    C:\WINDOWS\$NtUninstallKB960715$
3/17/2009 6:27:13 AM    620943    C:\WINDOWS\$NtUninstallKB960715$\spuninst
3/17/2009 6:27:00 AM    9084189    C:\WINDOWS\$NtUninstallKB967715$
3/17/2009 6:27:00 AM    622877    C:\WINDOWS\$NtUninstallKB967715$\spuninst
3/14/2009 11:39:50 PM    7316581    C:\WINDOWS\Pixart
3/14/2009 11:40:07 PM    3252587    C:\WINDOWS\Pixart\Pac207
3/14/2009 11:39:50 PM    2056061    C:\WINDOWS\Pixart\PXIINST-32
3/14/2009 11:39:50 PM    2007933    C:\WINDOWS\Pixart\PXIINST-64
3/16/2009 10:10:32 AM    127034    1    C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2/5/2009 12:43:55 AM    0    32    C:\WINDOWS\Dvm.INI
3/14/2009 11:41:05 PM    212480    32    C:\WINDOWS\PCDLIB32.DLL
3/17/2009 2:08:15 AM    16896    32    C:\WINDOWS\svcho.exe
3/17/2009 2:08:15 AM    16896    32    C:\WINDOWS\syssvc.exe
3/14/2009 11:39:47 PM    6656    32    C:\WINDOWS\system32\CoInst.dll
3/16/2009 10:12:32 AM    20992    32    C:\WINDOWS\system32\dshowext.ax
3/14/2009 11:40:30 PM    16384    32    C:\WINDOWS\system32\ipsink.ax
3/14/2009 11:40:06 PM    61952    32    C:\WINDOWS\system32\kstvtune.ax
3/14/2009 11:40:06 PM    91136    32    C:\WINDOWS\system32\kswdmcap.ax
3/14/2009 11:40:06 PM    43008    32    C:\WINDOWS\system32\ksxbar.ax
3/16/2009 10:12:33 AM    129824    33    C:\WINDOWS\system32\lvci1051.dll
3/16/2009 10:12:33 AM    264992    33    C:\WINDOWS\system32\lvcodec2.dll
3/16/2009 10:12:33 AM    50127    33    C:\WINDOWS\system32\lvcoinst.ini
3/16/2009 10:12:33 AM    3734    32    C:\WINDOWS\system32\lvcoinst.log
3/16/2009 10:12:33 AM    215840    33    C:\WINDOWS\system32\LVUI2.dll
3/16/2009 10:12:33 AM    527136    33    C:\WINDOWS\system32\LVUI2RC.dll
3/17/2009 1:35:03 AM    55808    32    C:\WINDOWS\system32\mcenspc.dll
3/16/2009 10:12:33 AM    13398    33    C:\WINDOWS\system32\Repository.reg
3/14/2009 11:39:46 PM    119296    32    C:\WINDOWS\system32\SP207.AX
3/14/2009 11:39:46 PM    518    32    C:\WINDOWS\system32\SP207.INI
3/14/2009 11:40:06 PM    53760    32    C:\WINDOWS\system32\vfwwdm32.dll

====== Files under "\Administrator\Startup" Last 60 Days======


====== Files under "\All Users\Startup" Last 60 Days======

3/16/2009 10:10:39 AM    2074    32    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk

====== Folders under "\Program Files" Last 60 Days======

3/14/2009 11:41:01 PM    453180026    C:\Program Files\ArcSoft
3/14/2009 11:42:15 PM    310745337    C:\Program Files\ArcSoft\PhotoImpression 5
3/14/2009 11:42:18 PM    189496    C:\Program Files\ArcSoft\PhotoImpression 5\Albums
3/14/2009 11:42:18 PM    451994    C:\Program Files\ArcSoft\PhotoImpression 5\CheckUpdate
3/14/2009 11:42:18 PM    197305579    C:\Program Files\ArcSoft\PhotoImpression 5\Contents
3/14/2009 11:42:19 PM    85127497    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar
3/14/2009 11:42:19 PM    40629807    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month
3/14/2009 11:42:19 PM    4779796    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals
3/14/2009 11:42:20 PM    1963012    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals\cal24
3/14/2009 11:42:20 PM    168172    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals\cal24\calMonth
3/14/2009 11:42:20 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals\cal24\calWeek
3/14/2009 11:42:24 PM    77808    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals\cal24\calYear
3/14/2009 11:42:25 PM    87672    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\FilmStrp
3/14/2009 11:42:25 PM    3699936    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers
3/14/2009 11:42:26 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers\cal85
3/14/2009 11:42:26 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers\cal85\calMonth
3/14/2009 11:42:27 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers\cal85\calWeek
3/14/2009 11:42:27 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers\cal85\calYear
3/14/2009 11:42:28 PM    6659496    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays
3/14/2009 11:42:30 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays\cal61
3/14/2009 11:42:30 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays\cal61\calMonth
3/14/2009 11:42:31 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays\cal61\calWeek
3/14/2009 11:42:32 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays\cal61\calYear
3/14/2009 11:42:33 PM    4306604    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter
3/14/2009 11:42:33 PM    1979708    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter\cal45
3/14/2009 11:42:33 PM    199512    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter\cal45\calMonth
3/14/2009 11:42:33 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter\cal45\calWeek
3/14/2009 11:42:34 PM    63164    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter\cal45\calYear
3/14/2009 11:42:35 PM    4833668    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons
3/14/2009 11:42:35 PM    2007436    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons\cal57
3/14/2009 11:42:35 PM    192840    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons\cal57\calMonth
3/14/2009 11:42:36 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons\cal57\calWeek
3/14/2009 11:42:37 PM    97564    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons\cal57\calYear
3/14/2009 11:42:37 PM    6235500    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies
3/14/2009 11:42:39 PM    1852788    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies\cal33
3/14/2009 11:42:39 PM    91476    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies\cal33\calMonth
3/14/2009 11:42:40 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies\cal33\calWeek
3/14/2009 11:42:41 PM    44280    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies\cal33\calYear
3/14/2009 11:42:41 PM    6060480    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports
3/14/2009 11:42:43 PM    1896128    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports\cal9
3/14/2009 11:42:43 PM    119920    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports\cal9\calMonth
3/14/2009 11:42:43 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports\cal9\calWeek
3/14/2009 11:42:44 PM    59176    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports\cal9\calYear
3/14/2009 11:42:44 PM    216017    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Thumb
3/14/2009 11:42:44 PM    3750056    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave
3/14/2009 11:42:45 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave\cal73
3/14/2009 11:42:45 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave\cal73\calMonth
3/14/2009 11:42:45 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave\cal73\calWeek
3/14/2009 11:42:46 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave\cal73\calYear
3/14/2009 11:42:20 PM    22987821    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly
3/14/2009 11:42:39 PM    11395552    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land
3/14/2009 11:42:48 PM    1852788    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal100
3/14/2009 11:42:48 PM    91476    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal100\calMonth
3/14/2009 11:42:48 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal100\calWeek
3/14/2009 11:42:49 PM    44280    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal100\calYear
3/14/2009 11:42:49 PM    1852788    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal101
3/14/2009 11:42:49 PM    91476    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal101\calMonth
3/14/2009 11:42:50 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal101\calWeek
3/14/2009 11:42:51 PM    44280    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal101\calYear
3/14/2009 11:42:39 PM    1852788    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal106
3/14/2009 11:42:39 PM    91476    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal106\calMonth
3/14/2009 11:42:52 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal106\calWeek
3/14/2009 11:42:41 PM    44280    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal106\calYear
3/14/2009 11:42:53 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal107
3/14/2009 11:42:53 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal107\calMonth
3/14/2009 11:42:53 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal107\calWeek
3/14/2009 11:42:54 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal107\calYear
3/14/2009 11:42:54 PM    1979708    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal109
3/14/2009 11:42:54 PM    199512    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal109\calMonth
3/14/2009 11:42:54 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal109\calWeek
3/14/2009 11:42:55 PM    63164    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal109\calYear
3/14/2009 11:42:55 PM    76876    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\Thumb
3/14/2009 11:42:20 PM    11592269    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port
3/14/2009 11:42:56 PM    2007436    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal102
3/14/2009 11:42:56 PM    192840    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal102\calMonth
3/14/2009 11:42:56 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal102\calWeek
3/14/2009 11:42:56 PM    97564    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal102\calYear
3/14/2009 11:42:35 PM    2007436    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal103
3/14/2009 11:42:35 PM    192840    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal103\calMonth
3/14/2009 11:42:57 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal103\calWeek
3/14/2009 11:42:37 PM    97564    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal103\calYear
3/14/2009 11:42:58 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal104
3/14/2009 11:42:58 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal104\calMonth
3/14/2009 11:42:58 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal104\calWeek
3/14/2009 11:42:58 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal104\calYear
3/14/2009 11:42:26 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal105
3/14/2009 11:42:26 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal105\calMonth
3/14/2009 11:42:59 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal105\calWeek
3/14/2009 11:42:27 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal105\calYear
3/14/2009 11:42:20 PM    1979708    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal108

*

Offline bamajim

  • Administrator
  • Platinum Member
  • 3116
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #3 on: March 18, 2009, 07:17:51 AM »
ryansarda

Part of the FileLister log is missing. But you have posted enough for us to get started

1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop

(How to extract (decompress) zipped or compressed files, help in the link here: )
[/list]
2. Copy all the text contained in the bold below to your Clipboard by highlighting it and pressing (Ctrl+C):


Files to Delete:
C:\WINDOWS\svcho.exe
C:\WINDOWS\syssvc.exe
C:\WINDOWS\system32\mcenspc.dll
C:\WINDOWS\sysguard.exe


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Select Load Script
  • Select Paste from Clipboard
  • The information should now appear in the Open window
  • Select Execute
  • Answer Yes When prompted "Are you sure you want to execute the current script?"
4. The Avenger will automatically do the following:
  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply.


2008-2010
Rights cannot exist without morals

*

Offline ryansarda

  • Bronze Member
  • 20
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #4 on: March 18, 2009, 09:24:27 AM »
Thank you again!!!




//////////////////////////////////////////
  Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 3)
Wed Mar 18 11:19:28 2009

11:19:28: Error: Invalid script.  A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform:  Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "C:\WINDOWS\svcho.exe" deleted successfully.
File "C:\WINDOWS\syssvc.exe" deleted successfully.
File "C:\WINDOWS\system32\mcenspc.dll" deleted successfully.

Error:  file "C:\WINDOWS\sysguard.exe" not found!
Deletion of file "C:\WINDOWS\sysguard.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist


Completed script processing.

*******************

Finished!  Terminate.

*

Offline bamajim

  • Administrator
  • Platinum Member
  • 3116
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #5 on: March 18, 2009, 09:41:42 AM »
ryansarda

You are most welcome.

Rerun FileLister and post a fresh FileLister log please

2008-2010
Rights cannot exist without morals

*

Offline ryansarda

  • Bronze Member
  • 20
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #6 on: March 18, 2009, 10:11:52 AM »
It says the post exceeds 50,000 characters, so I'm going to send the log in two parts.

+++++++++++++++++++++++++++++++++
+ File Lister  Version 1.0.7
+
+  By bamajim / bamajim.com
+++++++++++++++++++++++++++++++++

Report ran on --->>>  3/18/2009 12:07:44 PM


====== Running Processes ======

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\System32\WScript.exe

====== BHO's ======

BHO: (NO NAME) - {02478D38-C3F9-4efb-9B51-7695ECA05670} -

BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

BHO: (NO NAME) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

====== HKLM\~\Run Keys ======

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

[SynTPEnh] = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[IgfxTray] = C:\WINDOWS\system32\igfxtray.exe
[HotKeysCmds] = C:\WINDOWS\system32\hkcmd.exe
[Persistence] = C:\WINDOWS\system32\igfxpers.exe
[Broadcom Wireless Manager UI] = C:\WINDOWS\system32\WLTRAY.exe
[SigmatelSysTrayApp] = stsystra.exe
[KADxMain] = C:\WINDOWS\system32\KADxMain.exe
[Google Desktop Search] = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[dscactivate] = "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
[Adobe Reader Speed Launcher] = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[ccApp] = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
[vptray] = C:\PROGRA~1\SYMANT~1\VPTray.exe
[QuickTime Task] = "C:\Program Files\QuickTime\qttask.exe" -atboottime
[iTunesHelper] = "C:\Program Files\iTunes\iTunesHelper.exe"
[DellSupportCenter] = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
[BCROReminder] = C:\Program Files\ByteCrusher\RegistryOptimax\BCRO.exe -rem
[SunJavaUpdateSched] = "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
[Monitor] = C:\WINDOWS\PixArt\PAC207\Monitor.exe
[LogitechCommunicationsManager] = "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
[LogitechQuickCamRibbon] = "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide

====== HKCU\~\Run Keys ======

[DellSupportCenter] = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
[BCROReminder] = C:\Program Files\ByteCrusher\RegistryOptimax\BCRO.exe -rem
[ctfmon.exe] = C:\WINDOWS\system32\ctfmon.exe
[Skype] = "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======

3/18/2009 11:20:42 AM    74649    C:\Avenger
2/13/2009 12:48:55 PM    152095    32    C:\A0000005.VOC
2/4/2009 1:38:55 PM    1626591    32    C:\A0000158.VOC
2/5/2009 1:43:25 AM    619871    32    C:\A0000161.VOC
3/18/2009 11:19:28 AM    2314    32    C:\avenger.txt
3/17/2009 11:11:59 PM    0    32    C:\Files.txt
3/17/2009 6:27:18 AM    621517    C:\WINDOWS\$NtUninstallKB938464-v2$
3/17/2009 6:27:18 AM    621517    C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst
3/17/2009 6:27:07 AM    955768    C:\WINDOWS\$NtUninstallKB958687$
3/17/2009 6:27:07 AM    621944    C:\WINDOWS\$NtUninstallKB958687$\spuninst
3/17/2009 6:26:53 AM    2468248    C:\WINDOWS\$NtUninstallKB958690$
3/17/2009 6:26:53 AM    621848    C:\WINDOWS\$NtUninstallKB958690$\spuninst
3/17/2009 6:26:45 AM    11456152    C:\WINDOWS\$NtUninstallKB959772_WM11$
3/17/2009 6:26:45 AM    621208    C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst
3/17/2009 6:27:22 AM    766398    C:\WINDOWS\$NtUninstallKB960225$
3/17/2009 6:27:22 AM    622014    C:\WINDOWS\$NtUninstallKB960225$\spuninst
3/17/2009 6:27:13 AM    870799    C:\WINDOWS\$NtUninstallKB960715$
3/17/2009 6:27:13 AM    620943    C:\WINDOWS\$NtUninstallKB960715$\spuninst
3/17/2009 6:27:00 AM    9084189    C:\WINDOWS\$NtUninstallKB967715$
3/17/2009 6:27:00 AM    622877    C:\WINDOWS\$NtUninstallKB967715$\spuninst
3/14/2009 11:39:50 PM    7316581    C:\WINDOWS\Pixart
3/14/2009 11:40:07 PM    3252587    C:\WINDOWS\Pixart\Pac207
3/14/2009 11:39:50 PM    2056061    C:\WINDOWS\Pixart\PXIINST-32
3/14/2009 11:39:50 PM    2007933    C:\WINDOWS\Pixart\PXIINST-64
3/18/2009 10:30:39 AM    0    32    C:\WINDOWS\0.log
3/16/2009 10:10:32 AM    127034    1    C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2/5/2009 12:43:55 AM    0    32    C:\WINDOWS\Dvm.INI
3/14/2009 11:41:05 PM    212480    32    C:\WINDOWS\PCDLIB32.DLL
3/18/2009 10:41:42 AM    1090    32    C:\WINDOWS\setupapi.log
3/14/2009 11:39:47 PM    6656    32    C:\WINDOWS\system32\CoInst.dll
3/16/2009 10:12:32 AM    20992    32    C:\WINDOWS\system32\dshowext.ax
3/14/2009 11:40:30 PM    16384    32    C:\WINDOWS\system32\ipsink.ax
3/14/2009 11:40:06 PM    61952    32    C:\WINDOWS\system32\kstvtune.ax
3/14/2009 11:40:06 PM    91136    32    C:\WINDOWS\system32\kswdmcap.ax
3/14/2009 11:40:06 PM    43008    32    C:\WINDOWS\system32\ksxbar.ax
3/16/2009 10:12:33 AM    129824    33    C:\WINDOWS\system32\lvci1051.dll
3/16/2009 10:12:33 AM    264992    33    C:\WINDOWS\system32\lvcodec2.dll
3/16/2009 10:12:33 AM    50127    33    C:\WINDOWS\system32\lvcoinst.ini
3/16/2009 10:12:33 AM    3734    32    C:\WINDOWS\system32\lvcoinst.log
3/16/2009 10:12:33 AM    215840    33    C:\WINDOWS\system32\LVUI2.dll
3/16/2009 10:12:33 AM    527136    33    C:\WINDOWS\system32\LVUI2RC.dll
3/16/2009 10:12:33 AM    13398    33    C:\WINDOWS\system32\Repository.reg
3/14/2009 11:39:46 PM    119296    32    C:\WINDOWS\system32\SP207.AX
3/14/2009 11:39:46 PM    518    32    C:\WINDOWS\system32\SP207.INI
3/14/2009 11:40:06 PM    53760    32    C:\WINDOWS\system32\vfwwdm32.dll

====== Files under "\Administrator\Startup" Last 60 Days======


====== Files under "\All Users\Startup" Last 60 Days======

3/16/2009 10:10:39 AM    2074    32    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk

*

Offline ryansarda

  • Bronze Member
  • 20
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #7 on: March 18, 2009, 10:12:58 AM »
====== Folders under "\Program Files" Last 60 Days======

3/14/2009 11:41:01 PM    453180026    C:\Program Files\ArcSoft
3/14/2009 11:42:15 PM    310745337    C:\Program Files\ArcSoft\PhotoImpression 5
3/14/2009 11:42:18 PM    189496    C:\Program Files\ArcSoft\PhotoImpression 5\Albums
3/14/2009 11:42:18 PM    451994    C:\Program Files\ArcSoft\PhotoImpression 5\CheckUpdate
3/14/2009 11:42:18 PM    197305579    C:\Program Files\ArcSoft\PhotoImpression 5\Contents
3/14/2009 11:42:19 PM    85127497    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar
3/14/2009 11:42:19 PM    40629807    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month
3/14/2009 11:42:19 PM    4779796    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals
3/14/2009 11:42:20 PM    1963012    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals\cal24
3/14/2009 11:42:20 PM    168172    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals\cal24\calMonth
3/14/2009 11:42:20 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals\cal24\calWeek
3/14/2009 11:42:24 PM    77808    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Animals\cal24\calYear
3/14/2009 11:42:25 PM    87672    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\FilmStrp
3/14/2009 11:42:25 PM    3699936    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers
3/14/2009 11:42:26 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers\cal85
3/14/2009 11:42:26 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers\cal85\calMonth
3/14/2009 11:42:27 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers\cal85\calWeek
3/14/2009 11:42:27 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Flowers\cal85\calYear
3/14/2009 11:42:28 PM    6659496    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays
3/14/2009 11:42:30 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays\cal61
3/14/2009 11:42:30 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays\cal61\calMonth
3/14/2009 11:42:31 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays\cal61\calWeek
3/14/2009 11:42:32 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Holidays\cal61\calYear
3/14/2009 11:42:33 PM    4306604    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter
3/14/2009 11:42:33 PM    1979708    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter\cal45
3/14/2009 11:42:33 PM    199512    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter\cal45\calMonth
3/14/2009 11:42:33 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter\cal45\calWeek
3/14/2009 11:42:34 PM    63164    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Letter\cal45\calYear
3/14/2009 11:42:35 PM    4833668    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons
3/14/2009 11:42:35 PM    2007436    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons\cal57
3/14/2009 11:42:35 PM    192840    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons\cal57\calMonth
3/14/2009 11:42:36 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons\cal57\calWeek
3/14/2009 11:42:37 PM    97564    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Seasons\cal57\calYear
3/14/2009 11:42:37 PM    6235500    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies
3/14/2009 11:42:39 PM    1852788    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies\cal33
3/14/2009 11:42:39 PM    91476    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies\cal33\calMonth
3/14/2009 11:42:40 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies\cal33\calWeek
3/14/2009 11:42:41 PM    44280    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Skies\cal33\calYear
3/14/2009 11:42:41 PM    6060480    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports
3/14/2009 11:42:43 PM    1896128    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports\cal9
3/14/2009 11:42:43 PM    119920    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports\cal9\calMonth
3/14/2009 11:42:43 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports\cal9\calWeek
3/14/2009 11:42:44 PM    59176    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Sports\cal9\calYear
3/14/2009 11:42:44 PM    216017    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Thumb
3/14/2009 11:42:44 PM    3750056    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave
3/14/2009 11:42:45 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave\cal73
3/14/2009 11:42:45 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave\cal73\calMonth
3/14/2009 11:42:45 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave\cal73\calWeek
3/14/2009 11:42:46 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\12month\Wave\cal73\calYear
3/14/2009 11:42:20 PM    22987821    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly
3/14/2009 11:42:39 PM    11395552    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land
3/14/2009 11:42:48 PM    1852788    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal100
3/14/2009 11:42:48 PM    91476    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal100\calMonth
3/14/2009 11:42:48 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal100\calWeek
3/14/2009 11:42:49 PM    44280    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal100\calYear
3/14/2009 11:42:49 PM    1852788    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal101
3/14/2009 11:42:49 PM    91476    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal101\calMonth
3/14/2009 11:42:50 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal101\calWeek
3/14/2009 11:42:51 PM    44280    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal101\calYear
3/14/2009 11:42:39 PM    1852788    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal106
3/14/2009 11:42:39 PM    91476    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal106\calMonth
3/14/2009 11:42:52 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal106\calWeek
3/14/2009 11:42:41 PM    44280    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal106\calYear
3/14/2009 11:42:53 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal107
3/14/2009 11:42:53 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal107\calMonth
3/14/2009 11:42:53 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal107\calWeek
3/14/2009 11:42:54 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal107\calYear
3/14/2009 11:42:54 PM    1979708    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal109
3/14/2009 11:42:54 PM    199512    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal109\calMonth
3/14/2009 11:42:54 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal109\calWeek
3/14/2009 11:42:55 PM    63164    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\cal109\calYear
3/14/2009 11:42:55 PM    76876    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Land\Thumb
3/14/2009 11:42:20 PM    11592269    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port
3/14/2009 11:42:56 PM    2007436    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal102
3/14/2009 11:42:56 PM    192840    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal102\calMonth
3/14/2009 11:42:56 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal102\calWeek
3/14/2009 11:42:56 PM    97564    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal102\calYear
3/14/2009 11:42:35 PM    2007436    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal103
3/14/2009 11:42:35 PM    192840    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal103\calMonth
3/14/2009 11:42:57 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal103\calWeek
3/14/2009 11:42:37 PM    97564    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal103\calYear
3/14/2009 11:42:58 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal104
3/14/2009 11:42:58 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal104\calMonth
3/14/2009 11:42:58 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal104\calWeek
3/14/2009 11:42:58 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal104\calYear
3/14/2009 11:42:26 PM    2028304    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal105
3/14/2009 11:42:26 PM    207704    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal105\calMonth
3/14/2009 11:42:59 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal105\calWeek
3/14/2009 11:42:27 PM    103568    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal105\calYear
3/14/2009 11:42:20 PM    1979708    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal108
3/14/2009 11:42:33 PM    199512    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal108\calMonth
3/14/2009 11:42:20 PM    1717032    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal108\calWeek
3/14/2009 11:42:34 PM    63164    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\cal108\calYear
3/14/2009 11:43:00 PM    35033    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Monthly\Port\Thumb
3/14/2009 11:43:00 PM    21509869    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly
3/14/2009 11:43:00 PM    11679066    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Land
3/14/2009 11:43:03 PM    1455416    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Land\cal1
3/14/2009 11:43:04 PM    1737440    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Land\cal2
3/14/2009 11:43:05 PM    3117208    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Land\cal3
3/14/2009 11:43:08 PM    1480412    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Land\cal4
3/14/2009 11:43:03 PM    1455416    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Land\cal9
3/14/2009 11:43:09 PM    21482    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Land\Thumb
3/14/2009 11:43:09 PM    9830803    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Port
3/14/2009 11:43:10 PM    1578268    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Port\cal10
3/14/2009 11:43:11 PM    1578268    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Port\cal5
3/14/2009 11:43:10 PM    1578268    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Port\cal6
3/14/2009 11:43:12 PM    1451176    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Port\cal7
3/14/2009 11:43:12 PM    1434756    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Port\cal8
3/14/2009 11:43:13 PM    19291    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Calendar\Yearly\Port\Thumb
3/14/2009 11:43:13 PM    13705524    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common
3/14/2009 11:43:13 PM    13705524    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common\CLIPARTS
3/14/2009 11:43:14 PM    677036    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common\CLIPARTS\ANIMALS
3/14/2009 11:43:14 PM    298520    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common\CLIPARTS\BITS
3/14/2009 11:43:15 PM    122936    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common\CLIPARTS\BUBBLES
3/14/2009 11:43:15 PM    131560    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common\CLIPARTS\COSTUM
3/14/2009 11:43:16 PM    178800    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common\CLIPARTS\FOOD
3/14/2009 11:43:16 PM    581692    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common\CLIPARTS\HOLIDAYS
3/14/2009 11:43:16 PM    57508    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common\CLIPARTS\SIGNS
3/14/2009 11:43:16 PM    264460    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Common\CLIPARTS\SPORTS
3/14/2009 11:43:17 PM    23769928    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Create
3/14/2009 11:43:17 PM    1526776    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Create\BORDERS
3/14/2009 11:43:18 PM    4722224    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Create\FRAMES
3/14/2009 11:43:20 PM    607924    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Create\SHAPES
3/14/2009 11:43:20 PM    16913004    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Create\TEXTURE
3/14/2009 11:43:27 PM    72056162    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb
3/14/2009 11:43:27 PM    2440    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Binder
3/14/2009 11:43:27 PM    37476877    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land
3/14/2009 11:43:27 PM    25898174    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Bk
3/14/2009 11:43:38 PM    904217    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Bk\Thumb
3/14/2009 11:43:39 PM    96645    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Layout
3/14/2009 11:43:39 PM    37329    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Layout\2
3/14/2009 11:43:39 PM    21507    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Layout\3
3/14/2009 11:43:39 PM    13097    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Layout\4
3/14/2009 11:43:39 PM    24414    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Layout\5
3/14/2009 11:43:38 PM    11482058    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Theme
3/14/2009 11:43:38 PM    6328260    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Theme\Cla
3/14/2009 11:43:40 PM    3728120    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Theme\Cla\Cover
3/14/2009 11:43:38 PM    238316    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Theme\Cla\Thumb
3/14/2009 11:43:39 PM    5153622    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Theme\Occ
3/14/2009 11:43:42 PM    3329196    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Theme\Occ\Cover
3/14/2009 11:43:39 PM    183278    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Land\Theme\Occ\Thumb
3/14/2009 11:43:43 PM    34576845    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port
3/14/2009 11:43:43 PM    23472933    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Bk
3/14/2009 11:43:54 PM    897331    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Bk\Thumb
3/14/2009 11:43:55 PM    69259    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Layout
3/14/2009 11:43:55 PM    24164    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Layout\2
3/14/2009 11:43:55 PM    18965    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Layout\3
3/14/2009 11:43:55 PM    12883    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Layout\4
3/14/2009 11:43:55 PM    12965    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Layout\5
3/14/2009 11:43:54 PM    11034653    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Theme
3/14/2009 11:43:54 PM    6197896    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Theme\Cla
3/14/2009 11:43:56 PM    3602592    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Theme\Cla\Cover
3/14/2009 11:43:54 PM    227104    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Theme\Cla\Thumb
3/14/2009 11:43:55 PM    4836581    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Theme\Occ
3/14/2009 11:43:57 PM    3023512    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Theme\Occ\Cover
3/14/2009 11:43:55 PM    189501    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Pb\Port\Theme\Occ\Thumb
3/14/2009 11:43:59 PM    2646468    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Project
3/14/2009 11:43:59 PM    1575707    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Project\Edges
3/14/2009 11:43:59 PM    280736    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Project\Edges\Thumb
3/14/2009 11:44:00 PM    1070761    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Project\Frames
3/14/2009 11:44:00 PM    217057    C:\Program Files\ArcSoft\PhotoImpression 5\Contents\Project\Frames\Thumb
3/14/2009 11:44:00 PM    13256    C:\Program Files\ArcSoft\PhotoImpression 5\Err
3/14/2009 11:44:00 PM    16064    C:\Program Files\ArcSoft\PhotoImpression 5\ini
3/14/2009 11:44:00 PM    91205971    C:\Program Files\ArcSoft\PhotoImpression 5\Modules
3/14/2009 11:44:00 PM    18691950    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Browser
3/14/2009 11:44:01 PM    17261573    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Browser\UI
3/14/2009 11:44:03 PM    966332    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Browser\UI\BUTTON
3/14/2009 11:44:03 PM    966332    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Browser\UI\BUTTON\Default
3/14/2009 11:44:03 PM    85968    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Browser\UI\ICON
3/14/2009 11:44:10 PM    13598506    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\create
3/14/2009 11:44:10 PM    4258232    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\create\abm
3/14/2009 11:44:11 PM    8552669    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\create\UI_Create
3/14/2009 11:44:11 PM    1733272    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\create\UI_Create\BUTTON
3/14/2009 11:44:11 PM    1733272    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\create\UI_Create\BUTTON\Default
3/14/2009 11:44:02 PM    8396369    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Enhance
3/14/2009 11:44:02 PM    7899226    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Enhance\UI_Enhance
3/14/2009 11:44:12 PM    1631428    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Enhance\UI_Enhance\BUTTON
3/14/2009 11:44:12 PM    1631428    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Enhance\UI_Enhance\BUTTON\Default
3/14/2009 11:44:03 PM    813108    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\MiniBrowser
3/14/2009 11:44:03 PM    497716    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\MiniBrowser\UI_MiniBrowser
3/14/2009 11:44:12 PM    166052    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\MiniBrowser\UI_MiniBrowser\BUTTON
3/14/2009 11:44:12 PM    166052    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\MiniBrowser\UI_MiniBrowser\BUTTON\Default
3/14/2009 11:44:03 PM    85968    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\MiniBrowser\UI_MiniBrowser\ICON
3/14/2009 11:44:13 PM    6110711    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Print
3/14/2009 11:44:13 PM    37702    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Print\Template
3/14/2009 11:44:13 PM    5552726    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Print\UI_Print
3/14/2009 11:44:13 PM    824896    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Print\UI_Print\BUTTON
3/14/2009 11:44:13 PM    824896    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Print\UI_Print\BUTTON\Default
3/14/2009 11:44:13 PM    37818379    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project
3/14/2009 11:44:13 PM    30412309    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\Projects
3/14/2009 11:44:13 PM    12267809    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\Projects\Calendar
3/14/2009 11:44:13 PM    11549783    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\Projects\Calendar\UI_Project
3/14/2009 11:44:14 PM    774324    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\Projects\Calendar\UI_Project\BUTTON
3/14/2009 11:44:14 PM    774324    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\Projects\Calendar\UI_Project\BUTTON\Default
3/14/2009 11:44:14 PM    18144500    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\Projects\PhotoBook
3/14/2009 11:44:15 PM    17352708    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\Projects\PhotoBook\UI_Project
3/14/2009 11:44:16 PM    933516    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\Projects\PhotoBook\UI_Project\BUTTON
3/14/2009 11:44:16 PM    933516    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\Projects\PhotoBook\UI_Project\BUTTON\Default
3/14/2009 11:44:16 PM    7167185    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\UI_Project
3/14/2009 11:44:17 PM    76776    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\UI_Project\BUTTON
3/14/2009 11:44:17 PM    76776    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Project\UI_Project\BUTTON\Default
3/14/2009 11:44:17 PM    5776948    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Share
3/14/2009 11:44:17 PM    5444365    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Share\ui_Share
3/14/2009 11:44:18 PM    762672    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Share\ui_Share\BUTTON
3/14/2009 11:44:18 PM    762672    C:\Program Files\ArcSoft\PhotoImpression 5\Modules\Share\ui_Share\BUTTON\Default
3/14/2009 11:42:17 PM    9776248    C:\Program Files\ArcSoft\PhotoImpression 5\Share
3/14/2009 11:44:20 PM    5148989    C:\Program Files\ArcSoft\PhotoImpression 5\Share\Samples
3/14/2009 11:44:26 PM    195506    C:\Program Files\ArcSoft\PhotoImpression 5\SUPPORT
3/14/2009 11:44:26 PM    195506    C:\Program Files\ArcSoft\PhotoImpression 5\SUPPORT\Registration
3/14/2009 11:44:27 PM    30886    C:\Program Files\ArcSoft\PhotoImpression 5\SUPPORT\Registration\Images
3/14/2009 11:44:26 PM    2007262    C:\Program Files\ArcSoft\PhotoImpression 5\UI_Framework
3/14/2009 11:44:27 PM    44382    C:\Program Files\ArcSoft\PhotoImpression 5\UI_Framework\3DIM
3/14/2009 11:41:01 PM    142434689    C:\Program Files\ArcSoft\VideoImpression 2
3/14/2009 11:41:06 PM    1752116    C:\Program Files\ArcSoft\VideoImpression 2\Albums
3/14/2009 11:41:27 PM    249765    C:\Program Files\ArcSoft\VideoImpression 2\ArcRevenueSharingUI
3/14/2009 11:41:07 PM    34633945    C:\Program Files\ArcSoft\VideoImpression 2\Contents
3/14/2009 11:41:07 PM    10321814    C:\Program Files\ArcSoft\VideoImpression 2\Contents\audio
3/14/2009 11:41:10 PM    310518    C:\Program Files\ArcSoft\VideoImpression 2\Contents\colors
3/14/2009 11:41:10 PM    3656047    C:\Program Files\ArcSoft\VideoImpression 2\Contents\stills
3/14/2009 11:41:12 PM    2912978    C:\Program Files\ArcSoft\VideoImpression 2\Contents\textures
3/14/2009 11:41:13 PM    17432588    C:\Program Files\ArcSoft\VideoImpression 2\Contents\videos
3/14/2009 11:41:20 PM    337408    C:\Program Files\ArcSoft\VideoImpression 2\MagicDll
3/14/2009 11:41:20 PM    28213047    C:\Program Files\ArcSoft\VideoImpression 2\template
3/14/2009 11:41:20 PM    5785632    C:\Program Files\ArcSoft\VideoImpression 2\template\frame
3/14/2009 11:41:20 PM    1377680    C:\Program Files\ArcSoft\VideoImpression 2\template\frame\album
3/14/2009 11:41:20 PM    4407952    C:\Program Files\ArcSoft\VideoImpression 2\template\frame\default
3/14/2009 11:41:22 PM    1695480    C:\Program Files\ArcSoft\VideoImpression 2\template\layout
3/14/2009 11:41:22 PM    1166240    C:\Program Files\ArcSoft\VideoImpression 2\template\layout\album
3/14/2009 11:41:22 PM    529240    C:\Program Files\ArcSoft\VideoImpression 2\template\layout\default
3/14/2009 11:41:22 PM    20731935    C:\Program Files\ArcSoft\VideoImpression 2\template\theme
3/14/2009 11:41:22 PM    1928016    C:\Program Files\ArcSoft\VideoImpression 2\template\theme\album
3/14/2009 11:41:23 PM    18803919    C:\Program Files\ArcSoft\VideoImpression 2\template\theme\default
3/17/2009 8:39:24 AM    2389124    C:\Program Files\CCleaner
3/17/2009 8:39:24 AM    801280    C:\Program Files\CCleaner\Lang
3/14/2009 11:39:43 PM    5878023    C:\Program Files\CIF USB Camera
3/14/2009 11:39:46 PM    2439816    C:\Program Files\CIF USB Camera\Frame
3/14/2009 11:39:47 PM    512835    C:\Program Files\CIF USB Camera\WNT
3/14/2009 11:39:48 PM    580293    C:\Program Files\CIF USB Camera\WXPAMD64
2/13/2009 1:52:12 AM    8918016    C:\Program Files\Graboid
2/13/2009 1:59:58 AM    8918016    C:\Program Files\Graboid\GraboidVideo
2/13/2009 1:59:58 AM    8918016    C:\Program Files\Graboid\GraboidVideo\1.4.0.0
3/16/2009 10:04:28 AM    21507729    C:\Program Files\Logitech
3/16/2009 10:10:20 AM    10975102    C:\Program Files\Logitech\Desktop Messenger
3/16/2009 10:10:30 AM    10975102    C:\Program Files\Logitech\Desktop Messenger\8876480
3/16/2009 10:10:30 AM    8715307    C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL
3/16/2009 10:10:31 AM    4471866    C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Install
3/16/2009 10:10:31 AM    12800    C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Plugins
3/16/2009 10:10:31 AM    4230641    C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Program
3/16/2009 10:10:31 AM    282624    C:\Program Files\Logitech\Desktop Messenger\8876480\8.1.1.50-8876480SL\Program\EN
3/16/2009 10:10:32 AM    100287    C:\Program Files\Logitech\Desktop Messenger\8876480\InitData
3/16/2009 10:10:32 AM    100287    C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data
3/16/2009 10:10:32 AM    25013    C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash
3/16/2009 10:10:32 AM    25013    C:\Program Files\Logitech\Desktop Messenger\8876480\InitData\Data\GenFlash\1
3/16/2009 10:10:34 AM    999853    C:\Program Files\Logitech\Desktop Messenger\8876480\Program
3/17/2009 1:23:13 AM    1110602    C:\Program Files\Logitech\Desktop Messenger\8876480\Users
3/17/2009 1:23:14 AM    1110492    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda
3/17/2009 1:23:14 AM    1110492    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Data
3/17/2009 1:23:47 AM    19366    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Data\210e
3/17/2009 1:23:47 AM    2716    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Data\5168
3/17/2009 1:23:46 AM    6922    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Data\857
3/17/2009 1:23:47 AM    299534    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Data\85a
3/17/2009 1:27:51 AM    285606    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Data\85a\11e4f6f3
3/17/2009 1:23:15 AM    25013    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Data\GenFlash
3/17/2009 1:23:16 AM    25013    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Data\GenFlash\1
3/17/2009 1:23:28 AM    0    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Data\LowIntegrity
3/17/2009 1:23:29 AM    0    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Misc
3/17/2009 1:23:29 AM    0    C:\Program Files\Logitech\Desktop Messenger\8876480\Users\Ryan Sarda\Misc\Temp
3/16/2009 10:04:28 AM    10532627    C:\Program Files\Logitech\QuickCam10
3/16/2009 10:04:30 AM    900889    C:\Program Files\Logitech\QuickCam10\LU
3/16/2009 10:04:30 AM    6681    C:\Program Files\Logitech\QuickCam10\LU\chs
3/16/2009 10:04:30 AM    6731    C:\Program Files\Logitech\QuickCam10\LU\cht
3/16/2009 10:04:31 AM    7116    C:\Program Files\Logitech\QuickCam10\LU\dan
3/16/2009 10:04:31 AM    7309    C:\Program Files\Logitech\QuickCam10\LU\deu
3/16/2009 10:04:31 AM    9233    C:\Program Files\Logitech\QuickCam10\LU\ell
3/16/2009 10:04:31 AM    7143    C:\Program Files\Logitech\QuickCam10\LU\enu
3/16/2009 10:04:31 AM    7329    C:\Program Files\Logitech\QuickCam10\LU\esp
3/16/2009 10:04:31 AM    7077    C:\Program Files\Logitech\QuickCam10\LU\fin
3/16/2009 10:04:31 AM    7552    C:\Program Files\Logitech\QuickCam10\LU\fra
3/16/2009 10:04:31 AM    7367    C:\Program Files\Logitech\QuickCam10\LU\ita
3/16/2009 10:04:31 AM    8316    C:\Program Files\Logitech\QuickCam10\LU\jpn
3/16/2009 10:04:31 AM    7572    C:\Program Files\Logitech\QuickCam10\LU\kor
3/16/2009 10:04:31 AM    7330    C:\Program Files\Logitech\QuickCam10\LU\nld
3/16/2009 10:04:31 AM    7190    C:\Program Files\Logitech\QuickCam10\LU\nor
3/16/2009 10:04:32 AM    7575    C:\Program Files\Logitech\QuickCam10\LU\plk
3/16/2009 10:04:32 AM    7377    C:\Program Files\Logitech\QuickCam10\LU\ptb
3/16/2009 10:04:32 AM    7395    C:\Program Files\Logitech\QuickCam10\LU\ptg
3/16/2009 10:04:32 AM    9066    C:\Program Files\Logitech\QuickCam10\LU\rus
3/16/2009 10:04:32 AM    7273    C:\Program Files\Logitech\QuickCam10\LU\sve
3/16/2009 10:04:34 AM    3441072    C:\Program Files\Logitech\QuickCam10\ModelPackages
2/13/2009 1:52:55 AM    11822378    C:\Program Files\Mozilla ActiveX Control v1.7.12
2/13/2009 1:52:56 AM    1273407    C:\Program Files\Mozilla ActiveX Control v1.7.12\chrome
2/13/2009 2:00:11 AM    1319    C:\Program Files\Mozilla ActiveX Control v1.7.12\chrome\overlayinfo
2/13/2009 2:00:11 AM    526    C:\Program Files\Mozilla ActiveX Control v1.7.12\chrome\overlayinfo\communicator
2/13/2009 2:00:11 AM    526    C:\Program Files\Mozilla ActiveX Control v1.7.12\chrome\overlayinfo\communicator\content
2/13/2009 2:00:11 AM    362    C:\Program Files\Mozilla ActiveX Control v1.7.12\chrome\overlayinfo\messenger
2/13/2009 2:00:12 AM    362    C:\Program Files\Mozilla ActiveX Control v1.7.12\chrome\overlayinfo\messenger\content
2/13/2009 2:00:11 AM    431    C:\Program Files\Mozilla ActiveX Control v1.7.12\chrome\overlayinfo\navigator
2/13/2009 2:00:11 AM    431    C:\Program Files\Mozilla ActiveX Control v1.7.12\chrome\overlayinfo\navigator\content
2/13/2009 1:52:56 AM    7011340    C:\Program Files\Mozilla ActiveX Control v1.7.12\components
2/13/2009 1:52:59 AM    4053    C:\Program Files\Mozilla ActiveX Control v1.7.12\defaults
2/13/2009 1:52:59 AM    4053    C:\Program Files\Mozilla ActiveX Control v1.7.12\defaults\pref
2/13/2009 1:52:59 AM    54261    C:\Program Files\Mozilla ActiveX Control v1.7.12\greprefs
2/13/2009 1:52:59 AM    49152    C:\Program Files\Mozilla ActiveX Control v1.7.12\ipc
2/13/2009 1:53:00 AM    49152    C:\Program Files\Mozilla ActiveX Control v1.7.12\ipc\modules
2/13/2009 1:53:00 AM    143360    C:\Program Files\Mozilla ActiveX Control v1.7.12\plugins
2/13/2009 1:53:00 AM    324921    C:\Program Files\Mozilla ActiveX Control v1.7.12\res
2/13/2009 1:53:01 AM    14235    C:\Program Files\Mozilla ActiveX Control v1.7.12\res\builtin
2/13/2009 1:53:01 AM    72928    C:\Program Files\Mozilla ActiveX Control v1.7.12\res\dtd
2/13/2009 1:53:01 AM    59522    C:\Program Files\Mozilla ActiveX Control v1.7.12\res\entityTables
2/13/2009 1:53:01 AM    89691    C:\Program Files\Mozilla ActiveX Control v1.7.12\res\fonts
2/13/2009 1:53:01 AM    1647    C:\Program Files\Mozilla ActiveX Control v1.7.12\res\html
3/17/2009 6:25:55 AM    0    C:\Program Files\MSXML 4.0
2/4/2009 2:39:45 PM    110592    C:\Program Files\NCH Software
2/4/2009 2:39:45 PM    110592    C:\Program Files\NCH Software\Components
2/4/2009 2:39:45 PM    110592    C:\Program Files\NCH Software\Components\mp3el
2/4/2009 2:39:40 PM    1622910    C:\Program Files\NCH Swift Sound
2/4/2009 2:39:40 PM    1622910    C:\Program Files\NCH Swift Sound\Switch
2/4/2009 2:39:44 PM    50038    C:\Program Files\NCH Swift Sound\Switch\Help
2/4/2009 1:30:56 PM    1278931    C:\Program Files\RCA
2/4/2009 1:30:56 PM    1278931    C:\Program Files\RCA\Digital Voice Recorder
2/4/2009 1:30:56 PM    1278931    C:\Program Files\RCA\Digital Voice Recorder\RP5120
3/14/2009 10:14:57 PM    26666962    C:\Program Files\Skype
3/14/2009 10:14:57 PM    24095944    C:\Program Files\Skype\Phone
3/14/2009 10:14:57 PM    2570934    C:\Program Files\Skype\Toolbars
3/14/2009 10:14:57 PM    1095054    C:\Program Files\Skype\Toolbars\Internet Explorer
3/14/2009 10:15:02 PM    1475880    C:\Program Files\Skype\Toolbars\Shared
2/13/2009 1:52:32 AM    2851328    C:\Program Files\VideoLAN
2/13/2009 1:52:32 AM    2851328    C:\Program Files\VideoLAN\VLC
2/13/2009 1:52:32 AM    97792    C:\Program Files\VideoLAN\VLC\plugins
3/17/2009 8:39:30 AM    0    C:\Program Files\Yahoo!
3/17/2009 8:39:41 AM    0    C:\Program Files\Yahoo!\Common


*

Offline ryansarda

  • Bronze Member
  • 20
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #8 on: March 18, 2009, 10:15:26 AM »
====== Files under "\System32\Drivers" Last 60 Days======

3/14/2009 11:41:35 PM    11776    32    C:\WINDOWS\system32\drivers\afc.sys
3/14/2009 11:40:18 PM    17024    32    C:\WINDOWS\system32\drivers\CCDECODE.sys
3/16/2009 10:12:48 AM    1507232    33    C:\WINDOWS\system32\drivers\lvpopflt.sys
3/16/2009 10:12:33 AM    41504    33    C:\WINDOWS\system32\drivers\LVUSBSta.sys
3/16/2009 10:12:39 AM    0    32    C:\WINDOWS\system32\drivers\lvuvc.hs
3/16/2009 10:12:33 AM    1939360    33    C:\WINDOWS\system32\drivers\lvuvc.sys
3/16/2009 10:12:24 AM    22560    33    C:\WINDOWS\system32\drivers\lvuvcflt.sys
3/14/2009 11:40:37 PM    5504    32    C:\WINDOWS\system32\drivers\MSTEE.sys
3/14/2009 11:40:21 PM    85248    32    C:\WINDOWS\system32\drivers\NABTSFEC.sys
3/14/2009 11:40:33 PM    10880    32    C:\WINDOWS\system32\drivers\NdisIP.sys
3/14/2009 11:39:48 PM    505984    32    C:\WINDOWS\system32\drivers\PFC027.SYS
3/14/2009 11:40:27 PM    11136    32    C:\WINDOWS\system32\drivers\SLIP.sys
3/14/2009 11:40:30 PM    15232    32    C:\WINDOWS\system32\drivers\StreamIP.sys
3/16/2009 10:12:47 AM    60032    32    C:\WINDOWS\system32\drivers\USBAUDIO.sys
3/16/2009 10:12:23 AM    32128    32    C:\WINDOWS\system32\drivers\usbccgp.sys
3/14/2009 11:40:24 PM    19200    32    C:\WINDOWS\system32\drivers\WSTCODEC.SYS

====== Files Deleted under "%Temp%" ======

C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\callingapps.xml
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\etilqs_RdYdq1voSS6nEr50J94M
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\etilqs_Yi9eO3uMxwe04Kf40gdZ
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\jusched.log
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\LVCOMSX.LOG
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\Wd0000000.doc
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\~DF1283.tmp
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\~DF6934.tmp
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\~DF8EFD.tmp
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\~DF9C49.tmp
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\~DFDE40.tmp
C:\DOCUME~1\RYANSA~1\LOCALS~1\Temp\~DFDE88.tmp

12 Files deleted

====== Files and Folders under "All Users\Application Data" Last 60 Days======

2/13/2009 2:00:24 AM    140173    C:\Documents and Settings\All Users\Application Data\Graboid Inc
2/13/2009 2:00:24 AM    140173    C:\Documents and Settings\All Users\Application Data\Graboid Inc\My
2/13/2009 2:00:24 AM    140173    C:\Documents and Settings\All Users\Application Data\Graboid Inc\My\1.4.0.0
2/13/2009 2:02:16 AM    0    C:\Documents and Settings\All Users\Application Data\Graboid Inc\My\1.4.0.0\blackhole
2/13/2009 2:00:24 AM    135366    C:\Documents and Settings\All Users\Application Data\Graboid Inc\My\1.4.0.0\logs
2/13/2009 2:02:16 AM    135366    C:\Documents and Settings\All Users\Application Data\Graboid Inc\My\1.4.0.0\logs\logs_ryansarda@graboid.com
3/16/2009 10:04:44 AM    2381336    C:\Documents and Settings\All Users\Application Data\Logishrd
3/16/2009 10:04:44 AM    2381336    C:\Documents and Settings\All Users\Application Data\Logishrd\LQCVFX
3/16/2009 10:04:44 AM    2381336    C:\Documents and Settings\All Users\Application Data\Logishrd\LQCVFX\Filters
3/16/2009 10:04:36 AM    12304800    C:\Documents and Settings\All Users\Application Data\Logitech
3/16/2009 10:04:36 AM    12304800    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam
3/16/2009 10:05:09 AM    3710318    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData
3/16/2009 10:05:09 AM    19066    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\4 Squares_{70621C6C-D8DC-4E59-8F0B-9DED1E1A100F}
3/16/2009 10:05:09 AM    17642    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\50's Movie Reel_{0C31C3E1-7E15-4BE7-9854-AD96B7FA2AE7}
3/16/2009 10:05:09 AM    17699    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\80's Music Video_{417F9037-0213-43C4-86BA-979C9E809CAC}
3/16/2009 10:05:09 AM    740355    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Alien_{C614E398-5BF5-4703-B19C-9D302288098A}
3/16/2009 10:05:09 AM    61274    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Arrow_through_head_{A00FE4B0-05E2-494F-B845-2D1ED9C42158}
3/16/2009 10:05:10 AM    17957    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Blockhead_{2A680E6D-4617-499E-98AE-3F5B9CC21755}
3/16/2009 10:05:10 AM    398322    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Cat_{9C7A29A3-BA63-4579-976D-4D3EE0CE7DFA}
3/16/2009 10:05:10 AM    17772    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Chalk_{2DA6ED37-5751-49D9-A5AF-4351BABE130F}
3/16/2009 10:05:10 AM    17408    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Cotton Candy_{3BF23BA9-4B07-4660-AF05-CD3B45EDA2DB}
3/16/2009 10:05:10 AM    77135    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Crown_{4D5F0C5E-FCE4-4472-A434-D5FD3969FD64}
3/16/2009 10:05:10 AM    562059    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Dinosaur_{17F8B0B2-2ED7-4E38-809C-C42BC55111ED}
3/16/2009 10:05:11 AM    17753    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Fisheye_{394F17FB-B2D0-45B7-ADBE-B0E77246D89E}
3/16/2009 10:05:11 AM    78447    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Goatee_{09161F3F-1EBD-4781-9EAE-6AB83A674E44}
3/16/2009 10:05:11 AM    18666    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\I See A Ghost_{D5594FF7-6B1A-4AF3-8F21-D7A7F32ED6AD}
3/16/2009 10:05:11 AM    18656    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Neonize_{481A76E6-7496-4674-88A0-7608DBE300D3}
3/16/2009 10:05:11 AM    64417    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Pig_nose_{52373697-C0A7-40C9-A9D0-F448C0E7A621}
3/16/2009 10:05:12 AM    106690    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Robot_Face_{446DBFE6-4E06-4320-818C-AFCE072048D2}
3/16/2009 10:05:12 AM    1006054    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Shark_{0B0FB8EA-CC0B-4FB8-BFD1-F1AB182761DC}
3/16/2009 10:05:12 AM    435211    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Stick_Figure_{A1A13D7E-C668-4046-B7BC-400922F632D4}
3/16/2009 10:05:12 AM    17735    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\ModelData\Tiled Up_{13F4D7E5-D931-443D-99AF-E9021029322C}
3/16/2009 10:04:36 AM    8594482    C:\Documents and Settings\All Users\Application Data\Logitech\QuickCam\PrivacyShades
2/4/2009 2:39:57 PM    0    C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2/4/2009 2:39:57 PM    0    C:\Documents and Settings\All Users\Application Data\NCH Swift Sound\Switch
3/14/2009 10:14:51 PM    20024424    C:\Documents and Settings\All Users\Application Data\Skype
3/14/2009 10:14:57 PM    647954    C:\Documents and Settings\All Users\Application Data\Skype\Pictures
3/14/2009 10:14:58 PM    384854    C:\Documents and Settings\All Users\Application Data\Skype\Wallpapers
3/14/2009 10:14:51 PM    18991616    C:\Documents and Settings\All Users\Application Data\Skype\{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}

====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======

HKLM\Software\microsoft\shared tools\msconfig\startupreg\


====== Services ( Services that are Whitelisted are not shown) ======

Afc (PPdus ASPI Shell)- C:\WINDOWS\system32\drivers\Afc.sys - Manual/Running
BCM43XX (Dell Wireless WLAN Card Driver)- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys - Manual/Running
DXEC02 (DXEC02)- C:\WINDOWS\system32\drivers\dxec02.sys - Manual/Running
E100B (Intel(R) PRO Adapter Driver)- C:\WINDOWS\system32\DRIVERS\e100b325.sys - Manual/Stopped
eeCtrl (Symantec Eraser Control driver)- \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys - System/Running
EraserUtilRebootDrv (EraserUtilRebootDrv)- \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys - Manual/Running
FilterService (UVC Filter Service)- C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys - Manual/Stopped
HSFHWAZL (HSFHWAZL)- C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys - Manual/Running
HSF_DPV (HSF_DPV)- C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys - Manual/Running
iaStor (Intel RAID Controller)- C:\WINDOWS\system32\drivers\iaStor.sys - Boot/Stopped
lvpopflt (Logitech POP Suppression Filter)- C:\WINDOWS\system32\DRIVERS\lvpopflt.sys - Manual/Stopped
LVUVC (QuickCam for Notebooks Deluxe(UVC))- C:\WINDOWS\system32\DRIVERS\lvuvc.sys - Manual/Stopped
NdisIP (Microsoft TV/Video Connection)- C:\WINDOWS\system32\DRIVERS\NdisIP.sys - Manual/Stopped
PAC207 (CIF USB Camera)- C:\WINDOWS\system32\DRIVERS\PFC027.SYS - Manual/Stopped
Packet (Auto Internet Protocol)- C:\WINDOWS\system32\DRIVERS\packet.sys - Auto/Running
rimmptsk (rimmptsk)- C:\WINDOWS\system32\DRIVERS\rimmptsk.sys - Auto/Running
rimsptsk (rimsptsk)- C:\WINDOWS\system32\DRIVERS\rimsptsk.sys - Auto/Running
rismxdp (Ricoh xD-Picture Card Driver)- C:\WINDOWS\system32\DRIVERS\rixdptsk.sys - Auto/Running
sdbus (sdbus)- C:\WINDOWS\system32\DRIVERS\sdbus.sys - Manual/Running
SLIP (BDA Slip De-Framer)- C:\WINDOWS\system32\DRIVERS\SLIP.sys - Manual/Stopped
SndTAudio (SndTAudio)- C:\WINDOWS\system32\drivers\SndTAudio.sys - Manual/Stopped
SndTVideo (SndTVideo)- C:\WINDOWS\system32\DRIVERS\SndTVideo.sys - Manual/Stopped
SPBBCDrv (SPBBCDrv)- \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys - System/Running
STHDA (SigmaTel High Definition Audio CODEC)- C:\WINDOWS\system32\drivers\sthda.sys - Manual/Running
SynTP (Synaptics TouchPad Driver)- C:\WINDOWS\system32\DRIVERS\SynTP.sys - Manual/Running
WmiAcpi (Microsoft Windows Management Interface for ACPI)- C:\WINDOWS\system32\DRIVERS\wmiacpi.sys - System/Running

====== Uninstall List From Registry ======

Adobe Flash Player 10 ActiveX
AIM 6
Dell Wireless WLAN Card
CCleaner (remove only)
Conexant HDA D330 MDC V.92 Modem
Google Desktop
Intel(R) Graphics Media Accelerator Driver
HijackThis 2.0.0
Microsoft Internationalized Domain Names Mitigation APIs
Windows Internet Explorer 7
High Definition Audio Driver Package - KB835221
Windows Installer 3.1 (KB893803)
Security Update for Windows Media Player (KB911564)
Security Update for Windows XP (KB923689)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player 6.4 (KB925398)
Hotfix for Windows Media Format 11 SDK (KB929399)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Hotfix for Windows Media Player 11 (KB939683)
Security Update for Windows XP (KB941569)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows XP (KB946648)
Hotfix for Windows Internet Explorer 7 (KB947864)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Update for Windows XP (KB951072-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Update for Windows XP (KB951978)
Security Update for Windows Media Player (KB952069)
Hotfix for Windows XP (KB952287)
Security Update for Windows XP (KB952954)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Update for Windows XP (KB955839)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Critical Update for Windows Media Player 11 (KB959772)
Security Update for Windows XP (KB960225)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows Internet Explorer 7 (KB961260)
Update for Windows XP (KB967715)
LiveUpdate 3.1 (Symantec Corporation)
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft National Language Support Downlevel APIs
Logitech® Camera Driver
Switch Sound File Converter
Dell Touchpad
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Windows Media Format 11 runtime
Windows Media Player 11
Microsoft User-Mode Driver Framework Feature Pack 1.0
Dell Network Assistant
CIF USB Camera
MSXML 6.0 Parser (KB933579)
Microsoft Works
ArcSoft VideoImpression 2
Skype™ 4.0
iTunes
Java(TM) 6 Update 7
Symantec AntiVirus
WebFldrs XP
MVision
NetWaiting
Browser Address Error Redirector
Apple Software Update
Microsoft .NET Framework 2.0
Microsoft Visual C++ 2005 Redistributable
Logitech QuickCam
Digital Voice Recorder
MSXML 4.0 SP2 (KB954430)
Logitech Desktop Messenger
Microsoft Office Professional Edition 2003
Compatibility Pack for the 2007 Office system
Microsoft Office PowerPoint Viewer 2007 (English)
OutlookAddinSetup
ArcSoft PhotoImpression 5
Adobe Reader 8.1.2
DivX Web Player
Logitech Audio Echo Cancellation Component
Microsoft .NET Framework 1.1
IntelliSonic Speech Enhancement
Dell Support Center (Support Software)
Logitech Video Enumerator
Apple Mobile Device Support
Modem Diagnostic Tool
QuickTime

======== Other Info ========

TOTAL PHYSICAL RAM: 2137 MB


*

Offline bamajim

  • Administrator
  • Platinum Member
  • 3116
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #9 on: March 18, 2009, 11:49:37 AM »
ryansarda

That looks good. Give me an update on how your PC is running now

2008-2010
Rights cannot exist without morals

*

Offline ryansarda

  • Bronze Member
  • 20
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #10 on: March 20, 2009, 10:36:19 PM »
BamaJim,
Running great. Thank you so much! What was wrong with it? How did I get that god awful virus? Thank you again!!

And to Hoov, who fixed me up a few months ago, I never got around to thanking him either. This site is greatly appreciated!!!

*

Offline bamajim

  • Administrator
  • Platinum Member
  • 3116
Re: [ In Progress ] I've been infected with some sort of virus
« Reply #11 on: March 21, 2009, 05:57:50 AM »
ryansarda

Unfortunately there are many ways to get infected all too easily, be sure you read the article at the end of my post.

You may now remove/delete/uninstall the tools we used to clean your PC

Now that your log is clean

There are some final notes:

Lets create a clean System Restore point
the instructions are here

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

Updating Java:

Download the latest version of
Java Runtime Environment (JRE) 6.u11.
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
Click the "Download" button to the right.
Check the box that says: "Accept License Agreement".
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u11-windowsi586-p.exe to install the newest version.

Update your Anti Virus Software

Use and maintain a Firewall
Visit Microsoft's Windows Update Site Frequently for critical updates

Backup your Important Documents and Files on a regular basis

To a disc or a USB key, not your Hardrive

You may want to read this article"So how did I get infected in the first place" by Tony Klein

surf safe

2008-2010
Rights cannot exist without morals