Hi,
Performed the removals, updates & Scan as requested. I see you were quite right about more work to be done. Can I delete limewire & torrent from application data folders?
Following is the KOS & ComboFix logs. DDS in next post
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, September 23, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, September 23, 2009 06:01:55
Records in database: 2870749
Scan settings
scan using the following database extended
Scan archives yes
Scan e-mail databases yes
Scan area My Computer
C:\
D:\
E:\
F:\
G:\
Scan statistics
Objects scanned 79746
Threats found 3
Infected objects found 4
Suspicious objects found 0
Scan duration 01:47:40
File name Threat Threats count
C:\Documents and Settings\All Users\Application Data\Microsoft\OneCare Protection\LocalCopy\{7DAF6782-CE2C-43B9-547B-8849618E8877}-rdl114.tmp.exe Infected: Trojan.Win32.Vaklik.fvi 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP666\A0304319.exe Infected: Trojan-Spy.Win32.Zbot.aatt 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP673\A0310929.exe Infected: Trojan-Dropper.Win32.WormDrop.r 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP673\A0311995.exe Infected: Trojan-Dropper.Win32.WormDrop.r 1
Selected area has been scanned.
-----------------------
ComboFix 09-09-17.04 - Office 09/22/2009 19:46.5.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.172 [GMT -5:00]
Running from: c:\documents and settings\Office\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Office\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 090817-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Windows Live OneCare *On-access scanning disabled* (Updated) {427ADFC3-B354-4A51-BE34-A9D4218E45C4}
FW: Windows Live OneCare Firewall *disabled* {A3899D22-27E6-4A7E-AE4E-2C106646DAAB}
FILE ::
"c:\program files\LimeWireWin-full.exe"
"c:\program files\LimeWireWin.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Office\LOCALS~1\Temp\catchme.dll
c:\documents and settings\Angie\Application Data\LimeWire
c:\documents and settings\Angie\Application Data\LimeWire\410splashfree.png
c:\documents and settings\Angie\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Angie\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Angie\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Angie\Application Data\LimeWire\filters.props
c:\documents and settings\Angie\Application Data\LimeWire\gnutella.net
c:\documents and settings\Angie\Application Data\LimeWire\installation.props
c:\documents and settings\Angie\Application Data\LimeWire\library.dat
c:\documents and settings\Angie\Application Data\LimeWire\limewire.props
c:\documents and settings\Angie\Application Data\LimeWire\mojito.props
c:\documents and settings\Angie\Application Data\LimeWire\pub1.key
c:\documents and settings\Angie\Application Data\LimeWire\public.key
c:\documents and settings\Angie\Application Data\LimeWire\questions.props
c:\documents and settings\Angie\Application Data\LimeWire\responses.cache
c:\documents and settings\Angie\Application Data\LimeWire\simpp.xml
c:\documents and settings\Angie\Application Data\LimeWire\spam.dat
c:\documents and settings\Angie\Application Data\LimeWire\tables.props
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme.lwtp
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\01_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\02_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\03_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\04_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\05_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\chat.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\dir_closed.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\dir_open.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\forward_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\forward_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\kill.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\kill_on.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\lime.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\logo.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\notsearching.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\pause_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\pause_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\play_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\play_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\question.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\rewind_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\rewind_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\searching.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\splash.png
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\stop_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\stop_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\theme.txt
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\version.txt
c:\documents and settings\Angie\Application Data\LimeWire\themes\black_theme\warning.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme.lwtp
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\01_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\02_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\03_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\04_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\05_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\chat.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\dir_closed.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\dir_open.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\forward_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\forward_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\kill.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\logo.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\notsearching.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\pause_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\pause_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\play_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\play_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\question.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\rewind_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\rewind_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\search.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\searching.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\splash.png
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\stop_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\stop_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\theme.txt
c:\documents and settings\Angie\Application Data\LimeWire\themes\classic_theme\warning.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme.lwtp
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\01_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\02_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\03_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\04_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\05_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\chat.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\dir_closed.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\dir_open.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\forward_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\forward_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\kill.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\kill_on.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\lime.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\logo.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\notsearching.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\pause_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\pause_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\play_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\play_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\question.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\rewind_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\rewind_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\searching.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\splash.png
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\stop_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\stop_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\theme.txt
c:\documents and settings\Angie\Application Data\LimeWire\themes\limewire_theme\warning.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme.lwtp
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\01_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\02_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\03_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\04_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\05_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\chat.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\forward_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\forward_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\kill.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\kill_on.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\logo.png
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\name.txt
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\notsearching.png
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\pause_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\pause_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\play_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\play_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\question.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\rewind_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\rewind_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\searching.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\splash.png
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\stop_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\stop_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\theme.txt
c:\documents and settings\Angie\Application Data\LimeWire\themes\other_theme\warning.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\01_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\02_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\03_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\04_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\05_star.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\logo.png
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\notsearching.png
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\searching.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\splash.png
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Angie\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Angie\Application Data\LimeWire\ttree.cache
c:\documents and settings\Angie\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Angie\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Angie\Application Data\LimeWire\update.xml
c:\documents and settings\Angie\Application Data\LimeWire\version.key
c:\documents and settings\Angie\Application Data\LimeWire\version.xml
c:\documents and settings\Angie\Application Data\LimeWire\xml\data\audio.sxml
c:\documents and settings\Angie\Application Data\LimeWire\xml\data\delete_me
c:\documents and settings\Angie\Application Data\LimeWire\xml\data\video.sxml
c:\documents and settings\Angie\Application Data\LimeWire\xml\misc\application.gif
c:\documents and settings\Angie\Application Data\LimeWire\xml\misc\audio.gif
c:\documents and settings\Angie\Application Data\LimeWire\xml\misc\document.gif
c:\documents and settings\Angie\Application Data\LimeWire\xml\misc\image.gif
c:\documents and settings\Angie\Application Data\LimeWire\xml\misc\video.gif
c:\documents and settings\Angie\Application Data\LimeWire\xml\schemas\application.xsd
c:\documents and settings\Angie\Application Data\LimeWire\xml\schemas\audio.xsd
c:\documents and settings\Angie\Application Data\LimeWire\xml\schemas\document.xsd
c:\documents and settings\Angie\Application Data\LimeWire\xml\schemas\image.xsd
c:\documents and settings\Angie\Application Data\LimeWire\xml\schemas\video.xsd
c:\documents and settings\Angie\Application Data\uTorrent
c:\documents and settings\Office\Application Data\uTorrent
c:\documents and settings\Office\Application Data\uTorrent\Blues Clues UK-1.torrent
c:\documents and settings\Office\Application Data\uTorrent\Dead alive (aka Braindead).1.torrent
c:\documents and settings\Office\Application Data\uTorrent\Dead alive (aka Braindead).torrent
c:\documents and settings\Office\Application Data\uTorrent\dht.dat
c:\documents and settings\Office\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Office\Application Data\uTorrent\District.9.R5.LiNE.XviD-KAMERA.torrent
c:\documents and settings\Office\Application Data\uTorrent\Freddy's Nightmares - 1x19 - Missing Persons.avi.torrent
c:\documents and settings\Office\Application Data\uTorrent\resume.dat
c:\documents and settings\Office\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Office\Application Data\uTorrent\rss.dat
c:\documents and settings\Office\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Office\Application Data\uTorrent\settings.dat
c:\documents and settings\Office\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Office\Local Settings\temp\catchme.dll
c:\program files\LimeWireWin-full.exe
c:\program files\LimeWireWin.exe
.
((((((((((((((((((((((((( Files Created from 2009-08-23 to 2009-09-23 )))))))))))))))))))))))))))))))
.
2009-09-22 21:29 . 2009-09-22 21:29 -------- d-----w- c:\documents and settings\Angie\Application Data\Malwarebytes
2009-09-21 08:15 . 2009-09-21 08:15 -------- dc----w- c:\documents and settings\Office\Application Data\Malwarebytes
2009-09-21 05:10 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-21 05:10 . 2009-09-21 05:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-21 05:10 . 2009-09-21 05:10 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-21 05:10 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-15 18:24 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-09-15 18:24 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-09-15 18:24 . 2009-08-17 16:03 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-09-15 18:24 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-09-15 18:23 . 2009-08-17 16:06 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-09-15 18:23 . 2009-08-17 16:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-09-15 18:23 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-09-15 18:23 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-09-15 18:23 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-15 18:23 . 2009-09-15 18:23 -------- d-----w- c:\program files\Alwil Software
2009-09-15 08:11 . 2009-09-15 08:11 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-15 05:00 . 2009-09-15 06:58 -------- d-----w- c:\program files\COMODO
2009-09-14 00:33 . 2009-09-14 00:33 -------- d-----w- c:\program files\Trend Micro
2009-09-13 13:06 . 2009-09-13 13:06 1119618 -c--a-w- C:\OneCareSupportData.zip
2009-09-09 21:48 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-09-04 04:45 . 2009-09-04 04:45 -------- dc----w- c:\documents and settings\Office\Local Settings\Application Data\Xara
2009-09-04 04:41 . 2007-04-27 14:43 120200 ----a-w- c:\windows\system32\DLLDEV32i.dll
2009-09-04 04:39 . 2009-09-04 04:46 -------- d-----w- c:\windows\system32\MAGIX
2009-09-04 04:39 . 2008-04-15 20:14 700416 ----a-w- c:\windows\system32\mgxoschk.dll
2009-09-04 03:37 . 2009-09-04 03:37 -------- d-----w- c:\program files\3ivx
2009-09-04 03:37 . 2009-09-04 03:37 -------- dc----w- c:\documents and settings\All Users\Application Data\Flip Video
2009-09-04 03:37 . 2009-09-04 03:37 -------- d-----w- c:\program files\Flip Video
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-22 21:32 . 2005-04-18 19:51 17920 -csha-w- c:\program files\Thumbs.db
2009-09-22 12:52 . 2009-07-17 23:56 273 -c--a-w- c:\documents and settings\Office\Application Data\ftpfile.dat
2009-09-22 08:27 . 2009-07-16 14:43 -------- d-----w- c:\program files\CoffeeCup Software
2009-09-22 03:24 . 2004-12-24 06:43 2835 ----a-w- c:\program files\photohse.ini
2009-09-22 03:24 . 2004-12-24 06:43 338 ----a-w- c:\program files\country.ini
2009-09-22 03:06 . 2004-12-23 13:25 -------- d-----w- c:\program files\Custom
2009-09-22 03:06 . 2004-12-24 06:43 1323 ----a-w- c:\program files\CorelApp.ini
2009-09-22 01:34 . 2009-07-26 08:22 -------- d-----w- c:\program files\Microsoft Windows OneCare Live
2009-09-15 05:32 . 2009-07-11 11:44 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2009-09-12 22:00 . 2009-08-09 20:07 109968 -c--a-w- c:\documents and settings\Jessy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-09 11:21 . 2004-12-24 06:42 3292 -c--a-w- c:\program files\printhse.ini
2009-09-09 06:23 . 2009-07-06 21:26 -------- dc----w- c:\documents and settings\All Users\Application Data\Motive
2009-09-05 18:22 . 2006-08-06 10:50 109968 -c--a-w- c:\documents and settings\Angie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-05 09:34 . 2005-01-26 13:32 171 ----a-w- c:\program files\Color.ini
2009-09-04 05:32 . 2009-03-07 21:05 109968 -c--a-w- c:\documents and settings\Office\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-04 04:46 . 2009-09-04 04:43 -------- dc----w- c:\documents and settings\All Users\Application Data\MAGIX
2009-09-04 04:45 . 2009-09-04 04:43 -------- d-----w- c:\program files\Common Files\MAGIX Shared
2009-09-04 04:43 . 2009-09-04 04:43 -------- d-----w- c:\program files\Common Files\xara
2009-08-31 18:17 . 2009-06-06 04:44 -------- d-----w- c:\documents and settings\Angie\Application Data\gtk-2.0
2009-08-21 18:12 . 2009-07-12 20:06 -------- d-----w- c:\documents and settings\Angie\Application Data\dvdcss
2009-08-11 22:33 . 2009-08-11 22:33 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-08-11 02:59 . 2009-07-09 09:31 -------- d-----w- c:\program files\Veoh Networks
2009-08-08 04:15 . 2005-04-01 23:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-07 07:05 . 2009-08-07 07:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-06 23:50 . 2009-08-01 22:40 -------- d-----w- c:\program files\NCH Software
2009-08-06 23:47 . 2009-08-01 22:40 -------- d-----w- c:\program files\NCH Swift Sound
2009-08-06 23:46 . 2009-08-06 23:46 -------- dc----w- c:\documents and settings\Office\Application Data\NCH Swift Sound
2009-08-05 09:01 . 2004-08-04 11:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 05:04 . 2009-04-29 02:04 -------- dc----w- c:\documents and settings\Office\Application Data\gtk-2.0
2009-08-02 12:09 . 2009-08-02 12:09 -------- d-----w- c:\program files\MSBuild
2009-08-02 12:09 . 2009-08-02 12:09 -------- d-----w- c:\program files\Reference Assemblies
2009-08-01 22:42 . 2009-08-01 22:42 -------- dc----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-08-01 22:41 . 2009-08-01 22:40 -------- d-----w- c:\documents and settings\Angie\Application Data\NCH Swift Sound
2009-08-01 17:19 . 2009-08-01 17:19 -------- d-----w- c:\documents and settings\LocalService\Application Data\PeerNetworking
2009-07-26 09:43 . 2006-05-24 01:32 -------- d-----w- c:\program files\Yahoo!
2009-07-26 09:24 . 2004-12-12 06:39 -------- d-----w- c:\program files\Java
2009-07-26 09:19 . 2005-01-13 23:11 -------- d-----w- c:\program files\DivX
2009-07-26 06:10 . 2009-07-09 08:53 -------- dc----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-25 20:27 . 2009-07-25 08:36 -------- d-----w- c:\program files\Windows Live Safety Center
2009-07-17 19:01 . 2004-08-04 11:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 12:04 . 2009-07-17 12:04 335 ----a-w- c:\windows\mozregistry.dat
2009-07-13 15:08 . 2004-08-04 11:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2004-08-04 11:00 915456 ------w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-04 11:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 11:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 11:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 11:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 11:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 11:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-17 03:47 . 2005-05-02 16:09 100261 -c-ha-w- c:\program files\photohse.GID
2009-05-14 21:54 . 2006-03-02 16:25 69477 -c-ha-w- c:\program files\aim95.GID
2009-03-05 09:35 . 2007-03-13 00:45 8444 -c--a-w- c:\program files\Xpcs Registry.dat
2009-02-09 23:57 . 2003-12-10 05:39 178 -c--a-w- c:\program files\log.txt
2008-10-30 17:39 . 2004-12-24 06:43 2449 -c--a-w- c:\program files\corelprn.ini
2005-05-26 13:32 . 2005-04-06 14:51 38435 -c--a-w- c:\program files\licens32.txt
2005-05-21 02:00 . 2005-05-21 01:58 148564 -c-ha-w- c:\program files\Printhse.GID
2005-04-08 13:07 . 2005-04-06 14:51 611 ----a-w- c:\program files\Uninstall AOL Instant Messenger.lnk
2004-12-24 06:44 . 2004-12-24 06:42 713 -c----w- c:\program files\BOX.REG
2004-12-24 06:44 . 2004-12-24 06:43 2860 -c----w- c:\program files\PHOTOHSE.REG
2004-12-24 06:44 . 2004-12-24 06:42 832 -c----w- c:\program files\PRINTHSE.REG
2004-08-27 23:29 . 2005-04-06 14:51 1935 -c--a-w- c:\program files\icbmftvc.lst
2004-03-12 21:02 . 2005-04-06 14:51 116900 ----a-w- c:\program files\uninstll.exe
2004-03-12 21:02 . 2005-04-06 14:51 1466368 ----a-w- c:\program files\AimRes.dll
2004-03-12 20:22 . 2005-04-06 14:51 61440 ----a-w- c:\program files\aim.exe
2004-03-12 20:22 . 2005-04-06 14:51 131072 ----a-w- c:\program files\ateima32.dll
2004-03-12 20:21 . 2005-04-06 14:51 61440 -c--a-w- c:\program files\AlertUI.ocm
2004-03-12 20:21 . 2005-04-06 14:51 25088 -c--a-w- c:\program files\browse.ocm
2004-03-12 20:21 . 2005-04-06 14:51 208896 -c--a-w- c:\program files\buddyui.ocm
2004-03-12 20:21 . 2005-04-06 14:51 225280 ----a-w- c:\program files\AimSecondarySvcs.dll
2004-03-12 20:21 . 2005-04-06 14:51 6144 -c--a-w- c:\program files\stats.ocm
2004-03-12 20:21 . 2005-04-06 14:51 98304 -c--a-w- c:\program files\ChatUI.ocm
2004-03-12 20:20 . 2005-04-06 14:51 192512 ----a-w- c:\program files\AimCoreSvcs.dll
2004-03-12 20:20 . 2005-04-06 14:51 237568 -c--a-w- c:\program files\icbmui.ocm
2004-03-12 20:20 . 2005-04-06 14:51 94208 -c--a-w- c:\program files\ticker.ocm
2004-03-12 20:19 . 2005-04-06 14:51 98304 ----a-w- c:\program files\aimapi.dll
2004-03-12 20:19 . 2005-04-06 14:51 15872 -c--a-w- c:\program files\Admin.ocm
2004-03-12 20:19 . 2005-04-06 14:51 135168 -c--a-w- c:\program files\locateui.ocm
2004-03-12 20:19 . 2005-04-06 14:51 184320 -c--a-w- c:\program files\miscui.ocm
2004-03-12 20:19 . 2005-04-06 14:51 14848 -c--a-w- c:\program files\NTP.ocm
2004-03-12 20:18 . 2005-04-06 14:51 59904 -c--a-w- c:\program files\OscMail.ocm
2004-03-12 20:18 . 2005-04-06 14:51 19456 ----a-w- c:\program files\aimtalk.dll
2004-03-12 20:18 . 2005-04-06 14:51 69632 -c--a-w- c:\program files\osclogin.ocm
2004-03-12 20:18 . 2005-04-06 14:51 9216 -c--a-w- c:\program files\oscmain.ocm
2004-03-12 20:18 . 2005-04-06 14:51 53248 -c--a-w- c:\program files\startup.ocm
2004-03-12 20:18 . 2005-04-06 14:51 147456 ----a-w- c:\program files\aimauto.exe
2004-03-12 20:17 . 2005-04-06 14:51 81920 -c--a-w- c:\program files\OscSrch.ocm
2004-03-12 20:17 . 2005-04-06 14:51 2048 ----a-w- c:\program files\ShareFile.exe
2004-03-12 20:17 . 2005-04-06 14:51 2048 ----a-w- c:\program files\SendFile.exe
2004-03-12 20:17 . 2005-04-06 14:51 13824 -c--a-w- c:\program files\osconfig.ocm
2004-03-12 20:17 . 2005-04-06 14:51 39424 -c--a-w- c:\program files\rvapps.ocm
2004-03-12 20:17 . 2005-04-06 14:51 13312 -c--a-w- c:\program files\popup.ocm
2004-03-12 20:17 . 2005-04-06 14:51 69632 ----a-w- c:\program files\Patcher.dll
2004-03-12 20:17 . 2005-04-06 14:51 172032 ----a-w- c:\program files\rtvideo.dll
2004-03-12 20:16 . 2005-04-06 14:51 49152 ----a-w- c:\program files\ProgressDlg.dll
2004-03-12 20:16 . 2005-04-06 14:51 204800 ----a-w- c:\program files\wndutils.dll
2004-03-12 20:16 . 2005-04-06 14:51 221184 ----a-w- c:\program files\inetsocket.dll
2004-03-12 20:15 . 2005-04-06 14:51 33792 -c--a-w- c:\program files\proto.ocm
2004-03-12 20:15 . 2005-04-06 14:51 147456 ----a-w- c:\program files\oscarui.dll
2004-03-12 20:14 . 2005-04-06 14:51 184320 ----a-w- c:\program files\oscore.dll
2004-03-12 20:14 . 2005-04-06 14:51 188416 ----a-w- c:\program files\ate32.dll
2002-08-01 00:55 . 2009-07-16 14:44 106 --sh--w- c:\windows\WSYS049.SYS
.
((((((((((((((((((((((((((((( SnapShot@2009-09-19_09.55.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-22 21:27 . 2009-09-22 21:27 16384 c:\windows\Temp\Perflib_Perfdata_744.dat
+ 2009-09-22 21:26 . 2009-09-22 21:26 16384 c:\windows\Temp\Perflib_Perfdata_6a4.dat
+ 2009-09-22 21:28 . 2009-09-22 21:28 16384 c:\windows\Temp\Perflib_Perfdata_3e4.dat
+ 2004-08-04 11:00 . 2004-08-04 11:00 14336 c:\windows\SYSTEM32\svchost.exe
+ 2004-08-04 11:00 . 2004-08-04 11:00 14336 c:\windows\SYSTEM32\DLLCACHE\svchost.exe
+ 2007-07-31 07:25 . 2007-07-31 07:25 142696 c:\windows\SYSTEM32\MicrosoftUpdateCatalogWebControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HughesNetTools_McciTrayApp"="c:\program files\HughesNetTools\1\McciTrayApp_SSR.exe" [2007-11-20 1454592]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2009-07-09 65240]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Picture Package Menu.lnk.disabled [2009-8-11 964]
Picture Package VCD Maker.lnk.disabled [2009-8-11 1015]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=c:\windows\pss\Picture Package VCD Maker.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"=
"c:\\Program Files\\aim.exe"=
"c:\\Program Files\\Real\\RealPlayer\\trueplay.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CoffeeCup Software\\CoffeeCup Visual Site Designer\\vsd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
"AllowInboundEchoRequest"= 1 (0x1)
R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [9/15/2009 1:23 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [9/15/2009 1:23 PM 20560]
R2 FlipShare Service;FlipShare Service;c:\program files\Flip Video\FlipShare\FlipShareService.exe [6/4/2009 5:41 PM 451904]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 6:00 AM 14336]
R2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [7/9/2009 12:15 PM 26104]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;g:\programs\Common\Database\bin\fbserver.exe [9/3/2009 11:44 PM 1527900]
S3 samhid;samhid;c:\windows\SYSTEM32\DRIVERS\Samhid.sys [12/25/2006 1:41 PM 7548]
S3 SDVPlus;Pinnacle Studio DVplus WDM Renderer;c:\windows\SYSTEM32\DRIVERS\SDVPlus.sys [3/14/2006 1:15 AM 42102]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-09-23 c:\windows\Tasks\User_Feed_Synchronization-{BABCC35D-64AE-4BD7-9952-16FE21501C3D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
Trusted Zone: musicmatch.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {CAEAFE12-7726-4C39-B620-2601216CFBB5} - hxxp://phughescw.hughes.motive.com/wizlet/spaceway/static/controls/Mcci_6-1-0.cab
FF - ProfilePath - c:\documents and settings\Office\Application Data\Mozilla\Firefox\Profiles\wpzoq6gr.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\nphssb.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-HijackThis - c:\documents and settings\John.HOME\Desktop\HijackThis.exe
AddRemove-uTorrent - c:\program files\uTorrent\uTorrent.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-22 19:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,7b,1e,4b,ac,24,
e1,ec,1c,2e,e8,e1,00,eb,16,2b,de,db,e8,ba,44,63,bf,ce,72,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,9d,66,59,76,69,
bf,ac,5a,46,47,15,b0,92,4b,c7,ef,3f,f1,c8,66,f8,84,06,49,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,00,50,1b,1c,cf,
c4,a6,06,7a,45,05,fd,91,e8,6f,31,04,54,e4,0d,6b,27,29,df,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,58,bf,f5,07,cb,
52,00,4f,6b,65,49,6a,7e,99,74,f7,f9,cf,61,ea,f1,72,cb,fa,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,67,d6,88,b8,9d,
38,aa,7f,e9,02,6c,fa,fb,1d,47,57,4d,0d,2a,85,62,38,64,f9,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,00,82,de,ec,3f,
0a,cc,fb,50,93,e5,ab,ec,6a,4e,ab,e0,97,50,c9,64,28,64,ba,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,07,78,44,eb,71,
24,be,e1,97,20,4e,9a,c7,f1,35,ee,d0,b1,34,3f,28,c4,69,07,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,6a,f2,d9,dc,ab,
e5,28,4c,aa,52,c6,00,84,3c,26,64,c8,aa,47,9e,c1,4e,91,48,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c2,24,5b,7d,92,
55,c3,dc,b2,46,9a,e2,1b,fe,1b,94,9a,f1,00,87,60,47,17,41,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:37,a4,aa,c3,a6,15,56,0a,d3,c1,88,36,87,
d6,a5,23,37,a4,aa,c3,a6,15,56,0a,f4,f2,95,01,81,b9,ce,71,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,eb,85,49,eb,1e,
f2,7b,fd,f8,31,0f,a9,5f,a0,ec,fb,d4,5a,c5,ee,5f,3a,cc,ee,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,cf,43,f6,74,c5,
5a,7d,8f,05,73,21,dd,54,d8,4a,c5,21,8e,7a,9a,25,96,11,4f,6c,43,2d,1e,aa,22,\
.
Completion time: 2009-09-23 20:02
ComboFix-quarantined-files.txt 2009-09-23 01:02
ComboFix2.txt 2009-09-21 02:45
ComboFix3.txt 2009-09-20 09:33
ComboFix4.txt 2009-09-19 10:37
ComboFix5.txt 2009-09-23 00:44
Pre-Run: 23,343,304,704 bytes free
Post-Run: 23,465,140,224 bytes free
525 --- E O F --- 2009-09-10 08:45