updated combofix log
ComboFix 09-06-29.04 - Tara Brooks 06/30/2009 21:52.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.284 [GMT -4:00]
Running from: c:\documents and settings\Tara Brooks\Desktop\SharonCF.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\6508vi5us9z8.bin
c:\windows\6595hacktzo959.exe
c:\windows\6599s5arse7z3.ocx
c:\windows\6756bzckdoor5399.cpl
c:\windows\679ha59toolz7f.exe
c:\windows\68fadzwn5oad9r1676.exe
c:\windows\69345roj5ze.exe
c:\windows\695ethr9zt50157.exe
c:\windows\6a96spyw9rez5.exe
c:\windows\6cd5steaz980.bin
c:\windows\6e55zackd5or29459.bin
c:\windows\6z295pars99.bin
c:\windows\7098th5efz251.bin
c:\windows\7215ack9ool4b9z.ocx
c:\windows\7293vir580z.exe
c:\windows\7360downlza59r3143.cpl
c:\windows\73c1s95alz327.exe
c:\windows\73ccthrzat959355.bin
c:\windows\7593steal2z81.exe
c:\windows\7619vzrus455.exe
c:\windows\7683addwar9z505.exe
c:\windows\774cthizf18295.exe
c:\windows\7835hrzat98508.dll
c:\windows\78c95pywzre2932.dll
c:\windows\78ze5p9ware555.bin
c:\windows\790dstea59z6.ocx
c:\windows\7911backd5oz808.bin
c:\windows\795aspar9ez58.ocx
c:\windows\7984zhi5f2089.ocx
c:\windows\7992zir357.exe
c:\windows\79a495arse161z.ocx
c:\windows\79ee9parze1558.bin
c:\windows\79zbthi5f2854.exe
c:\windows\7bd0d9wnlza5er3247.ocx
c:\windows\7cz5t9reat7269.ocx
c:\windows\7f35back9oor64z.cpl
c:\windows\7z40tro5159.dll
c:\windows\808th59f15z9.exe
c:\windows\813not-z9vir5s60c.bin
c:\windows\8195ddwarez015.dll
c:\windows\8619hackt9olz9f5.dll
c:\windows\86z95irus560.dll
c:\windows\90112hack5ool4z4.exe
c:\windows\902bvir5z6.dll
c:\windows\90fca5dware3z31.bin
c:\windows\9147viruz59.bin
c:\windows\916bthzef11405.ocx
c:\windows\9225st5al186z.bin
c:\windows\92975hzcktool7c2.dll
c:\windows\936baddwzre835.exe
c:\windows\9395zo9m220.cpl
c:\windows\94a1adzware1956.dll
c:\windows\9510szambo95c7.ocx
c:\windows\95723trzj537.ocx
c:\windows\9575steal1z46.bin
c:\windows\95z5spa5bot279.exe
c:\windows\969ft5reatz8612.bin
c:\windows\97831szambot4945.bin
c:\windows\979259y2z1.bin
c:\windows\983spam5zt696.exe
c:\windows\9849tr5jzf5.exe
c:\windows\985dzhief521.exe
c:\windows\9865thzeat23013.dll
c:\windows\987avzr549.cpl
c:\windows\99098trz558e.bin
c:\windows\9933nzt-95virus3d4.dll
c:\windows\9ab1zddw5re431.bin
c:\windows\9e69hrzat935.ocx
c:\windows\9f4azddware5845.exe
c:\windows\9z050virus265.cpl
c:\windows\9z5th9ef586.bin
c:\windows\9z5threa57982.dll
c:\windows\a29zhie5973.bin
c:\windows\c3espzrse905.cpl
c:\windows\c70d9wnlz5der461.ocx
c:\windows\d595ir199z.ocx
c:\windows\f95backdoor15z7.ocx
c:\windows\fzaaddwar59779.ocx
c:\windows\system32\10295teal156z.dll
c:\windows\system32\10349sp5mbzt293.exe
c:\windows\system32\1080znot-a-vi9us40c5.bin
c:\windows\system32\11089spz5bot759.ocx
c:\windows\system32\1137s9yzfa5.exe
c:\windows\system32\11767tro59z9.bin
c:\windows\system32\11a5addw9re592z.exe
c:\windows\system32\11z965py699.exe
c:\windows\system32\12315h9cztool20a.cpl
c:\windows\system32\12550wzrm75e9.dll
c:\windows\system32\13395t5oj5e1z.ocx
c:\windows\system32\13415not-a-virus5z69.exe
c:\windows\system32\13576spamzot914.bin
c:\windows\system32\1395download59z193.ocx
c:\windows\system32\14245p9wzre2880.exe
c:\windows\system32\14293zo5m129.exe
c:\windows\system32\145ztro927.cpl
c:\windows\system32\14z14ha9ktoo539.exe
c:\windows\system32\150z9troj324.ocx
c:\windows\system32\1519vir5s909z.dll
c:\windows\system32\151bthzeat91160.dll
c:\windows\system32\1533bac9dooz694.bin
c:\windows\system32\153et5rza928299.exe
c:\windows\system32\15460not-z-virus90b.dll
c:\windows\system32\15567troz49b.dll
c:\windows\system32\155999rojz2e.dll
c:\windows\system32\1559addwa9e2455z.ocx
c:\windows\system32\1593zs5y279.cpl
c:\windows\system32\15949spy5zc.ocx
c:\windows\system32\15ebs9yware1022z.exe
c:\windows\system32\15z96spy4c1.exe
c:\windows\system32\15z9back9oor1531.ocx
c:\windows\system32\15zcs9ywar52549.exe
c:\windows\system32\1689spzrse24535.dll
c:\windows\system32\17400not-5-viru9z38.cpl
c:\windows\system32\17431zpambo592e.bin
c:\windows\system32\175z9worm35b.bin
c:\windows\system32\17zbthi9f1557.dll
c:\windows\system32\1817h5ckt9zlfb.dll
c:\windows\system32\183adzwnlo5der2092.bin
c:\windows\system32\1855559y5z4.exe
c:\windows\system32\18c49pywarz1535.cpl
c:\windows\system32\19002hazkto5l5f7.bin
c:\windows\system32\19113zpy250.ocx
c:\windows\system32\1916thiez559.exe
c:\windows\system32\19322zorm5d.cpl
c:\windows\system32\19435troj115z.exe
c:\windows\system32\195a9dwaze5859.ocx
c:\windows\system32\19878tzoj59b5.bin
c:\windows\system32\19959z5y163.bin
c:\windows\system32\1997thief538z.bin
c:\windows\system32\1999znot-a5virus4e7.cpl
c:\windows\system32\19dt5zef799.dll
c:\windows\system32\19z0ste592724.dll
c:\windows\system32\1b2ds5azse9501.ocx
c:\windows\system32\1b9zthief11759.exe
c:\windows\system32\1c55th5efz962.cpl
c:\windows\system32\20027worz6059.bin
c:\windows\system32\20039not-5zvirus179.cpl
c:\windows\system32\20094zpy45c.bin
c:\windows\system32\20259irus5a9z.cpl
c:\windows\system32\20531spzmbo9b4.bin
c:\windows\system32\2055zvirus34e9.ocx
c:\windows\system32\20629szy685.bin
c:\windows\system32\20939not-azv5rus234.dll
c:\windows\system32\209d9znl5ader426.exe
c:\windows\system32\20z85ackdoo9190.dll
c:\windows\system32\2124d9wnzoader1515.exe
c:\windows\system32\2129ztroj5365.bin
c:\windows\system32\21353zp95bot10.ocx
c:\windows\system32\213db9zkdoo51136.exe
c:\windows\system32\2189not-a-v5rus6zd.ocx
c:\windows\system32\218bth9zf750.ocx
c:\windows\system32\2190thr5at6966z.dll
c:\windows\system32\2210zs9y587.cpl
c:\windows\system32\224bspy95ze2626.exe
c:\windows\system32\22507wo9m5ez.bin
c:\windows\system32\2255zhackto9l369.exe
c:\windows\system32\22592virus1z79.ocx
c:\windows\system32\2259spazse1785.exe
c:\windows\system32\2265zspy969.ocx
c:\windows\system32\22905w9zm655.dll
c:\windows\system32\23252tz9j6015.ocx
c:\windows\system32\232555o9z678.dll
c:\windows\system32\23512wzr97f5.cpl
c:\windows\system32\23592not-5-virz97e9.dll
c:\windows\system32\235z7not-a-virus9c.cpl
c:\windows\system32\23734no9-5-vzrus143.cpl
c:\windows\system32\2374595rz4cc.cpl
c:\windows\system32\23989tr5j93dz.ocx
c:\windows\system32\24173vzrus579.ocx
c:\windows\system32\24399spyz5c.bin
c:\windows\system32\2445tr9j3fbz.dll
c:\windows\system32\24917h9cktooz1935.bin
c:\windows\system32\24adviz2595.dll
c:\windows\system32\24f49owzl5ader2509.ocx
c:\windows\system32\24z36wo5m97.exe
c:\windows\system32\25661spa9bot1bz.ocx
c:\windows\system32\25769hzckt5ol660.bin
c:\windows\system32\25785hzcktool490.exe
c:\windows\system32\25965sp56ffz.ocx
c:\windows\system32\25abtzrea915509.cpl
c:\windows\system32\25b7stez52497.dll
c:\windows\system32\25d8zteal920.exe
c:\windows\system32\25z09hief1042.dll
c:\windows\system32\263z79i5usa4.ocx
c:\windows\system32\265zac5door9535.ocx
c:\windows\system32\2696downloaderz058.cpl
c:\windows\system32\269z0worm5e0.cpl
c:\windows\system32\2751zv9rusf8.exe
c:\windows\system32\276959py25ez.cpl
c:\windows\system32\27789hzck5oo933b.bin
c:\windows\system32\27969nzt-a-vi5us580.exe
c:\windows\system32\27e95pywaze9982.dll
c:\windows\system32\27z1spy5ar91882.ocx
c:\windows\system32\27z89hackt5ol60e.dll
c:\windows\system32\28860no9-a5virus67z.dll
c:\windows\system32\289ds5ywzre1168.ocx
c:\windows\system32\29130hackzool53e.exe
c:\windows\system32\2915bac9dzor2580.dll
c:\windows\system32\29551szy9a8.dll
c:\windows\system32\29599tzoj389.ocx
c:\windows\system32\296z3v9ru5268.exe
c:\windows\system32\29969vzr9s5d6.cpl
c:\windows\system32\29976spamz5t775.exe
c:\windows\system32\29z2not-a-virus556.cpl
c:\windows\system32\29z59v9rus5f5.cpl
c:\windows\system32\2b8zdown5oader2559.exe
c:\windows\system32\2b93t5i9fz160.bin
c:\windows\system32\2ba3thr9at2z159.bin
c:\windows\system32\2badow59oadez1189.exe
c:\windows\system32\2c5sp9rsz3149.dll
c:\windows\system32\2c7aaddza5e23719.dll
c:\windows\system32\2d19spyware198z5.cpl
c:\windows\system32\2e145ozn9oader1441.exe
c:\windows\system32\2e93tzief252.bin
c:\windows\system32\2z257not9a-virus556.ocx
c:\windows\system32\2z332tro5359.ocx
c:\windows\system32\2z490sp5937.exe
c:\windows\system32\2z595hreat27811.ocx
c:\windows\system32\2z85vir3969.cpl
c:\windows\system32\2z929ddware5309.cpl
c:\windows\system32\2z952worm7a.bin
c:\windows\system32\3047threatz59.exe
c:\windows\system32\3055znot-a-virus5659.cpl
c:\windows\system32\3063tzoj659.dll
c:\windows\system32\3094z59ambot257.exe
c:\windows\system32\31582tro5z829.bin
c:\windows\system32\315abazkdoor9781.dll
c:\windows\system32\31964not-a-vi5us466z.cpl
c:\windows\system32\32001hack9ool45z.cpl
c:\windows\system32\32078s5y9z7.bin
c:\windows\system32\32259tro559ez.ocx
c:\windows\system32\3229baczdoor365.exe
c:\windows\system32\32372troz795.exe
c:\windows\system32\32667zroj5329.cpl
c:\windows\system32\3267addwarz14059.bin
c:\windows\system32\3339stzal2157.cpl
c:\windows\system32\3393ste9l28z5.dll
c:\windows\system32\33a9d9wnloaze51173.exe
c:\windows\system32\33c15tza91677.exe
c:\windows\system32\3529ad9ware1z59.dll
c:\windows\system32\352aspyware9520z.exe
c:\windows\system32\352ethreat9z443.dll
c:\windows\system32\35419spz4c5.exe
c:\windows\system32\35594worz554.bin
c:\windows\system32\35629szy6ce.ocx
c:\windows\system32\3584sp9ware2z0.cpl
c:\windows\system32\359tzief5214.bin
c:\windows\system32\35zhacktool937.dll
c:\windows\system32\36359zrm2c8.dll
c:\windows\system32\363bb5ckdoor1z119.ocx
c:\windows\system32\36c9addwaze2598.ocx
c:\windows\system32\3988hac9tool5z05.bin
c:\windows\system32\398dthief5z0.ocx
c:\windows\system32\39967z5y16b.ocx
c:\windows\system32\39orz335.exe
c:\windows\system32\39z19py4d5.cpl
c:\windows\system32\3c9aspywarz1592.bin
c:\windows\system32\3ca1spywa5e1099z.ocx
c:\windows\system32\3z201n5t-9-virusf7.cpl
c:\windows\system32\3z651no5-a-virus5e9.cpl
c:\windows\system32\3z93backdoor1205.dll
c:\windows\system32\3z98thi59426.bin
c:\windows\system32\40z8s9y5are2391.ocx
c:\windows\system32\4105worm9z.cpl
c:\windows\system32\4189s9ywar5z246.ocx
c:\windows\system32\41f9zparse93225.exe
c:\windows\system32\42z9spyware925.ocx
c:\windows\system32\430c9pzware503.cpl
c:\windows\system32\451059amzot2d.dll
c:\windows\system32\459spamboz39d.cpl
c:\windows\system32\45ca5hzeat3098.ocx
c:\windows\system32\45zspy59re411.bin
c:\windows\system32\4647stea51z039.cpl
c:\windows\system32\4652thi5z3945.exe
c:\windows\system32\473a5par9e3z81.dll
c:\windows\system32\4753hacktool7z9.dll
c:\windows\system32\4a09zh5eat9537.ocx
c:\windows\system32\4c3e5ownloadez2291.bin
c:\windows\system32\4c51sparse9z09.cpl
c:\windows\system32\4c95sparze2453.dll
c:\windows\system32\4da9thzef5539.exe
c:\windows\system32\4fz5steal593.ocx
c:\windows\system32\5005spy9z55.bin
c:\windows\system32\50682no9-a-vzrus762.bin
c:\windows\system32\506bspywar92558z.exe
c:\windows\system32\50710not-a-virzs30d9.exe
c:\windows\system32\50830viru95zb.bin
c:\windows\system32\50zfth59f2045.ocx
c:\windows\system32\512zdown5oa9er1631.ocx
c:\windows\system32\51492szy729.exe
c:\windows\system32\51905ot-a-vir9szc7.exe
c:\windows\system32\51969virus11z.exe
c:\windows\system32\51df9ownloade5z075.cpl
c:\windows\system32\52035zreat81639.bin
c:\windows\system32\521not-z-viru9536.dll
c:\windows\system32\5310h9zktool52d.bin
c:\windows\system32\53zaaddwa9e1985.bin
c:\windows\system32\540fst5al5z9.bin
c:\windows\system32\548a9dwaze6225.ocx
c:\windows\system32\54zethre9t5557.exe
c:\windows\system32\5549steal84z.exe
c:\windows\system32\555z9py32b.bin
c:\windows\system32\556z9ack5ool2aa.cpl
c:\windows\system32\556zworm3589.cpl
c:\windows\system32\559faddwzre1119.bin
c:\windows\system32\55a99zeal2962.dll
c:\windows\system32\5681spa5se1967z.exe
c:\windows\system32\5694spamb5t38z.ocx
c:\windows\system32\5695addwa5ez99.exe
c:\windows\system32\569bspzr5e2339.exe
c:\windows\system32\56c9sparse293z5.exe
c:\windows\system32\56dfszyw9r51048.exe
c:\windows\system32\56z5backdoor16189.dll
c:\windows\system32\56z5s9eal39.cpl
c:\windows\system32\57d15ownloader23z9.dll
c:\windows\system32\57db9zreat2883.dll
c:\windows\system32\57zbadd5are955.cpl
c:\windows\system32\585559py3fz.cpl
c:\windows\system32\5900dow5lozder1641.dll
c:\windows\system32\59571worm4z7.cpl
c:\windows\system32\595dtzief1780.bin
c:\windows\system32\597zth9ef5518.bin
c:\windows\system32\59a9d5wnloader2z90.exe
c:\windows\system32\59z8vir1695.dll
c:\windows\system32\59zcvi9589.bin
c:\windows\system32\5a7down9oader145z.bin
c:\windows\system32\5a9bthief5436z.exe
c:\windows\system32\5ac8bazkdoor2090.exe
c:\windows\system32\5af9addwarz576.cpl
c:\windows\system32\5b6bdownload9r28z85.bin
c:\windows\system32\5b8z9hreat27165.dll
c:\windows\system32\5cb9threat31705z.cpl
c:\windows\system32\5d16threzt296.exe
c:\windows\system32\5d1bacz9oor3142.dll
c:\windows\system32\5d58steal9959z.dll
c:\windows\system32\5d729pywzre3073.exe
c:\windows\system32\5da79pyware110z5.bin
c:\windows\system32\5e09spywar5z549.bin
c:\windows\system32\5e56do9nloader1115z.cpl
c:\windows\system32\5ed6backd9or1570z.dll
c:\windows\system32\5eedadzw95e1576.ocx
c:\windows\system32\5ez4ba95door171.exe
c:\windows\system32\5ez9ddware3154.exe
c:\windows\system32\5f42back95orz059.cpl
c:\windows\system32\5z4spyware29545.bin
c:\windows\system32\5zdethreat20497.ocx
c:\windows\system32\6030n9t-a-virzs501.ocx
c:\windows\system32\605zstea91430.exe
c:\windows\system32\6152zparse28959.exe
c:\windows\system32\6269backz9or5525.bin
c:\windows\system32\6280th9ef534z.bin
c:\windows\system32\6425zroj599.dll
c:\windows\system32\6485thie9z352.dll
c:\windows\system32\65869hief1492z.ocx
c:\windows\system32\6599backdozr2598.cpl
c:\windows\system32\659cvi91z37.ocx
c:\windows\system32\65f5ste9z81.bin
c:\windows\system32\6674zot-a9v5rus5ca.cpl
c:\windows\system32\667bvir39z95.cpl
c:\windows\system32\66b0thr9at2359z.dll
c:\windows\system32\675espyw9rez965.exe
c:\windows\system32\68dzaddwa5e9092.bin
c:\windows\system32\6902viz4755.dll
c:\windows\system32\69steal26z5.exe
c:\windows\system32\6a39zownlo5der1777.dll
c:\windows\system32\6a90t9ie5z37.dll
c:\windows\system32\6b8zspa9se17355.cpl
c:\windows\system32\6d8zthief1975.dll
c:\windows\system32\6f5cstzal3955.ocx
c:\windows\system32\6faa5h9zf3089.dll
c:\windows\system32\7073downloade53z209.dll
c:\windows\system32\715ea9zware257.ocx
c:\windows\system32\71z3s5e9l1829.bin
c:\windows\system32\722ca9dwarz5533.cpl
c:\windows\system32\7272threz598426.dll
c:\windows\system32\73bbthiz512659.ocx
c:\windows\system32\745badd9are11z8.exe
c:\windows\system32\7525sp9r5ez292.exe
c:\windows\system32\757addwz9e1568.cpl
c:\windows\system32\7599spyware180z.ocx
c:\windows\system32\75c49ir1792z.bin
c:\windows\system32\76f5s9ealz935.cpl
c:\windows\system32\7771backzo9r1508.bin
c:\windows\system32\7957a5z9are642.ocx
c:\windows\system32\796z9reat91315.ocx
c:\windows\system32\79b2sp5ware19z4.exe
c:\windows\system32\79f4bzckdoo92752.bin
c:\windows\system32\7a955ownl9zder1248.ocx
c:\windows\system32\7bc1thi5f2958z.bin
c:\windows\system32\7c5a9zr2161.dll
c:\windows\system32\7dfcbaz95oor1811.cpl
c:\windows\system32\7ffzthr5at23809.cpl
c:\windows\system32\7z15spyw5re961.bin
c:\windows\system32\7z59orm167.exe
c:\windows\system32\81025rojzd9.dll
c:\windows\system32\834thiefz5409.ocx
c:\windows\system32\8539zpy5859.bin
c:\windows\system32\8773troz5f9.bin
c:\windows\system32\89z5worm1b75.ocx
c:\windows\system32\9025vir2807z.ocx
c:\windows\system32\90612spz6455.exe
c:\windows\system32\9061h9cktozl235.bin
c:\windows\system32\90755hackzo5l7ba.dll
c:\windows\system32\91196zpambot3d45.cpl
c:\windows\system32\9145vzr5166.bin
c:\windows\system32\91650zr5j4b3.ocx
c:\windows\system32\91espyw59e155z.cpl
c:\windows\system32\9247h5ckzool7c7.ocx
c:\windows\system32\93253troz451.cpl
c:\windows\system32\934fs5yware296z.bin
c:\windows\system32\935dtzreat4332.ocx
c:\windows\system32\93839s5y571z.dll
c:\windows\system32\93abac5zoor1582.bin
c:\windows\system32\93zfs5eal558.dll
c:\windows\system32\94475spy1z0.exe
c:\windows\system32\944sp5rse95z.bin
c:\windows\system32\954wor53az.exe
c:\windows\system32\95578hacktool4z7.cpl
c:\windows\system32\95649ziru54e4.cpl
c:\windows\system32\956dstzal2256.cpl
c:\windows\system32\9597zvirus3e8.ocx
c:\windows\system32\95daddwaze7405.bin
c:\windows\system32\9649troj5cfz.bin
c:\windows\system32\965zspy299.dll
c:\windows\system32\9676backdzo5230.ocx
c:\windows\system32\969zs5y7919.ocx
c:\windows\system32\97305vizusab.bin
c:\windows\system32\97904s5amboz38a.cpl
c:\windows\system32\9805not-9-virzs2a4.ocx
c:\windows\system32\98z45tro5140.dll
c:\windows\system32\99402vi5us225z.exe
c:\windows\system32\994fbac5dozr1407.bin
c:\windows\system32\9957hacztool5d2.dll
c:\windows\system32\996bs5zrse1131.cpl
c:\windows\system32\99983haczto5l499.cpl
c:\windows\system32\9a32vir3215z.cpl
c:\windows\system32\9b7cbackzoor1255.dll
c:\windows\system32\9d85hie93049z.dll
c:\windows\system32\9dad5pywarez924.cpl
c:\windows\system32\9eab5ddwaze571.bin
c:\windows\system32\9eef5zwnloader1208.exe
c:\windows\system32\a2avi569z.ocx
c:\windows\system32\b2z9own5oader2499.bin
c:\windows\system32\b39downl5adez1269.cpl
c:\windows\system32\b695hiefz4109.exe
c:\windows\system32\b9etzief2511.bin
c:\windows\system32\c0athreaz545659.ocx
c:\windows\system32\ca5vi59705z.dll
c:\windows\system32\ccespywaz95858.ocx
c:\windows\system32\cecsp9zs51158.dll
c:\windows\system32\d69s5yware3z.dll
c:\windows\system32\e4eba9zd5or2735.exe
c:\windows\system32\e555tza91215.ocx
c:\windows\system32\z0097sp52a3.ocx
c:\windows\system32\z0169parse1556.ocx
c:\windows\system32\z02t5oj69e.exe
c:\windows\system32\z0386sp51b9.ocx
c:\windows\system32\z0955troj149.ocx
c:\windows\system32\z097backdo5r2629.exe
c:\windows\z1691virus595.dll
c:\windows\z1715hi9f1504.exe
c:\windows\z33spywa9e35.ocx
c:\windows\z35b95dware1264.ocx
c:\windows\z4778tr5j1f39.cpl
c:\windows\z5395py6349.dll
c:\windows\z53spyw59e940.bin
c:\windows\z5484virus659.exe
c:\windows\z5500tro9195.cpl
c:\windows\z5539hackto9l5f2.exe
c:\windows\z55bth95f2171.dll
c:\windows\z65dth9eat1493.dll
c:\windows\z6999spamb5935f.dll
c:\windows\z717v9r875.bin
c:\windows\z7974s5ydf9.dll
c:\windows\z874spyware5999.bin
c:\windows\z894t9oj65.ocx
c:\windows\z97cad9ware5953.cpl
c:\windows\z9bdvir95075.ocx
c:\windows\za88spyw9re5395.bin
c:\windows\zabbdo9n5oader2434.ocx
.
((((((((((((((((((((((((( Files Created from 2009-06-01 to 2009-07-01 )))))))))))))))))))))))))))))))
.
2009-09-18 09:57 . 2009-09-18 09:57 10951 ----a-w- c:\windows\system32\za929pyw5re487.bin
2009-07-25 23:37 . 2009-07-25 23:37 9046 ----a-w- c:\windows\system32\zb799p5rse821.bin
2009-07-11 16:46 . 2009-07-11 16:46 4921 ----a-w- c:\windows\system32\zc5avir9995.dll
2009-07-01 01:41 . 2009-07-01 01:41 152576 ----a-w- c:\documents and settings\Tara Brooks\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-01 01:19 . 2009-07-01 01:36 -------- d-----w- c:\documents and settings\Tara Brooks\.SunDownloadManager
2009-06-30 03:11 . 2009-06-30 03:11 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-06-28 22:18 . 2009-06-28 22:19 -------- d-----w- C:\rsit
2009-06-28 21:06 . 2009-06-28 21:06 14 ----a-w- c:\windows\ASSE.dat
2009-06-28 17:45 . 2009-06-30 02:23 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-28 17:45 . 2009-06-28 17:49 -------- d-----w- c:\program files\SpywareBlaster
2009-06-28 00:58 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-28 00:58 . 2009-06-28 00:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-28 00:58 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-28 00:58 . 2009-06-28 01:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-26 16:20 . 2009-02-12 09:35 38208 ----a-w- c:\documents and settings\Tara Brooks\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-06-26 16:20 . 2009-06-26 16:20 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-26 16:15 . 2009-06-26 16:15 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-06-26 16:13 . 2009-06-27 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-26 16:13 . 2009-06-27 17:31 -------- d-----w- c:\program files\NOS
2009-06-26 06:03 . 2009-06-28 22:19 -------- d-----w- c:\program files\Trend Micro
2009-06-26 05:40 . 2009-06-26 05:40 -------- d-----w- c:\program files\ERUNT
2009-06-24 01:39 . 2009-06-24 01:39 34062 ----a-w- c:\documents and settings\Tara Brooks\Application Data\Move Networks\ie_bin\Uninst.exe
2009-06-23 19:16 . 2009-06-25 23:20 -------- d-----w- c:\program files\DivX
2009-06-23 18:54 . 2009-06-23 18:55 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-06-17 13:04 . 2009-06-17 13:04 4370 ----a-w- c:\windows\system32\z54455p9mbot18.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 01:43 . 2006-07-19 21:23 -------- d-----w- c:\program files\Java
2009-06-28 01:22 . 2005-02-17 14:44 -------- d-----w- c:\documents and settings\Tara Brooks\Application Data\WeatherBug
2009-06-26 16:29 . 2004-08-18 21:37 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-25 23:25 . 2009-01-20 00:09 -------- d-----w- c:\program files\SmartDraw 2009
2009-06-25 23:23 . 2004-07-29 23:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-25 23:20 . 2008-11-26 06:04 -------- d-----w- c:\program files\DNA
2009-06-24 01:40 . 2007-03-24 00:31 -------- d--h--w- c:\documents and settings\Tara Brooks\Application Data\Move Networks
2009-06-16 01:48 . 2006-11-20 01:14 1915520 -c--a-w- c:\documents and settings\Tara Brooks\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-05-27 05:04 . 2006-10-22 18:25 3688 ----a-w- c:\windows\system32\d3d9caps.dat
2009-05-21 15:33 . 2008-11-26 06:28 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-07 15:32 . 2004-07-29 23:21 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-03 21:37 . 2007-02-02 02:37 -------- d-----w- c:\program files\McAfee
2009-04-29 04:56 . 2004-08-24 00:32 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-07-29 23:21 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 00:31 . 2009-04-17 00:31 6292 ----a-w- c:\windows\system32\z35vir21579.bin
2009-04-15 14:51 . 2004-07-29 23:22 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-14 21:33 . 2009-04-14 21:33 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-12 05:04 . 2009-04-12 05:04 12727 ----a-w- c:\windows\system32\z9935orm4e8.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-06-30_04.03.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-01 01:44 . 2009-07-01 01:44 16384 c:\windows\Temp\Perflib_Perfdata_b84.dat
+ 2004-07-29 23:21 . 2009-06-30 21:51 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-07-29 23:21 . 2009-06-30 02:24 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-07-29 23:21 . 2009-06-30 21:51 49152 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2004-07-29 23:21 . 2009-06-30 02:24 49152 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-26 06:28 . 2008-11-26 06:27 148888 c:\windows\system32\javaws.exe
+ 2009-07-01 01:44 . 2009-05-21 15:34 148888 c:\windows\system32\javaws.exe
+ 2009-07-01 01:44 . 2009-05-21 15:34 144792 c:\windows\system32\javaw.exe
- 2008-11-26 06:28 . 2008-11-26 06:27 144792 c:\windows\system32\javaw.exe
+ 2009-07-01 01:44 . 2009-05-21 15:34 144792 c:\windows\system32\java.exe
- 2008-11-26 06:28 . 2008-11-26 06:27 144792 c:\windows\system32\java.exe
+ 2004-07-29 23:21 . 2009-06-30 21:51 262144 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-07-29 23:21 . 2009-06-30 02:24 262144 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="c:\progra~1\AWS\WEATHE~1\Weather.exe" [2005-06-07 1339392]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-23 39408]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"CheckNetworkConnection"="c:\program files\Support.com\providerComcast\desktopdoctor.exe" [2006-06-02 1286144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-02-03 155648]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-29 335872]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-05-28 86016]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-07-17 28672]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2006-10-30 131072]
"iRiver AutoDB"="c:\program files\iRiver\Service\MLService.exe" [2004-09-10 1040384]
"iRiver Updater"="c:\program files\iRiver\Service\Updater.exe" [2004-09-07 212992]
"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2007-03-07 1773568]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-05 28672]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-7-29 24576]
Hawking Wireless Utility.lnk - c:\program files\Hawking\HWU8DD\HWU8DD.exe [2006-12-18 479232]
Post-itr Software Notes Lite.lnk - c:\program files\3M\PSNLite\PsnLite.exe [2004-6-2 1622016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-12 11:55 110592 ----a-w- c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=c:\windows\pss\Picture Package VCD Maker.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Tara Brooks^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Tara Brooks\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\GameHouse\\TextTwist\\TextTwist.exe"=
"c:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\Rio\\Rio Music Manager\\riomm.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 lowpp;Lowrance MMC Parallel Port Driver;c:\windows\system32\drivers\lowpp.sys [6/3/2007 11:20 AM 7787]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 8:26 PM 24652]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\system32\drivers\BRGSp50.sys [12/18/2006 10:31 PM 20608]
S3 MLFILEM;MLFILEM;c:\windows\system32\drivers\MLFILEM.SYS [12/11/2004 1:40 AM 28160]
S3 NaiAvFilter101;NAI Anti Virus;\Device\NaiAvFilter101.sys --> \Device\NaiAvFilter101.sys [?]
S3 ZD1211U(Hawking);Hawking Hi-Gain Wireless-G USB Dish Adapter(Hawking);c:\windows\system32\drivers\ZD1211U.sys [12/18/2006 10:31 PM 278016]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - JAVAQUICKSTARTERSERVICE
.
Contents of the 'Scheduled Tasks' folder
2009-06-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-06-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-02-02 17:32]
2009-04-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-02-02 17:32]
2009-06-30 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-22 02:18]
.
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.utk.edu/
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = actsvr.comcastonline.com:8100
uInternet Settings,ProxyOverride = cdn
IE: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029BBUS_ZCxdm481YYUS
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-30 22:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(884)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\LgNotify.dll
.
Completion time: 2009-07-01 22:03
ComboFix-quarantined-files.txt 2009-07-01 02:02
ComboFix2.txt 2009-06-30 04:06
Pre-Run: 5,867,626,496 bytes free
Post-Run: 5,939,720,192 bytes free
682 --- E O F --- 2009-06-25 19:29