Hey guys,
Can someone take a look at my logs here and let me know if there is anything wrong.. My computer slowed way down and then I noticed that comodo was using like 160k on task manager. I tried to shut it down and couldn't so I uninstalled it that seemed to take care of things. Did a virus attach itself to comodo.. or did something go wrong there... I decided to shut off comodo safesurf as well just to be safe.
Let me know what you guys think. Also I turned window firewall back on but should I try reinstalling comodo or try another firewall.. opinions?
But first and foremost.. do I have anything.. ?
Thanks a lot.. here are my hijackthis log and combofix...
HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:46:30 PM, on 5/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [LXCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1670103657-2857965304-651090504-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader45.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxci_device - - C:\WINDOWS\system32\lxcicoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
--
End of file - 6607 bytes
COMBOFIX LOG:
ComboFix 10-05-25.02 - Owner 05/25/2010 20:58:54.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.413 [GMT -5:00]
Running from: c:\documents and settings\Owner\My Documents\Downloads\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Application Data\inst.exe
c:\windows\system32\CE8B5AC411.dll
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Created from 2010-04-26 to 2010-05-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-26 01:36 . 2007-10-18 07:54 -------- d-----w- c:\documents and settings\Owner\Application Data\Comodo
2010-05-26 01:36 . 2007-10-18 07:52 -------- d-----w- c:\program files\Comodo
2010-05-26 01:33 . 2007-10-18 07:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo
2010-05-24 20:00 . 2006-01-09 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-22 10:22 . 2006-04-25 20:24 -------- d-----w- c:\program files\Lx_cats
2010-04-14 07:38 . 2010-04-09 06:23 2110440 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-04-07 17:23 . 2005-12-02 22:32 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-03-29 06:39 . 2010-03-29 06:39 -------- d-----w- c:\documents and settings\Owner\Application Data\PixelMetrics
2010-03-29 06:38 . 2010-03-29 06:38 -------- d-----w- c:\program files\Windows Media Adapter v615
2010-03-29 06:38 . 2010-03-29 06:38 -------- d-----w- c:\program files\CaptureWiz
2010-03-27 06:39 . 2007-09-25 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2010-03-10 06:15 . 2005-03-23 16:52 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-26 05:23 . 2005-07-31 18:58 73360 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-25 06:24 . 2005-03-23 16:53 916480 ----a-w- c:\windows\system32\wininet.dll
2009-09-13 04:44 . 2009-09-13 04:44 1962544 ----a-w- c:\program files\install_flash_player_ax.exe
2009-04-16 11:20 . 2009-04-16 11:19 17920 --sha-w- c:\program files\Thumbs.db
2008-09-17 00:08 . 2008-11-29 21:29 65686 ----a-w- c:\program files\Photoshop CS4 Read Me.pdf
2008-09-11 16:49 . 2008-11-29 21:29 108336 ----a-w- c:\program files\Photoshop CS4 — Lisez-moi.pdf
2008-09-11 16:47 . 2008-11-29 21:29 103148 ----a-w- c:\program files\Léame de Photoshop CS4.pdf
2007-04-02 00:34 . 2008-06-03 18:52 1093226 ----a-w- c:\program files\undelete_plus_setup.exe
2006-01-09 06:51 . 2005-12-13 05:39 774144 ----a-w- c:\program files\RngInterstitial.dll
2005-07-31 03:35 . 2005-07-31 03:35 0 --sha-w- c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( SnapShot_2009-10-31_20.49.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-12-02 06:46 . 2006-12-02 06:46 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
+ 2009-07-12 01:41 . 2009-07-12 01:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2010-03-12 06:06 . 2010-03-12 06:06 45344 c:\windows\WinSxS\MSIL_Intuit.Spc.Esd.WinClient.Application.Update_540d4816ead86321_3.0.335.0_x-ww_e51d7605\Intuit.Spc.Esd.WinClient.Application.Update.exe
+ 2010-03-12 06:06 . 2010-03-12 06:06 40224 c:\windows\WinSxS\MSIL_Intuit.Spc.Esd.WinClient.Application.ConfigUXv2_540d4816ead86321_3.0.335.0_x-ww_29a6be0d\Intuit.Spc.Esd.WinClient.Application.ConfigUXv2.exe
+ 2010-05-26 01:37 . 2010-05-26 01:37 16384 c:\windows\temp\Perflib_Perfdata_60c.dat
+ 2004-08-04 07:56 . 2008-04-13 23:12 23552 c:\windows\system32\wdmaud.drv
- 2004-08-04 07:56 . 2008-04-14 00:12 23552 c:\windows\system32\wdmaud.drv
- 2007-01-29 08:58 . 2009-07-14 11:03 46080 c:\windows\system32\tzchange.exe
+ 2007-01-29 08:58 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe
- 2005-03-23 16:52 . 2008-04-14 00:12 75776 c:\windows\system32\strmfilt.dll
+ 2005-03-23 16:52 . 2009-10-21 05:38 75776 c:\windows\system32\strmfilt.dll
+ 2005-05-09 23:13 . 2007-04-09 19:23 28552 c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2005-05-09 23:13 . 2007-04-09 19:23 46472 c:\windows\system32\spool\drivers\w32x86\mdiui.dll
+ 2005-05-09 23:13 . 2007-04-09 19:23 46472 c:\windows\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2010-03-02 16:32 . 2009-07-21 08:40 41472 c:\windows\system32\RtkCoInstXP.dll
- 2005-03-23 16:52 . 2008-04-14 00:12 79872 c:\windows\system32\raschap.dll
+ 2005-03-23 16:52 . 2009-10-12 13:38 79872 c:\windows\system32\raschap.dll
+ 2005-03-23 16:52 . 2010-05-26 01:59 71060 c:\windows\system32\perfc009.dat
+ 2005-03-23 16:52 . 2009-10-08 20:56 20480 c:\windows\system32\oleaccrc.dll
+ 2004-08-04 07:56 . 2009-11-27 17:11 17920 c:\windows\system32\msyuv.dll
+ 2005-03-23 16:52 . 2009-11-27 16:07 28672 c:\windows\system32\msvidc32.dll
- 2005-03-23 16:52 . 2008-04-14 00:12 11264 c:\windows\system32\msrle32.dll
+ 2005-03-23 16:52 . 2009-11-27 16:07 11264 c:\windows\system32\msrle32.dll
+ 2006-11-08 04:03 . 2010-02-25 06:24 55296 c:\windows\system32\msfeedsbs.dll
- 2006-11-08 04:03 . 2009-08-29 08:08 55296 c:\windows\system32\msfeedsbs.dll
+ 2005-05-09 23:13 . 2007-04-09 19:23 28040 c:\windows\system32\mdimon.dll
- 2009-05-11 22:24 . 2009-09-27 18:39 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2010-01-31 06:38 . 2010-02-24 07:39 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2005-03-23 16:52 . 2009-08-29 08:08 25600 c:\windows\system32\jsproxy.dll
+ 2005-03-23 16:52 . 2010-02-25 06:24 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-04 07:56 . 2009-11-27 16:07 48128 c:\windows\system32\iyuv_32.dll
+ 2005-03-23 16:52 . 2009-10-21 05:38 25088 c:\windows\system32\httpapi.dll
- 2005-03-23 16:52 . 2009-06-16 14:36 81920 c:\windows\system32\fontsub.dll
+ 2005-03-23 16:52 . 2009-10-15 16:28 81920 c:\windows\system32\fontsub.dll
+ 2007-03-23 01:17 . 2007-03-23 01:17 35440 c:\windows\system32\FM20ENU.DLL
+ 2004-08-04 06:08 . 2008-04-13 17:45 49408 c:\windows\system32\drivers\stream.sys
- 2004-08-04 06:08 . 2008-04-13 18:45 49408 c:\windows\system32\drivers\stream.sys
+ 2009-04-14 09:34 . 2009-12-23 20:46 47360 c:\windows\system32\drivers\pcouffin.sys
- 2009-04-14 09:34 . 2009-04-14 09:34 47360 c:\windows\system32\drivers\pcouffin.sys
+ 2010-03-02 16:36 . 2009-07-01 03:53 13824 c:\windows\system32\drivers\nvnetbus.sys
+ 2010-03-02 16:38 . 2009-07-01 03:53 66688 c:\windows\system32\drivers\NVENETFD.sys
- 2009-03-12 05:33 . 2009-09-10 19:54 38224 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2009-03-12 05:33 . 2009-09-10 20:54 38224 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2009-03-12 05:33 . 2009-09-10 20:53 19160 c:\windows\system32\drivers\mbam.sys
- 2009-03-12 05:33 . 2009-09-10 19:53 19160 c:\windows\system32\drivers\mbam.sys
+ 2009-11-16 15:06 . 2009-11-16 15:06 96408 c:\windows\system32\drivers\epfwtdir.sys
+ 2005-05-09 23:17 . 2008-04-13 17:45 60160 c:\windows\system32\drivers\drmk.sys
- 2005-05-09 23:17 . 2008-04-13 18:45 60160 c:\windows\system32\drivers\drmk.sys
+ 2009-06-12 01:51 . 2010-02-25 06:24 12800 c:\windows\system32\dllcache\xpshims.dll
- 2009-06-12 01:51 . 2009-08-29 08:08 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-10-21 05:38 . 2009-10-21 05:38 75776 c:\windows\system32\dllcache\strmfilt.dll
+ 2009-10-12 13:38 . 2009-10-12 13:38 79872 c:\windows\system32\dllcache\raschap.dll
+ 2009-10-08 20:56 . 2009-10-08 20:56 20480 c:\windows\system32\dllcache\oleaccrc.dll
+ 2009-11-27 17:11 . 2009-11-27 17:11 17920 c:\windows\system32\dllcache\msyuv.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 28672 c:\windows\system32\dllcache\msvidc32.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 11264 c:\windows\system32\dllcache\msrle32.dll
- 2007-05-09 02:05 . 2009-08-29 08:08 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-05-09 02:05 . 2010-02-25 06:24 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2006-05-10 05:22 . 2009-08-29 08:08 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:22 . 2010-02-25 06:24 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 48128 c:\windows\system32\dllcache\iyuv_32.dll
+ 2009-10-21 05:38 . 2009-10-21 05:38 25088 c:\windows\system32\dllcache\httpapi.dll
+ 2009-06-16 14:36 . 2009-10-15 16:28 81920 c:\windows\system32\dllcache\fontsub.dll
- 2009-06-16 14:36 . 2009-06-16 14:36 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2009-12-14 07:08 . 2009-12-14 07:08 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2010-01-13 14:01 . 2010-01-13 14:01 86016 c:\windows\system32\dllcache\cabview.dll
+ 2009-06-10 14:13 . 2009-11-27 16:07 84992 c:\windows\system32\dllcache\avifil32.dll
- 2009-06-10 14:13 . 2009-06-10 14:13 84992 c:\windows\system32\dllcache\avifil32.dll
+ 2005-03-23 16:52 . 2009-12-14 07:08 33280 c:\windows\system32\csrsrv.dll
+ 2009-11-05 03:54 . 2007-07-13 04:33 87552 c:\windows\system32\cpwmon2k.dll
+ 2005-03-23 16:52 . 2010-01-13 14:01 86016 c:\windows\system32\cabview.dll
+ 2010-03-02 16:36 . 2009-07-01 03:55 11264 c:\windows\system32\bdco1ins.dll
+ 2010-03-02 16:36 . 2009-07-01 03:55 11264 c:\windows\system32\bdco1.dll
+ 2005-03-23 16:52 . 2009-11-27 16:07 84992 c:\windows\system32\avifil32.dll
- 2005-03-23 16:52 . 2009-06-10 14:13 84992 c:\windows\system32\avifil32.dll
- 2005-05-09 23:17 . 2005-04-15 18:01 77824 c:\windows\SOUNDMAN.EXE
+ 2005-05-09 23:17 . 2008-08-19 05:26 77824 c:\windows\SOUNDMAN.EXE
+ 2010-03-14 05:30 . 2010-03-14 05:30 25088 c:\windows\Installer\a1e8bf4.msi
+ 2010-03-12 06:28 . 2010-03-12 06:28 27648 c:\windows\Installer\4bf31.msi
+ 2010-03-12 06:08 . 2010-03-12 06:08 97792 c:\windows\Installer\49261f6.msi
+ 2010-03-12 06:07 . 2010-03-12 06:07 69120 c:\windows\Installer\49261ec.msi
+ 2010-03-12 06:05 . 2010-03-12 06:05 23040 c:\windows\Installer\49261de.msi
+ 2010-03-23 01:08 . 2010-03-23 01:08 78336 c:\windows\Installer\3dcf0f8.msp
+ 2010-01-30 19:49 . 2010-01-30 19:49 49664 c:\windows\Installer\292d37f6.msi
+ 2010-03-02 17:04 . 2010-03-02 17:04 20480 c:\windows\Installer\163660.msi
+ 2009-11-29 09:34 . 2009-11-29 09:34 27648 c:\windows\Installer\1555810b.msi
+ 2009-11-24 21:17 . 2009-11-24 21:17 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe
- 2005-05-09 23:13 . 2005-10-05 05:44 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2005-05-09 23:13 . 2010-05-12 02:40 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2005-05-09 23:13 . 2005-10-05 05:44 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2005-05-09 23:13 . 2010-05-12 02:40 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2005-05-09 23:13 . 2010-05-12 02:40 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2005-05-09 23:13 . 2005-10-05 05:44 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2005-05-09 23:13 . 2010-05-12 02:40 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2005-05-09 23:13 . 2005-10-05 05:44 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2010-04-14 07:11 . 2010-04-14 07:11 34632 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-12-02 11:44 . 2009-12-02 11:44 10134 c:\windows\Installer\{6864ABC3-A982-436B-BEF1-5652D6303361}\callmsi.exe
+ 2007-03-23 01:07 . 2007-03-23 01:07 78168 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\RM.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 41824 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\RECALL.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 91488 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\ADDRPARS.DLL
+ 2003-01-17 21:03 . 2003-01-17 21:03 59466 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\XSCAN32.DAT
+ 2002-10-07 16:49 . 2002-10-07 16:49 81983 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TWRECS.DLL
+ 2002-10-07 16:49 . 2002-10-07 16:49 81984 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\REVERSE.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 78168 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\RM.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 41824 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\RECALL.DLL
+ 2007-03-23 01:05 . 2007-03-23 01:05 97632 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PP7X32.DLL
+ 2007-04-19 19:53 . 2007-04-19 19:53 69984 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OUTLRPC.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 80224 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\DLGSETP.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 91488 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\ADDRPARS.DLL
+ 2005-05-09 23:13 . 2005-05-09 23:13 64088 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\VBIDEPIA.DLL
+ 2003-07-15 06:00 . 2003-07-15 06:00 99904 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TRANSMGR.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 11848 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SMARTTAGINSTALL.EXE
+ 2003-07-15 05:57 . 2003-07-15 05:57 58944 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 66616 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SENDTO.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 40512 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
+ 2003-05-09 04:54 . 2003-05-09 04:54 77824 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
+ 2003-07-15 05:42 . 2003-07-15 05:42 37432 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\RECALL.DLL
+ 2003-07-15 06:40 . 2003-07-15 06:40 51256 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PUBTRAP.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 93752 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 49208 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLWAB.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 64056 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLRPC.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 88128 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLMIME.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 27192 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
+ 2003-07-15 05:56 . 2003-07-15 05:56 13888 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 56888 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\NAME.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 41528 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 16384 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 39488 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 55360 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
+ 2003-07-15 05:46 . 2003-07-15 05:46 42040 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 39488 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOSVFBR.DLL
Can someone take a look at my logs here and let me know if there is anything wrong.. My computer slowed way down and then I noticed that comodo was using like 160k on task manager. I tried to shut it down and couldn't so I uninstalled it that seemed to take care of things. Did a virus attach itself to comodo.. or did something go wrong there... I decided to shut off comodo safesurf as well just to be safe.
Let me know what you guys think. Also I turned window firewall back on but should I try reinstalling comodo or try another firewall.. opinions?
But first and foremost.. do I have anything.. ?
Thanks a lot.. here are my hijackthis log and combofix...
HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:46:30 PM, on 5/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [LXCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1670103657-2857965304-651090504-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
O16 - DPF: {AE6C4705-0F11-4ACB-BDD4-37F138BEF289} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader45.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxci_device - - C:\WINDOWS\system32\lxcicoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
--
End of file - 6607 bytes
COMBOFIX LOG:
ComboFix 10-05-25.02 - Owner 05/25/2010 20:58:54.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.413 [GMT -5:00]
Running from: c:\documents and settings\Owner\My Documents\Downloads\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Application Data\inst.exe
c:\windows\system32\CE8B5AC411.dll
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Created from 2010-04-26 to 2010-05-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-26 01:36 . 2007-10-18 07:54 -------- d-----w- c:\documents and settings\Owner\Application Data\Comodo
2010-05-26 01:36 . 2007-10-18 07:52 -------- d-----w- c:\program files\Comodo
2010-05-26 01:33 . 2007-10-18 07:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo
2010-05-24 20:00 . 2006-01-09 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-22 10:22 . 2006-04-25 20:24 -------- d-----w- c:\program files\Lx_cats
2010-04-14 07:38 . 2010-04-09 06:23 2110440 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-04-07 17:23 . 2005-12-02 22:32 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-03-29 06:39 . 2010-03-29 06:39 -------- d-----w- c:\documents and settings\Owner\Application Data\PixelMetrics
2010-03-29 06:38 . 2010-03-29 06:38 -------- d-----w- c:\program files\Windows Media Adapter v615
2010-03-29 06:38 . 2010-03-29 06:38 -------- d-----w- c:\program files\CaptureWiz
2010-03-27 06:39 . 2007-09-25 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2010-03-10 06:15 . 2005-03-23 16:52 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-26 05:23 . 2005-07-31 18:58 73360 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-25 06:24 . 2005-03-23 16:53 916480 ----a-w- c:\windows\system32\wininet.dll
2009-09-13 04:44 . 2009-09-13 04:44 1962544 ----a-w- c:\program files\install_flash_player_ax.exe
2009-04-16 11:20 . 2009-04-16 11:19 17920 --sha-w- c:\program files\Thumbs.db
2008-09-17 00:08 . 2008-11-29 21:29 65686 ----a-w- c:\program files\Photoshop CS4 Read Me.pdf
2008-09-11 16:49 . 2008-11-29 21:29 108336 ----a-w- c:\program files\Photoshop CS4 — Lisez-moi.pdf
2008-09-11 16:47 . 2008-11-29 21:29 103148 ----a-w- c:\program files\Léame de Photoshop CS4.pdf
2007-04-02 00:34 . 2008-06-03 18:52 1093226 ----a-w- c:\program files\undelete_plus_setup.exe
2006-01-09 06:51 . 2005-12-13 05:39 774144 ----a-w- c:\program files\RngInterstitial.dll
2005-07-31 03:35 . 2005-07-31 03:35 0 --sha-w- c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( SnapShot_2009-10-31_20.49.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-12-02 06:46 . 2006-12-02 06:46 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
+ 2009-07-12 01:41 . 2009-07-12 01:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2010-03-12 06:06 . 2010-03-12 06:06 45344 c:\windows\WinSxS\MSIL_Intuit.Spc.Esd.WinClient.Application.Update_540d4816ead86321_3.0.335.0_x-ww_e51d7605\Intuit.Spc.Esd.WinClient.Application.Update.exe
+ 2010-03-12 06:06 . 2010-03-12 06:06 40224 c:\windows\WinSxS\MSIL_Intuit.Spc.Esd.WinClient.Application.ConfigUXv2_540d4816ead86321_3.0.335.0_x-ww_29a6be0d\Intuit.Spc.Esd.WinClient.Application.ConfigUXv2.exe
+ 2010-05-26 01:37 . 2010-05-26 01:37 16384 c:\windows\temp\Perflib_Perfdata_60c.dat
+ 2004-08-04 07:56 . 2008-04-13 23:12 23552 c:\windows\system32\wdmaud.drv
- 2004-08-04 07:56 . 2008-04-14 00:12 23552 c:\windows\system32\wdmaud.drv
- 2007-01-29 08:58 . 2009-07-14 11:03 46080 c:\windows\system32\tzchange.exe
+ 2007-01-29 08:58 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe
- 2005-03-23 16:52 . 2008-04-14 00:12 75776 c:\windows\system32\strmfilt.dll
+ 2005-03-23 16:52 . 2009-10-21 05:38 75776 c:\windows\system32\strmfilt.dll
+ 2005-05-09 23:13 . 2007-04-09 19:23 28552 c:\windows\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2005-05-09 23:13 . 2007-04-09 19:23 46472 c:\windows\system32\spool\drivers\w32x86\mdiui.dll
+ 2005-05-09 23:13 . 2007-04-09 19:23 46472 c:\windows\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2010-03-02 16:32 . 2009-07-21 08:40 41472 c:\windows\system32\RtkCoInstXP.dll
- 2005-03-23 16:52 . 2008-04-14 00:12 79872 c:\windows\system32\raschap.dll
+ 2005-03-23 16:52 . 2009-10-12 13:38 79872 c:\windows\system32\raschap.dll
+ 2005-03-23 16:52 . 2010-05-26 01:59 71060 c:\windows\system32\perfc009.dat
+ 2005-03-23 16:52 . 2009-10-08 20:56 20480 c:\windows\system32\oleaccrc.dll
+ 2004-08-04 07:56 . 2009-11-27 17:11 17920 c:\windows\system32\msyuv.dll
+ 2005-03-23 16:52 . 2009-11-27 16:07 28672 c:\windows\system32\msvidc32.dll
- 2005-03-23 16:52 . 2008-04-14 00:12 11264 c:\windows\system32\msrle32.dll
+ 2005-03-23 16:52 . 2009-11-27 16:07 11264 c:\windows\system32\msrle32.dll
+ 2006-11-08 04:03 . 2010-02-25 06:24 55296 c:\windows\system32\msfeedsbs.dll
- 2006-11-08 04:03 . 2009-08-29 08:08 55296 c:\windows\system32\msfeedsbs.dll
+ 2005-05-09 23:13 . 2007-04-09 19:23 28040 c:\windows\system32\mdimon.dll
- 2009-05-11 22:24 . 2009-09-27 18:39 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2010-01-31 06:38 . 2010-02-24 07:39 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2005-03-23 16:52 . 2009-08-29 08:08 25600 c:\windows\system32\jsproxy.dll
+ 2005-03-23 16:52 . 2010-02-25 06:24 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-04 07:56 . 2009-11-27 16:07 48128 c:\windows\system32\iyuv_32.dll
+ 2005-03-23 16:52 . 2009-10-21 05:38 25088 c:\windows\system32\httpapi.dll
- 2005-03-23 16:52 . 2009-06-16 14:36 81920 c:\windows\system32\fontsub.dll
+ 2005-03-23 16:52 . 2009-10-15 16:28 81920 c:\windows\system32\fontsub.dll
+ 2007-03-23 01:17 . 2007-03-23 01:17 35440 c:\windows\system32\FM20ENU.DLL
+ 2004-08-04 06:08 . 2008-04-13 17:45 49408 c:\windows\system32\drivers\stream.sys
- 2004-08-04 06:08 . 2008-04-13 18:45 49408 c:\windows\system32\drivers\stream.sys
+ 2009-04-14 09:34 . 2009-12-23 20:46 47360 c:\windows\system32\drivers\pcouffin.sys
- 2009-04-14 09:34 . 2009-04-14 09:34 47360 c:\windows\system32\drivers\pcouffin.sys
+ 2010-03-02 16:36 . 2009-07-01 03:53 13824 c:\windows\system32\drivers\nvnetbus.sys
+ 2010-03-02 16:38 . 2009-07-01 03:53 66688 c:\windows\system32\drivers\NVENETFD.sys
- 2009-03-12 05:33 . 2009-09-10 19:54 38224 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2009-03-12 05:33 . 2009-09-10 20:54 38224 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2009-03-12 05:33 . 2009-09-10 20:53 19160 c:\windows\system32\drivers\mbam.sys
- 2009-03-12 05:33 . 2009-09-10 19:53 19160 c:\windows\system32\drivers\mbam.sys
+ 2009-11-16 15:06 . 2009-11-16 15:06 96408 c:\windows\system32\drivers\epfwtdir.sys
+ 2005-05-09 23:17 . 2008-04-13 17:45 60160 c:\windows\system32\drivers\drmk.sys
- 2005-05-09 23:17 . 2008-04-13 18:45 60160 c:\windows\system32\drivers\drmk.sys
+ 2009-06-12 01:51 . 2010-02-25 06:24 12800 c:\windows\system32\dllcache\xpshims.dll
- 2009-06-12 01:51 . 2009-08-29 08:08 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-10-21 05:38 . 2009-10-21 05:38 75776 c:\windows\system32\dllcache\strmfilt.dll
+ 2009-10-12 13:38 . 2009-10-12 13:38 79872 c:\windows\system32\dllcache\raschap.dll
+ 2009-10-08 20:56 . 2009-10-08 20:56 20480 c:\windows\system32\dllcache\oleaccrc.dll
+ 2009-11-27 17:11 . 2009-11-27 17:11 17920 c:\windows\system32\dllcache\msyuv.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 28672 c:\windows\system32\dllcache\msvidc32.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 11264 c:\windows\system32\dllcache\msrle32.dll
- 2007-05-09 02:05 . 2009-08-29 08:08 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-05-09 02:05 . 2010-02-25 06:24 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2006-05-10 05:22 . 2009-08-29 08:08 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:22 . 2010-02-25 06:24 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-11-27 16:07 . 2009-11-27 16:07 48128 c:\windows\system32\dllcache\iyuv_32.dll
+ 2009-10-21 05:38 . 2009-10-21 05:38 25088 c:\windows\system32\dllcache\httpapi.dll
+ 2009-06-16 14:36 . 2009-10-15 16:28 81920 c:\windows\system32\dllcache\fontsub.dll
- 2009-06-16 14:36 . 2009-06-16 14:36 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2009-12-14 07:08 . 2009-12-14 07:08 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2010-01-13 14:01 . 2010-01-13 14:01 86016 c:\windows\system32\dllcache\cabview.dll
+ 2009-06-10 14:13 . 2009-11-27 16:07 84992 c:\windows\system32\dllcache\avifil32.dll
- 2009-06-10 14:13 . 2009-06-10 14:13 84992 c:\windows\system32\dllcache\avifil32.dll
+ 2005-03-23 16:52 . 2009-12-14 07:08 33280 c:\windows\system32\csrsrv.dll
+ 2009-11-05 03:54 . 2007-07-13 04:33 87552 c:\windows\system32\cpwmon2k.dll
+ 2005-03-23 16:52 . 2010-01-13 14:01 86016 c:\windows\system32\cabview.dll
+ 2010-03-02 16:36 . 2009-07-01 03:55 11264 c:\windows\system32\bdco1ins.dll
+ 2010-03-02 16:36 . 2009-07-01 03:55 11264 c:\windows\system32\bdco1.dll
+ 2005-03-23 16:52 . 2009-11-27 16:07 84992 c:\windows\system32\avifil32.dll
- 2005-03-23 16:52 . 2009-06-10 14:13 84992 c:\windows\system32\avifil32.dll
- 2005-05-09 23:17 . 2005-04-15 18:01 77824 c:\windows\SOUNDMAN.EXE
+ 2005-05-09 23:17 . 2008-08-19 05:26 77824 c:\windows\SOUNDMAN.EXE
+ 2010-03-14 05:30 . 2010-03-14 05:30 25088 c:\windows\Installer\a1e8bf4.msi
+ 2010-03-12 06:28 . 2010-03-12 06:28 27648 c:\windows\Installer\4bf31.msi
+ 2010-03-12 06:08 . 2010-03-12 06:08 97792 c:\windows\Installer\49261f6.msi
+ 2010-03-12 06:07 . 2010-03-12 06:07 69120 c:\windows\Installer\49261ec.msi
+ 2010-03-12 06:05 . 2010-03-12 06:05 23040 c:\windows\Installer\49261de.msi
+ 2010-03-23 01:08 . 2010-03-23 01:08 78336 c:\windows\Installer\3dcf0f8.msp
+ 2010-01-30 19:49 . 2010-01-30 19:49 49664 c:\windows\Installer\292d37f6.msi
+ 2010-03-02 17:04 . 2010-03-02 17:04 20480 c:\windows\Installer\163660.msi
+ 2009-11-29 09:34 . 2009-11-29 09:34 27648 c:\windows\Installer\1555810b.msi
+ 2009-11-24 21:17 . 2009-11-24 21:17 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe
- 2005-05-09 23:13 . 2005-10-05 05:44 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2005-05-09 23:13 . 2010-05-12 02:40 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2005-05-09 23:13 . 2005-10-05 05:44 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2005-05-09 23:13 . 2010-05-12 02:40 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2005-05-09 23:13 . 2010-05-12 02:40 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2005-05-09 23:13 . 2005-10-05 05:44 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2005-05-09 23:13 . 2010-05-12 02:40 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2005-05-09 23:13 . 2005-10-05 05:44 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2010-04-14 07:11 . 2010-04-14 07:11 34632 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2006-01-02 21:41 . 2010-05-12 02:40 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2006-01-02 21:41 . 2007-12-13 22:20 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-12-02 11:44 . 2009-12-02 11:44 10134 c:\windows\Installer\{6864ABC3-A982-436B-BEF1-5652D6303361}\callmsi.exe
+ 2007-03-23 01:07 . 2007-03-23 01:07 78168 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\RM.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 41824 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\RECALL.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 91488 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\ADDRPARS.DLL
+ 2003-01-17 21:03 . 2003-01-17 21:03 59466 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\XSCAN32.DAT
+ 2002-10-07 16:49 . 2002-10-07 16:49 81983 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\TWRECS.DLL
+ 2002-10-07 16:49 . 2002-10-07 16:49 81984 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.5614\REVERSE.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 78168 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\RM.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 41824 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\RECALL.DLL
+ 2007-03-23 01:05 . 2007-03-23 01:05 97632 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PP7X32.DLL
+ 2007-04-19 19:53 . 2007-04-19 19:53 69984 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OUTLRPC.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 80224 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\DLGSETP.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 91488 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\ADDRPARS.DLL
+ 2005-05-09 23:13 . 2005-05-09 23:13 64088 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\VBIDEPIA.DLL
+ 2003-07-15 06:00 . 2003-07-15 06:00 99904 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\TRANSMGR.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 11848 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SMARTTAGINSTALL.EXE
+ 2003-07-15 05:57 . 2003-07-15 05:57 58944 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 66616 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SENDTO.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 40512 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
+ 2003-05-09 04:54 . 2003-05-09 04:54 77824 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
+ 2003-07-15 05:42 . 2003-07-15 05:42 37432 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\RECALL.DLL
+ 2003-07-15 06:40 . 2003-07-15 06:40 51256 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PUBTRAP.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 93752 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 49208 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLWAB.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 64056 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLRPC.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 88128 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLMIME.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 27192 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
+ 2003-07-15 05:56 . 2003-07-15 05:56 13888 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 56888 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\NAME.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 41528 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 16384 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 39488 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 55360 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
+ 2003-07-15 05:46 . 2003-07-15 05:46 42040 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 39488 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOSVFBR.DLL