Hi,
Attached are reports as requested.
Many thanks,
John.
ComboFix 10-08-18.04 - Any1 20/08/2010 20:26:45.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.755 [GMT 1:00]
Running from: c:\documents and settings\Any1\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\Any1\My Documents\CFScript.txt
* Created a new restore point
FILE ::
"c:\documents and settings\Any1\Start Menu\Programs\Startup\0kkaq0r.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\0p60q3c.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\1bcxd60.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\1bm3e1q.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\1ep2fgb.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\21mmsy5.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\25rmmsy.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\2nii6uu.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\2pka6ww.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\2vb3n1y.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\2ws0ooj.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\5kv38mi.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\6gbmsy5.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\6mmhyyt.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\6nyt086.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\7x2i2pu.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\8sy586w.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\9bc0ne1.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\bmrsnep2fgb.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\brhndtze.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\ccxytku6wb.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\cntu0avwr0.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\csi3kk5l.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\ddyu1q5r1.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\dtupllrhsoe.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\dyje8qrc.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\fbmm11yo.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\flm70nje.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\g3injzpfg70.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\gbmsy5uf.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\gm5n1yo70l.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\gw0yo0e3a.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\hcc70jffg.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\hstepalgm.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\i0jzqggw.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\i1eaavrr.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\kvvlccs60zf.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\lhcc70jf.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\lhxxtjjf.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\lq81cnoj.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\lrhsny3kk6.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\m5ny3jfaqm.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\mrcs9o25l.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\n0jklbrs0.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\neezqqlc.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\oe6qvrhxij1.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\pu86g81sde.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\rcd70ppgbm.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\rinjzpfg.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\s1ee6glh.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\sy5zvgbb.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\ttpffbrrndd.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\u1alccs60.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\ufqvgrsnd.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\ufw1mns870.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\v706hy0zeu.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\vmhhytez.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\vwcnx1tkkal.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\w3ydzppgbm.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\wcnx1tkka.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\wrx60zfplg.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\wxxijju8.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\x66o86a8.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\xdi6kffb.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\xookplgbssn.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\xtoo6aa6.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\xtou70a7.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\xxijju86.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\xy0uu5v0.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\y3aqqrrnddz.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\y6pq70rx.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\y7epalgm3s.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\ytpp2vwr0.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\yy6pq70rx.exe"
"c:\documents and settings\Any1\Start Menu\Programs\Startup\yy70fbww6.exe"
file zipped: c:\documents and settings\Any1\Start Menu\Programs\Startup\03e0fbb.exe
file zipped: c:\documents and settings\Any1\Start Menu\Programs\Startup\081cs60.exe
file zipped: c:\documents and settings\Any1\Start Menu\Programs\Startup\0g9iid2.exe
file zipped: c:\documents and settings\Any1\Start Menu\Programs\Startup\0m3e1qq.exe
file zipped: c:\documents and settings\Any1\Start Menu\Programs\Startup\16mmhyy.exe
file zipped: c:\documents and settings\Any1\Start Menu\Programs\Startup\c1jj083g.exe
file zipped: c:\documents and settings\Any1\Start Menu\Programs\Startup\c1yu6aa70h.exe
file zipped: C:\sssA1234567890.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Any1\Start Menu\Programs\Startup\03e0fbb.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\081cs60.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\0g9iid2.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\0kkaq0r.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\0m3e1qq.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\0p60q3c.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\16mmhyy.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\1bcxd60.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\1bm3e1q.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\1ep2fgb.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\21mmsy5.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\25rmmsy.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\2nii6uu.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\2pka6ww.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\2vb3n1y.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\2ws0ooj.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\5kv38mi.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\6gbmsy5.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\6mmhyyt.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\6nyt086.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\7x2i2pu.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\8sy586w.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\9bc0ne1.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\bmrsnep2fgb.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\brhndtze.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\c1jj083g.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\c1yu6aa70h.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\ccxytku6wb.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\cntu0avwr0.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\csi3kk5l.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\ddyu1q5r1.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\dtupllrhsoe.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\dyje8qrc.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\fbmm11yo.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\flm70nje.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\g3injzpfg70.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\gbmsy5uf.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\gm5n1yo70l.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\gw0yo0e3a.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\hcc70jffg.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\hstepalgm.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\i0jzqggw.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\i1eaavrr.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\kvvlccs60zf.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\lhcc70jf.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\lhxxtjjf.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\lq81cnoj.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\lrhsny3kk6.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\m5ny3jfaqm.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\mrcs9o25l.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\n0jklbrs0.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\neezqqlc.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\oe6qvrhxij1.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\pu86g81sde.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\rcd70ppgbm.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\rinjzpfg.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\s1ee6glh.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\sy5zvgbb.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\ttpffbrrndd.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\u1alccs60.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\ufqvgrsnd.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\ufw1mns870.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\v706hy0zeu.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\vmhhytez.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\vwcnx1tkkal.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\w3ydzppgbm.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\wcnx1tkka.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\wrx60zfplg.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\wxxijju8.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\x66o86a8.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\xdi6kffb.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\xookplgbssn.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\xtoo6aa6.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\xtou70a7.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\xxijju86.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\xy0uu5v0.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\y3aqqrrnddz.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\y6pq70rx.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\y7epalgm3s.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\ytpp2vwr0.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\yy6pq70rx.exe
c:\documents and settings\Any1\Start Menu\Programs\Startup\yy70fbww6.exe
C:\sssA1234567890.exe
.
((((((((((((((((((((((((( Files Created from 2010-07-20 to 2010-08-20 )))))))))))))))))))))))))))))))
.
2010-08-16 19:41 . 2010-08-16 19:42 -------- d-----w- c:\program files\ERUNT
2010-08-11 19:33 . 2010-08-11 19:33 12736 ---ha-w- c:\windows\system32\mlfcache.dat
2010-08-03 18:04 . 2010-08-03 18:04 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-08-03 18:04 . 2010-08-18 20:46 -------- d-----w- c:\documents and settings\Any1\Application Data\skypePM
2010-08-03 18:01 . 2010-08-18 20:50 -------- d-----w- c:\documents and settings\Any1\Application Data\Skype
2010-08-03 18:00 . 2008-04-13 23:09 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2010-08-03 18:00 . 2008-04-13 23:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2010-08-03 18:00 . 2008-04-13 23:16 10880 -c--a-w- c:\windows\system32\dllcache\ndisip.sys
2010-08-03 18:00 . 2008-04-13 23:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2010-08-03 18:00 . 2008-04-13 23:16 15232 -c--a-w- c:\windows\system32\dllcache\streamip.sys
2010-08-03 18:00 . 2008-04-13 23:16 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2010-08-03 18:00 . 2008-04-13 23:16 11136 -c--a-w- c:\windows\system32\dllcache\slip.sys
2010-08-03 18:00 . 2008-04-13 23:16 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
2010-08-03 18:00 . 2008-04-13 23:16 19200 -c--a-w- c:\windows\system32\dllcache\wstcodec.sys
2010-08-03 18:00 . 2008-04-13 23:16 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2010-08-03 18:00 . 2008-04-13 23:16 85248 -c--a-w- c:\windows\system32\dllcache\nabtsfec.sys
2010-08-03 18:00 . 2008-04-13 23:16 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2010-08-03 17:59 . 2008-04-13 23:16 17024 -c--a-w- c:\windows\system32\dllcache\ccdecode.sys
2010-08-03 17:59 . 2008-04-13 23:16 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2010-08-03 17:59 . 2008-04-14 04:42 53760 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-08-03 17:59 . 2008-04-14 04:42 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2010-08-03 17:59 . 2008-04-13 23:16 121984 -c--a-w- c:\windows\system32\dllcache\usbvideo.sys
2010-08-03 17:59 . 2008-04-13 23:16 121984 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-08-03 17:59 . 2008-04-13 23:15 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-08-03 17:59 . 2008-04-13 23:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-08-03 17:59 . 2010-08-18 20:55 -------- d-----r- c:\program files\Skype
2010-08-03 17:58 . 2010-08-18 20:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-07-25 12:52 . 2010-07-25 12:52 -------- d-----w- c:\documents and settings\Any1\Application Data\U3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-18 21:02 . 2010-03-28 17:59 -------- d-----w- c:\program files\iMesh Applications
2010-08-15 16:34 . 2010-01-24 16:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-15 16:07 . 2010-03-28 17:47 -------- d-----w- c:\documents and settings\Any1\Application Data\Spotify
2010-08-12 12:01 . 2010-01-24 16:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-12 18:19 . 2010-07-12 18:17 -------- d-----w- c:\program files\iTunes
2010-07-12 18:18 . 2010-07-12 18:18 -------- d-----w- c:\program files\iPod
2010-07-12 18:18 . 2010-03-31 15:15 -------- d-----w- c:\program files\Common Files\Apple
2010-07-12 18:11 . 2010-07-12 18:11 -------- d-----w- c:\program files\Bonjour
2010-07-12 18:08 . 2010-07-12 18:08 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-30 12:31 . 2008-04-14 00:42 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2008-06-23 15:57 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2008-04-13 20:00 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2008-04-13 19:45 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2008-04-14 00:41 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2010-01-03 20:13 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2008-04-14 00:42 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-06 16:12 . 2010-06-06 16:12 655360 ----a-w- c:\documents and settings\Any1\Application Data\Spotify\Gracenote\gnsdk_sdkmanager.dll
2010-06-06 16:12 . 2010-06-06 16:12 282624 ----a-w- c:\documents and settings\Any1\Application Data\Spotify\Gracenote\gnsdk_musicid_file.dll
2010-06-06 16:12 . 2010-06-06 16:12 208896 ----a-w- c:\documents and settings\Any1\Application Data\Spotify\Gracenote\gnsdk_dsp.dll
.
------- Sigcheck -------
[-] 2008-08-29 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-08-18_22.16.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-20 19:09 . 2010-08-20 19:09 28672 c:\windows\ERDNT\AutoBackup\20-08-2010\Users\00000002\UsrClass.dat
+ 2010-08-19 11:11 . 2010-08-19 11:11 28672 c:\windows\ERDNT\AutoBackup\19-08-2010\Users\00000002\UsrClass.dat
+ 2010-08-20 19:09 . 2005-10-20 11:02 163328 c:\windows\ERDNT\AutoBackup\20-08-2010\ERDNT.EXE
+ 2010-08-19 11:11 . 2005-10-20 11:02 163328 c:\windows\ERDNT\AutoBackup\19-08-2010\ERDNT.EXE
+ 2010-08-20 19:09 . 2010-08-20 19:09 6901760 c:\windows\ERDNT\AutoBackup\20-08-2010\Users\00000001\NTUSER.DAT
+ 2010-08-19 11:11 . 2010-08-19 11:11 6901760 c:\windows\ERDNT\AutoBackup\19-08-2010\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 339968]
"AGRSMMSG"="AGRSMMSG.exe" [2004-08-30 88363]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\Any1\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
Contents of the 'Scheduled Tasks' folder
2010-08-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
2010-08-19 c:\windows\Tasks\PCConfidential.job
- c:\program files\Winferno\PC Confidential\PCConfidential.exe [2010-04-27 13:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.sky.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://bq.kp.2020.net/planner/Core/Player/2020PlayerAX_Win32.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-20 20:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x862A5ACE]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf766ff28
\Driver\ACPI -> ACPI.sys @ 0xf75c2cb8
\Driver\atapi -> atapi.sys @ 0xf7536852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0615
ParseProcedure -> ntoskrnl.exe @ 0x8056c3ac
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0615
ParseProcedure -> ntoskrnl.exe @ 0x8056c3ac
NDIS: Intel(R) PRO/Wireless 2200BG Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf7442bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7431a0d
SendHandler -> NDIS.sys @ 0xf7445b40
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(760)
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(820)
c:\windows\system32\WININET.dll
.
Completion time: 2010-08-20 20:38:56
ComboFix-quarantined-files.txt 2010-08-20 19:38
ComboFix2.txt 2010-08-19 20:47
ComboFix3.txt 2010-08-18 22:21
Pre-Run: 53,563,887,616 bytes free
Post-Run: 53,552,730,112 bytes free
- - End Of File - - 52EE18694C0AC91CBD28F1BC5BED32D1
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Bredolabfb5.zip Win32/Bagle.gen.zip worm
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RegistryHelper1.zip Win32/Bagle.gen.zip worm
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RegistryHelper2.zip Win32/Bagle.gen.zip worm
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\RegistryHelper3.zip Win32/Bagle.gen.zip worm
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\xwponeh.exe.vir Win32/Tofsee.AA trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\0kkaq0r.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\0p60q3c.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\1bcxd60.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\1bm3e1q.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\1ep2fgb.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\21mmsy5.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\25rmmsy.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\2nii6uu.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\2pka6ww.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\2vb3n1y.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\2ws0ooj.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\5kv38mi.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\6gbmsy5.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\6mmhyyt.exe.vir Win32/Lethic.AA trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\6nyt086.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\7x2i2pu.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\8sy586w.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\9bc0ne1.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\bmrsnep2fgb.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\brhndtze.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\ccxytku6wb.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\cntu0avwr0.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\csi3kk5l.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\ddyu1q5r1.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\dtupllrhsoe.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\dyje8qrc.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\fbmm11yo.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\flm70nje.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\g3injzpfg70.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\gbmsy5uf.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\gm5n1yo70l.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\gw0yo0e3a.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\hcc70jffg.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\hstepalgm.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\i0jzqggw.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\i1eaavrr.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\kvvlccs60zf.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\lhcc70jf.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\lhxxtjjf.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\lq81cnoj.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\lrhsny3kk6.exe.vir Win32/Lethic.AA trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\m5ny3jfaqm.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\mrcs9o25l.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\n0jklbrs0.exe.vir Win32/Lethic.AA trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\neezqqlc.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\oe6qvrhxij1.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\pu86g81sde.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\rcd70ppgbm.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\rinjzpfg.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\s1ee6glh.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\sy5zvgbb.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\ttpffbrrndd.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\u1alccs60.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\ufqvgrsnd.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\ufw1mns870.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\v706hy0zeu.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\vmhhytez.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\vwcnx1tkkal.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\w3ydzppgbm.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\wcnx1tkka.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\wrx60zfplg.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\wxxijju8.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\x66o86a8.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\xdi6kffb.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\xookplgbssn.exe.vir a variant of Win32/Injector.CQB trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\xtoo6aa6.exe.vir a variant of Win32/Injector.CQB trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\xtou70a7.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\xxijju86.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\xy0uu5v0.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\y3aqqrrnddz.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\y6pq70rx.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\y7epalgm3s.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\ytpp2vwr0.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\yy6pq70rx.exe.vir a variant of Win32/Injector.CQE trojan
C:\Qoobox\Quarantine\C\Documents and Settings\Any1\Start Menu\Programs\Startup\yy70fbww6.exe.vir a variant of Win32/Injector.CQD trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\6to4ex.dll.vir a variant of Win32/Routmo.N trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP3\A0000288.exe a variant of Win32/Injector.CRC trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP3\A0000290.exe Win32/Tofsee.AA trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP3\A0000570.dll a variant of Win32/Routmo.N trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000836.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000838.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000840.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000841.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000842.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000843.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000844.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000845.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000846.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000847.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000848.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000849.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000850.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000851.exe Win32/Lethic.AA trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000852.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000853.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000854.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000855.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000856.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000857.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000860.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000861.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000862.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000863.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000864.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000865.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000866.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000867.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000868.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000869.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000870.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000871.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000872.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000873.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000874.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000875.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000876.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000877.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000878.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000879.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000880.exe Win32/Lethic.AA trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000881.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000882.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000883.exe Win32/Lethic.AA trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000884.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000885.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000886.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000887.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000888.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000889.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000890.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000891.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000892.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000893.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000894.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000895.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000896.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000897.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000898.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000899.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000900.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000901.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000902.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000903.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000904.exe a variant of Win32/Injector.CQB trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000905.exe a variant of Win32/Injector.CQB trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000906.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000907.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000908.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000909.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000910.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000911.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000912.exe a variant of Win32/Injector.CQD trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000913.exe a variant of Win32/Injector.CQE trojan
C:\System Volume Information\_restore{66971694-BB6C-4B8A-A97E-01949B4BFD14}\RP4\A0000914.exe a variant of Win32/Injector.CQD trojan
DDS (Ver_10-03-17.01) - NTFSx86
Run by Any1 at 21:29:43.12 on 20/08/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.642 [GMT 1:00]
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Any1\My Documents\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.sky.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32
StartupFolder: c:\docume~1\any1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://bq.kp.2020.net/planner/Core/Player/2020PlayerAX_Win32.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1262556294453
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
LSA: Authentication Packages = msv1_0 nwprovau
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2010-08-20 20:09:20 0 d-----w- c:\program files\ESET
2010-08-20 19:26:27 1213 ----a-w- C:\CF-Submit.htm
2010-08-18 22:01:06 0 d-sha-r- C:\cmdcons
2010-08-18 21:58:08 98816 ----a-w- c:\windows\sed.exe
2010-08-18 21:58:08 77312 ----a-w- c:\windows\MBR.exe
2010-08-18 21:58:08 256512 ----a-w- c:\windows\PEV.exe
2010-08-18 21:58:08 161792 ----a-w- c:\windows\SWREG.exe
2010-08-18 20:55:35 0 d-----w- c:\windows\system32\appmgmt
2010-08-16 15:36:49 0 d-----w- c:\windows\pss
2010-08-15 18:01:23 91 ----a-w- c:\windows\wininit.ini
2010-08-11 19:33:49 12736 ---ha-w- c:\windows\system32\mlfcache.dat
2010-08-03 18:04:01 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-08-03 17:59:57 17024 -c--a-w- c:\windows\system32\dllcache\ccdecode.sys
2010-08-03 17:59:02 0 d-----r- c:\program files\Skype
==================== Find3M ====================
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-01-03 20:32:59 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012010010320100104\index.dat
============= FINISH: 21:31:01.03 ===============