Ive used HijackThis many years ago, so i kinda understand how to use it. Yes you are right, i should probably try to recover those removed entries… It was just a not so smart attempt to speed up my computer…. What do you think i should do about it.
here are my logs… Thanks!
ComboFix 08-05-21.2 - Ray II 2008-05-22 22:02:56.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1553 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ray II\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Ray II\Local Settings\Temporary Internet Files\CPV.stt
C:\WINDOWS\mrofinu1188.exe.tmp
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\drivers\core.cache(2).dsk
C:\WINDOWS\system32\drivers\core.cache(3).dsk
C:\WINDOWS\system32\drivers\core.cache(4).dsk
C:\WINDOWS\system32\drivers\core.cache.dsk
.
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.
2008-05-21 00:00 . 2008-05-21 00:00 d——– C:\Program Files\Common Files\Adobe AIR
2008-05-21 00:00 . 2008-05-21 00:00 d——– C:\Program Files\Adobe Media Player
2008-05-20 23:50 . 2008-05-20 23:53 1,206 –a—— C:\WINDOWS\mozver.dat
2008-05-20 16:25 . 2008-05-20 21:44 d——– C:\WINDOWS\system32\CatRoot_bak
2008-05-20 11:28 . 2008-05-20 11:28 d——– C:\Deckard
2008-05-16 19:58 . 2008-05-16 19:59 2,135,438 –a—— C:\Rich Boy & Lil Wayne - Throw Some D's (JF Remix).mp3
2008-05-16 11:45 . 2008-05-16 11:49 5,403,013 –a—— C:\Jean Carne - You Are All I Need.mp3
2008-05-16 11:45 . 2008-05-16 11:47 4,956,995 –a—— C:\Mary J Blige, Method Man - You Are All I Need.mp3
2008-05-16 11:45 . 2008-05-16 11:47 3,406,913 –a—— C:\Aretha Franklin - You're all I need to get by.mp3
2008-05-15 17:32 . 2007-07-30 19:19 203,096 –a—— C:\WINDOWS\system32\wuweb.dll
2008-05-15 17:32 . 2007-07-30 19:19 203,096 –a–c— C:\WINDOWS\system32\dllcache\wuweb.dll
2008-05-13 19:56 . 2008-05-13 19:56 d——– C:\Documents and Settings\All Users\Application Data\AcrobatInstall
2008-05-11 19:41 . 2008-05-20 21:53 4,300,832 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-11 19:41 . 2008-05-20 21:53 187,936 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-11 19:41 . 2008-05-20 21:53 51,476 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-11 19:41 . 2008-05-20 21:53 18,668 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-11 00:27 . 2008-05-11 00:27 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2008-05-10 22:34 . 2008-05-10 22:52 5,738,676 –a—— C:\The Isley Brothers ft r. kelly & kelly price - Busted.mp3
2008-05-10 22:34 . 2008-05-10 22:46 5,688,214 –a—— C:\Swiss Beats ft. Ron Isley, P. Diddy, Baby, Jadakiss Snoop Dogg, Cassidy & TQ - Bigger Business.mp3
2008-05-10 22:34 . 2008-05-10 22:46 5,482,496 –a—— C:\Slow Jams - Isley Brothers - Between The Sheets.mp3
2008-05-10 22:34 . 2008-05-10 22:46 5,215,388 –a—— C:\R. Kelly, Ron Isley, Aaron Hall, Charlie Wilson.. Heaven's Girl.mp3
2008-05-10 22:34 . 2008-05-10 22:49 4,529,946 –a—— C:\Kelley Price ft. R Kelly & Ron Isley- Friend of Mine.mp3
2008-05-10 22:34 . 2008-05-10 22:50 4,431,203 –a—— C:\Tupac feat Snoop, Nate Dogg, Dru Hill - All About You.mp3
2008-05-10 22:34 . 2008-05-10 22:51 4,322,096 –a—— C:\R. Kelly-12 Play-Down Low (remix) f. Ron Isley.mp3
2008-05-10 22:34 . 2008-05-10 22:46 4,049,940 –a—— C:\R Kelly f. The Isley Brothers - Down Low.mp3
2008-05-10 22:34 . 2008-05-10 22:46 3,328,488 –a—— C:\Dru Hill - Baby I'm Sorry.mp3
2008-05-10 22:33 . 2008-05-10 22:48 6,386,294 –a—— C:\Dru Hill - I Should Be Your Boyfriend.mp3
2008-05-10 22:33 . 2008-05-10 22:39 4,827,136 –a—— C:\Slow Jams - Dru Hill - 5 Steps.mp3
2008-05-10 22:33 . 2008-05-10 22:40 4,335,688 –a—— C:\Dru Hill - Beauty is Her Name.mp3
2008-05-10 22:33 . 2008-05-10 22:48 4,294,784 –a—— C:\Dru Hill & Sisqo - Incomplete.mp3
2008-05-02 19:37 . 2008-05-02 19:37 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-02 19:25 . 2008-05-02 19:27 d——– C:\Adobe Acrobat 8 Professional
2008-05-01 23:56 . 2008-05-01 23:57 570,025,984 –a—— C:\Adobe Acrobat 8 Professional.iso
2008-05-01 21:38 . 2008-05-01 21:39 57,884 –a—— C:\trend micro anti-spyware 3.0.zip
2008-05-01 13:28 . 2008-05-06 10:59 4,170,231 –a—— C:\Hustle & Flow Soundtrack - DJay - Hard Out Here For A Pimp.mp3
2008-05-01 13:28 . 2008-05-01 13:42 2,948,756 –a—— C:\Hustle and Flow the soundtrack - DJay - It Ain't Over.MP3
2008-05-01 13:27 . 2008-05-01 13:39 5,812,869 –a—— C:\Hustle and Flow Soundtrack-Whoop That Trick.mp3
2008-04-28 21:29 . 2008-05-13 17:54 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-04-28 21:29 . 2008-04-28 21:29 1,409 –a—— C:\WINDOWS\QTFont.for
2008-04-27 17:05 . 2008-05-20 12:35 d–h—– C:\$AVG8.VAULT$
2008-04-27 17:01 . 2008-05-21 22:44 d——– C:\WINDOWS\system32\drivers\Avg
2008-04-27 17:01 . 2008-04-27 17:01 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-27 17:01 . 2008-04-27 17:01 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-04-27 17:00 . 2008-04-27 17:00 d——– C:\Program Files\AVG
2008-04-27 17:00 . 2008-04-27 17:00 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-04-26 19:23 . 2008-04-27 17:02 d——– C:\Documents and Settings\Administrator.LAP
2008-04-26 18:16 . 2008-04-26 18:16 d——– C:\WINDOWS\system32\bits
2008-04-26 18:15 . 2007-03-29 07:56 7,168 —–c— C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-04-26 18:15 . 2007-03-29 07:56 7,168 –a—— C:\WINDOWS\system32\bitsprx4.dll
2008-04-26 17:58 . 2008-04-26 17:58 d——– C:\751f87b2e1aa8f71566681e9fc0b
2008-04-26 17:52 . 2008-04-26 17:52 d——– C:\Documents and Settings\Ray II\Application Data\HouseCall 6.6
2008-04-25 20:58 . 2008-04-25 20:58 d——– C:\WINDOWS\zmir
2008-04-25 20:58 . 2008-04-26 16:49 d——– C:\Program Files\Common Files\zmir
2008-04-25 18:09 . 2008-04-25 18:09 10 –a—— C:\Program Files\.autoreg
2008-04-24 19:09 . 2008-04-26 16:50 d—s—- C:\Documents and Settings\Administrator
2008-04-24 17:45 . 2008-04-24 17:45 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2008-04-24 17:41 . 2008-04-27 17:56 d——– C:\WINDOWS\system32\pnVes18
2008-04-24 17:41 . 2008-04-27 17:56 d——– C:\WINDOWS\system32\pb1
2008-04-24 17:41 . 2008-04-27 17:52 d——– C:\WINDOWS\system32\hn3
2008-04-24 17:41 . 2008-04-24 17:41 d——– C:\Temp\zvebs14
2008-04-24 17:41 . 2008-04-24 17:41 d——– C:\Temp\kvebs14
2008-04-24 17:41 . 2008-05-20 21:49 d——– C:\Temp
2008-04-24 17:24 . 2007-03-22 10:31 152,624 –a—— C:\WINDOWS\system32\WIN2PDFS.DLL
2008-04-24 17:24 . 2007-03-22 10:31 21,552 –a—— C:\WINDOWS\system32\WIN2PDFM.DLL
2008-04-24 17:24 . 2006-03-08 18:21 2 –a—— C:\WINDOWS\1way.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-21 05:07 ——— d—–w C:\Program Files\Common Files\Adobe
2008-05-21 02:53 ——— d—–w C:\Documents and Settings\Ray II\Application Data\Def
2008-05-21 01:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-21 01:54 ——— d—–w C:\Program Files\LimeWire
2008-05-21 01:53 ——— d—–w C:\Program Files\Java
2008-05-20 18:35 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-05-17 00:56 ——— d—–w C:\Documents and Settings\Ray II\Application Data\LimeWire
2008-05-15 22:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-11 05:00 ——— d—–w C:\Program Files\Defender Pro
2008-05-11 04:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Defender Pro
2008-05-11 04:03 ——— d—–w C:\Program Files\PeerGuardian2
2008-05-04 19:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-04 01:58 ——— d—–w C:\Program Files\Symantec
2008-05-04 01:58 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-04-24 22:23 ——— d—–w C:\Program Files\Docudesk
2008-04-22 18:13 ——— d—–w C:\Program Files\DivX
2008-04-19 03:10 96,645 —-a-w C:\WINDOWS\system32\drivers\klin.dat
2008-04-19 03:10 87,941 —-a-w C:\WINDOWS\system32\drivers\klick.dat
2008-04-12 19:25 ——— d—–w C:\Documents and Settings\Ray II\Application Data\uTorrent
2008-04-11 02:38 ——— d—–w C:\Documents and Settings\Ray II\Application Data\AdobeUM
2008-04-08 17:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-04-08 17:10 ——— d—–w C:\Program Files\Activision
2008-04-08 16:57 ——— d—–w C:\Program Files\Hp
2008-04-08 02:26 ——— d—–w C:\Documents and Settings\Ray II\Application Data\Bin
.
((((((((((((((((((((((((((((( snapshot@2008-05-20_22.01.03.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-21 02:54:08 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-23 03:07:21 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-21 05:07:54 295,606 —-a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\SC_Reader.exe
- 2008-05-16 06:12:49 294,072 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-05-23 03:07:18 293,272 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Valve\\Condition Zero\\czero.exe"=
"C:\\Program Files\\Red Storm Entertainment\\Ghost Recon\\GhostRecon.exe"=
"C:\\Program Files\\Defender Pro\\Defender Pro Internet Security 6.0\\avp.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-27 17:01]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-27 17:00]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 16:06]
S1 drmkaudd;drmkaudd;C:\WINDOWS\system32\drivers\drmkaudd.sys []
S3 jbridgep;jbridgep;C:\DOCUME~1\RAYII~1\LOCALS~1\Temp\jbridgep.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9d9b79fb-0cb2-11dd-b1f1-0014a564aead}]
\Shell\AutoRun\command - nsv.bat
\Shell\explore\Command - nsv.bat
\Shell\open\Command - nsv.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ab8ea3fb-81dc-11dc-b15c-0014a564aead}]
\Shell\Auto\command - Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc6108a8-0ed8-11dc-b11d-0014a564aead}]
\Shell\AutoRun\command - E:\f2ir.com
\Shell\explore\Command - E:\f2ir.com
\Shell\open\Command - E:\f2ir.com
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-22 22:08:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\ufdsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-05-22 22:15:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-23 03:15:44
ComboFix2.txt 2008-05-21 03:01:24
Pre-Run: 11,603,664,896 bytes free
Post-Run: 11,782,406,144 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
221 — E O F — 2008-05-20 18:35:56
—————————————————————————————————————————————————————————————————————————————
ComboFix 08-05-21.2 - Ray II 2008-05-22 22:48:58.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1586 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ray II\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\mrofinu1188.exe.tmp
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\vbzip10.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Ray II\Application Data\LimeWire
C:\Program Files\LimeWire
C:\Program Files\LimeWire\GenericWindowsUtils.dll
C:\Program Files\LimeWire\Incomplete\downloads.bak
C:\Program Files\LimeWire\Incomplete\downloads.dat
C:\Program Files\LimeWire\Incomplete\T-5528938-Isley Brothers - Between The Sheets.mp3
C:\Program Files\LimeWire\Incomplete\T-5764332-Rich Boy-Throw Some Ds.mp3
C:\Program Files\LimeWire\Incomplete\T-8455850-Rich Boy ft. Lil Jon, Andre 3000, Jim Jones, Too Short, Nelly, Murphy Lee, & Game- Throw Some D's On It (Remix).mp3
C:\Program Files\LimeWire\LimeWire20.dll
C:\Program Files\LimeWire\log4j.properties
C:\Program Files\LimeWire\MessagesBundle.properties
C:\Program Files\LimeWire\update.ver
C:\Program Files\LimeWire\WindowsFirewall.dll
C:\Program Files\LimeWire\WindowsV5PlusUtils.dll
C:\Temp\kvebs14
C:\Temp\kvebs14\zvKarru.log
C:\Temp\zvebs14
C:\WINDOWS\GPX5DLT19GOW4BJR
C:\WINDOWS\system32\vbzip10.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_DRMKAUDD
——-\Legacy_JBRIDGEP
——-\Service_drmkaudd
——-\Service_jbridgep
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.
2008-05-21 00:00 . 2008-05-21 00:00 d——– C:\Program Files\Common Files\Adobe AIR
2008-05-21 00:00 . 2008-05-21 00:00 d——– C:\Program Files\Adobe Media Player
2008-05-20 23:50 . 2008-05-20 23:53 1,206 –a—— C:\WINDOWS\mozver.dat
2008-05-20 16:25 . 2008-05-20 21:44 d——– C:\WINDOWS\system32\CatRoot_bak
2008-05-20 11:28 . 2008-05-20 11:28 d——– C:\Deckard
2008-05-16 19:58 . 2008-05-16 19:59 2,135,438 –a—— C:\Rich Boy & Lil Wayne - Throw Some D's (JF Remix).mp3
2008-05-16 11:45 . 2008-05-16 11:49 5,403,013 –a—— C:\Jean Carne - You Are All I Need.mp3
2008-05-16 11:45 . 2008-05-16 11:47 4,956,995 –a—— C:\Mary J Blige, Method Man - You Are All I Need.mp3
2008-05-16 11:45 . 2008-05-16 11:47 3,406,913 –a—— C:\Aretha Franklin - You're all I need to get by.mp3
2008-05-15 17:32 . 2007-07-30 19:19 203,096 –a—— C:\WINDOWS\system32\wuweb.dll
2008-05-15 17:32 . 2007-07-30 19:19 203,096 –a–c— C:\WINDOWS\system32\dllcache\wuweb.dll
2008-05-13 19:56 . 2008-05-13 19:56 d——– C:\Documents and Settings\All Users\Application Data\AcrobatInstall
2008-05-11 19:41 . 2008-05-20 21:53 4,300,832 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-11 19:41 . 2008-05-20 21:53 187,936 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-11 19:41 . 2008-05-20 21:53 51,476 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-11 19:41 . 2008-05-20 21:53 18,668 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-11 00:27 . 2008-05-11 00:27 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2008-05-10 22:34 . 2008-05-10 22:52 5,738,676 –a—— C:\The Isley Brothers ft r. kelly & kelly price - Busted.mp3
2008-05-10 22:34 . 2008-05-10 22:46 5,688,214 –a—— C:\Swiss Beats ft. Ron Isley, P. Diddy, Baby, Jadakiss Snoop Dogg, Cassidy & TQ - Bigger Business.mp3
2008-05-10 22:34 . 2008-05-10 22:46 5,482,496 –a—— C:\Slow Jams - Isley Brothers - Between The Sheets.mp3
2008-05-10 22:34 . 2008-05-10 22:46 5,215,388 –a—— C:\R. Kelly, Ron Isley, Aaron Hall, Charlie Wilson.. Heaven's Girl.mp3
2008-05-10 22:34 . 2008-05-10 22:49 4,529,946 –a—— C:\Kelley Price ft. R Kelly & Ron Isley- Friend of Mine.mp3
2008-05-10 22:34 . 2008-05-10 22:50 4,431,203 –a—— C:\Tupac feat Snoop, Nate Dogg, Dru Hill - All About You.mp3
2008-05-10 22:34 . 2008-05-10 22:51 4,322,096 –a—— C:\R. Kelly-12 Play-Down Low (remix) f. Ron Isley.mp3
2008-05-10 22:34 . 2008-05-10 22:46 4,049,940 –a—— C:\R Kelly f. The Isley Brothers - Down Low.mp3
2008-05-10 22:34 . 2008-05-10 22:46 3,328,488 –a—— C:\Dru Hill - Baby I'm Sorry.mp3
2008-05-10 22:33 . 2008-05-10 22:48 6,386,294 –a—— C:\Dru Hill - I Should Be Your Boyfriend.mp3
2008-05-10 22:33 . 2008-05-10 22:39 4,827,136 –a—— C:\Slow Jams - Dru Hill - 5 Steps.mp3
2008-05-10 22:33 . 2008-05-10 22:40 4,335,688 –a—— C:\Dru Hill - Beauty is Her Name.mp3
2008-05-10 22:33 . 2008-05-10 22:48 4,294,784 –a—— C:\Dru Hill & Sisqo - Incomplete.mp3
2008-05-02 19:37 . 2008-05-02 19:37 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-02 19:25 . 2008-05-02 19:27 d——– C:\Adobe Acrobat 8 Professional
2008-05-01 23:56 . 2008-05-01 23:57 570,025,984 –a—— C:\Adobe Acrobat 8 Professional.iso
2008-05-01 21:38 . 2008-05-01 21:39 57,884 –a—— C:\trend micro anti-spyware 3.0.zip
2008-05-01 13:28 . 2008-05-06 10:59 4,170,231 –a—— C:\Hustle & Flow Soundtrack - DJay - Hard Out Here For A Pimp.mp3
2008-05-01 13:28 . 2008-05-01 13:42 2,948,756 –a—— C:\Hustle and Flow the soundtrack - DJay - It Ain't Over.MP3
2008-05-01 13:27 . 2008-05-01 13:39 5,812,869 –a—— C:\Hustle and Flow Soundtrack-Whoop That Trick.mp3
2008-04-28 21:29 . 2008-05-13 17:54 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-04-28 21:29 . 2008-04-28 21:29 1,409 –a—— C:\WINDOWS\QTFont.for
2008-04-27 17:05 . 2008-05-20 12:35 d–h—– C:\$AVG8.VAULT$
2008-04-27 17:01 . 2008-05-22 22:16 d——– C:\WINDOWS\system32\drivers\Avg
2008-04-27 17:01 . 2008-04-27 17:01 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-27 17:01 . 2008-04-27 17:01 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-04-27 17:00 . 2008-04-27 17:00 d——– C:\Program Files\AVG
2008-04-27 17:00 . 2008-04-27 17:00 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-04-26 19:23 . 2008-04-27 17:02 d——– C:\Documents and Settings\Administrator.LAP
2008-04-26 18:16 . 2008-04-26 18:16 d——– C:\WINDOWS\system32\bits
2008-04-26 18:15 . 2007-03-29 07:56 7,168 —–c— C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-04-26 18:15 . 2007-03-29 07:56 7,168 –a—— C:\WINDOWS\system32\bitsprx4.dll
2008-04-26 17:58 . 2008-04-26 17:58 d——– C:\751f87b2e1aa8f71566681e9fc0b
2008-04-26 17:52 . 2008-04-26 17:52 d——– C:\Documents and Settings\Ray II\Application Data\HouseCall 6.6
2008-04-25 20:58 . 2008-04-25 20:58 d——– C:\WINDOWS\zmir
2008-04-25 20:58 . 2008-04-26 16:49 d——– C:\Program Files\Common Files\zmir
2008-04-25 18:09 . 2008-04-25 18:09 10 –a—— C:\Program Files\.autoreg
2008-04-24 19:09 . 2008-04-26 16:50 d—s—- C:\Documents and Settings\Administrator
2008-04-24 17:41 . 2008-04-27 17:56 d——– C:\WINDOWS\system32\pnVes18
2008-04-24 17:41 . 2008-04-27 17:56 d——– C:\WINDOWS\system32\pb1
2008-04-24 17:41 . 2008-04-27 17:52 d——– C:\WINDOWS\system32\hn3
2008-04-24 17:41 . 2008-05-22 22:49 d——– C:\Temp
2008-04-24 17:24 . 2007-03-22 10:31 152,624 –a—— C:\WINDOWS\system32\WIN2PDFS.DLL
2008-04-24 17:24 . 2007-03-22 10:31 21,552 –a—— C:\WINDOWS\system32\WIN2PDFM.DLL
2008-04-24 17:24 . 2006-03-08 18:21 2 –a—— C:\WINDOWS\1way.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-21 05:07 ——— d—–w C:\Program Files\Common Files\Adobe
2008-05-21 02:53 ——— d—–w C:\Documents and Settings\Ray II\Application Data\Def
2008-05-21 01:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-21 01:53 ——— d—–w C:\Program Files\Java
2008-05-20 18:35 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-05-15 22:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-11 05:00 ——— d—–w C:\Program Files\Defender Pro
2008-05-11 04:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Defender Pro
2008-05-11 04:03 ——— d—–w C:\Program Files\PeerGuardian2
2008-05-04 19:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-04 01:58 ——— d—–w C:\Program Files\Symantec
2008-05-04 01:58 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-04-24 22:23 ——— d—–w C:\Program Files\Docudesk
2008-04-22 18:13 ——— d—–w C:\Program Files\DivX
2008-04-19 03:10 96,645 —-a-w C:\WINDOWS\system32\drivers\klin.dat
2008-04-19 03:10 87,941 —-a-w C:\WINDOWS\system32\drivers\klick.dat
2008-04-12 19:25 ——— d—–w C:\Documents and Settings\Ray II\Application Data\uTorrent
2008-04-11 02:38 ——— d—–w C:\Documents and Settings\Ray II\Application Data\AdobeUM
2008-04-08 17:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-04-08 17:10 ——— d—–w C:\Program Files\Activision
2008-04-08 16:57 ——— d—–w C:\Program Files\Hp
2008-04-08 02:26 ——— d—–w C:\Documents and Settings\Ray II\Application Data\Bin
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\751f87b2e1aa8f71566681e9fc0b —-
2008-01-22 20:23 95744 –a—— C:\751f87b2e1aa8f71566681e9fc0b\atl80.dll
2008-01-22 20:23 69160 –a—— C:\751f87b2e1aa8f71566681e9fc0b\ochelpagent.dll
2008-01-22 20:23 626688 –a—— C:\751f87b2e1aa8f71566681e9fc0b\msvcr80.dll
2008-01-22 20:23 597146 –a—— C:\751f87b2e1aa8f71566681e9fc0b\ja-jp\eula.rtf
2008-01-22 20:23 58408 –a—— C:\751f87b2e1aa8f71566681e9fc0b\conflictingappmodule.dll
2008-01-22 20:23 56872 –a—— C:\751f87b2e1aa8f71566681e9fc0b\cert.dll
2008-01-22 20:23 554024 –a—— C:\751f87b2e1aa8f71566681e9fc0b\winssplatform.dll
2008-01-22 20:23 548864 –a—— C:\751f87b2e1aa8f71566681e9fc0b\msvcp80.dll
2008-01-22 20:23 54600 –a—— C:\751f87b2e1aa8f71566681e9fc0b\es-us\eula.rtf
2008-01-22 20:23 522 –a—— C:\751f87b2e1aa8f71566681e9fc0b\microsoft.vc80.crt.manifest
2008-01-22 20:23 4709 –a—— C:\751f87b2e1aa8f71566681e9fc0b\service.xml
2008-01-22 20:23 456 –a—— C:\751f87b2e1aa8f71566681e9fc0b\microsoft.vc80.atl.manifest
2008-01-22 20:23 339496 –a—— C:\751f87b2e1aa8f71566681e9fc0b\ocsetup.exe
2008-01-22 20:23 210984 –a—— C:\751f87b2e1aa8f71566681e9fc0b\winsscommon.dll
2008-01-22 20:23 162503 –a—— C:\751f87b2e1aa8f71566681e9fc0b\de-at\eula.rtf
2008-01-22 20:23 162165 –a—— C:\751f87b2e1aa8f71566681e9fc0b\de-de\eula.rtf
2008-01-22 20:23 161780 –a—— C:\751f87b2e1aa8f71566681e9fc0b\de-ch\eula.rtf
2008-01-22 20:23 159878 –a—— C:\751f87b2e1aa8f71566681e9fc0b\fr-fr\eula.rtf
2008-01-22 20:23 159258 –a—— C:\751f87b2e1aa8f71566681e9fc0b\fr-be\eula.rtf
2008-01-22 20:23 158870 –a—— C:\751f87b2e1aa8f71566681e9fc0b\fr-ca\eula.rtf
2008-01-22 20:23 158236 –a—— C:\751f87b2e1aa8f71566681e9fc0b\fr-ch\eula.rtf
2008-01-22 20:23 157952 –a—— C:\751f87b2e1aa8f71566681e9fc0b\es-es\eula.rtf
2008-01-22 20:23 157853 –a—— C:\751f87b2e1aa8f71566681e9fc0b\es-mx\eula.rtf
2008-01-22 20:23 157215 –a—— C:\751f87b2e1aa8f71566681e9fc0b\ko-kr\eula.rtf
2008-01-22 20:23 157215 –a—— C:\751f87b2e1aa8f71566681e9fc0b\ja-jp-psloc\eula.rtf
2008-01-22 20:23 155309 –a—— C:\751f87b2e1aa8f71566681e9fc0b\it-it\eula.rtf
2008-01-22 20:23 154394 –a—— C:\751f87b2e1aa8f71566681e9fc0b\nl-be\eula.rtf
2008-01-22 20:23 153735 –a—— C:\751f87b2e1aa8f71566681e9fc0b\nl-nl\eula.rtf
2008-01-22 20:23 148575 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-au\eula.rtf
2008-01-22 20:23 147589 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-ca\eula.rtf
2008-01-22 20:23 146554 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-sg\eula.rtf
2008-01-22 20:23 145964 –a—— C:\751f87b2e1aa8f71566681e9fc0b\eula.rtf
2008-01-22 20:23 145184 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-nz\eula.rtf
2008-01-22 20:23 145133 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-ie\eula.rtf
2008-01-22 20:23 145035 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-gb\eula.rtf
2008-01-22 20:23 132648 –a—— C:\751f87b2e1aa8f71566681e9fc0b\de-de\ocsetupro.dll
2008-01-22 20:23 132648 –a—— C:\751f87b2e1aa8f71566681e9fc0b\de-ch\ocsetupro.dll
2008-01-22 20:23 132648 –a—— C:\751f87b2e1aa8f71566681e9fc0b\de-at\ocsetupro.dll
2008-01-22 20:23 129576 –a—— C:\751f87b2e1aa8f71566681e9fc0b\nl-nl\ocsetupro.dll
2008-01-22 20:23 129576 –a—— C:\751f87b2e1aa8f71566681e9fc0b\nl-be\ocsetupro.dll
2008-01-22 20:23 127016 –a—— C:\751f87b2e1aa8f71566681e9fc0b\es-us\ocsetupro.dll
2008-01-22 20:23 127016 –a—— C:\751f87b2e1aa8f71566681e9fc0b\es-mx\ocsetupro.dll
2008-01-22 20:23 127016 –a—— C:\751f87b2e1aa8f71566681e9fc0b\es-es\ocsetupro.dll
2008-01-22 20:23 122920 –a—— C:\751f87b2e1aa8f71566681e9fc0b\ocsetupro.dll
2008-01-22 20:23 122920 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-sg\ocsetupro.dll
2008-01-22 20:23 122920 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-nz\ocsetupro.dll
2008-01-22 20:23 122920 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-ie\ocsetupro.dll
2008-01-22 20:23 122920 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-gb\ocsetupro.dll
2008-01-22 20:23 122920 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-ca\ocsetupro.dll
2008-01-22 20:23 122920 –a—— C:\751f87b2e1aa8f71566681e9fc0b\en-au\ocsetupro.dll
2008-01-22 20:23 121896 –a—— C:\751f87b2e1aa8f71566681e9fc0b\fr-fr\ocsetupro.dll
2008-01-22 20:23 121896 –a—— C:\751f87b2e1aa8f71566681e9fc0b\fr-ch\ocsetupro.dll
2008-01-22 20:23 121896 –a—— C:\751f87b2e1aa8f71566681e9fc0b\fr-ca\ocsetupro.dll
2008-01-22 20:23 121896 –a—— C:\751f87b2e1aa8f71566681e9fc0b\fr-be\ocsetupro.dll
2008-01-22 20:23 120360 –a—— C:\751f87b2e1aa8f71566681e9fc0b\it-it\ocsetupro.dll
2008-01-22 20:23 114728 –a—— C:\751f87b2e1aa8f71566681e9fc0b\ko-kr\ocsetupro.dll
2008-01-22 20:23 105000 –a—— C:\751f87b2e1aa8f71566681e9fc0b\ja-jp-psloc\ocsetupro.dll
2008-01-22 20:23 103976 –a—— C:\751f87b2e1aa8f71566681e9fc0b\ja-jp\ocsetupro.dll
—- Directory of C:\Program Files\Common Files\zmir —-
2004-04-19 21:26 4933375 –a—— C:\Program Files\Common Files\zmir\zmird\class-barrel
2004-04-19 21:26 1234193 –a—— C:\Program Files\Common Files\zmir\zmird\vocabulary
—- Directory of C:\WINDOWS\system32\hn3 —-
—- Directory of C:\WINDOWS\system32\pb1 —-
—- Directory of C:\WINDOWS\system32\pnVes18 —-
—- Directory of C:\WINDOWS\zmir —-
2008-04-25 21:02 4427 –a—— C:\WINDOWS\zmir\zmir.dat
2002-07-26 17:02 153088 –a—— C:\WINDOWS\zmir\wu
((((((((((((((((((((((((((((( snapshot@2008-05-20_22.01.03.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-21 02:54:08 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-23 03:52:14 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-21 05:07:54 295,606 —-a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\SC_Reader.exe
- 2008-05-16 06:12:49 294,072 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-05-23 03:07:18 293,272 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Valve\\Condition Zero\\czero.exe"=
"C:\\Program Files\\Red Storm Entertainment\\Ghost Recon\\GhostRecon.exe"=
"C:\\Program Files\\Defender Pro\\Defender Pro Internet Security 6.0\\avp.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-27 17:01]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-27 17:00]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 16:06]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9d9b79fb-0cb2-11dd-b1f1-0014a564aead}]
\Shell\AutoRun\command - nsv.bat
\Shell\explore\Command - nsv.bat
\Shell\open\Command - nsv.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ab8ea3fb-81dc-11dc-b15c-0014a564aead}]
\Shell\Auto\command - Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc6108a8-0ed8-11dc-b11d-0014a564aead}]
\Shell\AutoRun\command - E:\f2ir.com
\Shell\explore\Command - E:\f2ir.com
\Shell\open\Command - E:\f2ir.com
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-22 22:52:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\ufdsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-05-22 22:58:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-23 03:58:45
ComboFix2.txt 2008-05-23 03:15:59
ComboFix3.txt 2008-05-21 03:01:24
Pre-Run: 11,773,710,336 bytes free
Post-Run: 11,761,995,776 bytes free
300 — E O F — 2008-05-20 18:35:56
—————————————————————————————————————————————————————————————————————————————-
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, May 23, 2008 10:05:32 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 23/05/2008
Kaspersky Anti-Virus database records: 797188
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 97017
Number of viruses found: 16
Number of infected objects: 43
Number of suspicious objects: 0
Duration of the scan process: 02:22:16
Infected Object Name / Virus Name / Last Action
C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru10.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru11.tmp Infected: Trojan-PSW.Win32.OnLineGames.acdy skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru12.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru13.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru14.tmp Infected: Worm.Win32.AutoRun.dkf skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru15.tmp Infected: Worm.Win32.AutoRun.dkf skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru16.tmp Infected: Worm.Win32.AutoRun.dlc skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru17.tmp Infected: Worm.Win32.AutoRun.dkw skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru18.tmp Infected: Worm.Win32.AutoRun.dkw skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru19.tmp Infected: Worm.Win32.AutoRun.dkw skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru1A.tmp Infected: Worm.Win32.AutoRun.dkw skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru1B.tmp Infected: Worm.Win32.AutoRun.dlc skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru1C.tmp Infected: Worm.Win32.AutoRun.dlc skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru1D.tmp Infected: Worm.Win32.AutoRun.dle skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru1E.tmp Infected: Worm.Win32.AutoRun.dle skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru1F.tmp Infected: Worm.Win32.AutoRun.dlz skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru20.tmp Infected: Worm.Win32.AutoRun.dlz skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru21.tmp Infected: Worm.Win32.AutoRun.dlz skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru22.tmp Infected: Worm.Win32.AutoRun.dlz skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru23.tmp Infected: Worm.Win32.AutoRun.dlz skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru24.tmp Infected: Worm.Win32.AutoRun.dlz skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru25.tmp Infected: Worm.Win32.AutoRun.dlz skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru26.tmp Infected: Worm.Win32.AutoRun.dmt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru27.tmp Infected: Worm.Win32.AutoRun.dmt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru28.tmp Infected: Worm.Win32.AutoRun.dmt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru29.tmp Infected: Worm.Win32.AutoRun.dmt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru2A.tmp Infected: Worm.Win32.AutoRun.dmt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru2B.tmp Infected: Worm.Win32.AutoRun.dmt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru48.tmp Infected: Worm.Win32.AutoRun.dlz skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru49.tmp Infected: Worm.Win32.AutoRun.dlz skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tru9.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\truA.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\truB.tmp Infected: Trojan-PSW.Win32.OnLineGames.xnw skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\truC.tmp Infected: Trojan-PSW.Win32.OnLineGames.xpu skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\truD.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\truE.tmp Infected: Trojan-PSW.Win32.OnLineGames.xtt skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tsupdate_4_0_4_1_b3.exe/WISE0009.BIN Infected: Trojan-Downloader.Win32.TSUpdate.n skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tsupdate_4_0_4_1_b3.exe/WISE0010.BIN Infected: Trojan-Downloader.Win32.TSUpdate.r skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tsupdate_4_0_4_1_b3.exe/WISE0011.BIN Infected: Trojan-Downloader.Win32.TSUpdate.l skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tsupdate_4_0_4_1_b3.exe/WISE0012.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f skipped
C:\Deckard\System Scanner\20080520162653\backup\DOCUME~1\RAYII~1\LOCALS~1\Temp\tsupdate_4_0_4_1_b3.exe WiseSFX: infected - 4 skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Ray II\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\cert8.db Object is locked skipped
C:\Documents and Settings\Ray II\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\history.dat Object is locked skipped
C:\Documents and Settings\Ray II\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\key3.db Object is locked skipped
C:\Documents and Settings\Ray II\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\parent.lock Object is locked skipped
C:\Documents and Settings\Ray II\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Ray II\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Ray II\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\Application Data\Mozilla\Firefox\Profiles\vkg2j1db.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\History\History.IE5\MSHist012008052220080523\index.dat Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\Temp\~ROMFN_000005BC Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Ray II\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ray II\ntuser.dat Object is locked skipped
C:\Documents and Settings\Ray II\ntuser.dat.LOG Object is locked skipped
C:\Eighties classic.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped
C:\QooBox\Quarantine\C\WINDOWS\mrofinu1188.exe.tmp.vir Infected: Trojan-Downloader.Win32.Homles.bj skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6A21C20C-F591-4FB3-9848-3C0A30AAE1C9}\RP15\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_AC97 Soft Data Fax Modem with SmartCP.txt Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{663E42DE-3A1E-4E47-9B30-808F6257B2BD}.crmlog Object is locked skipped
C:\WINDOWS\S2AC0027E.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{FB0F43AA-82CB-437E-BAE0-54D0FA7ACE0B}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.