ok heres the new
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:13:14 PM, on 5/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WUSB54GSC.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\Integrator.exe
E:\AlienGUIse\AlienwareDock\ObjectDock.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = +
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {17E9BA56-7A36-4109-AA9B-34E2ABF07CA1} - C:\WINDOWS\system32\iifgGXol.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Hare.lnk = C:\Program Files\Dachshund Software\Hare\Hare.exe
O4 - Startup: Zoom.lnk = C:\Program Files\Dachshund Software\Zoom\Zoom.exe
O4 - Startup: AntiCrash.lnk = C:\Program Files\Dachshund Software\AntiCrash\AntiCrash.exe
O4 - Startup: Alienware Dock.lnk = E:\AlienGUIse\AlienwareDock\ObjectDock.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1200449297473
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll,wbsys.dll
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O20 - Winlogon Notify: tuvUOHwu - tuvUOHwu.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - Unknown owner - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: WUSB54GSCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe
--
End of file - 6960 bytes
Heres
combofix log:
ComboFix 08-05-27.4 - Ry 2008-05-27 16:53:22.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.578 [GMT -7:00]
Running from: C:\Documents and Settings\Ry\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ry\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM17363b41.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\start.exe
C:\WINDOWS\system32\cidvuwlk.ini
C:\WINDOWS\system32\eckdelut.dll
C:\WINDOWS\system32\iqvatxuf.ini
C:\WINDOWS\SYSTEM32\istttkyl.ini
C:\WINDOWS\system32\JHVUHBCS.DLL
C:\WINDOWS\system32\loXGgfii.ini
C:\WINDOWS\SYSTEM32\loXGgfii.ini2
C:\WINDOWS\system32\lyktttsi.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\NHNVAKAU.DLL
C:\WINDOWS\system32\qhwirncy.dll
C:\WINDOWS\system32\qrdcqgjh.dll
C:\WINDOWS\SYSTEM32\RXFfgMoq.ini
C:\WINDOWS\SYSTEM32\RXFfgMoq.ini2
C:\WINDOWS\system32\uakavnhn.ini
C:\WINDOWS\Web\default.htt
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.
2008-05-26 22:17 . 2008-05-26 22:17 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-26 17:19 . 2008-05-26 17:20 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-26 16:07 . 2008-05-26 16:08 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-26 15:44 . 2008-05-27 16:16 64,512 --ah----- C:\Documents and Settings\Ry\Application Data\dach100.dll
2008-05-25 20:42 . 2008-05-25 20:42 <DIR> d-------- C:\Program Files\Stardock
2008-05-25 20:42 . 2008-05-25 20:42 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\{8CC5CF4A-124E-41BA-B58C-A41F05BE09CC}
2008-05-25 20:31 . 2008-05-25 20:31 42 --a------ C:\WINDOWS\WB.INI
2008-05-25 18:29 . 2008-05-25 18:29 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-25 18:28 . 2008-05-25 18:28 <DIR> d-------- C:\WINDOWS\SYSTEM32\DRIVERS\Avg
2008-05-25 18:28 . 2008-05-25 18:28 96,520 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgldx86.sys
2008-05-25 18:28 . 2008-05-25 18:28 75,272 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgtdix.sys
2008-05-25 18:28 . 2008-05-25 18:28 12,424 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgrkx86.sys
2008-05-25 18:28 . 2008-05-25 18:28 10,520 --a------ C:\WINDOWS\SYSTEM32\avgrsstx.dll
2008-05-25 18:27 . 2008-05-25 18:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-25 18:25 . 2008-05-25 18:25 <DIR> d-------- C:\Program Files\AVG
2008-05-25 17:15 . 2008-05-25 17:15 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-25 17:14 . 2008-05-25 17:14 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-25 16:58 . 2008-05-25 16:58 <DIR> d-------- C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster
2008-05-25 16:58 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\SYSTEM32\bcm42rly.sys
2008-05-25 16:58 . 2008-05-25 16:58 17,801 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AegisP.sys
2008-05-25 16:57 . 2008-05-25 16:57 609 --a------ C:\WINDOWS\SYSTEM32\WLAN.INI
2008-05-24 18:32 . 2008-05-24 18:32 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\~0
2008-05-24 14:53 . 2008-05-24 17:52 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-05-24 14:49 . 2003-03-18 15:05 89,088 --a------ C:\WINDOWS\SYSTEM32\atl71.dll
2008-05-24 14:49 . 2000-10-20 01:05 25,088 --a------ C:\WINDOWS\SYSTEM32\msxml3a.dll
2008-05-24 14:39 . 2008-05-24 14:39 <DIR> d-------- C:\Program Files\Common Files\Stardock
2008-05-21 22:49 . 2008-05-21 22:49 <DIR> d-------- C:\Program Files\Dachshund Software
2008-05-21 22:27 . 2008-05-21 22:27 <DIR> d--hs---- C:\FOUND.005
2008-05-19 22:02 . 2008-05-19 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-05-19 22:02 . 2008-05-23 14:34 143,104 --a------ C:\WINDOWS\SYSTEM32\guard32.dll
2008-05-19 22:02 . 2008-05-19 22:02 139,008 --a------ C:\WINDOWS\SYSTEM32\guard32.dll1
2008-05-19 22:02 . 2008-05-23 14:34 87,056 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\cmdguard.sys
2008-05-19 22:02 . 2008-05-23 14:34 24,208 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\cmdhlp.sys
2008-05-17 13:48 . 2008-05-17 13:48 <DIR> d-------- C:\Documents and Settings\Adri\Application Data\Comodo
2008-05-16 18:56 . 2008-05-16 18:56 <DIR> d-------- C:\WINDOWS\SYSTEM32\scripting
2008-05-16 18:56 . 2008-05-16 18:56 <DIR> d-------- C:\WINDOWS\SYSTEM32\en
2008-05-16 18:56 . 2008-05-16 18:56 <DIR> d-------- C:\WINDOWS\l2schemas
2008-05-16 18:30 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\
005566_.tmp
2008-05-16 18:30 . 2008-04-13 17:11 9,216 --------- C:\WINDOWS\SYSTEM32\dot3dlg.dll
2008-05-16 18:30 . 2008-04-13 17:11 7,168 --------- C:\WINDOWS\SYSTEM32\bitsprx4.dll
2008-05-16 18:30 . 2008-04-13 17:09 6,144 --------- C:\WINDOWS\SYSTEM32\kbdpash.dll
2008-05-16 18:30 . 2008-04-13 17:09 6,144 --------- C:\WINDOWS\SYSTEM32\kbdnepr.dll
2008-05-16 18:30 . 2008-04-13 17:09 6,144 --------- C:\WINDOWS\SYSTEM32\kbdiultn.dll
2008-05-16 18:30 . 2008-04-13 17:09 6,144 --------- C:\WINDOWS\SYSTEM32\kbdbhc.dll
2008-05-16 18:30 . 2007-09-17 01:48 1,261 --------- C:\WINDOWS\SYSTEM32\pid.inf
2008-05-16 17:57 . 2008-05-16 17:57 <DIR> d-------- C:\Program Files\MSBuild
2008-05-16 17:54 . 2008-05-16 17:54 <DIR> d-------- C:\WINDOWS\SYSTEM32\XPSViewer
2008-05-16 17:53 . 2008-05-16 17:53 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-05-16 17:52 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\SYSTEM32\spmsg2.dll
2008-05-16 15:02 . 2008-05-16 15:02 <DIR> d-------- C:\Program Files\COMODO
2008-05-16 15:02 . 2008-05-16 15:02 <DIR> d-------- C:\Documents and Settings\Ry\Application Data\Comodo
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\SYSTEM32\lsdelete.exe
2008-05-02 14:07 . 2008-05-02 14:07 <DIR> d-------- C:\Documents and Settings\All Users\temp
2008-05-02 14:07 . 2008-05-02 14:07 <DIR> d-------- C:\Documents and Settings\All Users\Gamespot
2008-05-02 14:03 . 2008-05-02 14:03 0 --a------ C:\WINDOWS\2E87ED.dmp
2008-04-29 11:20 . 2008-04-29 11:20 15,648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\NSDriver.sys
2008-04-29 11:19 . 2008-04-29 11:19 15,648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Awrtrd.sys
2008-04-29 11:19 . 2008-04-29 11:19 12,960 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Awrtpd.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-25 06:33 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-26 23:14 42,672 ------w C:\WINDOWS\SYSTEM32\wbsys.dll
2008-04-19 06:28 585,728 ----a-w C:\WINDOWS\SYSTEM32\bsratswf.dll
2008-04-19 06:28 147,456 ----a-w C:\WINDOWS\SYSTEM32\bsratwmv.dll
2008-04-19 06:28 --------- d-----w C:\Program Files\Bulent's Screen Recorder 4
2008-04-16 04:28 --------- d-----w C:\Program Files\Bonjour
2008-04-16 04:19 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-04-16 01:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-14 12:42 985,088 ----a-w C:\WINDOWS\SYSTEM32\setupapi.dll
2008-04-14 12:42 11,264 ------w C:\WINDOWS\SYSTEM32\spnpinst.exe
2008-04-14 12:41 423,936 ----a-w C:\WINDOWS\SYSTEM32\licdll.dll
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\SYSTEM32\Dcache.bin
2008-04-14 00:16 329,728 ----a-w C:\WINDOWS\SYSTEM32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\SYSTEM32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\SYSTEM32\rdpwsx.dll
2008-04-14 00:13 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 00:13 299,520 ----a-w C:\WINDOWS\SYSTEM32\drmclien.dll
2008-04-14 00:13 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 00:13 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\SYSTEM32\tsddd.dll
2008-04-14 00:13 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 00:11 98,304 ----a-w C:\WINDOWS\SYSTEM32\actxprxy.dll
2008-04-14 00:10 67,584 ----a-w C:\WINDOWS\SYSTEM32\dllcache\pmigrate.dll
2008-04-14 00:10 53,760 ----a-w C:\WINDOWS\SYSTEM32\dllcache\pintlcsd.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\SYSTEM32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\SYSTEM32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\SYSTEM32\msafd.dll
2008-04-14 00:10 175,104 ----a-w C:\WINDOWS\SYSTEM32\dllcache\pintlcsa.dll
2008-04-14 00:10 15,872 ----a-w C:\WINDOWS\SYSTEM32\dllcache\padrs404.dll
2008-04-14 00:10 15,360 ----a-w C:\WINDOWS\SYSTEM32\dllcache\padrs804.dll
2008-04-13 21:00 103,424 ----a-w C:\WINDOWS\SYSTEM32\dpcdll.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\SYSTEM32\win32k.sys
2008-04-13 19:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:27 2,188,928 ----a-w C:\WINDOWS\SYSTEM32\ntoskrnl.exe
2008-04-13 19:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:18 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 19:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 19:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 19:00 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 18:56 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 18:56 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 18:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 18:56 30,592 ------w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 18:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 18:56 12,800 ------w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 18:56 12,288 ------w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 18:55 202,624 ----a-w C:\WINDOWS\system32\drivers\RMCast.sys
2008-04-13 18:55 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 18:54 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 18:53 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 18:53 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 18:53 36,608 ------w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 18:53 264,832 ------w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 18:51 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 18:51 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 18:51 59,904 ----a-w C:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 18:51 55,808 ----a-w C:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 18:51 101,120 ------w C:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 18:47 25,856 ----a-w C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-13 18:46 61,696 ----a-w C:\WINDOWS\system32\drivers\ohci1394.sys
2008-04-13 18:46 59,136 ------w C:\WINDOWS\system32\drivers\rfcomm.sys
2008-04-13 18:46 53,376 ----a-w C:\WINDOWS\system32\drivers\1394bus.sys
2008-04-13 18:46 37,888 ------w C:\WINDOWS\system32\drivers\bthmodem.sys
2008-04-13 18:46 36,480 ------w C:\WINDOWS\system32\drivers\bthprint.sys
2008-04-13 18:46 273,024 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-13 18:46 25,600 ------w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-13 18:46 25,344 ----a-w C:\WINDOWS\system32\drivers\sonydcam.sys
2008-04-13 18:46 18,944 ------w C:\WINDOWS\system32\drivers\bthusb.sys
2008-04-13 18:46 17,024 ------w C:\WINDOWS\system32\drivers\bthenum.sys
2008-04-13 18:46 121,984 ------w C:\WINDOWS\system32\drivers\usbvideo.sys
2008-04-13 18:44 81,664 ----a-w C:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 18:44 799,744 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05e4c875-cf99-4b55-95ae-fe93abda4a61}]
C:\WINDOWS\system32\qrdcqgjh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{08B80F8D-8EFB-4AC3-92B3-4383DE556D18}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{129FA2A1-408C-4824-83A4-5001581FD01E}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{140BD8E3-C167-11D4-B4A3-080000180323}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{17E9BA56-7A36-4109-AA9B-34E2ABF07CA1}]
C:\WINDOWS\system32\iifgGXol.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8AC58714-3578-4566-AC9E-3D02448E73D5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8EA74DED-828B-4D4D-A898-D082E0344D4F}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F4BFF10B-B727-4436-8322-6946A7B6430A}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay]
@={7D688A77-C613-11D0-999B-00C04FD655E1}
[HKEY_CLASSES_ROOT\CLSID\{7D688A77-C613-11D0-999B-00C04FD655E1}]
2008-04-13 17:12 8461312 --a------ C:\WINDOWS\SYSTEM32\SHELL32.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 17:12 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe" [2006-11-13 22:25 363008]
"nwiz"="nwiz.exe" [2007-06-28 08:43 1626112 C:\WINDOWS\SYSTEM32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-15 01:21 16270848 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-17 02:04 2879488 C:\WINDOWS\SkyTel.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-05-23 14:30 1575680]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-25 18:27 1177368]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2007-12-05 01:41 8523776]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2007-12-05 01:41 81920]
"140508dd"="C:\WINDOWS\system32\nhnvakau.dll" [ ]
"BM17363b41"="C:\WINDOWS\system32\jhvuhbcs.dll" [ ]
C:\Documents and Settings\Adri\Start Menu\Programs\Startup\
MEMonitor.lnk - C:\Program Files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2008-01-19 19:25:47 947544]
C:\Documents and Settings\Ry\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]
Hare.lnk - C:\Program Files\Dachshund Software\Hare\Hare.exe [2002-09-21 12:26:40 1874381]
Zoom.lnk - C:\Program Files\Dachshund Software\Zoom\Zoom.exe [2002-09-21 12:27:14 1446302]
AntiCrash.lnk - C:\Program Files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 12:00:44 2301798]
Alienware Dock.lnk - E:\AlienGUIse\AlienwareDock\ObjectDock.exe [2008-05-25 20:31:54 2074360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
antiwpa.dll 2005-09-18 02:32 5376 C:\WINDOWS\SYSTEM32\antiwpa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvUOHwu]
tuvUOHwu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\AlienGUIse\wbsrv.dll 2008-04-29 21:58 210168 C:\Program Files\Stardock\AlienGUIse\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll,wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-05-25 18:28]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-25 18:28]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-05-23 14:34]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-05-23 14:34]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-25 18:27]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-25 18:27]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-25 18:28]
R2 WUSB54GSCSVC;WUSB54GSCSVC;"C:\Program Files\Compact Wireless-G USB Network Adapter with SpeedBooster\WLService.exe" "WUSB54GSC.exe" []
S3 bkqyzjwALj;bkqyzjwALj;C:\Documents and Settings\Ry\Desktop\WT hacks\New Folder\INNPCDM []
S3 CwUCzJqYcx;CwUCzJqYcx;C:\DOCUME~1\Ry\LOCALS~1\Temp\Rar$EX00.422\BWFIXVB []
S3 luIMlvG;luIMlvG;C:\DOCUME~1\Ry\LOCALS~1\Temp\YQTXRI []
S3 OnkSJlN;OnkSJlN;C:\DOCUME~1\Ry\LOCALS~1\Temp\LMGGW []
S3 projectx1;projectx1;C:\DOCUME~1\Ry\LOCALS~1\Temp\Rar$EX57.594\Project X\FelipeZe.sys []
S3 Revolution1;Revolution1;C:\DOCUME~1\Ry\LOCALS~1\Temp\Rar$EX00.391\Revolution Engine 6.2\SHAK3.sys []
S3 Sex1;Sex1;C:\DOCUME~1\Ry\LOCALS~1\Temp\Rar$EX00.000\Sex Engine\Sex Engine\Sex.sys []
S3 SoRa01;SoRa01;C:\DOCUME~1\Ry\LOCALS~1\Temp\Rar$EX00.938\SoRa Remake Engine 2.6\SoRa Remak Engine 2.6\SoRa.sys []
S3 sora121;sora121;C:\DOCUME~1\Ry\LOCALS~1\Temp\Rar$EX00.078\SoRa Engine2.90\sora12.sys []
S3 SysCom1;syscom1;H:\Documents\Downloads\XTK2175\XTK2175.sys []
S3 XDva078;XDva078;C:\WINDOWS\system32\XDva078.sys []
S3 XDva081;XDva081;C:\WINDOWS\system32\XDva081.sys []
S3 XDva090;XDva090;C:\WINDOWS\system32\XDva090.sys []
S3 XDva098;XDva098;C:\WINDOWS\system32\XDva098.sys []
S3 XDva104;XDva104;C:\WINDOWS\system32\XDva104.sys []
S3 XDva107;XDva107;C:\WINDOWS\system32\XDva107.sys []
S3 XDva110;XDva110;C:\WINDOWS\system32\XDva110.sys []
S3 XDva115;XDva115;C:\WINDOWS\system32\XDva115.sys []
S3 XDva120;XDva120;C:\WINDOWS\system32\XDva120.sys []
S3 XDva123;XDva123;C:\WINDOWS\system32\XDva123.sys []
S3 XDva129;XDva129;C:\WINDOWS\system32\XDva129.sys []
S3 XDva136;XDva136;C:\WINDOWS\system32\XDva136.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ca44452-d398-11dc-9241-001a703ad148}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-05-08 02:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-27 17:05:42
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bkqyzjwALj]
"ImagePath"="\??\C:\Documents and Settings\Ry\Desktop\WT hacks\New Folder\INNPCDM"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CwUCzJqYcx]
"ImagePath"="\??\C:\DOCUME~1\Ry\LOCALS~1\Temp\Rar$EX00.422\BWFIXVB"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\luIMlvG]
"ImagePath"="\??\C:\DOCUME~1\Ry\LOCALS~1\Temp\YQTXRI"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OnkSJlN]
"ImagePath"="\??\C:\DOCUME~1\Ry\LOCALS~1\Temp\LMGGW"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> E:\AlienGUIse\AlienwareDock\DockShellHookOEM.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\LAVASOFT\AD-AWARE\AAWSERVICE.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGWDSVC.EXE
C:\PROGRAM FILES\BONJOUR\MDNSRESPONDER.EXE
C:\PROGRAM FILES\COMODO\FIREWALL\CMDAGENT.EXE
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\SYSTEM32\HPZIPM12.EXE
C:\PROGRAM FILES\COMPACT WIRELESS-G USB NETWORK ADAPTER WITH SPEEDBOOSTER\WUSB54GSC.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGAM.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGRSX.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGNSX.EXE
C:\PROGRAM FILES\AVG\AVG8\AVGEMC.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\Integrator.exe
C:\WINDOWS\System32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-05-27 17:09:03 - machine was rebooted [Ry]
ComboFix-quarantined-files.txt 2008-05-28 00:08:50
Pre-Run: 20,593,049,600 bytes free
Post-Run: 21,053,374,464 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout = 30
default = multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS = "Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
350 --- E O F --- 2008-05-15 23:04:04
Heres
Kaspersky:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 27, 2008 9:14:43 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/05/2008
Kaspersky Anti-Virus database records: 802914
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 80080
Number of viruses found: 7
Number of infected objects: 33
Number of suspicious objects: 0
Duration of the scan process: 02:03:58
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\OSession.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\config\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\SchedLog.Txt Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{F0803E5F-B073-4756-8A95-BFDD8B6DFF91}.bin Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\JHVUHBCS.DLL.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\lyktttsi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.tsk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\NHNVAKAU.DLL.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ttc skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\qhwirncy.dll.vir Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\qrdcqgjh.dll.vir Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\comodo\Firewall Pro\cfplogdb.sdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\emc\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\AvgAm\avgam.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgam.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgns.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsrm.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Ry\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Ry\ntuser.dat Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Temp\~DF936C.tmp Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Temp\Perflib_Perfdata_8f4.dat Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\History\History.IE5\MSHist012008052720080528\index.dat Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Temporary Internet Files\Content.Word\~WRS{C03E6245-4D52-496F-8556-C84DEFCF9A41}.tmp Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Temporary Internet Files\Content.Word\~WRS{BD84D12A-A013-4D93-8011-6A19A46E4E87}.tmp Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Application Data\Microsoft\Windows Media\11.0\WMSDKNSD.XML Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Ry\Local Settings\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Ry\My Documents\Downloads\Programs\ca_setup_2.exe/WISE0025.BIN Infected: not-a-virus

SWTool.Win32.Cain.284 skipped
C:\Documents and Settings\Ry\My Documents\Downloads\Programs\ca_setup_2.exe WiseSFX: infected - 1 skipped
C:\Documents and Settings\Ry\My Documents\personal statement.docx Object is locked skipped
C:\Documents and Settings\Ry\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Ry\Application Data\Microsoft\Templates\Normal.dotm Object is locked skipped
C:\Documents and Settings\Ry\Application Data\Microsoft\Word\AutoRecovery save of personal statement.asd Object is locked skipped
C:\Documents and Settings\Ry\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\history.dat Object is locked skipped
C:\Documents and Settings\Ry\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\cert8.db Object is locked skipped
C:\Documents and Settings\Ry\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\key3.db Object is locked skipped
C:\Documents and Settings\Ry\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\parent.lock Object is locked skipped
C:\Documents and Settings\Ry\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Ry\Application Data\Mozilla\Firefox\Profiles\hg5l10gh.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Adri\Shared\hawaiian rollor coaster ride 5.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP140\A0059221.RBF/file.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.tso skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP140\A0059221.RBF CAB: infected - 1 skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP140\A0059222.RBF/file.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.tso skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP140\A0059222.RBF CAB: infected - 1 skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP145\A0064362.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ttc skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP146\A0066345.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP146\A0066346.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.ttc skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP146\A0066347.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP146\A0066348.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP147\A0066786.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP147\A0066787.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ttc skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP147\A0066788.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP147\A0066789.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP148\A0067388.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP148\A0067389.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.ttc skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP148\A0067390.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP148\A0067391.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP149\A0067829.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP149\A0067830.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.ttc skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP149\A0067831.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP149\A0067832.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP150\A0068442.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP150\A0068444.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ttc skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP150\A0068445.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP150\A0068446.dll Infected: Trojan-Downloader.Win32.ConHook.te skipped
C:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP150\change.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{3D8E86C1-2347-4ACC-998D-B2C3DA8DB39B}\RP150\change.log Object is locked skipped
Scan process completed.