Spyware / Malware / Virus Removal
[Resolved] HELP nasty infection
13 min read
ganjadank
Topic Starter
I am on another computer right now.
HELP, this infection is really bad and i'm out of ideas. The virus won't allow me to run any anti virus programs(ie. avg, spybot, hijackthis). When i double-click the programs, nothing happens. I haven't tried malwarebytes because it is so hard to access the sites that I want; I keep getting redirected and errors. It also auto downloads antispyware2009xp. I also tried booting in safe mode for system restore, but apparently my restore points were deleted. Lastly, my computer runs super slow so it's even more frustrating.
I'm sorry I can't post a HJT log because of stated reasons. Any ideas? Please help thanks!
ganjadank
Luckily, I somehow found a way to run Malwarebytes and got rid of the program blocking.
Here's my HJT log. Please have a look, thanks!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:55 AM, on 10/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\internet explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {299B5FAC-2168-4A5D-A67D-AA4C8F8055DA} - (no file)
O2 - BHO: (no name) - {53CDB936-7A8D-4B44-9B7B-70525D0C9D50} - (no file)
O2 - BHO: (no name) - {6839DB84-A6EC-4E8B-9320-2C6E98A3C27C} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {A32BF1D3-1110-4507-8F5E-235E0586F08C} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Facegame] "C:\Documents and Settings\NetworkService\Application Data\Facegame\Facegame.exe" 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: OKI LPR Utility.lnk = C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://primis.ebrary.com/support/plugins/ebraryRdr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158097811062
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7D4733C0-C43B-4A81-AF43-F9B20D1F8348} - http://www.octoshape.com/test/ax/octoshape.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: fccyyYpp - C:\WINDOWS\
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DCS Loader (DCSLoader) - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
–
End of file - 7736 bytes
Here's my HJT log. Please have a look, thanks!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:55 AM, on 10/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\internet explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {299B5FAC-2168-4A5D-A67D-AA4C8F8055DA} - (no file)
O2 - BHO: (no name) - {53CDB936-7A8D-4B44-9B7B-70525D0C9D50} - (no file)
O2 - BHO: (no name) - {6839DB84-A6EC-4E8B-9320-2C6E98A3C27C} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {A32BF1D3-1110-4507-8F5E-235E0586F08C} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Facegame] "C:\Documents and Settings\NetworkService\Application Data\Facegame\Facegame.exe" 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: OKI LPR Utility.lnk = C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://primis.ebrary.com/support/plugins/ebraryRdr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158097811062
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7D4733C0-C43B-4A81-AF43-F9B20D1F8348} - http://www.octoshape.com/test/ax/octoshape.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=23100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: karna.dat
O20 - Winlogon Notify: fccyyYpp - C:\WINDOWS\
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DCS Loader (DCSLoader) - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
–
End of file - 7736 bytes
Rorschach112
Hello
Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.
Download SDFix and save it to your Desktop.
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
Disable resident protections (Antivirus…); you'll re-enable them after the scan
Download Lop S&D < here
Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.
Download SDFix and save it to your Desktop.
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, the Advanced Options Menu should appear;
- Select the first option, to run Windows in Safe Mode, then press Enter.
- Choose your usual account.
- Open the extracted SDFix folder and double click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum). - Finally paste the contents of the Report.txt back on the forum.
Disable resident protections (Antivirus…); you'll re-enable them after the scan
Download Lop S&D < here
Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
ganjadank
I couldn't finish the SDFix repair after the reboot. It kept saying "Could not find c:\SDFix\TESTspreadbot5.txt" so I stopped there. Should I go to the next step and run LOP S&D anyway? Thanks!
Rorschach112
yep go ahead with it
ganjadank
Lop S&D report:
——————–\\ Lop S&D 4.2.4-8 XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 2.66GHz )
BIOS : Phoenix - Award BIOS v6.00PG
USER : Owner ( Administrator )
BOOT : Normal boot
Antivirus : AVG 7.5.549 7.5.549 (Activated)
C:\ (Local Disk) - NTFS - Total:189 Go (Free:109 Go)
D:\ (CD or DVD)
E:\ (Local Disk) - FAT32 - Total:232 Go (Free:144 Go)
"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [1] ( Thu 10/30/2008|16:07 )
——————–\\ Listing folders in APPLIC~1
[09/19/2008|04:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[09/19/2008|07:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ALM
[01/26/2007|07:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[08/19/2008|10:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ATI
[10/17/2008|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ avg7
[10/14/2008|11:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Blizzard
[09/19/2008|04:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ espionServerData
[09/19/2008|04:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FLEXnet
[06/02/2008|11:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[12/03/2007|03:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Grisoft
[11/03/2006|07:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[04/14/2008|01:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[08/18/2008|11:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Kaspersky Lab
[06/15/2008|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[06/15/2008|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[06/06/2007|10:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[10/15/2008|03:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft Help
[02/09/2007|11:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NVIDIA
[10/02/2008|01:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[10/22/2006|01:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[06/23/2007|12:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[09/12/2006|03:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[07/28/2005|10:38] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[12/03/2007|03:38] C:\DOCUME~1\LOCALS~1\APPLIC~1\ AVG7
[05/04/2008|02:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Macromedia
[12/03/2007|03:38] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[12/03/2007|03:38] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft
[09/19/2008|08:22] C:\DOCUME~1\Owner\APPLIC~1\ Adobe
[08/17/2008|04:13] C:\DOCUME~1\Owner\APPLIC~1\ AdobeUM
[10/25/2006|01:50] C:\DOCUME~1\Owner\APPLIC~1\ Ahead
[10/23/2006|02:33] C:\DOCUME~1\Owner\APPLIC~1\ Aim
[12/27/2006|08:05] C:\DOCUME~1\Owner\APPLIC~1\ Apple Computer
[08/19/2008|10:51] C:\DOCUME~1\Owner\APPLIC~1\ ATI
[07/04/2008|10:05] C:\DOCUME~1\Owner\APPLIC~1\ AVG7
[10/28/2008|03:58] C:\DOCUME~1\Owner\APPLIC~1\ Azureus
[09/19/2008|03:53] C:\DOCUME~1\Owner\APPLIC~1\ DAEMON Tools
[06/02/2008|09:36] C:\DOCUME~1\Owner\APPLIC~1\ Google
[11/03/2007|06:13] C:\DOCUME~1\Owner\APPLIC~1\ Help
[07/28/2005|10:38] C:\DOCUME~1\Owner\APPLIC~1\ Identities
[07/05/2008|05:02] C:\DOCUME~1\Owner\APPLIC~1\ InstallShield
[04/14/2008|01:16] C:\DOCUME~1\Owner\APPLIC~1\ Intuit
[10/30/2006|07:49] C:\DOCUME~1\Owner\APPLIC~1\ Leadertech
[06/07/2008|02:17] C:\DOCUME~1\Owner\APPLIC~1\ Macromedia
[06/15/2008|12:42] C:\DOCUME~1\Owner\APPLIC~1\ Malwarebytes
[09/12/2006|04:25] C:\DOCUME~1\Owner\APPLIC~1\ Media Player Classic
[06/17/2008|06:54] C:\DOCUME~1\Owner\APPLIC~1\ Microsoft
[10/28/2008|09:44] C:\DOCUME~1\Owner\APPLIC~1\ Move Networks
[06/14/2008|12:27] C:\DOCUME~1\Owner\APPLIC~1\ Mozilla
[10/30/2006|07:51] C:\DOCUME~1\Owner\APPLIC~1\ Sonic
[10/03/2006|08:10] C:\DOCUME~1\Owner\APPLIC~1\ Sun
[08/08/2007|06:45] C:\DOCUME~1\Owner\APPLIC~1\ teamspeak2
[07/12/2007|04:57] C:\DOCUME~1\Owner\APPLIC~1\ Ventrilo
[01/11/2007|12:24] C:\DOCUME~1\Owner\APPLIC~1\ Viewpoint
[10/30/2008|12:18] C:\DOCUME~1\Owner\APPLIC~1\ WinRAR
——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[10/30/2008 02:49 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 12:00 PM][-r-h—–] C:\WINDOWS\tasks\desktop.ini
——————–\\ Listing Folders in C:\Program Files
[09/19/2008|07:00] C:\Program Files\ Adobe
[10/23/2006|02:33] C:\Program Files\ AIM
[10/23/2006|02:33] C:\Program Files\ AOD
[08/19/2008|10:47] C:\Program Files\ ATI Technologies
[07/10/2008|04:02] C:\Program Files\ Azureus
[09/19/2008|06:36] C:\Program Files\ Bonjour
[09/02/2008|12:23] C:\Program Files\ CCleaner
[09/03/2008|12:34] C:\Program Files\ Combined Community Codec Pack
[10/29/2008|08:15] C:\Program Files\ Common Files
[07/28/2005|10:38] C:\Program Files\ ComPlus Applications
[10/29/2008|09:56] C:\Program Files\ ERUNT
[11/03/2006|07:15] C:\Program Files\ GALA-NET
[10/14/2006|11:47] C:\Program Files\ GamaSoft
[06/03/2008|10:27] C:\Program Files\ Google
[12/03/2007|03:38] C:\Program Files\ Grisoft
[09/03/2008|12:31] C:\Program Files\ Hijackthis
[08/19/2008|10:47] C:\Program Files\ InstallShield Installation Information
[08/19/2008|10:27] C:\Program Files\ Internet Explorer
[07/05/2008|05:04] C:\Program Files\ ItsDeductible2006
[07/17/2008|07:40] C:\Program Files\ Java
[09/12/2006|04:50] C:\Program Files\ KSIGN
[10/20/2008|10:03] C:\Program Files\ LimeWire
[10/29/2008|09:57] C:\Program Files\ Malwarebytes' Anti-Malware
[08/19/2008|10:04] C:\Program Files\ Messenger
[07/28/2005|10:38] C:\Program Files\ microsoft frontpage
[06/06/2007|10:49] C:\Program Files\ Microsoft Office
[04/09/2007|06:02] C:\Program Files\ Microsoft Visual Studio
[06/06/2007|10:50] C:\Program Files\ Microsoft Visual Studio 8
[04/09/2007|06:02] C:\Program Files\ Microsoft Works
[04/09/2007|06:01] C:\Program Files\ Microsoft.NET
[04/01/2008|05:24] C:\Program Files\ mIRC
[08/19/2008|10:01] C:\Program Files\ Movie Maker
[06/06/2007|10:54] C:\Program Files\ MSBuild
[07/28/2005|10:38] C:\Program Files\ MSN
[07/28/2005|10:38] C:\Program Files\ MSN Gaming Zone
[10/25/2006|01:46] C:\Program Files\ Nero
[08/19/2008|09:59] C:\Program Files\ NetMeeting
[10/17/2008|02:41] C:\Program Files\ New Folder
[09/12/2006|04:09] C:\Program Files\ Ntreev
[06/17/2008|06:39] C:\Program Files\ Octoshape Streaming Services
[11/21/2006|11:04] C:\Program Files\ Okidata
[09/12/2006|02:04] C:\Program Files\ Online Services
[08/19/2008|09:59] C:\Program Files\ Outlook Express
[05/28/2007|10:32] C:\Program Files\ Paltalk Messenger
[09/19/2008|04:01] C:\Program Files\ PowerISO
[01/26/2007|07:03] C:\Program Files\ QuickTime
[09/12/2006|03:54] C:\Program Files\ Realtek AC97
[08/20/2008|04:35] C:\Program Files\ RegScrubXP
[10/30/2006|07:47] C:\Program Files\ Sonic
[06/15/2008|12:02] C:\Program Files\ Spybot - Search & Destroy
[10/29/2008|09:19] C:\Program Files\ Trend Micro
[07/05/2008|05:02] C:\Program Files\ TurboTax
[07/28/2005|10:38] C:\Program Files\ Uninstall Information
[11/16/2007|08:55] C:\Program Files\ Ventrilo
[01/21/2007|02:26] C:\Program Files\ Western Digital Technologies
[10/22/2006|12:18] C:\Program Files\ Winamp
[09/19/2008|04:11] C:\Program Files\ Windows Media Player
[08/19/2008|09:59] C:\Program Files\ Windows NT
[07/28/2005|10:38] C:\Program Files\ WindowsUpdate
[09/12/2006|04:01] C:\Program Files\ WinRAR
[10/21/2008|11:00] C:\Program Files\ World of Warcraft
[07/28/2005|10:38] C:\Program Files\ xerox
——————–\\ Listing Folders in C:\Program Files\Common Files
[09/19/2008|06:35] C:\Program Files\Common Files\ Adobe
[10/25/2006|07:54] C:\Program Files\Common Files\ Ahead
[04/14/2008|01:14] C:\Program Files\Common Files\ AnswerWorks 4.0
[08/18/2008|12:02] C:\Program Files\Common Files\ Blizzard Entertainment
[08/18/2008|03:00] C:\Program Files\Common Files\ DESIGNER
[06/15/2008|12:41] C:\Program Files\Common Files\ Download Manager
[11/03/2006|07:15] C:\Program Files\Common Files\ InstallShield
[04/14/2008|01:13] C:\Program Files\Common Files\ Intuit
[07/17/2008|07:40] C:\Program Files\Common Files\ Java
[09/19/2008|04:16] C:\Program Files\Common Files\ Macrovision Shared
[08/19/2008|01:20] C:\Program Files\Common Files\ Microsoft Shared
[07/28/2005|10:38] C:\Program Files\Common Files\ MSSoap
[07/28/2005|10:38] C:\Program Files\Common Files\ ODBC
[09/12/2006|02:17] C:\Program Files\Common Files\ Services
[07/28/2005|10:38] C:\Program Files\Common Files\ SpeechEngines
[08/19/2008|09:58] C:\Program Files\Common Files\ System
[04/09/2007|09:54] C:\Program Files\Common Files\ Viewpoint
[06/15/2008|12:40] C:\Program Files\Common Files\ Wise Installation Wizard
——————–\\ Process
( 34 Processes )
… OK !
——————–\\ Searching with S_Lop
No Lop folder found !
——————–\\ Searching for Lop Files - Folders
C:\DOCUME~1\ALLUSE~1\APPLIC~1\espionServerData
C:\DOCUME~1\ALLUSE~1\APPLIC~1\espionServerData\globData.mk4
——————–\\ Searching within the Registry
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
….. OK !
——————–\\ Checking the Hosts file
Hosts file CLEAN
——————–\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 16:08:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0
——————–\\ Searching for other infections
——————–\\ ROOTKIT !!
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV.SYS]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_TDSSSERV.SYS]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV.SYS]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDSSserv.sys]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\TDSSserv.sys]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys]
——————–\\ Suspect ..
C:\WINDOWS\system32\TDSSmtvd.dat
——————–\\ Cracks & Keygens ..
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\keygen.exe
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\Nero-7.5.1.1_ptb.exe
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\Nero7.0-Kg.rar
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\read.txt
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\Serials.txt
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\Torrent_downloaded_from_Demonoid_com.txt
[F:4][D:1]-> C:\DOCUME~1\Owner\LOCALS~1\Temp
[F:48][D:0]-> C:\DOCUME~1\Owner\Cookies
[F:168][D:4]-> C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Thu 10/30/2008|16:09 - Option : [1]
——————–\\ Scan completed at 16:09:44
——————–\\ Lop S&D 4.2.4-8 XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 2.66GHz )
BIOS : Phoenix - Award BIOS v6.00PG
USER : Owner ( Administrator )
BOOT : Normal boot
Antivirus : AVG 7.5.549 7.5.549 (Activated)
C:\ (Local Disk) - NTFS - Total:189 Go (Free:109 Go)
D:\ (CD or DVD)
E:\ (Local Disk) - FAT32 - Total:232 Go (Free:144 Go)
"C:\Lop SD" ( MAJ : 27-10-2008|09:15 )
Option : [1] ( Thu 10/30/2008|16:07 )
——————–\\ Listing folders in APPLIC~1
[09/19/2008|04:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[09/19/2008|07:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ALM
[01/26/2007|07:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[08/19/2008|10:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ATI
[10/17/2008|10:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ avg7
[10/14/2008|11:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Blizzard
[09/19/2008|04:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ espionServerData
[09/19/2008|04:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FLEXnet
[06/02/2008|11:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[12/03/2007|03:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Grisoft
[11/03/2006|07:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[04/14/2008|01:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[08/18/2008|11:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Kaspersky Lab
[06/15/2008|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[06/15/2008|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[06/06/2007|10:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[10/15/2008|03:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft Help
[02/09/2007|11:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NVIDIA
[10/02/2008|01:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[10/22/2006|01:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[06/23/2007|12:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[09/12/2006|03:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[07/28/2005|10:38] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[12/03/2007|03:38] C:\DOCUME~1\LOCALS~1\APPLIC~1\ AVG7
[05/04/2008|02:37] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Macromedia
[12/03/2007|03:38] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[12/03/2007|03:38] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft
[09/19/2008|08:22] C:\DOCUME~1\Owner\APPLIC~1\ Adobe
[08/17/2008|04:13] C:\DOCUME~1\Owner\APPLIC~1\ AdobeUM
[10/25/2006|01:50] C:\DOCUME~1\Owner\APPLIC~1\ Ahead
[10/23/2006|02:33] C:\DOCUME~1\Owner\APPLIC~1\ Aim
[12/27/2006|08:05] C:\DOCUME~1\Owner\APPLIC~1\ Apple Computer
[08/19/2008|10:51] C:\DOCUME~1\Owner\APPLIC~1\ ATI
[07/04/2008|10:05] C:\DOCUME~1\Owner\APPLIC~1\ AVG7
[10/28/2008|03:58] C:\DOCUME~1\Owner\APPLIC~1\ Azureus
[09/19/2008|03:53] C:\DOCUME~1\Owner\APPLIC~1\ DAEMON Tools
[06/02/2008|09:36] C:\DOCUME~1\Owner\APPLIC~1\ Google
[11/03/2007|06:13] C:\DOCUME~1\Owner\APPLIC~1\ Help
[07/28/2005|10:38] C:\DOCUME~1\Owner\APPLIC~1\ Identities
[07/05/2008|05:02] C:\DOCUME~1\Owner\APPLIC~1\ InstallShield
[04/14/2008|01:16] C:\DOCUME~1\Owner\APPLIC~1\ Intuit
[10/30/2006|07:49] C:\DOCUME~1\Owner\APPLIC~1\ Leadertech
[06/07/2008|02:17] C:\DOCUME~1\Owner\APPLIC~1\ Macromedia
[06/15/2008|12:42] C:\DOCUME~1\Owner\APPLIC~1\ Malwarebytes
[09/12/2006|04:25] C:\DOCUME~1\Owner\APPLIC~1\ Media Player Classic
[06/17/2008|06:54] C:\DOCUME~1\Owner\APPLIC~1\ Microsoft
[10/28/2008|09:44] C:\DOCUME~1\Owner\APPLIC~1\ Move Networks
[06/14/2008|12:27] C:\DOCUME~1\Owner\APPLIC~1\ Mozilla
[10/30/2006|07:51] C:\DOCUME~1\Owner\APPLIC~1\ Sonic
[10/03/2006|08:10] C:\DOCUME~1\Owner\APPLIC~1\ Sun
[08/08/2007|06:45] C:\DOCUME~1\Owner\APPLIC~1\ teamspeak2
[07/12/2007|04:57] C:\DOCUME~1\Owner\APPLIC~1\ Ventrilo
[01/11/2007|12:24] C:\DOCUME~1\Owner\APPLIC~1\ Viewpoint
[10/30/2008|12:18] C:\DOCUME~1\Owner\APPLIC~1\ WinRAR
——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[10/30/2008 02:49 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 12:00 PM][-r-h—–] C:\WINDOWS\tasks\desktop.ini
——————–\\ Listing Folders in C:\Program Files
[09/19/2008|07:00] C:\Program Files\ Adobe
[10/23/2006|02:33] C:\Program Files\ AIM
[10/23/2006|02:33] C:\Program Files\ AOD
[08/19/2008|10:47] C:\Program Files\ ATI Technologies
[07/10/2008|04:02] C:\Program Files\ Azureus
[09/19/2008|06:36] C:\Program Files\ Bonjour
[09/02/2008|12:23] C:\Program Files\ CCleaner
[09/03/2008|12:34] C:\Program Files\ Combined Community Codec Pack
[10/29/2008|08:15] C:\Program Files\ Common Files
[07/28/2005|10:38] C:\Program Files\ ComPlus Applications
[10/29/2008|09:56] C:\Program Files\ ERUNT
[11/03/2006|07:15] C:\Program Files\ GALA-NET
[10/14/2006|11:47] C:\Program Files\ GamaSoft
[06/03/2008|10:27] C:\Program Files\ Google
[12/03/2007|03:38] C:\Program Files\ Grisoft
[09/03/2008|12:31] C:\Program Files\ Hijackthis
[08/19/2008|10:47] C:\Program Files\ InstallShield Installation Information
[08/19/2008|10:27] C:\Program Files\ Internet Explorer
[07/05/2008|05:04] C:\Program Files\ ItsDeductible2006
[07/17/2008|07:40] C:\Program Files\ Java
[09/12/2006|04:50] C:\Program Files\ KSIGN
[10/20/2008|10:03] C:\Program Files\ LimeWire
[10/29/2008|09:57] C:\Program Files\ Malwarebytes' Anti-Malware
[08/19/2008|10:04] C:\Program Files\ Messenger
[07/28/2005|10:38] C:\Program Files\ microsoft frontpage
[06/06/2007|10:49] C:\Program Files\ Microsoft Office
[04/09/2007|06:02] C:\Program Files\ Microsoft Visual Studio
[06/06/2007|10:50] C:\Program Files\ Microsoft Visual Studio 8
[04/09/2007|06:02] C:\Program Files\ Microsoft Works
[04/09/2007|06:01] C:\Program Files\ Microsoft.NET
[04/01/2008|05:24] C:\Program Files\ mIRC
[08/19/2008|10:01] C:\Program Files\ Movie Maker
[06/06/2007|10:54] C:\Program Files\ MSBuild
[07/28/2005|10:38] C:\Program Files\ MSN
[07/28/2005|10:38] C:\Program Files\ MSN Gaming Zone
[10/25/2006|01:46] C:\Program Files\ Nero
[08/19/2008|09:59] C:\Program Files\ NetMeeting
[10/17/2008|02:41] C:\Program Files\ New Folder
[09/12/2006|04:09] C:\Program Files\ Ntreev
[06/17/2008|06:39] C:\Program Files\ Octoshape Streaming Services
[11/21/2006|11:04] C:\Program Files\ Okidata
[09/12/2006|02:04] C:\Program Files\ Online Services
[08/19/2008|09:59] C:\Program Files\ Outlook Express
[05/28/2007|10:32] C:\Program Files\ Paltalk Messenger
[09/19/2008|04:01] C:\Program Files\ PowerISO
[01/26/2007|07:03] C:\Program Files\ QuickTime
[09/12/2006|03:54] C:\Program Files\ Realtek AC97
[08/20/2008|04:35] C:\Program Files\ RegScrubXP
[10/30/2006|07:47] C:\Program Files\ Sonic
[06/15/2008|12:02] C:\Program Files\ Spybot - Search & Destroy
[10/29/2008|09:19] C:\Program Files\ Trend Micro
[07/05/2008|05:02] C:\Program Files\ TurboTax
[07/28/2005|10:38] C:\Program Files\ Uninstall Information
[11/16/2007|08:55] C:\Program Files\ Ventrilo
[01/21/2007|02:26] C:\Program Files\ Western Digital Technologies
[10/22/2006|12:18] C:\Program Files\ Winamp
[09/19/2008|04:11] C:\Program Files\ Windows Media Player
[08/19/2008|09:59] C:\Program Files\ Windows NT
[07/28/2005|10:38] C:\Program Files\ WindowsUpdate
[09/12/2006|04:01] C:\Program Files\ WinRAR
[10/21/2008|11:00] C:\Program Files\ World of Warcraft
[07/28/2005|10:38] C:\Program Files\ xerox
——————–\\ Listing Folders in C:\Program Files\Common Files
[09/19/2008|06:35] C:\Program Files\Common Files\ Adobe
[10/25/2006|07:54] C:\Program Files\Common Files\ Ahead
[04/14/2008|01:14] C:\Program Files\Common Files\ AnswerWorks 4.0
[08/18/2008|12:02] C:\Program Files\Common Files\ Blizzard Entertainment
[08/18/2008|03:00] C:\Program Files\Common Files\ DESIGNER
[06/15/2008|12:41] C:\Program Files\Common Files\ Download Manager
[11/03/2006|07:15] C:\Program Files\Common Files\ InstallShield
[04/14/2008|01:13] C:\Program Files\Common Files\ Intuit
[07/17/2008|07:40] C:\Program Files\Common Files\ Java
[09/19/2008|04:16] C:\Program Files\Common Files\ Macrovision Shared
[08/19/2008|01:20] C:\Program Files\Common Files\ Microsoft Shared
[07/28/2005|10:38] C:\Program Files\Common Files\ MSSoap
[07/28/2005|10:38] C:\Program Files\Common Files\ ODBC
[09/12/2006|02:17] C:\Program Files\Common Files\ Services
[07/28/2005|10:38] C:\Program Files\Common Files\ SpeechEngines
[08/19/2008|09:58] C:\Program Files\Common Files\ System
[04/09/2007|09:54] C:\Program Files\Common Files\ Viewpoint
[06/15/2008|12:40] C:\Program Files\Common Files\ Wise Installation Wizard
——————–\\ Process
( 34 Processes )
… OK !
——————–\\ Searching with S_Lop
No Lop folder found !
——————–\\ Searching for Lop Files - Folders
C:\DOCUME~1\ALLUSE~1\APPLIC~1\espionServerData
C:\DOCUME~1\ALLUSE~1\APPLIC~1\espionServerData\globData.mk4
——————–\\ Searching within the Registry
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
….. OK !
——————–\\ Checking the Hosts file
Hosts file CLEAN
——————–\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 16:08:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0
——————–\\ Searching for other infections
——————–\\ ROOTKIT !!
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV.SYS]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_TDSSSERV.SYS]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV.SYS]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDSSserv.sys]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\TDSSserv.sys]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys]
——————–\\ Suspect ..
C:\WINDOWS\system32\TDSSmtvd.dat
——————–\\ Cracks & Keygens ..
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\keygen.exe
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\Nero-7.5.1.1_ptb.exe
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\Nero7.0-Kg.rar
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\read.txt
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\Serials.txt
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen\Torrent_downloaded_from_Demonoid_com.txt
[F:4][D:1]-> C:\DOCUME~1\Owner\LOCALS~1\Temp
[F:48][D:0]-> C:\DOCUME~1\Owner\Cookies
[F:168][D:4]-> C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Thu 10/30/2008|16:09 - Option : [1]
——————–\\ Scan completed at 16:09:44
Rorschach112
You got infected because you downloaded cracks
Please download the OTMoveIt3 by OldTimer or from here.
Download ComboFix from one of these locations:
Link 1
Link 2
Link 3
* IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Please download the OTMoveIt3 by OldTimer or from here.
- Save it to your desktop.
- Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:Processes explorer.exe :Services :Reg :Files C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen :Commands [purity] [emptytemp] [start explorer] [Reboot]
- Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTMoveIt3
Download ComboFix from one of these locations:
Link 1
Link 2
Link 3
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
ganjadank
Thanks for the fast reply!
There's a slight problem with SDFix still trying to finish malware scan whenever I reboot.
Here's the OTMoveIt3 and Combofix logs:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10302008_162044
Files moved on Reboot…
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
ComboFix 08-10-30.09 - Owner 2008-10-30 16:31:00.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.519 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\fbk.sts
C:\WINDOWS\system32\dllcache\figaro.sys
C:\WINDOWS\system32\fihkucta.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\qnycchoy.dll
C:\WINDOWS\system32\TDSSmtvd.dat
C:\WINDOWS\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
2008-10-30 16:20 . 2008-10-30 16:20 d——– C:\_OTMoveIt
2008-10-30 16:07 . 2008-10-30 16:09 d——– C:\Lop SD
2008-10-30 12:08 . 2008-10-30 12:08 578,560 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-10-30 12:02 . 2008-10-30 12:03 d——– C:\WINDOWS\ERUNT
2008-10-30 11:57 . 2008-10-30 12:18 d——– C:\SDFix
2008-10-29 21:57 . 2008-10-29 21:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 21:57 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 21:57 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-29 21:56 . 2008-10-29 21:56 d——– C:\Program Files\ERUNT
2008-10-29 21:19 . 2008-10-29 21:19 d——– C:\Program Files\Trend Micro
2008-10-29 21:15 . 2008-10-29 21:15 101,376 –a—— C:\WINDOWS\system32\yxsswf.dll
2008-10-29 21:15 . 2008-10-29 21:15 101,376 –a—— C:\WINDOWS\system32\guohmubg.dll
2008-10-29 20:15 . 2008-10-29 20:15 19,199 –a—— C:\WINDOWS\vawaqota.exe
2008-10-29 20:15 . 2008-10-29 20:15 18,279 –a—— C:\Program Files\Common Files\wypylar.dll
2008-10-29 20:15 . 2008-10-29 20:15 14,929 –a—— C:\Documents and Settings\Owner\Application Data\myqulitav.exe
2008-10-29 20:15 . 2008-10-29 20:15 14,830 –a—— C:\WINDOWS\omun.exe
2008-10-29 20:15 . 2008-10-29 20:15 14,715 –a—— C:\WINDOWS\awyzymih.bin
2008-10-29 20:15 . 2008-10-29 20:15 14,333 –a—— C:\WINDOWS\kuceqoci.db
2008-10-29 20:15 . 2008-10-29 20:15 13,611 –a—— C:\WINDOWS\ilusojylu.dll
2008-10-29 20:15 . 2008-10-29 20:15 13,126 –a—— C:\WINDOWS\fanubupeje.lib
2008-10-29 20:15 . 2008-10-29 20:15 11,350 –a—— C:\WINDOWS\lutep.lib
2008-10-29 19:58 . 2008-10-29 19:58 19,705 –a—— C:\Program Files\Common Files\uqaxuco.exe
2008-10-29 19:58 . 2008-10-29 19:58 19,551 –a—— C:\WINDOWS\system32\reryf.sys
2008-10-29 19:58 . 2008-10-29 19:58 19,396 –a—— C:\Program Files\Common Files\ezybizu.bat
2008-10-29 19:58 . 2008-10-29 19:58 17,779 –a—— C:\Program Files\Common Files\devybugaxe.dll
2008-10-29 19:58 . 2008-10-29 19:58 15,711 –a—— C:\WINDOWS\system32\gevuf.dl
2008-10-29 19:58 . 2008-10-29 19:58 14,424 –a—— C:\Documents and Settings\All Users\Application Data\piguhykovo.sys
2008-10-29 19:58 . 2008-10-29 19:58 13,904 –a—— C:\WINDOWS\oxoxax.ban
2008-10-29 19:58 . 2008-10-29 19:58 12,508 –a—— C:\WINDOWS\inuxawikov._dl
2008-10-29 19:58 . 2008-10-29 19:58 11,365 –a—— C:\WINDOWS\system32\fabodypyk.dat
2008-10-29 19:58 . 2008-10-29 19:58 10,278 –a—— C:\WINDOWS\uqyteriq.sys
2008-10-29 18:45 . 2008-10-29 18:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-29 18:45 . 2008-10-29 18:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-24 09:06 . 2008-10-15 09:34 337,408 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 10:29 . 2008-08-14 03:11 2,189,184 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 10:29 . 2008-08-14 03:09 2,145,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,066,048 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,023,936 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 10:29 . 2008-09-15 05:12 1,846,400 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 10:29 . 2008-09-08 03:41 333,824 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 11:33 . 2008-10-14 11:33 d——– C:\Documents and Settings\All Users\Application Data\Blizzard
2008-09-19 19:00 . 2008-09-19 19:00 d——– C:\Documents and Settings\All Users\Application Data\ALM
2008-09-19 18:36 . 2008-09-19 18:36 d——– C:\Program Files\Bonjour
2008-09-19 16:23 . 2008-09-19 16:23 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2008-09-19 16:20 . 2008-09-19 16:20 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-19 16:16 . 2008-09-19 16:16 d——– C:\Program Files\Common Files\Macrovision Shared
2008-09-19 16:11 . 2008-09-19 16:10 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-09-19 16:11 . 2008-09-19 16:10 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 9,464 –a—— C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-19 16:11 . 2008-09-19 16:10 9,336 –a—— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-19 16:01 . 2008-09-19 16:01 d——– C:\Program Files\PowerISO
2008-09-19 15:53 . 2008-09-19 15:53 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-03 00:34 . 2008-09-03 00:34 d——– C:\Program Files\Combined Community Codec Pack
2008-09-02 12:23 . 2008-09-02 12:23 d——– C:\Program Files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 22:58 ——— d—–w C:\Documents and Settings\Owner\Application Data\Azureus
2008-10-28 16:44 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-10-21 18:00 ——— d—–w C:\Program Files\World of Warcraft
2008-10-21 05:03 ——— d—–w C:\Program Files\LimeWire
2008-10-17 21:41 ——— d–h–w C:\Program Files\New Folder
2008-10-17 17:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-10-15 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-02 20:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 01:35 ——— d—–w C:\Program Files\Common Files\Adobe
2008-09-19 23:10 43,528 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-09-19 22:53 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:30 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-19 17:29 3,222 —-a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-08-14 10:09 2,145,280 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-19 05:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(4).dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(3).dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-04 04:05 593,920 —-a-w C:\WINDOWS\system32\ati2sgag.exe
2008-07-04 03:48 9,490,432 —-a-w C:\WINDOWS\system32\atioglx2.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2008-07-04 03:14 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-07-04 03:14 184,320 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2008-07-04 03:14 143,360 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2008-07-04 03:13 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2008-07-04 03:12 561,152 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2008-07-04 03:10 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-07-04 03:06 253,952 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\system32\ati3duag.dll
2008-07-04 02:55 307,200 —-a-w C:\WINDOWS\system32\atiiiexx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2008-07-04 02:34 48,640 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2008-07-04 02:30 348,160 —-a-w C:\WINDOWS\system32\atikvmag.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\system32\atiadlxx.dll
2008-07-04 02:28 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2008-07-04 02:25 5,439,488 —-a-w C:\WINDOWS\system32\atioglxx.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\system32\ati2cqag.dll
.
——- Sigcheck ——-
2004-08-04 12:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\system32\svchost.exe
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2007-03-08 08:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2004-08-04 12:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\ServicePackFiles\i386\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\user32.dll
2008-10-30 12:08 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 12:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\system32\ws2_32.dll
2006-06-23 04:25 664576 64ce26db72810b30f7855ea51e1df836 C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll
2006-09-14 01:31 664576 d207370287cf769aebebf03837784963 C:\WINDOWS\$hf_mig$\KB922760\SP2QFE\wininet.dll
2006-10-23 08:34 664576 231ef4179acabe486376b5ca893f1076 C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\wininet.dll
2007-01-04 07:05 665088 3ffa1573fc274e5aa7467d03941c45ee C:\WINDOWS\$hf_mig$\KB928090\SP2QFE\wininet.dll
2007-02-20 02:52 665600 b258c922d22deec880b60720531d7627 C:\WINDOWS\$hf_mig$\KB931768\SP2QFE\wininet.dll
2007-04-18 05:46 665600 4261ba03afd659de04f0a17dfbdd454d C:\WINDOWS\$hf_mig$\KB933566\SP2QFE\wininet.dll
2007-06-26 07:35 665600 e1a3dd68b5380b360a7310a64d9bb188 C:\WINDOWS\$hf_mig$\KB937143\SP2QFE\wininet.dll
2007-08-22 05:55 665600 a1bc17eb3758d73c3938b2318820f5b4 C:\WINDOWS\$hf_mig$\KB939653\SP2QFE\wininet.dll
2007-10-10 22:57 666112 80d660a49e0d118144423099b2a9f5da C:\WINDOWS\$hf_mig$\KB942615\SP2QFE\wininet.dll
2007-12-06 17:44 666112 085a7c37f9c6ede1ba870b7dbec06399 C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\wininet.dll
2008-02-16 02:32 666112 bb1eacd6ab47e78ebca02eb781550d55 C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
2008-04-20 23:56 666624 2e7de1bf9418b071799eb53de8cc22f5 C:\WINDOWS\$hf_mig$\KB950759\SP2QFE\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$hf_mig$\KB950759\SP3GDR\wininet.dll
2008-04-20 23:24 666624 26f240c250e5b4b395cb4b178ba75437 C:\WINDOWS\$hf_mig$\KB950759\SP3QFE\wininet.dll
2008-06-23 09:12 667136 611ace3f4201e9610af8452f7c268995 C:\WINDOWS\$hf_mig$\KB953838\SP2QFE\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\wininet.dll
2008-06-23 07:54 666624 972299b7241ec325d8c7e5638c884925 C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\wininet.dll
2008-08-19 21:58 666624 94418f53d2612c26dbadc04dafbc197c C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\wininet.dll
2008-06-23 08:38 659456 9eea04bc4c3fa521d256d89940fab4db C:\WINDOWS\$NtServicePackUninstall$\wininet.dll
2004-08-04 12:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
2006-06-23 04:02 658944 2b4db890936430c71419037039502752 C:\WINDOWS\$NtUninstallKB922760$\wininet.dll
2006-09-14 01:39 658944 621af3f6174a3f60677f5230e28bcc07 C:\WINDOWS\$NtUninstallKB925454$\wininet.dll
2006-10-23 08:17 658944 6b2735adff5a5d3b9130ca4a794722f0 C:\WINDOWS\$NtUninstallKB928090$\wininet.dll
2007-01-04 06:37 658944 8c393df5234cbcbff1ee31902d6b40ae C:\WINDOWS\$NtUninstallKB931768$\wininet.dll
2007-02-20 02:48 658944 30d1c47e40efbb792ff8d3c3b51ce507 C:\WINDOWS\$NtUninstallKB933566$\wininet.dll
2007-04-18 05:31 658944 b7156cd97e739f3014bc4d61758f868a C:\WINDOWS\$NtUninstallKB937143$\wininet.dll
2007-06-26 07:09 658944 184e47c8f7b331025e6dc92740db188f C:\WINDOWS\$NtUninstallKB939653$\wininet.dll
2007-08-22 06:12 658944 1901ad51da8be9f8b38d5d526e5d1788 C:\WINDOWS\$NtUninstallKB942615$\wininet.dll
2007-10-10 23:13 659456 2005ad86a22aee68e21ee59f9ccb77f2 C:\WINDOWS\$NtUninstallKB944533$\wininet.dll
2007-12-06 18:07 659456 57d1b5150cf6331fac6b3e04c1fcb966 C:\WINDOWS\$NtUninstallKB947864$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\$NtUninstallKB950759$\wininet.dll
2008-02-16 01:59 659456 0c690e77c0e924c45b4d7045b182fff1 C:\WINDOWS\$NtUninstallKB950759_0$\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$NtUninstallKB953838$\wininet.dll
2008-04-21 00:04 659456 1efb8a3ea8454aec1bb8a240a2845598 C:\WINDOWS\$NtUninstallKB953838_0$\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$NtUninstallKB956390$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\dllcache\wininet.dll
2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 12:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 12:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\system32\winlogon.exe
2004-08-04 12:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\ServicePackFiles\i386\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 12:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 09:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 02:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2007-02-28 01:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-03 22:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 17:34 2015232 3cd941e472ddf3534e53038535719771 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 05:55 2015744 bbb2322eb14ad9ad55b1024ffd4d88bf C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2008-04-13 11:31 2023936 7f653a89f6e89e3ae0d49830eece35d4 C:\WINDOWS\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 11:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-08-14 02:33 2023936 8206b5f94a6a9450e934029420c1693f C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2004-08-03 15:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 18:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 09:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 02:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2007-02-28 02:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-03 23:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 17:57 2135552 48b3e89af7074cee0314a3e0c7faffdb C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 07:15 2136064 8318ed54797f3e513fd5817a1d4bbd18 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2008-04-13 12:24 2145280 40f8880122a030a7e9e1fedea833b33d C:\WINDOWS\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2008-04-13 12:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-08-14 03:09 2145280 f6f8245b3a2e9ca834dd318e7ae0c6d0 C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2004-08-04 12:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntoskrnl.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\explorer.exe
2007-06-13 04:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2004-08-04 12:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\$NtServicePackUninstall$\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\ServicePackFiles\i386\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\system32\services.exe
2004-08-04 12:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\ServicePackFiles\i386\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\system32\lsass.exe
2004-08-04 12:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\system32\ctfmon.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 16:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 12:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\system32\spoolsv.exe
2004-08-04 12:00 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\system32\userinit.exe
2004-08-04 12:00 295424 b60c877d16d9c880b952fda04adf16e6 C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 35328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-10-16 590848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 67488]
"SDFix"="C:\SDFix\RunThis.bat" [2008-10-26 918612]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-03 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
OKI LPR Utility.lnk - C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe [2006-11-21 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
.
- - - - ORPHANS REMOVED - - - -
BHO-{299B5FAC-2168-4A5D-A67D-AA4C8F8055DA} - (no file)
BHO-{53CDB936-7A8D-4B44-9B7B-70525D0C9D50} - (no file)
BHO-{6839DB84-A6EC-4E8B-9320-2C6E98A3C27C} - (no file)
BHO-{A32BF1D3-1110-4507-8F5E-235E0586F08C} - (no file)
Notify-fccyyYpp - (no file)
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: {7D4733C0-C43B-4A81-AF43-F9B20D1F8348} - hxxp://www.octoshape.com/test/ax/octoshape.cab
C:\WINDOWS\Downloaded Program Files\octoshape.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 16:34:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\OPHALDCS.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-30 16:40:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-30 23:39:52
ComboFix2.txt 2008-05-05 21:13:08
Pre-Run: 118,897,549,312 bytes free
Post-Run: 118,451,728,384 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
355 — E O F — 2008-10-24 20:18:02
There's a slight problem with SDFix still trying to finish malware scan whenever I reboot.
Here's the OTMoveIt3 and Combofix logs:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\DOCUME~1\Owner\Desktop\New Folder (2)\New Folder\Nero 7 Premium Reloaded 7.5.1.1 - Official PT-BR With Keygen moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10302008_162044
Files moved on Reboot…
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
ComboFix 08-10-30.09 - Owner 2008-10-30 16:31:00.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.519 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\fbk.sts
C:\WINDOWS\system32\dllcache\figaro.sys
C:\WINDOWS\system32\fihkucta.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\qnycchoy.dll
C:\WINDOWS\system32\TDSSmtvd.dat
C:\WINDOWS\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
2008-10-30 16:20 . 2008-10-30 16:20 d——– C:\_OTMoveIt
2008-10-30 16:07 . 2008-10-30 16:09 d——– C:\Lop SD
2008-10-30 12:08 . 2008-10-30 12:08 578,560 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-10-30 12:02 . 2008-10-30 12:03 d——– C:\WINDOWS\ERUNT
2008-10-30 11:57 . 2008-10-30 12:18 d——– C:\SDFix
2008-10-29 21:57 . 2008-10-29 21:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 21:57 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 21:57 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-29 21:56 . 2008-10-29 21:56 d——– C:\Program Files\ERUNT
2008-10-29 21:19 . 2008-10-29 21:19 d——– C:\Program Files\Trend Micro
2008-10-29 21:15 . 2008-10-29 21:15 101,376 –a—— C:\WINDOWS\system32\yxsswf.dll
2008-10-29 21:15 . 2008-10-29 21:15 101,376 –a—— C:\WINDOWS\system32\guohmubg.dll
2008-10-29 20:15 . 2008-10-29 20:15 19,199 –a—— C:\WINDOWS\vawaqota.exe
2008-10-29 20:15 . 2008-10-29 20:15 18,279 –a—— C:\Program Files\Common Files\wypylar.dll
2008-10-29 20:15 . 2008-10-29 20:15 14,929 –a—— C:\Documents and Settings\Owner\Application Data\myqulitav.exe
2008-10-29 20:15 . 2008-10-29 20:15 14,830 –a—— C:\WINDOWS\omun.exe
2008-10-29 20:15 . 2008-10-29 20:15 14,715 –a—— C:\WINDOWS\awyzymih.bin
2008-10-29 20:15 . 2008-10-29 20:15 14,333 –a—— C:\WINDOWS\kuceqoci.db
2008-10-29 20:15 . 2008-10-29 20:15 13,611 –a—— C:\WINDOWS\ilusojylu.dll
2008-10-29 20:15 . 2008-10-29 20:15 13,126 –a—— C:\WINDOWS\fanubupeje.lib
2008-10-29 20:15 . 2008-10-29 20:15 11,350 –a—— C:\WINDOWS\lutep.lib
2008-10-29 19:58 . 2008-10-29 19:58 19,705 –a—— C:\Program Files\Common Files\uqaxuco.exe
2008-10-29 19:58 . 2008-10-29 19:58 19,551 –a—— C:\WINDOWS\system32\reryf.sys
2008-10-29 19:58 . 2008-10-29 19:58 19,396 –a—— C:\Program Files\Common Files\ezybizu.bat
2008-10-29 19:58 . 2008-10-29 19:58 17,779 –a—— C:\Program Files\Common Files\devybugaxe.dll
2008-10-29 19:58 . 2008-10-29 19:58 15,711 –a—— C:\WINDOWS\system32\gevuf.dl
2008-10-29 19:58 . 2008-10-29 19:58 14,424 –a—— C:\Documents and Settings\All Users\Application Data\piguhykovo.sys
2008-10-29 19:58 . 2008-10-29 19:58 13,904 –a—— C:\WINDOWS\oxoxax.ban
2008-10-29 19:58 . 2008-10-29 19:58 12,508 –a—— C:\WINDOWS\inuxawikov._dl
2008-10-29 19:58 . 2008-10-29 19:58 11,365 –a—— C:\WINDOWS\system32\fabodypyk.dat
2008-10-29 19:58 . 2008-10-29 19:58 10,278 –a—— C:\WINDOWS\uqyteriq.sys
2008-10-29 18:45 . 2008-10-29 18:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-29 18:45 . 2008-10-29 18:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-24 09:06 . 2008-10-15 09:34 337,408 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 10:29 . 2008-08-14 03:11 2,189,184 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 10:29 . 2008-08-14 03:09 2,145,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,066,048 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,023,936 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 10:29 . 2008-09-15 05:12 1,846,400 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 10:29 . 2008-09-08 03:41 333,824 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 11:33 . 2008-10-14 11:33 d——– C:\Documents and Settings\All Users\Application Data\Blizzard
2008-09-19 19:00 . 2008-09-19 19:00 d——– C:\Documents and Settings\All Users\Application Data\ALM
2008-09-19 18:36 . 2008-09-19 18:36 d——– C:\Program Files\Bonjour
2008-09-19 16:23 . 2008-09-19 16:23 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2008-09-19 16:20 . 2008-09-19 16:20 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-19 16:16 . 2008-09-19 16:16 d——– C:\Program Files\Common Files\Macrovision Shared
2008-09-19 16:11 . 2008-09-19 16:10 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-09-19 16:11 . 2008-09-19 16:10 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 9,464 –a—— C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-19 16:11 . 2008-09-19 16:10 9,336 –a—— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-19 16:01 . 2008-09-19 16:01 d——– C:\Program Files\PowerISO
2008-09-19 15:53 . 2008-09-19 15:53 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-03 00:34 . 2008-09-03 00:34 d——– C:\Program Files\Combined Community Codec Pack
2008-09-02 12:23 . 2008-09-02 12:23 d——– C:\Program Files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 22:58 ——— d—–w C:\Documents and Settings\Owner\Application Data\Azureus
2008-10-28 16:44 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-10-21 18:00 ——— d—–w C:\Program Files\World of Warcraft
2008-10-21 05:03 ——— d—–w C:\Program Files\LimeWire
2008-10-17 21:41 ——— d–h–w C:\Program Files\New Folder
2008-10-17 17:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-10-15 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-02 20:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 01:35 ——— d—–w C:\Program Files\Common Files\Adobe
2008-09-19 23:10 43,528 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-09-19 22:53 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:30 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-19 17:29 3,222 —-a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-08-14 10:09 2,145,280 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-19 05:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(4).dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(3).dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-04 04:05 593,920 —-a-w C:\WINDOWS\system32\ati2sgag.exe
2008-07-04 03:48 9,490,432 —-a-w C:\WINDOWS\system32\atioglx2.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2008-07-04 03:14 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-07-04 03:14 184,320 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2008-07-04 03:14 143,360 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2008-07-04 03:13 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2008-07-04 03:12 561,152 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2008-07-04 03:10 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-07-04 03:06 253,952 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\system32\ati3duag.dll
2008-07-04 02:55 307,200 —-a-w C:\WINDOWS\system32\atiiiexx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2008-07-04 02:34 48,640 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2008-07-04 02:30 348,160 —-a-w C:\WINDOWS\system32\atikvmag.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\system32\atiadlxx.dll
2008-07-04 02:28 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2008-07-04 02:25 5,439,488 —-a-w C:\WINDOWS\system32\atioglxx.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\system32\ati2cqag.dll
.
——- Sigcheck ——-
2004-08-04 12:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\system32\svchost.exe
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2007-03-08 08:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2004-08-04 12:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\ServicePackFiles\i386\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\user32.dll
2008-10-30 12:08 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 12:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\system32\ws2_32.dll
2006-06-23 04:25 664576 64ce26db72810b30f7855ea51e1df836 C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll
2006-09-14 01:31 664576 d207370287cf769aebebf03837784963 C:\WINDOWS\$hf_mig$\KB922760\SP2QFE\wininet.dll
2006-10-23 08:34 664576 231ef4179acabe486376b5ca893f1076 C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\wininet.dll
2007-01-04 07:05 665088 3ffa1573fc274e5aa7467d03941c45ee C:\WINDOWS\$hf_mig$\KB928090\SP2QFE\wininet.dll
2007-02-20 02:52 665600 b258c922d22deec880b60720531d7627 C:\WINDOWS\$hf_mig$\KB931768\SP2QFE\wininet.dll
2007-04-18 05:46 665600 4261ba03afd659de04f0a17dfbdd454d C:\WINDOWS\$hf_mig$\KB933566\SP2QFE\wininet.dll
2007-06-26 07:35 665600 e1a3dd68b5380b360a7310a64d9bb188 C:\WINDOWS\$hf_mig$\KB937143\SP2QFE\wininet.dll
2007-08-22 05:55 665600 a1bc17eb3758d73c3938b2318820f5b4 C:\WINDOWS\$hf_mig$\KB939653\SP2QFE\wininet.dll
2007-10-10 22:57 666112 80d660a49e0d118144423099b2a9f5da C:\WINDOWS\$hf_mig$\KB942615\SP2QFE\wininet.dll
2007-12-06 17:44 666112 085a7c37f9c6ede1ba870b7dbec06399 C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\wininet.dll
2008-02-16 02:32 666112 bb1eacd6ab47e78ebca02eb781550d55 C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
2008-04-20 23:56 666624 2e7de1bf9418b071799eb53de8cc22f5 C:\WINDOWS\$hf_mig$\KB950759\SP2QFE\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$hf_mig$\KB950759\SP3GDR\wininet.dll
2008-04-20 23:24 666624 26f240c250e5b4b395cb4b178ba75437 C:\WINDOWS\$hf_mig$\KB950759\SP3QFE\wininet.dll
2008-06-23 09:12 667136 611ace3f4201e9610af8452f7c268995 C:\WINDOWS\$hf_mig$\KB953838\SP2QFE\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\wininet.dll
2008-06-23 07:54 666624 972299b7241ec325d8c7e5638c884925 C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\wininet.dll
2008-08-19 21:58 666624 94418f53d2612c26dbadc04dafbc197c C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\wininet.dll
2008-06-23 08:38 659456 9eea04bc4c3fa521d256d89940fab4db C:\WINDOWS\$NtServicePackUninstall$\wininet.dll
2004-08-04 12:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
2006-06-23 04:02 658944 2b4db890936430c71419037039502752 C:\WINDOWS\$NtUninstallKB922760$\wininet.dll
2006-09-14 01:39 658944 621af3f6174a3f60677f5230e28bcc07 C:\WINDOWS\$NtUninstallKB925454$\wininet.dll
2006-10-23 08:17 658944 6b2735adff5a5d3b9130ca4a794722f0 C:\WINDOWS\$NtUninstallKB928090$\wininet.dll
2007-01-04 06:37 658944 8c393df5234cbcbff1ee31902d6b40ae C:\WINDOWS\$NtUninstallKB931768$\wininet.dll
2007-02-20 02:48 658944 30d1c47e40efbb792ff8d3c3b51ce507 C:\WINDOWS\$NtUninstallKB933566$\wininet.dll
2007-04-18 05:31 658944 b7156cd97e739f3014bc4d61758f868a C:\WINDOWS\$NtUninstallKB937143$\wininet.dll
2007-06-26 07:09 658944 184e47c8f7b331025e6dc92740db188f C:\WINDOWS\$NtUninstallKB939653$\wininet.dll
2007-08-22 06:12 658944 1901ad51da8be9f8b38d5d526e5d1788 C:\WINDOWS\$NtUninstallKB942615$\wininet.dll
2007-10-10 23:13 659456 2005ad86a22aee68e21ee59f9ccb77f2 C:\WINDOWS\$NtUninstallKB944533$\wininet.dll
2007-12-06 18:07 659456 57d1b5150cf6331fac6b3e04c1fcb966 C:\WINDOWS\$NtUninstallKB947864$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\$NtUninstallKB950759$\wininet.dll
2008-02-16 01:59 659456 0c690e77c0e924c45b4d7045b182fff1 C:\WINDOWS\$NtUninstallKB950759_0$\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$NtUninstallKB953838$\wininet.dll
2008-04-21 00:04 659456 1efb8a3ea8454aec1bb8a240a2845598 C:\WINDOWS\$NtUninstallKB953838_0$\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$NtUninstallKB956390$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\dllcache\wininet.dll
2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 12:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 12:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\system32\winlogon.exe
2004-08-04 12:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\ServicePackFiles\i386\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 12:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 09:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 02:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2007-02-28 01:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-03 22:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 17:34 2015232 3cd941e472ddf3534e53038535719771 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 05:55 2015744 bbb2322eb14ad9ad55b1024ffd4d88bf C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2008-04-13 11:31 2023936 7f653a89f6e89e3ae0d49830eece35d4 C:\WINDOWS\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 11:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-08-14 02:33 2023936 8206b5f94a6a9450e934029420c1693f C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2004-08-03 15:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 18:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 09:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 02:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2007-02-28 02:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-03 23:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 17:57 2135552 48b3e89af7074cee0314a3e0c7faffdb C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 07:15 2136064 8318ed54797f3e513fd5817a1d4bbd18 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2008-04-13 12:24 2145280 40f8880122a030a7e9e1fedea833b33d C:\WINDOWS\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2008-04-13 12:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-08-14 03:09 2145280 f6f8245b3a2e9ca834dd318e7ae0c6d0 C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2004-08-04 12:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntoskrnl.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\explorer.exe
2007-06-13 04:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2004-08-04 12:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\$NtServicePackUninstall$\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\ServicePackFiles\i386\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\system32\services.exe
2004-08-04 12:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\ServicePackFiles\i386\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\system32\lsass.exe
2004-08-04 12:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\system32\ctfmon.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 16:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 12:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\system32\spoolsv.exe
2004-08-04 12:00 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\system32\userinit.exe
2004-08-04 12:00 295424 b60c877d16d9c880b952fda04adf16e6 C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 35328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-10-16 590848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 67488]
"SDFix"="C:\SDFix\RunThis.bat" [2008-10-26 918612]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-03 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
OKI LPR Utility.lnk - C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe [2006-11-21 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
.
- - - - ORPHANS REMOVED - - - -
BHO-{299B5FAC-2168-4A5D-A67D-AA4C8F8055DA} - (no file)
BHO-{53CDB936-7A8D-4B44-9B7B-70525D0C9D50} - (no file)
BHO-{6839DB84-A6EC-4E8B-9320-2C6E98A3C27C} - (no file)
BHO-{A32BF1D3-1110-4507-8F5E-235E0586F08C} - (no file)
Notify-fccyyYpp - (no file)
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: {7D4733C0-C43B-4A81-AF43-F9B20D1F8348} - hxxp://www.octoshape.com/test/ax/octoshape.cab
C:\WINDOWS\Downloaded Program Files\octoshape.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 16:34:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\OPHALDCS.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-30 16:40:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-30 23:39:52
ComboFix2.txt 2008-05-05 21:13:08
Pre-Run: 118,897,549,312 bytes free
Post-Run: 118,451,728,384 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
355 — E O F — 2008-10-24 20:18:02
Rorschach112
Hello
Open notepad and copy/paste the text in the quotebox below into it:
[external image: Posted Image]
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you. Post that log in your next reply.
**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
Open notepad and copy/paste the text in the quotebox below into it:
http://forums.whatthetech.com/HELP_nasty_infection_t96496.html#entry496796 Collect:: C:\WINDOWS\system32\yxsswf.dll C:\WINDOWS\system32\guohmubg.dll C:\WINDOWS\vawaqota.exe C:\Program Files\Common Files\wypylar.dll C:\Documents and Settings\Owner\Application Data\myqulitav.exe C:\WINDOWS\omun.exe C:\WINDOWS\awyzymih.bin C:\WINDOWS\kuceqoci.db C:\WINDOWS\ilusojylu.dll C:\WINDOWS\fanubupeje.lib C:\WINDOWS\lutep.lib C:\Program Files\Common Files\uqaxuco.exe C:\WINDOWS\system32\reryf.sys C:\Program Files\Common Files\ezybizu.bat C:\Program Files\Common Files\devybugaxe.dll C:\WINDOWS\system32\gevuf.dl C:\Documents and Settings\All Users\Application Data\piguhykovo.sys C:\WINDOWS\oxoxax.ban C:\WINDOWS\inuxawikov._dl C:\WINDOWS\system32\fabodypyk.dat C:\WINDOWS\uqyteriq.sys Suspect::Save this as CFScript.txt
[external image: Posted Image]
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you. Post that log in your next reply.
**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
- Ensure you are connected to the internet and click OK on the message box.
- A browser will open.
- Simply follow the instructions to copy/paste/send the requested file.
ganjadank
File has been sent.
New Combofix log
ComboFix 08-10-30.09 - Owner 2008-10-30 16:53:06.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.515 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\piguhykovo.sys
C:\Documents and Settings\Owner\Application Data\myqulitav.exe
C:\Program Files\Common Files\devybugaxe.dll
C:\Program Files\Common Files\ezybizu.bat
C:\Program Files\Common Files\uqaxuco.exe
C:\Program Files\Common Files\wypylar.dll
C:\WINDOWS\awyzymih.bin
C:\WINDOWS\fanubupeje.lib
C:\WINDOWS\ilusojylu.dll
C:\WINDOWS\inuxawikov._dl
C:\WINDOWS\kuceqoci.db
C:\WINDOWS\lutep.lib
C:\WINDOWS\omun.exe
C:\WINDOWS\oxoxax.ban
C:\WINDOWS\system32\fabodypyk.dat
C:\WINDOWS\system32\gevuf.dl
C:\WINDOWS\system32\guohmubg.dll
C:\WINDOWS\system32\reryf.sys
C:\WINDOWS\system32\yxsswf.dll
C:\WINDOWS\uqyteriq.sys
C:\WINDOWS\vawaqota.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
2008-10-30 16:20 . 2008-10-30 16:20 d——– C:\_OTMoveIt
2008-10-30 16:07 . 2008-10-30 16:09 d——– C:\Lop SD
2008-10-30 12:08 . 2008-10-30 12:08 578,560 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-10-30 12:02 . 2008-10-30 12:03 d——– C:\WINDOWS\ERUNT
2008-10-30 11:57 . 2008-10-30 12:18 d——– C:\SDFix
2008-10-29 21:57 . 2008-10-29 21:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 21:57 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 21:57 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-29 21:56 . 2008-10-29 21:56 d——– C:\Program Files\ERUNT
2008-10-29 21:19 . 2008-10-29 21:19 d——– C:\Program Files\Trend Micro
2008-10-29 18:45 . 2008-10-29 18:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-29 18:45 . 2008-10-29 18:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-24 09:06 . 2008-10-15 09:34 337,408 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 10:29 . 2008-08-14 03:11 2,189,184 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 10:29 . 2008-08-14 03:09 2,145,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,066,048 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,023,936 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 10:29 . 2008-09-15 05:12 1,846,400 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 10:29 . 2008-09-08 03:41 333,824 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 11:33 . 2008-10-14 11:33 d——– C:\Documents and Settings\All Users\Application Data\Blizzard
2008-09-19 19:00 . 2008-09-19 19:00 d——– C:\Documents and Settings\All Users\Application Data\ALM
2008-09-19 18:36 . 2008-09-19 18:36 d——– C:\Program Files\Bonjour
2008-09-19 16:23 . 2008-09-19 16:23 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2008-09-19 16:20 . 2008-09-19 16:20 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-19 16:16 . 2008-09-19 16:16 d——– C:\Program Files\Common Files\Macrovision Shared
2008-09-19 16:11 . 2008-09-19 16:10 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-09-19 16:11 . 2008-09-19 16:10 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 9,464 –a—— C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-19 16:11 . 2008-09-19 16:10 9,336 –a—— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-19 16:01 . 2008-09-19 16:01 d——– C:\Program Files\PowerISO
2008-09-19 15:53 . 2008-09-19 15:53 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-03 00:34 . 2008-09-03 00:34 d——– C:\Program Files\Combined Community Codec Pack
2008-09-02 12:23 . 2008-09-02 12:23 d——– C:\Program Files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 22:58 ——— d—–w C:\Documents and Settings\Owner\Application Data\Azureus
2008-10-28 16:44 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-10-21 18:00 ——— d—–w C:\Program Files\World of Warcraft
2008-10-21 05:03 ——— d—–w C:\Program Files\LimeWire
2008-10-17 21:41 ——— d–h–w C:\Program Files\New Folder
2008-10-17 17:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-10-15 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-02 20:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 01:35 ——— d—–w C:\Program Files\Common Files\Adobe
2008-09-19 23:10 43,528 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-09-19 22:53 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:30 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-19 17:29 3,222 —-a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-08-14 10:09 2,145,280 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-19 05:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(4).dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(3).dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-04 04:05 593,920 —-a-w C:\WINDOWS\system32\ati2sgag.exe
2008-07-04 03:48 9,490,432 —-a-w C:\WINDOWS\system32\atioglx2.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2008-07-04 03:14 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-07-04 03:14 184,320 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2008-07-04 03:14 143,360 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2008-07-04 03:13 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2008-07-04 03:12 561,152 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2008-07-04 03:10 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-07-04 03:06 253,952 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\system32\ati3duag.dll
2008-07-04 02:55 307,200 —-a-w C:\WINDOWS\system32\atiiiexx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2008-07-04 02:34 48,640 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2008-07-04 02:30 348,160 —-a-w C:\WINDOWS\system32\atikvmag.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\system32\atiadlxx.dll
2008-07-04 02:28 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2008-07-04 02:25 5,439,488 —-a-w C:\WINDOWS\system32\atioglxx.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\system32\ati2cqag.dll
.
——- Sigcheck ——-
2004-08-04 12:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\system32\svchost.exe
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2007-03-08 08:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2004-08-04 12:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\ServicePackFiles\i386\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\user32.dll
2008-10-30 12:08 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 12:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\system32\ws2_32.dll
2006-06-23 04:25 664576 64ce26db72810b30f7855ea51e1df836 C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll
2006-09-14 01:31 664576 d207370287cf769aebebf03837784963 C:\WINDOWS\$hf_mig$\KB922760\SP2QFE\wininet.dll
2006-10-23 08:34 664576 231ef4179acabe486376b5ca893f1076 C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\wininet.dll
2007-01-04 07:05 665088 3ffa1573fc274e5aa7467d03941c45ee C:\WINDOWS\$hf_mig$\KB928090\SP2QFE\wininet.dll
2007-02-20 02:52 665600 b258c922d22deec880b60720531d7627 C:\WINDOWS\$hf_mig$\KB931768\SP2QFE\wininet.dll
2007-04-18 05:46 665600 4261ba03afd659de04f0a17dfbdd454d C:\WINDOWS\$hf_mig$\KB933566\SP2QFE\wininet.dll
2007-06-26 07:35 665600 e1a3dd68b5380b360a7310a64d9bb188 C:\WINDOWS\$hf_mig$\KB937143\SP2QFE\wininet.dll
2007-08-22 05:55 665600 a1bc17eb3758d73c3938b2318820f5b4 C:\WINDOWS\$hf_mig$\KB939653\SP2QFE\wininet.dll
2007-10-10 22:57 666112 80d660a49e0d118144423099b2a9f5da C:\WINDOWS\$hf_mig$\KB942615\SP2QFE\wininet.dll
2007-12-06 17:44 666112 085a7c37f9c6ede1ba870b7dbec06399 C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\wininet.dll
2008-02-16 02:32 666112 bb1eacd6ab47e78ebca02eb781550d55 C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
2008-04-20 23:56 666624 2e7de1bf9418b071799eb53de8cc22f5 C:\WINDOWS\$hf_mig$\KB950759\SP2QFE\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$hf_mig$\KB950759\SP3GDR\wininet.dll
2008-04-20 23:24 666624 26f240c250e5b4b395cb4b178ba75437 C:\WINDOWS\$hf_mig$\KB950759\SP3QFE\wininet.dll
2008-06-23 09:12 667136 611ace3f4201e9610af8452f7c268995 C:\WINDOWS\$hf_mig$\KB953838\SP2QFE\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\wininet.dll
2008-06-23 07:54 666624 972299b7241ec325d8c7e5638c884925 C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\wininet.dll
2008-08-19 21:58 666624 94418f53d2612c26dbadc04dafbc197c C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\wininet.dll
2008-06-23 08:38 659456 9eea04bc4c3fa521d256d89940fab4db C:\WINDOWS\$NtServicePackUninstall$\wininet.dll
2004-08-04 12:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
2006-06-23 04:02 658944 2b4db890936430c71419037039502752 C:\WINDOWS\$NtUninstallKB922760$\wininet.dll
2006-09-14 01:39 658944 621af3f6174a3f60677f5230e28bcc07 C:\WINDOWS\$NtUninstallKB925454$\wininet.dll
2006-10-23 08:17 658944 6b2735adff5a5d3b9130ca4a794722f0 C:\WINDOWS\$NtUninstallKB928090$\wininet.dll
2007-01-04 06:37 658944 8c393df5234cbcbff1ee31902d6b40ae C:\WINDOWS\$NtUninstallKB931768$\wininet.dll
2007-02-20 02:48 658944 30d1c47e40efbb792ff8d3c3b51ce507 C:\WINDOWS\$NtUninstallKB933566$\wininet.dll
2007-04-18 05:31 658944 b7156cd97e739f3014bc4d61758f868a C:\WINDOWS\$NtUninstallKB937143$\wininet.dll
2007-06-26 07:09 658944 184e47c8f7b331025e6dc92740db188f C:\WINDOWS\$NtUninstallKB939653$\wininet.dll
2007-08-22 06:12 658944 1901ad51da8be9f8b38d5d526e5d1788 C:\WINDOWS\$NtUninstallKB942615$\wininet.dll
2007-10-10 23:13 659456 2005ad86a22aee68e21ee59f9ccb77f2 C:\WINDOWS\$NtUninstallKB944533$\wininet.dll
2007-12-06 18:07 659456 57d1b5150cf6331fac6b3e04c1fcb966 C:\WINDOWS\$NtUninstallKB947864$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\$NtUninstallKB950759$\wininet.dll
2008-02-16 01:59 659456 0c690e77c0e924c45b4d7045b182fff1 C:\WINDOWS\$NtUninstallKB950759_0$\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$NtUninstallKB953838$\wininet.dll
2008-04-21 00:04 659456 1efb8a3ea8454aec1bb8a240a2845598 C:\WINDOWS\$NtUninstallKB953838_0$\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$NtUninstallKB956390$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\dllcache\wininet.dll
2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 12:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 12:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\system32\winlogon.exe
2004-08-04 12:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\ServicePackFiles\i386\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 12:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 09:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 02:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2007-02-28 01:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-03 22:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 17:34 2015232 3cd941e472ddf3534e53038535719771 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 05:55 2015744 bbb2322eb14ad9ad55b1024ffd4d88bf C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2008-04-13 11:31 2023936 7f653a89f6e89e3ae0d49830eece35d4 C:\WINDOWS\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 11:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-08-14 02:33 2023936 8206b5f94a6a9450e934029420c1693f C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2004-08-03 15:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 18:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 09:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 02:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2007-02-28 02:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-03 23:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 17:57 2135552 48b3e89af7074cee0314a3e0c7faffdb C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 07:15 2136064 8318ed54797f3e513fd5817a1d4bbd18 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2008-04-13 12:24 2145280 40f8880122a030a7e9e1fedea833b33d C:\WINDOWS\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2008-04-13 12:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-08-14 03:09 2145280 f6f8245b3a2e9ca834dd318e7ae0c6d0 C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2004-08-04 12:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntoskrnl.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\explorer.exe
2007-06-13 04:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2004-08-04 12:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\$NtServicePackUninstall$\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\ServicePackFiles\i386\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\system32\services.exe
2004-08-04 12:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\ServicePackFiles\i386\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\system32\lsass.exe
2004-08-04 12:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\system32\ctfmon.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 16:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 12:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\system32\spoolsv.exe
2004-08-04 12:00 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\system32\userinit.exe
2004-08-04 12:00 295424 b60c877d16d9c880b952fda04adf16e6 C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 35328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-10-16 590848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 67488]
"SDFix"="C:\SDFix\RunThis.bat" [2008-10-26 918612]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-03 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
OKI LPR Utility.lnk - C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe [2006-11-21 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 16:54:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-30 16:55:40
ComboFix-quarantined-files.txt 2008-10-30 23:55:24
ComboFix2.txt 2008-10-30 23:40:30
ComboFix3.txt 2008-05-05 21:13:08
Pre-Run: 118,835,163,136 bytes free
Post-Run: 118,823,907,328 bytes free
309 — E O F — 2008-10-24 20:18:02
New Combofix log
ComboFix 08-10-30.09 - Owner 2008-10-30 16:53:06.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.515 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\piguhykovo.sys
C:\Documents and Settings\Owner\Application Data\myqulitav.exe
C:\Program Files\Common Files\devybugaxe.dll
C:\Program Files\Common Files\ezybizu.bat
C:\Program Files\Common Files\uqaxuco.exe
C:\Program Files\Common Files\wypylar.dll
C:\WINDOWS\awyzymih.bin
C:\WINDOWS\fanubupeje.lib
C:\WINDOWS\ilusojylu.dll
C:\WINDOWS\inuxawikov._dl
C:\WINDOWS\kuceqoci.db
C:\WINDOWS\lutep.lib
C:\WINDOWS\omun.exe
C:\WINDOWS\oxoxax.ban
C:\WINDOWS\system32\fabodypyk.dat
C:\WINDOWS\system32\gevuf.dl
C:\WINDOWS\system32\guohmubg.dll
C:\WINDOWS\system32\reryf.sys
C:\WINDOWS\system32\yxsswf.dll
C:\WINDOWS\uqyteriq.sys
C:\WINDOWS\vawaqota.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
2008-10-30 16:20 . 2008-10-30 16:20 d——– C:\_OTMoveIt
2008-10-30 16:07 . 2008-10-30 16:09 d——– C:\Lop SD
2008-10-30 12:08 . 2008-10-30 12:08 578,560 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-10-30 12:02 . 2008-10-30 12:03 d——– C:\WINDOWS\ERUNT
2008-10-30 11:57 . 2008-10-30 12:18 d——– C:\SDFix
2008-10-29 21:57 . 2008-10-29 21:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 21:57 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 21:57 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-29 21:56 . 2008-10-29 21:56 d——– C:\Program Files\ERUNT
2008-10-29 21:19 . 2008-10-29 21:19 d——– C:\Program Files\Trend Micro
2008-10-29 18:45 . 2008-10-29 18:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-29 18:45 . 2008-10-29 18:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-24 09:06 . 2008-10-15 09:34 337,408 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 10:29 . 2008-08-14 03:11 2,189,184 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 10:29 . 2008-08-14 03:09 2,145,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,066,048 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,023,936 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 10:29 . 2008-09-15 05:12 1,846,400 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 10:29 . 2008-09-08 03:41 333,824 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 11:33 . 2008-10-14 11:33 d——– C:\Documents and Settings\All Users\Application Data\Blizzard
2008-09-19 19:00 . 2008-09-19 19:00 d——– C:\Documents and Settings\All Users\Application Data\ALM
2008-09-19 18:36 . 2008-09-19 18:36 d——– C:\Program Files\Bonjour
2008-09-19 16:23 . 2008-09-19 16:23 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2008-09-19 16:20 . 2008-09-19 16:20 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-19 16:16 . 2008-09-19 16:16 d——– C:\Program Files\Common Files\Macrovision Shared
2008-09-19 16:11 . 2008-09-19 16:10 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-09-19 16:11 . 2008-09-19 16:10 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 9,464 –a—— C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-19 16:11 . 2008-09-19 16:10 9,336 –a—— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-19 16:01 . 2008-09-19 16:01 d——– C:\Program Files\PowerISO
2008-09-19 15:53 . 2008-09-19 15:53 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-03 00:34 . 2008-09-03 00:34 d——– C:\Program Files\Combined Community Codec Pack
2008-09-02 12:23 . 2008-09-02 12:23 d——– C:\Program Files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 22:58 ——— d—–w C:\Documents and Settings\Owner\Application Data\Azureus
2008-10-28 16:44 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-10-21 18:00 ——— d—–w C:\Program Files\World of Warcraft
2008-10-21 05:03 ——— d—–w C:\Program Files\LimeWire
2008-10-17 21:41 ——— d–h–w C:\Program Files\New Folder
2008-10-17 17:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-10-15 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-02 20:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 01:35 ——— d—–w C:\Program Files\Common Files\Adobe
2008-09-19 23:10 43,528 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-09-19 22:53 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:30 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-19 17:29 3,222 —-a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-08-14 10:09 2,145,280 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-19 05:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(4).dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(3).dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-04 04:05 593,920 —-a-w C:\WINDOWS\system32\ati2sgag.exe
2008-07-04 03:48 9,490,432 —-a-w C:\WINDOWS\system32\atioglx2.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2008-07-04 03:14 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-07-04 03:14 184,320 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2008-07-04 03:14 143,360 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2008-07-04 03:13 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2008-07-04 03:12 561,152 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2008-07-04 03:10 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-07-04 03:06 253,952 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\system32\ati3duag.dll
2008-07-04 02:55 307,200 —-a-w C:\WINDOWS\system32\atiiiexx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2008-07-04 02:34 48,640 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2008-07-04 02:30 348,160 —-a-w C:\WINDOWS\system32\atikvmag.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\system32\atiadlxx.dll
2008-07-04 02:28 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2008-07-04 02:25 5,439,488 —-a-w C:\WINDOWS\system32\atioglxx.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\system32\ati2cqag.dll
.
——- Sigcheck ——-
2004-08-04 12:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\system32\svchost.exe
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2007-03-08 08:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2004-08-04 12:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\ServicePackFiles\i386\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\user32.dll
2008-10-30 12:08 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 12:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\system32\ws2_32.dll
2006-06-23 04:25 664576 64ce26db72810b30f7855ea51e1df836 C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll
2006-09-14 01:31 664576 d207370287cf769aebebf03837784963 C:\WINDOWS\$hf_mig$\KB922760\SP2QFE\wininet.dll
2006-10-23 08:34 664576 231ef4179acabe486376b5ca893f1076 C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\wininet.dll
2007-01-04 07:05 665088 3ffa1573fc274e5aa7467d03941c45ee C:\WINDOWS\$hf_mig$\KB928090\SP2QFE\wininet.dll
2007-02-20 02:52 665600 b258c922d22deec880b60720531d7627 C:\WINDOWS\$hf_mig$\KB931768\SP2QFE\wininet.dll
2007-04-18 05:46 665600 4261ba03afd659de04f0a17dfbdd454d C:\WINDOWS\$hf_mig$\KB933566\SP2QFE\wininet.dll
2007-06-26 07:35 665600 e1a3dd68b5380b360a7310a64d9bb188 C:\WINDOWS\$hf_mig$\KB937143\SP2QFE\wininet.dll
2007-08-22 05:55 665600 a1bc17eb3758d73c3938b2318820f5b4 C:\WINDOWS\$hf_mig$\KB939653\SP2QFE\wininet.dll
2007-10-10 22:57 666112 80d660a49e0d118144423099b2a9f5da C:\WINDOWS\$hf_mig$\KB942615\SP2QFE\wininet.dll
2007-12-06 17:44 666112 085a7c37f9c6ede1ba870b7dbec06399 C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\wininet.dll
2008-02-16 02:32 666112 bb1eacd6ab47e78ebca02eb781550d55 C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
2008-04-20 23:56 666624 2e7de1bf9418b071799eb53de8cc22f5 C:\WINDOWS\$hf_mig$\KB950759\SP2QFE\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$hf_mig$\KB950759\SP3GDR\wininet.dll
2008-04-20 23:24 666624 26f240c250e5b4b395cb4b178ba75437 C:\WINDOWS\$hf_mig$\KB950759\SP3QFE\wininet.dll
2008-06-23 09:12 667136 611ace3f4201e9610af8452f7c268995 C:\WINDOWS\$hf_mig$\KB953838\SP2QFE\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\wininet.dll
2008-06-23 07:54 666624 972299b7241ec325d8c7e5638c884925 C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\wininet.dll
2008-08-19 21:58 666624 94418f53d2612c26dbadc04dafbc197c C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\wininet.dll
2008-06-23 08:38 659456 9eea04bc4c3fa521d256d89940fab4db C:\WINDOWS\$NtServicePackUninstall$\wininet.dll
2004-08-04 12:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
2006-06-23 04:02 658944 2b4db890936430c71419037039502752 C:\WINDOWS\$NtUninstallKB922760$\wininet.dll
2006-09-14 01:39 658944 621af3f6174a3f60677f5230e28bcc07 C:\WINDOWS\$NtUninstallKB925454$\wininet.dll
2006-10-23 08:17 658944 6b2735adff5a5d3b9130ca4a794722f0 C:\WINDOWS\$NtUninstallKB928090$\wininet.dll
2007-01-04 06:37 658944 8c393df5234cbcbff1ee31902d6b40ae C:\WINDOWS\$NtUninstallKB931768$\wininet.dll
2007-02-20 02:48 658944 30d1c47e40efbb792ff8d3c3b51ce507 C:\WINDOWS\$NtUninstallKB933566$\wininet.dll
2007-04-18 05:31 658944 b7156cd97e739f3014bc4d61758f868a C:\WINDOWS\$NtUninstallKB937143$\wininet.dll
2007-06-26 07:09 658944 184e47c8f7b331025e6dc92740db188f C:\WINDOWS\$NtUninstallKB939653$\wininet.dll
2007-08-22 06:12 658944 1901ad51da8be9f8b38d5d526e5d1788 C:\WINDOWS\$NtUninstallKB942615$\wininet.dll
2007-10-10 23:13 659456 2005ad86a22aee68e21ee59f9ccb77f2 C:\WINDOWS\$NtUninstallKB944533$\wininet.dll
2007-12-06 18:07 659456 57d1b5150cf6331fac6b3e04c1fcb966 C:\WINDOWS\$NtUninstallKB947864$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\$NtUninstallKB950759$\wininet.dll
2008-02-16 01:59 659456 0c690e77c0e924c45b4d7045b182fff1 C:\WINDOWS\$NtUninstallKB950759_0$\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$NtUninstallKB953838$\wininet.dll
2008-04-21 00:04 659456 1efb8a3ea8454aec1bb8a240a2845598 C:\WINDOWS\$NtUninstallKB953838_0$\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$NtUninstallKB956390$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\dllcache\wininet.dll
2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 12:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 12:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\system32\winlogon.exe
2004-08-04 12:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\ServicePackFiles\i386\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 12:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 09:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 02:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2007-02-28 01:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-03 22:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 17:34 2015232 3cd941e472ddf3534e53038535719771 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 05:55 2015744 bbb2322eb14ad9ad55b1024ffd4d88bf C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2008-04-13 11:31 2023936 7f653a89f6e89e3ae0d49830eece35d4 C:\WINDOWS\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 11:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-08-14 02:33 2023936 8206b5f94a6a9450e934029420c1693f C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2004-08-03 15:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 18:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 09:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 02:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2007-02-28 02:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-03 23:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 17:57 2135552 48b3e89af7074cee0314a3e0c7faffdb C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 07:15 2136064 8318ed54797f3e513fd5817a1d4bbd18 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2008-04-13 12:24 2145280 40f8880122a030a7e9e1fedea833b33d C:\WINDOWS\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2008-04-13 12:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-08-14 03:09 2145280 f6f8245b3a2e9ca834dd318e7ae0c6d0 C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2004-08-04 12:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntoskrnl.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\explorer.exe
2007-06-13 04:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2004-08-04 12:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\$NtServicePackUninstall$\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\ServicePackFiles\i386\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\system32\services.exe
2004-08-04 12:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\ServicePackFiles\i386\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\system32\lsass.exe
2004-08-04 12:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\system32\ctfmon.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 16:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 12:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\system32\spoolsv.exe
2004-08-04 12:00 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\system32\userinit.exe
2004-08-04 12:00 295424 b60c877d16d9c880b952fda04adf16e6 C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 35328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-10-16 590848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 67488]
"SDFix"="C:\SDFix\RunThis.bat" [2008-10-26 918612]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-03 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
OKI LPR Utility.lnk - C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe [2006-11-21 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-30 16:54:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-30 16:55:40
ComboFix-quarantined-files.txt 2008-10-30 23:55:24
ComboFix2.txt 2008-10-30 23:40:30
ComboFix3.txt 2008-05-05 21:13:08
Pre-Run: 118,835,163,136 bytes free
Post-Run: 118,823,907,328 bytes free
309 — E O F — 2008-10-24 20:18:02
Rorschach112
Hello
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Go to Kaspersky website and perform an online antivirus scan.
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
- Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Go to Kaspersky website and perform an online antivirus scan.
- Read through the requirements and privacy statement and click on Accept button.
- It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
- When the downloads have finished, click on Settings.
- Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
- Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases
- Spyware, Adware, Dialers, and other potentially dangerous programs
- Click on My Computer under Scan.
- Once the scan is complete, it will display the results. Click on View Scan Report.
- You will see a list of infected items there. Click on Save Report As….
- Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
ganjadank
Sorry the scans took awhile
Here are the MBAM and Kaspersky Logs:
Malwarebytes' Anti-Malware 1.30
Database version: 1340
Windows 5.1.2600 Service Pack 3
10/30/2008 5:08:49 PM
mbam-log-2008-10-30 (17-08-49).txt
Scan type: Quick Scan
Objects scanned: 48094
Time elapsed: 3 minute(s), 57 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, October 30, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, October 30, 2008 21:42:43
Records in database: 1362205
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Files scanned: 90691
Threat name: 6
Infected objects: 9
Suspicious objects: 0
Duration of the scan: 05:40:24
File name / Threat name / Threats count
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\figaro.sys.vir Infected: Backdoor.Win32.UltimateDefender.a 1
C:\SDFix\backups\wrdwn2 Infected: Trojan.Win32.FraudPack.grf 1
C:\SDFix\backups\wrdwn3 Infected: Trojan.Win32.Agent.akkh 1
C:\SDFix\backups\wrdwn6 Infected: not-a-virus:FraudTool.Win32.XPSecurityCenter.bf 1
E:\The Teenagers - Reality Check 2008\00-bonus_-_the_teenagers_-_reality_check_2008.exe Infected: Trojan.Win32.Monderb.sgr 1
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.m3u.exe Infected: Trojan.Win32.Monderb.sgr 1
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.nfo.exe Infected: Trojan.Win32.Monderb.sgr 1
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.sfv.exe Infected: Trojan.Win32.Monderb.sgr 1
The selected area was scanned.
Rorschach112
Hello
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
Save this as CFScript.txt, in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:
File::
E:\The Teenagers - Reality Check 2008\00-bonus_-_the_teenagers_-_reality_check_2008.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.m3u.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.nfo.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.sfv.exe
Folder::
Registry::
Driver::
Save this as CFScript.txt, in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
ganjadank
Combofix log
ComboFix 08-10-30.13 - Owner 2008-10-31 10:47:28.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.514 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
E:\The Teenagers - Reality Check 2008\00-bonus_-_the_teenagers_-_reality_check_2008.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.m3u.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.nfo.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.sfv.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\The Teenagers - Reality Check 2008\00-bonus_-_the_teenagers_-_reality_check_2008.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.m3u.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.nfo.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.sfv.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-31 )))))))))))))))))))))))))))))))
.
2008-10-30 23:35 . 2008-10-30 23:35 0 –a—— C:\WINDOWS\nsreg.dat
2008-10-30 16:20 . 2008-10-30 16:20 d——– C:\_OTMoveIt
2008-10-30 16:07 . 2008-10-30 16:09 d——– C:\Lop SD
2008-10-30 12:08 . 2008-10-30 12:08 578,560 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-10-30 12:02 . 2008-10-30 12:03 d——– C:\WINDOWS\ERUNT
2008-10-30 11:57 . 2008-10-30 12:18 d——– C:\SDFix
2008-10-29 21:57 . 2008-10-29 21:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 21:57 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 21:57 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-29 21:56 . 2008-10-29 21:56 d——– C:\Program Files\ERUNT
2008-10-29 21:19 . 2008-10-29 21:19 d——– C:\Program Files\Trend Micro
2008-10-29 18:45 . 2008-10-29 18:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-29 18:45 . 2008-10-29 18:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-24 09:06 . 2008-10-15 09:34 337,408 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 10:29 . 2008-08-14 03:11 2,189,184 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 10:29 . 2008-08-14 03:09 2,145,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,066,048 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,023,936 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 10:29 . 2008-09-15 05:12 1,846,400 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 10:29 . 2008-09-08 03:41 333,824 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 11:33 . 2008-10-14 11:33 d——– C:\Documents and Settings\All Users\Application Data\Blizzard
2008-09-19 19:00 . 2008-09-19 19:00 d——– C:\Documents and Settings\All Users\Application Data\ALM
2008-09-19 18:36 . 2008-09-19 18:36 d——– C:\Program Files\Bonjour
2008-09-19 16:23 . 2008-09-19 16:23 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2008-09-19 16:20 . 2008-09-19 16:20 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-19 16:16 . 2008-09-19 16:16 d——– C:\Program Files\Common Files\Macrovision Shared
2008-09-19 16:11 . 2008-09-19 16:10 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-09-19 16:11 . 2008-09-19 16:10 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 9,464 –a—— C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-19 16:11 . 2008-09-19 16:10 9,336 –a—— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-19 16:01 . 2008-09-19 16:01 d——– C:\Program Files\PowerISO
2008-09-19 15:53 . 2008-09-19 15:53 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-03 00:34 . 2008-09-03 00:34 d——– C:\Program Files\Combined Community Codec Pack
2008-09-02 12:23 . 2008-09-02 12:23 d——– C:\Program Files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 07:21 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-10-28 22:58 ——— d—–w C:\Documents and Settings\Owner\Application Data\Azureus
2008-10-21 18:00 ——— d—–w C:\Program Files\World of Warcraft
2008-10-21 05:03 ——— d—–w C:\Program Files\LimeWire
2008-10-17 21:41 ——— d–h–w C:\Program Files\New Folder
2008-10-17 17:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-10-15 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-02 20:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 01:35 ——— d—–w C:\Program Files\Common Files\Adobe
2008-09-19 23:10 43,528 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-09-19 22:53 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:30 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-19 17:29 3,222 —-a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-08-14 10:09 2,145,280 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-19 05:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(4).dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(3).dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-04 04:05 593,920 —-a-w C:\WINDOWS\system32\ati2sgag.exe
2008-07-04 03:48 9,490,432 —-a-w C:\WINDOWS\system32\atioglx2.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2008-07-04 03:14 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-07-04 03:14 184,320 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2008-07-04 03:14 143,360 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2008-07-04 03:13 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2008-07-04 03:12 561,152 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2008-07-04 03:10 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-07-04 03:06 253,952 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\system32\ati3duag.dll
2008-07-04 02:55 307,200 —-a-w C:\WINDOWS\system32\atiiiexx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2008-07-04 02:34 48,640 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2008-07-04 02:30 348,160 —-a-w C:\WINDOWS\system32\atikvmag.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\system32\atiadlxx.dll
2008-07-04 02:28 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2008-07-04 02:25 5,439,488 —-a-w C:\WINDOWS\system32\atioglxx.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\system32\ati2cqag.dll
.
——- Sigcheck ——-
2004-08-04 12:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\system32\svchost.exe
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2007-03-08 08:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2004-08-04 12:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\ServicePackFiles\i386\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\user32.dll
2008-10-30 12:08 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 12:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\system32\ws2_32.dll
2006-06-23 04:25 664576 64ce26db72810b30f7855ea51e1df836 C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll
2006-09-14 01:31 664576 d207370287cf769aebebf03837784963 C:\WINDOWS\$hf_mig$\KB922760\SP2QFE\wininet.dll
2006-10-23 08:34 664576 231ef4179acabe486376b5ca893f1076 C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\wininet.dll
2007-01-04 07:05 665088 3ffa1573fc274e5aa7467d03941c45ee C:\WINDOWS\$hf_mig$\KB928090\SP2QFE\wininet.dll
2007-02-20 02:52 665600 b258c922d22deec880b60720531d7627 C:\WINDOWS\$hf_mig$\KB931768\SP2QFE\wininet.dll
2007-04-18 05:46 665600 4261ba03afd659de04f0a17dfbdd454d C:\WINDOWS\$hf_mig$\KB933566\SP2QFE\wininet.dll
2007-06-26 07:35 665600 e1a3dd68b5380b360a7310a64d9bb188 C:\WINDOWS\$hf_mig$\KB937143\SP2QFE\wininet.dll
2007-08-22 05:55 665600 a1bc17eb3758d73c3938b2318820f5b4 C:\WINDOWS\$hf_mig$\KB939653\SP2QFE\wininet.dll
2007-10-10 22:57 666112 80d660a49e0d118144423099b2a9f5da C:\WINDOWS\$hf_mig$\KB942615\SP2QFE\wininet.dll
2007-12-06 17:44 666112 085a7c37f9c6ede1ba870b7dbec06399 C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\wininet.dll
2008-02-16 02:32 666112 bb1eacd6ab47e78ebca02eb781550d55 C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
2008-04-20 23:56 666624 2e7de1bf9418b071799eb53de8cc22f5 C:\WINDOWS\$hf_mig$\KB950759\SP2QFE\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$hf_mig$\KB950759\SP3GDR\wininet.dll
2008-04-20 23:24 666624 26f240c250e5b4b395cb4b178ba75437 C:\WINDOWS\$hf_mig$\KB950759\SP3QFE\wininet.dll
2008-06-23 09:12 667136 611ace3f4201e9610af8452f7c268995 C:\WINDOWS\$hf_mig$\KB953838\SP2QFE\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\wininet.dll
2008-06-23 07:54 666624 972299b7241ec325d8c7e5638c884925 C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\wininet.dll
2008-08-19 21:58 666624 94418f53d2612c26dbadc04dafbc197c C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\wininet.dll
2008-06-23 08:38 659456 9eea04bc4c3fa521d256d89940fab4db C:\WINDOWS\$NtServicePackUninstall$\wininet.dll
2004-08-04 12:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
2006-06-23 04:02 658944 2b4db890936430c71419037039502752 C:\WINDOWS\$NtUninstallKB922760$\wininet.dll
2006-09-14 01:39 658944 621af3f6174a3f60677f5230e28bcc07 C:\WINDOWS\$NtUninstallKB925454$\wininet.dll
2006-10-23 08:17 658944 6b2735adff5a5d3b9130ca4a794722f0 C:\WINDOWS\$NtUninstallKB928090$\wininet.dll
2007-01-04 06:37 658944 8c393df5234cbcbff1ee31902d6b40ae C:\WINDOWS\$NtUninstallKB931768$\wininet.dll
2007-02-20 02:48 658944 30d1c47e40efbb792ff8d3c3b51ce507 C:\WINDOWS\$NtUninstallKB933566$\wininet.dll
2007-04-18 05:31 658944 b7156cd97e739f3014bc4d61758f868a C:\WINDOWS\$NtUninstallKB937143$\wininet.dll
2007-06-26 07:09 658944 184e47c8f7b331025e6dc92740db188f C:\WINDOWS\$NtUninstallKB939653$\wininet.dll
2007-08-22 06:12 658944 1901ad51da8be9f8b38d5d526e5d1788 C:\WINDOWS\$NtUninstallKB942615$\wininet.dll
2007-10-10 23:13 659456 2005ad86a22aee68e21ee59f9ccb77f2 C:\WINDOWS\$NtUninstallKB944533$\wininet.dll
2007-12-06 18:07 659456 57d1b5150cf6331fac6b3e04c1fcb966 C:\WINDOWS\$NtUninstallKB947864$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\$NtUninstallKB950759$\wininet.dll
2008-02-16 01:59 659456 0c690e77c0e924c45b4d7045b182fff1 C:\WINDOWS\$NtUninstallKB950759_0$\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$NtUninstallKB953838$\wininet.dll
2008-04-21 00:04 659456 1efb8a3ea8454aec1bb8a240a2845598 C:\WINDOWS\$NtUninstallKB953838_0$\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$NtUninstallKB956390$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\dllcache\wininet.dll
2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 12:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 12:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\system32\winlogon.exe
2004-08-04 12:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\ServicePackFiles\i386\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 12:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 09:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 02:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2007-02-28 01:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-03 22:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 17:34 2015232 3cd941e472ddf3534e53038535719771 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 05:55 2015744 bbb2322eb14ad9ad55b1024ffd4d88bf C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2008-04-13 11:31 2023936 7f653a89f6e89e3ae0d49830eece35d4 C:\WINDOWS\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 11:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-08-14 02:33 2023936 8206b5f94a6a9450e934029420c1693f C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2004-08-03 15:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 18:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 09:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 02:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2007-02-28 02:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-03 23:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 17:57 2135552 48b3e89af7074cee0314a3e0c7faffdb C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 07:15 2136064 8318ed54797f3e513fd5817a1d4bbd18 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2008-04-13 12:24 2145280 40f8880122a030a7e9e1fedea833b33d C:\WINDOWS\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2008-04-13 12:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-08-14 03:09 2145280 f6f8245b3a2e9ca834dd318e7ae0c6d0 C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2004-08-04 12:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntoskrnl.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\explorer.exe
2007-06-13 04:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2004-08-04 12:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\$NtServicePackUninstall$\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\ServicePackFiles\i386\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\system32\services.exe
2004-08-04 12:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\ServicePackFiles\i386\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\system32\lsass.exe
2004-08-04 12:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\system32\ctfmon.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 16:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 12:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\system32\spoolsv.exe
2004-08-04 12:00 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\system32\userinit.exe
2004-08-04 12:00 295424 b60c877d16d9c880b952fda04adf16e6 C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\system32\termsrv.dll
.
((((((((((((((((((((((((((((( snapshot@2008-10-30_16.39.04.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-06-11 20:34:36 2,115,816 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-05 03:24:02 3,695,008 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
- 2007-06-11 20:04:38 190,696 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-10-05 03:24:04 235,936 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-10-31 07:18:59 84,661 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 35328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-10-16 590848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 67488]
"SDFix"="C:\SDFix\RunThis.bat" [2008-10-26 918612]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-03 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
OKI LPR Utility.lnk - C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe [2006-11-21 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyyYpp]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
.
- - - - ORPHANS REMOVED - - - -
BHO-{53CDB936-7A8D-4B44-9B7B-70525D0C9D50} - (no file)
BHO-{6839DB84-A6EC-4E8B-9320-2C6E98A3C27C} - (no file)
BHO-{A32BF1D3-1110-4507-8F5E-235E0586F08C} - (no file)
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-31 10:50:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-31 10:52:31
ComboFix-quarantined-files.txt 2008-10-31 17:51:59
ComboFix2.txt 2008-10-30 23:55:41
ComboFix3.txt 2008-10-30 23:40:30
ComboFix4.txt 2008-05-05 21:13:08
Pre-Run: 117,839,216,640 bytes free
Post-Run: 118,492,729,344 bytes free
311 — E O F — 2008-10-24 20:18:02
ComboFix 08-10-30.13 - Owner 2008-10-31 10:47:28.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.514 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
E:\The Teenagers - Reality Check 2008\00-bonus_-_the_teenagers_-_reality_check_2008.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.m3u.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.nfo.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.sfv.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\The Teenagers - Reality Check 2008\00-bonus_-_the_teenagers_-_reality_check_2008.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.m3u.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.nfo.exe
E:\The Teenagers - Reality Check 2008\00-the_teenagers_-_reality_check_2008.sfv.exe
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-31 )))))))))))))))))))))))))))))))
.
2008-10-30 23:35 . 2008-10-30 23:35 0 –a—— C:\WINDOWS\nsreg.dat
2008-10-30 16:20 . 2008-10-30 16:20 d——– C:\_OTMoveIt
2008-10-30 16:07 . 2008-10-30 16:09 d——– C:\Lop SD
2008-10-30 12:08 . 2008-10-30 12:08 578,560 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-10-30 12:02 . 2008-10-30 12:03 d——– C:\WINDOWS\ERUNT
2008-10-30 11:57 . 2008-10-30 12:18 d——– C:\SDFix
2008-10-29 21:57 . 2008-10-29 21:57 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 21:57 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 21:57 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-29 21:56 . 2008-10-29 21:56 d——– C:\Program Files\ERUNT
2008-10-29 21:19 . 2008-10-29 21:19 d——– C:\Program Files\Trend Micro
2008-10-29 18:45 . 2008-10-29 18:45 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-10-29 18:45 . 2008-10-29 18:45 1,409 –a—— C:\WINDOWS\QTFont.for
2008-10-24 09:06 . 2008-10-15 09:34 337,408 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 10:29 . 2008-08-14 03:11 2,189,184 –a–c— C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 10:29 . 2008-08-14 03:09 2,145,280 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,066,048 –a–c— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 10:29 . 2008-08-14 02:33 2,023,936 –a–c— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 10:29 . 2008-09-15 05:12 1,846,400 –a–c— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 10:29 . 2008-09-08 03:41 333,824 –a–c— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 11:33 . 2008-10-14 11:33 d——– C:\Documents and Settings\All Users\Application Data\Blizzard
2008-09-19 19:00 . 2008-09-19 19:00 d——– C:\Documents and Settings\All Users\Application Data\ALM
2008-09-19 18:36 . 2008-09-19 18:36 d——– C:\Program Files\Bonjour
2008-09-19 16:23 . 2008-09-19 16:23 d——– C:\Documents and Settings\All Users\Application Data\espionServerData
2008-09-19 16:20 . 2008-09-19 16:20 d——– C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-09-19 16:16 . 2008-09-19 16:16 d——– C:\Program Files\Common Files\Macrovision Shared
2008-09-19 16:11 . 2008-09-19 16:10 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-09-19 16:11 . 2008-09-19 16:10 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 116,472 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-09-19 16:11 . 2008-09-19 16:10 9,464 –a—— C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-19 16:11 . 2008-09-19 16:10 9,336 –a—— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-19 16:01 . 2008-09-19 16:01 d——– C:\Program Files\PowerISO
2008-09-19 15:53 . 2008-09-19 15:53 d——– C:\Documents and Settings\Owner\Application Data\DAEMON Tools
2008-09-03 00:34 . 2008-09-03 00:34 d——– C:\Program Files\Combined Community Codec Pack
2008-09-02 12:23 . 2008-09-02 12:23 d——– C:\Program Files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 07:21 ——— d–h–w C:\Documents and Settings\Owner\Application Data\Move Networks
2008-10-28 22:58 ——— d—–w C:\Documents and Settings\Owner\Application Data\Azureus
2008-10-21 18:00 ——— d—–w C:\Program Files\World of Warcraft
2008-10-21 05:03 ——— d—–w C:\Program Files\LimeWire
2008-10-17 21:41 ——— d–h–w C:\Program Files\New Folder
2008-10-17 17:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-10-15 22:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-02 20:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 01:35 ——— d—–w C:\Program Files\Common Files\Adobe
2008-09-19 23:10 43,528 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-09-19 22:53 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:30 666,112 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-19 17:29 3,222 —-a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-08-14 10:09 2,145,280 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-19 05:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(4).dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es(3).dll
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-04 04:05 593,920 —-a-w C:\WINDOWS\system32\ati2sgag.exe
2008-07-04 03:48 9,490,432 —-a-w C:\WINDOWS\system32\atioglx2.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2008-07-04 03:14 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-07-04 03:14 184,320 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2008-07-04 03:14 143,360 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2008-07-04 03:13 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2008-07-04 03:12 561,152 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2008-07-04 03:10 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-07-04 03:06 253,952 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\system32\ati3duag.dll
2008-07-04 02:55 307,200 —-a-w C:\WINDOWS\system32\atiiiexx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2008-07-04 02:34 48,640 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2008-07-04 02:30 348,160 —-a-w C:\WINDOWS\system32\atikvmag.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\system32\atiadlxx.dll
2008-07-04 02:28 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2008-07-04 02:25 5,439,488 —-a-w C:\WINDOWS\system32\atioglxx.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\system32\ati2cqag.dll
.
——- Sigcheck ——-
2004-08-04 12:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-04-13 17:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 C:\WINDOWS\system32\svchost.exe
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2007-03-08 08:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2004-08-04 12:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\ServicePackFiles\i386\user32.dll
2008-04-13 17:12 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\user32.dll
2008-10-30 12:08 578560 b26b135ff1b9f60c9388b4a7d16f600b C:\WINDOWS\system32\dllcache\user32.dll
2004-08-04 12:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
2008-04-13 17:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a C:\WINDOWS\system32\ws2_32.dll
2006-06-23 04:25 664576 64ce26db72810b30f7855ea51e1df836 C:\WINDOWS\$hf_mig$\KB918899\SP2QFE\wininet.dll
2006-09-14 01:31 664576 d207370287cf769aebebf03837784963 C:\WINDOWS\$hf_mig$\KB922760\SP2QFE\wininet.dll
2006-10-23 08:34 664576 231ef4179acabe486376b5ca893f1076 C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\wininet.dll
2007-01-04 07:05 665088 3ffa1573fc274e5aa7467d03941c45ee C:\WINDOWS\$hf_mig$\KB928090\SP2QFE\wininet.dll
2007-02-20 02:52 665600 b258c922d22deec880b60720531d7627 C:\WINDOWS\$hf_mig$\KB931768\SP2QFE\wininet.dll
2007-04-18 05:46 665600 4261ba03afd659de04f0a17dfbdd454d C:\WINDOWS\$hf_mig$\KB933566\SP2QFE\wininet.dll
2007-06-26 07:35 665600 e1a3dd68b5380b360a7310a64d9bb188 C:\WINDOWS\$hf_mig$\KB937143\SP2QFE\wininet.dll
2007-08-22 05:55 665600 a1bc17eb3758d73c3938b2318820f5b4 C:\WINDOWS\$hf_mig$\KB939653\SP2QFE\wininet.dll
2007-10-10 22:57 666112 80d660a49e0d118144423099b2a9f5da C:\WINDOWS\$hf_mig$\KB942615\SP2QFE\wininet.dll
2007-12-06 17:44 666112 085a7c37f9c6ede1ba870b7dbec06399 C:\WINDOWS\$hf_mig$\KB944533\SP2QFE\wininet.dll
2008-02-16 02:32 666112 bb1eacd6ab47e78ebca02eb781550d55 C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
2008-04-20 23:56 666624 2e7de1bf9418b071799eb53de8cc22f5 C:\WINDOWS\$hf_mig$\KB950759\SP2QFE\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$hf_mig$\KB950759\SP3GDR\wininet.dll
2008-04-20 23:24 666624 26f240c250e5b4b395cb4b178ba75437 C:\WINDOWS\$hf_mig$\KB950759\SP3QFE\wininet.dll
2008-06-23 09:12 667136 611ace3f4201e9610af8452f7c268995 C:\WINDOWS\$hf_mig$\KB953838\SP2QFE\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\wininet.dll
2008-06-23 07:54 666624 972299b7241ec325d8c7e5638c884925 C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\wininet.dll
2008-08-19 21:58 666624 94418f53d2612c26dbadc04dafbc197c C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\wininet.dll
2008-06-23 08:38 659456 9eea04bc4c3fa521d256d89940fab4db C:\WINDOWS\$NtServicePackUninstall$\wininet.dll
2004-08-04 12:00 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
2006-06-23 04:02 658944 2b4db890936430c71419037039502752 C:\WINDOWS\$NtUninstallKB922760$\wininet.dll
2006-09-14 01:39 658944 621af3f6174a3f60677f5230e28bcc07 C:\WINDOWS\$NtUninstallKB925454$\wininet.dll
2006-10-23 08:17 658944 6b2735adff5a5d3b9130ca4a794722f0 C:\WINDOWS\$NtUninstallKB928090$\wininet.dll
2007-01-04 06:37 658944 8c393df5234cbcbff1ee31902d6b40ae C:\WINDOWS\$NtUninstallKB931768$\wininet.dll
2007-02-20 02:48 658944 30d1c47e40efbb792ff8d3c3b51ce507 C:\WINDOWS\$NtUninstallKB933566$\wininet.dll
2007-04-18 05:31 658944 b7156cd97e739f3014bc4d61758f868a C:\WINDOWS\$NtUninstallKB937143$\wininet.dll
2007-06-26 07:09 658944 184e47c8f7b331025e6dc92740db188f C:\WINDOWS\$NtUninstallKB939653$\wininet.dll
2007-08-22 06:12 658944 1901ad51da8be9f8b38d5d526e5d1788 C:\WINDOWS\$NtUninstallKB942615$\wininet.dll
2007-10-10 23:13 659456 2005ad86a22aee68e21ee59f9ccb77f2 C:\WINDOWS\$NtUninstallKB944533$\wininet.dll
2007-12-06 18:07 659456 57d1b5150cf6331fac6b3e04c1fcb966 C:\WINDOWS\$NtUninstallKB947864$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\$NtUninstallKB950759$\wininet.dll
2008-02-16 01:59 659456 0c690e77c0e924c45b4d7045b182fff1 C:\WINDOWS\$NtUninstallKB950759_0$\wininet.dll
2008-04-20 23:44 666112 2b0c24aa747a93a28987b6d65a4a74bc C:\WINDOWS\$NtUninstallKB953838$\wininet.dll
2008-04-21 00:04 659456 1efb8a3ea8454aec1bb8a240a2845598 C:\WINDOWS\$NtUninstallKB953838_0$\wininet.dll
2008-06-23 08:09 666112 f12fbb673de9cc802c5dc518fe99aa2f C:\WINDOWS\$NtUninstallKB956390$\wininet.dll
2008-04-13 17:12 666112 7a4f775abb2f1c97def3e73afa2faedd C:\WINDOWS\ServicePackFiles\i386\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\wininet.dll
2008-08-19 22:30 666112 9af5f25124fbdc36e2b510729cba2674 C:\WINDOWS\system32\dllcache\wininet.dll
2006-04-20 05:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 03:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 04:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 03:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 12:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 04:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 12:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 04:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 12:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2008-04-13 17:12 507904 ed0ef0a136dec83df69f04118870003e C:\WINDOWS\system32\winlogon.exe
2004-08-04 12:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\ServicePackFiles\i386\ndis.sys
2008-04-13 12:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 12:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 09:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 02:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2007-02-28 01:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-03 22:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 17:34 2015232 3cd941e472ddf3534e53038535719771 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 05:55 2015744 bbb2322eb14ad9ad55b1024ffd4d88bf C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2008-04-13 11:31 2023936 7f653a89f6e89e3ae0d49830eece35d4 C:\WINDOWS\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 11:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2008-08-14 02:33 2023936 8206b5f94a6a9450e934029420c1693f C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 02:33 2066048 4ac58f03eb94a72809949d757fc39d80 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2004-08-03 15:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 18:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 09:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 02:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2007-02-28 02:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-03 23:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 17:57 2135552 48b3e89af7074cee0314a3e0c7faffdb C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 07:15 2136064 8318ed54797f3e513fd5817a1d4bbd18 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2008-04-13 12:24 2145280 40f8880122a030a7e9e1fedea833b33d C:\WINDOWS\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2008-04-13 12:27 2188928 0c89243c7c3ee199b96fcc16990e0679 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2008-08-14 03:09 2145280 f6f8245b3a2e9ca834dd318e7ae0c6d0 C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 03:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2004-08-04 12:00 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\ntoskrnl.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\explorer.exe
2007-06-13 04:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 03:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\$NtServicePackUninstall$\explorer.exe
2004-08-04 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 17:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 C:\WINDOWS\ServicePackFiles\i386\explorer.exe
2004-08-04 12:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\$NtServicePackUninstall$\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\ServicePackFiles\i386\services.exe
2008-04-13 17:12 108544 0e776ed5f7cc9f94299e70461b7b8185 C:\WINDOWS\system32\services.exe
2004-08-04 12:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\ServicePackFiles\i386\lsass.exe
2008-04-13 17:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 C:\WINDOWS\system32\lsass.exe
2004-08-04 12:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe
2008-04-13 17:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 C:\WINDOWS\system32\ctfmon.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 16:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 12:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe
2008-04-13 17:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b C:\WINDOWS\system32\spoolsv.exe
2004-08-04 12:00 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\ServicePackFiles\i386\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 C:\WINDOWS\system32\userinit.exe
2004-08-04 12:00 295424 b60c877d16d9c880b952fda04adf16e6 C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
2008-04-13 17:12 295424 ff3477c03be7201c294c35f684b3479f C:\WINDOWS\system32\termsrv.dll
.
((((((((((((((((((((((((((((( snapshot@2008-10-30_16.39.04.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-06-11 20:34:36 2,115,816 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-05 03:24:02 3,695,008 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
- 2007-06-11 20:04:38 190,696 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-10-05 03:24:04 235,936 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-10-31 07:18:59 84,661 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-21 35328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-10-16 590848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-11 67488]
"SDFix"="C:\SDFix\RunThis.bat" [2008-10-26 918612]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-03 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
OKI LPR Utility.lnk - C:\Program Files\Okidata\OKI LPR Utility\okilpr.exe [2006-11-21 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccyyYpp]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
.
- - - - ORPHANS REMOVED - - - -
BHO-{53CDB936-7A8D-4B44-9B7B-70525D0C9D50} - (no file)
BHO-{6839DB84-A6EC-4E8B-9320-2C6E98A3C27C} - (no file)
BHO-{A32BF1D3-1110-4507-8F5E-235E0586F08C} - (no file)
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-31 10:50:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-31 10:52:31
ComboFix-quarantined-files.txt 2008-10-31 17:51:59
ComboFix2.txt 2008-10-30 23:55:41
ComboFix3.txt 2008-10-30 23:40:30
ComboFix4.txt 2008-05-05 21:13:08
Pre-Run: 117,839,216,640 bytes free
Post-Run: 118,492,729,344 bytes free
311 — E O F — 2008-10-24 20:18:02
Rorschach112
Hello
Also post a new HJT log
- Make sure to use Internet Explorer for this
- Please go to VirSCAN.org FREE on-line scan service
- Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
- C:\WINDOWS\system32\svchost.exe
- Click on the Upload button
- Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
- Paste the contents of the Clipboard in your next reply.
Also post a new HJT log
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI