OK something called
yapiniti.dll is bugging my SpyCatcher
its a thing that keeps popping up if I turn off spycatcher
I know its already stopped
but the spycatcher is slowing down my CPU when its stopping it
it opens every second
Spy catcher directed me to C:/Windows/System32/yapiniti.dll
but when I checked the file wasnt there I tried deleting it with a CMD window I tried opening it with CMD and it worked I dont know but its like a ghost malware I know little about these things so help!
Ne wayz here are my logs and stuff
DDS (Ver_09-02-01.01) - FAT32x86
Run by Joshua at 20:33:42.26 on 02/03/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Home Edition 5.1.2600.2.1252.2.1033.18.768.226 [GMT -8:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Memeo\AutoBackup\MemeoService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
"C:\WINDOWS\system32\svchost.exe"
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Dell AIO 810\dlcgmon.exe
C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\libusbd-nt.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\WebUpdateSvc4.exe
C:\WINDOWS\system32\taskmagr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Joshua\Desktop\dds.scr
C:\Program Files\iTunes\iTunes.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://home.ez-tracks.com/
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCxdm860MFCA&fl=0&ptb=OyeO7ohJ.SI6f7ydDBuGDg&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.defaulthomepage.info
mStart Page = hxxp://home.ez-tracks.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: H - No File
BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\program files\flashget\jccatch.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {53934df1-8469-4b78-bb3e-9c757e07de20} - c:\windows\system32\pihemova.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {b43c0f8d-92ca-155b-dda4-f8491db567d6}: {6d765bd1-948f-4add-b551-ac29d8f0c34b} - c:\windows\system32\xxiepd.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Skype Control Class: {9018f6a8-2495-45df-9f16-c738f8f3c8ff} - c:\windows\system32\SkypeComm.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Megaupload Toolbar: {a057a204-bacc-4d26-c39e-35f1d2a32ec8} - c:\progra~1\megaup~2\MEGAUP~1.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Little Fighter 2 Toolbar Helper: {ae90c38c-97cf-4696-b290-c7973dc9675e} - c:\program files\little fighter 2 toolbar\v3.3.0.1\Little_Fighter_2_Toolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: IeMonitorBho Class: {bf00e119-21a3-4fd1-b178-3b8537e75c92} - c:\program files\megaupload\mega manager\MegaIEMn.dll
BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\program files\flashget\getflash.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 8\SnagItIEAddin.dll
TB: McAfee SiteAdvisor: {0bf43445-2f28-4351-9252-17fe6e806aa0} - c:\program files\siteadvisor\6253\SiteAdv.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: Megaupload Toolbar: {a057a204-bacc-4d26-c39e-35f1d2a32ec8} - c:\progra~1\megaup~2\MEGAUP~1.DLL
TB: Little Fighter 2 Toolbar: {c3cd744d-2fae-4640-8297-16b5da423104} - c:\program files\little fighter 2 toolbar\v3.3.0.1\Little_Fighter_2_Toolbar.dll
TB: {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - No File
TB: {74CC49F7-EB32-4A08-B204-948962A6E3DB} - No File
TB: {07AA283A-43D7-4CBE-A064-32A21112D94D} - No File
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - c:\windows\system32\BROWSEUI.DLL
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot
uRun: [322b12a7] rundll32.exe "c:\windows\system32\zajeyema.dll",b
uRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SystemTray] SysTray.Exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe
mRun: [dlcgmon.exe] "c:\program files\dell aio 810\dlcgmon.exe"
mRun: [ClientGW]
mRun: [DLCGCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCGtime.dll,_RunDLLEntry@16
mRun: [SpyCatcher Reminder] c:\program files\spycatcher\SpyCatcher.exe reminder
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [StxTrayMenu] "c:\program files\seagate\systemtray\StxMenuMgr.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_03\bin\jusched.exe"
mRun: [Flashget] c:\program files\flashget\FlashGet.exe /min
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [yujilibobe] Rundll32.exe "c:\windows\system32\fihijazo.dll",s
mRun: [322b12a7] rundll32.exe "c:\windows\system32\zajeyema.dll",b
mRun: [CPM3118213b] Rundll32.exe "c:\windows\system32\dogejuhu.dll",a
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\joshua\startm~1\programs\startup\schedu~1.lnk - c:\program files\spycatcher\Scheduler daemon.exe
StartupFolder: c:\documents and settings\joshua\start menu\programs\startup\DesktopComic.exe
StartupFolder: c:\docume~1\joshua\startm~1\programs\startup\autoba~1.lnk - c:\program files\memeo\autobackup\MemeoLauncher.exe
StartupFolder: c:\docume~1\joshua\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office12\GROOVE.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\spycat~1.lnk - c:\program files\spycatcher\Protector.exe
uPolicies-explorer: EditLevel = 0 (0x0)
uPolicies-system: NoDispAppearancePage = 0 (0x0)
dPolicies-explorer: EditLevel = 0 (0x0)
dPolicies-system: NoDispAppearancePage = 0 (0x0)
IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm
IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm
IE: &Search -
http://edits.mywebsearch.com/toolbar...p=ZCxdm860MFCA
IE: &Winamp Toolbar Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download Link Using Mega Manager... - c:\program files\megaupload\mega manager\mm_file.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\system\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: Win32 Classes
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {17D667BA-5675-4AAB-9221-08B9379384D4} - hxxp://cdnimg.piczo.com/images/uploader/piczo_fast_uploader.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {5876CAD0-1636-42EA-AC50-4C06F3196089} - hxxp://down.hangame.com/dist/activex/HanGamePlugin19.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - c:\program files\siteadvisor\6253\SiteAdv.dll
Notify: Fly - smart.dll
AppInit_DLLs: secuload.dll,c:\progra~1\google\google~3\goec62~1.dll,c:\windows\system32\rlai.dll,c:\windows\system32\rlai.dll,c:\progra~1\google\google~1\goec62~1.dll,c:\windows\system32\yapiniti.dll,c:\windows\system32\dogejuhu.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\dogejuhu.dll
STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\dogejuhu.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli c:\windows\system32\yapiniti.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\joshua\applic~1\mozilla\firefox\profiles\sv0ouu29.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.google.ca
FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - component: c:\documents and settings\joshua\application data\mozilla\firefox\profiles\sv0ouu29.default\extensions\{81bf1d23-5f17-408d-ac6b-bd6df7caf670}\components\XpcomOpusConnector.dll
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\real\realplayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\progra~1\mozill~1\plugins\np_gp.dll
FF - plugin: c:\program files\google\google updater\2.4.1508.6312\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
user_pref(network.proxy.http_port,);
FF - user.js: network.proxy.no_proxies_on -
============= SERVICES / DRIVERS ===============
R0 FILELOCK;FILELOCK;c:\windows\system32\drivers\FLockXP.sys [2007-7-20 25930]
R0 pxark;pxark;c:\windows\system32\drivers\pxark.sys [2009-3-2 25784]
R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [2007-8-23 33824]
R2 CSIScanner;CSIScanner;c:\program files\prevxcsi\prevxcsi.exe [2009-3-2 878648]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R2 WebUpdate4;Web Update Wizard Service V4;c:\windows\system32\WebUpdateSvc4.exe [2007-10-15 237784]
R3 Envy24HFS;ICE Envy24 Family Audio Controller WDM V1.01 (Envy24HT-S Eval. Only);c:\windows\system32\drivers\Envy24HF.sys [2006-9-2 561144]
R3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\drivers\libusb0.sys [2008-1-16 29184]
S2 gupdate1c99a0511ff297e;Google Update Service (gupdate1c99a0511ff297e);c:\program files\google\update\GoogleUpdate.exe [2009-2-28 133104]
S3 CEDRIVER53;CEDRIVER53;c:\program files\cheat engine\dbk32.sys [2008-10-13 35840]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-1-6 33752]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-11-2 30192]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2008-3-17 40832]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
S3 XDva032;XDva032;\??\c:\windows\system32\xdva032.sys --> c:\windows\system32\XDva032.sys [?]
=============== Created Last 30 ================
2009-03-02 18:50 <DIR> --d-h--- c:\docume~1\alluse~1\applic~1\~0
2009-03-02 18:50 <DIR> --d----- c:\program files\Lavasoft
2009-03-02 17:10 25,784 a------- c:\windows\system32\drivers\pxark.sys
2009-03-02 17:10 <DIR> --d----- c:\program files\PrevxCSI
2009-03-02 17:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PrevxCSI
2009-03-02 16:35 <DIR> --d----- c:\docume~1\joshua\applic~1\PE Explorer
2009-03-02 16:35 <DIR> --d----- c:\program files\PE Explorer
2009-03-01 22:57 1,694,220 ---sh--- c:\windows\system32\ameyejaz.ini
2009-03-01 22:57 144,896 a--sh--- c:\windows\system32\zhhpss.dll
2009-03-01 22:57 110,080 a--sh--- c:\windows\system32\dogejuhu.dll
2009-03-01 22:56 144,896 a--sh--- c:\windows\system32\fidetiga.dll
2009-03-01 22:56 103,936 a--sh--- c:\windows\system32\zajeyema.dll
2009-03-01 10:57 1,694,220 ---sh--- c:\windows\system32\ugifufak.ini
2009-03-01 10:57 143,360 a--sh--- c:\windows\system32\iatmbw.dll
2009-03-01 10:57 143,360 a--sh--- c:\windows\system32\nejopoyi.dll
2009-03-01 10:57 110,080 a--sh--- c:\windows\system32\wadejino.dll
2009-03-01 09:46 87,608 a------- c:\docume~1\joshua\applic~1\inst.exe
2009-03-01 09:46 47,360 a------- c:\windows\system32\drivers\pcouffin.sys
2009-03-01 09:46 47,360 a------- c:\docume~1\joshua\applic~1\pcouffin.sys
2009-03-01 09:46 102,439 a------- c:\windows\system32\sipr3260.dll
2009-03-01 09:46 217,127 a------- c:\windows\system32\drv43260.dll
2009-03-01 09:46 208,935 a------- c:\windows\system32\drv33260.dll
2009-03-01 09:46 176,165 a------- c:\windows\system32\drv23260.dll
2009-03-01 09:46 65,602 a------- c:\windows\system32\cook3260.dll
2009-03-01 09:46 1,184,984 a------- c:\windows\system32\wvc1dmod.dll
2009-03-01 09:46 626,688 a------- c:\windows\system32\vp7vfw.dll
2009-03-01 09:45 <DIR> --d----- c:\program files\VSO
2009-02-28 22:57 1,694,207 ---sh--- c:\windows\system32\uyadehil.ini
2009-02-28 22:57 143,360 a--sh--- c:\windows\system32\xxiepd.dll
2009-02-28 22:57 109,568 a--sh--- c:\windows\system32\munovolu.dll
2009-02-28 22:56 103,936 -------- c:\windows\system32\lihedayu.dll
2009-02-28 22:56 143,360 a--sh--- c:\windows\system32\rakubuse.dll
2009-02-28 22:51 70,656 a--sh--- c:\windows\system32\yapiniti.dll
2009-02-28 22:51 70,656 a--sh--- c:\windows\system32\pihemova.dll
2009-02-28 22:51 70,656 a--sh--- c:\windows\system32\fihijazo.dll
2009-02-28 22:51 6,456 a---h--- c:\windows\system32\fulesemu
2009-02-28 18:38 <DIR> --d----- c:\program files\common files\xing shared
2009-02-28 18:37 348,160 a------- c:\windows\system32\pnup0.dll
2009-02-28 16:10 <DIR> --d----- c:\program files\Little Fighter 2.5 - v2.0
2009-02-24 17:11 <DIR> --d----- c:\program files\BrineSoft
2009-02-23 17:29 232,846 a------- c:\windows\Little_Fighter_2_Toolbar_Uninstaller_5890.exe
2009-02-23 17:29 <DIR> --d----- c:\program files\Little Fighter 2 Toolbar
2009-02-23 17:28 <DIR> --d----- c:\program files\LittleFighter2
2009-02-21 08:11 <DIR> --d----- c:\program files\Bots
2009-02-20 22:28 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PMB Files
2009-02-17 23:17 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Megaupload
2009-02-17 23:17 <DIR> --d----- c:\docume~1\joshua\applic~1\EmailNotifier
2009-02-13 23:07 <DIR> --d----- c:\program files\Pando Networks
2009-02-09 09:47 <DIR> --d----- c:\program files\Password Recovery for MSN
2009-02-09 05:40 <DIR> --d----- c:\program files\DemonicSoftware
==================== Find3M ====================
2009-03-02 19:30 25,930 a------- c:\windows\system32\drivers\FLockXP.sys
2009-03-02 15:37 98,304 a------- c:\windows\DUMP596a.tmp
2009-02-22 17:16 15,124 a------- c:\docume~1\joshua\applic~1\wklnhst.dat
2009-02-21 11:02 82,856 a------- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-01-16 21:35 3,594,752 a------- c:\windows\system32\dllcache\mshtml.dll
2008-12-19 01:10 70,656 a------- c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 01:10 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-12-18 21:25 634,024 a------- c:\windows\system32\dllcache\iexplore.exe
2008-12-18 21:23 161,792 a------- c:\windows\system32\dllcache\ieakui.dll
2008-12-11 03:57 333,184 a------- c:\windows\system32\dllcache\srv.sys
2008-09-29 09:50 0 a------- c:\documents and settings\joshua\jagex_runescape_preferences.dat
2008-04-03 18:09 61,800 a------- c:\docume~1\joshua\applic~1\GDIPFONTCACHEV1.DAT
2008-01-01 17:17 2,379,862 a------- c:\program files\No_limit_Winmugen_patch.zip
2006-09-02 10:29 271 ---sh--- c:\program files\desktop.ini
2004-08-04 12:00 94,784 ---sh--- c:\windows\twain.dll
2004-08-04 12:00 50,688 ---sh--- c:\windows\twain_32.dll
2008-03-25 18:29 848 a--sh--- c:\windows\system32\KGyGaAvL.sys
2008-03-25 18:29 56 ---shr-- c:\windows\system32\1B63C507BD.sys
2008-07-09 09:46 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008070920080710\index.dat
2004-08-04 12:00 60,416 a--sh--- c:\windows\bricopacks\sysfiles\80_msimn.exe
============= FINISH: 20:42:51.53 ===============
more info:
if I shut down SpyCatcher it spams my internet with virus infected ads