ComboFix 09-08-30.04 - eu 08/31/2009 13:00.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.702.444 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\FunWebProducts
c:\program files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\2.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\2.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\2.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\2.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\2.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\2.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\2.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\2.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\2.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\Cache\0004F278.bin
c:\program files\MyWebSearch\bar\Cache\0004F8A6.bin
c:\program files\MyWebSearch\bar\Cache\0004FAAF.bin
c:\program files\MyWebSearch\bar\Cache\05F1851B
c:\program files\MyWebSearch\bar\Cache\05F1886E
c:\program files\MyWebSearch\bar\Cache\05F18F97.bin
c:\program files\MyWebSearch\bar\Cache\05F19254.bin
c:\program files\MyWebSearch\bar\Cache\05F193C7.bin
c:\program files\MyWebSearch\bar\Cache\05F19E2E.bin
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search
c:\program files\MyWebSearch\bar\Settings\prevcfg.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
C:\rb.exe
C:\rbz.exe
c:\recycler\S-1-5-21-507921405-1563985344-854245398-1003
c:\recycler\S-1-5-21-965127544-1210913887-3220548547-1003
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\Fonts\Wphv07nb.ttf
c:\windows\gg.exe
c:\windows\Installer\1089a0.msi
c:\windows\Installer\152478.msi
c:\windows\Installer\5581f84.msi
c:\windows\patch.exe
c:\windows\system32\~.exe
c:\windows\system32\AVR09.exe
c:\windows\system32\braviax.exe
c:\windows\system32\cache329
c:\windows\system32\cache329\B_329_0_1_554300.gif
c:\windows\system32\cache329\B_329_0_1_558800.gif
c:\windows\system32\cache329\B_329_0_1_560800.gif
c:\windows\system32\cache329\B_329_0_1_566800.gif
c:\windows\system32\cache329\B_329_0_1_568300.htm
c:\windows\system32\cache329\B_329_0_1_568300.swf
c:\windows\system32\cache329\B_329_0_1_568900.gif
c:\windows\system32\cache329\B_329_0_1_588400.htm
c:\windows\system32\cache329\B_329_0_1_588400.swf
c:\windows\system32\cache329\B_329_0_1_594800.htm
c:\windows\system32\cache329\B_329_0_1_594800.swf
c:\windows\system32\cache329\B_329_0_1_595300.htm
c:\windows\system32\cache329\B_329_0_1_595300.swf
c:\windows\system32\cache329\B_329_0_1_611900.gif
c:\windows\system32\cache329\B_329_0_1_618500.gif
c:\windows\system32\cache329\B_329_0_1_619300.gif
c:\windows\system32\cache329\B_329_0_1_655300.htm
c:\windows\system32\cache329\B_329_0_1_655300.swf
c:\windows\system32\cache329\B_329_0_1_656000.gif
c:\windows\system32\cache329\B_329_0_1_656100.gif
c:\windows\system32\cache329\B_329_0_1_673000.gif
c:\windows\system32\cache329\B_329_0_1_673600.gif
c:\windows\system32\cache329\B_329_0_1_688400.htm
c:\windows\system32\cache329\B_329_0_1_688400.swf
c:\windows\system32\cache329\B_329_0_1_688900.htm
c:\windows\system32\cache329\B_329_0_1_688900.swf
c:\windows\system32\cache329\B_329_0_1_737400.htm
c:\windows\system32\cache329\B_329_0_1_737400.swf
c:\windows\system32\cache329\B_329_0_1_784200.htm
c:\windows\system32\cache329\B_329_0_1_784200.swf
c:\windows\system32\cache329\B_329_0_2_547900.htm
c:\windows\system32\cache329\B_329_0_2_547900.swf
c:\windows\system32\cache329\B_329_0_2_552800.gif
c:\windows\system32\cache329\B_329_0_2_554700.htm
c:\windows\system32\cache329\B_329_0_2_554700.swf
c:\windows\system32\cache329\B_329_0_2_556200.htm
c:\windows\system32\cache329\B_329_0_2_556200.swf
c:\windows\system32\cache329\B_329_0_2_557200.htm
c:\windows\system32\cache329\B_329_0_2_557200.swf
c:\windows\system32\cache329\B_329_0_2_557900.htm
c:\windows\system32\cache329\B_329_0_2_557900.swf
c:\windows\system32\cache329\B_329_0_2_561600.htm
c:\windows\system32\cache329\B_329_0_2_561600.swf
c:\windows\system32\cache329\B_329_0_2_562200.htm
c:\windows\system32\cache329\B_329_0_2_562200.swf
c:\windows\system32\cache329\B_329_0_2_563500.htm
c:\windows\system32\cache329\B_329_0_2_563500.swf
c:\windows\system32\cache329\B_329_0_2_570500.htm
c:\windows\system32\cache329\B_329_0_2_570500.swf
c:\windows\system32\cache329\B_329_0_2_576400.htm
c:\windows\system32\cache329\B_329_0_2_576400.swf
c:\windows\system32\cache329\B_329_0_2_582300.htm
c:\windows\system32\cache329\B_329_0_2_582300.swf
c:\windows\system32\cache329\B_329_0_2_585800.htm
c:\windows\system32\cache329\B_329_0_2_585800.swf
c:\windows\system32\cache329\B_329_0_2_586300.htm
c:\windows\system32\cache329\B_329_0_2_586300.swf
c:\windows\system32\cache329\B_329_0_2_589300.htm
c:\windows\system32\cache329\B_329_0_2_589300.swf
c:\windows\system32\cache329\B_329_0_2_589500.htm
c:\windows\system32\cache329\B_329_0_2_589500.swf
c:\windows\system32\cache329\B_329_0_2_599000.gif
c:\windows\system32\cache329\B_329_0_2_599900.htm
c:\windows\system32\cache329\B_329_0_2_599900.swf
c:\windows\system32\cache329\B_329_0_2_604100.gif
c:\windows\system32\cache329\B_329_0_2_607900.gif
c:\windows\system32\cache329\B_329_0_2_626100.gif
c:\windows\system32\cache329\B_329_0_2_638100.htm
c:\windows\system32\cache329\B_329_0_2_638500.htm
c:\windows\system32\cache329\B_329_0_2_638500.swf
c:\windows\system32\cache329\B_329_0_2_668500.htm
c:\windows\system32\cache329\B_329_0_2_668500.swf
c:\windows\system32\cache329\B_329_0_2_675100.htm
c:\windows\system32\cache329\B_329_0_2_675100.swf
c:\windows\system32\cache329\B_329_0_2_688000.htm
c:\windows\system32\cache329\B_329_0_2_688000.swf
c:\windows\system32\cache329\B_329_0_2_689600.htm
c:\windows\system32\cache329\B_329_0_2_689600.swf
c:\windows\system32\cache329\B_329_0_2_737100.htm
c:\windows\system32\cache329\B_329_0_2_737100.swf
c:\windows\system32\cache329\B_329_0_2_775800.htm
c:\windows\system32\cache329\B_329_0_2_775800.swf
c:\windows\system32\cache329\B_329_0_3_572800.htm
c:\windows\system32\cache329\B_329_0_3_572800.swf
c:\windows\system32\cache329\B_329_0_3_667200.htm
c:\windows\system32\cache329\B_329_0_3_667200.swf
c:\windows\system32\cache329\B_329_0_3_694800.htm
c:\windows\system32\cache329\B_329_0_3_694800.swf
c:\windows\system32\cache329\B_329_0_3_694900.htm
c:\windows\system32\cache329\B_329_0_3_694900.swf
c:\windows\system32\cache329\B_329_0_3_695000.htm
c:\windows\system32\cache329\B_329_0_3_695000.swf
c:\windows\system32\cache329\B_329_0_3_695100.htm
c:\windows\system32\cache329\B_329_0_3_695100.swf
c:\windows\system32\cache329\B_329_0_3_731700.gif
c:\windows\system32\cache329\B_329_2_1_554300.gif
c:\windows\system32\cache329\B_329_2_1_558800.gif
c:\windows\system32\cache329\B_329_2_1_560800.gif
c:\windows\system32\cache329\B_329_2_1_566800.gif
c:\windows\system32\cache329\B_329_2_1_568300.htm
c:\windows\system32\cache329\B_329_2_1_568300.swf
c:\windows\system32\cache329\B_329_2_1_568900.gif
c:\windows\system32\cache329\B_329_2_1_588400.htm
c:\windows\system32\cache329\B_329_2_1_588400.swf
c:\windows\system32\cache329\B_329_2_1_594800.htm
c:\windows\system32\cache329\B_329_2_1_594800.swf
c:\windows\system32\cache329\B_329_2_1_595300.htm
c:\windows\system32\cache329\B_329_2_1_595300.swf
c:\windows\system32\cache329\B_329_2_1_611900.gif
c:\windows\system32\cache329\B_329_2_1_618500.gif
c:\windows\system32\cache329\B_329_2_1_619300.gif
c:\windows\system32\cache329\B_329_2_1_654600.htm
c:\windows\system32\cache329\B_329_2_1_654600.swf
c:\windows\system32\cache329\B_329_2_1_655300.htm
c:\windows\system32\cache329\B_329_2_1_655300.swf
c:\windows\system32\cache329\B_329_2_1_655800.gif
c:\windows\system32\cache329\B_329_2_1_656000.gif
c:\windows\system32\cache329\B_329_2_1_656100.gif
c:\windows\system32\cache329\B_329_2_1_673000.gif
c:\windows\system32\cache329\B_329_2_1_673600.gif
c:\windows\system32\cache329\B_329_2_1_688400.htm
c:\windows\system32\cache329\B_329_2_1_688400.swf
c:\windows\system32\cache329\B_329_2_1_688900.htm
c:\windows\system32\cache329\B_329_2_1_688900.swf
c:\windows\system32\cache329\B_329_2_1_737400.htm
c:\windows\system32\cache329\B_329_2_1_737400.swf
c:\windows\system32\cache329\B_329_2_1_784200.htm
c:\windows\system32\cache329\B_329_2_1_784200.swf
c:\windows\system32\cache329\B_329_2_2_547900.htm
c:\windows\system32\cache329\B_329_2_2_547900.swf
c:\windows\system32\cache329\B_329_2_2_552800.gif
c:\windows\system32\cache329\B_329_2_2_554700.htm
c:\windows\system32\cache329\B_329_2_2_554700.swf
c:\windows\system32\cache329\B_329_2_2_556200.htm
c:\windows\system32\cache329\B_329_2_2_556200.swf
c:\windows\system32\cache329\B_329_2_2_557200.htm
c:\windows\system32\cache329\B_329_2_2_557200.swf
c:\windows\system32\cache329\B_329_2_2_557900.htm
c:\windows\system32\cache329\B_329_2_2_557900.swf
c:\windows\system32\cache329\B_329_2_2_561600.htm
c:\windows\system32\cache329\B_329_2_2_561600.swf
c:\windows\system32\cache329\B_329_2_2_562200.htm
c:\windows\system32\cache329\B_329_2_2_562200.swf
c:\windows\system32\cache329\B_329_2_2_563500.htm
c:\windows\system32\cache329\B_329_2_2_563500.swf
c:\windows\system32\cache329\B_329_2_2_570500.htm
c:\windows\system32\cache329\B_329_2_2_570500.swf
c:\windows\system32\cache329\B_329_2_2_576400.htm
c:\windows\system32\cache329\B_329_2_2_576400.swf
c:\windows\system32\cache329\B_329_2_2_582300.htm
c:\windows\system32\cache329\B_329_2_2_582300.swf
c:\windows\system32\cache329\B_329_2_2_585800.htm
c:\windows\system32\cache329\B_329_2_2_585800.swf
c:\windows\system32\cache329\B_329_2_2_586300.htm
c:\windows\system32\cache329\B_329_2_2_586300.swf
c:\windows\system32\cache329\B_329_2_2_589300.htm
c:\windows\system32\cache329\B_329_2_2_589300.swf
c:\windows\system32\cache329\B_329_2_2_589500.htm
c:\windows\system32\cache329\B_329_2_2_589500.swf
c:\windows\system32\cache329\B_329_2_2_592100.htm
c:\windows\system32\cache329\B_329_2_2_592100.swf
c:\windows\system32\cache329\B_329_2_2_594200.htm
c:\windows\system32\cache329\B_329_2_2_594200.jpg
c:\windows\system32\cache329\B_329_2_2_595900.gif
c:\windows\system32\cache329\B_329_2_2_596700.htm
c:\windows\system32\cache329\B_329_2_2_596700.swf
c:\windows\system32\cache329\B_329_2_2_596900.htm
c:\windows\system32\cache329\B_329_2_2_596900.swf
c:\windows\system32\cache329\B_329_2_2_599000.gif
c:\windows\system32\cache329\B_329_2_2_599900.htm
c:\windows\system32\cache329\B_329_2_2_599900.swf
c:\windows\system32\cache329\B_329_2_2_600200.htm
c:\windows\system32\cache329\B_329_2_2_600200.swf
c:\windows\system32\cache329\B_329_2_2_601700.htm
c:\windows\system32\cache329\B_329_2_2_601700.swf
c:\windows\system32\cache329\B_329_2_2_604100.gif
c:\windows\system32\cache329\B_329_2_2_607900.gif
c:\windows\system32\cache329\B_329_2_2_626100.gif
c:\windows\system32\cache329\B_329_2_2_638100.htm
c:\windows\system32\cache329\B_329_2_2_638500.htm
c:\windows\system32\cache329\B_329_2_2_638500.swf
c:\windows\system32\cache329\B_329_2_2_648400.htm
c:\windows\system32\cache329\B_329_2_2_648400.swf
c:\windows\system32\cache329\B_329_2_2_668500.htm
c:\windows\system32\cache329\B_329_2_2_668500.swf
c:\windows\system32\cache329\B_329_2_2_675100.htm
c:\windows\system32\cache329\B_329_2_2_675100.swf
c:\windows\system32\cache329\B_329_2_2_688000.htm
c:\windows\system32\cache329\B_329_2_2_688000.swf
c:\windows\system32\cache329\B_329_2_2_689600.htm
c:\windows\system32\cache329\B_329_2_2_689600.swf
c:\windows\system32\cache329\B_329_2_2_737100.htm
c:\windows\system32\cache329\B_329_2_2_737100.swf
c:\windows\system32\cache329\B_329_2_2_752900.gif
c:\windows\system32\cache329\B_329_2_2_773700.htm
c:\windows\system32\cache329\B_329_2_2_773700.swf
c:\windows\system32\cache329\B_329_2_2_773900.htm
c:\windows\system32\cache329\B_329_2_2_773900.swf
c:\windows\system32\cache329\B_329_2_2_775800.htm
c:\windows\system32\cache329\B_329_2_2_775800.swf
c:\windows\system32\cache329\B_329_2_3_557300.htm
c:\windows\system32\cache329\B_329_2_3_557300.swf
c:\windows\system32\cache329\B_329_2_3_572800.htm
c:\windows\system32\cache329\B_329_2_3_572800.swf
c:\windows\system32\cache329\B_329_2_3_576500.gif
c:\windows\system32\cache329\B_329_2_3_578100.gif
c:\windows\system32\cache329\B_329_2_3_582000.gif
c:\windows\system32\cache329\B_329_2_3_590600.htm
c:\windows\system32\cache329\B_329_2_3_590600.swf
c:\windows\system32\cache329\B_329_2_3_599100.htm
c:\windows\system32\cache329\B_329_2_3_599100.swf
c:\windows\system32\cache329\B_329_2_3_605000.htm
c:\windows\system32\cache329\B_329_2_3_605000.swf
c:\windows\system32\cache329\B_329_2_3_617900.htm
c:\windows\system32\cache329\B_329_2_3_617900.swf
c:\windows\system32\cache329\B_329_2_3_639500.htm
c:\windows\system32\cache329\B_329_2_3_639500.swf
c:\windows\system32\cache329\B_329_2_3_654100.gif
c:\windows\system32\cache329\B_329_2_3_654800.gif
c:\windows\system32\cache329\B_329_2_3_676100.htm
c:\windows\system32\cache329\B_329_2_3_676100.swf
c:\windows\system32\cache329\B_329_2_3_694800.htm
c:\windows\system32\cache329\B_329_2_3_694800.swf
c:\windows\system32\cache329\B_329_2_3_694900.htm
c:\windows\system32\cache329\B_329_2_3_694900.swf
c:\windows\system32\cache329\B_329_2_3_695000.htm
c:\windows\system32\cache329\B_329_2_3_695000.swf
c:\windows\system32\cache329\B_329_2_3_695100.htm
c:\windows\system32\cache329\B_329_2_3_695100.swf
c:\windows\system32\cache329\B_329_2_3_695200.htm
c:\windows\system32\cache329\B_329_2_3_695200.swf
c:\windows\system32\cache329\B_329_2_3_731700.gif
c:\windows\system32\cache329\B_329_2_3_731800.gif
c:\windows\system32\cache329\B_329_3_1_554300.gif
c:\windows\system32\cache329\B_329_3_1_558800.gif
c:\windows\system32\cache329\B_329_3_1_560800.gif
c:\windows\system32\cache329\B_329_3_1_566800.gif
c:\windows\system32\cache329\B_329_3_1_568300.htm
c:\windows\system32\cache329\B_329_3_1_568300.swf
c:\windows\system32\cache329\B_329_3_1_568900.gif
c:\windows\system32\cache329\B_329_3_1_588400.htm
c:\windows\system32\cache329\B_329_3_1_588400.swf
c:\windows\system32\cache329\B_329_3_1_594800.htm
c:\windows\system32\cache329\B_329_3_1_594800.swf
c:\windows\system32\cache329\B_329_3_1_595300.htm
c:\windows\system32\cache329\B_329_3_1_595300.swf
c:\windows\system32\cache329\B_329_3_1_611900.gif
c:\windows\system32\cache329\B_329_3_1_618500.gif
c:\windows\system32\cache329\B_329_3_1_619300.gif
c:\windows\system32\cache329\B_329_3_1_654600.htm
c:\windows\system32\cache329\B_329_3_1_654600.swf
c:\windows\system32\cache329\B_329_3_1_655300.htm
c:\windows\system32\cache329\B_329_3_1_655300.swf
c:\windows\system32\cache329\B_329_3_1_656000.gif
c:\windows\system32\cache329\B_329_3_1_656100.gif
c:\windows\system32\cache329\B_329_3_1_673000.gif
c:\windows\system32\cache329\B_329_3_1_673600.gif
c:\windows\system32\cache329\B_329_3_1_688400.htm
c:\windows\system32\cache329\B_329_3_1_688400.swf
c:\windows\system32\cache329\B_329_3_1_688900.htm
c:\windows\system32\cache329\B_329_3_1_688900.swf
c:\windows\system32\cache329\B_329_3_1_737400.htm
c:\windows\system32\cache329\B_329_3_1_737400.swf
c:\windows\system32\cache329\B_329_3_1_784200.htm
c:\windows\system32\cache329\B_329_3_1_784200.swf
c:\windows\system32\cache329\B_329_3_2_547900.htm
c:\windows\system32\cache329\B_329_3_2_547900.swf
c:\windows\system32\cache329\B_329_3_2_552800.gif
c:\windows\system32\cache329\B_329_3_2_554700.htm
c:\windows\system32\cache329\B_329_3_2_554700.swf
c:\windows\system32\cache329\B_329_3_2_556200.htm
c:\windows\system32\cache329\B_329_3_2_556200.swf
c:\windows\system32\cache329\B_329_3_2_557200.htm
c:\windows\system32\cache329\B_329_3_2_557200.swf
c:\windows\system32\cache329\B_329_3_2_557900.htm
c:\windows\system32\cache329\B_329_3_2_557900.swf
c:\windows\system32\cache329\B_329_3_2_561600.htm
c:\windows\system32\cache329\B_329_3_2_561600.swf
c:\windows\system32\cache329\B_329_3_2_562200.htm
c:\windows\system32\cache329\B_329_3_2_562200.swf
c:\windows\system32\cache329\B_329_3_2_563500.htm
c:\windows\system32\cache329\B_329_3_2_563500.swf
c:\windows\system32\cache329\B_329_3_2_570500.htm
c:\windows\system32\cache329\B_329_3_2_570500.swf
c:\windows\system32\cache329\B_329_3_2_576400.htm
c:\windows\system32\cache329\B_329_3_2_576400.swf
c:\windows\system32\cache329\B_329_3_2_582300.htm
c:\windows\system32\cache329\B_329_3_2_582300.swf
c:\windows\system32\cache329\B_329_3_2_585800.htm
c:\windows\system32\cache329\B_329_3_2_585800.swf
c:\windows\system32\cache329\B_329_3_2_586300.htm
c:\windows\system32\cache329\B_329_3_2_586300.swf
c:\windows\system32\cache329\B_329_3_2_589300.htm
c:\windows\system32\cache329\B_329_3_2_589300.swf
c:\windows\system32\cache329\B_329_3_2_589500.htm
c:\windows\system32\cache329\B_329_3_2_589500.swf
c:\windows\system32\cache329\B_329_3_2_599000.gif
c:\windows\system32\cache329\B_329_3_2_599900.htm
c:\windows\system32\cache329\B_329_3_2_599900.swf
c:\windows\system32\cache329\B_329_3_2_600200.htm
c:\windows\system32\cache329\B_329_3_2_600200.swf
c:\windows\system32\cache329\B_329_3_2_601700.htm
c:\windows\system32\cache329\B_329_3_2_601700.swf
c:\windows\system32\cache329\B_329_3_2_604100.gif
c:\windows\system32\cache329\B_329_3_2_607900.gif
c:\windows\system32\cache329\B_329_3_2_626100.gif
c:\windows\system32\cache329\B_329_3_2_638100.htm
c:\windows\system32\cache329\B_329_3_2_638500.htm
c:\windows\system32\cache329\B_329_3_2_638500.swf
c:\windows\system32\cache329\B_329_3_2_648400.htm
c:\windows\system32\cache329\B_329_3_2_648400.swf
c:\windows\system32\cache329\B_329_3_2_668500.htm
c:\windows\system32\cache329\B_329_3_2_668500.swf
c:\windows\system32\cache329\B_329_3_2_675100.htm
c:\windows\system32\cache329\B_329_3_2_675100.swf
c:\windows\system32\cache329\B_329_3_2_688000.htm
c:\windows\system32\cache329\B_329_3_2_688000.swf
c:\windows\system32\cache329\B_329_3_2_689600.htm
c:\windows\system32\cache329\B_329_3_2_689600.swf
c:\windows\system32\cache329\B_329_3_2_737100.htm
c:\windows\system32\cache329\B_329_3_2_737100.swf
c:\windows\system32\cache329\B_329_3_2_775800.htm
c:\windows\system32\cache329\B_329_3_2_775800.swf
c:\windows\system32\cache329\B_329_3_3_557300.htm
c:\windows\system32\cache329\B_329_3_3_557300.swf
c:\windows\system32\cache329\B_329_3_3_572800.htm
c:\windows\system32\cache329\B_329_3_3_572800.swf
c:\windows\system32\cache329\B_329_3_3_576500.gif
c:\windows\system32\cache329\B_329_3_3_578100.gif
c:\windows\system32\cache329\B_329_3_3_582000.gif
c:\windows\system32\cache329\B_329_3_3_590600.htm
c:\windows\system32\cache329\B_329_3_3_590600.swf
c:\windows\system32\cache329\B_329_3_3_599100.htm
c:\windows\system32\cache329\B_329_3_3_599100.swf
c:\windows\system32\cache329\B_329_3_3_605000.htm
c:\windows\system32\cache329\B_329_3_3_605000.swf
c:\windows\system32\cache329\B_329_3_3_617900.htm
c:\windows\system32\cache329\B_329_3_3_617900.swf
c:\windows\system32\cache329\B_329_3_3_639500.htm
c:\windows\system32\cache329\B_329_3_3_639500.swf
c:\windows\system32\cache329\B_329_3_3_654800.gif
c:\windows\system32\cache329\B_329_3_3_694800.htm
c:\windows\system32\cache329\B_329_3_3_694800.swf
c:\windows\system32\cache329\B_329_3_3_694900.htm
c:\windows\system32\cache329\B_329_3_3_694900.swf
c:\windows\system32\cache329\B_329_3_3_695000.htm
c:\windows\system32\cache329\B_329_3_3_695000.swf
c:\windows\system32\cache329\B_329_3_3_695100.htm
c:\windows\system32\cache329\B_329_3_3_695100.swf
c:\windows\system32\cache329\B_329_3_3_695200.htm
c:\windows\system32\cache329\B_329_3_3_695200.swf
c:\windows\system32\cache329\B_329_3_3_731700.gif
c:\windows\system32\cache329\B_329_4_1_500500.gif
c:\windows\system32\cache329\B_329_4_1_500500.htm
c:\windows\system32\cache329\B_329_4_1_504200.gif
c:\windows\system32\cache329\B_329_4_1_504200.htm
c:\windows\system32\cache329\B_329_4_1_517600.gif
c:\windows\system32\cache329\B_329_4_1_517600.htm
c:\windows\system32\cache329\B_329_4_1_536000.htm
c:\windows\system32\cache329\B_329_4_1_536000.swf
c:\windows\system32\cache329\B_329_4_1_577000.htm
c:\windows\system32\cache329\B_329_4_1_577000.swf
c:\windows\system32\cache329\B_329_4_1_584300.htm
c:\windows\system32\cache329\B_329_4_1_584300.swf
c:\windows\system32\cache329\B_329_4_1_593200.htm
c:\windows\system32\cache329\B_329_4_1_593200.swf
c:\windows\system32\cache329\B_329_4_1_600800.htm
c:\windows\system32\cache329\B_329_4_1_615900.gif
c:\windows\system32\cache329\B_329_4_1_615900.htm
c:\windows\system32\cache329\B_329_4_1_633800.htm
c:\windows\system32\cache329\B_329_4_1_644500.htm
c:\windows\system32\cache329\B_329_4_1_653100.htm
c:\windows\system32\cache329\B_329_4_1_653100.swf
c:\windows\system32\cache329\B_329_4_2_554100.htm
c:\windows\system32\cache329\B_329_4_2_576700.gif
c:\windows\system32\cache329\B_329_4_2_576700.htm
c:\windows\system32\cache329\B_329_4_2_582200.gif
c:\windows\system32\cache329\B_329_4_2_582200.htm
c:\windows\system32\cache329\B_329_4_2_582600.gif
c:\windows\system32\cache329\B_329_4_2_582600.htm
c:\windows\system32\cache329\B_329_4_2_583000.gif
c:\windows\system32\cache329\B_329_4_2_583000.htm
c:\windows\system32\cache329\B_329_4_2_583500.htm
c:\windows\system32\cache329\B_329_4_2_583500.jpg
c:\windows\system32\cache329\B_329_4_2_585600.htm
c:\windows\system32\cache329\B_329_4_2_585600.jpg
c:\windows\system32\cache329\B_329_4_2_587800.htm
c:\windows\system32\cache329\B_329_4_2_587800.jpg
c:\windows\system32\cache329\B_329_4_2_588900.htm
c:\windows\system32\cache329\B_329_4_2_588900.jpg
c:\windows\system32\cache329\B_329_4_2_590700.htm
c:\windows\system32\cache329\B_329_4_2_590700.swf
c:\windows\system32\cache329\B_329_4_2_591900.htm
c:\windows\system32\cache329\B_329_4_2_591900.jpg
c:\windows\system32\cache329\B_329_4_2_599800.gif
c:\windows\system32\cache329\B_329_4_2_599800.htm
c:\windows\system32\cache329\B_329_4_2_600700.gif
c:\windows\system32\cache329\B_329_4_2_600700.htm
c:\windows\system32\cache329\B_329_4_2_621000.htm
c:\windows\system32\cache329\B_329_4_2_621100.htm
c:\windows\system32\cache329\B_329_4_2_621500.htm
c:\windows\system32\cache329\B_329_4_2_621600.htm
c:\windows\system32\cache329\B_329_4_2_622400.htm
c:\windows\system32\cache329\B_329_4_2_634300.htm
c:\windows\system32\cache329\B_329_4_2_634300.swf
c:\windows\system32\cache329\B_329_4_2_642300.htm
c:\windows\system32\cache329\B_329_4_2_654900.gif
c:\windows\system32\cache329\B_329_4_2_654900.htm
c:\windows\system32\cache329\B_329_4_2_655000.gif
c:\windows\system32\cache329\B_329_4_2_655000.htm
c:\windows\system32\cache329\B_329_4_2_655200.gif
c:\windows\system32\cache329\B_329_4_2_655200.htm
c:\windows\system32\cache329\B_329_4_2_670700.htm
c:\windows\system32\cache329\B_329_4_2_684600.htm
c:\windows\system32\cache329\B_329_4_2_684600.swf
c:\windows\system32\cache329\B_329_4_2_686400.htm
c:\windows\system32\cache329\B_329_4_3_586100.htm
c:\windows\system32\cache329\B_329_4_3_619000.htm
c:\windows\system32\cache329\B_329_4_3_619000.swf
c:\windows\system32\cache329\B_329_4_3_629500.htm
c:\windows\system32\cache329\B_329_4_3_629500.swf
c:\windows\system32\cache329\B_329_4_4_596800.htm
c:\windows\system32\cache329\B_515200.htm
c:\windows\system32\cache329\B_525100.htm
c:\windows\system32\cache329\B_544700.htm
c:\windows\system32\cache329\B_580600.htm
c:\windows\system32\cache329\B_580900.htm
c:\windows\system32\cache329\B_604700.htm
c:\windows\system32\cache329\B_634700.htm
c:\windows\system32\cache329\B_637600.htm
c:\windows\system32\cache329\B_638200.htm
c:\windows\system32\cache329\B_640700.htm
c:\windows\system32\cache329\B_641700.htm
c:\windows\system32\cache329\B_642100.htm
c:\windows\system32\cache329\B_644900.htm
c:\windows\system32\cache329\B_658100.htm
c:\windows\system32\cache329\B_670300.htm
c:\windows\system32\cache329\B_686800.htm
c:\windows\system32\cache329\B_686900.htm
c:\windows\system32\cache329\B_692000.htm
c:\windows\system32\cache329\B_753400.htm
c:\windows\system32\cache329\B_791300.htm
c:\windows\system32\cache329\t_B_329_0_2_638100.htm
c:\windows\system32\cache329\t_B_329_2_2_638100.htm
c:\windows\system32\cache329\t_B_329_3_2_638100.htm
c:\windows\system32\cache329\t_B_329_4_1_600800.htm
c:\windows\system32\cache329\t_B_329_4_1_633800.htm
c:\windows\system32\cache329\t_B_329_4_1_644500.htm
c:\windows\system32\cache329\t_B_329_4_2_554100.htm
c:\windows\system32\cache329\t_B_329_4_2_621000.htm
c:\windows\system32\cache329\t_B_329_4_2_621100.htm
c:\windows\system32\cache329\t_B_329_4_2_621500.htm
c:\windows\system32\cache329\t_B_329_4_2_621600.htm
c:\windows\system32\cache329\t_B_329_4_2_622400.htm
c:\windows\system32\cache329\t_B_329_4_2_642300.htm
c:\windows\system32\cache329\t_B_329_4_2_670700.htm
c:\windows\system32\cache329\t_B_329_4_2_686400.htm
c:\windows\system32\cache329\t_B_329_4_3_586100.htm
c:\windows\system32\cache329\t_B_329_4_4_596800.htm
c:\windows\system32\cache329\t_B_515200.htm
c:\windows\system32\cache329\t_B_525100.htm
c:\windows\system32\cache329\t_B_544700.htm
c:\windows\system32\cache329\t_B_576800.htm
c:\windows\system32\cache329\t_B_580600.htm
c:\windows\system32\cache329\t_B_580900.htm
c:\windows\system32\cache329\t_B_604700.htm
c:\windows\system32\cache329\t_B_634700.htm
c:\windows\system32\cache329\t_B_637600.htm
c:\windows\system32\cache329\t_B_638200.htm
c:\windows\system32\cache329\t_B_640700.htm
c:\windows\system32\cache329\t_B_641700.htm
c:\windows\system32\cache329\t_B_642100.htm
c:\windows\system32\cache329\t_B_644900.htm
c:\windows\system32\cache329\t_B_658100.htm
c:\windows\system32\cache329\t_B_670300.htm
c:\windows\system32\cache329\t_B_686800.htm
c:\windows\system32\cache329\t_B_686900.htm
c:\windows\system32\cache329\t_B_692000.htm
c:\windows\system32\cache329\t_B_753400.htm
c:\windows\system32\cache329\t_B_791300.htm
c:\windows\system32\critical_warning.html
c:\windows\system32\cru629.dat
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\UACbukilrnghd.sys
c:\windows\system32\msxml71.dll
c:\windows\system32\UACbrvqqutlud.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACrmauaqsyqd.dll
c:\windows\system32\UACtqlxnwrefq.dat
c:\windows\system32\UACvjhajscdem.dll
c:\windows\system32\uninstall.exe
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\winhelper.dll
c:\windows\system32\wisdstr.exe
c:\windows\uncanny.exe
C:\yihw.exe
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\logevent.dll
c:\windows\system32\drivers\beep.sys . . . is infected!!
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.
2009-08-31 17:22 . 2004-08-04 07:56 50176 —-a-w- c:\windows\system32\proquota.exe
2009-08-26 17:26 . 2009-08-26 17:26 ——– d–h–w- c:\windows\PIF
2009-08-25 03:52 . 2009-08-27 14:25 153104 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-08-24 05:30 . 2009-08-24 05:30 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-24 05:30 . 2009-08-24 05:30 ——– d—–w- c:\program files\MSBuild
2009-08-24 05:30 . 2009-08-24 05:30 ——– d—–w- c:\program files\Reference Assemblies
2009-08-24 05:28 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-24 05:28 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-24 05:28 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-24 05:28 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-24 05:28 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-24 05:28 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-24 05:28 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-24 05:28 . 2009-08-24 05:29 ——– d—–w- C:\8334069a618e675d9df81f1d
2009-08-24 05:21 . 2009-08-24 05:21 ——– d—–w- c:\program files\MSXML 6.0
2009-08-22 17:31 . 2009-08-22 17:31 ——– d—–w- c:\program files\MSECache
2009-08-22 15:53 . 2009-08-22 15:53 ——– d—–w- c:\documents and settings\eu.YOUR-6BVPXYZTOQ\log
2009-08-18 08:34 . 2009-08-31 17:16 ——– d-sh–w- c:\windows\Installer
2009-08-18 08:31 . 2009-08-18 16:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-18 08:31 . 2009-08-18 08:32 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-18 06:37 . 2009-08-18 06:37 31232 —-a-w- c:\windows\system32\wingenocx.dll
2009-08-13 02:54 . 2009-06-05 07:42 655872 ——w- c:\windows\system32\dllcache\mstscax.dll
2009-08-12 02:06 . 2009-08-29 16:12 ——– d—–w- c:\documents and settings\eu.YOUR-6BVPXYZTOQ\Tracing
2009-08-11 06:40 . 2009-08-11 06:40 ——– d—–w- c:\program files\Microsoft
2009-08-11 06:40 . 2009-08-11 06:40 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-08-11 06:39 . 2009-08-11 06:40 ——– d—–w- c:\program files\Windows Live
2009-08-11 06:36 . 2009-08-11 06:36 ——– d—–w- c:\program files\Common Files\Windows Live
2009-08-10 05:48 . 2004-01-13 13:51 45056 ——w- c:\windows\system32\WLTRYSVC.EXE
2009-08-10 05:48 . 2004-01-13 13:51 499712 ——w- c:\windows\system32\BCMWLTRY.EXE
2009-08-10 05:48 . 2004-01-13 13:51 110592 ——w- c:\windows\system32\AegisI5.exe
2009-08-10 05:46 . 2004-08-04 22:05 57344 ——w- c:\windows\system32\BCMWLD2K.EXE
2009-08-10 05:46 . 2004-08-04 22:05 139264 ——w- c:\windows\system32\BCMWLU00.EXE
2009-08-05 09:11 . 2009-08-05 09:11 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-02 15:47 . 2009-08-02 15:47 ——– d—–w- C:\Restaurant stuff
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-21 16:39 . 2009-01-29 01:54 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-21 05:28 . 2005-10-01 16:10 ——– d—–w- c:\program files\Lavasoft
2009-08-21 04:46 . 2004-11-20 04:53 ——– d—–w- c:\documents and settings\eu.YOUR-6BVPXYZTOQ\Application Data\Lavasoft
2009-08-18 15:59 . 2009-01-29 01:55 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-18 15:59 . 2009-01-29 01:55 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-18 15:59 . 2007-04-12 14:13 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-12 02:06 . 2005-03-24 19:05 82000 —-a-w- c:\documents and settings\eu.YOUR-6BVPXYZTOQ\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-11 06:41 . 2004-08-27 22:47 ——– d—–w- c:\program files\MSN Messenger
2009-08-10 05:54 . 2007-07-29 05:31 15584 —-a-w- c:\windows\system32\drivers\mdc8021x.sys
2009-08-05 09:11 . 2002-08-29 02:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 16:09 . 2007-04-19 18:50 ——– d—–w- c:\documents and settings\eu.YOUR-6BVPXYZTOQ\Application Data\CoreFTP
2009-07-17 18:55 . 2002-08-29 02:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 14:08 . 2004-12-14 09:26 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-26 16:18 . 2004-12-08 00:37 659456 —-a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-12-14 09:22 81920 ——w- c:\windows\system32\ieencode.dll
2009-06-16 14:55 . 2002-08-29 02:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2002-08-29 02:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 2002-08-29 02:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 2002-08-29 02:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 2002-08-29 02:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-05 07:42 . 2002-08-29 02:00 655872 —-a-w- c:\windows\system32\mstscax.dll
2009-06-03 19:27 . 2002-08-29 02:00 1290752 —-a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXBUCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2004-11-02 69632]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-03-14 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-03-14 634880]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"srmclean"="c:\cpqs\Scom\srmclean.exe" [2001-07-24 36864]
"PreloadApp"="c:\hp\drivers\printers\photosmart\hphprld.exe" [2001-12-12 36864]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"Display Settings"="c:\program files\HPQ\Notebook Utilities\hptasks.exe" [2002-08-15 45056]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-18 2007832]
"CARPService"="carpserv.exe" - c:\windows\system32\carpserv.exe [2003-05-21 4608]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2002-06-11 28672]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
D-Link AirPlus Xtreme G Configuration Utility.lnk - c:\program files\D-Link AirPlus Xtreme G\AirPlus.exe [2007-7-29 512082]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-18 15:59 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digimax Viewer 2.1.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digimax Viewer 2.1.lnk
backup=c:\windows\pss\Digimax Viewer 2.1.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1128308973\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\1128308973\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1128308973\\ee\\aim6.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/28/2009 9:55 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/28/2009 9:55 PM 108552]
R2 AdvancedDirectRemailer;Advanced Direct Remailer;c:\program files\Explorer\adr.exe [10/11/2004 3:13 AM 386048]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/28/2009 9:54 PM 297752]
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;c:\windows\system32\drivers\caliaud.sys [5/15/2003 9:05 PM 291328]
R3 CALIHALA;CALIHALA;c:\windows\system32\drivers\calihal.sys [5/15/2003 9:05 PM 244608]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;c:\windows\system32\drivers\DP83815.sys [5/15/2003 9:03 PM 16512]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/18/2009 11:59 AM 908056]
.
Contents of the 'Scheduled Tasks' folder
2004-09-01 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-05-16 16:04]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-WindowsRegKeys update - winsysi.exe
HKLM-Run-Win32 Usb Driver - AvpG.exe
HKLM-Run-Microsoft Management - lmas.exe
HKU-Default-Run-eZWO - c:\progra~1\Web Offer\wo.exe
HKU-Default-Run-WindowsRegKeys update - winsysi.exe
HKU-Default-Run-Win32 Configuration - videosd32.exe
HKU-Default-Run-Win32 USB2 Driver - svchosting.exe
HKU-Default-Run-Microsoft Management - lmas.exe
HKU-Default-RunOnce-Win32 Configuration - videosd32.exe
HKU-Default-RunOnce-Win32 USB2 Driver - svchosting.exe
HKU-Default-RunOnce-Win32 Usb Driver - AvpG.exe
HKU-Default-RunOnce-Microsoft Management - lmas.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://us8l.hpwis.com/
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
IE: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZN
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: yahoo.com\www
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\eu.YOUR-6BVPXYZTOQ\Application Data\Mozilla\Firefox\Profiles\8u2xwlpi.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-31 13:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBUCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3452)
c:\windows\System32\shdoclc.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\HPConfig.exe
c:\program files\HPQ\Notebook Utilities\HPWirelessMgr.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\WLTRYSVC.EXE
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\BCMWLTRY.EXE
.
**************************************************************************
.
Completion time: 2009-08-31 13:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-31 17:50
Pre-Run: 15,434,866,688 bytes free
Post-Run: 16,703,012,864 bytes free
826 — E O F — 2009-08-31 17:44