deepak4490
New member
I just did this procedure and after that i scanned my pendrive with Avast and it detected Win32:confi[wrm] at G:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
i just deleted it and removed the pendrive immediately, might be the pendrive is still infected and it will infect my laptop too, waiting for your help.
Combofix log
ComboFix 09-07-25.06 - Deepak 07/26/2009 22:37.5.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1646 [GMT 5.5:30]
Running from: c:\documents and settings\Deepak\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Deepak\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090725-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\system32\oauhyn.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CFNGIZ
-------\Service_cfngiz
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-25 14:42 . 2009-07-25 14:42 -------- d-----w- c:\documents and settings\Deepak\Local Settings\Application Data\Stardock
2009-07-24 09:23 . 2009-07-24 09:23 -------- d-----w- C:\vghd
2009-07-22 10:26 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-22 10:24 . 2009-07-22 10:26 -------- d--h--w- c:\windows\$hf_mig$
2009-07-19 19:32 . 2009-07-19 19:32 -------- d-----w- c:\documents and settings\Deepak\Application Data\Malwarebytes
2009-07-19 19:12 . 2009-07-13 08:06 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-19 19:12 . 2009-07-19 19:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-19 19:12 . 2009-07-13 08:06 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-19 19:12 . 2009-07-19 19:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-19 13:19 . 2009-07-19 13:19 -------- d-----w- c:\documents and settings\Deepak\Application Data\DivX
2009-07-19 06:14 . 2009-07-19 07:01 442400 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-16 16:38 . 2009-07-16 16:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-07-16 16:35 . 2009-07-16 16:36 -------- d-----w- c:\program files\Yahoo!
2009-07-13 21:07 . 2009-07-13 21:07 -------- d-----w- c:\program files\Trend Micro
2009-07-12 12:59 . 2009-07-12 12:59 1078 ----a-r- c:\documents and settings\Deepak\Application Data\Microsoft\Installer\{30BA50ED-0F32-421B-BC6A-132A03EFF299}\ARPPRODUCTICON.exe
2009-07-12 10:08 . 2009-07-12 10:08 12328 ----a-w- c:\documents and settings\Deepak\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-12 09:53 . 2009-02-05 21:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-07-12 09:53 . 2009-02-05 21:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-07-12 09:53 . 2009-02-05 21:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-07-12 09:52 . 2009-02-05 21:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-07-12 09:52 . 2009-02-05 21:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-07-12 09:52 . 2009-02-05 21:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-07-12 09:52 . 2009-02-05 21:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-07-12 09:52 . 2009-02-05 21:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-07-12 09:52 . 2009-02-05 21:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-07-12 09:52 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-07-12 09:52 . 2003-03-18 19:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2009-07-12 09:52 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2009-07-12 09:52 . 2009-07-12 09:52 -------- d-----w- c:\program files\Alwil Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 07:01 . 2009-07-19 06:14 6260 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-12 15:24 . 2009-07-11 14:28 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-11 19:42 . 2009-07-11 19:42 -------- d-----w- c:\program files\RomanWare
2009-07-11 19:28 . 2009-07-11 19:28 0 ----a-w- c:\windows\nsreg.dat
2009-07-11 19:26 . 2009-07-11 19:26 -------- d-----w- c:\program files\AVG
2009-07-11 17:49 . 2009-07-11 17:49 -------- d-----w- c:\program files\Synaptics
2009-07-11 17:49 . 2009-07-11 17:49 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-11 17:39 . 2009-07-11 17:39 -------- d-----w- c:\program files\PaqTool
2009-07-11 17:35 . 2009-07-11 17:35 -------- d-----w- c:\program files\eLitecore
2009-07-11 17:28 . 2009-07-11 17:28 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Intel
2009-07-11 17:28 . 2009-07-11 17:28 -------- d-----w- c:\documents and settings\LocalService\Application Data\Intel
2009-07-11 17:28 . 2009-07-11 17:28 -------- d-----w- c:\documents and settings\Default User\Application Data\Intel
2009-07-11 17:28 . 2009-07-11 17:28 -------- d-----w- c:\documents and settings\Deepak\Application Data\Intel
2009-07-11 17:27 . 2009-07-11 17:27 356352 ----a-w- c:\windows\system32\AegisI5Installer.exe
2009-07-11 17:27 . 2009-07-11 17:27 21393 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-11 17:27 . 2009-07-11 17:27 21393 ----a-w- c:\windows\AegisP.sys
2009-07-11 17:27 . 2009-07-11 17:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2009-07-11 17:27 . 2009-07-11 17:20 -------- d-----w- c:\program files\Intel
2009-07-11 14:29 . 2009-07-11 14:29 -------- d-----w- c:\program files\microsoft frontpage
2009-07-11 14:25 . 2009-07-11 14:25 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-23 20:02 . 2009-07-11 19:28 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-16_19.19.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-26 17:10 . 2009-07-26 17:10 16384 c:\windows\Temp\Perflib_Perfdata_6d4.dat
+ 2009-07-20 12:38 . 2009-07-20 12:38 16384 c:\windows\Temp\Perflib_Perfdata_6d0.dat
+ 2009-07-22 10:24 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
+ 2009-07-22 18:11 . 2009-07-22 18:11 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-25 19:43 . 2008-03-19 05:38 36352 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Clock\SDPlugins\SDAnalogClock3.dll
+ 2004-08-04 00:56 . 2008-10-15 16:57 332800 c:\windows\system32\netapi32.dll
+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2004-08-03 23:15 . 2008-10-24 11:10 453632 c:\windows\system32\drivers\mrxsmb.sys
+ 2004-08-04 00:56 . 2008-10-15 16:57 332800 c:\windows\system32\dllcache\netapi32.dll
+ 2009-07-25 19:43 . 2008-02-14 10:00 439544 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Weather\SDPlugins\DXAxHost.dll
+ 2009-07-25 19:43 . 2008-03-20 06:18 740088 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Weather\Mustang Weather.exe
+ 2009-07-25 19:43 . 2008-02-14 10:00 421624 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Media Player\SDPlugins\DXPlayer.dll
+ 2009-07-25 19:43 . 2008-02-14 10:00 439544 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Media Player\SDPlugins\DXAxHost.dll
+ 2009-07-25 19:43 . 2008-03-19 05:42 746232 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Media Player\Mustang Media Player.exe
+ 2009-07-25 19:43 . 2008-02-14 10:00 439544 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Clock\SDPlugins\DXAxHost.dll
+ 2009-07-25 19:43 . 2008-03-19 05:40 767736 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Clock\Mustang Clock.exe
+ 2009-07-25 19:43 . 2008-02-14 10:00 439544 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Calendar\SDPlugins\DXAxHost.dll
+ 2009-07-25 19:43 . 2008-03-19 05:40 730872 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Calendar\Mustang Calendar.exe
+ 2009-07-22 10:26 . 2008-10-24 11:10 453632 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\system32\Macromed\Flash\NPSWF32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-10 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-10 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-10 137752]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 823296]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 974848]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 774233]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
24Online Client.lnk - c:\program files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe [2004-5-31 249856]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 ENO;ENO;c:\windows\system32\drivers\ENO.sys [5/27/2004 6:51 PM 51564]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7/12/2009 3:22 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/12/2009 3:22 PM 20560]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\Deepak\LOCALS~1\Temp\ALSysIO.sys --> c:\docume~1\Deepak\LOCALS~1\Temp\ALSysIO.sys [?]
.
.
------- Supplementary Scan -------
.
TCP: {F294541A-6EC8-4BEA-B87A-373231CFEAA6} = 202.56.215.55,202.56.215.54
FF - ProfilePath - c:\documents and settings\Deepak\Application Data\Mozilla\Firefox\Profiles\mj97nr66.default\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-26 22:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\igfxsrvc.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-26 22:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-26 17:11
ComboFix2.txt 2009-07-23 18:15
ComboFix3.txt 2009-07-20 07:15
ComboFix4.txt 2009-07-19 06:10
ComboFix5.txt 2009-07-26 17:02
Pre-Run: 34,767,880,192 bytes free
Post-Run: 34,729,488,384 bytes free
161
DDS Log
DDS (Ver_09-06-26.01) - NTFSx86
Run by Deepak at 22:44:05.26 on Sun 07/26/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1647 [GMT 5.5:30]
AV: avast! antivirus 4.8.1335 [VPS 090725-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Deepak\Desktop\dds.pif
============== Pseudo HJT Report ===============
mURLSearchHooks: H - No File
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\24onli~1.lnk - c:\program files\elitecore\cyberoam client for 24online\CyberoamClient.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: {F294541A-6EC8-4BEA-B87A-373231CFEAA6} = 202.56.215.55,202.56.215.54
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\deepak\applic~1\mozilla\firefox\profiles\mj97nr66.default\
============= SERVICES / DRIVERS ===============
R0 ENO;ENO;c:\windows\system32\drivers\ENO.sys [2004-5-27 51564]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-7-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-7-12 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-7-12 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-7-12 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-7-12 352920]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\deepak\locals~1\temp\alsysio.sys --> c:\docume~1\deepak\locals~1\temp\ALSysIO.sys [?]
=============== Created Last 30 ================
2009-07-24 14:53 <DIR> --d----- C:\vghd
2009-07-22 15:56 453,632 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-07-22 15:54 <DIR> --d-h--- c:\windows\$hf_mig$
2009-07-20 01:02 <DIR> --d----- c:\docume~1\deepak\applic~1\Malwarebytes
2009-07-20 00:42 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-20 00:42 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-20 00:42 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-20 00:42 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-19 11:44 442,400 a--sh--- c:\windows\system32\drivers\fidbox.dat
2009-07-19 11:44 6,260 a--sh--- c:\windows\system32\drivers\fidbox.idx
2009-07-17 00:49 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-07-17 00:47 <DIR> a-dshr-- C:\cmdcons
2009-07-17 00:40 219,648 a------- c:\windows\PEV.exe
2009-07-17 00:40 161,792 a------- c:\windows\SWREG.exe
2009-07-17 00:40 98,816 a------- c:\windows\sed.exe
2009-07-16 22:05 <DIR> --d----- c:\program files\Yahoo!
2009-07-14 02:37 <DIR> --d----- c:\program files\Trend Micro
2009-07-12 15:22 1,060,864 a------- c:\windows\system32\MFC71.dll
2009-07-12 15:22 499,712 a------- c:\windows\system32\MSVCP71.dll
2009-07-12 15:22 348,160 a------- c:\windows\system32\MSVCR71.dll
2009-07-12 01:20 3,072 a------- c:\windows\system32\drivers\audstub.sys
2009-07-12 01:19 57,472 a------- c:\windows\system32\drivers\redbook.sys
2009-07-12 01:19 23,040 a------- c:\windows\system32\drivers\mouclass.sys
2009-07-12 01:19 74,240 ac------ c:\windows\system32\dllcache\usbui.dll
2009-07-12 01:19 74,240 a------- c:\windows\system32\usbui.dll
2009-07-12 01:18 9,344 a------- c:\windows\system32\drivers\compbatt.sys
2009-07-12 01:18 14,080 a------- c:\windows\system32\drivers\battc.sys
2009-07-12 01:18 14,080 a------- c:\windows\system32\drivers\CmBatt.sys
2009-07-12 01:17 <DIR> --d----- c:\program files\common files\ODBC
2009-07-12 01:17 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-07-12 01:17 <DIR> --d--r-- c:\documents and settings\all users\Documents
2009-07-12 01:16 <DIR> --d----- C:\Documents and Settings
2009-07-12 01:15 261 a------- c:\windows\system32\$winnt$.inf
2009-07-12 01:12 <DIR> --d----- c:\program files\RomanWare
2009-07-12 00:56 <DIR> --d----- c:\program files\AVG
2009-07-11 23:22 <DIR> --ds---- c:\documents and settings\deepak\UserData
2009-07-11 23:19 <DIR> --d----- c:\program files\Synaptics
2009-07-11 23:09 <DIR> --d----- c:\program files\PaqTool
2009-07-11 23:05 <DIR> --d----- c:\program files\eLitecore
2009-07-11 22:58 <DIR> --d----- c:\docume~1\deepak\applic~1\Intel
2009-07-11 19:58 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-07-11 19:57 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-07-11 19:56 <DIR> --d----- c:\program files\common files\MSSoap
2009-07-11 19:55 <DIR> --d----- c:\program files\Online Services
2009-07-11 19:55 <DIR> --d----- c:\program files\Messenger
2009-07-11 19:55 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-07-11 19:54 <DIR> --d----- c:\program files\Windows NT
==================== Find3M ====================
2009-07-12 20:54 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-11 22:57 356,352 a------- c:\windows\system32\AegisI5Installer.exe
2009-07-11 22:57 21,393 a------- c:\windows\system32\drivers\AegisP.sys
2009-07-11 22:57 21,393 a------- c:\windows\AegisP.sys
2009-07-11 19:55 21,640 a------- c:\windows\system32\emptyregdb.dat
============= FINISH: 22:44:13.45 ===============
i just deleted it and removed the pendrive immediately, might be the pendrive is still infected and it will infect my laptop too, waiting for your help.
Combofix log
ComboFix 09-07-25.06 - Deepak 07/26/2009 22:37.5.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1646 [GMT 5.5:30]
Running from: c:\documents and settings\Deepak\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Deepak\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090725-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\system32\oauhyn.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CFNGIZ
-------\Service_cfngiz
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-25 14:42 . 2009-07-25 14:42 -------- d-----w- c:\documents and settings\Deepak\Local Settings\Application Data\Stardock
2009-07-24 09:23 . 2009-07-24 09:23 -------- d-----w- C:\vghd
2009-07-22 10:26 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-22 10:24 . 2009-07-22 10:26 -------- d--h--w- c:\windows\$hf_mig$
2009-07-19 19:32 . 2009-07-19 19:32 -------- d-----w- c:\documents and settings\Deepak\Application Data\Malwarebytes
2009-07-19 19:12 . 2009-07-13 08:06 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-19 19:12 . 2009-07-19 19:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-19 19:12 . 2009-07-13 08:06 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-19 19:12 . 2009-07-19 19:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-19 13:19 . 2009-07-19 13:19 -------- d-----w- c:\documents and settings\Deepak\Application Data\DivX
2009-07-19 06:14 . 2009-07-19 07:01 442400 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-16 16:38 . 2009-07-16 16:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-07-16 16:35 . 2009-07-16 16:36 -------- d-----w- c:\program files\Yahoo!
2009-07-13 21:07 . 2009-07-13 21:07 -------- d-----w- c:\program files\Trend Micro
2009-07-12 12:59 . 2009-07-12 12:59 1078 ----a-r- c:\documents and settings\Deepak\Application Data\Microsoft\Installer\{30BA50ED-0F32-421B-BC6A-132A03EFF299}\ARPPRODUCTICON.exe
2009-07-12 10:08 . 2009-07-12 10:08 12328 ----a-w- c:\documents and settings\Deepak\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-12 09:53 . 2009-02-05 21:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-07-12 09:53 . 2009-02-05 21:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-07-12 09:53 . 2009-02-05 21:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-07-12 09:52 . 2009-02-05 21:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-07-12 09:52 . 2009-02-05 21:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-07-12 09:52 . 2009-02-05 21:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-07-12 09:52 . 2009-02-05 21:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-07-12 09:52 . 2009-02-05 21:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-07-12 09:52 . 2009-02-05 21:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-07-12 09:52 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-07-12 09:52 . 2003-03-18 19:14 499712 ----a-w- c:\windows\system32\MSVCP71.dll
2009-07-12 09:52 . 2003-02-21 03:42 348160 ----a-w- c:\windows\system32\MSVCR71.dll
2009-07-12 09:52 . 2009-07-12 09:52 -------- d-----w- c:\program files\Alwil Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 07:01 . 2009-07-19 06:14 6260 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-12 15:24 . 2009-07-11 14:28 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-11 19:42 . 2009-07-11 19:42 -------- d-----w- c:\program files\RomanWare
2009-07-11 19:28 . 2009-07-11 19:28 0 ----a-w- c:\windows\nsreg.dat
2009-07-11 19:26 . 2009-07-11 19:26 -------- d-----w- c:\program files\AVG
2009-07-11 17:49 . 2009-07-11 17:49 -------- d-----w- c:\program files\Synaptics
2009-07-11 17:49 . 2009-07-11 17:49 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-11 17:39 . 2009-07-11 17:39 -------- d-----w- c:\program files\PaqTool
2009-07-11 17:35 . 2009-07-11 17:35 -------- d-----w- c:\program files\eLitecore
2009-07-11 17:28 . 2009-07-11 17:28 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Intel
2009-07-11 17:28 . 2009-07-11 17:28 -------- d-----w- c:\documents and settings\LocalService\Application Data\Intel
2009-07-11 17:28 . 2009-07-11 17:28 -------- d-----w- c:\documents and settings\Default User\Application Data\Intel
2009-07-11 17:28 . 2009-07-11 17:28 -------- d-----w- c:\documents and settings\Deepak\Application Data\Intel
2009-07-11 17:27 . 2009-07-11 17:27 356352 ----a-w- c:\windows\system32\AegisI5Installer.exe
2009-07-11 17:27 . 2009-07-11 17:27 21393 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-11 17:27 . 2009-07-11 17:27 21393 ----a-w- c:\windows\AegisP.sys
2009-07-11 17:27 . 2009-07-11 17:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2009-07-11 17:27 . 2009-07-11 17:20 -------- d-----w- c:\program files\Intel
2009-07-11 14:29 . 2009-07-11 14:29 -------- d-----w- c:\program files\microsoft frontpage
2009-07-11 14:25 . 2009-07-11 14:25 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-07-23 20:02 . 2009-07-11 19:28 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-16_19.19.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-26 17:10 . 2009-07-26 17:10 16384 c:\windows\Temp\Perflib_Perfdata_6d4.dat
+ 2009-07-20 12:38 . 2009-07-20 12:38 16384 c:\windows\Temp\Perflib_Perfdata_6d0.dat
+ 2009-07-22 10:24 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
+ 2009-07-22 18:11 . 2009-07-22 18:11 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-25 19:43 . 2008-03-19 05:38 36352 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Clock\SDPlugins\SDAnalogClock3.dll
+ 2004-08-04 00:56 . 2008-10-15 16:57 332800 c:\windows\system32\netapi32.dll
+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2004-08-03 23:15 . 2008-10-24 11:10 453632 c:\windows\system32\drivers\mrxsmb.sys
+ 2004-08-04 00:56 . 2008-10-15 16:57 332800 c:\windows\system32\dllcache\netapi32.dll
+ 2009-07-25 19:43 . 2008-02-14 10:00 439544 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Weather\SDPlugins\DXAxHost.dll
+ 2009-07-25 19:43 . 2008-03-20 06:18 740088 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Weather\Mustang Weather.exe
+ 2009-07-25 19:43 . 2008-02-14 10:00 421624 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Media Player\SDPlugins\DXPlayer.dll
+ 2009-07-25 19:43 . 2008-02-14 10:00 439544 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Media Player\SDPlugins\DXAxHost.dll
+ 2009-07-25 19:43 . 2008-03-19 05:42 746232 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Media Player\Mustang Media Player.exe
+ 2009-07-25 19:43 . 2008-02-14 10:00 439544 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Clock\SDPlugins\DXAxHost.dll
+ 2009-07-25 19:43 . 2008-03-19 05:40 767736 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Clock\Mustang Clock.exe
+ 2009-07-25 19:43 . 2008-02-14 10:00 439544 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Calendar\SDPlugins\DXAxHost.dll
+ 2009-07-25 19:43 . 2008-03-19 05:40 730872 c:\windows\Resources\Themes\Mustang\Gadgets\Mustang Calendar\Mustang Calendar.exe
+ 2009-07-22 10:26 . 2008-10-24 11:10 453632 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\system32\Macromed\Flash\NPSWF32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-10 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-10 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-08-10 137752]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 823296]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 974848]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 774233]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
24Online Client.lnk - c:\program files\eLitecore\Cyberoam Client for 24Online\CyberoamClient.exe [2004-5-31 249856]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 ENO;ENO;c:\windows\system32\drivers\ENO.sys [5/27/2004 6:51 PM 51564]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7/12/2009 3:22 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/12/2009 3:22 PM 20560]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\Deepak\LOCALS~1\Temp\ALSysIO.sys --> c:\docume~1\Deepak\LOCALS~1\Temp\ALSysIO.sys [?]
.
.
------- Supplementary Scan -------
.
TCP: {F294541A-6EC8-4BEA-B87A-373231CFEAA6} = 202.56.215.55,202.56.215.54
FF - ProfilePath - c:\documents and settings\Deepak\Application Data\Mozilla\Firefox\Profiles\mj97nr66.default\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-26 22:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\igfxsrvc.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-26 22:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-26 17:11
ComboFix2.txt 2009-07-23 18:15
ComboFix3.txt 2009-07-20 07:15
ComboFix4.txt 2009-07-19 06:10
ComboFix5.txt 2009-07-26 17:02
Pre-Run: 34,767,880,192 bytes free
Post-Run: 34,729,488,384 bytes free
161
DDS Log
DDS (Ver_09-06-26.01) - NTFSx86
Run by Deepak at 22:44:05.26 on Sun 07/26/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1647 [GMT 5.5:30]
AV: avast! antivirus 4.8.1335 [VPS 090725-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Deepak\Desktop\dds.pif
============== Pseudo HJT Report ===============
mURLSearchHooks: H - No File
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\24onli~1.lnk - c:\program files\elitecore\cyberoam client for 24online\CyberoamClient.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: {F294541A-6EC8-4BEA-B87A-373231CFEAA6} = 202.56.215.55,202.56.215.54
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\deepak\applic~1\mozilla\firefox\profiles\mj97nr66.default\
============= SERVICES / DRIVERS ===============
R0 ENO;ENO;c:\windows\system32\drivers\ENO.sys [2004-5-27 51564]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-7-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-7-12 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-7-12 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-7-12 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-7-12 352920]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\deepak\locals~1\temp\alsysio.sys --> c:\docume~1\deepak\locals~1\temp\ALSysIO.sys [?]
=============== Created Last 30 ================
2009-07-24 14:53 <DIR> --d----- C:\vghd
2009-07-22 15:56 453,632 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-07-22 15:54 <DIR> --d-h--- c:\windows\$hf_mig$
2009-07-20 01:02 <DIR> --d----- c:\docume~1\deepak\applic~1\Malwarebytes
2009-07-20 00:42 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-20 00:42 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-20 00:42 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-20 00:42 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-19 11:44 442,400 a--sh--- c:\windows\system32\drivers\fidbox.dat
2009-07-19 11:44 6,260 a--sh--- c:\windows\system32\drivers\fidbox.idx
2009-07-17 00:49 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-07-17 00:47 <DIR> a-dshr-- C:\cmdcons
2009-07-17 00:40 219,648 a------- c:\windows\PEV.exe
2009-07-17 00:40 161,792 a------- c:\windows\SWREG.exe
2009-07-17 00:40 98,816 a------- c:\windows\sed.exe
2009-07-16 22:05 <DIR> --d----- c:\program files\Yahoo!
2009-07-14 02:37 <DIR> --d----- c:\program files\Trend Micro
2009-07-12 15:22 1,060,864 a------- c:\windows\system32\MFC71.dll
2009-07-12 15:22 499,712 a------- c:\windows\system32\MSVCP71.dll
2009-07-12 15:22 348,160 a------- c:\windows\system32\MSVCR71.dll
2009-07-12 01:20 3,072 a------- c:\windows\system32\drivers\audstub.sys
2009-07-12 01:19 57,472 a------- c:\windows\system32\drivers\redbook.sys
2009-07-12 01:19 23,040 a------- c:\windows\system32\drivers\mouclass.sys
2009-07-12 01:19 74,240 ac------ c:\windows\system32\dllcache\usbui.dll
2009-07-12 01:19 74,240 a------- c:\windows\system32\usbui.dll
2009-07-12 01:18 9,344 a------- c:\windows\system32\drivers\compbatt.sys
2009-07-12 01:18 14,080 a------- c:\windows\system32\drivers\battc.sys
2009-07-12 01:18 14,080 a------- c:\windows\system32\drivers\CmBatt.sys
2009-07-12 01:17 <DIR> --d----- c:\program files\common files\ODBC
2009-07-12 01:17 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-07-12 01:17 <DIR> --d--r-- c:\documents and settings\all users\Documents
2009-07-12 01:16 <DIR> --d----- C:\Documents and Settings
2009-07-12 01:15 261 a------- c:\windows\system32\$winnt$.inf
2009-07-12 01:12 <DIR> --d----- c:\program files\RomanWare
2009-07-12 00:56 <DIR> --d----- c:\program files\AVG
2009-07-11 23:22 <DIR> --ds---- c:\documents and settings\deepak\UserData
2009-07-11 23:19 <DIR> --d----- c:\program files\Synaptics
2009-07-11 23:09 <DIR> --d----- c:\program files\PaqTool
2009-07-11 23:05 <DIR> --d----- c:\program files\eLitecore
2009-07-11 22:58 <DIR> --d----- c:\docume~1\deepak\applic~1\Intel
2009-07-11 19:58 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-07-11 19:57 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-07-11 19:56 <DIR> --d----- c:\program files\common files\MSSoap
2009-07-11 19:55 <DIR> --d----- c:\program files\Online Services
2009-07-11 19:55 <DIR> --d----- c:\program files\Messenger
2009-07-11 19:55 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-07-11 19:54 <DIR> --d----- c:\program files\Windows NT
==================== Find3M ====================
2009-07-12 20:54 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-11 22:57 356,352 a------- c:\windows\system32\AegisI5Installer.exe
2009-07-11 22:57 21,393 a------- c:\windows\system32\drivers\AegisP.sys
2009-07-11 22:57 21,393 a------- c:\windows\AegisP.sys
2009-07-11 19:55 21,640 a------- c:\windows\system32\emptyregdb.dat
============= FINISH: 22:44:13.45 ===============