sagittorius
New member
combofix and drweb
ComboFix 08-04-24.1 - R 2008-04-30 0:59:28.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1256.963.1033.18.1150 [GMT 2:00]
Running from: C:\Users\R\Desktop\Combo-Fix.exe
Command switches used :: C:\Users\R\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Windows\system32\mdelk.exe
D:\nideiect.com
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\ban_list.txt
C:\Windows\system32\drivers\downld
C:\Windows\system32\drivers\downld\142038.exe
C:\Windows\system32\drivers\downld\166967.exe
C:\Windows\system32\drivers\downld\185500.exe
C:\Windows\system32\drivers\downld\188652.exe
C:\Windows\system32\drivers\downld\193612.exe
C:\Windows\system32\drivers\downld\196935.exe
C:\Windows\system32\drivers\downld\197856.exe
C:\Windows\system32\drivers\downld\203846.exe
C:\Windows\system32\drivers\downld\209431.exe
C:\Windows\system32\drivers\downld\214750.exe
C:\Windows\system32\drivers\downld\235811.exe
C:\Windows\system32\drivers\downld\243720.exe
C:\Windows\system32\drivers\downld\247667.exe
C:\Windows\system32\drivers\downld\254843.exe
C:\Windows\system32\drivers\downld\296074.exe
C:\Windows\system32\drivers\downld\306042.exe
C:\Windows\system32\drivers\downld\311268.exe
C:\Windows\system32\drivers\downld\325449.exe
C:\Windows\system32\drivers\downld\337726.exe
C:\Windows\system32\drivers\downld\343202.exe
C:\Windows\system32\drivers\downld\356446.exe
C:\Windows\system32\drivers\downld\368739.exe
C:\Windows\system32\drivers\downld\380221.exe
C:\Windows\system32\drivers\downld\395821.exe
C:\Windows\system32\drivers\downld\406101.exe
C:\Windows\system32\drivers\downld\408285.exe
C:\Windows\system32\drivers\downld\410532.exe
C:\Windows\system32\drivers\downld\412794.exe
C:\Windows\system32\drivers\downld\4237876.exe
C:\Windows\system32\drivers\downld\4240559.exe
C:\Windows\system32\drivers\downld\4242103.exe
C:\Windows\system32\drivers\downld\430172.exe
C:\Windows\system32\drivers\downld\434883.exe
C:\Windows\system32\drivers\downld\443604.exe
C:\Windows\system32\drivers\downld\483681.exe
C:\Windows\system32\drivers\downld\514007.exe
C:\Windows\system32\drivers\downld\527564.exe
C:\Windows\system32\drivers\downld\534428.exe
C:\Windows\system32\drivers\downld\534802.exe
C:\Windows\system32\drivers\downld\547610.exe
C:\Windows\system32\drivers\downld\777430.exe
C:\Windows\system32\drivers\downld\782017.exe
C:\Windows\system32\drivers\hldrrr.exe
C:\Windows\system32\drivers\mdelk.exe
C:\Windows\system32\drivers\srosa.sys
C:\Windows\system32\mdelk.exe
C:\Windows\system32\wintems.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-29 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-29 22:29 --------- d-----w C:\Program Files\ChrisTV PVR
2008-04-29 21:43 --------- d-----w C:\Program Files\DScaler
2008-04-29 21:37 --------- d-----w C:\Users\R\AppData\Roaming\River Past G5
2008-04-29 21:37 --------- d-----w C:\ProgramData\River Past G5
2008-04-29 21:32 161,140 ----a-w C:\Windows\DirectShow Detective Uninstaller.exe
2008-04-29 21:32 --------- d-----w C:\Program Files\River Past
2008-04-29 21:32 --------- d-----w C:\Program Files\Common Files\River Past
2008-04-29 21:12 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft
2008-04-29 21:11 --------- d-----w C:\Program Files\DVDVideoSoft
2008-04-29 19:20 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-29 19:20 --------- d-----w C:\Users\R\AppData\Roaming\GHISLER
2008-04-29 19:20 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-29 19:20 --------- d-----w C:\ProgramData\FLEXnet
2008-04-29 19:20 --------- d-----w C:\Program Files\Norton Internet Security
2008-04-29 19:20 --------- d-----w C:\Program Files\My Ebook Library
2008-04-29 19:20 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-29 19:20 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-29 19:20 --------- d-----w C:\Program Files\Common Files\AVerMedia
2008-04-29 19:20 --------- d-----w C:\Program Files\AVerMedia
2008-04-28 19:39 --------- d-----w C:\Program Files\QuickMediaConverter
2008-04-26 17:33 --------- d-----w C:\Program Files\Trend Micro
2008-04-26 15:27 --------- d-----w C:\Users\Guest\AppData\Roaming\Flock
2008-04-26 11:44 --------- d-----w C:\Program Files\CCleaner
2008-04-26 07:51 87,497 ----a-w C:\MGlogs.zip
2008-04-26 06:06 --------- d-----w C:\Users\R\AppData\Roaming\Malwarebytes
2008-04-26 06:06 --------- d-----w C:\ProgramData\Malwarebytes
2008-04-26 06:06 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-04-26 06:04 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-04-26 06:01 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-26 05:54 --------- d-----w C:\Users\R\AppData\Roaming\SUPERAntiSpyware.com
2008-04-26 05:54 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com
2008-04-26 05:35 1,238,055 ----a-w C:\MGtools.exe
2008-04-26 03:36 --------- d-----w C:\ProgramData\avg8
2008-04-26 03:35 10,520 ------w C:\Windows\System32\avgrsstx.dll
2008-04-26 03:35 --------- d-----w C:\Program Files\AVG
2008-04-26 02:35 --------- d-----w C:\Users\R\AppData\Roaming\TrueCrypt
2008-04-26 02:35 --------- d-----w C:\Program Files\WinVDRPRO
2008-04-26 01:09 --------- d-----w C:\Users\R\AppData\Roaming\Greyfirst
2008-04-26 01:09 --------- d-----w C:\Program Files\Celtx
2008-04-25 23:42 --------- d-----w C:\Program Files\MatroskaProp
2008-04-25 00:29 --------- d-----w C:\Program Files\Movienizer
2008-04-19 23:45 --------- d-----w C:\Users\R\AppData\Roaming\Microgaming
2008-04-18 10:35 --------- d-----w C:\Program Files\KeyScrambler
2008-04-16 08:38 --------- d-----w C:\Program Files\QuickTime
2008-04-16 08:37 --------- d-----w C:\ProgramData\Apple Computer
2008-04-16 08:33 --------- d-----w C:\ProgramData\Apple
2008-04-16 08:33 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 18:19 --------- d-----w C:\Program Files\DivXLand
2008-04-15 17:49 --------- d-----w C:\Users\R\AppData\Roaming\Jubler
2008-04-15 16:58 --------- d-----w C:\Users\R\AppData\Roaming\Aegisub
2008-04-10 23:02 --------- d-----w C:\Program Files\LearnPoker
2008-04-10 19:44 --------- d-----w C:\Program Files\DivX
2008-04-10 03:02 --------- d-----w C:\Program Files\Windows Mail
2008-04-07 18:16 --------- d-----w C:\Program Files\ChrisTV
2008-04-07 17:01 --------- d-----w C:\Program Files\Common Files\NacreWare
2008-04-07 14:16 --------- d-----w C:\ProgramData\Team MediaPortal
2008-04-07 14:15 --------- d-----w C:\Program Files\Team MediaPortal
2008-04-06 12:31 205,792 ----a-w C:\GDIPFONTCACHEV1.DAT
2008-04-06 10:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 08:05 --------- d-----w C:\Program Files\EMDB
2008-04-05 00:01 --------- d-----w C:\Program Files\AMC2000
2008-04-02 13:40 --------- d-----w C:\Program Files\Aspell
2008-04-02 08:49 --------- d-----w C:\Users\R\AppData\Roaming\Movienizer
2008-03-31 21:25 831,488 ----a-w C:\Windows\System32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\Windows\System32\DivX.dll
2008-03-31 21:25 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-03-31 03:33 --------- d-----w C:\Users\R\AppData\Roaming\Vidalia
2008-03-31 03:02 --------- d-----w C:\Users\R\AppData\Roaming\tor
2008-03-31 00:25 223,424 ----a-w C:\Windows\system32\drivers\truecrypt.sys
2008-03-30 17:15 --------- d-----w C:\Program Files\CD Audio Reader Filter
2008-03-30 17:14 --------- d-----w C:\Program Files\RealMedia
2008-03-30 17:14 --------- d-----w C:\Program Files\OpenSource Flash Video Splitter
2008-03-30 17:12 --------- d-----w C:\Program Files\SHOUTcast Source
2008-03-30 17:12 --------- d-----w C:\Program Files\DSP-worx
2008-03-30 17:12 --------- d-----w C:\Program Files\DirectVobSub
2008-03-28 14:45 --------- d-----w C:\Program Files\DC++
2008-03-28 00:35 --------- d-----w C:\Users\R\AppData\Roaming\Uniblue
2008-03-28 00:35 --------- d-----w C:\Program Files\Uniblue
2008-03-25 15:45 --------- d-----w C:\Users\R\AppData\Roaming\Autodesk
2008-03-25 15:45 --------- d-----w C:\ProgramData\Autodesk
2008-03-25 00:52 --------- d-----w C:\ProgramData\Symantec
2008-03-21 20:30 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-03-20 22:36 --------- d-----w C:\Users\R\AppData\Roaming\uTorrent
2008-03-20 09:24 --------- d-----w C:\Program Files\Crown Forex Trading Station 4
2008-03-19 11:27 --------- d-----w C:\Users\R\AppData\Roaming\Bytescout SWF To Video Scout
2007-09-04 13:10 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-09-04 13:10 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-09-04 13:10 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\k ----
------- Sigcheck -------
2007-04-09 09:27 802816 8828315f2976c705d5a668de1aa58555 C:\Windows\System32\drivers\tcpip.sys
2006-11-02 10:58 802816 d944522b048a5feb7700b5170d3d9423 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16386_none_5f4ed3e0926e99e4\tcpip.sys
2008-01-09 12:53 802816 028061c7f6d2d03068c72e2a27e4228a C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16567_none_5f6577ce925d75a7\tcpip.sys
2007-04-09 09:27 802816 8828315f2976c705d5a668de1aa58555 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16627_none_5f90b964923d030a\tcpip.sys
2008-01-09 12:53 804352 43eae40b50fe3e60d194dd9c97ebb1fd C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20689_none_5fdb7555ab898001\tcpip.sys
2008-02-13 18:13 806400 52a8bd6294f7d1443c6184c67ae13af4 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20752_none_5ff4e4f9ab7777f4\tcpip.sys
.
((((((((((((((((((((((((((((( snapshot_2008-04-27_22.17.51,16 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-27 20:02:58 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-29 23:08:25 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-29 18:55:34 57,344 ----a-r C:\Windows\Installer\{799A3CB8-DCD5-4B48-ACAD-4D5FABCC7B21}\ARPPRODUCTICON.exe
- 2008-04-27 20:01:43 9,967,920 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2008-04-29 23:07:07 9,967,920 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2008-04-27 20:03:01 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-04-29 23:08:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-04-27 20:03:01 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-04-29 23:08:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-04-27 20:04:47 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-04-29 23:20:44 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-04-27 20:04:54 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-29 23:20:38 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-29 23:20:38 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-04-27 20:05:14 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-29 19:27:04 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-04-27 20:05:14 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-29 19:27:04 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-27 20:05:14 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-04-29 19:27:04 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-26 15:23:25 122,410 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-04-29 21:07:03 122,410 ----a-w C:\Windows\System32\perfc009.dat
- 2008-04-26 15:23:25 659,754 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-04-29 21:07:03 659,754 ----a-w C:\Windows\System32\perfh009.dat
- 2006-11-17 12:35:06 262,144 ------r C:\Windows\System32\sptlib01.dll
+ 2006-11-17 05:35:06 262,144 ------r C:\Windows\System32\sptlib01.dll
- 2007-03-16 02:27:36 253,952 ------r C:\Windows\System32\sptlib02.dll
+ 2007-03-15 19:27:36 253,952 ------r C:\Windows\System32\sptlib02.dll
+ 2004-09-23 05:01:00 638,976 ---ha-w C:\Windows\System32\TOSCDSPD.EXE
- 2008-04-27 20:05:10 13,262 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-750633413-4032638155-1365244786-1000_UserData.bin
+ 2008-04-29 19:25:10 13,646 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-750633413-4032638155-1365244786-1000_UserData.bin
- 2008-04-27 20:05:09 111,066 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-29 19:25:09 111,978 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-04-27 20:01:41 4,790 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-04-28 21:57:17 4,790 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-04-27 20:05:07 70,092 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-29 19:25:07 70,494 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-04-16 08:27:44 415,072 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-04-28 01:12:37 417,276 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="TOSCDSPD.EXE" [2004-09-23 07:01 638976 C:\Windows\System32\TOSCDSPD.EXE]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-07-10 09:40 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-01-18 15:46 4349952 C:\Windows\RtHDVCpl.exe]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-20 01:16 411768]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [2006-12-07 18:49 55416]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2007-01-29 13:43 509496]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-01-17 15:46 534648]
"KeNotify"="C:\Program Files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 19:14 34352]
"HWSetup"="C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 10:06 413696]
"SVPWUTIL"="C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-11-01 13:08 438272]
"NDSTray.exe"="NDSTray.exe" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-04-30 01:03 115816]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-04-30 01:03 22696]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-01-13 10:40 90191]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-01-13 10:40 7766016]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-01-13 10:40 81920]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-27 05:32 898344]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 05:00 204800]
"Wah"="C:\Program Files\Common Files\Mdn2.exe" [2007-09-21 21:21 298496]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 20:54 623992]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 20:51 583048]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-11 20:13 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-11 20:13 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-11 20:13 133656]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2008-04-29 20:55:51 618496]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= E:\1\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
E:\1\SASWINLO.dll 2007-04-19 12:41 294912 E:\1\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"msacm.l3codec"= l3codecp.acm
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-750633413-4032638155-1365244786-1000]
"EnableNotificationsRef"=dword:00000009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{62FA87DF-113A-453C-BCA0-ACA385B5EE65}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{5EA8B303-9DAE-4E1A-A73D-1A127FE16BBC}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{58125C7D-B430-4BD9-B491-87389DDE2A81}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{63A173B0-C9AD-46CB-A81D-9A324C6056B0}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{47D27F1D-EA25-4C77-A137-ED1CAF387567}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C7D7F429-D75D-4C48-9920-9296AFDE1EFD}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{5750A28D-0251-49F5-BC8B-9D36237D45D5}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{CBD0881F-E7E7-4490-8A2C-947A16395419}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{6B90128A-8526-4C76-8527-E22B4BC09273}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{04C7A7AE-3C28-4FF4-AF86-3AD0B9CD0FF7}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{69D4F31B-E0C4-4DA3-B9C4-632E9F3D34A5}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{4ED654C1-BF0F-4353-AEC0-AF1C7495251B}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{03605E4F-77E3-4095-ADBE-30D00693D00B}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{B8926958-DA97-4F8E-998B-34CABFC7FC82}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{D4155DA4-5FEA-42D6-B07E-6C4EFA616C14}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 LPCFilter;LPC Lower Filter Driver;C:\Windows\system32\DRIVERS\LPCFilter.sys [2006-07-28 18:25]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20071002.003\IDSvix86.sys [2007-09-13 16:49]
R1 nm3;Microsoft Network Monitor 3 Driver;C:\Windows\system32\DRIVERS\nm3.sys [2007-06-19 09:59]
R1 PSched;QoS Packet Scheduler;C:\Windows\system32\DRIVERS\pacer.sys [2007-08-29 10:07]
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 06:29]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-02 16:56]
R2 VPCAppSv;Virtual PC Application Services;C:\Windows\system32\DRIVERS\VPCAppSv.sys [2002-10-10 23:10]
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2007-07-14 05:30]
R3 AVerFx2hbtv;AVerMedia USB SW Hybrid Tuner;C:\Windows\system32\drivers\AVerFx2hbtv.sys [2007-08-16 11:54]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 19:36]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 13:50]
R3 tosrfec;Bluetooth ACPI;C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 18:32]
R3 UVCFTR;UVCFTR;C:\Windows\system32\DRIVERS\UVCFTR_S.SYS [2007-01-26 16:13]
S2 CardBusService;CardBusService;C:\Program Files\Common Files\AVerMedia\Service\CardBusService.exe [2007-04-24 02:15]
S2 SBSDWSCService;SBSD Security Center Service;E:\2\SDWinSec.exe [2008-01-28 11:43]
S3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-10-30 20:55]
S3 tap0801;TAP-Win32 Adapter V8;C:\Windows\system32\DRIVERS\tap0801.sys [2006-10-01 14:37]
S4 KR10I;KR10I;C:\Windows\system32\drivers\kr10i.sys [2007-01-18 16:40]
S4 KR10N;KR10N;C:\Windows\system32\drivers\kr10n.sys [2007-01-18 16:47]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c27c1af2-294a-11dc-a41c-806e6f6e6963}]
\shell\AutoRun\command - F:\Autorun.exe
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-04-25 18:43:00 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - R.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeB/TASK:
"2008-04-29 23:40:04 C:\Windows\Tasks\User_Feed_Synchronization-{FB15F4EB-BD17-472F-8975-5C236FC8AC98}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-30 01:32:41
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 4
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Windows\System32\Crypserv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Windows\System32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\conime.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Windows\System32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehrecvr.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2008-04-30 1:40:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-29 23:40:28
ComboFix2.txt 2008-04-27 20:18:34
ComboFix3.txt 2008-04-26 17:45:39
ComboFix4.txt 2008-04-26 13:15:48
The system cannot find message text for message number 0x2379 in the message file for Application.
The system cannot find message text for message number 0x2379 in the message file for Application.
390 --- E O F --- 2008-04-24 16:46:15
DrWeb.csv
MGtools.exe;C:\;Adware.Borlander.231;;
_SetupPoker.exe;C:\Poker\CDPoker;Adware.Casino.49;;
process.exe;C:\Program Files\myphotobook\xtras;Tool.Prockill;;
188652.exe.vir;C:\QooBox\Quarantine\C\Windows\System32\drivers\downld;Win32.HLLM.Beagle;Deleted.;
209431.exe.vir;C:\QooBox\Quarantine\C\Windows\System32\drivers\downld;Win32.HLLM.Beagle;Deleted.;
4240559.exe.vir;C:\QooBox\Quarantine\C\Windows\System32\drivers\downld;Win32.HLLM.Beagle;Deleted.;
430172.exe.vir;C:\QooBox\Quarantine\C\Windows\System32\drivers\downld;Win32.HLLM.Beagle;Deleted.;
PSEXESVC.EXE;C:\Windows;Program.PsExec.170;;
SetupPoker.exe;E:\download\Poker\Online;Adware.Casino.49;;
viewer.exe;E:\download\Virtual Network\vnc;Program.RemoteAdmin;;
MGtools.exe;E:\rescue;Adware.Borlander.231;;
ComboFix 08-04-24.1 - R 2008-04-30 0:59:28.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1256.963.1033.18.1150 [GMT 2:00]
Running from: C:\Users\R\Desktop\Combo-Fix.exe
Command switches used :: C:\Users\R\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Windows\system32\mdelk.exe
D:\nideiect.com
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\ban_list.txt
C:\Windows\system32\drivers\downld
C:\Windows\system32\drivers\downld\142038.exe
C:\Windows\system32\drivers\downld\166967.exe
C:\Windows\system32\drivers\downld\185500.exe
C:\Windows\system32\drivers\downld\188652.exe
C:\Windows\system32\drivers\downld\193612.exe
C:\Windows\system32\drivers\downld\196935.exe
C:\Windows\system32\drivers\downld\197856.exe
C:\Windows\system32\drivers\downld\203846.exe
C:\Windows\system32\drivers\downld\209431.exe
C:\Windows\system32\drivers\downld\214750.exe
C:\Windows\system32\drivers\downld\235811.exe
C:\Windows\system32\drivers\downld\243720.exe
C:\Windows\system32\drivers\downld\247667.exe
C:\Windows\system32\drivers\downld\254843.exe
C:\Windows\system32\drivers\downld\296074.exe
C:\Windows\system32\drivers\downld\306042.exe
C:\Windows\system32\drivers\downld\311268.exe
C:\Windows\system32\drivers\downld\325449.exe
C:\Windows\system32\drivers\downld\337726.exe
C:\Windows\system32\drivers\downld\343202.exe
C:\Windows\system32\drivers\downld\356446.exe
C:\Windows\system32\drivers\downld\368739.exe
C:\Windows\system32\drivers\downld\380221.exe
C:\Windows\system32\drivers\downld\395821.exe
C:\Windows\system32\drivers\downld\406101.exe
C:\Windows\system32\drivers\downld\408285.exe
C:\Windows\system32\drivers\downld\410532.exe
C:\Windows\system32\drivers\downld\412794.exe
C:\Windows\system32\drivers\downld\4237876.exe
C:\Windows\system32\drivers\downld\4240559.exe
C:\Windows\system32\drivers\downld\4242103.exe
C:\Windows\system32\drivers\downld\430172.exe
C:\Windows\system32\drivers\downld\434883.exe
C:\Windows\system32\drivers\downld\443604.exe
C:\Windows\system32\drivers\downld\483681.exe
C:\Windows\system32\drivers\downld\514007.exe
C:\Windows\system32\drivers\downld\527564.exe
C:\Windows\system32\drivers\downld\534428.exe
C:\Windows\system32\drivers\downld\534802.exe
C:\Windows\system32\drivers\downld\547610.exe
C:\Windows\system32\drivers\downld\777430.exe
C:\Windows\system32\drivers\downld\782017.exe
C:\Windows\system32\drivers\hldrrr.exe
C:\Windows\system32\drivers\mdelk.exe
C:\Windows\system32\drivers\srosa.sys
C:\Windows\system32\mdelk.exe
C:\Windows\system32\wintems.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-29 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-29 22:29 --------- d-----w C:\Program Files\ChrisTV PVR
2008-04-29 21:43 --------- d-----w C:\Program Files\DScaler
2008-04-29 21:37 --------- d-----w C:\Users\R\AppData\Roaming\River Past G5
2008-04-29 21:37 --------- d-----w C:\ProgramData\River Past G5
2008-04-29 21:32 161,140 ----a-w C:\Windows\DirectShow Detective Uninstaller.exe
2008-04-29 21:32 --------- d-----w C:\Program Files\River Past
2008-04-29 21:32 --------- d-----w C:\Program Files\Common Files\River Past
2008-04-29 21:12 --------- d-----w C:\Program Files\Common Files\DVDVideoSoft
2008-04-29 21:11 --------- d-----w C:\Program Files\DVDVideoSoft
2008-04-29 19:20 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-29 19:20 --------- d-----w C:\Users\R\AppData\Roaming\GHISLER
2008-04-29 19:20 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-29 19:20 --------- d-----w C:\ProgramData\FLEXnet
2008-04-29 19:20 --------- d-----w C:\Program Files\Norton Internet Security
2008-04-29 19:20 --------- d-----w C:\Program Files\My Ebook Library
2008-04-29 19:20 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-29 19:20 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-29 19:20 --------- d-----w C:\Program Files\Common Files\AVerMedia
2008-04-29 19:20 --------- d-----w C:\Program Files\AVerMedia
2008-04-28 19:39 --------- d-----w C:\Program Files\QuickMediaConverter
2008-04-26 17:33 --------- d-----w C:\Program Files\Trend Micro
2008-04-26 15:27 --------- d-----w C:\Users\Guest\AppData\Roaming\Flock
2008-04-26 11:44 --------- d-----w C:\Program Files\CCleaner
2008-04-26 07:51 87,497 ----a-w C:\MGlogs.zip
2008-04-26 06:06 --------- d-----w C:\Users\R\AppData\Roaming\Malwarebytes
2008-04-26 06:06 --------- d-----w C:\ProgramData\Malwarebytes
2008-04-26 06:06 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-04-26 06:04 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-04-26 06:01 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-26 05:54 --------- d-----w C:\Users\R\AppData\Roaming\SUPERAntiSpyware.com
2008-04-26 05:54 --------- d-----w C:\ProgramData\SUPERAntiSpyware.com
2008-04-26 05:35 1,238,055 ----a-w C:\MGtools.exe
2008-04-26 03:36 --------- d-----w C:\ProgramData\avg8
2008-04-26 03:35 10,520 ------w C:\Windows\System32\avgrsstx.dll
2008-04-26 03:35 --------- d-----w C:\Program Files\AVG
2008-04-26 02:35 --------- d-----w C:\Users\R\AppData\Roaming\TrueCrypt
2008-04-26 02:35 --------- d-----w C:\Program Files\WinVDRPRO
2008-04-26 01:09 --------- d-----w C:\Users\R\AppData\Roaming\Greyfirst
2008-04-26 01:09 --------- d-----w C:\Program Files\Celtx
2008-04-25 23:42 --------- d-----w C:\Program Files\MatroskaProp
2008-04-25 00:29 --------- d-----w C:\Program Files\Movienizer
2008-04-19 23:45 --------- d-----w C:\Users\R\AppData\Roaming\Microgaming
2008-04-18 10:35 --------- d-----w C:\Program Files\KeyScrambler
2008-04-16 08:38 --------- d-----w C:\Program Files\QuickTime
2008-04-16 08:37 --------- d-----w C:\ProgramData\Apple Computer
2008-04-16 08:33 --------- d-----w C:\ProgramData\Apple
2008-04-16 08:33 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 18:19 --------- d-----w C:\Program Files\DivXLand
2008-04-15 17:49 --------- d-----w C:\Users\R\AppData\Roaming\Jubler
2008-04-15 16:58 --------- d-----w C:\Users\R\AppData\Roaming\Aegisub
2008-04-10 23:02 --------- d-----w C:\Program Files\LearnPoker
2008-04-10 19:44 --------- d-----w C:\Program Files\DivX
2008-04-10 03:02 --------- d-----w C:\Program Files\Windows Mail
2008-04-07 18:16 --------- d-----w C:\Program Files\ChrisTV
2008-04-07 17:01 --------- d-----w C:\Program Files\Common Files\NacreWare
2008-04-07 14:16 --------- d-----w C:\ProgramData\Team MediaPortal
2008-04-07 14:15 --------- d-----w C:\Program Files\Team MediaPortal
2008-04-06 12:31 205,792 ----a-w C:\GDIPFONTCACHEV1.DAT
2008-04-06 10:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 08:05 --------- d-----w C:\Program Files\EMDB
2008-04-05 00:01 --------- d-----w C:\Program Files\AMC2000
2008-04-02 13:40 --------- d-----w C:\Program Files\Aspell
2008-04-02 08:49 --------- d-----w C:\Users\R\AppData\Roaming\Movienizer
2008-03-31 21:25 831,488 ----a-w C:\Windows\System32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\Windows\System32\DivX.dll
2008-03-31 21:25 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-03-31 03:33 --------- d-----w C:\Users\R\AppData\Roaming\Vidalia
2008-03-31 03:02 --------- d-----w C:\Users\R\AppData\Roaming\tor
2008-03-31 00:25 223,424 ----a-w C:\Windows\system32\drivers\truecrypt.sys
2008-03-30 17:15 --------- d-----w C:\Program Files\CD Audio Reader Filter
2008-03-30 17:14 --------- d-----w C:\Program Files\RealMedia
2008-03-30 17:14 --------- d-----w C:\Program Files\OpenSource Flash Video Splitter
2008-03-30 17:12 --------- d-----w C:\Program Files\SHOUTcast Source
2008-03-30 17:12 --------- d-----w C:\Program Files\DSP-worx
2008-03-30 17:12 --------- d-----w C:\Program Files\DirectVobSub
2008-03-28 14:45 --------- d-----w C:\Program Files\DC++
2008-03-28 00:35 --------- d-----w C:\Users\R\AppData\Roaming\Uniblue
2008-03-28 00:35 --------- d-----w C:\Program Files\Uniblue
2008-03-25 15:45 --------- d-----w C:\Users\R\AppData\Roaming\Autodesk
2008-03-25 15:45 --------- d-----w C:\ProgramData\Autodesk
2008-03-25 00:52 --------- d-----w C:\ProgramData\Symantec
2008-03-21 20:30 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-03-20 22:36 --------- d-----w C:\Users\R\AppData\Roaming\uTorrent
2008-03-20 09:24 --------- d-----w C:\Program Files\Crown Forex Trading Station 4
2008-03-19 11:27 --------- d-----w C:\Users\R\AppData\Roaming\Bytescout SWF To Video Scout
2007-09-04 13:10 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-09-04 13:10 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-09-04 13:10 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\k ----
------- Sigcheck -------
2007-04-09 09:27 802816 8828315f2976c705d5a668de1aa58555 C:\Windows\System32\drivers\tcpip.sys
2006-11-02 10:58 802816 d944522b048a5feb7700b5170d3d9423 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16386_none_5f4ed3e0926e99e4\tcpip.sys
2008-01-09 12:53 802816 028061c7f6d2d03068c72e2a27e4228a C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16567_none_5f6577ce925d75a7\tcpip.sys
2007-04-09 09:27 802816 8828315f2976c705d5a668de1aa58555 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16627_none_5f90b964923d030a\tcpip.sys
2008-01-09 12:53 804352 43eae40b50fe3e60d194dd9c97ebb1fd C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20689_none_5fdb7555ab898001\tcpip.sys
2008-02-13 18:13 806400 52a8bd6294f7d1443c6184c67ae13af4 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20752_none_5ff4e4f9ab7777f4\tcpip.sys
.
((((((((((((((((((((((((((((( snapshot_2008-04-27_22.17.51,16 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-27 20:02:58 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-29 23:08:25 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-29 18:55:34 57,344 ----a-r C:\Windows\Installer\{799A3CB8-DCD5-4B48-ACAD-4D5FABCC7B21}\ARPPRODUCTICON.exe
- 2008-04-27 20:01:43 9,967,920 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2008-04-29 23:07:07 9,967,920 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2008-04-27 20:03:01 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-04-29 23:08:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-04-27 20:03:01 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-04-29 23:08:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-04-27 20:04:47 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-04-29 23:20:44 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-04-27 20:04:54 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-29 23:20:38 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-29 23:20:38 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-04-27 20:05:14 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-29 19:27:04 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-04-27 20:05:14 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-29 19:27:04 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-27 20:05:14 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-04-29 19:27:04 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-26 15:23:25 122,410 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-04-29 21:07:03 122,410 ----a-w C:\Windows\System32\perfc009.dat
- 2008-04-26 15:23:25 659,754 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-04-29 21:07:03 659,754 ----a-w C:\Windows\System32\perfh009.dat
- 2006-11-17 12:35:06 262,144 ------r C:\Windows\System32\sptlib01.dll
+ 2006-11-17 05:35:06 262,144 ------r C:\Windows\System32\sptlib01.dll
- 2007-03-16 02:27:36 253,952 ------r C:\Windows\System32\sptlib02.dll
+ 2007-03-15 19:27:36 253,952 ------r C:\Windows\System32\sptlib02.dll
+ 2004-09-23 05:01:00 638,976 ---ha-w C:\Windows\System32\TOSCDSPD.EXE
- 2008-04-27 20:05:10 13,262 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-750633413-4032638155-1365244786-1000_UserData.bin
+ 2008-04-29 19:25:10 13,646 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-750633413-4032638155-1365244786-1000_UserData.bin
- 2008-04-27 20:05:09 111,066 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-29 19:25:09 111,978 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-04-27 20:01:41 4,790 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-04-28 21:57:17 4,790 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-04-27 20:05:07 70,092 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-29 19:25:07 70,494 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-04-16 08:27:44 415,072 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-04-28 01:12:37 417,276 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="TOSCDSPD.EXE" [2004-09-23 07:01 638976 C:\Windows\System32\TOSCDSPD.EXE]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-07-10 09:40 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-01-18 15:46 4349952 C:\Windows\RtHDVCpl.exe]
"TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-20 01:16 411768]
"HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [2006-12-07 18:49 55416]
"SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2007-01-29 13:43 509496]
"00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-01-17 15:46 534648]
"KeNotify"="C:\Program Files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 19:14 34352]
"HWSetup"="C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 10:06 413696]
"SVPWUTIL"="C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-11-01 13:08 438272]
"NDSTray.exe"="NDSTray.exe" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-04-30 01:03 115816]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-04-30 01:03 22696]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-01-13 10:40 90191]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-01-13 10:40 7766016]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-01-13 10:40 81920]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-27 05:32 898344]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 05:00 204800]
"Wah"="C:\Program Files\Common Files\Mdn2.exe" [2007-09-21 21:21 298496]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 20:54 623992]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 20:51 583048]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-11 20:13 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-11 20:13 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-11 20:13 133656]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2008-04-29 20:55:51 618496]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 20:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= E:\1\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
E:\1\SASWINLO.dll 2007-04-19 12:41 294912 E:\1\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"msacm.l3codec"= l3codecp.acm
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-750633413-4032638155-1365244786-1000]
"EnableNotificationsRef"=dword:00000009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{62FA87DF-113A-453C-BCA0-ACA385B5EE65}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{5EA8B303-9DAE-4E1A-A73D-1A127FE16BBC}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{58125C7D-B430-4BD9-B491-87389DDE2A81}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{63A173B0-C9AD-46CB-A81D-9A324C6056B0}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{47D27F1D-EA25-4C77-A137-ED1CAF387567}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C7D7F429-D75D-4C48-9920-9296AFDE1EFD}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{5750A28D-0251-49F5-BC8B-9D36237D45D5}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{CBD0881F-E7E7-4490-8A2C-947A16395419}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{6B90128A-8526-4C76-8527-E22B4BC09273}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{04C7A7AE-3C28-4FF4-AF86-3AD0B9CD0FF7}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{69D4F31B-E0C4-4DA3-B9C4-632E9F3D34A5}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{4ED654C1-BF0F-4353-AEC0-AF1C7495251B}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{03605E4F-77E3-4095-ADBE-30D00693D00B}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{B8926958-DA97-4F8E-998B-34CABFC7FC82}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{D4155DA4-5FEA-42D6-B07E-6C4EFA616C14}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 LPCFilter;LPC Lower Filter Driver;C:\Windows\system32\DRIVERS\LPCFilter.sys [2006-07-28 18:25]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20071002.003\IDSvix86.sys [2007-09-13 16:49]
R1 nm3;Microsoft Network Monitor 3 Driver;C:\Windows\system32\DRIVERS\nm3.sys [2007-06-19 09:59]
R1 PSched;QoS Packet Scheduler;C:\Windows\system32\DRIVERS\pacer.sys [2007-08-29 10:07]
R2 SQLWriter;SQL Server VSS Writer;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 06:29]
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2007-02-02 16:56]
R2 VPCAppSv;Virtual PC Application Services;C:\Windows\system32\DRIVERS\VPCAppSv.sys [2002-10-10 23:10]
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2007-07-14 05:30]
R3 AVerFx2hbtv;AVerMedia USB SW Hybrid Tuner;C:\Windows\system32\drivers\AVerFx2hbtv.sys [2007-08-16 11:54]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 19:36]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 13:50]
R3 tosrfec;Bluetooth ACPI;C:\Windows\system32\DRIVERS\tosrfec.sys [2006-10-23 18:32]
R3 UVCFTR;UVCFTR;C:\Windows\system32\DRIVERS\UVCFTR_S.SYS [2007-01-26 16:13]
S2 CardBusService;CardBusService;C:\Program Files\Common Files\AVerMedia\Service\CardBusService.exe [2007-04-24 02:15]
S2 SBSDWSCService;SBSD Security Center Service;E:\2\SDWinSec.exe [2008-01-28 11:43]
S3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-10-30 20:55]
S3 tap0801;TAP-Win32 Adapter V8;C:\Windows\system32\DRIVERS\tap0801.sys [2006-10-01 14:37]
S4 KR10I;KR10I;C:\Windows\system32\drivers\kr10i.sys [2007-01-18 16:40]
S4 KR10N;KR10N;C:\Windows\system32\drivers\kr10n.sys [2007-01-18 16:47]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c27c1af2-294a-11dc-a41c-806e6f6e6963}]
\shell\AutoRun\command - F:\Autorun.exe
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-04-25 18:43:00 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - R.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeB/TASK:
"2008-04-29 23:40:04 C:\Windows\Tasks\User_Feed_Synchronization-{FB15F4EB-BD17-472F-8975-5C236FC8AC98}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-30 01:32:41
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 4
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Windows\System32\Crypserv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Windows\System32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\conime.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Windows\System32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehrecvr.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2008-04-30 1:40:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-29 23:40:28
ComboFix2.txt 2008-04-27 20:18:34
ComboFix3.txt 2008-04-26 17:45:39
ComboFix4.txt 2008-04-26 13:15:48
The system cannot find message text for message number 0x2379 in the message file for Application.
The system cannot find message text for message number 0x2379 in the message file for Application.
390 --- E O F --- 2008-04-24 16:46:15
DrWeb.csv
MGtools.exe;C:\;Adware.Borlander.231;;
_SetupPoker.exe;C:\Poker\CDPoker;Adware.Casino.49;;
process.exe;C:\Program Files\myphotobook\xtras;Tool.Prockill;;
188652.exe.vir;C:\QooBox\Quarantine\C\Windows\System32\drivers\downld;Win32.HLLM.Beagle;Deleted.;
209431.exe.vir;C:\QooBox\Quarantine\C\Windows\System32\drivers\downld;Win32.HLLM.Beagle;Deleted.;
4240559.exe.vir;C:\QooBox\Quarantine\C\Windows\System32\drivers\downld;Win32.HLLM.Beagle;Deleted.;
430172.exe.vir;C:\QooBox\Quarantine\C\Windows\System32\drivers\downld;Win32.HLLM.Beagle;Deleted.;
PSEXESVC.EXE;C:\Windows;Program.PsExec.170;;
SetupPoker.exe;E:\download\Poker\Online;Adware.Casino.49;;
viewer.exe;E:\download\Virtual Network\vnc;Program.RemoteAdmin;;
MGtools.exe;E:\rescue;Adware.Borlander.231;;