ComboFix 09-10-30.01 - Kyla's Laptop 10/30/2009 17:54.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1915.867 [GMT -5:00]
Running from: c:\users\Kyla's Laptop\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3263087516-1746803172-730395602-500
c:\windows\010112010146101105.rx
c:\windows\010112010146116101.xxe
c:\windows\0101120101464955.xxe
c:\windows\0101120101465050.xxe
c:\windows\0101120101465249.xxe
c:\windows\0101120101465349.xxe
c:\windows\0101120101465649.xxe
c:\windows\1009ztea51547.dll
c:\windows\10295hz5ktool589.exe
c:\windows\106fspywa5ez099.dll
c:\windows\1088z5p9191.dll
c:\windows\10bzst9al5024.ocx
c:\windows\1115addwaze1619.ocx
c:\windows\11342tr5z9e0.cpl
c:\windows\11718vzrus1459.bin
c:\windows\11z74hac59ool7c2.exe
c:\windows\12555spambzt5e99.dll
c:\windows\12561wo5m4z59.bin
c:\windows\12b9zteal2059.dll
c:\windows\13325spambo59zc.cpl
c:\windows\14098hackt95z566.dll
c:\windows\145s5ywzr91072.cpl
c:\windows\14740not-9-5irus772z.cpl
c:\windows\14958wo9z63c.cpl
c:\windows\14z83hackt9o575a.bin
c:\windows\15009ziru9737.ocx
c:\windows\15076trzj690.ocx
c:\windows\150z8spy9e5.dll
c:\windows\151fdow9lozder5847.ocx
c:\windows\155bspzwa9e5330.bin
c:\windows\15912tro5z93.bin
c:\windows\159aspar9ez433.exe
c:\windows\15d9th9eatz0575.exe
c:\windows\15zethief921.exe
c:\windows\16464hazktoo9357.bin
c:\windows\17055n9t-a-vzrus53e.exe
c:\windows\171tzreat85955.ocx
c:\windows\17262z9ru5779.exe
c:\windows\17560z9y653.exe
c:\windows\179dthiez2572.dll
c:\windows\17b0vz5919.ocx
c:\windows\18109not-a-vzrus598.ocx
c:\windows\185955pam9oz516.exe
c:\windows\19073s5amboz7f5.bin
c:\windows\19140troz5b0.bin
c:\windows\19151spambotz0b.ocx
c:\windows\1925downloader110z.bin
c:\windows\193749ackt5oz36d.dll
c:\windows\19391vizu5268.cpl
c:\windows\19408zroj695.exe
c:\windows\19557wo9ma4z.exe
c:\windows\19825wor51z49.bin
c:\windows\19dzsparse3575.exe
c:\windows\19z0vi95992.bin
c:\windows\19z66sp57a9.dll
c:\windows\1c1fsteal98z5.ocx
c:\windows\1c8thzef915.bin
c:\windows\1c9adownlzader1295.cpl
c:\windows\1cd9th5eaz34069.cpl
c:\windows\1f9bsparsez9545.bin
c:\windows\1fe9v5r207z.bin
c:\windows\1z304t9oj3f55.cpl
c:\windows\1z3cthreat95580.dll
c:\windows\1z958hack9ool5d8.exe
c:\windows\1zdcthi9f20585.cpl
c:\windows\20135azk9oor1992.ocx
c:\windows\211z9not5a-virus9e4.ocx
c:\windows\22076not-a5vi9us17dz.dll
c:\windows\2209z9roj5e0.dll
c:\windows\22129s5y2z0.ocx
c:\windows\22231ha5kzoo959d.cpl
c:\windows\223z1not-a-virus59.dll
c:\windows\228ezackd9or3151.cpl
c:\windows\22905spamboz3cf5.ocx
c:\windows\22996zackt5ol97a.bin
c:\windows\229z9v5rus6b.dll
c:\windows\22z639irus510.cpl
c:\windows\231fad5warz29209.bin
c:\windows\23850vizus6fa9.ocx
c:\windows\24446n95-a-virzs375.dll
c:\windows\244d9ack5oor20z4.dll
c:\windows\24701not95-virus4z0.cpl
c:\windows\2485t9reat5z69.bin
c:\windows\2498zvi5us619.ocx
c:\windows\24d4spa9se135z.cpl
c:\windows\25259hzcktool2b4.ocx
c:\windows\25515z9rm704.dll
c:\windows\25669spyz505.bin
c:\windows\25a1thiez2921.exe
c:\windows\25zespa9se2453.cpl
c:\windows\26974zpambo53be.exe
c:\windows\26z62spa59ot4a4.dll
c:\windows\27090tr5j28z.cpl
c:\windows\274z9troj26d5.bin
c:\windows\27716tro943z5.cpl
c:\windows\277319zambot585.ocx
c:\windows\27917wor54f4z.cpl
c:\windows\27968not9z-virus495.ocx
c:\windows\286275oz9a-virus191.exe
c:\windows\28d1s9ywar51702z.bin
c:\windows\29098not-a-vi9us4ze5.ocx
c:\windows\294925zrm2419.bin
c:\windows\29511not-a-vir95z8d.dll
c:\windows\297605zrm22c.dll
c:\windows\297925rojz9.bin
c:\windows\297z9not-a5virus9d5.dll
c:\windows\299565py557z.dll
c:\windows\29cedzwnloa5er24.cpl
c:\windows\29dzsparse21265.dll
c:\windows\29z2spyware750.exe
c:\windows\2afzs9e5l3039.bin
c:\windows\2az0dow9loa5er1433.exe
c:\windows\2d4c5pywaze1915.exe
c:\windows\2d99downzoade5259.ocx
c:\windows\2e6bthr9atz577.bin
c:\windows\2fz9spyware2950.exe
c:\windows\2fzfthr59t5401.ocx
c:\windows\2z410wor95c5.ocx
c:\windows\2z5555or95b.exe
c:\windows\2z5fbackd9or20815.exe
c:\windows\3033wozm59b.ocx
c:\windows\30368spamb9t55z.exe
c:\windows\30375zr5j179.cpl
c:\windows\304ftz5e9t5170.exe
c:\windows\31319spambot5z0.dll
c:\windows\31489hac5zoo92df.dll
c:\windows\32401nzt-a5vir9sc8.exe
c:\windows\3314thze5t99659.bin
c:\windows\3398stezl2571.exe
c:\windows\3447st9z53023.cpl
c:\windows\34e2z5ck9oor3021.dll
c:\windows\35212hacktozl479.ocx
c:\windows\35367spambo9z0a.dll
c:\windows\354039otza-virus5f9.dll
c:\windows\355bac9dooz3268.bin
c:\windows\3560zpar9e2375.dll
c:\windows\357959oj69z.bin
c:\windows\366zthi592436.exe
c:\windows\372f5zeal15899.bin
c:\windows\37ddown5oader893z.bin
c:\windows\388t9re5t49z6.exe
c:\windows\3899thr5at64z4.bin
c:\windows\39112s5azbot6b1.exe
c:\windows\395zspy16c.ocx
c:\windows\39698hackzool5d6.cpl
c:\windows\398ztroj5959.cpl
c:\windows\39c6spar95179z.bin
c:\windows\39z81not-a-vi5us525.ocx
c:\windows\3az8down5oader916.exe
c:\windows\3b495dwzre508.ocx
c:\windows\3d565hreatz9869.exe
c:\windows\3dcazhief9235.cpl
c:\windows\3e49vzr953.ocx
c:\windows\3f555py9zre1333.cpl
c:\windows\3z3bdown5oade9576.exe
c:\windows\420zb5ckdo9r945.exe
c:\windows\423a9pywaze1255.exe
c:\windows\4341spyware2597z.exe
c:\windows\4450azdware6995.bin
c:\windows\46b9thief359z.dll
c:\windows\4788not-a-5irus9a9z.exe
c:\windows\490cvzr15435.exe
c:\windows\4916backdo9r875z.ocx
c:\windows\4948stezl1505.exe
c:\windows\495av9r68z.bin
c:\windows\495csparz91943.dll
c:\windows\4964not-a-9ir5s3z.bin
c:\windows\49ezv5r3225.ocx
c:\windows\49zdsp5ware7.exe
c:\windows\4c25spywa5e110z9.ocx
c:\windows\4c91z95ware3231.ocx
c:\windows\4eaezh9eat1506.ocx
c:\windows\4f64b5zkdoo91260.exe
c:\windows\4f97virz985.bin
c:\windows\4fa69irz7835.dll
c:\windows\4ffbackdoor393z5.exe
c:\windows\4z04th5ef5659.dll
c:\windows\4z3sparse5429.ocx
c:\windows\4z59troj3785.cpl
c:\windows\5046viz1529.exe
c:\windows\5069szeal24625.exe
c:\windows\511z9s9y42f.cpl
c:\windows\512bacz9oor558.ocx
c:\windows\513759z83.bin
c:\windows\51794wozm313.bin
c:\windows\518aa9dwzre2574.bin
c:\windows\5194wzrm793.exe
c:\windows\52216not-z-virus91a.exe
c:\windows\5285virus19z.cpl
c:\windows\52bspa9se24z2.cpl
c:\windows\53458hacktool995z.dll
c:\windows\538csparse2992z.dll
c:\windows\53f1zhie9158.cpl
c:\windows\5411hack5z9l3a8.exe
c:\windows\54309spy205z.cpl
c:\windows\54b5vzr91235.cpl
c:\windows\54c69ir5103z.dll
c:\windows\550trz94b3.dll
c:\windows\5522spambot59az.bin
c:\windows\5532a9dware35z.cpl
c:\windows\5535vzr3199.exe
c:\windows\5598z9r2456.bin
c:\windows\559cbackzoor1949.ocx
c:\windows\55b7spa5sz9712.cpl
c:\windows\55e75ackdoor1z97.ocx
c:\windows\55z1steal1925.cpl
c:\windows\55z5spar9e1156.bin
c:\windows\55zfth9ef2888.ocx
c:\windows\5615t95ef27z9.cpl
c:\windows\56614trzj98f.exe
c:\windows\573bthre5t3039z.cpl
c:\windows\5757spz9are1673.bin
c:\windows\57dcsparsz9273.dll
c:\windows\5849st9al2755z.cpl
c:\windows\5902wz9m635.ocx
c:\windows\5941thr5atz055.ocx
c:\windows\59986wzrm55c.dll
c:\windows\5999zorm765.cpl
c:\windows\59bdbackdoorz14.cpl
c:\windows\59dd59reat4z.dll
c:\windows\59z39vir9se0.dll
c:\windows\5a08spar5z459.ocx
c:\windows\5a9dazdware1203.dll
c:\windows\5aa4zp5w9re559.bin
c:\windows\5b40spywarez4859.exe
c:\windows\5b5ab59kdoor291z.bin
c:\windows\5bbf9ir259z.cpl
c:\windows\5bc8zownl59der3013.bin
c:\windows\5befthre5t90z96.exe
c:\windows\5cf9thre9t542z5.exe
c:\windows\5d5ead9wz5e208.dll
c:\windows\5d9zsparse789.bin
c:\windows\5df1adzw9re9535.bin
c:\windows\5dz9spyw5re15509.dll
c:\windows\5f55ste9512z9.dll
c:\windows\5f65s59az518.bin
c:\windows\5z55steal96515.ocx
c:\windows\5z8bsparse51559.exe
c:\windows\61545pazbot3499.cpl
c:\windows\634bszea91659.bin
c:\windows\64d19z5ef2456.exe
c:\windows\653asp9rse57z3.dll
c:\windows\6583spambo958z.cpl
c:\windows\6583thi9f277z.ocx
c:\windows\6598hac9tooz191.bin
c:\windows\65bddo9nloazer725.bin
c:\windows\65d0b5ckdoo9215z.cpl
c:\windows\65efzddware9845.bin
c:\windows\65fzdown9oader1953.exe
c:\windows\666bsparse5z49.exe
c:\windows\6681spywa9e3z345.ocx
c:\windows\66dzsparse5059.cpl
c:\windows\67z9addware2557.bin
c:\windows\6957zt5al981.ocx
c:\windows\6a215ownloade9321z.dll
c:\windows\6bz1ad9w5re2926.bin
c:\windows\6e48azd95re1219.cpl
c:\windows\7003threz590242.bin
c:\windows\7050spa9se10z7.bin
c:\windows\70ze9hre5t7021.bin
c:\windows\718cbackdo9r775z.exe
c:\windows\71b8t5rza920778.cpl
c:\windows\71down9o5der22z4.dll
c:\windows\7272zpars53982.dll
c:\windows\72d2spyware395z.bin
c:\windows\755eazd9are1890.cpl
c:\windows\755zspam9ote2.cpl
c:\windows\7597n9t-a-virz5258.ocx
c:\windows\7675not9a-zirus20a5.bin
c:\windows\7965spzrse2547.cpl
c:\windows\7975sp5zse959.ocx
c:\windows\7990hackzool175.cpl
c:\windows\799bzpar5e2026.exe
c:\windows\79c9sp9rse5180z.cpl
c:\windows\79fespyware55z5.ocx
c:\windows\7a7cdo9n5oader14z4.cpl
c:\windows\7aczackdoo59557.cpl
c:\windows\7d06zh5ef3449.dll
c:\windows\7eacbackzoor5910.cpl
c:\windows\7edspy5arz1595.ocx
c:\windows\7f9aaddwarz3951.bin
c:\windows\7f9fzdd5are503.dll
c:\windows\7fz7spars9656.bin
c:\windows\7z659ir2996.dll
c:\windows\7z79sparse9205.dll
c:\windows\7zcaspy5a9e1937.dll
c:\windows\8035zr1359.bin
c:\windows\8568sp529z.bin
c:\windows\8598sp5mbot7zd9.bin
c:\windows\8777sp5zbo9431.bin
c:\windows\8a7spzw5re569.bin
c:\windows\9042zhief2539.dll
c:\windows\90935roj192z.exe
c:\windows\91319spamzot75e.dll
c:\windows\913zspywa5e747.bin
c:\windows\916dth5efz333.dll
c:\windows\91855hacktool2bz.dll
c:\windows\925z3worm4d5.ocx
c:\windows\9276spzware5562.exe
c:\windows\9352s9am5ot75cz.exe
c:\windows\935ezir31975.bin
c:\windows\94598wozm780.bin
c:\windows\95083spambztfd5.cpl
c:\windows\9515worm65z.cpl
c:\windows\9525wozm9b8.dll
c:\windows\95730not-a-virz53bd.ocx
c:\windows\959ztr5j1fc.dll
c:\windows\95z9s5yware2226.dll
c:\windows\9623z95mbot19e.dll
c:\windows\965ethreat3109z.ocx
c:\windows\9771wor54dz.ocx
c:\windows\97d0szyware5748.exe
c:\windows\985virus395z.exe
c:\windows\98659izus3d.exe
c:\windows\9877ad5warz1768.dll
c:\windows\98993hacktoo540cz.dll
c:\windows\989zs9ambot592.dll
c:\windows\98e5addwzre596.cpl
c:\windows\9954sz95f0.exe
c:\windows\99612worm95z.exe
c:\windows\9a3fth5zat32221.ocx
c:\windows\9d80vzr5279.ocx
c:\windows\9z70worm752.bin
c:\windows\9zbaddware27175.exe
c:\windows\b0c5h9eat2z272.bin
c:\windows\b5asparsez979.cpl
c:\windows\bk23567.dat
c:\windows\c25spywaz91205.dll
c:\windows\ce9thzeat26745.exe
c:\windows\d5vir2z369.cpl
c:\windows\de5threatz9490.exe
c:\windows\f91t5reaz17922.dll
c:\windows\rdr_1256270202.exe
c:\windows\rdr_1256270203.exe
c:\windows\rdr_1256270209.exe
c:\windows\rdr_1256270210.exe
c:\windows\system32\1069backz5or300.ocx
c:\windows\system32\109729oz-a-v5rus4be.bin
c:\windows\system32\1098backd9o5304z.bin
c:\windows\system32\111879pambzt75c.cpl
c:\windows\system32\1124z5r91d1.dll
c:\windows\system32\11333spy5z9.dll
c:\windows\system32\11559notza-vi9u554.dll
c:\windows\system32\11797not-a-vi59s6ez.bin
c:\windows\system32\11z0t5reat23769.dll
c:\windows\system32\1207ste5l699z.cpl
c:\windows\system32\12211zpy2f59.ocx
c:\windows\system32\12389s9y2za5.bin
c:\windows\system32\124965pambotz58.cpl
c:\windows\system32\12627tz9j2e5.bin
c:\windows\system32\129z95r2304.bin
c:\windows\system32\1323spy5z59.cpl
c:\windows\system32\1399sp5rsez594.cpl
c:\windows\system32\1425s5y9arz120.ocx
c:\windows\system32\14506tzo57619.cpl
c:\windows\system32\14z859ir5s641.bin
c:\windows\system32\15069z9oj70e.exe
c:\windows\system32\1509th95at1789z.exe
c:\windows\system32\151z4spy5f69.cpl
c:\windows\system32\15309virzs795.dll
c:\windows\system32\154z2virus92f.cpl
c:\windows\system32\1552z5pamb9t28e.cpl
c:\windows\system32\1552zroj59.ocx
c:\windows\system32\15569dzware627.cpl
c:\windows\system32\15569hacktozl90b.exe
c:\windows\system32\15658vi9us5z8.dll
c:\windows\system32\15666wo9z122.ocx
c:\windows\system32\157235orz9f2.exe
c:\windows\system32\159fthief1284z.dll
c:\windows\system32\15z095rm175.bin
c:\windows\system32\16325wo5m9ze.ocx
c:\windows\system32\16453virz5519.cpl
c:\windows\system32\16921w9rm5bz.bin
c:\windows\system32\16bez9reat15767.ocx
c:\windows\system32\17246wzrm94a5.ocx
c:\windows\system32\17365worm59ez.dll
c:\windows\system32\174135pamboz3e9.ocx
c:\windows\system32\17513spamb59z97.ocx
c:\windows\system32\17z6spywa5e984.bin
c:\windows\system32\18453ha5kto9lzd0.ocx
c:\windows\system32\19138not-a-v5zus6f7.cpl
c:\windows\system32\195atzief5960.ocx
c:\windows\system32\195bdow5load9r1197z.ocx
c:\windows\system32\195z9n5t-a-virus6019.cpl
c:\windows\system32\19783wo5m3c8z.ocx
c:\windows\system32\1a905zyware300.dll
c:\windows\system32\1b6evzr5953.bin
c:\windows\system32\1c2fbac5doorz983.cpl
c:\windows\system32\1c92stealz599.cpl
c:\windows\system32\1da6s9ar5e6z2.cpl
c:\windows\system32\1e95iz492.cpl
c:\windows\system32\1z387worm59.exe
c:\windows\system32\1z54vir25529.exe
c:\windows\system32\1z552v5rus39a.dll
c:\windows\system32\1z659t9oj65e.cpl
c:\windows\system32\1z706tro91095.cpl
c:\windows\system32\1z79vir30185.bin
c:\windows\system32\1z9bth59f342.exe
c:\windows\system32\1z9ds95rse746.dll
c:\windows\system32\1zb4thre9t31151.bin
c:\windows\system32\20057t9oj12z.exe
c:\windows\system32\20278sp5m9otz0e.exe
c:\windows\system32\205189i5uz5b4.dll
c:\windows\system32\20z0a9dwa5e191.ocx
c:\windows\system32\20z60spamb9t53d.ocx
c:\windows\system32\21293wzrm5325.bin
c:\windows\system32\2138znot-9-5irus525.dll
c:\windows\system32\21482z9y5d5.bin
c:\windows\system32\21513wozm429.exe
c:\windows\system32\2192sza5bot595.dll
c:\windows\system32\22895spam9otz215.exe
c:\windows\system32\22cazd5ware795.bin
c:\windows\system32\23650sp9mzot16e.ocx
c:\windows\system32\2406s9ambotz75.cpl
c:\windows\system32\24118z596d.bin
c:\windows\system32\24ccvi59493z.bin
c:\windows\system32\25255t5o94cz.dll
c:\windows\system32\25390troj55z.ocx
c:\windows\system32\25531not-a9virusz3.dll
c:\windows\system32\255z59orm626.ocx
c:\windows\system32\2591thiez335.ocx
c:\windows\system32\25a3vzr3179.ocx
c:\windows\system32\25e7z9r3205.cpl
c:\windows\system32\25f5s59rse3z48.exe
c:\windows\system32\25z39pambotd8.ocx
c:\windows\system32\25zedow59oader3210.bin
c:\windows\system32\26565h9cz5ool33d.cpl
c:\windows\system32\2668addwa952276z.dll
c:\windows\system32\2719zvirus5915.bin
c:\windows\system32\272699ac5tool4bez.ocx
c:\windows\system32\272zpamb5t938.ocx
c:\windows\system32\2787threa95z52.exe
c:\windows\system32\27cbvi941z5.cpl
c:\windows\system32\27z54wo5m9da.exe
c:\windows\system32\2845hzc5tool2129.exe
c:\windows\system32\2850download5r9560z.cpl
c:\windows\system32\28522not-a-vi9usz5b.bin
c:\windows\system32\28910vi5us6za.ocx
c:\windows\system32\28957sp5z15.bin
c:\windows\system32\290z7vi5usac.cpl
c:\windows\system32\29169tr9z154.bin
c:\windows\system32\292589pz243.cpl
c:\windows\system32\2945zworm5e9.bin
c:\windows\system32\29494wor5z21.exe
c:\windows\system32\29507hac9zool16d.ocx
c:\windows\system32\29552worm7z9.cpl
c:\windows\system32\29605not-a-v5rus5z1.exe
c:\windows\system32\29895zpyae.bin
c:\windows\system32\299389a5ktooz249.ocx
c:\windows\system32\29949hacktozl55c.ocx
c:\windows\system32\299605pyz909.exe
c:\windows\system32\299zspar5e2559.ocx
c:\windows\system32\29abdow5loader1z9.dll
c:\windows\system32\2a0s9z5are2197.cpl
c:\windows\system32\2a50ad9wzre2651.ocx
c:\windows\system32\2azcspyware27995.dll
c:\windows\system32\2c5c5a9kzoor909.exe
c:\windows\system32\2ce5downl5adez2569.cpl
c:\windows\system32\2d2bthze9t1115.dll
c:\windows\system32\2defadzwa9e2952.ocx
c:\windows\system32\2z055viru92ac.bin
c:\windows\system32\2z059rus4b1.exe
c:\windows\system32\2z099troj59a5.exe
c:\windows\system32\2z685p95db.dll
c:\windows\system32\2z6ct5ief9938.cpl
c:\windows\system32\2z98addwa5e2727.bin
c:\windows\system32\30085spy9z5.dll
c:\windows\system32\3019hac9zo5l457.exe
c:\windows\system32\30469n5t-a-vizus398.cpl
c:\windows\system32\30529wzr9563.cpl
c:\windows\system32\30799spyz5c9.ocx
c:\windows\system32\307bzackdo9r5239.cpl
c:\windows\system32\3099hazktool652.dll
c:\windows\system32\30fz5ir9554.bin
c:\windows\system32\31586not-a5vi9uz7e4.exe
c:\windows\system32\31650spzmb5t198.exe
c:\windows\system32\32056s9amboz5c.bin
c:\windows\system32\32389spazb9t530.ocx
c:\windows\system32\3259thrzat95304.ocx
c:\windows\system32\32959wzrm1325.exe
c:\windows\system32\32965hack5ooz2f5.bin
c:\windows\system32\32d8baczdo5r6819.dll
c:\windows\system32\3351tro914z.ocx
c:\windows\system32\3398backzo952989.cpl
c:\windows\system32\3513zt9al2995.ocx
c:\windows\system32\3559thre59z2360.exe
c:\windows\system32\359959izus4ad.bin
c:\windows\system32\36zbs9ars553.ocx
c:\windows\system32\38e9threa557z9.dll
c:\windows\system32\38f8dowzloade92905.dll
c:\windows\system32\38f9ba5kdzor2099.ocx
c:\windows\system32\39135pamb9t4z9.bin
c:\windows\system32\39abthze59065.bin
c:\windows\system32\3a59szeal1669.dll
c:\windows\system32\3bb69ir785z.ocx
c:\windows\system32\3c2cthrezt25195.ocx
c:\windows\system32\3czev5r1509.ocx
c:\windows\system32\3d3z9hief435.cpl
c:\windows\system32\3d64th95f19z0.ocx
c:\windows\system32\3d93steaz1459.bin
c:\windows\system32\3db59hrez54010.dll
c:\windows\system32\3e99bzc9door865.cpl
c:\windows\system32\3ecbszyw9re13305.exe
c:\windows\system32\3ezbs9eal3145.bin
c:\windows\system32\3f9v5z2912.ocx
c:\windows\system32\3fz5spyw5r9157.dll
c:\windows\system32\3z759hief2988.ocx
c:\windows\system32\3z95vir23715.dll
c:\windows\system32\3zf2backd9o5992.exe
c:\windows\system32\3zf9t9reat5976.exe
c:\windows\system32\4151zow9loa5er3159.ocx
c:\windows\system32\42cfazdwa591732.cpl
c:\windows\system32\42e0ba9kzoor2513.cpl
c:\windows\system32\434ezhief92045.ocx
c:\windows\system32\43615zr9s75.dll
c:\windows\system32\43cfsze9l11225.cpl
c:\windows\system32\4427noz-a9vi5us489.cpl
c:\windows\system32\451asteal9z9.ocx
c:\windows\system32\4598not-z-v5rus.bin
c:\windows\system32\45aest9a517z5.exe
c:\windows\system32\45b7thief39z2.exe
c:\windows\system32\480zthreat5094.cpl
c:\windows\system32\4855woz9261.exe
c:\windows\system32\4897addwzre1195.ocx
c:\windows\system32\4902spar9z5975.exe
c:\windows\system32\4902tzief15179.cpl
c:\windows\system32\49c8v5r227z.exe
c:\windows\system32\49f5zpyware49.cpl
c:\windows\system32\4cc5thief9z45.cpl
c:\windows\system32\4e99backdo5z32.cpl
c:\windows\system32\4f409pazs51004.exe
c:\windows\system32\4f75b9ckdooz2997.cpl
c:\windows\system32\4z469orm2a5.ocx
c:\windows\system32\4zc0spy9are2356.cpl
c:\windows\system32\500adownl9ader6z3.cpl
c:\windows\system32\504zdown95ader1016.ocx
c:\windows\system32\5066ba9kzoor10595.dll
c:\windows\system32\50f2addwzr92595.dll
c:\windows\system32\5125zpyware2998.ocx
c:\windows\system32\51570viruz5759.bin
c:\windows\system32\51efzhre9t2559.bin
c:\windows\system32\51z1spy291.dll
c:\windows\system32\5214znot-a-virus594.dll
c:\windows\system32\5229t5ief157z.bin
c:\windows\system32\524ba5kdoor16z9.bin
c:\windows\system32\5258backdoo92824z.exe
c:\windows\system32\525etzreat309739.bin
c:\windows\system32\5310spar9e1796z.exe
c:\windows\system32\5339ha5ktool66z.exe
c:\windows\system32\5352zvirus791.cpl
c:\windows\system32\537zsp59se1572.dll
c:\windows\system32\53b3th5eat1699z.bin
c:\windows\system32\53d6bazkd95r2526.ocx
c:\windows\system32\544zspars57309.dll
c:\windows\system32\5450h9zktoo51e8.ocx
c:\windows\system32\5457vi91z99.ocx
c:\windows\system32\54z07tro94a6.exe
c:\windows\system32\54z0wo5m6b09.cpl
c:\windows\system32\54z4thief2962.bin
c:\windows\system32\54zt9oj740.dll
c:\windows\system32\553espz9are2337.dll
c:\windows\system32\5590virzs912.bin
c:\windows\system32\55c7stea9z855.bin
c:\windows\system32\55d9v5r2261z.ocx
c:\windows\system32\5619threzt2797.exe
c:\windows\system32\56b9stealz395.exe
c:\windows\system32\56f8szeal1936.bin
c:\windows\system32\56z9backd5or302.exe
c:\windows\system32\5760sp59bot1zd.dll
c:\windows\system32\57z9spamb5t28f.bin
c:\windows\system32\58f5downlz5der20359.ocx
c:\windows\system32\58f9thze92057.ocx
c:\windows\system32\59298hacktooz96.bin
c:\windows\system32\59429spambot2ez.cpl
c:\windows\system32\5945baczdoor895.bin
c:\windows\system32\5958z9r2591.exe
c:\windows\system32\59d6zp9ware1378.bin
c:\windows\system32\59f89zr5at15043.ocx
c:\windows\system32\59zbs9eal2506.exe
c:\windows\system32\5a399ownloaderz580.exe
c:\windows\system32\5a6s9a5se3077z.dll
c:\windows\system32\5a8addwar92697z.ocx
c:\windows\system32\5b2dthz5f24569.ocx
c:\windows\system32\5b83vir1695z.exe
c:\windows\system32\5bff59dwzre1682.ocx
c:\windows\system32\5bz7vir1099.bin
c:\windows\system32\5c95spywaze496.cpl
c:\windows\system32\5cazv9r826.bin
c:\windows\system32\5d435hreat23z90.exe
c:\windows\system32\5d7spa9ze3151.bin
c:\windows\system32\5eaedow5loader25z9.bin
c:\windows\system32\5f269ac5doorz559.cpl
c:\windows\system32\5z322virus499.bin
c:\windows\system32\5z59v9r193.cpl
c:\windows\system32\5z9thief13569.bin
c:\windows\system32\5zba5teal9253.ocx
c:\windows\system32\5zd7threa929386.bin
c:\windows\system32\600zhack5ool398.ocx
c:\windows\system32\6379worz539.dll
c:\windows\system32\63d8szywar5479.exe
c:\windows\system32\65179ir5s78z.bin
c:\windows\system32\6575hack9ool2zf.exe
c:\windows\system32\65bcza9kdoor1904.dll
c:\windows\system32\65fdadd9are4z5.dll
c:\windows\system32\6648virz8859.exe
c:\windows\system32\6694spy5are282z.ocx
c:\windows\system32\66z7s9e5l239.dll
c:\windows\system32\672t95ef2z78.bin
c:\windows\system32\675a9ownloader2767z.bin
c:\windows\system32\675aa5dwarz1491.ocx
c:\windows\system32\675ado5nzo9der2872.ocx
c:\windows\system32\67fes9azse30565.ocx
c:\windows\system32\6921stezl9542.exe
c:\windows\system32\6933spamb5tz37.cpl
c:\windows\system32\6987addware5z30.ocx
c:\windows\system32\699eaddwa5e8z8.ocx
c:\windows\system32\69a9spar9e152z.ocx
c:\windows\system32\69c6downlo5de9235z.exe
c:\windows\system32\69z0steal2255.dll
c:\windows\system32\6a20spar9z652.dll
c:\windows\system32\6b7eth9ef259z.cpl
c:\windows\system32\6c47thz9at18415.ocx
c:\windows\system32\6ez9spyw5re941.ocx
c:\windows\system32\6z2f9hief13275.exe
c:\windows\system32\700f9own5zader2986.cpl
c:\windows\system32\7191downloa9er58z0.exe
c:\windows\system32\7289stezl956.ocx
c:\windows\system32\7355spywa9e12z.dll
c:\windows\system32\7356s9ezl153.dll
c:\windows\system32\7358s9yware279z.bin
c:\windows\system32\75395ownloz9er754.bin
c:\windows\system32\754ethr9at26z045.cpl
c:\windows\system32\7599zir1853.exe
c:\windows\system32\75a89ir7z1.exe
c:\windows\system32\77935zy86.bin
c:\windows\system32\77z6s5arse9339.dll
c:\windows\system32\78favi59296z.ocx
c:\windows\system32\793059rezt30305.bin
c:\windows\system32\7995trojz8.cpl
c:\windows\system32\7996hack5ool62z.ocx
c:\windows\system32\79ct9iefz57.ocx
c:\windows\system32\79z9spyware165.bin
c:\windows\system32\7ac9st5al2z6.exe
c:\windows\system32\7b96spyw5r926z2.ocx
c:\windows\system32\7c3fthr9at2z3225.bin
c:\windows\system32\7c92st5alz879.exe
c:\windows\system32\7ed8backdoor3z59.exe
c:\windows\system32\7f25addzar91073.ocx
c:\windows\system32\7fe15te9l2685z.dll
c:\windows\system32\822hac5to9lzf.dll
c:\windows\system32\8258troj51z9.cpl
c:\windows\system32\8343not-a-v5zus9df.ocx
c:\windows\system32\8655spy5dz9.ocx
c:\windows\system32\91141spy4z5.exe
c:\windows\system32\927zthief1539.cpl
c:\windows\system32\92955worz580.cpl
c:\windows\system32\9345t5reat2559z.exe
c:\windows\system32\9430z5r333.dll
c:\windows\system32\9517spambotz44.ocx
c:\windows\system32\9532zorm15e.cpl
c:\windows\system32\95604spyz9e.dll
c:\windows\system32\9569spy66z.dll
c:\windows\system32\9586tr9j7zc.ocx
c:\windows\system32\96577zpy7d9.bin
c:\windows\system32\9680spars5275z.cpl
c:\windows\system32\9691t5oj5cz.exe
c:\windows\system32\9759zspy4fa.bin
c:\windows\system32\9856spa9bo54z3.ocx
c:\windows\system32\98z5troj4b5.ocx
c:\windows\system32\99521not-a-vi5us1fz.cpl
c:\windows\system32\9955spy1b3z.cpl
c:\windows\system32\995thiz929555.bin
c:\windows\system32\997spamz5t296.dll
c:\windows\system32\99bzh9ef28055.ocx
c:\windows\system32\9abasparse255z.exe
c:\windows\system32\9b8zv5r1449.cpl
c:\windows\system32\9becv5z1031.cpl
c:\windows\system32\9d1addwzre2955.dll
c:\windows\system32\9d1bspywzre582.ocx
c:\windows\system32\9d36spywarz815.ocx
c:\windows\system32\9ev9r2350z.exe
c:\windows\system32\9fc5backdoor26z0.ocx
c:\windows\system32\9z45spy50e9.exe
c:\windows\system32\9z78not-a-vi5us942.bin
c:\windows\system32\9zfb5hief2506.cpl
c:\windows\system32\a59thrzat32412.ocx
c:\windows\system32\c2ds9a5se329z.ocx
c:\windows\system32\c595hreat100z8.dll
c:\windows\system32\d0f95zrse1566.bin
c:\windows\system32\ez5downloa9er97.bin
c:\windows\system32\f4zbackdoo922245.cpl
c:\windows\system32\z0670not-a-5i9us45.exe
c:\windows\system32\z0dethief5925.dll
c:\windows\system32\z192spyware2550.ocx
c:\windows\system32\z3855sp91fc.ocx
c:\windows\system32\z4055spambo9757.ocx
c:\windows\system32\z420wor540c9.cpl
c:\windows\system32\z455spars92535.dll
c:\windows\system32\z47985orm29c.dll
c:\windows\system32\z5512wor96395.dll
c:\windows\system32\z5758n9t-a-5irus13f.cpl
c:\windows\system32\z581spy1a9.ocx
c:\windows\system32\z657addw9re156.dll
c:\windows\system32\z7c1spa9se1581.bin
c:\windows\system32\z7d9th5ef17569.dll
c:\windows\system32\z9354t5oj50d.ocx
c:\windows\system32\z9390troj520.cpl
c:\windows\system32\z95dsparse3003.bin
c:\windows\system32\z9793w5rm7d6.dll
c:\windows\system32\z9db5ackdoo91786.cpl
c:\windows\system32\z9des9arse30825.cpl
c:\windows\system32\z9e2a5dware1562.ocx
c:\windows\system32\zb30thre5t94088.dll
c:\windows\system32\zbc29i51432.dll
c:\windows\system32\zd77addware2859.bin
c:\windows\system32\zdd2s9eal16625.exe
c:\windows\system32\zfa9pyware2245.ocx
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
c:\windows\z07a9i53257.dll
c:\windows\z10259py5d9.exe
c:\windows\z1049p56c2.ocx
c:\windows\z12479ot-a-virus56d.ocx
c:\windows\z159troj59e.ocx
c:\windows\z18119orm625.exe
c:\windows\z1890virus9f5.bin
c:\windows\z1afbac9d5or940.exe
c:\windows\z2794spam5ot786.exe
c:\windows\z35troj96a5.bin
c:\windows\z4839tro5298.exe
c:\windows\z51669pycb.ocx
c:\windows\z55469roj4c9.exe
c:\windows\z5877ha5ktool930.dll
c:\windows\z6205hreat12902.dll
c:\windows\z793steal1375.exe
c:\windows\z795vir9305.cpl
c:\windows\z8675worm5739.ocx
c:\windows\z875w5rm791.cpl
c:\windows\z904tro514b.cpl
c:\windows\z9308s5y192.bin
c:\windows\z949s5yware2983.cpl
c:\windows\z9e2vir659.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_fioo32
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-31 )))))))))))))))))))))))))))))))
.
2009-10-31 00:07 . 2009-10-31 00:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-30 22:54 . 2008-03-12 06:38 28728 ----a-w- c:\windows\system32\drivers\msahci.sys
2009-10-30 22:54 . 2008-04-16 01:53 312344 ----a-w- c:\windows\system32\drivers\iaStor.sys
2009-10-30 22:54 . 2008-03-12 06:38 21560 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-10-27 23:31 . 2009-09-10 15:21 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-27 23:31 . 2009-09-10 15:21 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-26 04:14 . 2009-10-26 04:14 -------- d-----w- c:\program files\ERUNT
2009-10-25 00:01 . 2009-10-25 00:01 -------- d-----w- c:\program files\Trend Micro
2009-10-24 23:56 . 2009-10-24 23:56 0 ----a-w- c:\windows\nsreg.dat
2009-10-24 23:41 . 2009-10-24 23:41 -------- d-----w- c:\users\Kyla's Laptop\AppData\Local\Opera
2009-10-24 23:40 . 2009-10-26 23:20 -------- d-----w- c:\program files\Opera
2009-10-24 22:11 . 2004-08-04 13:00 506368 ----a-w- c:\windows\system32\msxml.dll
2009-10-24 19:58 . 2009-10-24 19:58 -------- d-----w- c:\programdata\WindowsSearch
2009-10-24 19:34 . 2009-10-24 19:34 -------- d-----w- c:\users\Kyla's Laptop\AppData\Local\Threat Expert
2009-10-23 18:02 . 2009-10-23 18:02 -------- d-----w- c:\windows\system32\EventProviders
2009-10-23 18:02 . 2009-10-24 21:09 -------- d-----w- C:\c6b78d74c8bcd61703b647c5f6b729
2009-10-23 14:35 . 2009-10-08 18:14 59664 --s---w- c:\windows\system32\drivers\TfSysMon.sys
2009-10-23 14:35 . 2009-10-08 18:14 33552 --s---w- c:\windows\system32\drivers\TfNetMon.sys
2009-10-23 14:35 . 2009-10-08 18:14 51984 --s---w- c:\windows\system32\drivers\TfFsMon.sys
2009-10-23 14:18 . 2009-09-24 13:55 97208 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2009-10-23 13:53 . 2009-09-24 13:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-10-23 13:53 . 2009-10-06 21:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-10-23 13:53 . 2009-09-23 21:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-23 13:53 . 2009-10-23 13:54 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-23 13:53 . 2009-09-03 14:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-10-23 13:53 . 2009-10-31 00:13 -------- d-----w- c:\program files\Spyware Doctor
2009-10-23 13:53 . 2009-10-23 14:35 -------- d-----w- c:\programdata\PC Tools
2009-10-23 13:53 . 2009-10-23 13:53 -------- d-----w- c:\users\Kyla's Laptop\AppData\Roaming\PC Tools
2009-10-23 03:54 . 2009-10-23 03:54 -------- d-----w- c:\users\Kyla's Laptop\AppData\Roaming\InstallShield
2009-10-23 03:54 . 2009-10-23 03:54 -------- d-----w- c:\users\Kyla's Laptop\AppData\Roaming\WinBatch
2009-10-23 03:46 . 2009-10-23 03:46 1 ---h--w- c:\windows\tgm2.dat
2009-10-23 03:46 . 2009-10-23 03:46 1 ---h--w- c:\windows\hpm2.dat
2009-10-23 03:45 . 2009-10-23 03:45 1 ---h--w- c:\windows\bx4657.dat
2009-10-21 01:46 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-21 01:46 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-21 01:46 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-21 01:46 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-21 01:45 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-21 01:45 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-21 01:45 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-21 01:45 . 2009-08-07 00:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-21 01:45 . 2009-08-06 23:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-15 22:42 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-15 22:42 . 2009-08-05 14:22 3597896 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-15 22:42 . 2009-08-05 14:22 3546184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-15 22:41 . 2009-08-31 13:55 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-10-15 22:41 . 2009-08-31 13:55 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-10-02 22:26 . 2009-10-01 15:29 195440 ------w- c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-26 04:04 . 2008-08-18 18:15 -------- d-----w- c:\program files\Google
2009-10-26 03:29 . 2008-08-18 17:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-24 21:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-10-24 21:08 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-23 08:02 . 2008-12-16 13:51 -------- d-----w- c:\programdata\Microsoft Help
2009-10-16 03:00 . 2009-02-13 22:54 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-16 08:20 . 2009-10-23 13:53 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-09-15 11:20 . 2009-10-23 14:18 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat
2009-09-15 07:12 . 2009-10-23 14:18 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat
2009-09-15 06:01 . 2009-10-23 14:18 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat
2009-09-14 09:44 . 2009-10-15 22:40 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-09 08:09 . 2009-08-23 18:59 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-04 12:24 . 2009-10-15 22:40 61440 ----a-w- c:\windows\system32\msasn1.dll
2009-08-28 12:39 . 2009-09-02 23:41 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 10:15 . 2009-09-02 23:41 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 05:22 . 2009-10-15 22:40 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-15 22:40 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-15 22:40 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-15 22:40 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-18 04:33 . 2009-08-18 04:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 17:07 . 2009-09-09 01:03 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-09 01:03 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 16:29 . 2009-09-09 01:03 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 14:16 . 2009-09-09 01:03 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-09 01:03 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-09 01:03 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-09 01:03 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-09 01:03 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-09 01:03 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-09 01:03 10240 ----a-w- c:\windows\system32\finger.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-02-08 19:20 . 2009-02-08 19:20 13 --sh--r- c:\windows\System32\drivers\fbd.sys
2009-02-08 19:20 . 2009-02-08 19:20 4 --sh--r- c:\windows\System32\drivers\taishop.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-04-24 430080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-04-03 3558648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-02-06 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-06-02 505720]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-05-09 716800]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-04-01 1283384]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-21 29744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-09-22 1243088]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-04-08 6037504]
"NDSTray.exe"="NDSTray.exe" [BU]
c:\users\Kyla's Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [10/23/2009 8:53 AM 207280]
R0 TfFsMon;TfFsMon;c:\windows\System32\drivers\TfFsMon.sys [10/23/2009 9:35 AM 51984]
R0 TfSysMon;TfSysMon;c:\windows\System32\drivers\TfSysMon.sys [10/23/2009 9:35 AM 59664]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [12/16/2008 9:12 AM 20384]
R1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [10/23/2009 8:53 AM 229304]
R2 ConfigFree Service;ConfigFree Service;c:\program files\Toshiba\ConfigFree\CFSvcs.exe [4/17/2008 2:19 AM 40960]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2/13/2009 5:54 PM 1153368]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/23/2009 8:53 AM 358600]
R2 TMachInfo;TMachInfo;c:\program files\Toshiba\TOSHIBA Service Station\TMachInfo.exe [8/18/2008 12:58 PM 62776]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\Toshiba\SMARTLogService\TosIPCSrv.exe [12/3/2007 8:03 PM 126976]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [8/18/2008 12:48 PM 7168]
R3 pctplsg;pctplsg;c:\windows\System32\drivers\pctplsg.sys [10/23/2009 8:53 AM 70408]
R3 TfNetMon;TfNetMon;c:\windows\System32\drivers\TfNetMon.sys [10/23/2009 9:35 AM 33552]
R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [8/21/2008 1:31 PM 29744]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [12/16/2008 9:12 AM 954368]
S3 SVRPEDRV;SVRPEDRV;c:\windows\System32\sysprep\PEDRV.SYS [8/21/2008 3:18 PM 9216]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
fioo32 REG_MULTI_SZ fioo32
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
FF - ProfilePath - c:\users\Kyla's Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\v7ud8aqx.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{472734EA-242A-422B-ADF8-83D1E48CC825} - (no file)
WebBrowser-{472734EA-242A-422B-ADF8-83D1E48CC825} - (no file)
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-30 19:15
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(808)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
- - - - - - - > 'lsass.exe'(724)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
- - - - - - - > 'Explorer.exe'(4752)
c:\program files\Spyware Doctor\TFEngine\TfWah.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\Wlanapi.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappcfg.dll
c:\windows\system32\WINHTTP.dll
c:\windows\System32\fwpuclnt.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\igfxext.exe
c:\program files\Spyware Doctor\TFEngine\TFService.exe
.
**************************************************************************
.
Completion time: 2009-10-31 19:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-31 00:28
Pre-Run: 103,488,159,744 bytes free
Post-Run: 103,349,587,968 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 814CC75D4BAEE05E0EE7BF864E2DB7BD