ComboFix 09-02-04.01 - Fluffy 2009-02-05 3:59:47.1 - NTFSx86
Running from: d:\documents and settings\Fluffy\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Outdated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\documents and settings\Fluffy\My Documents\My Documents.url
d:\documents and settings\Fluffy\My Documents\My Music\My Music.url
d:\documents and settings\Fluffy\My Documents\My Pictures\My Pictures.url
d:\documents and settings\Fluffy\My Documents\My Videos\My Video.url
d:\windows\IE4 Error Log.txt
d:\windows\system32\abojoloh.ini
d:\windows\system32\adenuhim.ini
d:\windows\system32\agejuhev.ini
d:\windows\system32\aharizep.ini
d:\windows\system32\ahohutus.ini
d:\windows\system32\akogisuf.ini
d:\windows\system32\akuluhej.ini
d:\windows\system32\akutebil.ini
d:\windows\system32\amiwarot.ini
d:\windows\system32\anodudog.ini
d:\windows\system32\apezawal.ini
d:\windows\system32\apolujet.ini
d:\windows\system32\araselos.ini
d:\windows\system32\arirahom.ini
d:\windows\system32\aromevom.ini
d:\windows\system32\asomagil.ini
d:\windows\system32\atamovar.ini
d:\windows\system32\awekiwov.ini
d:\windows\system32\azawosam.ini
d:\windows\system32\azeminaf.ini
d:\windows\system32\bafoline.dll
d:\windows\system32\bakevibe.dll
d:\windows\system32\basojefo.dll
d:\windows\system32\bekoduya.dll
d:\windows\system32\besotuja.dll.tmp
d:\windows\system32\bewivupi.dll
d:\windows\system32\boduvipe.dll
d:\windows\system32\bohahefe.dll
d:\windows\system32\bojilale.dll
d:\windows\system32\boloyahe.dll.tmp
d:\windows\system32\bosetiti.dll
d:\windows\system32\bovenage.dll
d:\windows\system32\dafumumu.dll
d:\windows\system32\debabawe.dll
d:\windows\system32\demewilu.dll.tmp
d:\windows\system32\difanuba.dll
d:\windows\system32\diguweha.dll
d:\windows\system32\dufazone.dll
d:\windows\system32\dugosupi.dll
d:\windows\system32\edihonay.ini
d:\windows\system32\eduhivik.ini
d:\windows\system32\eganevob.ini
d:\windows\system32\ehosoduy.ini
d:\windows\system32\ejakidep.ini
d:\windows\system32\enifiyif.ini
d:\windows\system32\enozafud.ini
d:\windows\system32\etamomuv.ini
d:\windows\system32\ewababed.ini
d:\windows\system32\ewosewij.ini
d:\windows\system32\eyakokak.ini
d:\windows\system32\fadonuna.dll
d:\windows\system32\falivigi.dll
d:\windows\system32\fanenoto.dll
d:\windows\system32\fegejuno.dll
d:\windows\system32\fitivipa.dll
d:\windows\system32\fiwegaha.dll.tmp
d:\windows\system32\fiyifine.dll
d:\windows\system32\folajese.dll
d:\windows\system32\fowoluye.dll
d:\windows\system32\fulajivu.dll
d:\windows\system32\funesabo.dll
d:\windows\system32\fusigoka.dll
d:\windows\system32\futagimo.dll
d:\windows\system32\gahehani.dll
d:\windows\system32\ganoseho.dll
d:\windows\system32\gasogole.dll.tmp
d:\windows\system32\gesopepo.dll
d:\windows\system32\gituyanu.dll
d:\windows\system32\godamuwe.dll
d:\windows\system32\godudona.dll
d:\windows\system32\gohahiyi.dll
d:\windows\system32\guyubaha.dll
d:\windows\system32\gxyjzc.dll
d:\windows\system32\hekemowu.dll
d:\windows\system32\hekeyapi.dll
d:\windows\system32\hibipida.dll
d:\windows\system32\hiwutiwa.dll
d:\windows\system32\holojoba.dll
d:\windows\system32\hutikovu.dll
d:\windows\system32\huyewipu.dll
d:\windows\system32\ibuyarok.ini
d:\windows\system32\ididiyed.ini
d:\windows\system32\ifitejul.ini
d:\windows\system32\ifolugal.ini
d:\windows\system32\igedadit.ini
d:\windows\system32\igiwubef.ini
d:\windows\system32\ihunehuv.ini
d:\windows\system32\ikuvivey.ini
d:\windows\system32\imivohiv.ini
d:\windows\system32\iniyotas.ini
d:\windows\system32\inuputaj.ini
d:\windows\system32\ipuviweb.ini
d:\windows\system32\iregulow.ini
d:\windows\system32\iremakum.ini
d:\windows\system32\irodudam.ini
d:\windows\system32\isusiduz.ini
d:\windows\system32\itetipef.ini
d:\windows\system32\iyihahog.ini
d:\windows\system32\izikufit.ini
d:\windows\system32\jatupuni.dll
d:\windows\system32\jehuluka.dll
d:\windows\system32\jelukahu.dll
d:\windows\system32\jijeruwa.dll.tmp
d:\windows\system32\jijuwimu.dll.tmp
d:\windows\system32\jisizosa.dll.tmp
d:\windows\system32\jitodujo.dll
d:\windows\system32\jizutamu.dll
d:\windows\system32\jobaruse.dll
d:\windows\system32\junipine.dll
d:\windows\system32\kagirevi.dll.tmp
d:\windows\system32\kakijigu.dll.tmp
d:\windows\system32\kakokaye.dll
d:\windows\system32\kasivaga.dll
d:\windows\system32\kazerevi.dll
d:\windows\system32\kefazuwa.dll
d:\windows\system32\kibigipu.dll
d:\windows\system32\kivihude.dll
d:\windows\system32\kopuroka.dll.tmp
d:\windows\system32\korayubi.dll
d:\windows\system32\kowavelo.dll
d:\windows\system32\kqbzcm.dll
d:\windows\system32\krzbnn.dll
d:\windows\system32\kubetole.dll
d:\windows\system32\kuboyohu.dll
d:\windows\system32\lagulofi.dll
d:\windows\system32\lalzfq.dll
d:\windows\system32\lawayede.dll
d:\windows\system32\lawazepa.dll
d:\windows\system32\ligamosa.dll
d:\windows\system32\lihujedo.dll
d:\windows\system32\linatopo.dll
d:\windows\system32\lufusezi.dll
d:\windows\system32\lugibifi.dll
d:\windows\system32\lujetifi.dll
d:\windows\system32\lupeyoyu.dll
d:\windows\system32\luzopobo.dll
d:\windows\system32\madudori.dll
d:\windows\system32\masibovi.dll.tmp
d:\windows\system32\masoyumu.dll
d:\windows\system32\mccnxj.dll
d:\windows\system32\menewudi.dll.tmp
d:\windows\system32\mnkiri.dll
d:\windows\system32\moharira.dll
d:\windows\system32\mukameri.dll
d:\windows\system32\musowewo.dll.tmp
d:\windows\system32\namegele.dll.tmp
d:\windows\system32\nipurowe.dll
d:\windows\system32\nitalolo.dll
d:\windows\system32\niwaluyu.dll
d:\windows\system32\nobikiwu.dll
d:\windows\system32\nobiyaki.dll
d:\windows\system32\nofirepo.dll.tmp
d:\windows\system32\nolagube.dll
d:\windows\system32\novufuvi.dll
d:\windows\system32\noyopesi.dll
d:\windows\system32\obasenuf.ini
d:\windows\system32\obijumaw.ini
d:\windows\system32\obopozul.ini
d:\windows\system32\ofazizer.ini
d:\windows\system32\ogobupaf.ini
d:\windows\system32\ohesonag.ini
d:\windows\system32\omazefik.ini
d:\windows\system32\onerabus.ini
d:\windows\system32\opeposeg.ini
d:\windows\system32\opotanil.ini
d:\windows\system32\otonenaf.ini
d:\windows\system32\owdmqt.dll
d:\windows\system32\oyorofes.ini
d:\windows\system32\padikona.dll.tmp
d:\windows\system32\papuboka.dll
d:\windows\system32\pekobuwe.dll
d:\windows\system32\penonoge.dll.tmp
d:\windows\system32\pidewaka.dll
d:\windows\system32\pinojudu.dll.tmp
d:\windows\system32\pivohude.dll.tmp
d:\windows\system32\popezaho.dll
d:\windows\system32\pumefunu.dll
d:\windows\system32\raripizu.dll.tmp
d:\windows\system32\ravezula.dll
d:\windows\system32\razinomi.dll
d:\windows\system32\rejufopa.dll.tmp
d:\windows\system32\rezadure.dll
d:\windows\system32\roloropo.dll.tmp
d:\windows\system32\ruhegozi.dll
d:\windows\system32\ruhufuga.dll
d:\windows\system32\rujamika.dll
d:\windows\system32\rukigigi.dll
d:\windows\system32\rulerujo.dll
d:\windows\system32\ruyezijo.dll
d:\windows\system32\sagujele.dll
d:\windows\system32\satoyini.dll
d:\windows\system32\segudedu.dll
d:\windows\system32\sehudoki.dll
d:\windows\system32\soboposi.dll
d:\windows\system32\solesara.dll
d:\windows\system32\sugefeso.dll
d:\windows\system32\sujobapi.dll
d:\windows\system32\suteniro.dll
d:\windows\system32\suzeyiji.dll.tmp
d:\windows\system32\suzezufu.dll
d:\windows\system32\swnpxg.dll
d:\windows\system32\tedefibu.dll
d:\windows\system32\tefifohi.dll
d:\windows\system32\tejulopa.dll
d:\windows\system32\tekulaze.dll.tmp
d:\windows\system32\telezeva.dll
d:\windows\system32\teyudasa.dll
d:\windows\system32\tidadegi.dll
d:\windows\system32\tifukizi.dll
d:\windows\system32\todolaze.dll
d:\windows\system32\ujuberuy.ini
d:\windows\system32\ukidosig.ini
d:\windows\system32\utoyulew.ini
d:\windows\system32\uvokituh.ini
d:\windows\system32\uyadejov.ini
d:\windows\system32\uyoyepul.ini
d:\windows\system32\vamayuve.dll
d:\windows\system32\vanabuje.dll
d:\windows\system32\varefaza.dll
d:\windows\system32\vasutadu.dll
d:\windows\system32\vatebapi.dll
d:\windows\system32\vehujega.dll
d:\windows\system32\vevapada.dll
d:\windows\system32\vihovimi.dll
d:\windows\system32\vojedayu.dll
d:\windows\system32\voluguhe.dll.tmp
d:\windows\system32\vosuloso.dll
d:\windows\system32\vowikewa.dll
d:\windows\system32\vudutowo.dll
d:\windows\system32\vuhenuhi.dll
d:\windows\system32\vunajopi.dll.tmp
d:\windows\system32\vuwizodi.dll
d:\windows\system32\wamujibo.dll
d:\windows\system32\wazejawe.dll
d:\windows\system32\weluyotu.dll
d:\windows\system32\werihova.dll
d:\windows\system32\weseniha.dll
d:\windows\system32\wevotegu.dll
d:\windows\system32\wideneje.dll
d:\windows\system32\wolugeri.dll
d:\windows\system32\wozijewu.dll
d:\windows\system32\wubogudo.dll
d:\windows\system32\wwhugk.dll
d:\windows\system32\xkktfr.dll
d:\windows\system32\yakituro.dll
d:\windows\system32\yebineza.dll
d:\windows\system32\yedonuse.dll
d:\windows\system32\yerulaji.dll.tmp
d:\windows\system32\yinasidu.dll
d:\windows\system32\yurezasa.dll
d:\windows\system32\zanlyr.dll
d:\windows\system32\zavomoru.dll
d:\windows\system32\zebekeli.dll
d:\windows\system32\zehejevo.dll
d:\windows\system32\zelorogi.dll
d:\windows\system32\zevehahu.dll
d:\windows\system32\zijaputa.dll
d:\windows\system32\zipejizo.dll.tmp
d:\windows\system32\ziwazele.dll
d:\windows\system32\zoravugi.dll.tmp
d:\windows\system32\zunobuli.dll
d:\windows\system32\zurafogu.dll
.
((((((((((((((((((((((((( Files Created from 2009-01-05 to 2009-02-05 )))))))))))))))))))))))))))))))
.
2009-01-31 18:04 . 2009-01-31 18:04 <DIR> d-------- d:\program files\Trend Micro
2009-01-28 18:06 . 2009-01-28 18:22 <DIR> d-------- d:\windows\Logs
2009-01-28 18:05 . 2009-01-28 18:27 <DIR> d--h----- d:\windows\msdownld.tmp
2009-01-28 16:55 . 2009-01-28 18:32 <DIR> d-------- d:\documents and settings\Fluffy\Application Data\Hamachi
2009-01-28 16:55 . 2009-01-28 16:55 25,280 --a------ d:\windows\system32\drivers\hamachi.sys
2009-01-28 15:29 . 2009-01-28 19:03 <DIR> d-------- d:\program files\BitComet
2009-01-18 18:03 . 2009-01-18 18:03 6,656 --a------ d:\windows\system32\SOUNDMAN.EXE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-05 08:59 1,033,728 ----a-w d:\windows\explorer.exe
2009-01-27 19:12 --------- d-----w d:\program files\World of Warcraft
2008-12-30 01:45 --------- d-----w d:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-30 00:58 --------- d-----w d:\program files\Spybot - Search & Destroy
2008-12-30 00:51 --------- d-----w d:\program files\Lavasoft
2008-12-30 00:51 --------- d-----w d:\documents and settings\All Users\Application Data\Lavasoft
2008-12-30 00:50 --------- d-----w d:\program files\Common Files\Wise Installation Wizard
2008-12-30 00:33 --------- d-----w d:\documents and settings\Administrator\Application Data\ATI
2008-12-30 00:30 --------- d-----w d:\program files\ATI
2008-12-30 00:26 --------- d-----w d:\program files\Common Files\Symantec Shared
2008-12-30 00:26 --------- d-----w d:\program files\Common Files\Blizzard Entertainment
2008-12-27 23:52 --------- d---a-w d:\documents and settings\All Users\Application Data\TEMP
2008-12-27 23:52 --------- d-----w d:\program files\ThreatFire
2008-12-27 23:49 --------- d-----w d:\program files\Canon
2008-12-27 23:23 --------- d-----w d:\program files\Java
2008-12-27 23:19 --------- d-----w d:\program files\DivX
2008-12-22 14:24 --------- d-----w d:\documents and settings\Fluffy\Application Data\Media Player Classic
2008-12-20 20:37 --------- d-----w d:\documents and settings\All Users\Application Data\PC Tools
2008-12-15 14:53 --------- d-----w d:\documents and settings\Fluffy\Application Data\AdobeUM
2008-12-15 14:52 --------- d-----w d:\program files\Common Files\Adobe
2008-12-14 23:49 --------- d-----w d:\program files\K-Lite Codec Pack
2008-12-10 19:53 --------- d-----w d:\documents and settings\Fluffy\Application Data\Move Networks
2008-04-28 06:57 56 --sh--r d:\windows\system32\E39D4B7680.sys
2008-04-28 06:57 3,350 --sha-w d:\windows\system32\KGyGaAvL.sys
2008-09-28 01:08 29,696 --sha-w d:\windows\system32\lidituhu.dll
2008-09-18 23:03 33,792 --sha-w d:\windows\system32\pofokago.dll
2008-09-23 12:05 63,488 --sha-w d:\windows\system32\wutawiko.dll
2008-07-06 17:02 32,768 --sha-w d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008070620080707\index.dat
.
------- Sigcheck -------
2004-08-04 07:00 14336 8f078ae4ed187aaabc0a305146de6716 d:\windows\$NtServicePackUninstall$\svchost.exe
2008-04-13 19:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 d:\windows\ServicePackFiles\i386\svchost.exe
2008-04-13 19:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 d:\windows\system32\svchost.exe
2005-03-02 13:19 577024 1800f293bccc8ede8a70e12b88d80036 d:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 10:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b d:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
2007-03-08 10:36 577536 b409909f6e2e8a7067076ed748abf1e7 d:\windows\$NtServicePackUninstall$\user32.dll
2004-08-04 07:00 577024 c72661f8552ace7c5c85e16a3cf505c4 d:\windows\$NtUninstallKB890859$\user32.dll
2005-03-02 13:09 577024 de2db164bbb35db061af0997e4499054 d:\windows\$NtUninstallKB925902$\user32.dll
2008-04-13 19:12 578560 b26b135ff1b9f60c9388b4a7d16f600b d:\windows\ServicePackFiles\i386\user32.dll
2008-04-13 19:12 578560 b26b135ff1b9f60c9388b4a7d16f600b d:\windows\system32\user32.dll
2004-08-04 07:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 d:\windows\$NtServicePackUninstall$\ws2_32.dll
2008-04-13 19:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a d:\windows\ServicePackFiles\i386\ws2_32.dll
2008-04-13 19:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a d:\windows\system32\ws2_32.dll
2005-10-20 22:38 661504 af785c4947676a7fc1673fdc5c8d0b5b d:\windows\$hf_mig$\KB905915\SP2QFE\wininet.dll
2006-03-03 22:58 663552 c0845ecbf4f9164e618ee381b79c9032 d:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll
2006-05-10 00:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc d:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
2006-06-23 06:25 664576 64ce26db72810b30f7855ea51e1df836 d:\windows\$hf_mig$\KB918899\SP2QFE\wininet.dll
2006-09-14 03:31 664576 d207370287cf769aebebf03837784963 d:\windows\$hf_mig$\KB922760\SP2QFE\wininet.dll
2006-10-23 10:34 664576 231ef4179acabe486376b5ca893f1076 d:\windows\$hf_mig$\KB925454\SP2QFE\wininet.dll
2007-01-04 09:05 665088 3ffa1573fc274e5aa7467d03941c45ee d:\windows\$hf_mig$\KB928090\SP2QFE\wininet.dll
2007-02-20 04:52 665600 b258c922d22deec880b60720531d7627 d:\windows\$hf_mig$\KB931768\SP2QFE\wininet.dll
2007-04-18 07:46 665600 4261ba03afd659de04f0a17dfbdd454d d:\windows\$hf_mig$\KB933566\SP2QFE\wininet.dll
2007-06-26 09:35 665600 e1a3dd68b5380b360a7310a64d9bb188 d:\windows\$hf_mig$\KB937143\SP2QFE\wininet.dll
2007-08-22 07:55 665600 a1bc17eb3758d73c3938b2318820f5b4 d:\windows\$hf_mig$\KB939653\SP2QFE\wininet.dll
2007-10-10 18:47 825344 0e5d918f87efa7d2424d66b499c7eb04 d:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-06 21:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 d:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 08:03 827392 6316c2f0c61271c8abdff7429174879e d:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-22 22:35 827392 41546b396a526918da7995a02ea04e51 d:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 11:01 827904 c66402a06b83b036c195242c0c8cf83c d:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2008-08-26 04:08 827904 77c192fe56a70d7fa0247ba0a6201c32 d:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
2008-10-16 15:24 827904 0d5b75171ff51775b630a431b6c667e8 d:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
2004-08-04 07:00 656384 c0823fc5469663ba63e7db88f9919d70 d:\windows\$NtUninstallKB905915$\wininet.dll
2005-10-20 22:39 658432 e7b27b6b6e06ce34ea019fd8b858c613 d:\windows\$NtUninstallKB912812$\wininet.dll
2006-03-03 22:33 658432 1c0979c7a489bee573cd0bf4ad94bb06 d:\windows\$NtUninstallKB916281$\wininet.dll
2006-05-10 00:23 658432 38ab7a56f566d9aaad31812494944824 d:\windows\$NtUninstallKB918899$\wininet.dll
2006-06-23 06:02 658944 2b4db890936430c71419037039502752 d:\windows\$NtUninstallKB922760$\wininet.dll
2006-09-14 03:39 658944 621af3f6174a3f60677f5230e28bcc07 d:\windows\$NtUninstallKB925454$\wininet.dll
2006-10-23 10:17 658944 6b2735adff5a5d3b9130ca4a794722f0 d:\windows\$NtUninstallKB928090$\wininet.dll
2007-01-04 08:37 658944 8c393df5234cbcbff1ee31902d6b40ae d:\windows\$NtUninstallKB931768$\wininet.dll
2007-02-20 04:48 658944 30d1c47e40efbb792ff8d3c3b51ce507 d:\windows\$NtUninstallKB933566$\wininet.dll
2007-04-18 07:31 658944 b7156cd97e739f3014bc4d61758f868a d:\windows\$NtUninstallKB937143$\wininet.dll
2007-06-26 09:09 658944 184e47c8f7b331025e6dc92740db188f d:\windows\$NtUninstallKB939653$\wininet.dll
2007-08-22 08:12 658944 1901ad51da8be9f8b38d5d526e5d1788 d:\windows\ie7\wininet.dll
2007-08-13 18:54 818688 a4a0fc92358f39538a6494c42ef99fe9 d:\windows\ie7updates\KB942615-IE7\wininet.dll
2007-10-10 18:56 824832 30c1e0f34ad2972c72a01db5c74ab065 d:\windows\ie7updates\KB944533-IE7\wininet.dll
2007-12-06 21:21 824832 806d274c9a6c3aaea5eae8e4af841e04 d:\windows\ie7updates\KB947864-IE7\wininet.dll
2008-03-01 08:06 826368 ad21461aef8244edec2ef18e55e1dcf3 d:\windows\ie7updates\KB950759-IE7\wininet.dll
2008-04-22 23:16 826368 f6589be784647cfdbc22ea51ccb1a57a d:\windows\ie7updates\KB953838-IE7\wininet.dll
2008-06-23 11:57 826368 8c13d4a7479fa0a026eda8abce82c0ed d:\windows\ie7updates\KB956390-IE7\wininet.dll
2008-08-26 02:24 826368 ef8eba98145bfa44e80d17a3b3453300 d:\windows\ie7updates\KB958215-IE7\wininet.dll
2008-04-13 19:12 666112 7a4f775abb2f1c97def3e73afa2faedd d:\windows\ServicePackFiles\i386\wininet.dll
2007-10-10 18:56 824832 30c1e0f34ad2972c72a01db5c74ab065 d:\windows\SoftwareDistribution\Download\e3709fbfd9557a7d083f543d51d38612\SP2GDR\wininet.dll
2007-10-10 18:47 825344 0e5d918f87efa7d2424d66b499c7eb04 d:\windows\SoftwareDistribution\Download\e3709fbfd9557a7d083f543d51d38612\SP2QFE\wininet.dll
2008-10-16 15:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 d:\windows\system32\wininet.dll
2008-10-16 15:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 d:\windows\system32\dllcache\wininet.dll
2006-01-13 12:07 360448 5562cc0a47b2aef06d3417b733f3c195 d:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
2006-04-20 07:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 d:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 11:53 360832 64798ecfa43d78c7178375fcdd16d8c8 d:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 06:59 361600 ad978a1b783b5719720cff204b666c8e d:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2007-10-30 12:20 360064 90caff4b094573449a0872a0f919b178 d:\windows\$NtServicePackUninstall$\tcpip.sys
2004-08-04 07:00 359040 9f4b36614a0fc234525ba224957de55c d:\windows\$NtUninstallKB913446$\tcpip.sys
2006-01-12 21:28 359808 583e063fdc888ca30d05c2724b0d7ef4 d:\windows\$NtUninstallKB917953$\tcpip.sys
2006-04-20 06:51 359808 1dbf125862891817f374f407626967f4 d:\windows\$NtUninstallKB941644$\tcpip.sys
2008-04-13 14:20 361344 93ea8d04ec73a85db02eb8805988f733 d:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-13 14:20 361344 93ea8d04ec73a85db02eb8805988f733 d:\windows\ServicePackFiles\i386\tcpip.sys
2008-06-20 06:51 361600 9aefa14bd6b182d61e3119fa5f436d3d d:\windows\system32\dllcache\tcpip.sys
2008-06-20 06:51 361600 9aefa14bd6b182d61e3119fa5f436d3d d:\windows\system32\drivers\tcpip.sys
2004-08-04 07:00 502272 01c3346c241652f43aed8e2149881bfe d:\windows\$NtServicePackUninstall$\winlogon.exe
2008-04-13 19:12 507904 ed0ef0a136dec83df69f04118870003e d:\windows\ServicePackFiles\i386\winlogon.exe
2008-04-13 19:12 507904 ed0ef0a136dec83df69f04118870003e d:\windows\system32\winlogon.exe
2004-08-04 07:00 182912 558635d3af1c7546d26067d5d9b6959e d:\windows\$NtServicePackUninstall$\ndis.sys
2008-04-13 14:20 182656 1df7f42665c94b825322fae71721130d d:\windows\ServicePackFiles\i386\ndis.sys
2008-04-13 14:20 182656 1df7f42665c94b825322fae71721130d d:\windows\system32\drivers\ndis.sys
2004-08-04 07:00 29056 4448006b6bc60e6c027932cfc38d6855 d:\windows\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 13:53 36608 3bb22519a194418d5fec05d800a19ad0 d:\windows\ServicePackFiles\i386\ip6fw.sys
2008-04-13 13:53 36608 3bb22519a194418d5fec05d800a19ad0 d:\windows\system32\drivers\ip6fw.sys
2005-03-01 19:36 2056832 d8aba3eab509627e707a3b14f00fbb6b d:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 11:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d d:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 04:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba d:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 14:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 d:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2007-02-28 03:38 2057600 515d30e2c90a3665a2739309334c9283 d:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-04 07:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 d:\windows\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 19:34 2056832 81013f36b21c7f72cf784cc6731e0002 d:\windows\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 07:55 2057600 1d659bfb788ed2ba45075624b748d249 d:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
2008-04-13 13:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 d:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 04:33 2066048 4ac58f03eb94a72809949d757fc39d80 d:\windows\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 13:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 d:\windows\ServicePackFiles\i386\ntkrnlpa.exe
2008-08-14 04:33 2066048 4ac58f03eb94a72809949d757fc39d80 d:\windows\system32\ntkrnlpa.exe
2008-08-14 04:33 2066048 4ac58f03eb94a72809949d757fc39d80 d:\windows\system32\dllcache\ntkrnlpa.exe
2005-03-01 20:04 2179456 28187802b7c368c0d3aef7d4c382aabb d:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 11:51 2182016 cef243f6defd20be4adde26c7ecacb54 d:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 04:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 d:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 15:11 2189184 31914172342bff330063f343ac6958fe d:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2007-02-28 04:10 2180352 582a8dbaa58c3b1f176eb2817daee77c d:\windows\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-04 07:00 2180992 ce218bc7088681faa06633e218596ca7 d:\windows\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 19:59 2179328 4d4cf2c14550a4b7718e94a6e581856e d:\windows\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 09:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f d:\windows\$NtUninstallKB931784$\ntoskrnl.exe
2008-04-13 14:27 2188928 0c89243c7c3ee199b96fcc16990e0679 d:\windows\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 05:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 d:\windows\Driver Cache\i386\ntoskrnl.exe
2008-04-13 14:27 2188928 0c89243c7c3ee199b96fcc16990e0679 d:\windows\ServicePackFiles\i386\ntoskrnl.exe
2008-08-14 05:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 d:\windows\system32\ntoskrnl.exe
2008-08-14 05:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 d:\windows\system32\dllcache\ntoskrnl.exe
2009-02-05 04:09 1033728 12896823fb95bfb3dc9b46bcaedc9923 d:\windows\explorer.exe
2007-06-13 06:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 d:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 05:23 1033216 97bd6515465659ff8f3b7be375b2ea87 d:\windows\$NtServicePackUninstall$\explorer.exe
2004-08-04 07:00 1032192 a0732187050030ae399b241436565e64 d:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-13 19:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 d:\windows\ServicePackFiles\i386\explorer.exe
2004-08-04 07:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 d:\windows\$NtServicePackUninstall$\services.exe
2008-04-13 19:12 108544 0e776ed5f7cc9f94299e70461b7b8185 d:\windows\ServicePackFiles\i386\services.exe
2008-04-13 19:12 108544 0e776ed5f7cc9f94299e70461b7b8185 d:\windows\system32\services.exe
2004-08-04 07:00 13312 84885f9b82f4d55c6146ebf6065d75d2 d:\windows\$NtServicePackUninstall$\lsass.exe
2008-04-13 19:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 d:\windows\ServicePackFiles\i386\lsass.exe
2008-04-13 19:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 d:\windows\system32\lsass.exe
2004-08-04 07:00 15360 24232996a38c0b0cf151c2140ae29fc8 d:\windows\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 19:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 d:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-13 19:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 d:\windows\system32\ctfmon.exe
2005-06-10 19:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 d:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 18:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f d:\windows\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 07:00 57856 7435b108b935e42ea92ca94f59c8e717 d:\windows\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 19:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b d:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-13 19:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b d:\windows\system32\spoolsv.exe
2004-08-04 07:00 24576 39b1ffb03c2296323832acbae50d2aff d:\windows\$NtServicePackUninstall$\userinit.exe
2008-04-13 19:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 d:\windows\ServicePackFiles\i386\userinit.exe
2008-04-13 19:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 d:\windows\system32\userinit.exe
2004-08-04 12:00 295424 b60c877d16d9c880b952fda04adf16e6 d:\windows\$NtServicePackUninstall$\termsrv.dll
2008-04-13 19:12 295424 ff3477c03be7201c294c35f684b3479f d:\windows\ServicePackFiles\i386\termsrv.dll
2008-04-13 19:12 295424 ff3477c03be7201c294c35f684b3479f d:\windows\system32\termsrv.dll
2006-07-05 05:57 985088 0fdd84928a5dde2510761b7ec76ccec9 d:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
2007-04-16 11:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 d:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
2007-04-16 10:52 984576 a01f9ca902a88f7ced06884174d6419d d:\windows\$NtServicePackUninstall$\kernel32.dll
2004-08-04 07:00 983552 888190e31455fad793312f8d087146eb d:\windows\$NtUninstallKB917422$\kernel32.dll
2006-07-05 05:55 984064 d8db5397de07577c1cb50ba6d23b3ad4 d:\windows\$NtUninstallKB935839$\kernel32.dll
2008-04-13 19:11 989696 c24b983d211c34da8fcc1ac38477971d d:\windows\ServicePackFiles\i386\kernel32.dll
2008-04-13 19:11 989696 c24b983d211c34da8fcc1ac38477971d d:\windows\system32\kernel32.dll
2004-08-04 07:00 17408 1b5f6923abb450692e9fe0672c897aed d:\windows\$NtServicePackUninstall$\powrprof.dll
2008-04-13 19:12 17408 50a166237a0fa771261275a405646cc0 d:\windows\ServicePackFiles\i386\powrprof.dll
2008-04-13 19:12 17408 50a166237a0fa771261275a405646cc0 d:\windows\system32\powrprof.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DrvMon.exe"="d:\windows\system32\DrvMon.exe" [2006-06-14 53248]
"SoundMan"="d:\windows\system32\SOUNDMAN.EXE" [2009-01-18 6656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="d:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="d:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Zune Launcher"="d:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"ShStatEXE"="d:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-01-24 111952]
"McAfeeUpdaterUI"="d:\program files\McAfee\Common Framework\UdaterUI.exe" [2007-10-25 136512]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"bncsaui.exe"="d:\program files\Bradford Networks\Persistent Agent\bncsaui.exe" [2008-06-29 2612616]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2008-12-27 136600]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=d:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin F5D8053 N Wireless USB Adapter Utility.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Belkin F5D8053 N Wireless USB Adapter Utility.lnk
backup=d:\windows\pss\Belkin F5D8053 N Wireless USB Adapter Utility.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^Fluffy^Start Menu^Programs^Startup^MagicDisc.lnk]
path=d:\documents and settings\Fluffy\Start Menu\Programs\Startup\MagicDisc.lnk
backup=d:\windows\pss\MagicDisc.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-06 22:46 57344 d:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2008-10-31 14:22 50480 d:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
--a------ 2007-04-03 20:50 1603152 d:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
--a------ 2007-04-03 20:00 644696 d:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
--a------ 2005-08-31 10:06 106496 d:\program files\Corel\Corel Photo Album 6\MediaDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dlcxmon.exe]
--a------ 2007-01-12 11:57 292336 d:\program files\Dell Photo AIO Printer 926\dlcxmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryCardManager]
--a------ 2006-11-03 17:04 304008 d:\program files\Dell Photo AIO Printer 926\memcard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 19:12 1695232 d:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 11:54 5674352 d:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2006-07-26 02:03 49263 d:\program files\Java\jre1.5.0_08\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2008-04-01 17:35 3587120 d:\program files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2006-09-26 09:49 35328 d:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EVOLOSTA.exe]
-ra------ 2002-09-19 02:32 147541 d:\windows\system32\EVOLOSTA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"aawservice"=2 (0x2)
"helpsvc"=2 (0x2)
"Microsoft Office Groove Audit Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\StubInstaller.exe"=
"d:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"d:\\Program Files\\AIM6\\aim6.exe"=
"d:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"d:\\Program Files\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\Aspyr\\Guitar Hero III\\GH3.exe"=
"d:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"d:\\WINDOWS\\system32\\dlcxcoms.exe"=
"d:\\Program Files\\Bradford Networks\\Persistent Agent\\bndaemon.exe"=
"d:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"d:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"d:\\Program Files\\Lavasoft\\Ad-Aware\\aawservice.exe"=
"%windir%\\explorer.exe"=
"d:\\Program Files\\Mozilla Firefox\\firefox.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"20651:TCP"= 20651:TCP:BitComet 20651 TCP
"20651:UDP"= 20651:UDP:BitComet 20651 UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 EVOLO;Uniden Wireless LAN Driver;d:\windows\system32\DRIVERS\EVOLONDS.sys [2002-09-02 50688]
R3 JL2005;JL2005A Toy Camera; [x]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;d:\windows\system32\DRIVERS\rt2870.sys [2007-03-13 476416]
R4 dlcx_device;dlcx_device;d:\windows\system32\dlcxcoms.exe [2006-10-11 532480]
S2 BNPagent;Bradford Persistent Agent Service;d:\program files\Bradford Networks\Persistent Agent\bndaemon.exe [2008-06-29 2944392]
S2 Viewpoint Manager Service;Viewpoint Manager Service;d:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 USB200M;Linksys USB 2.0 Network Adapter ver.2;d:\windows\system32\DRIVERS\USB200M2.sys [2005-04-21 18048]
--- Other Services/Drivers In Memory ---
*Deregistered* - aawservice
*Deregistered* - AegisP
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - BNPagent
*Deregistered* - Cdfs
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - HTTP
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - Kbdclass
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - McAfeeFramework
*Deregistered* - mcdbus
*Deregistered* - McShield
*Deregistered* - McTaskManager
*Deregistered* - mfeapfk
*Deregistered* - mfeavfk
*Deregistered* - mfebopk
*Deregistered* - mfehidk
*Deregistered* - mferkdk
*Deregistered* - mfetdik
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - MSIServer
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - NetTcpPortSharing
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - Viewpoint Manager Service
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - Wdf01000
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WudfPf
*Deregistered* - WudfSvc
*Deregistered* - WZCSVC
*Deregistered* - zumbus
*Deregistered* - ZuneBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\Loaderw.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-04 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2009-02-04 d:\windows\Tasks\Norton Security Scan for Fluffy.job
- d:\program files\Norton Security Scan\Nss.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{ff36a9c3-526a-4850-ac75-7bc6c4853e87} - d:\windows\system32\sagujele.dll
HKCU-Run-VirRL2009 - d:\program files\VirRL2009\VirRL2009.exe
HKCU-Run-Aim6 - (no file)
SafeBoot-Wdf01000.sys
MSConfigStartUp-AIM - f:\program files\AIM95\aim.exe
MSConfigStartUp-ANIWZCS2Service - d:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
MSConfigStartUp-D-Link AirPlus G - d:\program files\D-Link\AirPlus G\AirGCFG.exe
MSConfigStartUp-FaxCenterServer - d:\program files\Dell PC Fax\fm3032.exe
MSConfigStartUp-QuickTime Task - d:\program files\QuickTime\QTTask.exe
MSConfigStartUp-ViewMgr - d:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: aol.com\free
FF - ProfilePath - d:\documents and settings\Fluffy\Application Data\Mozilla\Firefox\Profiles\io30lf4m.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: d:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npagent.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npvirtools.dll
FF - plugin: d:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: d:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-05 04:07:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
d:\windows\explorer.exe:extractor6.jpg 110592 bytes executable
d:\windows\explorer.exe:maim2.jpg 800256 bytes executable
d:\windows\explorer.exe:mian.nest.9.10 18944 bytes executable
scan completed successfully
hidden files: 3
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(672)
d:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
d:\windows\system32\ati2evxx.exe
d:\windows\system32\ati2evxx.exe
d:\program files\Lavasoft\Ad-Aware\aawservice.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\McAfee\Common Framework\FrameworkService.exe
d:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
d:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
d:\windows\system32\msiexec.exe
d:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
d:\windows\system32\ZuneBusEnum.exe
d:\program files\McAfee\Common Framework\Mctray.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-02-05 4:12:10 - machine was rebooted [Fluffy]
ComboFix-quarantined-files.txt 2009-02-05 09:12:05
Pre-Run: 110,286,700,544 bytes free
Post-Run: 110,650,867,712 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
d:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect ? /NoExecute=OptIn
752 --- E O F --- 2009-02-05 09:09:52
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:15:00 AM, on 2/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\McAfee\Common Framework\FrameworkService.exe
D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
D:\WINDOWS\system32\msiexec.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Viewpoint\Common\ViewpointService.exe
d:\WINDOWS\system32\ZuneBusEnum.exe
D:\Program Files\Zune\ZuneLauncher.exe
D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
D:\Program Files\McAfee\Common Framework\UdaterUI.exe
D:\Program Files\McAfee\Common Framework\McTray.exe
D:\Program Files\Bradford Networks\Persistent Agent\bncsaui.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\DrvMon.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\system32\notepad.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ISUSPM Startup] "D:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "D:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Zune Launcher] "d:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [ShStatEXE] "D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [bncsaui.exe] %ProgramFiles%\Bradford Networks\Persistent Agent\bncsaui.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DrvMon.exe] D:\WINDOWS\system32\DrvMon.exe
O4 - HKCU\..\Run: [SoundMan] D:\WINDOWS\system32\SOUNDMAN.EXE
O4 - HKUS\S-1-5-21-1229272821-602162358-839522115-1003\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1229272821-602162358-839522115-1003\..\Run: [DrvMon.exe] D:\WINDOWS\system32\DrvMon.exe (User '?')
O4 - HKUS\S-1-5-21-1229272821-602162358-839522115-1003\..\Run: [SoundMan] D:\WINDOWS\system32\SOUNDMAN.EXE (User '?')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bradford Persistent Agent Service (BNPagent) - Unknown owner - D:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - D:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - D:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 5262 bytes