-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, June 26, 2008 9:05:12 AM
Operating System: Microsoft Windows Vista Home Edition, Service Pack 1 (Build 6001)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/06/2008
Kaspersky Anti-Virus database records: 884699
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 180925
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 02:02:10
Infected Object Name / Virus Name / Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\Program Files\CA\SharedComponents\PPRT\logs\2008-06-25.csv Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bb9924fb7e0f985a566e16ddde8650f1_63a35456-f54e-4e79-8ab9-a6093afc8bb9 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cd62b96cb2f6b94949614e73c287cbc7_63a35456-f54e-4e79-8ab9-a6093afc8bb9 Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.296.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.296.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010008.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000C.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010019.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001B.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001C.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001D.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001E.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy667.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfD6CE.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfD6EE.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Windows\UsrClass.dat{9a8e8da8-3fca-11dd-ab92-001bfca4bc3d}.TM.blf Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Windows\UsrClass.dat{9a8e8da8-3fca-11dd-ab92-001bfca4bc3d}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\MJK\AppData\Local\Microsoft\Windows\UsrClass.dat{9a8e8da8-3fca-11dd-ab92-001bfca4bc3d}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\JETCB2F.tmp Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\JETCC19.tmp Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\JETCC57.tmp Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\JETD212.tmp Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\JETD34A.tmp Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\~DF5983.tmp Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\~DF6D57.tmp Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\~DF91A2.tmp Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\~DFA6FE.tmp Object is locked skipped
C:\Users\MJK\AppData\Local\Temp\~DFB6D2.tmp Object is locked skipped
C:\Users\MJK\AppData\Roaming\CallingID\CallingID.ldb Object is locked skipped
C:\Users\MJK\AppData\Roaming\CallingID\CallingID.mdb Object is locked skipped
C:\Users\MJK\AppData\Roaming\CallingID\CIDLight.ldb Object is locked skipped
C:\Users\MJK\AppData\Roaming\CallingID\CIDLight.mdb Object is locked skipped
C:\Users\MJK\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\MJK\ntuser.dat Object is locked skipped
C:\Users\MJK\ntuser.dat.LOG1 Object is locked skipped
C:\Users\MJK\ntuser.dat.LOG2 Object is locked skipped
C:\Users\MJK\ntuser.dat{9a8e8da6-3fca-11dd-ab92-001bfca4bc3d}.TM.blf Object is locked skipped
C:\Users\MJK\ntuser.dat{9a8e8da6-3fca-11dd-ab92-001bfca4bc3d}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\MJK\ntuser.dat{9a8e8da6-3fca-11dd-ab92-001bfca4bc3d}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat{9a8e8da4-3fca-11dd-ab92-001bfca4bc3d}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat{9a8e8da4-3fca-11dd-ab92-001bfca4bc3d}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat{9a8e8da4-3fca-11dd-ab92-001bfca4bc3d}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{9a8e8da2-3fca-11dd-ab92-001bfca4bc3d}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{9a8e8da2-3fca-11dd-ab92-001bfca4bc3d}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat{9a8e8da2-3fca-11dd-ab92-001bfca4bc3d}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\components Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\default Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\sam Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\security Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\software Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\system Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9a8e8d97-3fca-11dd-ab92-001bfca4bc3d}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9a8e8d97-3fca-11dd-ab92-001bfca4bc3d}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9a8e8d97-3fca-11dd-ab92-001bfca4bc3d}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9a8e8d97-3fca-11dd-ab92-001bfca4bc3d}.TxR.blf Object is locked skipped
C:\Windows\System32\drivers\core.cache.dsk Object is locked skipped
C:\Windows\System32\drivers\KmxFilee.sys Object is locked skipped
C:\Windows\System32\LogFiles\HTTPERR\httperr1.log Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.003 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Metrics.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
Scan process completed.
ComboFix 08-06-20.4 - MJK 2008-06-26 9:20:12.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1036 [GMT -4:00]
Running from: C:\Users\MJK\Desktop\ComboFix.exe
Command switches used :: C:\Users\MJK\Desktop\CFScript.txt
FILE ::
C:\Windows\System32\drivers\core.cache.dsk
C:\Windows\System32\TmpA5608532
C:\Windows\System32\TmpA5616332
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\tn3
C:\Windows\System32\drivers\core.cache.dsk . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-05-26 to 2008-06-26 )))))))))))))))))))))))))))))))
.
2008-06-26 09:26 . 2008-06-26 09:26 <DIR> d-------- C:\Temp\tn3
2008-06-25 15:44 . 2008-06-25 15:44 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-06-25 15:44 . 2008-06-25 15:44 <DIR> d-------- C:\ProgramData\Kaspersky Lab
2008-06-22 15:46 . 2008-06-22 15:46 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-22 10:16 . 2008-06-22 10:16 167,976 --------- C:\Windows\System32\drivers\core.cache.dsk
2008-06-21 15:50 . 2008-06-21 15:50 85,888 --a------ C:\Windows\System32\drivers\KmxFilee.sys
2008-06-21 15:44 . 2008-05-29 09:28 28,416 --a------ C:\Windows\System32\uxtuneup.dll
2008-06-21 15:44 . 2008-05-29 09:28 16,640 --a------ C:\Windows\System32\authuitu.dll
2008-06-21 15:43 . 2008-06-21 15:43 <DIR> d-------- C:\ProgramData\TuneUp Software
2008-06-21 15:43 . 2008-06-21 15:43 355,584 --a------ C:\Windows\System32\TuneUpDefragService.exe
2008-06-21 13:54 . 2008-06-21 13:54 <DIR> d-------- C:\Users\MJK\AppData\Roaming\WinBatch
2008-06-21 13:32 . 2008-06-21 13:33 <DIR> d-------- C:\Program Files\QuickTime
2008-06-19 22:46 . 2008-06-20 09:25 <DIR> d-------- C:\Users\MJK\dwhelper
2008-06-19 15:17 . 2008-06-25 00:47 245,526,712 --a------ C:\Windows\MEMORY.DMP
2008-06-17 18:58 . 2008-06-17 18:58 <DIR> d-------- C:\Windows\Sun
2008-06-16 22:55 . 2008-06-16 22:55 <DIR> d-------- C:\Program Files\Java
2008-06-16 22:46 . 2008-06-16 22:46 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-14 13:47 . 2008-04-23 00:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-06-14 13:47 . 2008-04-23 00:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-06-14 13:47 . 2008-04-23 00:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-14 13:47 . 2008-04-23 00:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-11 18:48 . 2008-04-24 22:12 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-06-11 18:48 . 2008-04-26 04:08 1,314,816 --a------ C:\Windows\System32\quartz.dll
2008-06-11 18:48 . 2008-04-25 00:35 826,880 --a------ C:\Windows\System32\wininet.dll
2008-06-11 18:48 . 2008-05-09 21:33 113,664 --a------ C:\Windows\System32\drivers\rmcast.sys
2008-06-08 17:47 . 2008-06-25 10:18 <DIR> d-------- C:\Program Files\Trillian
2008-06-07 21:41 . 2008-06-07 21:41 <DIR> d-------- C:\Users\MJK\AppData\Roaming\Trillian
2008-06-07 21:41 . 2008-06-07 21:41 99 --a------ C:\Windows\(null)toolkit.ini
2008-05-30 15:27 . 2008-05-30 15:27 <DIR> d-------- C:\ProgramData\acccore
2008-05-28 07:23 . 2008-03-07 22:08 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-28 07:23 . 2008-03-08 00:21 1,695,744 --a------ C:\Windows\System32\gameux.dll
2008-05-27 10:50 . 2008-05-27 10:50 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 --a------ C:\Windows\System32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-26 13:23 64 ----a-w C:\Windows\system32\drivers\kmxcfg.u2k7
2008-06-26 13:23 64 ----a-w C:\Windows\system32\drivers\kmxcfg.u2k6
2008-06-26 13:23 64 ----a-w C:\Windows\system32\drivers\kmxcfg.u2k5
2008-06-26 13:23 64 ----a-w C:\Windows\system32\drivers\kmxcfg.u2k4
2008-06-26 13:23 64 ----a-w C:\Windows\system32\drivers\kmxcfg.u2k3
2008-06-26 13:23 64 ----a-w C:\Windows\system32\drivers\kmxcfg.u2k2
2008-06-26 13:23 64 ----a-w C:\Windows\system32\drivers\kmxcfg.u2k1
2008-06-26 13:23 421,516 ----a-w C:\Windows\system32\drivers\kmxcfg.u2k0
2008-06-26 13:05 --------- d-----w C:\Users\MJK\AppData\Roaming\CallingID
2008-06-25 14:40 --------- d-----w C:\Users\MJK\AppData\Roaming\Sony
2008-06-25 04:52 --------- d-----w C:\ProgramData\Roxio
2008-06-25 04:19 --------- d-----w C:\Users\MJK\AppData\Roaming\Publish Providers
2008-06-23 19:44 --------- d-----w C:\Users\MJK\AppData\Roaming\NetMedia Providers
2008-06-22 20:56 --------- d-----w C:\Users\MJK\AppData\Roaming\uTorrent
2008-06-21 19:43 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-06-21 19:43 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 19:38 --------- d-----w C:\Program Files\Sony
2008-06-21 19:37 --------- d-----w C:\Program Files\Vstplugins
2008-06-21 19:37 --------- d-----w C:\Program Files\Roger Nichols Digital, Inc
2008-06-21 19:36 --------- d-----w C:\Program Files\iZotope
2008-06-21 19:36 --------- d-----w C:\Program Files\Hewlett-Packard
2008-06-13 21:00 91,376 ----a-w C:\Windows\System32\isafprod.dll
2008-06-13 21:00 32,240 ----a-w C:\Windows\system32\drivers\vetmonnt.sys
2008-06-13 21:00 26,352 ----a-w C:\Windows\system32\drivers\vet-filt.sys
2008-06-13 21:00 21,488 ----a-w C:\Windows\system32\drivers\vetfddnt.sys
2008-06-13 21:00 21,104 ----a-w C:\Windows\system32\drivers\vet-rec.sys
2008-06-12 14:55 --------- d-----w C:\Program Files\Windows Mail
2008-06-09 00:44 --------- d-----w C:\Program Files\Common Files\AOL
2008-06-08 01:48 --------- d-----w C:\Users\MJK\AppData\Roaming\Aim
2008-06-04 19:24 880,560 ----a-w C:\Windows\system32\drivers\vetefile.sys
2008-06-04 19:24 108,368 ----a-w C:\Windows\system32\drivers\veteboot.sys
2008-05-31 01:04 --------- d-----w C:\ProgramData\Creative
2008-05-30 19:27 --------- d-----w C:\ProgramData\Viewpoint
2008-05-30 19:27 --------- d-----w C:\Program Files\Viewpoint
2008-05-25 00:39 --------- d-----w C:\Program Files\Native Instruments
2008-05-25 00:39 --------- d-----w C:\Program Files\Common Files\Native Instruments
2008-05-25 00:09 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-05-25 00:06 --------- d-----w C:\Program Files\Microsoft IntelliType Pro
2008-05-20 00:50 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-19 01:57 --------- d-----w C:\ProgramData\Creative Labs
2008-05-17 17:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-17 17:11 --------- d-----w C:\Program Files\Creative
2008-05-17 17:11 --------- d-----w C:\Program Files\Common Files\Creative Labs Shared
2008-05-17 02:42 409,600 ----a-w C:\Windows\System32\wrap_oal.dll
2008-05-17 02:42 114,688 ----a-w C:\Windows\System32\OpenAL32.dll
2008-05-15 13:34 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-03 13:31 --------- d-----w C:\Program Files\Shareaza
2008-04-05 15:20 174 --sha-w C:\Program Files\desktop.ini
2008-04-05 14:41 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-05 14:41 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2007-08-22 23:26 0 ----a-w C:\Users\MJK\AppData\Roaming\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-06-25_14.53.09.65 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-25 18:46:23 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-06-26 13:25:28 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-06-25 18:46:25 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-06-26 13:25:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-06-25 18:46:25 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-06-26 13:25:29 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-06-25 18:47:03 212,992 ----a-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-06-26 13:26:09 212,992 ----a-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
- 2008-06-25 18:47:03 208,896 ----a-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-06-26 13:26:09 208,896 ----a-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
- 2008-06-25 00:11:44 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-26 00:19:02 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-06-25 00:11:44 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-26 00:19:02 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-25 00:11:44 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-26 00:19:02 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2005-05-24 16:27:16 213,048 ----a-w C:\Windows\System32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\Windows\System32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\Windows\System32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-06-25 15:23:58 108,884 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-06-26 00:25:03 108,884 ----a-w C:\Windows\System32\perfc009.dat
- 2008-06-25 15:23:58 633,886 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-06-26 00:25:03 633,886 ----a-w C:\Windows\System32\perfh009.dat
- 2008-06-25 15:20:56 13,140 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3933803197-207350744-2630264868-1000_UserData.bin
+ 2008-06-26 00:20:10 13,312 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3933803197-207350744-2630264868-1000_UserData.bin
- 2008-06-25 15:20:56 54,828 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-06-26 00:20:10 54,844 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-06-25 15:20:55 48,072 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-06-25 18:48:26 48,244 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 09:42 65536]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 18:22 184320]
"SPIRunE"="SPIRunE.dll" [2007-05-09 05:07 18432 C:\Windows\System32\SpiRunE.dll]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2008-05-22 09:30 181512]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-06-13 17:00 234736]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-04-15 08:45 771336]
"cafw"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-04-15 08:45 771336]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-04-15 08:45 173320]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 21:15 86016]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 21:15 81920]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 15:13 988584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\LinkAdvisor\CIDLinkAdvisor.dll [2007-10-15 21:40 1373624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll 2007-01-31 14:00 79368 C:\Windows\System32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
--a------ 2005-12-18 14:18 307200 C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-17 02:11 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2008-01-19 03:33 202240 C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
"ehTray.exe"=C:\Windows\ehome\ehTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NvMediaCenter"=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3933803197-207350744-2630264868-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A8A9EA7F-5D5D-452D-8F21-16B71E413447}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{8799E948-6BD4-42DB-ABFD-46B3264B2F4D}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C46C8BD1-E9C6-45C1-B8F7-6DD3E6258472}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{AEF99B29-A69B-47F4-83B2-B00647F0D548}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{B70631F6-7276-4C9E-9F71-B845936CDA20}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{376EFD73-E19E-4193-A369-7772EB787EB9}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{E068B7BF-514E-4C2B-94DA-7F9AABE1F08E}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{8536C8D6-F1A5-454B-BF7E-9C329C889C2D}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{CD585463-3EED-4683-9FFF-A9617556C877}"= UDP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
"{CC66FF51-993C-4ADE-B8F2-BE2041C71880}"= TCP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
"{B487B041-E4F3-4416-A489-467AF765B411}"= UDP:64408:uTorrent
"{20B32E15-8877-48B3-BF78-59569772B801}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{EF3DCCDA-07EA-42B5-AE2D-2A107251A2E7}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{F928D369-F867-4A72-90D6-020AAF340BD0}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{02F4F4D3-A473-4B8A-890C-6C0422BE351C}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{8C0CC9A5-2DF7-4273-8678-5B6DEB13A028}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{8E673369-324C-40B5-94E0-03513BE41295}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{522A07B6-C4D4-424B-9C78-B6A4FEF23941}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{AC587733-4344-4D35-85F2-3CF55A464531}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{F8340991-7727-443D-845B-91A9EDB64E96}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{89BFEF88-0FB4-4836-BD3C-52EC31F737EE}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{1BAEC33F-4D61-4F82-B220-347FE1562490}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{948633ED-46A1-4369-85CD-DD78BAADD0E4}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{D01B513B-34E6-464F-802E-FABBB36F96EF}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{61F232C3-C8B9-40D3-870E-09605B180C49}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{729C877A-DF30-4752-BCCB-B38968B5544C}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{5DB56F76-2528-4F00-BA21-20B476018121}"= UDP:C:\Program Files\AIM6\aim6.exe:AIM
"{0EEAE749-0EEE-48F3-9731-0F643E0B35EC}"= TCP:C:\Program Files\AIM6\aim6.exe:AIM
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R0 KmxFw;KmxFw;C:\Windows\system32\DRIVERS\kmxfw.sys [2007-10-18 14:28]
R1 KmxAgent;KmxAgent;C:\Windows\system32\DRIVERS\kmxagent.sys [2007-03-21 18:49]
R1 KmxFile;KmxFile;C:\Windows\system32\DRIVERS\KmxFile.sys [2007-03-16 03:39]
R1 KmxFilter;HIPS Core Filter Driver;C:\Windows\system32\DRIVERS\KmxFilter.sys [2007-09-05 11:50]
R2 CTAudSvcService;Creative Audio Service;C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2007-11-26 09:22]
R2 KmxCF;KmxCF;C:\Windows\system32\DRIVERS\KmxCF.sys [2007-10-18 10:46]
R2 KmxSbx;KmxSbx;C:\Windows\system32\DRIVERS\KmxSbx.sys [2007-11-02 04:54]
R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-10-04 09:23]
R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-10-18 09:39]
R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2007-03-05 18:36]
R2 UxTuneUp;TuneUp Theme Extension;C:\Windows\System32\svchost.exe [2008-01-19 03:33]
R3 CLEDX;Team H2O CLEDX service;C:\Windows\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
R3 KmxCfg;KmxCfg;C:\Windows\system32\DRIVERS\kmxcfg.sys [2007-09-12 12:02]
R3 netr73;Linksys Compact Wireless-G USB Adapter Driver for Vista;C:\Windows\system32\DRIVERS\WUSB54GCx86.sys [2007-03-12 10:12]
R3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2008-04-15 08:45]
R3 t3;Sound Blaster X-Fi Xtreme Audio (Vista);C:\Windows\system32\drivers\t3.sys [2008-01-29 03:03]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;"C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe" [2008-05-17 13:11]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.exe [2008-06-21 15:43]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{181E34DA-8AAF-51A4-113B-C5C8DE522977}]
C:\Windows\system32:wupdate.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-25 21:09:32 C:\Windows\Tasks\User_Feed_Synchronization-{96539F52-3FCE-4368-94D4-69740D029F39}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-26 09:28:16
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\cappactiveprotection.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\wbem\WMIADAP.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovep.exe
C:\Program Files\CA\CA Internet Security Suite\ccupdate\ccupdate.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-06-26 9:31:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-26 13:31:39
ComboFix2.txt 2008-06-25 18:55:34
ComboFix3.txt 2008-06-25 12:49:02
Pre-Run: 53,362,089,984 bytes free
Post-Run: 53,327,847,424 bytes free
310 --- E O F --- 2008-06-24 19:28:27