Good morning from the east coast usa
thanks again for your help
i was actually doing a spybot scan when you replied
i have included the results because it found two entries for virtumonde.generic
i DID NOT remove or fix using spybot...i will only do as or when you instruct.
thank you again
C:/Archive is empty
----- SPYBOT RESULTS BELOW -----
Hint of the Day: Click the bar at the right of this to see more information! ()
Virtumonde.generic: [SBI $6C003E72] User settings (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
Virtumonde.generic: [SBI $6C003E72] User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
Common Dialogs: History (82 files) (Registry key, nothing done)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
Log: Activity: SchedLgU.Txt (Backup file, nothing done)
C:\WINDOWS\SchedLgU.Txt
Log: Activity: imsins.log (Backup file, nothing done)
C:\WINDOWS\imsins.log
Log: Activity: OEWABLog.txt (Backup file, nothing done)
C:\WINDOWS\OEWABLog.txt
Log: Activity: ntbtlog.txt (Backup file, nothing done)
C:\WINDOWS\ntbtlog.txt
Log: Install: comsetup.log (Backup file, nothing done)
C:\WINDOWS\comsetup.log
Log: Install: Directx.log (Backup file, nothing done)
C:\WINDOWS\Directx.log
Log: Install: ocgen.log (Backup file, nothing done)
C:\WINDOWS\ocgen.log
Log: Install: setupact.log (Backup file, nothing done)
C:\WINDOWS\setupact.log
Log: Install: setupapi.log (Backup file, nothing done)
C:\WINDOWS\setupapi.log
Log: Install: setuplog.txt (Backup file, nothing done)
C:\WINDOWS\setuplog.txt
Log: Install: svcpack.log (Backup file, nothing done)
C:\WINDOWS\svcpack.log
Log: Install: wmsetup.log (Backup file, nothing done)
C:\WINDOWS\wmsetup.log
Log: Install: DtcInstall.log (Backup file, nothing done)
C:\WINDOWS\DtcInstall.log
Log: Shutdown: System32\wbem\logs\mofcomp.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\mofcomp.log
Log: Shutdown: System32\wbem\logs\setup.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\setup.log
Log: Shutdown: System32\wbem\logs\wbemcore.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemcore.log
Log: Shutdown: System32\wbem\logs\wbemess.lo_ (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemess.lo_
Log: Shutdown: System32\wbem\logs\wbemess.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemess.log
Log: Shutdown: System32\wbem\logs\wmiadap.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\wmiadap.log
Log: Shutdown: System32\wbem\logs\wmiprov.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\wmiprov.log
Alcohol 120%: [SBI $33A21B15] Images history (8 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Alcohol Soft\Alcohol 120%\Images
Alcohol 120%: [SBI $B1D42532] Image location history (7 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Alcohol Soft\Alcohol 120%\Images\Location
Internet Explorer: [SBI $1E8157BE] Typed URL list (10 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Internet Explorer\TypedURLs
Internet Explorer: [SBI $FF589D0C] Download directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Internet Explorer\Download Directory
Internet Explorer: [SBI $0BC7B918] User agent (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
Internet Explorer: [SBI $0BC7B918] User agent (Registry change, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
Internet Explorer: [SBI $0BC7B918] User agent (Registry change, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
Internet Explorer: [SBI $0BC7B918] User agent (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
Internet Explorer: [SBI $0BC7B918] User agent (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
Internet Explorer: [SBI $D5C3373A] AutoComplete data (1 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Internet Explorer\IntelliForms\SPW
MS Management Console: [SBI $ECD50EAD] Recent command list (3 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Microsoft Management Console\Recent File List
MS Media Player: [SBI $E48560B4] Recent file list (3 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\MediaPlayer\Player\RecentFileList
MS Media Player: [SBI $8E65C0EE] Last opened playlist (Registry value, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\MediaPlayer\Preferences\LastPlaylist
MS Media Player: [SBI $1BDA487B] Last selected track index (Registry value, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\MediaPlayer\Preferences\LastPlaylistIndex
MS Media Player: [SBI $5C51E349] Client ID (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\MediaPlayer\Player\Settings\Client ID
MS Media Player: [SBI $5C51E349] Client ID (Registry change, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\MediaPlayer\Player\Settings\Client ID
MS Media Player: [SBI $5C51E349] Client ID (Registry change, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\MediaPlayer\Player\Settings\Client ID
MS Media Player: [SBI $5C51E349] Client ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\MediaPlayer\Player\Settings\Client ID
MS Media Player: [SBI $5C51E349] Client ID (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\MediaPlayer\Player\Settings\Client ID
MS Direct3D: [SBI $7FB7B83F] Most recent application (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name
MS Direct3D: [SBI $C2A44980] Most recent application (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Direct3D\MostRecentApplication\Name
MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name
MS DirectInput: [SBI $9A063C91] Most recent application (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\DirectInput\MostRecentApplication\Name
MS DirectInput: [SBI $7B184199] Most recent application ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\DirectInput\MostRecentApplication\Id
MS Paint: [SBI $07867C39] Recent file list (1 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List
MS Regedit: [SBI $C3B62FC1] Recent open key (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\LastKey
MS Search Assistant: [SBI $AE0C4647] Typed search terms history (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Search Assistant\ACMru
Paint Shop Pro 7: [SBI $9A5AA171] Recent file list (10 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\JASC\Paint Shop Pro 7\Recent File List
Paint Shop Pro 7: [SBI $FB631FBF] Recent GIF directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Jasc\Paint Shop Pro 7\ExportGIF\Directory
Paint Shop Pro 7: [SBI $2DC89A0E] Recent JPG directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Jasc\Paint Shop Pro 7\ExportJPG\Directory
Windows: [SBI $1E4E2003] Drivers installation paths (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Installation Sources
Windows.OpenWith: [SBI $CDE7D0A6] Open with list - .ASX extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ASX\OpenWithList
Windows.OpenWith: [SBI $F7204896] Open with list - .AVI extension (4 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList
Windows.OpenWith: [SBI $691C1B44] Open with list - .BIN extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BIN\OpenWithList
Windows.OpenWith: [SBI $A1C94E79] Open with list - .BMP extension (3 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\OpenWithList
Windows.OpenWith: [SBI $9E8D5C8A] Open with list - .CDA extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\OpenWithList
Windows.OpenWith: [SBI $99432203] Open with list - .CFG extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CFG\OpenWithList
Windows.OpenWith: [SBI $F34FE1D0] Open with list - .CUE extension (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CUE\OpenWithList
Windows Explorer: [SBI $A2C7B3CD] Recent wallpaper list (501 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU
Windows Explorer: [SBI $7308A845] Run history (8 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
Windows Explorer: [SBI $AA0766B5] Stream history (11 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU
Windows Explorer: [SBI $2026AFB6] User Assistant history IE (15 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count
Windows Explorer: [SBI $6107D172] User Assistant history files (251 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count
Windows Explorer: [SBI $B7EBA926] Last visited history (21 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
Windows Explorer: [SBI $D20DA0AD] Recent file global history (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\ComputerName
Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows Media\WMSDK\General\ComputerName
Windows Media SDK: [SBI $37AAEDE6] Computer name (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\ComputerName
Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\UniqueID
Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows Media\WMSDK\General\UniqueID
Windows Media SDK: [SBI $CAA58B6E] Unique ID (Registry change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\UniqueID
Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry value, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry value, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: [SBI $BACCD0DA] Volume serial number (Registry value, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
WinRAR: [SBI $0B56E92B] Recent file list (2 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\WinRAR\ArcHistory
WinRAR: [SBI $B84F9965] Last used directory (Registry change, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\WinRAR\General\LastFolder
WinRAR: [SBI $B510882E] Extraction directory history (6 files) (Registry key, nothing done)
HKEY_USERS\S-1-5-21-220523388-1547161642-725345543-1004\Software\WinRAR\DialogEditHistory\ExtrPath
Cookie: [SBI $49804B54] Cookie (4) (Cookie, nothing done)
Cache: [SBI $49804B54] Cache (74) (Cache, nothing done)
History: [SBI $49804B54] History (37) (History, nothing done)
Cookie: [SBI $49804B54] Cookie (712) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---
2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe (1.0.2.3)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-09-16 TeaTimer.exe (1.6.3.25)
2008-12-20 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-10-22 advcheck.dll (1.6.2.13)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-10-22 Tools.dll (2.1.6.8)
2008-11-04 Includes\Adware.sbi (*)
2008-12-09 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-09-02 Includes\Dialer.sbi (*)
2008-09-09 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-11-18 Includes\Hijackers.sbi (*)
2008-12-16 Includes\HijackersC.sbi (*)
2008-12-09 Includes\Keyloggers.sbi (*)
2008-12-16 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-11-18 Includes\Malware.sbi (*)
2008-12-16 Includes\MalwareC.sbi (*)
2008-12-16 Includes\PUPS.sbi (*)
2008-12-16 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-12-16 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-12-10 Includes\Spyware.sbi (*)
2008-12-10 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti (*)
2008-11-04 Includes\Trojans.sbi (*)
2008-12-16 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
----- END OF SPYBOT FILE -----
ComboFix 08-12-26.03 - electrochemic° 2008-12-28 8:21:53.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1611 [GMT -5:00]
Running from: c:\documents and settings\electrochemic°\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\electrochemic°\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\system32\drivers\ulfpbziy.sys
c:\windows\system32\urqQigee.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\ulfpbziy.sys
c:\windows\system32\urqQigee.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-28 )))))))))))))))))))))))))))))))
.
2008-12-27 17:48 . 2008-12-28 07:22 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\uTorrent
2008-12-27 08:48 . 2008-12-27 08:48 <DIR> d-------- c:\program files\TrayMin
2008-12-27 08:47 . 1997-01-18 11:40 299,520 --a------ c:\windows\uninst.exe
2008-12-26 10:02 . 2008-12-26 10:03 1,407 --a------ c:\windows\ATICIM.INI
2008-12-26 09:59 . 2008-12-26 09:59 <DIR> d-------- C:\ATI
2008-12-25 22:56 . 2008-12-25 22:56 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\Softland
2008-12-25 20:08 . 2008-12-27 14:20 <DIR> d-------- c:\program files\Fighter Ace Anniversary Edition
2008-12-25 15:27 . 2008-12-25 15:27 0 --a------ c:\windows\ativpsrm.bin
2008-12-25 15:18 . 2008-12-25 15:18 <DIR> d-------- c:\program files\Common Files\ATI Technologies
2008-12-25 15:16 . 2008-06-02 21:05 593,920 --a------ c:\windows\system32\ati2sgag.exe
2008-12-25 12:40 . 2008-12-26 10:12 <DIR> d-------- c:\program files\ATI Technologies
2008-12-22 06:47 . 2008-12-28 08:05 <DIR> d-------- c:\program files\Absolute Poker
2008-12-22 06:47 . 2008-12-22 06:47 <DIR> d-------- c:\program files\_uninstallation_info
2008-12-20 13:14 . 2008-12-20 13:14 153 --a------ c:\windows\wininit.ini
2008-12-20 12:06 . 2008-12-20 12:10 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-20 12:06 . 2008-12-20 14:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-19 10:59 . 2008-12-19 10:59 <DIR> d-------- c:\windows\system32\NtmsData
2008-12-19 10:41 . 2008-12-19 10:41 <DIR> d-------- c:\windows\Sun
2008-12-19 10:26 . 2008-12-19 10:26 <DIR> d-------- c:\program files\Security Task Manager
2008-12-19 10:26 . 2008-12-23 15:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\SecTaskMan
2008-12-19 06:09 . 2008-12-19 06:09 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Softland
2008-12-19 06:06 . 2008-12-19 06:06 <DIR> d-------- c:\program files\Softland
2008-12-19 06:06 . 2008-12-02 12:11 20,632 --a------ c:\windows\system32\dopdfmn6.dll
2008-12-19 06:06 . 2008-12-02 12:11 18,072 --a------ c:\windows\system32\dopdfmi6.dll
2008-12-19 06:06 . 2008-10-13 15:23 7,533 --a------ c:\windows\system32\dopdf6.ctm
2008-12-19 05:49 . 2008-12-19 05:49 <DIR> d-------- C:\Archive
2008-12-19 02:14 . 2008-12-19 02:16 43 --a------ c:\windows\gswin32.ini
2008-12-16 06:30 . 2008-12-16 06:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Syscan
2008-12-13 07:06 . 2008-12-13 07:06 <DIR> d-------- c:\program files\ratDVD
2008-12-09 15:42 . 2008-12-09 15:42 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-09 07:08 . 2008-12-09 07:08 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2008-12-08 20:45 . 2008-12-08 20:45 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\OpenOffice.org
2008-12-08 20:43 . 2008-12-08 20:43 <DIR> d-------- c:\program files\OpenOffice.org 3
2008-12-08 20:43 . 2008-12-08 20:43 <DIR> d-------- c:\program files\JRE
2008-12-08 20:43 . 2008-12-09 15:42 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-08 20:42 . 2008-12-09 15:42 <DIR> d-------- c:\program files\Java
2008-12-08 20:42 . 2008-12-08 20:42 <DIR> d-------- c:\program files\Common Files\Java
2008-12-06 23:03 . 2008-12-06 23:03 91,632 --a------ c:\windows\system32\dsofile.dll
2008-12-06 22:53 . 2008-12-06 22:53 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\KALiNKOsoft
2008-12-06 22:48 . 2008-12-06 22:48 <DIR> d-------- c:\program files\KALiNKOsoft
2008-12-06 20:19 . 2008-12-10 02:48 <DIR> d-------- c:\program files\Sauerbraten
2008-12-05 03:18 . 2008-12-05 03:18 <DIR> d-------- c:\program files\Yahoo!
2008-12-05 03:18 . 2008-12-05 03:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-05 03:14 . 2008-12-05 03:14 <DIR> d-------- c:\documents and settings\default
2008-12-04 21:21 . 2008-12-04 21:24 <DIR> d-------- c:\program files\Microsoft Streets & Trips 2009
2008-12-04 21:19 . 2008-12-04 21:19 <DIR> d-------- c:\program files\MSECache
2008-12-03 19:19 . 2008-12-03 19:19 <DIR> d-------- C:\97914e1baa146da91f977c89fc7be2d0
2008-12-03 19:18 . 2008-12-03 19:19 <DIR> d-------- C:\ecc3bbfb26245cd3fd5f96eb1e
2008-12-03 17:56 . 2008-12-03 17:56 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\j2 Global
2008-12-03 17:54 . 2008-12-03 17:54 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\j2 Messenger
2008-12-03 17:54 . 2008-12-03 17:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\j2 Messenger 4.4 Output
2008-12-03 17:54 . 2008-12-03 17:54 0 --a------ c:\windows\system32\jConnect_4_4_Port
2008-12-03 17:53 . 2008-12-03 17:54 <DIR> d-------- c:\program files\j2 Messenger 4.4
2008-12-03 02:08 . 2008-04-13 20:12 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-12-03 02:08 . 2008-04-13 14:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-12-03 02:08 . 2008-04-13 14:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2008-12-03 02:08 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-12-01 22:42 . 2008-12-01 22:42 <DIR> d-------- c:\program files\Pidgin
2008-12-01 16:02 . 2008-04-13 14:45 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-11-28 22:29 . 2008-11-28 22:57 <DIR> d-------- c:\windows\system32\Defaults
2008-11-28 22:29 . 2000-12-05 09:11 4,174,814 --a------ c:\windows\system32\CT4MGM.SF2
2008-11-28 22:17 . 2008-11-28 22:18 <DIR> d--h----- c:\program files\Creative Installation Information
2008-11-28 22:17 . 2008-11-28 22:17 <DIR> d-------- c:\program files\Common Files\Creative
2008-11-28 22:17 . 1999-12-13 01:01 44,032 --a------ c:\windows\system32\CTSVCCDA.EXE
2008-11-28 22:17 . 1999-11-18 01:00 25,088 --a------ c:\windows\system32\CTSVCCTL.EXE
2008-11-28 21:05 . 2008-12-11 04:43 <DIR> d-------- c:\program files\Bodog Poker
2008-11-28 01:20 . 2008-11-28 01:20 <DIR> d-------- c:\program files\Syscan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 13:19 --------- d-----w c:\documents and settings\electrochemic°\Application Data\.purple
2008-12-27 22:12 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-27 15:24 53,248 ----a-w c:\windows\system32\zlib.dll
2008-12-25 20:19 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-06 02:06 --------- d-----w c:\documents and settings\electrochemic°\Application Data\vlc
2008-12-02 03:41 --------- d-----w c:\program files\Common Files\GTK
2008-11-29 06:07 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2008-11-29 06:07 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS
2008-11-29 03:20 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2008-11-29 03:17 --------- d-----w c:\program files\Creative
2008-11-28 06:26 --------- d-----w c:\program files\Common Files\Adobe
2008-11-28 06:20 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-09-26 08:18 32 --sha-w c:\windows\{D3FB4103-4A4A-4968-AA94-68E0D6F76E4C}.dat
2008-09-26 08:18 32 --sha-w c:\windows\system32\{8D0A2401-5F60-430C-B7E3-558C05FB2A7A}.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-09-26 4608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Pinnacle Game Profiler"="c:\program files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe" [2008-12-06 2535424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2002-09-21 54976]
"ccRegVfy"="c:\program files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-09-21 38592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-09 136600]
"SmartGuardian"="c:\program files\SOYO\HW Monitor\ITESmart.exe" [2002-05-24 163840]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
c:\documents and settings\electrochemicø\Start Menu\Programs\Startup\
Dialog Box Assistant.lnk - c:\program files\OSDEx\OSDEx.exe [2002-07-13 176128]
c:\documents and settings\electrochemicø\Start Menu\Programs\Startup\
Dialog Box Assistant.lnk - c:\program files\OSDEx\OSDEx.exe [2002-07-13 176128]
c:\documents and settings\electrochemicø\Start Menu\Programs\Startup\
Dialog Box Assistant.lnk - c:\program files\OSDEx\OSDEx.exe [2002-07-13 176128]
c:\docume~1\ALLUSE~1\Start Menu\Programs\Startup\
Pidgin.lnk - c:\program files\Pidgin\pidgin.exe [2008-10-19 45603]
TrayMin.lnk - c:\program files\TrayMin\traymin.exe [2008-12-27 45056]
WordWeb Pro.lnk - c:\program files\WordWeb\wweb32.exe [2008-09-26 19968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-26 16:37 133104 c:\documents and settings\electrochemic°\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\j2 4.4]
--a------ 2008-10-07 16:53 95744 c:\program files\j2 Messenger 4.4\J2GDllCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
--a------ 2003-03-11 15:24 86016 c:\program files\Intel\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSnD]
-rahs---- 2008-07-07 09:42 4891472 c:\program files\Spybot - Search & Destroy\SpybotSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RegistryMechanic"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"x:\\Software Downloads\\Data.Integrity\\utorrent.exe"=
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\DRIVERS\SI3112r.sys [2007-08-29 116264]
R2 ccPxySvc;Symantec Proxy Service;"c:\program files\Norton Personal Firewall\ccPxySvc.exe" [2002-09-21 34496]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-12-25 93696]
R3 ctgame;Game Port;c:\windows\system32\DRIVERS\ctgame.sys [2002-12-30 18840]
R3 iteio;iteio;\??\c:\windows\system32\drivers\iteio.sys [2008-09-25 3680]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2008-06-27 99352]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2008-06-27 555032]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2008-06-27 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2008-06-27 566296]
S3 itsernum;itsernum Filter ÅX°Êµ{¦¡;c:\windows\system32\DRIVERS\itsernum.sys [2008-09-25 20133]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2008-09-27 112384]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-12-28 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\electrochemic []
2008-09-26 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2002-08-07 08:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
c:\windows\Downloaded Program Files\CTSUEng.ocx - c:\windows\Downloaded Program Files\CTSUEngn.ocx
O16 -: {6C269571-C6D7-4818-BCA4-32A035E8C884}
hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
c:\windows\Downloaded Program Files\CTSUEng.inf
FF - ProfilePath - c:\documents and settings\electrochemic°\Application Data\Mozilla\Firefox\Profiles\i7eprqrr.default\
FF - prefs.js: browser.search.selectedEngine - IMDB
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\electrochemic°\Application Data\Mozilla\Firefox\Profiles\i7eprqrr.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-28 08:22:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2008-12-28 8:23:29
ComboFix-quarantined-files.txt 2008-12-28 13:23:25
ComboFix2.txt 2008-12-27 22:14:49
ComboFix3.txt 2008-12-27 16:06:55
Pre-Run: 51,523,424,256 bytes free
Post-Run: 51,509,407,744 bytes free
215 --- E O F --- 2008-12-09 12:08:16
Malwarebytes' Anti-Malware 1.31
Database version: 1550
Windows 5.1.2600 Service Pack 3
12/28/2008 10:02:00 AM
mbam-log-2008-12-28 (10-02-00).txt
Scan type: Full Scan (C:\|D:\|F:\|X:\|)
Objects scanned: 227401
Time elapsed: 1 hour(s), 30 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 55
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\All Users\Application Data\SecTaskMan\eetbuk.dll.q_804F001_q (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecTaskMan\mqoiyyvv.dll.q_8041E01_q (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SecTaskMan\xrppat.dll.q_804EE01_q (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\arpqzt.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\duxohnvn.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dyhslt.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fbeuoxev.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fccaWqqr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\jjohsifj.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\lcvwftkp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\migdnhkj.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ncdcwfsq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\nuystygd.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\okhwfgfl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\powamahe.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\qvjfvb.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\reibiu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\vwgihh.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\wtyeqegc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\wvUljHYr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\xxyyvvUl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\yvjyoyhu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ulfpbziy.sys.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP25\A0004336.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP27\A0004339.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP31\A0004499.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP40\A0004751.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP46\A0004813.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP46\A0004812.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011415.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011399.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011400.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011401.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011403.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011404.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011408.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011411.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011412.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011414.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011417.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011419.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011420.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011426.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011427.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011428.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011429.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP52\A0011431.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP53\A0012452.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP54\A0012562.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
D:\Software Downloads\Data.Integrity\Max.Half.EvID4226Patch223d-en\EvID4226Patch.exe (Adware.Agent) -> Quarantined and deleted successfully.
D:\Software Downloads\Windows\Keygen, Serials, Cracks\Keygens\keygenerator_win_xp_pro.exe (Malware.Tool) -> Quarantined and deleted successfully.
D:\Software Downloads\Windows\Keygen, Serials, Cracks\Keygens\windows.xp.keygenerator.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
X:\Software Downloads\Windows\Keygen, Serials, Cracks\Keygens\keygenerator_win_xp_pro.exe (Malware.Tool) -> Quarantined and deleted successfully.
X:\Software Downloads\Windows\Keygen, Serials, Cracks\Keygens\windows.xp.keygenerator.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
X:\System Volume Information\_restore{B607BB40-5BB9-4516-A3F9-17E8582A3A8E}\RP30\A0004474.exe (Adware.Agent) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:07:12 AM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\SOYO\HW Monitor\ITESmart.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\TrayMin\traymin.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\OSDEx\OSDEx.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
X:\TorrentialRain\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SmartGuardian] C:\Program Files\SOYO\HW Monitor\ITESmart.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Pinnacle Game Profiler] "C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe" -atboottime
O4 - S-1-5-18 Startup: Dialog Box Assistant.lnk = C:\Program Files\OSDEx\OSDEx.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: E-mail.lnk = ? (User 'SYSTEM')
O4 - S-1-5-18 Startup: Shortcut to tclock.lnk = X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Dialog Box Assistant.lnk = C:\Program Files\OSDEx\OSDEx.exe (User 'Default user')
O4 - .DEFAULT Startup: E-mail.lnk = ? (User 'Default user')
O4 - .DEFAULT Startup: Shortcut to tclock.lnk = X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe (User 'Default user')
O4 - Startup: Dialog Box Assistant.lnk = C:\Program Files\OSDEx\OSDEx.exe
O4 - Startup: E-mail.lnk = ?
O4 - Startup: Shortcut to tclock.lnk = X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe
O4 - Global Startup: Pidgin.lnk = C:\Program Files\Pidgin\pidgin.exe
O4 - Global Startup: TrayMin.lnk = C:\Program Files\TrayMin\traymin.exe
O4 - Global Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\electrochemic°\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\electrochemic°\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) -
http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222471195500
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: PinnacleUpdate Service (PinnacleUpdateSvc) - KALiNKOsoft - C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle_updater.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 7641 bytes