I uninstalled Vuze.
TDSSKiller.2.3.2.0_17.06.2010_02.06.33_log
02:06:33:424 3468 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48
02:06:33:424 3468 ===========================================================================
=====
02:06:33:424 3468 SystemInfo:
02:06:33:424 3468 OS Version: 6.1.7600 ServicePack: 0.0
02:06:33:424 3468 Product type: Workstation
02:06:33:424 3468 ComputerName: MAHA-WINDESK
02:06:33:426 3468 UserName: Maha
02:06:33:426 3468 Windows directory: C:\Windows
02:06:33:426 3468 Processor architecture: Intel x86
02:06:33:426 3468 Number of processors: 2
02:06:33:426 3468 Page size: 0x1000
02:06:33:426 3468 Boot type: Normal boot
02:06:33:426 3468 ===========================================================================
=====
02:06:33:634 3468 Initialize success
02:06:33:634 3468
02:06:33:634 3468 Scanning Services …
02:06:34:589 3468 Raw services enum returned 466 services
02:06:34:599 3468
02:06:34:599 3468 Scanning Drivers …
02:06:35:566 3468 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
02:06:35:644 3468 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
02:06:35:671 3468 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
02:06:35:694 3468 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
02:06:35:716 3468 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
02:06:35:746 3468 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
02:06:35:789 3468 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
02:06:35:816 3468 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
02:06:35:834 3468 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
02:06:35:856 3468 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
02:06:35:879 3468 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
02:06:35:901 3468 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
02:06:35:919 3468 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
02:06:35:941 3468 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
02:06:35:954 3468 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
02:06:35:971 3468 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
02:06:35:991 3468 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
02:06:36:014 3468 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
02:06:36:034 3468 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
02:06:36:054 3468 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
02:06:36:071 3468 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
02:06:36:089 3468 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
02:06:36:131 3468 AvgLdx86 (9c0a7e6d3cb9a8a7ad4e4575d9a42e94) C:\Windows\system32\Drivers\avgldx86.sys
02:06:36:156 3468 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\Windows\system32\Drivers\avgmfx86.sys
02:06:36:189 3468 AvgTdiX (6e11bbc8dc5af836adc9c5f682fa3186) C:\Windows\system32\Drivers\avgtdix.sys
02:06:36:219 3468 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
02:06:36:249 3468 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
02:06:36:274 3468 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
02:06:36:301 3468 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
02:06:36:321 3468 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys
02:06:36:341 3468 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
02:06:36:356 3468 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
02:06:36:386 3468 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
02:06:36:406 3468 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
02:06:36:436 3468 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
02:06:36:464 3468 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
02:06:36:496 3468 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\DRIVERS\BthEnum.sys
02:06:36:524 3468 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
02:06:36:554 3468 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys
02:06:36:586 3468 BTHPORT (4a34888e13224678dd062466afec4240) C:\Windows\system32\Drivers\BTHport.sys
02:06:36:616 3468 BTHUSB (fa04c63916fa221dbb91fce153d07a55) C:\Windows\system32\Drivers\BTHUSB.sys
02:06:36:699 3468 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
02:06:36:759 3468 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
02:06:36:786 3468 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
02:06:36:819 3468 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
02:06:36:841 3468 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
02:06:36:861 3468 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
02:06:36:911 3468 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
02:06:36:939 3468 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
02:06:36:959 3468 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
02:06:36:976 3468 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
02:06:37:044 3468 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
02:06:37:089 3468 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
02:06:37:114 3468 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
02:06:37:139 3468 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
02:06:37:166 3468 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
02:06:37:201 3468 DXGKrnl (39806cfeddcc55e686a49bccd2972f23) C:\Windows\System32\drivers\dxgkrnl.sys
02:06:37:301 3468 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
02:06:37:391 3468 EL90Xbc (fd3821285b943648a32adc39dacc4e11) C:\Windows\system32\DRIVERS\el90Xbc5.SYS
02:06:37:426 3468 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
02:06:37:454 3468 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
02:06:37:476 3468 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
02:06:37:514 3468 Ext2Fsd (0f8f910c369d8b45facfda04cbb8008e) C:\Windows\system32\drivers\Ext2Fsd.sys
02:06:37:536 3468 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
02:06:37:559 3468 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
02:06:37:604 3468 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
02:06:37:621 3468 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
02:06:37:639 3468 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
02:06:37:679 3468 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
02:06:37:704 3468 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
02:06:37:724 3468 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
02:06:37:774 3468 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys
02:06:37:809 3468 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
02:06:37:841 3468 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
02:06:37:869 3468 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
02:06:37:896 3468 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
02:06:37:916 3468 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
02:06:37:939 3468 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
02:06:37:964 3468 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
02:06:37:981 3468 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
02:06:37:996 3468 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
02:06:38:024 3468 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
02:06:38:054 3468 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
02:06:38:071 3468 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
02:06:38:091 3468 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
02:06:38:119 3468 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
02:06:38:136 3468 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
02:06:38:154 3468 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
02:06:38:166 3468 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
02:06:38:186 3468 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
02:06:38:214 3468 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
02:06:38:234 3468 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
02:06:38:256 3468 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
02:06:38:279 3468 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
02:06:38:311 3468 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
02:06:38:331 3468 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
02:06:38:359 3468 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\Windows\system32\drivers\klmd.sys
02:06:38:394 3468 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
02:06:38:434 3468 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
02:06:38:469 3468 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\Windows\system32\DRIVERS\Lbd.sys
02:06:38:489 3468 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
02:06:38:519 3468 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
02:06:38:541 3468 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
02:06:38:571 3468 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
02:06:38:591 3468 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
02:06:38:614 3468 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
02:06:38:636 3468 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
02:06:38:656 3468 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
02:06:38:679 3468 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
02:06:38:696 3468 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
02:06:38:719 3468 MotioninJoyXFilter (ff9cf969e122a19a6948a4e483ccded8) C:\Windows\system32\DRIVERS\MijXfilt.sys
02:06:38:739 3468 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
02:06:38:754 3468 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
02:06:38:784 3468 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
02:06:38:804 3468 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
02:06:38:821 3468 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
02:06:38:839 3468 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
02:06:38:869 3468 mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\Windows\system32\DRIVERS\mrxsmb.sys
02:06:38:891 3468 mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\Windows\system32\DRIVERS\mrxsmb10.sys
02:06:38:916 3468 mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\Windows\system32\DRIVERS\mrxsmb20.sys
02:06:38:934 3468 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
02:06:38:949 3468 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
02:06:38:966 3468 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
02:06:38:984 3468 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
02:06:39:001 3468 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
02:06:39:026 3468 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
02:06:39:046 3468 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
02:06:39:069 3468 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
02:06:39:089 3468 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
02:06:39:124 3468 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
02:06:39:141 3468 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
02:06:39:156 3468 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
02:06:39:201 3468 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
02:06:39:229 3468 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
02:06:39:299 3468 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
02:06:39:339 3468 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
02:06:39:361 3468 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
02:06:39:376 3468 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
02:06:39:399 3468 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
02:06:39:419 3468 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
02:06:39:451 3468 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
02:06:39:489 3468 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
02:06:39:534 3468 netr28 (a03fe2ea906e7172290d9888b894903a) C:\Windows\system32\DRIVERS\netr28.sys
02:06:39:571 3468 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
02:06:39:589 3468 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
02:06:39:611 3468 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
02:06:39:654 3468 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
02:06:39:709 3468 NTIDrvr (7f1c1f78d709c4a54cbb46ede7e0b48d) C:\Windows\system32\DRIVERS\NTIDrvr.sys
02:06:39:726 3468 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
02:06:39:956 3468 nvlddmkm (c8cb6135884cbc2a10225c4c3cef0f95) C:\Windows\system32\DRIVERS\nvlddmkm.sys
02:06:40:026 3468 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
02:06:40:046 3468 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
02:06:40:071 3468 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
02:06:40:094 3468 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
02:06:40:114 3468 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
02:06:40:146 3468 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
02:06:40:169 3468 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
02:06:40:201 3468 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
02:06:40:226 3468 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
02:06:40:249 3468 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
02:06:40:276 3468 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
02:06:40:301 3468 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
02:06:40:336 3468 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
02:06:40:359 3468 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
02:06:40:394 3468 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
02:06:40:441 3468 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
02:06:40:494 3468 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
02:06:40:519 3468 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
02:06:40:539 3468 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
02:06:40:569 3468 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
02:06:40:589 3468 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
02:06:40:609 3468 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
02:06:40:626 3468 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
02:06:40:654 3468 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
02:06:40:681 3468 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
02:06:40:694 3468 RDPCDD (8b4cbb570649f3600f11eafd2c2ccc5f) C:\Windows\system32\DRIVERS\RDPCDD.sys
02:06:40:694 3468 Suspicious file (Forged): C:\Windows\system32\DRIVERS\RDPCDD.sys. Real md5: 8b4cbb570649f3600f11eafd2c2ccc5f, Fake md5: 1e016846895b15a99f9a176a05029075
02:06:40:694 3468 File "C:\Windows\system32\DRIVERS\RDPCDD.sys" infected by TDSS rootkit … 02:06:40:849 3468 Backup copy found, using it..
02:06:40:864 3468 will be cured on next reboot
02:06:40:906 3468 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
02:06:40:921 3468 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
02:06:40:936 3468 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
02:06:40:961 3468 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
02:06:41:019 3468 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
02:06:41:044 3468 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys
02:06:41:064 3468 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
02:06:41:096 3468 RTL8167 (7dfd48e24479b68b258d8770121155a0) C:\Windows\system32\DRIVERS\Rt86win7.sys
02:06:41:119 3468 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
02:06:41:139 3468 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
02:06:41:171 3468 SCDEmu (23aa53256ce05b975398b78a33474265) C:\Windows\system32\drivers\SCDEmu.sys
02:06:41:181 3468 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
02:06:41:199 3468 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
02:06:41:216 3468 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
02:06:41:241 3468 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
02:06:41:261 3468 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
02:06:41:279 3468 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
02:06:41:301 3468 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
02:06:41:324 3468 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys
02:06:41:344 3468 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
02:06:41:364 3468 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
02:06:41:384 3468 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
02:06:41:406 3468 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
02:06:41:429 3468 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
02:06:41:449 3468 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
02:06:41:496 3468 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
02:06:41:539 3468 srv (2ba4ebc7dfba845a1edbe1f75913be33) C:\Windows\system32\DRIVERS\srv.sys
02:06:41:566 3468 srv2 (dce7e10feaabd4cae95948b3de5340bb) C:\Windows\system32\DRIVERS\srv2.sys
02:06:41:591 3468 srvnet (b5665baa2120b8a54e22e9cd07c05106) C:\Windows\system32\DRIVERS\srvnet.sys
02:06:41:614 3468 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
02:06:41:644 3468 StillCam (edb05bd63148796f23ea78506404a538) C:\Windows\system32\DRIVERS\serscan.sys
02:06:41:674 3468 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
02:06:41:701 3468 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
02:06:41:716 3468 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
02:06:41:816 3468 Tcpip (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\drivers\tcpip.sys
02:06:41:879 3468 TCPIP6 (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\DRIVERS\tcpip.sys
02:06:41:904 3468 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
02:06:41:926 3468 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
02:06:41:944 3468 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
02:06:41:974 3468 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
02:06:42:014 3468 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
02:06:42:031 3468 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
02:06:42:051 3468 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
02:06:42:071 3468 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
02:06:42:096 3468 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
02:06:42:119 3468 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
02:06:42:139 3468 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
02:06:42:164 3468 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
02:06:42:181 3468 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
02:06:42:206 3468 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
02:06:42:224 3468 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
02:06:42:251 3468 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys
02:06:42:276 3468 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
02:06:42:299 3468 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
02:06:42:329 3468 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
02:06:42:346 3468 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
02:06:42:374 3468 usb_rndisx (d82f43d15fdaa666856c0190cb73e7c9) C:\Windows\system32\DRIVERS\usb8023x.sys
02:06:42:401 3468 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
02:06:42:434 3468 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
02:06:42:459 3468 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
02:06:42:479 3468 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
02:06:42:499 3468 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
02:06:42:524 3468 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
02:06:42:541 3468 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
02:06:42:574 3468 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys
02:06:42:599 3468 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys
02:06:42:634 3468 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
02:06:42:684 3468 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
02:06:42:734 3468 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
02:06:42:756 3468 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
02:06:42:776 3468 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
02:06:42:806 3468 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
02:06:42:824 3468 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys
02:06:42:844 3468 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
02:06:42:879 3468 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
02:06:42:884 3468 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
02:06:42:901 3468 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
02:06:42:964 3468 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
02:06:42:986 3468 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
02:06:43:009 3468 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
02:06:43:031 3468 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
02:06:43:051 3468 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
02:06:43:074 3468 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
02:06:43:101 3468 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
02:06:43:129 3468 xusb21 (ee9144207ee0211eb5656ba6808ac4a0) C:\Windows\system32\DRIVERS\xusb21.sys
02:06:43:131 3468 Reboot required for cure complete..
02:06:43:331 3468 Cure on reboot scheduled successfully
02:06:43:331 3468
02:06:43:331 3468 Completed
02:06:43:331 3468
02:06:43:331 3468 Results:
02:06:43:331 3468 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
02:06:43:331 3468 File objects infected / cured / cured on reboot: 1 / 0 / 1
02:06:43:331 3468
02:06:43:334 3468 KLMD(ARK) unloaded successfully
ComboFix Log
ComboFix 10-06-16.02 - Maha 06/17/2010 3:28.4.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.2.1033.18.2046.987 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Maha\Desktop\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2010-05-17 to 2010-06-17 )))))))))))))))))))))))))))))))
.
2010-06-16 21:30 . 2010-06-16 21:30 3304 ——w- C:\bootsqm.dat
2010-06-16 07:27 . 2010-06-09 13:58 85464 —-a-w- c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
2010-06-16 07:27 . 2010-06-09 13:58 38872 —-a-w- c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINCE\components\WeaveCrypto.dll
2010-06-15 09:59 . 2010-06-15 10:00 ——– d—–w- c:\users\Maha\KeeperData
2010-06-15 09:59 . 2010-06-15 09:59 ——– d—–w- c:\program files\Callpod
2010-06-14 00:00 . 2010-06-13 23:33 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-13 03:50 . 2010-06-14 02:37 ——– d—–w- c:\users\Maha\AppData\Roaming\dvdcss
2010-06-12 07:58 . 2010-06-12 07:58 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE
2010-06-12 07:58 . 2010-06-12 07:58 ——– d—–w- c:\windows\system32\xlive
2010-06-12 06:42 . 2010-06-12 06:43 ——– d—–w- c:\users\Maha\AppData\Roaming\KVIrc
2010-06-12 06:42 . 2010-06-12 06:42 ——– d—–w- c:\users\Maha\download
2010-06-12 06:39 . 2010-06-12 06:42 ——– d—–w- c:\program files\KVIrc
2010-06-11 23:02 . 2010-06-11 23:02 48648 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2010-06-11 23:02 . 2010-06-11 23:02 573760 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2010-06-11 23:02 . 2010-06-11 23:02 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2010-06-11 23:01 . 2010-06-11 23:01 29512 —-a-w- c:\programdata\avg9\update\backup\avgmfx86.sys
2010-06-11 23:01 . 2010-06-11 23:01 242896 —-a-w- c:\programdata\avg9\update\backup\avgtdix.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-17 07:37 . 2010-04-25 21:42 ——– d—–w- c:\users\Maha\AppData\Roaming\.purple
2010-06-17 07:36 . 2010-05-13 02:52 ——– d—–w- c:\users\Maha\AppData\Roaming\Dropbox
2010-06-17 07:25 . 2010-04-26 05:20 ——– d—–w- c:\users\Maha\AppData\Roaming\Skype
2010-06-17 07:22 . 2009-07-14 02:37 ——– d—–w- c:\program files\Windows Mail
2010-06-17 06:19 . 2010-06-17 06:19 2165 —-a-w- c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\rsi.hotmail.com
2010-06-17 06:19 . 2010-06-17 06:19 2157 —-a-w- c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\omega.contacts.msn.com
2010-06-17 06:19 . 2010-06-17 06:19 2095 —-a-w- c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\login.live.com
2010-06-17 06:19 . 2010-06-17 06:19 1089 —-a-w- c:\users\Maha\AppData\Roaming\.purple\certificates\x509\tls_peers\login.yahoo.com
2010-06-17 06:19 . 2009-07-14 00:01 6656 —-a-w- c:\windows\system32\drivers\RDPCDD.sys
2010-06-17 02:06 . 2010-04-25 22:43 ——– d—–w- c:\program files\Vuze
2010-06-17 01:37 . 2010-04-27 02:50 48648 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2010-06-17 01:37 . 2010-04-27 02:50 573760 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-06-17 01:37 . 2010-04-27 02:50 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2010-06-16 21:32 . 2010-04-26 05:21 ——– d—–w- c:\users\Maha\AppData\Roaming\skypePM
2010-06-16 21:10 . 2010-04-25 22:43 ——– d—–w- c:\users\Maha\AppData\Roaming\Azureus
2010-06-15 04:25 . 2010-04-26 07:00 ——– d—–w- c:\users\Maha\AppData\Roaming\vlc
2010-06-14 02:34 . 2010-04-25 23:47 ——– d—–w- c:\programdata\Zoom Player
2010-06-14 00:41 . 2010-04-27 01:04 65 —-a-w- c:\windows\system32\bd7020.dat
2010-06-12 23:14 . 2010-04-26 02:12 ——– d—–w- c:\program files\Brother
2010-06-12 23:14 . 2010-04-25 15:10 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-12 07:52 . 2010-04-25 20:31 ——– d—–w- c:\program files\Common Files\Steam
2010-06-11 23:10 . 2010-04-25 23:28 ——– d—–w- c:\program files\Google
2010-06-11 23:01 . 2010-04-25 21:00 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-11 23:01 . 2010-04-25 21:00 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-18 01:54 . 2010-05-14 10:30 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-05-18 01:54 . 2010-05-14 10:30 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-05-18 01:53 . 2010-05-14 08:55 ——– d—–w- c:\users\Maha\AppData\Roaming\OpenOffice.org
2010-05-18 01:53 . 2010-05-13 01:51 ——– d—–w- c:\program files\MotioninJoy
2010-05-14 08:58 . 2010-05-14 08:58 1 —-a-w- c:\users\Maha\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-13 05:28 . 2010-04-26 23:37 174 —-a-w- c:\users\Maha\AppData\Roaming\Azureus\restart.bat
2010-05-13 04:46 . 2010-05-13 04:46 ——– d—–w- c:\users\Maha\AppData\Roaming\KeePass
2010-05-13 04:45 . 2010-05-13 04:45 ——– d—–w- c:\program files\KeePass Password Safe 2
2010-05-13 02:52 . 2010-05-13 02:52 89831 —-a-w- c:\users\Maha\AppData\Roaming\Dropbox\bin\Uninstall.exe
2010-05-13 01:53 . 2010-05-13 01:53 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01009.Wdf
2010-05-13 01:53 . 2010-05-13 01:53 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_MijXfilt_01009.Wdf
2010-05-13 01:51 . 2010-05-13 01:51 ——– d—–w- c:\users\Maha\AppData\Roaming\MotioninJoy
2010-05-13 01:51 . 2010-05-13 01:51 ——– d—–w- c:\programdata\MotioninJoy
2010-05-12 04:44 . 2010-04-26 00:23 ——– d—–w- c:\programdata\Microsoft Help
2010-05-09 00:39 . 2010-05-09 00:39 ——– d—–w- c:\users\Maha\AppData\Roaming\OtakuSoftware
2010-05-08 22:36 . 2010-05-08 08:18 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-05-08 10:06 . 2010-05-08 10:06 ——– d—–w- c:\users\Maha\AppData\Roaming\360desktop
2010-05-08 09:20 . 2010-05-08 09:20 ——– d—–w- c:\users\Maha\AppData\Roaming\BMG
2010-05-02 08:33 . 2010-05-02 08:33 ——– d—–w- c:\program files\Gabest
2010-05-02 06:41 . 2010-05-02 06:41 15884 —-a-w- c:\users\Maha\AppData\Roaming\Azureus\plugins\azitunes\libProcessAccess.dll
2010-05-02 06:41 . 2010-05-02 06:41 102400 —-a-w- c:\users\Maha\AppData\Roaming\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll
2010-05-02 06:41 . 2010-05-02 06:41 7282688 —-a-w- c:\users\Maha\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe
2010-05-02 06:41 . 2010-05-02 06:41 4141117 —-a-w- c:\users\Maha\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe
2010-05-02 06:10 . 2010-05-02 06:10 ——– d—–w- c:\users\Maha\AppData\Roaming\AnvSoft
2010-05-02 06:10 . 2010-05-02 06:10 ——– d—–w- c:\program files\AnvSoft
2010-05-02 00:37 . 2010-05-01 21:44 ——– d—–w- c:\users\Maha\AppData\Roaming\WinFF
2010-05-01 21:44 . 2010-05-01 21:44 ——– d—–w- c:\program files\WinFF
2010-05-01 21:14 . 2010-04-25 18:54 ——– d—–w- c:\program files\Opera
2010-05-01 19:16 . 2010-05-01 19:16 ——– d—–w- c:\users\Maha\AppData\Roaming\AVS4YOU
2010-05-01 19:16 . 2010-04-25 21:00 ——– d—–w- c:\programdata\AVG Security Toolbar
2010-05-01 19:16 . 2010-05-01 19:14 ——– d—–w- c:\programdata\AVS4YOU
2010-05-01 19:15 . 2010-05-01 19:14 ——– d—–w- c:\program files\AVS4YOU
2010-05-01 19:15 . 2010-05-01 19:14 ——– d—–w- c:\program files\Common Files\AVSMedia
2010-04-27 02:24 . 2010-04-27 02:23 ——– d—–w- c:\program files\DVDStyler
2010-04-27 02:23 . 2010-04-27 02:23 ——– d—–w- c:\program files\Burn To DVD
2010-04-27 01:38 . 2010-04-27 01:38 ——– d—–r- c:\users\Maha\AppData\Roaming\Brother
2010-04-27 00:19 . 2010-04-25 22:41 ——– d—–w- c:\users\Maha\AppData\Roaming\uTorrent
2010-04-27 00:19 . 2009-07-13 23:40 409088 —-a-w- c:\windows\system32\systemcpl.dll
2010-04-27 00:19 . 2009-07-13 23:36 13824 —-a-w- c:\windows\system32\slwga.dll
2010-04-27 00:19 . 2009-07-13 23:24 811520 —-a-w- c:\windows\system32\user32.dll
2010-04-26 20:40 . 2010-04-26 20:40 ——– d—–w- c:\users\Maha\AppData\Roaming\Media Player Classic
2010-04-26 08:08 . 2010-04-25 21:57 ——– d—–w- c:\program files\AIM Toolbar
2010-04-26 08:08 . 2010-04-25 21:57 ——– d—–w- c:\program files\AIM
2010-04-26 08:08 . 2010-04-25 21:57 ——– d—–w- c:\program files\Common Files\AOL
2010-04-26 08:08 . 2010-04-25 23:21 ——– d—–w- c:\program files\NVIDIA Corporation
2010-04-26 07:51 . 2010-04-26 07:51 1024 ——w- c:\windows\system32\NTIMPEG2.dll
2010-04-26 07:51 . 2010-04-26 07:51 1024 ——w- c:\windows\system32\NTIMP3.dll
2010-04-26 07:51 . 2010-04-26 07:51 1024 ——w- c:\windows\system32\NTICDMK7.dll
2010-04-26 07:51 . 2010-04-26 07:51 6144 ——w- c:\windows\system32\drivers\NTIDrvr.sys
2010-04-26 07:33 . 2010-04-25 23:37 ——– d—–w- c:\program files\Ext2Fsd
2010-04-26 07:30 . 2010-04-25 23:49 ——– d—–w- c:\program files\DCoder Image Source
2010-04-26 07:30 . 2010-04-25 23:49 ——– d—–w- c:\program files\7-Zip
2010-04-26 07:30 . 2010-04-25 23:49 ——– d—–w- c:\program files\FFMPEG Core Files
2010-04-26 07:29 . 2010-04-26 07:29 ——– d—–w- c:\program files\SHOUTcast Source
2010-04-26 07:29 . 2010-04-26 07:29 ——– d—–w- c:\program files\MONOGRAM AMR SplitterDecoder
2010-04-26 07:29 . 2010-04-26 07:29 ——– d—–w- c:\program files\CD Audio Reader Filter
2010-04-26 07:29 . 2010-04-25 23:49 ——– d—–w- c:\program files\OpenSource AVI Splitter
2010-04-26 07:29 . 2010-04-25 23:49 ——– d—–w- c:\program files\Gabest MPEG Splitter
2010-04-26 07:29 . 2010-04-25 23:49 ——– d—–w- c:\program files\OpenSource DTSAC3DD+ Source Filter
2010-04-26 07:29 . 2010-04-25 23:49 ——– d—–w- c:\program files\RealMedia
2010-04-26 07:28 . 2010-04-25 23:49 ——– d—–w- c:\program files\DScaler5
2010-04-26 07:28 . 2010-04-25 23:49 ——– d—–w- c:\program files\AC3Filter
2010-04-26 07:28 . 2010-04-25 23:49 ——– d—–w- c:\program files\OpenSource Flash Video Splitter
2010-04-26 07:28 . 2010-04-26 07:28 ——– d—–w- c:\program files\DirectVobSub
2010-04-26 07:28 . 2010-04-26 07:28 ——– d—–w- c:\program files\Haali
2010-04-26 07:28 . 2010-04-25 23:48 ——– d—–w- c:\program files\Bass Audio Decoder
2010-04-26 07:27 . 2010-04-25 23:47 ——– d—–w- c:\program files\Zoom Player
2010-04-26 07:23 . 2010-04-25 22:45 ——– d—–w- c:\users\Maha\AppData\Roaming\DAEMON Tools Lite
2010-04-26 07:18 . 2010-04-25 22:45 ——– d—–w- c:\program files\PowerISO
2010-04-26 07:17 . 2010-04-26 07:17 ——– d—–w- c:\program files\DAEMON Tools Toolbar
2010-04-26 07:17 . 2010-04-25 22:46 ——– d—–w- c:\program files\DAEMON Tools Lite
2010-04-26 07:16 . 2010-04-26 07:16 691696 ——w- c:\windows\system32\drivers\sptd.sys
2010-04-26 07:15 . 2010-04-25 23:13 ——– d—–w- c:\program files\Audacity
2010-04-26 06:58 . 2010-04-26 06:58 95024 ——w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-26 06:56 . 2010-04-25 23:27 ——– dc-h–w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-26 06:47 . 2010-04-25 22:43 113712 —-a-w- c:\users\Maha\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
——- Sigcheck ——-
[-] 2010-04-27 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
.
((((((((((((((((((((((((((((( SnapShot_2010-06-17_00.34.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-25 20:52 . 2010-06-17 07:26 30814 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-06-17 07:26 36408 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-04-25 14:27 . 2010-06-16 23:32 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-04-25 14:27 . 2010-06-17 07:24 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:41 . 2010-06-16 23:32 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:41 . 2010-06-17 07:24 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-04-25 15:02 . 2010-06-17 00:29 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-04-25 15:02 . 2010-06-17 07:25 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-04-25 15:02 . 2010-06-17 00:29 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-25 15:02 . 2010-06-17 07:25 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-04-25 15:02 . 2010-06-17 00:29 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-04-25 15:02 . 2010-06-17 07:25 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-04-25 15:02 . 2010-06-17 00:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-04-25 15:02 . 2010-06-17 07:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-04-25 17:58 . 2010-06-17 07:31 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2010-04-25 17:58 . 2010-06-17 00:05 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-25 17:58 . 2010-06-17 07:31 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
- 2010-04-25 17:58 . 2010-06-17 00:05 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2010-04-25 17:58 . 2010-06-17 07:31 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2010-04-25 17:58 . 2010-06-17 00:05 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2010-04-25 15:02 . 2010-06-17 00:26 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-25 15:02 . 2010-06-17 07:31 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-04-25 15:02 . 2010-06-17 07:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-04-25 15:02 . 2010-06-17 00:26 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-04-25 20:11 . 2010-06-17 07:26 6718 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1037914879-3900162407-3989981119-1001_UserData.bin
+ 2010-06-17 07:23 . 2010-06-17 07:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-06-17 00:26 . 2010-06-17 00:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-06-17 07:23 . 2010-06-17 07:36 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-06-17 00:26 . 2010-06-17 00:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-06-17 06:56 . 2009-09-10 06:26 257024 c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7600.20524_none_7d52c0e5dccc347d\msv1_0.dll
+ 2010-06-17 06:56 . 2009-09-10 05:52 257024 c:\windows\winsxs\x86_microsoft-windows-security-ntlm_31bf3856ad364e35_6.1.7600.16420_none_7cc522f2c3b22f57\msv1_0.dll
+ 2010-06-17 06:55 . 2010-01-28 02:11 128424 c:\windows\winsxs\x86_microsoft-windows-s..ologies-webcontrols_31bf3856ad364e35_7.1.7600.16395_none_39bc056e339474f4\WatWeb.dll
+ 2010-06-17 06:55 . 2010-01-28 02:11 114600 c:\windows\winsxs\x86_microsoft-windows-s..ologies-webcontrols_31bf3856ad364e35_7.1.7600.16395_none_39bc056e339474f4\npWatWeb.dll
+ 2010-06-17 06:55 . 2010-01-28 02:11 249768 c:\windows\winsxs\x86_microsoft-windows-s..ivationtechnologies_31bf3856ad364e35_7.1.7600.16395_none_2dac82dbc20710f5\WatUX.exe
+ 2010-06-17 07:23 . 2010-06-17 07:23 128424 c:\windows\winsxs\Temp\PendingRenames\f65ddb0dee0dcb0130000000d8043405.WatWeb.dll
+ 2010-06-17 07:17 . 2010-06-17 07:17 128424 c:\windows\winsxs\Temp\PendingRenames\ced0b036ed0dcb013400000098042c05.WatWeb.dll
+ 2010-06-17 07:23 . 2010-06-17 07:23 114600 c:\windows\winsxs\Temp\PendingRenames\96fcd80dee0dcb012f000000d8043405.npWatWeb.dll
+ 2010-06-17 07:17 . 2010-06-17 07:17 114600 c:\windows\winsxs\Temp\PendingRenames\6e6fae36ed0dcb013300000098042c05.npWatWeb.dll
+ 2010-06-17 07:23 . 2010-06-17 07:23 249768 c:\windows\winsxs\Temp\PendingRenames\57bfdd0dee0dcb0131000000d8043405.WatUX.exe
+ 2010-06-17 07:17 . 2010-06-17 07:17 249768 c:\windows\winsxs\Temp\PendingRenames\2e32b336ed0dcb013500000098042c05.WatUX.exe
+ 2009-07-14 02:05 . 2010-06-17 07:28 619206 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-06-17 00:31 619206 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-06-17 00:31 107388 c:\windows\System32\perfc009.dat
+ 2009-07-14 02:05 . 2010-06-17 07:28 107388 c:\windows\System32\perfc009.dat
- 2009-07-14 04:33 . 2010-05-13 01:39 427432 c:\windows\System32\FNTCACHE.DAT
+ 2009-07-14 04:33 . 2010-06-17 07:23 427432 c:\windows\System32\FNTCACHE.DAT
+ 2010-06-17 07:21 . 2010-06-17 07:21 705024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\f335d7d1029aa934986acece3a635939\Microsoft.MediaCenter.Sports.ni.dll
- 2010-05-13 01:40 . 2010-05-13 01:40 324096 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\e5a6bb7d8f34559e2024c62babee5d86\Microsoft.MediaCenter.Playback.ni.dll
+ 2010-06-17 07:24 . 2010-06-17 07:24 324096 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\e5a6bb7d8f34559e2024c62babee5d86\Microsoft.MediaCenter.Playback.ni.dll
- 2010-05-13 01:40 . 2010-05-13 01:40 229888 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cc61539a8e48c0883a6b3a4ddf845205\Microsoft.MediaCenter.iTv.ni.dll
+ 2010-06-17 07:24 . 2010-06-17 07:24 229888 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cc61539a8e48c0883a6b3a4ddf845205\Microsoft.MediaCenter.iTv.ni.dll
+ 2010-06-17 07:22 . 2010-06-17 07:22 229888 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\cbdddbcdca1579a6cc099978cc7296e0\Microsoft.MediaCenter.iTv.ni.dll
+ 2010-06-17 07:22 . 2010-06-17 07:22 142848 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\b71b9c373e27540d6224bc5f01ce9449\Microsoft.MediaCenter.iTv.Media.ni.dll
- 2010-05-13 01:40 . 2010-05-13 01:40 705024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7289063be214d2d4ce367a298949cae7\Microsoft.MediaCenter.Sports.ni.dll
+ 2010-06-17 07:24 . 2010-06-17 07:24 705024 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\7289063be214d2d4ce367a298949cae7\Microsoft.MediaCenter.Sports.ni.dll
+ 2010-06-17 07:24 . 2010-06-17 07:24 142848 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\44402a1799f222acbec11a2730cf1882\Microsoft.MediaCenter.iTv.Media.ni.dll
- 2010-05-13 01:40 . 2010-05-13 01:40 142848 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\44402a1799f222acbec11a2730cf1882\Microsoft.MediaCenter.iTv.Media.ni.dll
+ 2010-06-17 07:21 . 2010-06-17 07:21 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.MediaCent#\42a11e7164074f20b499b1bb794b1cfb\Microsoft.MediaCenter.Playback.ni.dll
+ 2010-06-17 07:21 . 2010-06-17 07:21 693248 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\eca169340ae5df7480031aa29e1e213d\ehRecObj.ni.dll
- 2010-05-13 01:40 . 2010-05-13 01:40 693248 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\3ad30d4c99b971d43964139031ab365f\ehRecObj.ni.dll
+ 2010-06-17 07:24 . 2010-06-17 07:24 693248 c:\windows\assembly\NativeImages_v2.0.50727_32\ehRecObj\3ad30d4c99b971d43964139031ab365f\ehRecObj.ni.dll
+ 2010-06-17 06:55 . 2010-01-28 02:11 1343400 c:\windows\winsxs\x86_microsoft-windows-s..ivationtechnologies_31bf3856ad364e35_7.1.7600.16395_none_2dac82dbc20710f5\WatAdminSvc.exe
+ 2010-06-17 07:23 . 2010-06-17 07:23 1343400 c:\windows\winsxs\Temp\PendingRenames\d639d40dee0dcb012e000000d8043405.WatAdminSvc.exe
+ 2010-06-17 07:17 . 2010-06-17 07:17 1343400 c:\windows\winsxs\Temp\PendingRenames\adaca936ed0dcb013200000098042c05.WatAdminSvc.exe
- 2009-07-14 02:03 . 2010-06-16 21:20 7340032 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:03 . 2010-06-17 07:35 7340032 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2010-04-25 14:27 . 2010-06-17 07:24 1622016 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-04-25 14:27 . 2010-06-16 23:32 1622016 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-06-17 07:28 . 2010-06-17 07:28 7217152 c:\windows\ERDNT\Hiv-backup\schema.dat
+ 2010-06-17 07:21 . 2010-06-17 07:21 3318784 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\eae730343aec2ba0aa22746cf0e14433\mcepg.ni.dll
- 2010-05-13 01:40 . 2010-05-13 01:40 3317248 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\e9c41a0951e933b0589c708f3bd1fb73\mcepg.ni.dll
+ 2010-06-17 07:24 . 2010-06-17 07:24 3317248 c:\windows\assembly\NativeImages_v2.0.50727_32\mcepg\e9c41a0951e933b0589c708f3bd1fb73\mcepg.ni.dll
+ 2009-07-14 07:18 . 2010-06-17 06:56 16521150 c:\windows\winsxs\ManifestCache\e4e8be02b8fae2a7_blobs.bin
+ 2010-06-17 06:56 . 2010-04-30 15:51 32058312 c:\windows\System32\MRT.exe
+ 2010-06-17 07:22 . 2010-06-17 07:22 18683904 c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\d569c1d188cbab71c6ecb9ab354a90b1\ehshell.ni.dll
- 2010-05-13 01:40 . 2010-05-13 01:40 18679296 c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\9b3d5ac3c6d0a37e98396f5702964566\ehshell.ni.dll
+ 2010-06-17 07:24 . 2010-06-17 07:24 18679296 c:\windows\assembly\NativeImages_v2.0.50727_32\ehshell\9b3d5ac3c6d0a37e98396f5702964566\ehshell.ni.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 18:04 1664256 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pidgin"="c:\program files\Pidgin\pidgin.exe" [2010-02-16 45603]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-06 26102056]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"DS3 Tool"="c:\program files\MotioninJoy\ds3\DS3_Tool.exe" [2010-01-19 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"Ext2 Volume Manager"="c:\program files\Ext2Fsd\Ext2Mgr.exe" [2009-07-30 1216648]
c:\users\Maha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Maha\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2010-4-25 1576960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 06:12 483328 —-a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-07-27 02:37 180224 —-a-w- c:\program files\PowerISO\PWRISOVM.EXE
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 135664]
R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-02-23 369920]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-06-16 1352832]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-04-26 691696]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-13 64288]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-04-25 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-06-11 242896]
S1 Ext2Fsd;Linux ext2 file system driver; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-04-25 916760]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-04-25 308064]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\DRIVERS\MijXfilt.sys [2010-03-18 48640]
S3 netr28;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28.sys [2009-08-04 616960]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
Contents of the 'Scheduled Tasks' folder
2010-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:56]
2010-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:56]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {DF59BE5D-7566-46BB-AD9E-484E898B646B} = 8.8.8.8,8.8.4.4
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\users\Maha\AppData\Roaming\Mozilla\Firefox\Profiles\3vdlk487.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pre
f", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1037914879-3900162407-3989981119-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DFD4E303-F5AB-6CB0-6EB8-E0E44EEB4DC4}*]
"paaphbglbkfpfpoehlhpbfpofipmgkkp"=hex:6a,61,66,70,6a,62,62,6d,70,62,69,6a,64,
67,69,66,70,62,62,65,00,b9
"abgofpbbjmegkimnollecfocoeimiadbom"=hex:69,61,6d,70,6f,62,6c,64,66,6c,6a,68,
6a,6c,6c,69,6c,6f,00,00
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(3696)
c:\users\Maha\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\AUDIODG.EXE
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\EDIMAX\Common\RaRegistry.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\WUDFHost.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\Brother\ControlCenter3\brccMCtl.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2010-06-17 03:39:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-17 07:38
ComboFix2.txt 2010-06-17 06:35
ComboFix3.txt 2010-06-17 00:35
ComboFix4.txt 2010-05-13 05:58
Pre-Run: 61,610,381,312 bytes free
Post-Run: 61,502,435,328 bytes free
- - End Of File - - 9A494D7D65F221771B94E27BF66B7E0A