alright i've uninstalled azureus, but there wasn't an entry for "antivirus pro 2010",
all visible signs of "antivirus pro 2010" are now gone.
i've tried to update adobe reader using the link you provided but that web page freezes everytime it loads and i get a message saying that it's not responding. i'm having a similar problem with the adobe flash page.
i have uninstalled all the old java versions and updates.
ATF cleaner has been downloaded and used.
ESET has detected 16 threats,please find all requested logs below:
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=6
# IEXPLORE.EXE=7.00.6000.16735 (vista_gdr.080820-1506)
# OnlineScanner.ocx=1.0.0.6050
# api_version=3.0.2
# EOSSerial=f91e63644d723d47a44074727b60255c
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2009-10-13 07:36:07
# local_time=2009-10-13 04:36:07 (+0900, Tokyo Standard Time)
# country="United States"
# lang=9
# osver=5.1.2600 NT Service Pack 2
# scanned=75020
# found=16
# cleaned=0
# scan_time=1684
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudXPAntivirus2.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudXPAntivirus3.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I
C:\Documents and Settings\Owner\a a variant of Win32/Kryptik.ASB trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Application Data\lizkavd.exe.vir Win32/Adware.Antivirus2010 application 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Documents and Settings\Owner\Application Data\seres.exe.vir a variant of Win32/Kryptik.ASB trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\Program Files\AntivirusPro_2010\AntivirusPro_2010.exe.vir Win32/Adware.Antivirus2010 application 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\_scui.cpl.vir a variant of Win32/Kryptik.ASB trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B435B95B-0754-4910-BE3C-A3A9924D188C}\RP459\A0082789.exe a variant of Win32/Kryptik.ASB trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B435B95B-0754-4910-BE3C-A3A9924D188C}\RP459\A0082795.exe a variant of Win32/Kryptik.ASB trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B435B95B-0754-4910-BE3C-A3A9924D188C}\RP459\A0082800.exe a variant of Win32/Kryptik.ASB trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B435B95B-0754-4910-BE3C-A3A9924D188C}\RP459\A0082801.exe Win32/Adware.Antivirus2010 application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B435B95B-0754-4910-BE3C-A3A9924D188C}\RP459\A0082804.exe Win32/Adware.Antivirus2010 application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B435B95B-0754-4910-BE3C-A3A9924D188C}\RP462\A0083090.exe Win32/Adware.Antivirus2010 application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B435B95B-0754-4910-BE3C-A3A9924D188C}\RP462\A0083092.exe a variant of Win32/Kryptik.ASB trojan 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B435B95B-0754-4910-BE3C-A3A9924D188C}\RP462\A0083106.exe Win32/Adware.Antivirus2010 application 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B435B95B-0754-4910-BE3C-A3A9924D188C}\RP462\A0083120.cpl a variant of Win32/Kryptik.ASB trojan 00000000000000000000000000000000 I
DDS (Ver_09-09-29.01) - NTFSx86
Run by Owner at 16:43:46.01 on 10/13/2009 Tue
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Home Edition 5.1.2600.2.932.81.1033.18.2047.1556 [GMT 9:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\conime.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.battrick.org/nl/main.htm
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [MemoryCardManager] c:\program files\lexmark\lexmark precision photo\MemCard.exe -startup
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [LXBSCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXBStime.dll,_RunDLLEntry@16
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\gamesp~1.lnk - c:\program files\gamespot\GameSpotDownloadManager_Win32.exe
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - hxxp://launch.gamespyarcade.com/software/launch/alaunch.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8EB4A251-D29C-4F3F-85DE-1C0BB71F0305} - hxxp://www.drm-x.com/download/p2pclient.cab
DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} - hxxp://www.ooxtv.com/livetv.ocx
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game03.zylom.com/activex/zylomgamesplayer.cab
DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} - hxxp://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\s294k6ld.default\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-10-3 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1028432]
R3 MOTOMI;YAMAHA Virtual MIDI Device;c:\windows\system32\drivers\YVMIDI.SYS [2007-8-16 7040]
S3 sssdbus;SAMSUNG WMC Composite Device driver (WDM);c:\windows\system32\drivers\sssdbus.sys [2007-8-16 66672]
S3 sssdmdfl;SAMSUNG Modem Filter;c:\windows\system32\drivers\sssdmdfl.sys [2007-8-16 9232]
S3 sssdmdm;SAMSUNG Modem Driver;c:\windows\system32\drivers\sssdmdm.sys [2007-8-16 100304]
S3 sssdmgmt;SAMSUNG AT command Port Drivers (WDM);c:\windows\system32\drivers\sssdmgmt.sys [2007-8-16 91744]
S3 sssdobex;SAMSUNG OBEX Port Drivers (WDM);c:\windows\system32\drivers\sssdobex.sys [2007-8-16 89584]
=============== Created Last 30 ================
2009-10-13 16:05 <DIR> --d----- c:\program files\ESET
2009-10-13 03:40 <DIR> --d----- C:\ComboFix
2009-10-13 01:48 236,544 a------- c:\windows\PEV.exe
2009-10-13 01:48 161,792 a------- c:\windows\SWREG.exe
2009-10-13 01:48 98,816 a------- c:\windows\sed.exe
2009-10-03 16:24 15,688 a------- c:\windows\system32\lsdelete.exe
2009-10-03 16:13 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-10-03 16:11 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-27 17:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\TVU Networks
2009-09-23 15:40 43,520 a------- c:\windows\system32\CmdLineExt03.dll
==================== Find3M ====================
2009-10-09 05:39 139,152 a------- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-09 05:38 111,928 a------- c:\windows\system32\PnkBstrB.exe
2009-08-14 21:28 98,304 a------- c:\windows\system32\CmdLineExt.dll
2009-07-25 05:23 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-23 21:43 106,496 a------- c:\windows\DUMP6716.tmp
2009-07-23 21:16 106,496 a------- c:\windows\DUMP5e3d.tmp
2009-07-23 21:14 106,496 a------- c:\windows\DUMP5e6b.tmp
2009-07-23 21:12 106,496 a------- c:\windows\DUMP63f9.tmp
2008-04-02 00:35 22,328 a------- c:\docume~1\owner\applic~1\PnkBstrK.sys
2008-11-06 01:05 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008110620081107\index.dat
============= FINISH: 16:44:12.50 ===============
ComboFix 09-10-11.03 - Owner 3/2009 Tue 3:40.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.932.81.1033.18.2047.1569 [GMT 9:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
FILE ::
"c:\documents and settings\Owner\Application Data\amuzimo.dat"
"c:\program files\Common Files\yzynebi.db"
"c:\windows\atifyfufub.db"
"c:\windows\dotimubupe.dat"
"c:\windows\luqilig.lib"
"c:\windows\system32\hajogofiv.com"
"c:\windows\system32\upapozarih.com"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Azureus
c:\documents and settings\All Users\Application Data\Azureus\azCID.txt
c:\documents and settings\Owner\Application Data\amuzimo.dat
c:\documents and settings\Owner\Application Data\Azureus
c:\documents and settings\Owner\Application Data\Azureus\.certs
c:\documents and settings\Owner\Application Data\Azureus\.keystore
c:\documents and settings\Owner\Application Data\Azureus\.lock
c:\documents and settings\Owner\Application Data\Azureus\active\0416D5CE2AD12740A689D4F5FE6C0BBA67821CED.dat
c:\documents and settings\Owner\Application Data\Azureus\active\0416D5CE2AD12740A689D4F5FE6C0BBA67821CED.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\0EC960C66930A4A38369D9853AA8886B89A609F5.dat
c:\documents and settings\Owner\Application Data\Azureus\active\0EC960C66930A4A38369D9853AA8886B89A609F5.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\2BAA11837CC77D76369AD3E542CC2B942F39F121.dat
c:\documents and settings\Owner\Application Data\Azureus\active\2BAA11837CC77D76369AD3E542CC2B942F39F121.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\2E46E72F29D6A491E6D9CEAE1E7D6FC981169FB0.dat
c:\documents and settings\Owner\Application Data\Azureus\active\2E46E72F29D6A491E6D9CEAE1E7D6FC981169FB0.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\3C22023CDAED7A5F4FCD6D1081C74B418E04EF4B.dat
c:\documents and settings\Owner\Application Data\Azureus\active\3C22023CDAED7A5F4FCD6D1081C74B418E04EF4B.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\3E2494F1C5FDA1CCE777E0D5DCCD2F12EEA18DF4.dat
c:\documents and settings\Owner\Application Data\Azureus\active\3E2494F1C5FDA1CCE777E0D5DCCD2F12EEA18DF4.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\531DDA8919C78EE7D8CE82ADF9493CD3E7D24666.dat
c:\documents and settings\Owner\Application Data\Azureus\active\531DDA8919C78EE7D8CE82ADF9493CD3E7D24666.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\5AE5632D5F013865A821B37296E3386641AE3E29.dat
c:\documents and settings\Owner\Application Data\Azureus\active\5AE5632D5F013865A821B37296E3386641AE3E29.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\68022C96E3FA7261CB1B90D5EA9EAF9ED37E9639.dat
c:\documents and settings\Owner\Application Data\Azureus\active\68022C96E3FA7261CB1B90D5EA9EAF9ED37E9639.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\9F8DA0236B58AADA1D25244957E39304430003D8.dat
c:\documents and settings\Owner\Application Data\Azureus\active\9F8DA0236B58AADA1D25244957E39304430003D8.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\A199AAEB185D6E91AE74DE80BDBCA37DEA24A366.dat
c:\documents and settings\Owner\Application Data\Azureus\active\A199AAEB185D6E91AE74DE80BDBCA37DEA24A366.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\A1D090F2AAF1B520F10F3F43AAE6D0C96FF08870.dat
c:\documents and settings\Owner\Application Data\Azureus\active\A1D090F2AAF1B520F10F3F43AAE6D0C96FF08870.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\BB074112A3D59E8E1035CBEE87336080C7FB8117.dat
c:\documents and settings\Owner\Application Data\Azureus\active\BB074112A3D59E8E1035CBEE87336080C7FB8117.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\BD1EF3E59F680565358DF7DD067920A35A98A23C.dat
c:\documents and settings\Owner\Application Data\Azureus\active\BD1EF3E59F680565358DF7DD067920A35A98A23C.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\C679FADC7921B2103CD9798535748B6185FE7AEB.dat
c:\documents and settings\Owner\Application Data\Azureus\active\C679FADC7921B2103CD9798535748B6185FE7AEB.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\cache.dat
c:\documents and settings\Owner\Application Data\Azureus\active\CB729ABB0C382257DA26E2B20EA0E6B65AE10D24.dat
c:\documents and settings\Owner\Application Data\Azureus\active\CB729ABB0C382257DA26E2B20EA0E6B65AE10D24.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\E1DEF3075B235557FE5EC40B73225DA6805B4D53.dat
c:\documents and settings\Owner\Application Data\Azureus\active\E1DEF3075B235557FE5EC40B73225DA6805B4D53.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\E8E582619FCADA8FC7DC41447E9EF97F1C644EAF.dat
c:\documents and settings\Owner\Application Data\Azureus\active\E8E582619FCADA8FC7DC41447E9EF97F1C644EAF.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\active\E9B58E7E8E25B95E4624246FF9CF4DFB9F626813.dat
c:\documents and settings\Owner\Application Data\Azureus\active\E9B58E7E8E25B95E4624246FF9CF4DFB9F626813.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\azureus.config
c:\documents and settings\Owner\Application Data\Azureus\azureus.config.bak
c:\documents and settings\Owner\Application Data\Azureus\azureus.statistics
c:\documents and settings\Owner\Application Data\Azureus\azureus.statistics.bak
c:\documents and settings\Owner\Application Data\Azureus\banips.config
c:\documents and settings\Owner\Application Data\Azureus\banips.config.bak
c:\documents and settings\Owner\Application Data\Azureus\cache\-1948657416.ico
c:\documents and settings\Owner\Application Data\Azureus\cache\-199958017.ico
c:\documents and settings\Owner\Application Data\Azureus\cache\-448067389.ico
c:\documents and settings\Owner\Application Data\Azureus\cache\1191085919.ico
c:\documents and settings\Owner\Application Data\Azureus\cache\1290137766.ico
c:\documents and settings\Owner\Application Data\Azureus\cache\185367522.ico
c:\documents and settings\Owner\Application Data\Azureus\cnetworks.config
c:\documents and settings\Owner\Application Data\Azureus\devices.config
c:\documents and settings\Owner\Application Data\Azureus\devices.config.bak
c:\documents and settings\Owner\Application Data\Azureus\devices\a5d7869e-1ab9-6098-fef9-88476d988455.dat
c:\documents and settings\Owner\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\Owner\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\Owner\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\Owner\Application Data\Azureus\dht\general.dat
c:\documents and settings\Owner\Application Data\Azureus\dht\version.dat
c:\documents and settings\Owner\Application Data\Azureus\downloads.config
c:\documents and settings\Owner\Application Data\Azureus\downloads.config.bak
c:\documents and settings\Owner\Application Data\Azureus\friends.config
c:\documents and settings\Owner\Application Data\Azureus\friends.config.bak
c:\documents and settings\Owner\Application Data\Azureus\ipfilter.cache
c:\documents and settings\Owner\Application Data\Azureus\logs\alerts_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\AutoSpeed_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\clientid_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\CNetworks_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\debug_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\debug_2.log
c:\documents and settings\Owner\Application Data\Azureus\logs\Devices_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\Devices_2.log
c:\documents and settings\Owner\Application Data\Azureus\logs\Friends_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\Friends_2.log
c:\documents and settings\Owner\Application Data\Azureus\logs\iTunes_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\MetaSearch_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\NetStatus_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\seltrace_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\seltrace_2.log
c:\documents and settings\Owner\Application Data\Azureus\logs\SpeedMan_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\SpeedMan_2.log
c:\documents and settings\Owner\Application Data\Azureus\logs\Subscriptions_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\thread_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\thread_2.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.ads_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.CMsgr_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.CMsgr_2.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.emp_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.emp_2.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.Friends_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.Friends_2.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.MD_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.PMsgr_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\v3.Stream_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\VuzeTranscoder_1.log
c:\documents and settings\Owner\Application Data\Azureus\logs\VuzeTranscoder_2.log
c:\documents and settings\Owner\Application Data\Azureus\metasearch.config
c:\documents and settings\Owner\Application Data\Azureus\metasearch.config.bak
c:\documents and settings\Owner\Application Data\Azureus\net\pm_17506.dat
c:\documents and settings\Owner\Application Data\Azureus\plugins\azemp\plugin.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\azitunes\azitunes_0.2.3.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azitunes\azitunes_0.2.3.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll
c:\documents and settings\Owner\Application Data\Azureus\plugins\azitunes\jacob_1.14.3.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azitunes\libProcessAccess.dll
c:\documents and settings\Owner\Application Data\Azureus\plugins\azitunes\libProcessAccess_0.1.2.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azitunes\plugin.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\azump\azump_1.3.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azump\azump_1.3.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azump\azump_1.5.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azump\azump_1.5.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azump\mplayer.exe
c:\documents and settings\Owner\Application Data\Azureus\plugins\azump\mplayer.exe.bak
c:\documents and settings\Owner\Application Data\Azureus\plugins\azump\mplayer\config
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.3.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.3.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.7.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.7.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.0.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.0.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.1.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.1.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.17.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.17.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.2.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.2.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.21.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.21.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.23.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.23.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.5.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.5.zip
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\cd.dat
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.3
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.7
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.0
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.1
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.17
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.2
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.21
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.23
c:\documents and settings\Owner\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.5
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\ffmpeg.exe
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\mediainfo.exe
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\plugin.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\AppleTV.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\Browser.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\Generic_directTV.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\Generic_mp4.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\iPhone.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\iPodClassic.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\iPodNano.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\iPodTouch.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\PS3_HD.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\PS3_SD.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\PSP.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\TiVo_HD.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\Wii.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\XBox_HD.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\XBox_SD.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\profiles\Zen.properties
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\vuzexcode_0.2.8.jar
c:\documents and settings\Owner\Application Data\Azureus\plugins\vuzexcode\vuzexcode_0.2.8.zip
c:\documents and settings\Owner\Application Data\Azureus\rcm.config
c:\documents and settings\Owner\Application Data\Azureus\rcm.config.bak
c:\documents and settings\Owner\Application Data\Azureus\sidebarauto.config
c:\documents and settings\Owner\Application Data\Azureus\sidebarauto.config.bak
c:\documents and settings\Owner\Application Data\Azureus\subs\09C5EF370AA8C1805B00.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\0AC74425FCD696B95977.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\0AEBAEBD9EB24CA336ED.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\0C329A68DF4256DC4A85.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\2D6F5B943313CDEAAC47.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\3AAA29A09AA3A72F0C9F.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\3B04FB9AFFDAE362BDB4.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\47F55630BD61F5EFB0EA.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\4F5D92DCB17E8F9148BB.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\54004C0B7ADCCE4069C9.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\5DB2F40EF01E0A64FD24.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\7076DB20A5F225DDB82C.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\873484835D9B583F8923.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\8DE6E5753F5ADF094F49.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\95B34C1A1F40931D0972.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\9881A270B088DDB92AAD.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\AA9A23B5897B4A074B3D.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\BC263953CBD07F4801A3.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\CC2B3860115B1348CDE3.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\E10711C92108E441C6AD.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\E28C3EBD157D5105AFF9.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\E67D8443DF3B6D5C02B4.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\E9DEE0D514B263FD12F8.vuze
c:\documents and settings\Owner\Application Data\Azureus\subs\FCC85A671C589DE02BA0.vuze
c:\documents and settings\Owner\Application Data\Azureus\subscriptions.config
c:\documents and settings\Owner\Application Data\Azureus\subscriptions.config.bak
c:\documents and settings\Owner\Application Data\Azureus\tables.config
c:\documents and settings\Owner\Application Data\Azureus\tables.config.bak
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU1660501465535346094.tmp
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU1940931718618880746.tmp
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU2083370849852705353.tmp
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU2343026535023784352.tmp
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU4219968040738155509.tmp
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU5445413723930525011.tmp
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU562873094056451055.tmp
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU6464354289953570002.tmp
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU8223564538158910736.tmp
c:\documents and settings\Owner\Application Data\Azureus\tmp\AZU8273522008775525989.tmp
c:\documents and settings\Owner\Application Data\Azureus\tracker.config
c:\documents and settings\Owner\Application Data\Azureus\tracker.config.bak
c:\documents and settings\Owner\Application Data\Azureus\unsentdata.config
c:\documents and settings\Owner\Application Data\Azureus\unsentdata.config.bak
c:\documents and settings\Owner\Application Data\Azureus\update.log
c:\documents and settings\Owner\Application Data\Azureus\update.properties
c:\documents and settings\Owner\Application Data\Azureus\v3.Friends.dat
c:\documents and settings\Owner\Application Data\Azureus\v3.Friends.dat.bak
c:\documents and settings\Owner\Application Data\Azureus\VuzeActivities.config
c:\documents and settings\Owner\Application Data\Azureus\VuzeActivities.config.bak
c:\documents and settings\Owner\Application Data\Azureus\xcodejobs.config
c:\documents and settings\Owner\Application Data\Azureus\xcodejobs.config.bak
c:\program files\Azureus
c:\program files\Azureus\aereg.dll
c:\program files\Azureus\Azureus.exe
c:\program files\Azureus\Azureus.exe.manifest
c:\program files\Azureus\Azureus2.jar
c:\program files\Azureus\AzureusUpdater.exe
c:\program files\Azureus\ChangeLog.txt
c:\program files\Azureus\License.txt
c:\program files\Azureus\msvcr71.dll
c:\program files\Azureus\plugins\azemp\azemp_2.1.06.jar
c:\program files\Azureus\plugins\azemp\azemp_2.1.06.zip
c:\program files\Azureus\plugins\azemp\azmplay.exe.bak
c:\program files\Azureus\plugins\azemp\cp1250-a.raw.bak
c:\program files\Azureus\plugins\azemp\cp1250-b.raw.bak
c:\program files\Azureus\plugins\azemp\font.desc.bak
c:\program files\Azureus\plugins\azemp\mplayer\config
c:\program files\Azureus\plugins\azemp\osd-mplayer-a.raw.bak
c:\program files\Azureus\plugins\azemp\osd-mplayer-b.raw.bak
c:\program files\Azureus\plugins\azemp\plugin.properties_2.1.06
c:\program files\Azureus\plugins\azplugins\azplugins_2.1.4.jar
c:\program files\Azureus\plugins\azrating\azrating_1.3.1.jar
c:\program files\Azureus\plugins\azupdater\azupdater_1.8.5.zip
c:\program files\Azureus\plugins\azupdater\azupdater_1.8.8.zip
c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.3.jar
c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.5.jar
c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.8.jar
c:\program files\Azureus\plugins\azupdater\plugin.properties
c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.5
c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.8
c:\program files\Azureus\plugins\azupdater\Updater.jar
c:\program files\Azureus\plugins\azupdater\Updater.jar.bak
c:\program files\Azureus\swt-about.html
c:\program files\Azureus\swt-awt-win32-3318.dll
c:\program files\Azureus\swt-gdip-win32-3318.dll
c:\program files\Azureus\swt-wgl-win32-3318.dll
c:\program files\Azureus\swt-win32-3318.dll
c:\program files\Azureus\swt.jar
c:\program files\Azureus\uninstall.exe
c:\program files\Common Files\yzynebi.db
c:\windows\atifyfufub.db
c:\windows\dotimubupe.dat
c:\windows\luqilig.lib
c:\windows\system32\hajogofiv.com
c:\windows\system32\upapozarih.com
.
((((((((((((((((((((((((( Files Created from 2009-09-12 to 2009-10-12 )))))))))))))))))))))))))))))))
.
2009-10-06 13:39 . 2009-10-06 13:40 -------- d-----w- c:\program files\ERUNT
2009-10-03 07:24 . 2009-10-03 07:12 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-10-03 07:13 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-10-03 07:11 . 2009-10-03 07:11 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-27 08:50 . 2009-09-27 08:50 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-09-23 06:40 . 2009-09-24 17:51 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 20:39 . 2008-04-01 09:54 139152 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-08 20:38 . 2008-04-01 09:53 111928 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-06 14:18 . 2009-03-16 12:39 -------- d-----w- c:\program files\Acro Software
2009-10-03 06:53 . 2007-10-13 14:43 -------- d-----w- c:\program files\pdf995
2009-10-03 06:50 . 2007-04-18 18:01 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-03 01:54 . 2007-03-25 02:41 -------- d-----w- c:\program files\Lx_cats
2009-10-02 20:23 . 2007-03-22 01:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-27 08:50 . 2009-03-26 01:50 -------- d-----w- c:\program files\TVUPlayer
2009-09-13 06:31 . 2008-11-11 11:48 -------- d-----w- c:\program files\OpenOffice.org 3
2009-08-31 12:54 . 2009-04-01 13:39 -------- d-----w- c:\program files\iTunes
2009-08-31 12:16 . 2009-08-31 12:16 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-31 12:16 . 2009-08-31 12:16 -------- d-----w- c:\program files\iPod
2009-08-31 12:16 . 2007-10-12 02:54 -------- d-----w- c:\program files\Common Files\Apple
2009-08-31 12:14 . 2009-08-31 12:13 -------- d-----w- c:\program files\QuickTime
2009-08-31 12:11 . 2007-09-05 14:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-08-26 11:56 . 2007-03-03 12:59 -------- d-----w- c:\program files\Java
2009-08-14 12:28 . 2007-11-18 02:44 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-24 20:23 . 2008-12-26 10:44 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-23 12:43 . 2007-02-21 07:03 106496 ----a-w- c:\windows\DUMP6716.tmp
2009-07-23 12:16 . 2007-02-21 07:03 106496 ----a-w- c:\windows\DUMP5e3d.tmp
2009-07-23 12:14 . 2007-02-21 07:03 106496 ----a-w- c:\windows\DUMP5e6b.tmp
2009-07-23 12:12 . 2007-02-21 07:03 106496 ----a-w- c:\windows\DUMP63f9.tmp
2008-05-02 09:59 . 2008-02-08 13:42 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-05-02 09:59 . 2008-02-08 13:42 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-05-02 09:59 . 2008-02-08 13:42 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-05-02 09:59 . 2008-02-08 13:42 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-05-02 09:59 . 2008-02-08 13:42 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
------- Sigcheck -------
[-] 2007-02-21 . 6225F14B8CE08CCBA8B25AD27843C674 . 502272 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2007-02-21 . 6225F14B8CE08CCBA8B25AD27843C674 . 502272 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"MemoryCardManager"="c:\program files\Lexmark\Lexmark Precision Photo\MemCard.exe" [2004-02-02 139264]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-03-30 180269]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-24 149280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"LXBSCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBStime.dll" [2004-03-17 65536]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-05-23 88363]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-28 1626112]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\EA GAMES\\Command & Conquer The First Decade\\Command & Conquer Renegade(tm)\\Renegade\\Game.exe"=
"c:\\Program Files\\EA GAMES\\Command & Conquer The First Decade\\Command & Conquer(tm) Generals Zero Hour\\generals.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\KONAMI\\Winning Eleven 8I\\WE8.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [10/3/2009 4:13 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 11:49 PM 1028432]
R3 MOTOMI;YAMAHA Virtual MIDI Device;c:\windows\system32\drivers\YVMIDI.SYS [8/16/2007 11:26 PM 7040]
S3 sssdbus;SAMSUNG WMC Composite Device driver (WDM);c:\windows\system32\drivers\sssdbus.sys [8/16/2007 1:06 AM 66672]
S3 sssdmdfl;SAMSUNG Modem Filter;c:\windows\system32\drivers\sssdmdfl.sys [8/16/2007 1:06 AM 9232]
S3 sssdmdm;SAMSUNG Modem Driver;c:\windows\system32\drivers\sssdmdm.sys [8/16/2007 1:06 AM 100304]
S3 sssdmgmt;SAMSUNG AT command Port Drivers (WDM);c:\windows\system32\drivers\sssdmgmt.sys [8/16/2007 1:06 AM 91744]
S3 sssdobex;SAMSUNG OBEX Port Drivers (WDM);c:\windows\system32\drivers\sssdobex.sys [8/16/2007 1:06 AM 89584]
.
Contents of the 'Scheduled Tasks' folder
2009-10-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 07:12]
2009-10-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 03:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.battrick.org/nl/main.htm
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {8EB4A251-D29C-4F3F-85DE-1C0BB71F0305} - hxxp://www.drm-x.com/download/p2pclient.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game03.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\s294k6ld.default\
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-13 03:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBSCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-10-12 3:47
ComboFix-quarantined-files.txt 2009-10-12 18:47
ComboFix2.txt 2009-10-12 17:00
Pre-Run: 32,017,711,104 bytes free
Post-Run: 31,981,625,344 bytes free
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
440 --- E O F --- 2008-10-29 13:12