Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice

Repeated spyware alerts

1117 Views 8 Replies 2 Participants Last post by  Cookiegal
About a week ago, I had accidentally received the msn "Hey, isn't this you?" virus, and using a separate computer I checked online for instructions to remove it,
I think most of it has been removed, but now, whenever I run Spybot - Search & Destroy and Ad-Aware, several spyware files keep on appearing, including redirected webpages...

Here is my most recent hijackthis log, any help would be greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:51:25 AM, on 02/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\User\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 211.231.187.4:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [PathNvidiaTV] C:\Program Files\Gigabyte\Nvidia\patchnvidiaTVout.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1169840645468
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 9302 bytes
See less See more
Status
Not open for further replies.
1 - 9 of 9 Posts
Hi and welcome to TSG,

Please close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix and make sure you are disconnected from the Internet after downloading the program and before scanning.

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix and remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re-enable the protection again afterwards before connecting to the Internet.

Download ComboFix and save it to your desktop.

**Note: In the event you already have ComboFix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running ComboFix.
  • WARNING: IF you have not already done so ComboFix will disconnect your machine from the Internet when it starts.
  • Please do not re-connect your machine back to the Internet until ComboFix has completely finished.
  • If there is no Internet connection when Combofix has completely finished then restart your computer to restore the connection.

Double-click on combofix.exe and follow the prompts. When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

**Note: Do not mouseclick comboFix's window while it's running. That may cause it to stall**
See less See more
Thank you for your help

ComboFix 08-02.05.3 - User 2008-02-05 16:22:06.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.597 [GMT -8:00]
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\User\Application Data\macromedia\Flash Player\#SharedObjects\54UJBZLW\iforex.com
C:\Documents and Settings\User\Application Data\macromedia\Flash Player\#SharedObjects\54UJBZLW\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\User\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol

.
((((((((((((((((((((((((( Files Created from 2008-01-06 to 2008-02-06 )))))))))))))))))))))))))))))))
.

2008-01-30 00:46 . 2008-01-30 00:47 d-------- C:\cyc
2008-01-26 20:59 . 2008-01-26 20:59 d-------- C:\Program Files\OpenAL
2008-01-26 20:59 . 2008-01-26 20:59 409,600 --a------ C:\WINDOWS\system32\wrap_oal.dll
2008-01-26 20:59 . 2008-01-26 20:59 114,688 --a------ C:\WINDOWS\system32\OpenAL32.dll
2008-01-24 23:25 . 2008-02-05 12:55 d-------- C:\Documents and Settings\User\Application Data\AVG7
2008-01-24 23:24 . 2008-01-24 23:24 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-24 23:24 . 2008-01-24 23:24 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-24 23:24 . 2008-01-25 19:49 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-22 18:24 . 2008-01-22 18:24 d-------- C:\Program Files\SecondLife
2008-01-22 18:24 . 2008-01-22 18:33 d-------- C:\Documents and Settings\User\Application Data\SecondLife
2008-01-21 20:06 . 2008-01-22 21:45 d-------- C:\WINDOWS\A3W_DATA
2008-01-21 19:56 . 2008-01-21 19:56 d-------- C:\MPS
2008-01-18 01:48 . 2008-02-05 12:55 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-18 01:48 . 2008-01-18 01:48 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-18 00:51 . 2008-01-18 00:52 d-------- C:\Program Files\iTunes
2008-01-18 00:51 . 2008-01-18 00:51 d-------- C:\Program Files\iPod
2008-01-18 00:49 . 2008-01-18 00:49 d-------- C:\Program Files\Common Files\Apple
2008-01-18 00:49 . 2008-01-18 00:49 d-------- C:\Program Files\Apple Software Update
2008-01-18 00:49 . 2008-01-18 00:49 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-11 09:13 . 2008-01-11 09:13 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-01-08 07:54 . 2008-01-08 07:54 d-------- C:\Documents and Settings\User\.psycle
2008-01-08 07:54 . 2008-01-08 10:24 4,445 --a------ C:\WINDOWS\PsycleKeys.INI
2008-01-08 07:53 . 2008-01-08 07:53 d-------- C:\Program Files\Psycle

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-06 00:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-06 00:18 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-02 01:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-24 07:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-24 07:39 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-24 01:21 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-24 01:21 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-24 01:21 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-24 01:21 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-24 01:21 --------- d-----w C:\Program Files\Symantec
2008-01-18 08:52 --------- d-----w C:\Documents and Settings\User\Application Data\Apple Computer
2008-01-18 08:51 --------- d-----w C:\Program Files\QuickTime
2008-01-18 08:51 --------- d-----w C:\Program Files\Bonjour
2008-01-18 08:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-15 17:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 13:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 02:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-09 14:12 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-03 13:30 --------- d-----w C:\Program Files\Enterbrain
2008-01-03 13:29 --------- d-----w C:\Program Files\RAGS Suite
2008-01-03 13:27 --------- d-----w C:\Program Files\VstPlugins
2007-12-31 23:00 --------- d-----w C:\Program Files\PixGrabber Free
2007-12-31 22:56 --------- d-----w C:\Documents and Settings\User\Application Data\SoftInform
2007-12-30 09:38 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-12-27 09:11 --------- d-----w C:\Documents and Settings\User\Application Data\Command & Conquer 3 Tiberium Wars
2007-12-27 02:50 --------- d-----w C:\Program Files\ADRIFT
2007-12-27 02:15 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-12-27 02:15 249,856 ------w C:\WINDOWS\Setup1.exe
2007-12-26 00:14 --------- d--h--r C:\Documents and Settings\User\Application Data\SecuROM
2007-12-25 23:49 --------- d-----w C:\Program Files\Electronic Arts
2007-12-25 09:50 --------- d-----w C:\Program Files\World of Warcraft
2007-12-24 20:13 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2007-12-19 23:02 --------- d-----w C:\Program Files\Java
2007-12-08 23:44 --------- d-----w C:\Program Files\Cave Story Deluxe
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-07-31 19:25 56 --sh--r C:\WINDOWS\system32\C3E2FDBB1E.sys
2007-07-31 19:25 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 04:00 15360]
"Start WingMan Profiler"="C:\Program Files\Logitech\Profiler\lwemon.exe" [2005-04-18 10:16 73728]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]
"AudioDeck"="C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe" [2007-01-26 11:34 528384]
"NVRTCLK"="C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe" [2003-12-30 01:44 24576]
"PathNvidiaTV"="C:\Program Files\Gigabyte\Nvidia\patchnvidiaTVout.exe" [ ]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 18:22 26248]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-12 00:42 185632]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-25 19:52 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-24 23:24 219136]

S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2004-10-21 06:26]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 05:15:02 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - User.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-05 16:26:44
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1????????????????????????????????????????????????
PathNvidiaTV = C:\Program Files\Gigabyte\Nvidia\patchnvidiaTVout.exe??????|E??|N??|[email protected][email protected]???D<[email protected]?????|[email protected]??x????D?|p??|???|?D?|?5?|?C?|????????????????????????????<??????????|????????Q??|????m??|???????????????|???????????|????????`???&s?|???|?s?|???Z???

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-05 16:29:22
ComboFix-quarantined-files.txt 2008-02-06 00:29:19
.
2008-01-09 11:01:50 --- E O F ---

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:41:41 PM, on 05/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\User\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 211.231.187.4:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [PathNvidiaTV] C:\Program Files\Gigabyte\Nvidia\patchnvidiaTVout.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1169840645468
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 9151 bytes
See less See more
Open Notepad and copy and paste the text in the code box below into it:

Code:
DirLook::
C:\cyc
C:\MPS
Save the file to your desktop and name it CFScript.txt

Then drag the CFScript.txt into the ComboFix.exe as shown in the screenshot below.



This will start ComboFix again. It may ask to reboot. Post the contents of Combofix.txt in your next reply together with a new HijackThis log.
See less See more
I'm sorry, both logs combined are too long for one post

ComboFix 08-02.05.3 - User 2008-02-09 18:44:24.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.593 [GMT -8:00]
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
.

2008-01-30 00:46 . 2008-01-30 00:47 d-------- C:\cyc
2008-01-26 20:59 . 2008-01-26 20:59 d-------- C:\Program Files\OpenAL
2008-01-26 20:59 . 2008-01-26 20:59 409,600 --a------ C:\WINDOWS\system32\wrap_oal.dll
2008-01-26 20:59 . 2008-01-26 20:59 114,688 --a------ C:\WINDOWS\system32\OpenAL32.dll
2008-01-24 23:25 . 2008-02-09 18:26 d-------- C:\Documents and Settings\User\Application Data\AVG7
2008-01-24 23:24 . 2008-01-24 23:24 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-24 23:24 . 2008-01-24 23:24 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-24 23:24 . 2008-01-25 19:49 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-01-22 18:24 . 2008-01-22 18:24 d-------- C:\Program Files\SecondLife
2008-01-22 18:24 . 2008-02-06 00:30 d-------- C:\Documents and Settings\User\Application Data\SecondLife
2008-01-21 20:06 . 2008-01-22 21:45 d-------- C:\WINDOWS\A3W_DATA
2008-01-21 19:56 . 2008-01-21 19:56 d-------- C:\MPS
2008-01-18 01:48 . 2008-02-09 18:42 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-18 01:48 . 2008-01-18 01:48 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-18 00:51 . 2008-01-18 00:52 d-------- C:\Program Files\iTunes
2008-01-18 00:51 . 2008-01-18 00:51 d-------- C:\Program Files\iPod
2008-01-18 00:49 . 2008-01-18 00:49 d-------- C:\Program Files\Common Files\Apple
2008-01-18 00:49 . 2008-01-18 00:49 d-------- C:\Program Files\Apple Software Update
2008-01-18 00:49 . 2008-01-18 00:49 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-11 09:13 . 2008-01-11 09:13 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 02:42 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-08 05:16 --------- d-----w C:\Program Files\ADRIFT
2008-02-06 00:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-02 01:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-24 07:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-24 07:39 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-24 01:21 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-24 01:21 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-24 01:21 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-24 01:21 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-24 01:21 --------- d-----w C:\Program Files\Symantec
2008-01-18 08:52 --------- d-----w C:\Documents and Settings\User\Application Data\Apple Computer
2008-01-18 08:51 --------- d-----w C:\Program Files\QuickTime
2008-01-18 08:51 --------- d-----w C:\Program Files\Bonjour
2008-01-18 08:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-15 17:54 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 13:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 02:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-09 14:12 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-08 15:53 --------- d-----w C:\Program Files\Psycle
2008-01-03 13:30 --------- d-----w C:\Program Files\Enterbrain
2008-01-03 13:29 --------- d-----w C:\Program Files\RAGS Suite
2008-01-03 13:27 --------- d-----w C:\Program Files\VstPlugins
2007-12-31 23:00 --------- d-----w C:\Program Files\PixGrabber Free
2007-12-31 22:56 --------- d-----w C:\Documents and Settings\User\Application Data\SoftInform
2007-12-30 09:38 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-12-27 09:11 --------- d-----w C:\Documents and Settings\User\Application Data\Command & Conquer 3 Tiberium Wars
2007-12-27 02:15 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-12-27 02:15 249,856 ------w C:\WINDOWS\Setup1.exe
2007-12-26 00:14 --------- d--h--r C:\Documents and Settings\User\Application Data\SecuROM
2007-12-25 23:49 --------- d-----w C:\Program Files\Electronic Arts
2007-12-25 09:50 --------- d-----w C:\Program Files\World of Warcraft
2007-12-24 20:13 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2007-12-19 23:02 --------- d-----w C:\Program Files\Java
2007-07-31 19:25 56 --sh--r C:\WINDOWS\system32\C3E2FDBB1E.sys
2007-07-31 19:25 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\cyc ----

2008-01-30 00:47 19456 --ahs---- C:\cyc\data\Thumbs.db
2007-08-16 11:12 7639 --a------ C:\cyc\readme_j.txt
2007-08-16 07:41 16216 --a------ C:\cyc\data\tit01.png
2007-08-16 07:41 13238 --a------ C:\cyc\data\tit00.png
2007-08-16 06:31 7927 --a------ C:\cyc\data\bg01.png
2007-08-16 06:31 29133 --a------ C:\cyc\data\bg02.png
2007-08-16 06:31 25262 --a------ C:\cyc\data\bg00.png
2007-08-15 07:11 2103 --a------ C:\cyc\data\char00.png
2007-08-14 07:23 7081 --a------ C:\cyc\data\add00.png
2007-08-13 10:35 4343 --a------ C:\cyc\data\font00.png

---- Directory of C:\MPS ----

2008-01-22 22:23 145859 --a------ C:\MPS\CIV2\Je_Auto.SAV
2008-01-22 22:20 145671 --a------ C:\MPS\CIV2\JE_AUTO2.SAV
2008-01-22 22:17 22 --a------ C:\MPS\CIV2\PEDIA\GET_INFO.TXT
2008-01-22 16:03 144545 --a------ C:\MPS\CIV2\CANADA1.SAV
2008-01-22 14:47 72 --a------ C:\MPS\CIV2\CIV2.DAT
2008-01-22 00:55 432 --a------ C:\MPS\CIV2\HALLFAME.DAT
2008-01-22 00:53 76361 --a------ C:\MPS\CIV2\To_Auto.SAV
2008-01-22 00:53 76309 --a------ C:\MPS\CIV2\TO_AUTO2.SAV
2008-01-21 22:30 139067 --a------ C:\MPS\CIV2\Ki_Auto.SAV
2008-01-21 22:25 139003 --a------ C:\MPS\CIV2\KI_AUTO2.SAV
2008-01-21 22:05 54098 --a------ C:\MPS\CIV2\TEST.MP
2008-01-21 19:57 10609 --a------ C:\MPS\CIV2\INSTALL.LOG
1996-10-08 03:33 1764880 --------- C:\MPS\CIV2\civ2.exe
1996-08-13 05:20 107111 --------- C:\MPS\CIV2\game.fre
1996-08-05 08:51 25824 --------- C:\MPS\CIV2\rules.txt
1996-04-23 02:07 28220 --------- C:\MPS\CIV2\rules.fre
1996-04-23 02:07 27237 --------- C:\MPS\CIV2\rules.ger
1996-04-16 03:00 106447 --------- C:\MPS\CIV2\game.ger
1996-04-16 02:50 93404 --------- C:\MPS\CIV2\game.txt
1996-04-15 04:31 2455 --------- C:\MPS\CIV2\menu.fre
1996-04-15 04:31 2390 --------- C:\MPS\CIV2\menu.ger
1996-04-15 04:24 2052 --------- C:\MPS\CIV2\menu.txt
1996-03-28 07:31 19 --------- C:\MPS\CIV2\inter.dat
1996-02-27 08:39 6905 --------- C:\MPS\CIV2\labels.fre
1996-02-27 05:41 7006 --------- C:\MPS\CIV2\labels.ger
1996-02-27 02:41 1179 --------- C:\MPS\CIV2\rome.fre
1996-02-27 02:29 692 --------- C:\MPS\CIV2\wwii.fre
1996-02-27 01:53 6873 --------- C:\MPS\CIV2\advice.fre
1996-02-27 01:21 1796 --------- C:\MPS\CIV2\readme.fra
1996-02-26 07:24 77339 --------- C:\MPS\CIV2\rome.scn
1996-02-20 05:06 69749 --------- C:\MPS\CIV2\tutorial.sav
1996-02-16 08:46 1765376 --------- C:\MPS\CIV2\civ2map.exe
1996-02-16 07:38 2569834 --------- C:\MPS\CIV2\mk.dll
1996-02-16 07:02 11087239 --------- C:\MPS\CIV2\PEDIA\get_info.exe
1996-02-16 07:00 859092 --------- C:\MPS\CIV2\PEDIA\graphics.apr
1996-02-16 07:00 46542 --------- C:\MPS\CIV2\PEDIA\function.apr
1996-02-16 04:29 14993 --------- C:\MPS\CIV2\PEDIA\describe.pdg
1996-02-16 02:19 276630 --------- C:\MPS\CIV2\SOUND\drumal.wav
1996-02-16 02:18 377908 --------- C:\MPS\CIV2\SOUND\drumbl.wav
1996-02-16 02:17 492366 --------- C:\MPS\CIV2\SOUND\drumcl.wav
1996-02-16 01:26 46491 --------- C:\MPS\CIV2\terrain1.gif
1996-02-15 20:41 122986 --------- C:\MPS\CIV2\civ2art.dll
1996-02-15 12:08 13745 --------- C:\MPS\CIV2\council0.ger
1996-02-15 12:07 13485 --------- C:\MPS\CIV2\council1.ger
1996-02-15 12:06 13904 --------- C:\MPS\CIV2\council2.ger
1996-02-15 10:23 14375 --------- C:\MPS\CIV2\council1.fre
1996-02-15 10:22 14540 --------- C:\MPS\CIV2\council0.fre
1996-02-15 10:01 19683 --------- C:\MPS\CIV2\pedia.fre
1996-02-15 10:01 16692 --------- C:\MPS\CIV2\pedia.ger
1996-02-15 10:00 16692 --------- C:\MPS\CIV2\pedia.txt
1996-02-15 07:42 74346 --------- C:\MPS\CIV2\wonder.dll
1996-02-15 07:19 11231 --------- C:\MPS\CIV2\council1.txt
1996-02-15 07:19 10995 --------- C:\MPS\CIV2\council0.txt
1996-02-15 06:38 46452 --------- C:\MPS\CIV2\cities.gif
1996-02-15 06:00 54241 --------- C:\MPS\CIV2\icons.gif
1996-02-15 05:27 341 --------- C:\MPS\CIV2\errors.db
1996-02-15 04:35 5789 --------- C:\MPS\CIV2\labels.txt
1996-02-15 03:04 1132138 --------- C:\MPS\CIV2\ss.dll
1996-02-14 15:37 12833 --------- C:\MPS\CIV2\tutorial.txt
1996-02-14 14:46 2801 --------- C:\MPS\CIV2\credits.txt
1996-02-14 11:34 4047252 --------- C:\MPS\CIV2\cv.dll
1996-02-14 10:55 674 --------- C:\MPS\CIV2\wwii.ger
1996-02-14 10:54 1239 --------- C:\MPS\CIV2\rome.ger
1996-02-14 10:44 895 --------- C:\MPS\CIV2\mapmenu.ger
1996-02-14 07:26 11606 --------- C:\MPS\CIV2\SOUND\feedbk03.wav
1996-02-14 07:22 2574 --------- C:\MPS\CIV2\SOUND\feedbk04.wav
1996-02-14 02:52 96 --------- C:\MPS\CIV2\PEDIA\frch_a
1996-02-14 02:52 89 --------- C:\MPS\CIV2\PEDIA\frch_e
1996-02-14 02:52 86 --------- C:\MPS\CIV2\PEDIA\frch_f
1996-02-14 02:52 68 --------- C:\MPS\CIV2\PEDIA\frch_b
1996-02-14 02:52 67 --------- C:\MPS\CIV2\PEDIA\frch_s
1996-02-14 02:52 66 --------- C:\MPS\CIV2\PEDIA\frch_d
1996-02-14 02:52 63 --------- C:\MPS\CIV2\PEDIA\frch_i
1996-02-14 02:52 56 --------- C:\MPS\CIV2\PEDIA\frch_g
1996-02-14 02:52 48 --------- C:\MPS\CIV2\PEDIA\frch_r
1996-02-14 02:52 47 --------- C:\MPS\CIV2\PEDIA\frch_o
1996-02-14 02:52 4111 --------- C:\MPS\CIV2\PEDIA\frchlist
1996-02-14 02:52 27 --------- C:\MPS\CIV2\PEDIA\frch_v
1996-02-14 02:52 27 --------- C:\MPS\CIV2\PEDIA\frch_u
1996-02-14 02:52 241 --------- C:\MPS\CIV2\PEDIA\frch_c
1996-02-14 02:52 22 --------- C:\MPS\CIV2\PEDIA\frch_l
1996-02-14 02:52 17 --------- C:\MPS\CIV2\PEDIA\frch_j
1996-02-14 02:52 17 --------- C:\MPS\CIV2\PEDIA\frch_h
1996-02-14 02:52 139 --------- C:\MPS\CIV2\PEDIA\frch_p
1996-02-14 02:52 12 --------- C:\MPS\CIV2\PEDIA\frch_n
1996-02-14 02:52 111 --------- C:\MPS\CIV2\PEDIA\frch_m
1996-02-14 02:52 105 --------- C:\MPS\CIV2\PEDIA\frch_t
1996-02-14 02:51 15799 --------- C:\MPS\CIV2\PEDIA\describe.pdf
1996-02-14 01:04 9 --------- C:\MPS\CIV2\PEDIA\germ_j
1996-02-14 01:04 88 --------- C:\MPS\CIV2\PEDIA\germ_r
1996-02-14 01:04 88 --------- C:\MPS\CIV2\PEDIA\germ_b
1996-02-14 01:04 71 --------- C:\MPS\CIV2\PEDIA\germ_p
1996-02-14 01:04 67 --------- C:\MPS\CIV2\PEDIA\germ_w
1996-02-14 01:04 67 --------- C:\MPS\CIV2\PEDIA\germ_a
1996-02-14 01:04 62 --------- C:\MPS\CIV2\PEDIA\germ_g
1996-02-14 01:04 59 --------- C:\MPS\CIV2\PEDIA\germ_e
1996-02-14 01:04 57 --------- C:\MPS\CIV2\PEDIA\germ_h
1996-02-14 01:04 49 --------- C:\MPS\CIV2\PEDIA\germ_t
1996-02-14 01:04 47 --------- C:\MPS\CIV2\PEDIA\germ_l
1996-02-14 01:04 42 --------- C:\MPS\CIV2\PEDIA\germ_d
1996-02-14 01:04 3914 --------- C:\MPS\CIV2\PEDIA\germlist
1996-02-14 01:04 37 --------- C:\MPS\CIV2\PEDIA\germ_o
1996-02-14 01:04 27 --------- C:\MPS\CIV2\PEDIA\germ_u
1996-02-14 01:04 26 --------- C:\MPS\CIV2\PEDIA\germ_v
1996-02-14 01:04 22 --------- C:\MPS\CIV2\PEDIA\germ_i
1996-02-14 01:04 182 --------- C:\MPS\CIV2\PEDIA\germ_k
1996-02-14 01:04 18 --------- C:\MPS\CIV2\PEDIA\germ_z
1996-02-14 01:04 17 --------- C:\MPS\CIV2\PEDIA\germ_n
1996-02-14 01:04 157 --------- C:\MPS\CIV2\PEDIA\germ_s
1996-02-14 01:04 12 --------- C:\MPS\CIV2\PEDIA\germ_c
1996-02-14 01:04 107 --------- C:\MPS\CIV2\PEDIA\germ_f
1996-02-14 01:04 101 --------- C:\MPS\CIV2\PEDIA\germ_m
1996-02-14 00:24 22155 --------- C:\MPS\CIV2\PEDIA\concept.pdf
1996-02-13 17:15 1900690 --------- C:\MPS\CIV2\loser.avi
1996-02-13 13:51 1091689 --------- C:\MPS\CIV2\tiles.dll
1996-02-13 07:28 40158 --------- C:\MPS\CIV2\SOUND\guillotn.wav
1996-02-13 04:26 54098 --------- C:\MPS\CIV2\world.mp
1996-02-13 04:25 24098 --------- C:\MPS\CIV2\world_m.mp
1996-02-13 04:20 1921 --------- C:\MPS\CIV2\debug.fre
1996-02-13 04:20 15674 --------- C:\MPS\CIV2\tutorial.fre
1996-02-13 03:18 30646 --------- C:\MPS\CIV2\PEDIA\civjump.dll
1996-02-13 03:18 14735 --------- C:\MPS\CIV2\council2.fre
1996-02-13 02:35 2211 --------- C:\MPS\CIV2\readme.ger
1996-02-13 02:00 1179 --------- C:\MPS\CIV2\rome.txt
1996-02-12 13:49 10984 --------- C:\MPS\CIV2\council2.txt
1996-02-12 09:38 23357 --------- C:\MPS\CIV2\PEDIA\terrain.pdg
1996-02-12 09:06 866921 --------- C:\MPS\CIV2\intro.dll
1996-02-12 08:29 27169 --------- C:\MPS\CIV2\PEDIA\improv.pdg
1996-02-12 07:52 1722 --------- C:\MPS\CIV2\SOUND\movpiece.wav
1996-02-12 07:34 54098 --------- C:\MPS\CIV2\pacific.mp
1996-02-12 07:25 246004 --------- C:\MPS\CIV2\SOUND\engnsput.wav
1996-02-12 07:25 218708 --------- C:\MPS\CIV2\SOUND\jetsputr.wav
1996-02-12 07:22 79832 --------- C:\MPS\CIV2\SOUND\spysound.wav
1996-02-12 07:05 6731 --------- C:\MPS\CIV2\advice.ger
1996-02-12 05:22 1916 --------- C:\MPS\CIV2\debug.ger
1996-02-12 05:20 15468 --------- C:\MPS\CIV2\tutorial.ger
1996-02-12 03:12 881 --------- C:\MPS\CIV2\mapmenu.fre
1996-02-11 23:48 4642 --------- C:\MPS\CIV2\SOUND\neg1.wav
1996-02-11 09:19 66152 --------- C:\MPS\CIV2\city.gif
1996-02-11 02:33 52880 --------- C:\MPS\CIV2\units.gif
1996-02-10 14:05 22968 --------- C:\MPS\CIV2\PEDIA\advanc3.pdg
1996-02-10 13:06 9559 --------- C:\MPS\CIV2\PEDIA\advanc4.pdg
1996-02-10 12:18 18654 --------- C:\MPS\CIV2\PEDIA\wonder.pdg
1996-02-10 06:22 5799 --------- C:\MPS\CIV2\advice.txt
1996-02-09 06:52 1852 --------- C:\MPS\CIV2\readme.eng
1996-02-08 06:46 10918 --------- C:\MPS\CIV2\PEDIA\units2.pdg
1996-02-08 06:08 24488 --------- C:\MPS\CIV2\PEDIA\advanc3.pdf
1996-02-07 13:47 154951 --------- C:\MPS\CIV2\wwii.scn
1996-02-06 07:08 13762 --------- C:\MPS\CIV2\PEDIA\describe.pde
1996-02-06 07:00 27155 --------- C:\MPS\CIV2\PEDIA\units.pdg
1996-02-06 06:17 92258 --------- C:\MPS\CIV2\SOUND\navbttle.wav
1996-02-06 06:16 130464 --------- C:\MPS\CIV2\SOUND\cathedrl.wav
1996-02-06 06:13 61366 --------- C:\MPS\CIV2\SOUND\sell.wav
1996-02-06 03:26 19368 --------- C:\MPS\CIV2\PEDIA\concept.pdg
1996-02-06 01:30 6626 --------- C:\MPS\CIV2\city.ger
1996-02-06 01:29 6785 --------- C:\MPS\CIV2\city.txt
1996-02-06 01:29 6771 --------- C:\MPS\CIV2\city.fre
1996-02-05 09:18 8553 --------- C:\MPS\CIV2\PEDIA\govern.pdg
1996-02-05 08:39 154158 --------- C:\MPS\CIV2\SOUND\drumc0.wav
1996-02-05 08:39 101762 --------- C:\MPS\CIV2\SOUND\drumcy.wav
1996-02-05 08:37 79822 --------- C:\MPS\CIV2\SOUND\drumcn.wav
1996-02-05 08:15 28028 --------- C:\MPS\CIV2\PEDIA\advanc2.pdg
1996-02-05 07:56 125016 --------- C:\MPS\CIV2\SOUND\drumbn.wav
1996-02-05 07:55 85568 --------- C:\MPS\CIV2\SOUND\drumb0.wav
1996-02-05 07:55 84850 --------- C:\MPS\CIV2\SOUND\drumby.wav
1996-02-05 07:17 96 --------- C:\MPS\CIV2\PEDIA\pedia_p
1996-02-05 07:17 92 --------- C:\MPS\CIV2\PEDIA\pedia_a
1996-02-05 07:17 87 --------- C:\MPS\CIV2\PEDIA\pedia_f
1996-02-05 07:17 77 --------- C:\MPS\CIV2\PEDIA\pedia_r
1996-02-05 07:17 64 --------- C:\MPS\CIV2\PEDIA\pedia_t
1996-02-05 07:17 62 --------- C:\MPS\CIV2\PEDIA\pedia_g
1996-02-05 07:17 55 --------- C:\MPS\CIV2\PEDIA\pedia_e
1996-02-05 07:17 51 --------- C:\MPS\CIV2\PEDIA\pedia_w
1996-02-05 07:17 48 --------- C:\MPS\CIV2\PEDIA\pedia_d
1996-02-05 07:17 47 --------- C:\MPS\CIV2\PEDIA\pedia_l
1996-02-05 07:17 47 --------- C:\MPS\CIV2\PEDIA\pedia_h
1996-02-05 07:17 43 --------- C:\MPS\CIV2\PEDIA\pedia_b
1996-02-05 07:17 42 --------- C:\MPS\CIV2\PEDIA\pedia_i
1996-02-05 07:17 3656 --------- C:\MPS\CIV2\PEDIA\wordlist
1996-02-05 07:17 27 --------- C:\MPS\CIV2\PEDIA\pedia_o
1996-02-05 07:17 25 --------- C:\MPS\CIV2\PEDIA\pedia_n
1996-02-05 07:17 195 --------- C:\MPS\CIV2\PEDIA\pedia_c
1996-02-05 07:17 17 --------- C:\MPS\CIV2\PEDIA\pedia_u
1996-02-05 07:17 166 --------- C:\MPS\CIV2\PEDIA\pedia_s
1996-02-05 07:17 136 --------- C:\MPS\CIV2\PEDIA\pedia_m
1996-02-05 07:17 12 --------- C:\MPS\CIV2\PEDIA\pedia_k
1996-02-05 07:17 12 --------- C:\MPS\CIV2\PEDIA\pedia_j
1996-02-05 07:17 11 --------- C:\MPS\CIV2\PEDIA\pedia_v
1996-02-04 11:45 55966 --------- C:\MPS\CIV2\terrain2.gif
1996-02-03 10:04 1562730 --------- C:\MPS\CIV2\pv.dll
1996-02-03 01:18 568 --------- C:\MPS\CIV2\wwii.txt
1996-02-02 04:22 28681 --------- C:\MPS\CIV2\PEDIA\advanc1.pdg
1996-02-02 02:15 9720 --------- C:\MPS\CIV2\PEDIA\units2.pde
1996-02-02 02:14 24589 --------- C:\MPS\CIV2\PEDIA\units.pde
1996-02-02 02:12 29260 --------- C:\MPS\CIV2\PEDIA\units.pdf
1996-02-02 02:12 11624 --------- C:\MPS\CIV2\PEDIA\units2.pdf
1996-02-02 01:45 8804 --------- C:\MPS\CIV2\PEDIA\advanc4.pde
1996-02-02 01:45 10253 --------- C:\MPS\CIV2\PEDIA\advanc4.pdf
1996-02-02 01:22 11504 --------- C:\MPS\CIV2\SOUND\pos1.wav
1996-02-02 01:15 24788 --------- C:\MPS\CIV2\PEDIA\advanc2.pde
1996-02-02 01:14 25552 --------- C:\MPS\CIV2\PEDIA\advanc1.pde
1996-02-02 01:08 29507 --------- C:\MPS\CIV2\PEDIA\advanc2.pdf
1996-02-02 01:07 30001 --------- C:\MPS\CIV2\PEDIA\advanc1.pdf
1996-02-01 10:48 24098 --------- C:\MPS\CIV2\greece.mp
1996-02-01 04:22 20609 --------- C:\MPS\CIV2\PEDIA\advanc3.pde
1996-02-01 02:51 91142 --------- C:\MPS\CIV2\SOUND\druma0.wav
1996-02-01 02:51 45976 --------- C:\MPS\CIV2\SOUND\druman.wav
1996-02-01 02:51 32028 --------- C:\MPS\CIV2\SOUND\drumay.wav
1996-01-31 11:24 1733 --------- C:\MPS\CIV2\debug.txt
1996-01-31 08:58 132188 --------- C:\MPS\CIV2\SOUND\crwdbugl.wav
1996-01-31 08:52 21227 --------- C:\MPS\CIV2\people.gif
1996-01-31 05:17 74906 --------- C:\MPS\CIV2\SOUND\missile.wav
1996-01-31 05:13 23536 --------- C:\MPS\CIV2\SOUND\medgun.wav
1996-01-31 02:27 83838 --------- C:\MPS\CIV2\SOUND\largexpl.wav
1996-01-31 02:26 57004 --------- C:\MPS\CIV2\SOUND\medexpl.wav
1996-01-31 02:23 42328 --------- C:\MPS\CIV2\SOUND\smallexp.wav
1996-01-31 01:32 120596 --------- C:\MPS\CIV2\SOUND\pompcirc.wav
1996-01-30 08:19 331178 --------- C:\MPS\CIV2\SOUND\nukexplo.wav
1996-01-30 00:58 83248 --------- C:\MPS\CIV2\SOUND\swrdhors.wav
1996-01-30 00:18 71460 --------- C:\MPS\CIV2\SOUND\stkmarkt.wav
1996-01-30 00:18 115372 --------- C:\MPS\CIV2\SOUND\bldcity.wav
1996-01-29 23:54 81182 --------- C:\MPS\CIV2\SOUND\bldspcsh.wav
1996-01-29 07:47 44344 --------- C:\MPS\CIV2\SOUND\biggun.wav
1996-01-29 06:55 179702 --------- C:\MPS\CIV2\SOUND\boatsink.wav
1996-01-29 06:41 88998 --------- C:\MPS\CIV2\SOUND\cheers1.wav
1996-01-29 05:44 131498 --------- C:\MPS\CIV2\SOUND\divcrash.wav
1996-01-29 05:42 203050 --------- C:\MPS\CIV2\SOUND\divebomb.wav
1996-01-29 05:07 138144 --------- C:\MPS\CIV2\SOUND\helishot.wav
1996-01-29 03:02 8510 --------- C:\MPS\CIV2\PEDIA\govern.pdf
1996-01-29 02:34 66674 --------- C:\MPS\CIV2\SOUND\infantry.wav
1996-01-29 02:19 25486 --------- C:\MPS\CIV2\PEDIA\terrain.pdf
1996-01-29 01:58 29962 --------- C:\MPS\CIV2\PEDIA\improv.pdf
1996-01-29 01:44 19875 --------- C:\MPS\CIV2\PEDIA\wonder.pdf
1996-01-29 01:12 318450 --------- C:\MPS\CIV2\SOUND\menuloop.wav
1996-01-29 00:59 12098 --------- C:\MPS\CIV2\world_s.mp
1996-01-28 23:21 149722 --------- C:\MPS\CIV2\SOUND\jetbomb.wav
1996-01-28 23:20 141104 --------- C:\MPS\CIV2\SOUND\jetcombt.wav
1996-01-28 23:19 103246 --------- C:\MPS\CIV2\SOUND\jetcrash.wav
1996-01-26 07:16 54098 --------- C:\MPS\CIV2\europe.mp
1996-01-26 03:49 609938 --------- C:\MPS\CIV2\SOUND\menuend.wav
1996-01-26 03:47 79736 --------- C:\MPS\CIV2\SOUND\menuok.wav
1996-01-25 02:41 18411 --------- C:\MPS\CIV2\PEDIA\concept.pde
1996-01-23 23:12 131592 --------- C:\MPS\CIV2\SOUND\cavalry.wav
1996-01-23 23:04 52682 --------- C:\MPS\CIV2\SOUND\elephant.wav
1996-01-23 08:45 82036 --------- C:\MPS\CIV2\SOUND\newonder.wav
1996-01-23 08:45 81232 --------- C:\MPS\CIV2\SOUND\newgovt.wav
1996-01-22 02:32 24098 --------- C:\MPS\CIV2\mediterr.mp
1996-01-22 00:17 127588 --------- C:\MPS\CIV2\SOUND\aqueduct.wav
1996-01-22 00:14 86928 --------- C:\MPS\CIV2\SOUND\barracks.wav
1996-01-22 00:10 82724 --------- C:\MPS\CIV2\SOUND\cheers2.wav
1996-01-22 00:04 85200 --------- C:\MPS\CIV2\SOUND\civdisor.wav
1996-01-16 06:00 209226 --------- C:\MPS\CIV2\SOUND\aircombt.wav
1996-01-16 05:59 64328 --------- C:\MPS\CIV2\SOUND\catapult.wav
1996-01-16 05:58 88088 --------- C:\MPS\CIV2\SOUND\cheers3.wav
1996-01-16 05:58 129380 --------- C:\MPS\CIV2\SOUND\diesel.wav
1996-01-16 05:57 3080 --------- C:\MPS\CIV2\SOUND\endoturn.wav
1996-01-16 05:57 140290 --------- C:\MPS\CIV2\SOUND\fanfare1.wav
1996-01-16 05:56 95462 --------- C:\MPS\CIV2\SOUND\fanfare3.wav
1996-01-16 05:56 91436 --------- C:\MPS\CIV2\SOUND\fanfare8.wav
1996-01-16 05:56 87324 --------- C:\MPS\CIV2\SOUND\fanfare7.wav
1996-01-16 05:56 78426 --------- C:\MPS\CIV2\SOUND\fanfare4.wav
1996-01-16 05:56 73310 --------- C:\MPS\CIV2\SOUND\fanfare5.wav
1996-01-16 05:56 151028 --------- C:\MPS\CIV2\SOUND\fanfare6.wav
1996-01-16 05:56 126760 --------- C:\MPS\CIV2\SOUND\fanfare2.wav
1996-01-16 05:52 74172 --------- C:\MPS\CIV2\SOUND\mchnguns.wav
1996-01-16 05:51 144936 --------- C:\MPS\CIV2\SOUND\mrktplce.wav
1996-01-16 05:50 44160 --------- C:\MPS\CIV2\SOUND\newbank.wav
1996-01-16 05:49 78990 --------- C:\MPS\CIV2\SOUND\swordfgt.wav
1996-01-16 05:48 134378 --------- C:\MPS\CIV2\SOUND\torpedos.wav
1996-01-09 05:00 3080 --------- C:\MPS\CIV2\SOUND\feedbkxx.wav
1996-01-09 05:00 19880 --------- C:\MPS\CIV2\SOUND\fire---.wav
1995-12-05 05:32 7274 --------- C:\MPS\CIV2\PEDIA\govern.pde
1995-12-05 03:44 24820 --------- C:\MPS\CIV2\PEDIA\improv.pde
1995-12-05 01:24 17363 --------- C:\MPS\CIV2\PEDIA\wonder.pde
1995-12-05 01:09 21467 --------- C:\MPS\CIV2\PEDIA\terrain.pde
1995-10-16 06:04 15314 --------- C:\MPS\CIV2\timerdll.dll
1995-10-11 04:47 86294 --------- C:\MPS\CIV2\smedsnet.dll
1995-09-06 06:12 728 --------- C:\MPS\CIV2\mapmenu.txt
1995-04-04 01:51 4192 --------- C:\MPS\CIV2\cpuid16.dll
1995-01-03 09:54 100 --------- C:\MPS\CIV2\modules.db

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 04:00 15360]
"Start WingMan Profiler"="C:\Program Files\Logitech\Profiler\lwemon.exe" [2005-04-18 10:16 73728]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]
"AudioDeck"="C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe" [2007-01-26 11:34 528384]
"NVRTCLK"="C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe" [2003-12-30 01:44 24576]
"PathNvidiaTV"="C:\Program Files\Gigabyte\Nvidia\patchnvidiaTVout.exe" [ ]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 18:22 26248]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-12 00:42 185632]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-25 19:52 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-24 23:24 219136]

S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2004-10-21 06:26]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-02 05:15:02 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - User.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-09 18:49:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1????????????????????????????????????????????????
PathNvidiaTV = C:\Program Files\Gigabyte\Nvidia\patchnvidiaTVout.exe??????|E??|N??|[email protected][email protected]???D<[email protected]?????|[email protected]??x????D?|p??|???|?D?|?5?|?C?|????????????????????????????<??????????|????????Q??|????m??|???????????????|???????????|????????`???&s?|???|?s?|???Z???

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-09 18:51:58
ComboFix-quarantined-files.txt 2008-02-10 02:51:55
ComboFix2.txt 2008-02-06 00:29:22
.
2008-01-09 11:01:50 --- E O F ---
See less See more
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:54:38 PM, on 09/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\lwemon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\User\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 211.231.187.4:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [PathNvidiaTV] C:\Program Files\Gigabyte\Nvidia\patchnvidiaTVout.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1169840645468
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 8882 bytes
See less See more
Do you recognize these folders as something you created?

C:\cyc\data

I'm not able to find much on the contents but the data folder contains some images. Can you tell me more about these?
(My apologies for the delay between posts, personal issues have interfered greatly...)

The cyc folder is from a japanese game I had downloaded a while back, and since uninstalled, but for some reason those pictures remained...
OK, thanks.

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.

Please post the results from the SuperAntiSpyware and Panda scans along with a new HijackThis log.
See less See more
1 - 9 of 9 Posts
Status
Not open for further replies.
Top