ComboFix 09-08-01.06 - JFairclough 08/01/2009 23:04.2.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1737 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\jfairclough\Desktop\CFScript.txt
AV: AVG 7.5.516 *On-access scanning enabled* (Updated) {41564737-3200-1071-989B-0000E87B4FB1}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
file zipped: c:\windows\1z539virusf.dll
file zipped: c:\windows\3d0asparse159z.exe
file zipped: c:\windows\3de69h5ez1970.exe
file zipped: c:\windows\4125bazkdo9r559.bin
file zipped: c:\windows\4b1adown5ozder395.dll
file zipped: c:\windows\5191spy9are186z.bin
file zipped: c:\windows\54359teal384z.bin
file zipped: c:\windows\555tr9jzf8.exe
file zipped: c:\windows\55davz92102.dll
file zipped: c:\windows\55f5t9zef2544.dll
file zipped: c:\windows\56245s9amboz75.exe
file zipped: c:\windows\58129py21z.bin
file zipped: c:\windows\5dd9baczdoo5718.bin
file zipped: c:\windows\5f96vzr1991.bin
file zipped: c:\windows\6179szyware951.dll
file zipped: c:\windows\6250stealz968.dll
file zipped: c:\windows\7456szarse9559.dll
file zipped: c:\windows\75z8a5dware26279.exe
file zipped: c:\windows\7c255zeal1967.bin
file zipped: c:\windows\7fe59zr696.exe
file zipped: c:\windows\8151n9t5a-vzrus2cf.dll
file zipped: c:\windows\82649otz5-virus379.exe
file zipped: c:\windows\8399hackzool75b.exe
file zipped: c:\windows\84bthief39z5.bin
file zipped: c:\windows\84zs5arse979.bin
file zipped: c:\windows\899sz56fc.bin
file zipped: c:\windows\9049zackt5ol442.dll
file zipped: c:\windows\92536spyz57.exe
file zipped: c:\windows\92b5d9zare277.exe
file zipped: c:\windows\9326tr9jz2a5.dll
file zipped: c:\windows\96c5threat39z0.bin
file zipped: c:\windows\9885stzal1565.exe
file zipped: c:\windows\a91thiez175.bin
file zipped: c:\windows\c4dba5k9oor972z.bin
file zipped: c:\windows\system32\107079ot-a-viruz253.exe
file zipped: c:\windows\system32\1195zwormc0.bin
file zipped: c:\windows\system32\1245zwo9m6b5.exe
file zipped: c:\windows\system32\1365spzmbo9652.exe
file zipped: c:\windows\system32\14091spy3z5.dll
file zipped: c:\windows\system32\15392not-a-viru549z.bin
file zipped: c:\windows\system32\17f3ad59are23z7.bin
file zipped: c:\windows\system32\1957hackt9ol5az.bin
file zipped: c:\windows\system32\1z799wor5912.exe
file zipped: c:\windows\system32\20895w9rz659.dll
file zipped: c:\windows\system32\222285irus49z.dll
file zipped: c:\windows\system32\22d1bzckdoor35359.dll
file zipped: c:\windows\system32\23545noz-a-vir5s9b8.dll
file zipped: c:\windows\system32\2386vir9z25.exe
file zipped: c:\windows\system32\245255ackto9l2z3.bin
file zipped: c:\windows\system32\24espazse859.bin
file zipped: c:\windows\system32\26398not-a-vi9u5z06.bin
file zipped: c:\windows\system32\27cdownloa9er253z.bin
file zipped: c:\windows\system32\28295tro56z1.dll
file zipped: c:\windows\system32\28561n9t-a-5zrus3a0.dll
file zipped: c:\windows\system32\299329roz755.exe
file zipped: c:\windows\system32\2999a59zare248.exe
file zipped: c:\windows\system32\29abszeal31625.dll
file zipped: c:\windows\system32\31982not-a-5irusz7d.exe
file zipped: c:\windows\system32\3669t5oj6z.bin
file zipped: c:\windows\system32\373bsteaz5689.exe
file zipped: c:\windows\system32\3b25backdoor55z9.bin
file zipped: c:\windows\system32\3d51zd5war91763.exe
file zipped: c:\windows\system32\3z99spa5se9752.exe
file zipped: c:\windows\system32\41c5threat2z109.exe
file zipped: c:\windows\system32\4325steal19z2.bin
file zipped: c:\windows\system32\45b4t9zef6565.dll
file zipped: c:\windows\system32\4710ha9kt5ol5zb.dll
file zipped: c:\windows\system32\4fcev5z3519.bin
file zipped: c:\windows\system32\51e9bzckdoor1891.exe
file zipped: c:\windows\system32\573a95arze797.exe
file zipped: c:\windows\system32\57925a9kzoor690.exe
file zipped: c:\windows\system32\5a679iz555.bin
file zipped: c:\windows\system32\5aeddow9loaderz252.dll
file zipped: c:\windows\system32\5cz9ad9ware1365.bin
file zipped: c:\windows\system32\5zc19ir2716.bin
file zipped: c:\windows\system32\67ba59dooz1582.bin
file zipped: c:\windows\system32\6e07backdo59158z.exe
file zipped: c:\windows\system32\6z9fthreat15219.dll
file zipped: c:\windows\system32\743addwa951389z.bin
file zipped: c:\windows\system32\757espa9ze2618.exe
file zipped: c:\windows\system32\7954thi9f2z21.dll
file zipped: c:\windows\system32\7998t9zeat19655.bin
file zipped: c:\windows\system32\9513hz95tool3c.exe
file zipped: c:\windows\system32\97a6thi5f15z9.bin
file zipped: c:\windows\system32\9922worm21z5.bin
file zipped: c:\windows\system32\az9teal2655.bin
file zipped: c:\windows\system32\c659yzare2990.dll
file zipped: c:\windows\system32\tixwf8p6.exe
file zipped: c:\windows\system32\z0132troj25a9.exe
file zipped: c:\windows\system32\z09859py456.dll
file zipped: c:\windows\system32\z15fdownloade92848.dll
file zipped: c:\windows\system32\z35999pambot718.dll
file zipped: c:\windows\system32\zc5edo9nloader152.exe
file zipped: c:\windows\system32\zc605teal993.dll
file zipped: c:\windows\system32\zf09threat10513.exe
file zipped: c:\windows\z0973not-a-9irus356.bin
file zipped: c:\windows\z4228w59m2f4.exe
file zipped: c:\windows\z598s9yfe.dll
file zipped: c:\windows\zeb9thief539.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\1z539virusf.dll
c:\windows\3c9b5hze9t23535.cpl
c:\windows\3d0asparse159z.exe
c:\windows\3d8dzwnl9ader1556.cpl
c:\windows\3de69h5ez1970.exe
c:\windows\3f9a59eal1z9.cpl
c:\windows\3fz5download5r14759.cpl
c:\windows\3z375not-a5vi9us316.cpl
c:\windows\4021spy59re1491z.cpl
c:\windows\4125bazkdo9r559.bin
c:\windows\4165hzcktool920.dll
c:\windows\4165ziru9593.exe
c:\windows\4212azdwa5e3960.ocx
c:\windows\4219ownloa5erz61.dll
c:\windows\422z5reat16694.ocx
c:\windows\4291down9oadzr13785.ocx
c:\windows\42z6dow5lo9der143.exe
c:\windows\43bfzo5nloader2589.exe
c:\windows\4428zackdo952537.dll
c:\windows\44c6threa5629z.bin
c:\windows\455ath5ea919658z.cpl
c:\windows\456aszeal2429.dll
c:\windows\45829zr799.dll
c:\windows\46b5threzt14809.ocx
c:\windows\47z8not-a-v95us70c.dll
c:\windows\493edown5oader2z16.bin
c:\windows\4959tz5l2716.ocx
c:\windows\495fsp5r9e5z4.cpl
c:\windows\4985wor9z05.exe
c:\windows\4abzt5ie92855.ocx
c:\windows\4b1adown5ozder395.dll
c:\windows\4b56tzre9t27889.bin
c:\windows\4d9ddowzloader9205.dll
c:\windows\4da5addwa9e888z.dll
c:\windows\4dz9thief159.dll
c:\windows\50cdsteal329z.exe
c:\windows\50e15t9az3192.bin
c:\windows\5109dowz5oad9r3054.bin
c:\windows\5147spambo918z.ocx
c:\windows\5191spy9are186z.bin
c:\windows\5196zworm393.cpl
c:\windows\51z3spyware1595.cpl
c:\windows\52516wo9m4bz.bin
c:\windows\5362szarse197.bin
c:\windows\536z8troj479.cpl
c:\windows\539bzownloa5er2824.ocx
c:\windows\54359teal384z.bin
c:\windows\543cdownload9r2213z.exe
c:\windows\5456st9alz22.cpl
c:\windows\545daddwar9318z.dll
c:\windows\5469spywaze2918.bin
c:\windows\555tr9jzf8.exe
c:\windows\5572virz559.cpl
c:\windows\5594thi5f2935z.bin
c:\windows\5595stzal2943.ocx
c:\windows\5595virus7z9.exe
c:\windows\55999ddware358z.bin
c:\windows\55c2zir9922.bin
c:\windows\55davz92102.dll
c:\windows\55f5t9zef2544.dll
c:\windows\56245s9amboz75.exe
c:\windows\563z6virus689.bin
c:\windows\56z7worm993.bin
c:\windows\5729addw5re1936z.dll
c:\windows\5768sparsz1119.ocx
c:\windows\57794virus7z29.exe
c:\windows\5795spy92z.cpl
c:\windows\58129py21z.bin
c:\windows\58672spamb9z7d9.dll
c:\windows\589ca5dzare3082.exe
c:\windows\590fspyware19z8.bin
c:\windows\5921down5ozder841.bin
c:\windows\59286hazktoo9521.dll
c:\windows\5947vir1z965.exe
c:\windows\5987z9r5at11031.exe
c:\windows\599359pz46.exe
c:\windows\5995down5ozder1056.bin
c:\windows\59a5tzief3250.ocx
c:\windows\59z9vir395.ocx
c:\windows\5a37backdozr9603.bin
c:\windows\5abdownlozder996.cpl
c:\windows\5b6downlo5de91z20.ocx
c:\windows\5d9zspyware411.exe
c:\windows\5dd9baczdoo5718.bin
c:\windows\5e95addware9z1.ocx
c:\windows\5eb2vir510z9.cpl
c:\windows\5f52zp9rse578.exe
c:\windows\5f96vzr1991.bin
c:\windows\5f9caddwa9e16z0.bin
c:\windows\5fa1downzo9der1637.ocx
c:\windows\5z59spy655.ocx
c:\windows\5z829spy3b8.ocx
c:\windows\5z91tro5600.ocx
c:\windows\5zd0backdoor22879.ocx
c:\windows\5zedv5r692.ocx
c:\windows\6059backd9orz800.bin
c:\windows\60z1spars95230.ocx
c:\windows\6153z9r3138.ocx
c:\windows\6179szyware951.dll
c:\windows\61905d9wzre2411.exe
c:\windows\6204z9rm29c5.cpl
c:\windows\6250stealz968.dll
c:\windows\62a0th9eatz2045.exe
c:\windows\6409zpy5are2371.cpl
c:\windows\6503bac5do9r17z.bin
c:\windows\650espyware9z69.dll
c:\windows\65309ir5sz15.bin
c:\windows\6557st5zl1919.ocx
c:\windows\675sp9zbot3e25.ocx
c:\windows\67679zt-a-vi5use4.bin
c:\windows\6799worm553z.ocx
c:\windows\679zt5oj297.ocx
c:\windows\6c5zthreat92487.exe
c:\windows\6e8zsparse93765.cpl
c:\windows\6f5at5ief205z9.exe
c:\windows\6z499ro5235.ocx
c:\windows\7364sp5mb9t1z5.bin
c:\windows\7456szarse9559.dll
c:\windows\749pzrse2985.ocx
c:\windows\7506tzief798.dll
c:\windows\756zbac9door3131.bin
c:\windows\75b79parsez764.cpl
c:\windows\75ff9pyware32z2.bin
c:\windows\75z8a5dware26279.exe
c:\windows\7639downl5adez1204.ocx
c:\windows\7656szywa9e9105.cpl
c:\windows\77229o5-a-vizus751.dll
c:\windows\7756thi9z734.cpl
c:\windows\7916zackdoor5093.exe
c:\windows\7957noz-a-vi5us4e4.dll
c:\windows\7bf79hreat10z955.dll
c:\windows\7c255zeal1967.bin
c:\windows\7ca95ackzoor3934.exe
c:\windows\7f019py5are25z1.exe
c:\windows\7fe59zr696.exe
c:\windows\7ffzaddware5509.exe
c:\windows\8008z9oj485.exe
c:\windows\8151n9t5a-vzrus2cf.dll
c:\windows\82649otz5-virus379.exe
c:\windows\8399hackzool75b.exe
c:\windows\8451troj59z.cpl
c:\windows\8458hacktozl5109.bin
c:\windows\84bthief39z5.bin
c:\windows\84zs5arse979.bin
c:\windows\8567v9rus11z.ocx
c:\windows\899sz56fc.bin
c:\windows\8a4a5dware12z9.cpl
c:\windows\8acbackdoo9591z.ocx
c:\windows\8f2tzief23759.bin
c:\windows\901755zt-a-virus3c3.cpl
c:\windows\9041spambot15z.bin
c:\windows\9049zackt5ol442.dll
c:\windows\905fzparse315.cpl
c:\windows\91285zoj199.dll
c:\windows\92536spyz57.exe
c:\windows\92b5d9zare277.exe
c:\windows\92ccbzckdoo51229.ocx
c:\windows\9326tr9jz2a5.dll
c:\windows\93709spy53z.dll
c:\windows\94206worm5b1z.bin
c:\windows\9507steal317z.ocx
c:\windows\95c5zarse2364.dll
c:\windows\95f2addzare420.exe
c:\windows\96c5threat39z0.bin
c:\windows\9720thiez2245.ocx
c:\windows\975ebackdozr2149.bin
c:\windows\9791zroj9b5.bin
c:\windows\9885stzal1565.exe
c:\windows\9995wozm625.cpl
c:\windows\99espa5se2013z.exe
c:\windows\9dz8spyware511.bin
c:\windows\9f2z5parse1730.cpl
c:\windows\9z9455irus48c.cpl
c:\windows\a19thzef1529.bin
c:\windows\a91thiez175.bin
c:\windows\a92vir2255z.ocx
c:\windows\b229hrea523z49.dll
c:\windows\c4dba5k9oor972z.bin
c:\windows\c99thiz52901.dll
c:\windows\ce5do9nloaz5r3158.exe
c:\windows\ceethrez59911.bin
c:\windows\d3b9pzr5e895.dll
c:\windows\ed6baczd5o9581.exe
c:\windows\f95downloadez9005.cpl
c:\windows\ffsze9l5872.bin
c:\windows\system32\107079ot-a-viruz253.exe
c:\windows\system32\1092z5dware766.exe
c:\windows\system32\1094zspy75f.ocx
c:\windows\system32\11925zo9m28c.dll
c:\windows\system32\1195zwormc0.bin
c:\windows\system32\1245zwo9m6b5.exe
c:\windows\system32\1254backdo9z2661.exe
c:\windows\system32\127795irus32bz.cpl
c:\windows\system32\1295st5az2515.bin
c:\windows\system32\129z2wo59d5.bin
c:\windows\system32\136509iru54zc.ocx
c:\windows\system32\1365spzmbo9652.exe
c:\windows\system32\14043s5azb9t783.bin
c:\windows\system32\14091spy3z5.dll
c:\windows\system32\14459zr9j5ea5.bin
c:\windows\system32\1495zvi5u973a.dll
c:\windows\system32\15048zpy5965.dll
c:\windows\system32\15367tzoj52e9.ocx
c:\windows\system32\15392not-a-viru549z.bin
c:\windows\system32\153995py4z8.cpl
c:\windows\system32\154529py553z.cpl
c:\windows\system32\15611hack9ozlf7.bin
c:\windows\system32\15629troj2d9z.dll
c:\windows\system32\15722noz-a-virus195.dll
c:\windows\system32\1579zwo9m196.bin
c:\windows\system32\1583spa9sez255.cpl
c:\windows\system32\15926not-a-v5rzs6c.bin
c:\windows\system32\1599vzr939.ocx
c:\windows\system32\15z4995oj19d.bin
c:\windows\system32\16553v9zus2f7.exe
c:\windows\system32\1659s9ywarz1195.exe
c:\windows\system32\165fthreat207z19.cpl
c:\windows\system32\16z55spy5a59.ocx
c:\windows\system32\1711zvirus595.exe
c:\windows\system32\174195orm1ez.cpl
c:\windows\system32\17536viru95ze.cpl
c:\windows\system32\17598zpy349.ocx
c:\windows\system32\17764trzj3935.ocx
c:\windows\system32\17856worm65z9.ocx
c:\windows\system32\1785threzt93296.bin
c:\windows\system32\17922zi5us296.ocx
c:\windows\system32\1798sparse28z15.cpl
c:\windows\system32\179z6hack5ool293.cpl
c:\windows\system32\17f3ad59are23z7.bin
c:\windows\system32\17z01v5rus98e.bin
c:\windows\system32\18299v5rzs516.cpl
c:\windows\system32\18645szamb9t27a.dll
c:\windows\system32\18719s5az9otcb.cpl
c:\windows\system32\19575virus24z.bin
c:\windows\system32\1957hackt9ol5az.bin
c:\windows\system32\1989sz5rs91492.dll
c:\windows\system32\198es5yware19z3.cpl
c:\windows\system32\1990wo9z5f6.cpl
c:\windows\system32\19939a5ktoolz62.exe
c:\windows\system32\1ac6sza59e234.exe
c:\windows\system32\1c1cadd59re58z.exe
c:\windows\system32\1d58vir3z09.cpl
c:\windows\system32\1d94bzckd5or1972.cpl
c:\windows\system32\1f28addwaze2957.dll
c:\windows\system32\1z39addware1515.dll
c:\windows\system32\1z628no9-a-virus355.ocx
c:\windows\system32\1z799wor5912.exe
c:\windows\system32\1z85spyware9537.dll
c:\windows\system32\1z97steal2593.ocx
c:\windows\system32\1z9989r5j5a3.cpl
c:\windows\system32\200z695y191.dll
c:\windows\system32\2019spars51z77.cpl
c:\windows\system32\206935roj611z.cpl
c:\windows\system32\20895w9rz659.dll
c:\windows\system32\21107zot9a-vir5s320.dll
c:\windows\system32\2128z9acktool2f75.ocx
c:\windows\system32\215z8worm6519.dll
c:\windows\system32\222285irus49z.dll
c:\windows\system32\22393sz94a5.dll
c:\windows\system32\225989py190z.bin
c:\windows\system32\2295s5arse1208z.bin
c:\windows\system32\22d1bzckdoor35359.dll
c:\windows\system32\23545noz-a-vir5s9b8.dll
c:\windows\system32\2375zvir9s6f5.dll
c:\windows\system32\2386vir9z25.exe
c:\windows\system32\23c3add9aze625.bin
c:\windows\system32\23f4s9yw5rz1731.ocx
c:\windows\system32\24059hack59ol2ze.ocx
c:\windows\system32\2430ztr5931d.exe
c:\windows\system32\245255ackto9l2z3.bin
c:\windows\system32\245aba9kdooz48.exe
c:\windows\system32\24be5dzware24009.ocx
c:\windows\system32\24espazse859.bin
c:\windows\system32\25199troj2zc.cpl
c:\windows\system32\25432n9t-a-virus7fz.cpl
c:\windows\system32\25769worz169.bin
c:\windows\system32\25878w5rmz92.ocx
c:\windows\system32\25ae5ir329z.bin
c:\windows\system32\25z02t9oj6fd5.bin
c:\windows\system32\25z8thief839.dll
c:\windows\system32\260739ot-azvirus533.bin
c:\windows\system32\26398not-a-vi9u5z06.bin
c:\windows\system32\26e2sp9rsz1615.cpl
c:\windows\system32\26fzs5e9l2539.cpl
c:\windows\system32\27cdownloa9er253z.bin
c:\windows\system32\28134zroj595.bin
c:\windows\system32\28157s9yza2.dll
c:\windows\system32\28295tro56z1.dll
c:\windows\system32\28561n9t-a-5zrus3a0.dll
c:\windows\system32\28587hzc95ool1b4.bin
c:\windows\system32\28865z9a5bot43a.ocx
c:\windows\system32\28943hacztool453.bin
c:\windows\system32\293645py1z.bin
c:\windows\system32\293downlo5der284z.ocx
c:\windows\system32\29487zackto5l3d9.bin
c:\windows\system32\29551wormbfz.bin
c:\windows\system32\299329roz755.exe
c:\windows\system32\29944spam5ot5z4.bin
c:\windows\system32\2999a59zare248.exe
c:\windows\system32\299ea5dwar92464z.exe
c:\windows\system32\299t5izf2296.cpl
c:\windows\system32\299z2wo5m6f.exe
c:\windows\system32\29abszeal31625.dll
c:\windows\system32\2a889dd5are190z.dll
c:\windows\system32\2a9bspy5aze76.cpl
c:\windows\system32\2azaadd9are335.ocx
c:\windows\system32\2c1abac9d5zr799.exe
c:\windows\system32\2c28spywa9z13345.bin
c:\windows\system32\2cf2a9zware2570.dll
c:\windows\system32\2e9asp5rze990.cpl
c:\windows\system32\2ef459dware5z9.ocx
c:\windows\system32\2f95thrzat23465.bin
c:\windows\system32\2z037sp59.exe
c:\windows\system32\2z985w9rm362.bin
c:\windows\system32\2ze9st5al302.exe
c:\windows\system32\3111s9y5are300z.ocx
c:\windows\system32\31982not-a-5irusz7d.exe
c:\windows\system32\32155ha9ktooz1e2.ocx
c:\windows\system32\32560spyz9f.bin
c:\windows\system32\32599zroj90.cpl
c:\windows\system32\3264dzwn5oader2299.dll
c:\windows\system32\326not-59virus5d6z.cpl
c:\windows\system32\33aastealz599.dll
c:\windows\system32\340259y1z4.cpl
c:\windows\system32\343czh5ef2691.exe
c:\windows\system32\34d5backd9or7z5.ocx
c:\windows\system32\3596vir2z82.ocx
c:\windows\system32\35f2steaz3249.dll
c:\windows\system32\3669t5oj6z.bin
c:\windows\system32\3699v9z559.exe
c:\windows\system32\369zvir1195.ocx
c:\windows\system32\373bsteaz5689.exe
c:\windows\system32\3799not-a-z5rus7db.exe
c:\windows\system32\38499o5m3acz.ocx
c:\windows\system32\38de9pazs51581.cpl
c:\windows\system32\3b25backdoor55z9.bin
c:\windows\system32\3b2zs5ywa9e1029.cpl
c:\windows\system32\3b9zadd5are1097.cpl
c:\windows\system32\3bbbt5reaz9314.ocx
c:\windows\system32\3bd8downzoa95r513.ocx
c:\windows\system32\3c1threat1594z9.ocx
c:\windows\system32\3d50spyza9e369.exe
c:\windows\system32\3d51zd5war91763.exe
c:\windows\system32\3db7threa9z2504.ocx
c:\windows\system32\3e65bac9door1884z.ocx
c:\windows\system32\3fz2sparse90225.exe
c:\windows\system32\3z509hief1099.bin
c:\windows\system32\3z99spa5se9752.exe
c:\windows\system32\4093not-a-virz5589.exe
c:\windows\system32\40dabaczdoor25249.cpl
c:\windows\system32\4175vi59z28a.exe
c:\windows\system32\41c5threat2z109.exe
c:\windows\system32\41ccs5e9l2565z.cpl
c:\windows\system32\42z6no9-a-virus4545.ocx
c:\windows\system32\4325steal19z2.bin
c:\windows\system32\4512wor5ze09.dll
c:\windows\system32\4557s5ealz945.cpl
c:\windows\system32\4569szyware51.cpl
c:\windows\system32\4589th5zat15912.exe
c:\windows\system32\4595steal2z68.exe
c:\windows\system32\45b4t9zef6565.dll
c:\windows\system32\45c79pywarez526.ocx
c:\windows\system32\4654zir957.ocx
c:\windows\system32\4705tro9z45.dll
c:\windows\system32\4710ha9kt5ol5zb.dll
c:\windows\system32\47615irus259z.exe
c:\windows\system32\4796hacktool4z65.cpl
c:\windows\system32\4853viz3192.bin
c:\windows\system32\48565hreaz5339.cpl
c:\windows\system32\487dowzlo5der1809.bin
c:\windows\system32\48f95teal2089z.ocx
c:\windows\system32\4906hac9tozl457.exe
c:\windows\system32\4919sparsz3557.bin
c:\windows\system32\4948tzreat28354.ocx
c:\windows\system32\495virzs7d25.ocx
c:\windows\system32\4982viz2155.ocx
c:\windows\system32\49b4b5ck9oor1214z.bin
c:\windows\system32\4a79ba5kdooz1485.ocx
c:\windows\system32\4b1at5rea9159z0.bin
c:\windows\system32\4bbavi95z07.exe
c:\windows\system32\4c57z9ckdoo52046.dll
c:\windows\system32\4fcev5z3519.bin
c:\windows\system32\50d59hiefz381.cpl
c:\windows\system32\5160zir5s296.cpl
c:\windows\system32\51959spam9oz601.bin
c:\windows\system32\51e0thrzat155099.ocx
c:\windows\system32\51e9bzckdoor1891.exe
c:\windows\system32\527z9spy334.exe
c:\windows\system32\52d6zteal495.ocx
c:\windows\system32\5396spywa5e2072z.exe
c:\windows\system32\54335hacktz9l3af.ocx
c:\windows\system32\5475tr9z57d.ocx
c:\windows\system32\54952not-azvirus1ea.dll
c:\windows\system32\55059acktooz5b1.ocx
c:\windows\system32\55257worm94z.exe
c:\windows\system32\5528th9eat1z826.ocx
c:\windows\system32\5549spyz599.exe
c:\windows\system32\5559virus31z.cpl
c:\windows\system32\55zthie9100.exe
c:\windows\system32\562downloa5z950.ocx
c:\windows\system32\5645dowz9oader2868.ocx
c:\windows\system32\5651spzmbot60f9.cpl
c:\windows\system32\573a95arze797.exe
c:\windows\system32\5750b9ckzoo52736.cpl
c:\windows\system32\57925a9kzoor690.exe
c:\windows\system32\5825b9ckdoor3z16.exe
c:\windows\system32\58z39ownloader827.bin
c:\windows\system32\58z7v9r2155.bin
c:\windows\system32\5909spzmbot53a.ocx
c:\windows\system32\59243virus608z.ocx
c:\windows\system32\5926zpa5bot97f.cpl
c:\windows\system32\59316troj3z.dll
c:\windows\system32\59329wzrm6ef.exe
c:\windows\system32\5935zddware96.bin
c:\windows\system32\5945thief152z.cpl
c:\windows\system32\59473worm56z.bin
c:\windows\system32\59491notza-virus5e39.dll
c:\windows\system32\5977viz2656.ocx
c:\windows\system32\598zpambot26b.ocx
c:\windows\system32\5994v9r105z.exe
c:\windows\system32\59cfbackdooz11815.cpl
c:\windows\system32\59f6sparse5169z.dll
c:\windows\system32\5a3dth9ez2493.bin
c:\windows\system32\5a679iz555.bin
c:\windows\system32\5a9zspywar91649.bin
c:\windows\system32\5aeddow9loaderz252.dll
c:\windows\system32\5b94ba9kdo5r1z15.bin
c:\windows\system32\5cz9ad9ware1365.bin
c:\windows\system32\5d96sz9ware5135.cpl
c:\windows\system32\5d9downlzad9r973.cpl
c:\windows\system32\5ddfste95z845.cpl
c:\windows\system32\5dz9s5arse348.ocx
c:\windows\system32\5e92z9ief858.ocx
c:\windows\system32\5z469spambot639.ocx
c:\windows\system32\5z736s9y46a.ocx
c:\windows\system32\5zc19ir2716.bin
c:\windows\system32\5zc8vir2932.bin
c:\windows\system32\5zecv5r2986.cpl
c:\windows\system32\603a9hze5t12857.dll
c:\windows\system32\6129spyza5e3169.cpl
c:\windows\system32\622zvi9u5754.dll
c:\windows\system32\64f0s9eaz5045.exe
c:\windows\system32\6512zor9209.cpl
c:\windows\system32\6557zorm5f9.exe
c:\windows\system32\6597stezl4695.ocx
c:\windows\system32\65z5spa9se429.dll
c:\windows\system32\65z9addwa5e1640.ocx
c:\windows\system32\65zavir5964.dll
c:\windows\system32\66e19hreatz9576.bin
c:\windows\system32\67ba59dooz1582.bin
c:\windows\system32\6854spazbo9150.dll
c:\windows\system32\6929sz5rse1542.ocx
c:\windows\system32\6933zhie52922.exe
c:\windows\system32\6955stezl753.dll
c:\windows\system32\6978thizf541.bin
c:\windows\system32\6azasp59are1527.ocx
c:\windows\system32\6d5a5zr2090.dll
c:\windows\system32\6ddzvir6395.bin
c:\windows\system32\6e07backdo59158z.exe
c:\windows\system32\6f659zief1754.exe
c:\windows\system32\6f93th5ez30209.dll
c:\windows\system32\6z16d9wnl5ader1834.cpl
c:\windows\system32\6z9fthreat15219.dll
c:\windows\system32\6zabback9oor258.bin
c:\windows\system32\71025iruszf19.ocx
c:\windows\system32\719z5r9j704.dll
c:\windows\system32\72d4thzeat159589.dll
c:\windows\system32\73z5steal7439.ocx
c:\windows\system32\743addwa951389z.bin
c:\windows\system32\749zpa9bot1c5.dll
c:\windows\system32\757a9zief19.exe
c:\windows\system32\757espa9ze2618.exe
c:\windows\system32\759zthief2656.exe
c:\windows\system32\75c9thrzat246639.ocx
c:\windows\system32\7769zhi5f1753.exe
c:\windows\system32\7890not-z-virus325.ocx
c:\windows\system32\78cbzteal5799.ocx
c:\windows\system32\7904addw5rez07.cpl
c:\windows\system32\7954thi9f2z21.dll
c:\windows\system32\7979spyz4f5.ocx
c:\windows\system32\7998t9zeat19655.bin
c:\windows\system32\79b4spyware1895z.cpl
c:\windows\system32\7bd6sp5rse29z6.exe
c:\windows\system32\7c5z9parse2945.cpl
c:\windows\system32\7d07th9eat60z15.cpl
c:\windows\system32\7d65sp5zse1109.exe
c:\windows\system32\7e34ba9k5oor81z.bin
c:\windows\system32\7e9dbackd9or1z05.bin
c:\windows\system32\7f0bdow5zoa9er1138.bin
c:\windows\system32\7z12t5o9a9.bin
c:\windows\system32\7z86viru9576.ocx
c:\windows\system32\7zcdthreat51949.exe
c:\windows\system32\81fbaz5door3079.ocx
c:\windows\system32\83cspywz9e1554.dll
c:\windows\system32\8780n9t-a-ziru5587.bin
c:\windows\system32\8900virzs754.dll
c:\windows\system32\909z5py14d.exe
c:\windows\system32\91577tr5j5cz.bin
c:\windows\system32\92486hackt5ol1za.exe
c:\windows\system32\9294tzief2256.bin
c:\windows\system32\92z38wor5326.ocx
c:\windows\system32\93532sp5mbot16z.ocx
c:\windows\system32\93575ir320z.bin
c:\windows\system32\9363t5ief240z.ocx
c:\windows\system32\94z55py2a4.dll
c:\windows\system32\9513hz95tool3c.exe
c:\windows\system32\9523wo9z305.ocx
c:\windows\system32\952baddware196z.dll
c:\windows\system32\95775not-a-virusz53.exe
c:\windows\system32\95812vizus41f.ocx
c:\windows\system32\9585worm6za.bin
c:\windows\system32\95e2szarse1631.bin
c:\windows\system32\964evir21z5.dll
c:\windows\system32\9691sp5mbot9z4.dll
c:\windows\system32\97a6thi5f15z9.bin
c:\windows\system32\9922worm21z5.bin
c:\windows\system32\996ztro5259.bin
c:\windows\system32\99985t5zj462.dll
c:\windows\system32\99d5backzoor1372.bin
c:\windows\system32\9a8athreatz6205.bin
c:\windows\system32\9z09spambo579a.ocx
c:\windows\system32\9z25sp5mbo9a0.cpl
c:\windows\system32\9z850virus33b.dll
c:\windows\system32\a89s9zrse1315.cpl
c:\windows\system32\az9teal2655.bin
c:\windows\system32\c1stza5239.bin
c:\windows\system32\c659yzare2990.dll
c:\windows\system32\cbz5pars91996.cpl
c:\windows\system32\d89spyzare53.ocx
c:\windows\system32\f5zv9r516.cpl
c:\windows\system32\tixwf8p6.exe
c:\windows\system32\z0132troj25a9.exe
c:\windows\system32\z0537spy953.dll
c:\windows\system32\z09859py456.dll
c:\windows\system32\z15fdownloade92848.dll
c:\windows\system32\z265th9e574.exe
c:\windows\system32\z284spambo9654.exe
c:\windows\system32\z35999pambot718.dll
c:\windows\system32\z416s5ambot1119.cpl
c:\windows\system32\z529vir1251.ocx
c:\windows\system32\z55299py3b4.cpl
c:\windows\system32\z5654vir9s7a.cpl
c:\windows\system32\z5859sp94c4.dll
c:\windows\system32\z5956t9oj375.bin
c:\windows\system32\z5d99pyware9675.cpl
c:\windows\system32\z5e9spy9are5284.ocx
c:\windows\system32\z65bst9al1761.cpl
c:\windows\system32\z7649s5ambot33b.exe
c:\windows\system32\z792worm55a.cpl
c:\windows\system32\z8eds5eal2198.dll
c:\windows\system32\z95avir22145.dll
c:\windows\system32\z9e5back9oor1252.cpl
c:\windows\system32\zc2spywar5794.cpl
c:\windows\system32\zc5edo9nloader152.exe
c:\windows\system32\zc605teal993.dll
c:\windows\system32\zf09threat10513.exe
c:\windows\system32\zfdcsparse1592.cpl
c:\windows\z089t5oj12.bin
c:\windows\z0973not-a-9irus356.bin
c:\windows\z111sp5mbot592.bin
c:\windows\z1491v5r9sce.bin
c:\windows\z15599roj60c5.dll
c:\windows\z1721sp5mbot249.ocx
c:\windows\z26bsparse2955.exe
c:\windows\z4054virus5985.dll
c:\windows\z4228w59m2f4.exe
c:\windows\z459sparse9316.bin
c:\windows\z4811wor55a9.ocx
c:\windows\z4cspyware3795.exe
c:\windows\z57e5hi9f2904.bin
c:\windows\z598s9yfe.dll
c:\windows\z665th59at8601.dll
c:\windows\z79addware755.dll
c:\windows\z8ebbackdo9r1605.bin
c:\windows\z991spy95e.exe
c:\windows\z9acbackdo5r2953.ocx
c:\windows\z9bbt5ief1542.dll
c:\windows\zd3adownlo5d9r1802.exe
c:\windows\zeb9thief539.exe
c:\windows\zf059ownloader266.bin
F:\autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-07-02 to 2009-08-02 )))))))))))))))))))))))))))))))
.
2009-08-01 20:53 . 2009-07-13 19:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-01 20:52 . 2009-08-01 20:53 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-01 20:52 . 2009-08-01 20:52 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-08-01 20:52 . 2009-07-13 19:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-01 20:38 . 2009-08-01 20:38 ——– d—–w- c:\program files\Video Server E
2009-08-01 19:28 . 2009-08-01 19:28 ——– d—–w- c:\program files\Trend Micro
2009-08-01 17:47 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-08-01 15:41 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-01 15:38 . 2009-08-01 15:38 ——– dc-h–w- c:\docume~1\ALLUSE~1\APPLIC~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-01 15:38 . 2009-08-01 15:41 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Lavasoft
2009-08-01 15:38 . 2009-08-01 15:38 ——– d—–w- c:\program files\Lavasoft
2009-07-30 02:10 . 2009-07-30 02:10 ——– d—–w- c:\program files\Seagate
2009-07-30 02:10 . 2009-07-30 02:10 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Seagate
2009-07-30 02:09 . 2009-07-30 02:09 ——– d—–w- c:\documents and settings\jfairclough\Local Settings\Application Data\Downloaded Installations
2009-07-30 02:09 . 2009-01-16 08:19 1731736 —-a-w- c:\documents and settings\jfairclough\Application Data\Leadertech\PowerRegister\Seagate 2GEY20ZG Product Registration.exe
2009-07-30 02:06 . 2009-07-30 02:06 ——– d—–w- c:\documents and settings\jfairclough\Application Data\Leadertech
2009-07-27 00:36 . 2009-07-27 00:36 ——– d—–w- C:\Garmin
2009-07-26 21:08 . 2009-08-01 15:39 ——– d—–w- c:\documents and settings\jfairclough\Local Settings\Application Data\Temp
2009-07-25 19:23 . 2009-07-25 19:23 ——– d—–w- c:\documents and settings\jfairclough\Application Data\GARMIN
2009-07-20 03:21 . 2009-07-20 03:21 ——– d—–w- c:\documents and settings\jfairclough\Application Data\Cakewalk
2009-07-20 03:20 . 2006-11-30 21:49 368640 —-a-w- c:\windows\system32\ReWire.dll
2009-07-20 03:20 . 2009-07-20 03:20 ——– d—–w- c:\program files\Cakewalk
2009-07-08 05:09 . 2009-07-08 05:09 ——– d-sh–w- c:\documents and settings\jfairclough\IECompatCache
2009-07-05 19:35 . 2009-07-05 20:27 ——– d—–w- c:\documents and settings\jfairclough\Application Data\LimeWire
2009-07-05 19:33 . 2009-07-05 19:33 ——– d—–w- c:\program files\LimeWire
2009-07-05 07:18 . 2009-07-05 07:18 ——– d—–w- c:\windows\system32\wbem\Repository
2009-07-05 06:13 . 2009-07-05 06:13 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-05 06:09 . 2009-07-05 07:28 ——– d—–w- C:\OEMSettings
2009-07-05 01:39 . 2009-07-05 01:39 ——– d-sh–w- c:\documents and settings\jfairclough\PrivacIE
2009-07-05 01:38 . 2009-07-05 01:38 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-07-05 01:29 . 2009-07-05 01:29 ——– d-sh–w- c:\documents and settings\jfairclough\IETldCache
2009-07-05 00:52 . 2009-07-05 00:52 ——– d—–w- c:\windows\system32\XPSViewer
2009-07-05 00:52 . 2009-07-05 00:52 ——– d—–w- c:\program files\MSBuild
2009-07-05 00:52 . 2009-07-05 00:52 ——– d—–w- c:\program files\Reference Assemblies
2009-07-05 00:51 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-07-05 00:51 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-07-05 00:51 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-07-05 00:51 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-07-05 00:51 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-07-05 00:51 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-07-05 00:51 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-07-05 00:50 . 2009-07-05 01:06 ——– d—–w- c:\windows\SxsCaPendDel
2009-07-04 22:21 . 2009-07-04 22:21 ——– d—–w- c:\windows\system32\KB905474
2009-07-04 22:21 . 2009-03-11 04:26 1403264 —-a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-07-04 22:21 . 2009-03-11 04:18 453512 —-a-w- c:\windows\system32\KB905474\wgasetup.exe
2009-07-04 21:55 . 2009-03-06 14:22 284160 -c—-w- c:\windows\system32\dllcache\pdh.dll
2009-07-04 21:55 . 2009-02-09 12:10 473600 -c—-w- c:\windows\system32\dllcache\fastprox.dll
2009-07-04 21:55 . 2009-02-09 12:10 453120 -c—-w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-07-04 21:55 . 2009-02-09 12:10 401408 -c—-w- c:\windows\system32\dllcache\rpcss.dll
2009-07-04 21:55 . 2009-02-06 11:11 110592 -c—-w- c:\windows\system32\dllcache\services.exe
2009-07-04 21:55 . 2009-02-06 10:10 227840 -c—-w- c:\windows\system32\dllcache\wmiprvse.exe
2009-07-04 21:55 . 2009-02-09 12:10 729088 -c—-w- c:\windows\system32\dllcache\lsasrv.dll
2009-07-04 21:55 . 2009-02-09 12:10 714752 -c—-w- c:\windows\system32\dllcache\ntdll.dll
2009-07-04 21:55 . 2009-02-09 12:10 617472 -c—-w- c:\windows\system32\dllcache\advapi32.dll
2009-07-04 21:55 . 2009-02-06 11:08 2189056 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-07-04 21:55 . 2009-02-06 11:06 2145280 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-07-04 21:55 . 2009-02-06 10:32 2023936 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-04 21:54 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-07-04 21:54 . 2008-04-21 12:08 215552 -c—-w- c:\windows\system32\dllcache\wordpad.exe
2009-07-04 21:52 . 2008-12-11 10:57 333952 -c—-w- c:\windows\system32\dllcache\srv.sys
2009-07-04 21:50 . 2008-10-24 11:21 455296 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-04 21:49 . 2008-09-04 17:15 1106944 -c—-w- c:\windows\system32\dllcache\msxml3.dll
2009-07-04 21:49 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2009-07-04 21:48 . 2008-05-01 14:33 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll
2009-07-04 21:47 . 2008-04-11 19:04 691712 -c—-w- c:\windows\system32\dllcache\inetcomm.dll
2009-07-04 21:45 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-07-04 21:45 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2009-07-04 18:23 . 2009-07-04 18:23 ——– d—–w- c:\windows\system32\scripting
2009-07-04 18:23 . 2009-07-04 18:23 ——– d—–w- c:\windows\l2schemas
2009-07-04 18:23 . 2009-07-04 18:23 ——– d—–w- c:\windows\system32\en
2009-07-04 18:23 . 2009-07-04 18:23 ——– d—–w- c:\windows\system32\bits
2009-07-04 17:58 . 2008-04-14 00:11 136192 ——w- c:\windows\system32\aaclient.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-02 04:04 . 2009-06-26 04:17 ——– d—–w- c:\documents and settings\jfairclough\Application Data\uTorrent
2009-08-01 15:39 . 2006-05-18 14:30 ——– d—–w- c:\program files\Google
2009-08-01 05:35 . 2006-07-21 16:15 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-01 05:35 . 2006-07-21 16:15 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-01 03:38 . 2008-07-22 04:40 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Soulseek
2009-07-31 10:05 . 2008-04-10 22:42 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Google Updater
2009-07-30 02:10 . 2006-05-18 14:16 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-29 03:26 . 2008-09-02 03:37 ——– d—–w- c:\program files\DivX
2009-07-27 01:20 . 2009-04-17 22:02 ——– d—–w- c:\documents and settings\jfairclough\Application Data\Azureus
2009-07-05 06:38 . 2008-09-01 19:52 ——– d—–w- c:\program files\K-Lite Codec Pack
2009-07-05 01:33 . 2006-05-18 14:51 70136 —-a-w- c:\documents and settings\jfairclough\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-04 18:27 . 2006-05-17 23:33 87263 —-a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-07-02 22:16 . 2009-07-02 22:14 ——– d—–w- c:\documents and settings\jfairclough\Application Data\WindSolutions
2009-07-02 22:14 . 2009-07-02 22:14 ——– d—–w- c:\program files\WindSolutions
2009-07-02 22:14 . 2009-07-02 22:14 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\WindSolutions
2009-07-02 20:53 . 2008-07-22 03:33 ——– d—–w- c:\program files\NETGEAR
2009-07-01 04:24 . 2009-06-28 02:16 ——– d—–w- c:\program files\MediaCoder
2009-07-01 03:49 . 2009-07-01 03:40 ——– d—–w- c:\program files\Magical Jelly Bean SHN Shortener
2009-06-28 02:23 . 2009-06-28 02:15 ——– d—–w- c:\program files\Xobni
2009-06-28 02:22 . 2006-06-07 17:31 ——– d—–w- c:\program files\Yahoo!
2009-06-28 02:15 . 2009-06-28 02:15 ——– d—–w- c:\documents and settings\jfairclough\Application Data\WeatherBug
2009-06-28 02:14 . 2009-06-28 02:14 ——– d—–w- c:\documents and settings\jfairclough\Application Data\blinkx
2009-06-28 02:14 . 2009-06-28 02:14 ——– d—–w- c:\documents and settings\jfairclough\Application Data\PriceGong
2009-06-26 14:49 . 2009-06-26 14:35 ——– d—–w- c:\program files\Winamp
2009-06-26 14:44 . 2009-06-26 14:35 ——– d—–w- c:\documents and settings\jfairclough\Application Data\Winamp
2009-06-26 04:17 . 2009-06-26 04:17 ——– d—–w- c:\program files\uTorrent
2009-05-07 15:32 . 2003-07-16 16:26 345600 —-a-w- c:\windows\system32\localspl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-12-10 00:40 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-10 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"EFI Job Monitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\efjm.dll" [2004-08-10 2510848]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-18 68856]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-07-07 288048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-17 148888]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-23 116040]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-05-26 180269]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-05-01 185640]
c:\documents and settings\jfairclough\Start Menu\Programs\Startup\
Seagate 2GEY20ZG Product Registration.lnk - c:\documents and settings\jfairclough\Application Data\Leadertech\PowerRegister\Seagate 2GEY20ZG Product Registration.exe [2009-7-29 1731736]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-12-11 2322432]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"MaxGPOScriptWait"= 1000 (0x3e8)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SideACT!.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SideACT!.lnk
backup=c:\windows\pss\SideACT!.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^jfairclough^Start Menu^Programs^Startup^Avaya IP Softphone.lnk]
path=c:\documents and settings\jfairclough\Start Menu\Programs\Startup\Avaya IP Softphone.lnk
backup=c:\windows\pss\Avaya IP Softphone.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Danware Data\\NetOp Remote Control\\Host\\NHSTW32.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/1/2009 9:41 AM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 8:49 AM 1029456]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [12/28/2007 3:02 PM 287232]
S1 NHostNT1;NetOp Driver 1 ver. 8.00 (2006047);c:\windows\system32\drivers\NHOSTNT1.SYS [5/18/2006 12:12 PM 90896]
S2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [4/17/2009 4:02 PM 464264]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [4/17/2009 4:02 PM 234888]
S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [10/9/2007 1:13 PM 38144]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [5/1/2009 2:35 PM 181544]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/26/2009 3:08 PM 133104]
S2 NetOp Host for NT Service;NetOp Helper ver. 8.00 (2006047);c:\program files\Danware Data\NetOp Remote Control\Host\NHOSTSVC.EXE [5/18/2006 12:12 PM 1196304]
S2 Retrospect Client;Retrospect Client;c:\program files\Dantz\Client\RemotSvc.exe [5/18/2006 10:21 AM 57344]
S3 ECCL100;ECCL100 NDIS Protocol Driver;\??\c:\windows\system32\ECCL100.SYS –> c:\windows\system32\ECCL100.SYS [?]
S3 NHOSTNT3;NetOp Driver 3 ver. 8.00 (2006047) (NHOSTNT3);c:\windows\system32\drivers\NHOSTNT3.SYS [5/18/2006 12:12 PM 3216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
DPF: {E3E02F12-2ADB-478C-8742-5F0819F9F0F4} - hxxp://qmedia.xlontech.net/100170/sdk/latest/qsp2ie06041001.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-01 23:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(808)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-08-02 23:18
ComboFix-quarantined-files.txt 2009-08-02 05:18
ComboFix2.txt 2009-08-02 04:17
Pre-Run: 21,705,953,280 bytes free
Post-Run: 21,650,018,304 bytes free
908 — E O F — 2008-04-20 10:06
Upload was successful