the Combofix log:
ComboFix 09-08-22.06 - Lonny Chant 08/23/2009 11:01.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1610 [GMT -4:00]
Running from: c:\documents and settings\Lonny Chant\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Lonny Chant\Desktop\CFScript.txt
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
FILE ::
"c:\documents and settings\Lonny Chant\Application Data\.BitTornado\moha.exe"
"c:\documents and settings\Lonny Chant\Application Data\acccore\reniga.dll"
"c:\documents and settings\Lonny Chant\Application Data\Adobe\socks32.exe"
"c:\documents and settings\Lonny Chant\Application Data\AdobeUM\horsi.exe"
"c:\documents and settings\Lonny Chant\Application Data\Ahead\megalon.exe"
"c:\windows\System32\fckyzqsl.tcg"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lonny Chant\Application Data\.BitTornado\moha.exe
c:\documents and settings\Lonny Chant\Application Data\acccore\reniga.dll
c:\documents and settings\Lonny Chant\Application Data\Adobe\socks32.exe
c:\documents and settings\Lonny Chant\Application Data\AdobeUM\horsi.exe
c:\documents and settings\Lonny Chant\Application Data\Ahead\megalon.exe
c:\documents and settings\Lonny Chant\Application Data\Azureus
c:\documents and settings\Lonny Chant\Application Data\Azureus\.certs
c:\documents and settings\Lonny Chant\Application Data\Azureus\.keystore
c:\documents and settings\Lonny Chant\Application Data\Azureus\.lock
c:\documents and settings\Lonny Chant\Application Data\Azureus\active\3ABA38C3B576DE59531F45B332CCA4442BB129FA.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\active\3C2BA09E1624D7C14AAEE5ED004269311A98B512.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\active\4438AF41E59C98EED6CDE27F5CC4D3E355F73063.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\active\6B317A643211A899233B451452BFB4F551038E3E.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\active\A948D818834E3F34896A61EEE2361871704C1968.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\active\cache.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\azureus.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\azureus.statistics
c:\documents and settings\Lonny Chant\Application Data\Azureus\banips.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\cnetworks.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\devices.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\dht\general.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\dht\version.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\downloads.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\filters.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\friends.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\ipfilter.cache
c:\documents and settings\Lonny Chant\Application Data\Azureus\logs\MetaSearch_Engine_3.txt
c:\documents and settings\Lonny Chant\Application Data\Azureus\metasearch.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\net\pm_22773.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.7.4.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.7.4.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.9.0.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.9.0.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.9.10.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.9.10.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.9.11.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.9.11.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.9.6.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_1.9.6.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.11.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.11.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.14.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.14.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.16.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.16.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.30.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.30.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.32.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.32.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.34.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.0.34.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.1.02.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azemp_2.1.02.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\azmplay.exe
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\cp1250-a.raw
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\cp1250-b.raw
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\font.desc
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\libInfoGetter.dll
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\osd-mplayer-a.raw
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\osd-mplayer-b.raw
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_1.7.4
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_1.9.0
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_1.9.10
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_1.9.11
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_1.9.6
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_2.0.11
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_2.0.14
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_2.0.16
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_2.0.30
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_2.0.32
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_2.0.34
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azemp\plugin.properties_2.1.02
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azump\azump_1.2.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azump\azump_1.2.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azump\azump_1.3.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azump\azump_1.3.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azump\mplayer.exe
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azump\mplayer\config
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.2.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.2.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.3.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.3.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.6.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.6.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.7.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.1.7.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.0.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.0.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.1.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.1.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.17.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.17.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.2.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.2.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.5.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.5.zip
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\cd.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.2
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.3
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.6
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.1.7
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.0
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.1
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.17
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.2
c:\documents and settings\Lonny Chant\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.5
c:\documents and settings\Lonny Chant\Application Data\Azureus\sidebarauto.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\01FE0E4954FEEB299706.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\0208EEB906A1C63F97E2.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\0FE2857420B40A53BB77.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\12533BF9649105ABA27A.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\1603EF58DAA24E05E927.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\1D2D9FBC3F4BE8AA689D.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\24DB0521CDEC3ACE7E8C.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\28CF14B604BFE173EEFF.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\292D07370EA3783CDCAC.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\29A2E7CB5E7A69DBBE14.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\2DCFAB8F832477D02694.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\2F7D51E79B34BE84F742.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\3C1C33756A83CC05D595.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\487A4B88740420E32C87.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\4964C136A88C465A6B48.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\4B713E793017BE7BA43A.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\4CD6D96573CE7093FB98.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\4F2AA8C2D919E9835A62.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\52C6D09A02BBB590C252.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\59A6E5D794A9DFCD6CDF.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\62E0DD046B0A2450A807.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\632A20E73961F1C133F2.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\65CE3C46ACE1B29F7AF8.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\6F5910EA3FFE2EA04ABF.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\71C6685E772F650EA387.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\72D2F5BA4A68FA6F677A.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\743517466E51A760F1BF.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\74F7267F1BCBC66CB79C.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\79D82923B992917F8430.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\79E766BACEC15D14BEA9.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\7D80FF0229178E1AD2BD.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\8208605FEAE769DF8C5B.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\829E59C40EFFE22EB406.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\83F9D7CFBA5E7496ACC5.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\88DA602C72BB0AB9CEE8.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\8A8138032CEB4BAFDDBC.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\8BF158E23CC6F3B41DF9.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\93B716386602D52C6EB7.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\95985978467DA9688755.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\9E68932BDE46973BFAD5.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\A36AB2DCB4226BA0F649.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\A37CED700C6A8093072F.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\A4C4F5D3B481321E52AF.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\A7EF32FC85BCF1692DDB.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\A8C1F452C6DA7C51AA2B.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\B23FF1607C78876627F3.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\B9F9824CB0A991DE3AC4.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\BA42C1C871ADA5B254DA.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\BAD9AC808DA5DC699651.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\C04565C3BABED3846AE4.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\C61A720916E29A0837B2.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\C868FF325124E3D0D58F.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\CE275B7D9043458D6329.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\D2D5ED50888A83E4C5DD.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\D2FC0BF3FD78ED958712.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\D36FC2A487705C854BDA.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\D5B735BDEA2EE95A3DFF.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\DB8EBA0A8243FAC1DD16.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\DCD20AB6684A16AA1475.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\E143495E02618735CB40.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\E267584D36198A287181.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\E32C595A861BADB257CC.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\E7CE62A3124A6E9AD402.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\F37F1C2264BA31BFB3E3.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subs\FC5CC391DA4BA78C3961.vuze
c:\documents and settings\Lonny Chant\Application Data\Azureus\subscriptions.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\tables.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\tmp\AZU36328.tmp\patch.jar
c:\documents and settings\Lonny Chant\Application Data\Azureus\torrents\Angel_complete_seasons_1_through_5.3351072.TPB [mininova].torrent
c:\documents and settings\Lonny Chant\Application Data\Azureus\torrents\Enchanted__2007__DVDRip-1.torrent
c:\documents and settings\Lonny Chant\Application Data\Azureus\torrents\Firefly_Series_200_2_DVDRip_x264.torrent
c:\documents and settings\Lonny Chant\Application Data\Azureus\torrents\Macromedia Flash 5 + Serial.zip [mininova].torrent
c:\documents and settings\Lonny Chant\Application Data\Azureus\torrents\NIN_-_THE_UNRELEASED_________________BEHIND_THE_SCENES_OF_CLOSER.4226814.TPB-1.torrent
c:\documents and settings\Lonny Chant\Application Data\Azureus\torrents\sims_2_all_expansions__november_9_2007_630462484091_913.torrent
c:\documents and settings\Lonny Chant\Application Data\Azureus\torrents\This.Film.Has.Not.Yet.Been.Rated.2006.DvdRip.eng.avi.4078123.TPB.torrent
c:\documents and settings\Lonny Chant\Application Data\Azureus\tracker.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\unsentdata.config
c:\documents and settings\Lonny Chant\Application Data\Azureus\update.properties
c:\documents and settings\Lonny Chant\Application Data\Azureus\v3.Friends.dat
c:\documents and settings\Lonny Chant\Application Data\Azureus\VuzeActivities.config
c:\windows\Fonts\FRE3OF9X.TTF
c:\windows\Fonts\FREE3OF9.TTF
c:\windows\Fonts\GUNSHIP2.TTF
c:\windows\smproflt.dll
c:\windows\wpd99.drv
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AASTRAMS
-------\Legacy_FCKYZQSL
-------\Service_Aastrams
-------\Service_FCKYZQSL
((((((((((((((((((((((((( Files Created from 2009-07-23 to 2009-08-23 )))))))))))))))))))))))))))))))
.
2009-08-19 13:23 . 2009-08-19 13:23 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-19 13:23 . 2009-08-19 13:23 152576 ----a-w- c:\documents and settings\Lonny Chant\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-19 12:42 . 2009-08-19 12:42 -------- d-----w- c:\program files\ERUNT
2009-08-19 10:33 . 2009-08-19 10:33 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-08-19 02:30 . 2009-08-19 02:32 -------- d-----w- c:\program files\Malwar
2009-08-18 21:03 . 2009-08-18 21:03 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-18 17:25 . 2009-08-18 17:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-18 12:06 . 2009-08-18 12:06 -------- d-----w- C:\rsit
2009-08-18 12:02 . 2009-08-18 12:02 -------- d-----w- c:\documents and settings\Lonny Chant\.SunDownloadManager
2009-08-16 00:47 . 2009-08-16 00:47 -------- d-----w- c:\program files\Trend Micro
2009-08-14 14:28 . 2009-08-14 14:45 -------- d-----w- c:\documents and settings\Lonny Chant\Application Data\IObit
2009-08-14 14:28 . 2009-08-14 14:28 -------- d-----w- c:\program files\IObit
2009-08-14 11:40 . 2009-08-14 11:40 3942047 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-14 11:40 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-14 11:40 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-12 18:49 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-23 15:08 . 2008-03-07 08:49 -------- d-----w- c:\documents and settings\Lonny Chant\Application Data\Ahead
2009-08-23 15:08 . 2005-03-08 19:14 -------- d-----w- c:\documents and settings\Lonny Chant\Application Data\AdobeUM
2009-08-23 15:08 . 2007-03-13 20:47 -------- d-----w- c:\documents and settings\Lonny Chant\Application Data\acccore
2009-08-23 15:08 . 2005-03-22 17:02 -------- d-----w- c:\documents and settings\Lonny Chant\Application Data\.BitTornado
2009-08-23 13:26 . 2006-05-29 23:24 -------- d-----w- c:\program files\bl
2009-08-19 13:23 . 2005-03-14 03:19 -------- d-----w- c:\program files\Java
2009-08-19 13:17 . 2007-07-04 00:46 -------- d-----w- c:\program files\Steam
2009-08-18 20:43 . 2004-01-03 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-18 20:42 . 2008-03-11 11:54 -------- d-----w- c:\program files\CCleaner
2009-08-18 20:23 . 2005-02-16 04:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-08-18 15:15 . 2009-08-18 15:56 11264 ----a-w- c:\windows\Internet Logs\xDB5.tmp
2009-08-18 15:15 . 2009-08-18 15:56 3396608 ----a-w- c:\windows\Internet Logs\xDB6.tmp
2009-08-18 13:21 . 2009-08-18 13:52 13824 ----a-w- c:\windows\Internet Logs\xDB3.tmp
2009-08-18 13:21 . 2009-08-18 13:52 3396096 ----a-w- c:\windows\Internet Logs\xDB4.tmp
2009-08-18 13:08 . 2009-08-18 13:21 3396096 ----a-w- c:\windows\Internet Logs\xDB2.tmp
2009-08-18 13:08 . 2009-08-18 13:21 44032 ----a-w- c:\windows\Internet Logs\xDB1.tmp
2009-08-17 10:34 . 2005-02-16 15:00 48622851 -c--a-w- c:\windows\Internet Logs\tvDebug.zip
2009-08-15 23:50 . 2002-10-04 20:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-15 22:24 . 2009-08-15 22:24 3391488 ----a-w- c:\windows\Internet Logs\xDB9A.tmp
2009-08-15 22:24 . 2009-08-15 22:24 25600 ----a-w- c:\windows\Internet Logs\xDB99.tmp
2009-08-15 20:48 . 2009-08-15 20:48 3390976 ----a-w- c:\windows\Internet Logs\xDB72.tmp
2009-08-15 20:48 . 2009-08-15 20:48 3000832 ----a-w- c:\windows\Internet Logs\xDB71.tmp
2009-08-14 14:44 . 2008-06-10 18:33 -------- d-----w- c:\program files\RightMark Memory Analyzer
2009-08-14 14:44 . 2008-03-04 14:35 -------- d-----w- c:\documents and settings\Lonny Chant\Application Data\Vso
2009-08-14 14:44 . 2007-12-24 15:30 -------- d-----w- c:\program files\EarthLink TotalAccess
2009-08-14 14:44 . 2003-03-07 23:56 -------- d-----w- c:\program files\DivX
2009-08-14 14:44 . 2002-10-04 20:52 -------- d-----w- c:\program files\MUSICMATCH
2009-08-14 11:41 . 2009-05-30 11:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-05 09:01 . 2009-02-05 03:27 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-21 21:40 . 2007-10-27 18:03 -------- d-----w- c:\program files\iTunes
2009-07-21 21:40 . 2006-04-09 21:36 -------- d-----w- c:\program files\iPod
2009-07-21 21:40 . 2009-02-19 21:10 -------- d-----w- c:\program files\Common Files\Apple
2009-07-21 21:31 . 2009-07-21 21:31 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-17 19:01 . 2009-02-05 03:28 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 14:08 . 2004-09-22 23:46 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-05 07:01 . 2009-07-05 07:01 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-05 07:01 . 2009-07-05 07:01 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-06-29 16:12 . 2009-02-05 03:27 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-02-05 03:28 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 ------w- c:\windows\system32\ieencode.dll
2009-06-16 14:36 . 2004-08-29 21:19 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2001-08-18 11:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2009-02-05 03:27 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-11 15:44 . 2002-11-21 21:00 209440 -c--a-w- c:\documents and settings\Lonny Chant\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-11 15:33 . 2009-06-11 15:33 36864 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{80E158EA-7181-40FE-A701-301CE6BE64AB}\PostBuild.exe
2009-06-10 14:13 . 2009-02-05 03:28 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2009-02-05 03:27 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2009-02-05 03:27 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-05 15:42 . 2009-05-13 19:15 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 15:42 . 2009-02-19 21:11 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-03 19:09 . 2009-02-05 03:27 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2006-01-20 00:23 . 2006-01-20 00:23 3072 ----a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-01-20 00:23 . 2006-01-20 00:23 245408 ----a-w- c:\program files\mozilla firefox\plugins\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-08-03 419088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-19 149280]
c:\documents and settings\Lonny Chant\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e\0SsiEfr.e\0smrgdf c:\program files\iolo\System Mechanic Professional 6\\0iolobtdfg c:\windows\system32
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Ati HotKey Poller"=2 (0x2)
"ATI Smart"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SMSystemAnalyzer"="c:\program files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe"
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"Microsoft Works Update Detection"=c:\program files\Microsoft Works\WkDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HPWITOOLBOX"=c:\program files\Hewlett-Packard\hp deskjet 9600 series\Toolbox\HPWITBX.exe "-i"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Microsoft Works Update Detection"=c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
"ioloDelayModule"=c:\program files\iolo\System Mechanic Professional 6\delay.exe
"AppleSyncNotifier"=c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 ppa;Iomega Parallel Port Filter Driver;c:\windows\SYSTEM32\DRIVERS\ppa.sys [2/7/2003 12:37 PM 17792]
R1 atitray;atitray;c:\program files\Ray Adams\ATI Tray Tools\atitray.sys [5/22/2007 5:04 AM 18088]
R1 ATMhelpr;ATMhelpr;c:\windows\SYSTEM32\DRIVERS\ATMHELPR.SYS [10/9/2002 10:36 AM 4064]
R2 CachemanXPService;CachemanXP;c:\progra~1\CACHEM~1\CachemanXP.exe [6/10/2008 2:28 PM 243200]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/14/2009 7:40 AM 232720]
R3 MBAMProtector;MBAMProtector;c:\windows\SYSTEM32\DRIVERS\mbam.sys [8/14/2009 7:40 AM 19096]
S3 ADSFilter;ADSFilter - (Aluria Filter Driver);c:\windows\system32\DRIVERS\ADSFilter.sys --> c:\windows\system32\DRIVERS\ADSFilter.sys [?]
S3 ati2mpaa;ati2mpaa;c:\windows\system32\DRIVERS\ati2mpaa.sys --> c:\windows\system32\DRIVERS\ati2mpaa.sys [?]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\Drivers\BW2NDIS5.sys --> c:\windows\system32\Drivers\BW2NDIS5.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\6.tmp --> c:\windows\system32\6.tmp [?]
S3 RTCore32;RTCore32;c:\program files\RightMark Memory Analyzer\RTCore32.sys [6/10/2008 2:33 PM 4608]
.
Contents of the 'Scheduled Tasks' folder
2009-06-18 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2005-12-09 19:45]
2009-08-16 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-03-09 18:39]
.
.
------- Supplementary Scan -------
.
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Lonny Chant\Application Data\Mozilla\Firefox\Profiles\h5abj7co.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-23 11:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\6.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\LP*]
"DisplayName"="?\13?\13"
"DeviceDesc"="?\13?\13"
"ProviderName"=""
"MFG"="???\\"
"ReinstallString"="c:\\WINDOWS\\System32\\ReinstallBackups\\?\13\\DriverFiles\\.INF"
"DeviceInstanceIds"=multi:"nf\\cx_08948.inf\00"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\}›õw”¶*]
"DisplayName"="\09"
"DeviceDesc"="\09"
"ProviderName"=""
"MFG"="?"
"ReinstallString"="2002, 6.13.10.5004"
"DeviceInstanceIds"=multi:"\00"
[HKEY_LOCAL_MACHINE\software\swearware\backup\winsock2]
@DACL=(02 0000)
@SACL=
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(3040)
c:\windows\system32\WININET.dll
c:\windows\system32\wuaucpl.old.cpl
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\SYSTEM32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-08-23 11:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-23 15:22
ComboFix2.txt 2009-08-18 13:17
Pre-Run: 13,385,707,520 bytes free
Post-Run: 13,315,846,144 bytes free
Current=5 Default=5 Failed=4 LastKnownGood=7 Sets=1,2,3,4,5,6,7
421 --- E O F --- 2009-08-13 03:40