Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:25:04 PM, on 4/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bitsoup.org/browse.php?c...c19=1&c6=1&c28=1&c7=1&c41=1&incldead=0&blah=0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: Staind Toolbar - {4E7BD74F-2B8D-469E-B4D8-CE39F0D3F960} - C:\PROGRA~1\PRODEG~1\PRODEG~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: Staind Toolbar - {4E7BD74F-2B8D-469E-B4D8-CE39F0D3F960} - C:\PROGRA~1\PRODEG~1\PRODEG~1.DLL
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
--
End of file - 7188 bytes
ComboFix 08-04-17.1 - Administrator 2008-04-22 14:58:32.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1594 [GMT -5:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-22 to 2008-04-22 )))))))))))))))))))))))))))))))
.
2008-04-22 14:52 . 2008-04-22 14:52 <DIR> d-------- C:\WINDOWS\LastGood
2008-04-21 12:41 . 2008-04-21 12:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
2008-04-20 20:24 . 2008-04-21 09:37 1,540,617 ---hs---- C:\WINDOWS\system32\xaweplwh.ini
2008-04-20 19:30 . 2008-04-20 19:30 1,540,617 ---hs---- C:\WINDOWS\system32\eymhuett.ini
2008-04-20 19:30 . 2008-04-20 19:30 88,128 --------- C:\WINDOWS\system32\gebdderg.qih
2008-04-20 19:29 . 2008-04-20 19:29 96,320 --------- C:\WINDOWS\system32\xocwbnxb.wra
2008-04-20 16:34 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-20 16:34 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-20 16:34 . 2008-04-14 19:28 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-20 16:34 . 2008-04-20 00:38 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-20 16:34 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-20 16:34 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-20 16:34 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-20 16:27 . 2008-04-20 16:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-20 15:43 . 2008-04-20 16:42 294 ---hs---- C:\WINDOWS\system32\krdgwbfo.ini
2008-04-20 15:30 . 2008-04-20 15:30 <DIR> d-------- C:\Program Files\Groove Games
2008-04-19 15:44 . 2008-04-20 12:37 1,540,617 ---hs---- C:\WINDOWS\system32\xydttfhl.ini
2008-04-19 15:43 . 2008-04-19 15:43 87,616 --------- C:\WINDOWS\system32\inpvmqwu.bly
2008-04-19 15:40 . 2008-04-19 15:40 95,296 --------- C:\WINDOWS\system32\fojvqmdt.tnb
2008-04-19 09:04 . 2008-04-20 15:25 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-04-19 09:04 . 2008-04-19 09:04 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-04-19 09:04 . 2008-04-21 19:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-04-19 09:04 . 2008-04-19 09:04 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SiteAdvisor
2008-04-19 09:04 . 2008-04-22 14:51 8,407 --a------ C:\WINDOWS\system32\Config.MPF
2008-04-19 09:03 . 2007-11-22 06:44 33,832 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-04-19 09:02 . 2008-04-19 09:02 <DIR> d-------- C:\Program Files\McAfee.com
2008-04-19 09:02 . 2008-04-20 15:04 <DIR> d-------- C:\Program Files\McAfee
2008-04-19 09:02 . 2008-04-19 09:02 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-04-19 09:02 . 2007-11-22 06:44 201,320 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-04-19 09:02 . 2007-07-13 06:20 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-04-19 09:02 . 2007-11-22 06:44 79,304 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-04-19 09:02 . 2007-12-02 12:51 40,488 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-04-19 09:02 . 2007-11-22 06:44 35,240 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-04-18 15:39 . 2008-04-18 15:39 96,320 --------- C:\WINDOWS\system32\gelvvtvo.dcc
2008-04-18 15:26 . 2008-04-18 15:26 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-18 13:16 . 2008-04-18 14:18 1,540,677 ---hs---- C:\WINDOWS\system32\rruorrxn.ini
2008-04-18 13:16 . 2008-04-20 20:23 109,738 --a------ C:\WINDOWS\BM0f74dd6b.xml
2008-04-18 12:16 . 2008-04-18 12:16 1,540,617 ---hs---- C:\WINDOWS\system32\fudasupc.ini
2008-04-17 15:57 . 2008-04-21 13:34 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\simon4
2008-04-17 15:16 . 2008-04-17 15:56 <DIR> d-------- C:\Program Files\Simon the Sorcerer - Chaos happens
2008-04-17 12:14 . 2008-04-17 12:41 1,528,779 ---hs---- C:\WINDOWS\system32\ytcsykme.ini
2008-04-16 20:31 . 2008-04-16 20:31 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-04-16 17:07 . 2008-04-20 20:46 <DIR> d-------- C:\CARNIVALE_SE1D1
2008-04-16 16:46 . 2008-04-16 16:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SlySoft
2008-04-16 16:46 . 2008-04-20 20:26 40 ---hs---- C:\Documents and Settings\All Users\Application Data\.zreglib
2008-04-16 16:30 . 2008-04-16 16:46 24 ---hs---- C:\WINDOWS\S86B6B59E.tmp
2008-04-16 16:29 . 2008-04-16 16:29 <DIR> d-------- C:\Program Files\AnyDVD
2008-04-16 16:21 . 2008-04-16 16:21 <DIR> d-------- C:\Program Files\DVD Shrink
2008-04-16 16:21 . 2008-04-16 17:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-16 13:56 . 2008-04-16 13:56 <DIR> d-------- C:\Program Files\Java
2008-04-16 13:56 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-16 13:55 . 2008-04-16 13:55 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-16 13:38 . 2008-04-19 09:39 <DIR> d-------- C:\WINDOWS\system32\Moved Files 4-15-08
2008-04-16 13:33 . 2008-04-16 13:33 <DIR> d-------- C:\VundoFix Backups
2008-04-16 12:12 . 2008-04-16 12:54 1,524,184 ---hs---- C:\WINDOWS\system32\gkwddnmv.ini
2008-04-15 19:51 . 2008-04-21 09:37 558 --a------ C:\WINDOWS\wininit.ini
2008-04-15 19:48 . 2008-04-15 19:48 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-04-15 19:42 . 2008-04-15 19:42 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-15 19:21 . 2008-04-15 19:21 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-15 19:21 . 2008-04-15 19:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-15 16:18 . 2008-04-15 16:18 <DIR> d-------- C:\Program Files\WinRAR2
2008-04-15 12:16 . 2008-04-15 12:17 1,602,087 ---hs---- C:\WINDOWS\system32\diexgapy.ini
2008-04-15 11:58 . 2008-04-15 12:02 32,764 --a------ C:\WINDOWS\17PHolmes572.exe
2008-04-14 09:17 . 2008-04-14 10:28 <DIR> d-------- C:\Indiana Jones Comic Collection Part 2 of 2 (Dark Horse Era) (1991-1996)
2008-04-14 08:04 . 2008-04-14 10:18 <DIR> d-------- C:\Indiana Jones Comic Collection Part 1 of 2 (Marvel Era) (1981-1989)
2008-04-13 09:01 . 2008-04-15 16:21 <DIR> d-------- C:\Program Files\VirtualDJ
2008-04-11 17:28 . 2008-04-11 19:10 <DIR> d-------- C:\Star Wars - Underworld - The Yavin Vassilika #1-5 (Rise of the Empire Era Part 30)
2008-04-11 12:40 . 2008-04-11 15:09 <DIR> d-------- C:\Star Wars - Boba Fett - Enemy of the Empire #1-4 (Rise of the Empire Era Part 29)
2008-04-11 09:54 . 2008-04-11 10:14 <DIR> d-------- C:\Star Wars Classic - Han Solo at Stars' End #1-3 (Rise of the Empire Era Part 28)
2008-04-11 08:23 . 2008-04-11 08:53 <DIR> d-------- C:\Star Wars - Jabba the Hutt - Art of the Deal (4 One-Shots) (Rise of the Empire Era Part 27)
2008-04-10 21:54 . 2008-04-10 21:54 <DIR> d-------- C:\Program Files\UltraISO
2008-04-10 21:54 . 2008-04-10 21:54 <DIR> d-------- C:\Program Files\Common Files\EZB Systems
2008-04-10 21:32 . 2008-04-10 21:32 <DIR> d-------- C:\Program Files\Medieval Software
2008-04-10 17:03 . 2008-04-10 17:13 <DIR> d-------- C:\Program Files\Winamp
2008-04-10 17:03 . 2008-04-10 17:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Winamp
2008-04-10 13:10 . 2008-04-10 13:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-04-09 17:04 . 2008-04-09 17:06 <DIR> d-------- C:\Program Files\MKVtoolnix
2008-04-09 15:42 . 2008-04-09 15:42 <DIR> d-------- C:\Program Files\TVersity
2008-04-09 15:37 . 2008-04-09 15:37 <DIR> d-------- C:\Program Files\mkv2vob
2008-04-09 15:23 . 2008-04-09 15:30 107 --a------ C:\WINDOWS\VobEdit.INI
2008-04-09 14:59 . 2008-04-09 17:50 <DIR> d-------- C:\Stardust
2008-04-09 09:15 . 2008-04-09 09:41 <DIR> d-------- C:\Buffy the Vampire Slayer Season Eight #1-13 (Ongoing) (Joss Whedon)
2008-04-08 11:49 . 2008-04-08 11:49 <DIR> d-------- C:\WINDOWS\Crusaders - Thy Kingdom Come
2008-04-08 09:00 . 2008-04-08 09:00 <DIR> d-------- C:\Program Files\Common Files\OverDrive Shared
2008-04-08 08:15 . 2008-04-19 09:25 <DIR> d-------- C:\Program Files\ESET
2008-04-07 08:18 . 2008-04-10 15:51 <DIR> d-------- C:\Star Wars - Droids (Volumes 1 & 2 + Specials) (Rise of the Empire Era Part 26)
2008-04-05 14:35 . 2008-04-19 09:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-02 16:39 . 2008-04-04 17:57 <DIR> d-------- C:\Star Wars - Clone Wars Vol. 9 - Endgame (TPB) (Rise of the Empire Era Part 25)
2008-04-02 16:34 . 2008-04-03 14:10 <DIR> d-------- C:\Star Wars - Clone Wars Adventures v.4-7 (Inspired by Cartoon Network TV Series) (Rise of the Empire Era Part 23)
2008-04-02 16:32 . 2008-04-04 15:11 <DIR> d-------- C:\Star Wars Episode III - Revenge of the Sith #1-4 (Rise of the Empire Era Part 24)
2008-04-02 16:31 . 2008-04-03 13:07 <DIR> d-------- C:\Star Wars - Clone Wars Vol. 8 - The Last Siege The Final Truth (TPB) (Rise of the Empire Era Part 22)
2008-04-02 14:31 . 2008-04-02 18:04 <DIR> d-------- C:\Star Wars - Clone Wars Vol. 7 - When They Were Brothers (TPB) (Rise of the Empire Era Part 21)
2008-04-02 10:37 . 2008-04-02 12:51 <DIR> d-------- C:\Star Wars - Clone Wars Vol. 6 - On the Fields of Battle (TPB) (Rise of the Empire Era Part 20) (Republic #65-71)
2008-04-02 09:28 . 2008-04-02 12:27 <DIR> d-------- C:\Star Wars - General Grievous #1-4 (Rise of the Empire Era Part 19)
2008-04-01 14:47 . 2008-04-01 14:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-01 11:37 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-01 11:37 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-04-01 11:26 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll
2008-04-01 11:26 . 2008-04-01 11:26 376 --a------ C:\WINDOWS\ODBC.INI
2008-04-01 11:25 . 2008-04-01 11:25 <DIR> d-------- C:\Program Files\Microsoft Works
2008-04-01 11:25 . 2008-04-01 11:25 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-04-01 11:25 . 2008-04-01 11:25 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-04-01 11:24 . 2008-04-01 11:25 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-04-01 11:24 . 2008-04-01 11:24 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-04-01 09:31 . 2008-04-16 13:50 <DIR> d-------- C:\Program Files\Bonjour
2008-04-01 09:27 . 2008-04-01 09:27 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-01 08:41 . 2008-04-01 08:50 <DIR> d-------- C:\Program Files\CamStudio
2008-03-31 12:10 . 2008-04-02 09:22 <DIR> d-------- C:\Star Wars - Clone Wars Vol. 5 - The Best Blades (TPB) (Rise of the Empire Era Part 18)
2008-03-31 10:56 . 2008-04-03 13:40 <DIR> d-------- C:\Star Wars - Clone Wars Adventures v.3 (Inspired by Cartoon Network TV Series) (Rise of the Empire Era Part 17)
2008-03-30 18:31 . 2008-03-30 19:17 <DIR> d-------- C:\Star Wars - Clone Wars Vol. 3 - Last Stand on Jabiim (TPB) (Rise of the Empire Era Part 16)
2008-03-30 16:14 . 2008-03-30 16:59 <DIR> d-------- C:\Star Wars - Clone Wars Vol. 4 - Light and Dark (TPB) (Rise of the Empire Era Part 15)
2008-03-30 09:12 . 2008-03-30 14:13 <DIR> d-------- C:\Star Wars - Clone Wars Adventures v.1-2 (Inspired by Cartoon Network TV Series) (Rise of the Empire Era Part 14)
2008-03-29 16:07 . 2008-03-29 17:05 <DIR> d-------- C:\Star Wars - Clone Wars Vol. 2 - Victories and Sacrifices (TPB) (Rise of the Empire Era Part 13)
2008-03-29 10:48 . 2008-03-29 12:37 <DIR> d-------- C:\Star Wars - Clone Wars Vol. 1 -The Defense of Kamino (TPB) (Rise of the Empire Era Part 12)
2008-03-29 10:10 . 2008-03-29 10:47 <DIR> d-------- C:\Star Wars - Jedi (4 One-Shots) (Rise of the Empire Era Part 12)
2008-03-29 02:20 . 2008-03-29 08:23 <DIR> d-------- C:\Star Wars Episode II - Attack of the Clones #1-4 (Rise of the Empire Era Part 11) (Complete)
2008-03-28 15:53 . 2008-04-20 14:43 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-28 15:53 . 2008-03-28 15:53 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-28 15:52 . 2008-03-28 15:52 <DIR> d-------- C:\Program Files\QuickTime
2008-03-28 15:52 . 2008-03-28 15:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-03-28 15:51 . 2008-03-28 15:51 <DIR> d-------- C:\Program Files\Apple Software Update
2008-03-28 15:51 . 2008-03-28 15:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-03-28 12:25 . 2008-03-28 12:40 <DIR> d-------- C:\Star Wars - Starfighter - Crossbones #1-3 (Rise of The Empire Era Part 10)
2008-03-27 16:17 . 2008-03-27 16:44 <DIR> d-------- C:\Star Wars - Zam Wesell (One-Shot, Graphic Novel) (Rise of The Empire Era Part 9)
2008-03-27 08:17 . 2008-03-27 11:59 <DIR> d-------- C:\Star Wars - Knights of the Old Republic #26 - Vector, Part 2 (Ongoing)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-22 19:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\nView_Wallpaper
2008-04-22 19:46 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-04-16 13:05 --------- d-----w C:\Program Files\prodegetoolbar429
2008-04-13 16:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-01 14:31 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-23 04:25 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-22 00:27 278,728 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2008-03-22 00:27 25,416 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2008-03-21 19:49 --------- d-----w C:\Program Files\QuickSFV
2008-03-20 12:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-03-16 16:49 --------- d-----w C:\Program Files\ReflexiveArcade
2008-03-16 16:05 --------- d-----w C:\Program Files\Logitech
2008-03-16 16:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logitech
2008-03-16 00:59 --------- d-----w C:\Program Files\DAEMON Tools Pro
2008-03-16 00:59 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DAEMON Tools Pro
2008-03-16 00:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2008-03-16 00:54 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-03-15 21:24 --------- d-----w C:\Program Files\DAMN NFO Viewer
2008-03-15 20:41 --------- d-----w C:\Program Files\uTorrent
2008-03-15 20:32 --------- d-----w C:\Documents and Settings\Administrator\Application Data\ImgBurn
2008-03-15 20:22 --------- d-----w C:\Program Files\ImgBurn
2008-03-14 18:36 --------- d-----w C:\Program Files\Microsoft Games
2008-03-14 16:31 --------- d-----w C:\Program Files\C-Media 6501 Sound
2008-03-14 06:41 --------- d-----w C:\Documents and Settings\Administrator\Application Data\DivX
2008-03-14 06:40 --------- d-----w C:\Program Files\DivX
2008-03-14 06:31 --------- d-----w C:\Program Files\AC3Filter
2008-03-14 05:55 --------- d-----w C:\Program Files\CDisplay
2008-03-14 03:48 --------- d-----w C:\Program Files\Google
2008-03-13 23:38 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-03-10 21:16 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2008-03-10 21:16 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2008-03-10 21:11 --------- d-----w C:\Program Files\Futuremark
2008-03-10 18:38 --------- d-----w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-03-10 18:13 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-10 18:09 --------- d-----w C:\Program Files\Windows Plus
.
((((((((((((((((((((((((((((( snapshot_2008-04-20_17.11.33.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-18 21:36:46 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-04-22 02:15:17 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2008-04-18 21:36:46 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-04-22 02:15:18 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2008-04-18 21:36:46 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-04-22 02:15:18 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2008-04-18 21:36:43 2,676,224 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:12 2,676,224 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:43 2,846,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:13 2,846,720 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:44 563,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:13 563,712 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:44 567,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:14 567,296 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:44 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:15 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:44 577,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:15 577,024 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:45 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:15 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:45 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:16 577,536 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:45 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:16 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:46 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-04-22 02:15:18 578,560 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-04-18 21:36:46 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-04-22 02:15:19 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2008-04-18 21:36:47 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-04-22 02:15:19 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2008-04-18 21:36:47 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-04-22 02:15:20 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2008-04-18 21:36:47 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-04-22 02:15:20 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2008-04-18 21:36:46 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-04-22 02:15:17 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2008-04-20 22:05:11 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-22 19:50:49 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-04-20 19:42:04 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-22 18:00:38 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-20 19:42:04 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-22 18:00:38 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-B4D8-CE39F0D3F960}]
2007-09-20 12:51 1719296 --a------ C:\PROGRA~1\PRODEG~1\PRODEG~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4E7BD74F-2B8D-469E-B4D8-CE39F0D3F960}"= "C:\PROGRA~1\PRODEG~1\PRODEG~1.DLL" [2007-09-20 12:51 1719296]
[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-b4d8-ce39f0d3f960}]
[HKEY_CLASSES_ROOT\prodegetoolbar429.PRODEGETOOLBAR429]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{4E7BD74F-2B8D-469E-B4D8-CE39F0D3F960}"= C:\PROGRA~1\PRODEG~1\PRODEG~1.DLL [2007-09-20 12:51 1719296]
[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-b4d8-ce39f0d3f960}]
[HKEY_CLASSES_ROOT\prodegetoolbar429.PRODEGETOOLBAR429]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 08:08 136136]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 07:04 59392]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-11 09:03 8429568]
"nwiz"="nwiz.exe" [2007-05-11 09:03 1626112 C:\WINDOWS\system32\nwiz.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 01:16 39792]
"C6501Sound"="c6501.cpl" []
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-05-11 09:03 81920]
"Launch LGDCore"="C:\Program Files\Logitech\G-series Software\LGDCore.exe" [2005-11-02 10:56 1110079]
"Launch LCDMon"="C:\Program Files\Logitech\G-series Software\LCDMon.exe" [2005-11-02 10:42 188928]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-08-24 16:57 36640]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM0f74dd6b]
C:\WINDOWS\system32\wwwuxyrk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite]
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4672:TCP"= 4672:TCP:uTorrent Port Forward
"4672:UDP"= 4672:UDP:uTorrent Port Forward UDP
"11244:TCP"= 11244:TCP:11244
"11244:UDP"= 11244:UDP:11244 UDP
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;C:\WINDOWS\system32\drivers\c6501.sys [2007-07-09 20:42]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-19 14:02:36 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-04-19 14:02:35 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-04-16 18:09:43 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-22 15:00:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-22 15:03:05
ComboFix-quarantined-files.txt 2008-04-22 20:02:49
ComboFix2.txt 2008-04-22 01:20:22
ComboFix3.txt 2008-04-21 01:01:55
ComboFix4.txt 2008-04-20 22:12:04
ComboFix5.txt 2008-04-18 20:36:36
Pre-Run: 32,873,472,000 bytes free
Post-Run: 32,863,961,088 bytes free
.
2008-04-22 08:00:18 --- E O F ---
Malwarebytes' Anti-Malware 1.11
Database version: 670
Scan type: Full Scan (C:\|)
Objects scanned: 113924
Time elapsed: 37 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\QooBox\Quarantine\C\WINDOWS\system32\cpusaduf[ORIG].dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\ymlnvotf[ORIG].dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP44\A0007205.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP44\A0007208.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP44\A0007210.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP45\A0007255.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP45\A0007256.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP45\A0007258.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP45\A0007533.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP45\A0007534.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP51\A0007882.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D96AED63-45F4-485F-8D2F-906783933B9A}\RP51\A0007886.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\17PHolmes572.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Moved Files 4-15-08\popdjsne[ORIG].dll (Trojan.Vundo) -> Quarantined and deleted successfully.