second combofix log
ComboFix 09-01-17.04 - Administrator 2009-01-18 21:31:28.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.147 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
FW: Norton Internet Worm Protection *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\
02000000099089e6517C.manifest
c:\documents and settings\Administrator\Application Data\
02000000099089e6517O.manifest
c:\documents and settings\Administrator\Application Data\
02000000099089e6517P.manifest
c:\documents and settings\Administrator\Application Data\
02000000099089e6517S.manifest
c:\program files\Enigma Software Group
c:\program files\Enigma Software Group\SpyHunter\def.dat.bak
c:\program files\Enigma Software Group\SpyHunter\key.dat
c:\program files\Enigma Software Group\SpyHunter\pgdata.dat
c:\program files\Enigma Software Group\SpyHunter\pr_support.log
c:\program files\Enigma Software Group\SpyHunter\rgdata.dat
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000000.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000001.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000002.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000003.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000004.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000005.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000006.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000007.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000008.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000009.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00000a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00000b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00000c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00000d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00000e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00000f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000010.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000011.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000012.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000013.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000014.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000015.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000016.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000017.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000018.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000019.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00001a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00001b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00001c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00001d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00001e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00001f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000020.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000021.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000022.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000023.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000024.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000025.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000026.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000027.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000028.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000029.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00002a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00002b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00002c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00002d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00002e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00002f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000030.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000031.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000032.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000033.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000034.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000035.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000036.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000037.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000038.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000039.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00003a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00003b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00003c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00003d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00003e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00003f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000040.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000041.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000042.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000043.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000044.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000045.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000046.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000047.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000048.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000049.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00004a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00004b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00004c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00004d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00004e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00004f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000050.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000051.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000052.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000053.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000054.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000055.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000056.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000057.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000058.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000059.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00005a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00005b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00005c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00005d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00005e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00005f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000060.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000061.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000062.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000063.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000064.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000065.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000066.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000067.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000068.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000069.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00006a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00006b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00006c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00006d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00006e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00006f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000070.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000071.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000072.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000073.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000074.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000075.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000076.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000077.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000078.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000079.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00007a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00007b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00007c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00007d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00007e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00007f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000080.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000081.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000082.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000083.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000084.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000085.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000086.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000087.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000088.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000089.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00008a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00008b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00008c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00008d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00008e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00008f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000090.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000091.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000092.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000094.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000095.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000096.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000097.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000098.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
000099.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00009a.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00009b.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00009c.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00009d.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00009e.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
00009f.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a0.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a1.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a2.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a3.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a4.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a5.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a6.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a7.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a8.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000a9.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000aa.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000ab.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000ac.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000ad.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000ae.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000af.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b0.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b1.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b2.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b3.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b4.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b5.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b6.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b7.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b8.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000b9.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000ba.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000bb.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000bc.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\
0000bd.ecd
c:\program files\Enigma Software Group\SpyHunter\Rollback\rollback.dat
c:\program files\Enigma Software Group\SpyHunter\scan.log
c:\program files\Enigma Software Group\SpyHunter\spyhunter.log
c:\program files\Enigma Software Group\SpyHunter\SpyHunterInstance.lock
c:\program files\Enigma Software Group\SpyHunter\support.log
c:\program files\Mozilla Firefox\components\nssnappyads.dll
c:\windows\GnuHashes.ini
c:\windows\system32\12.tmp
c:\windows\system32\58.tmp
c:\windows\system32\cont_snappyads-remove.exe
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\GroupPolicyManifest
c:\windows\system32\GroupPolicyManifest\23.music.mp3
c:\windows\system32\GroupPolicyManifest\23.music.mp3.kwd
c:\windows\system32\GroupPolicyManifest\24.crack.zip
c:\windows\system32\GroupPolicyManifest\24.crack.zip.kwd
c:\windows\system32\GroupPolicyManifest\25.video.zip
c:\windows\system32\GroupPolicyManifest\25.video.zip.kwd
c:\windows\system32\GroupPolicyManifest\26.setup.zip
c:\windows\system32\GroupPolicyManifest\26.setup.zip.kwd
c:\windows\system32\GroupPolicyManifest\27.unpack.zip
c:\windows\system32\GroupPolicyManifest\27.unpack.zip.kwd
c:\windows\system32\GroupPolicyManifest\28.keygen.zip
c:\windows\system32\GroupPolicyManifest\28.keygen.zip.kwd
c:\windows\system32\GroupPolicyManifest\29.serial.zip
c:\windows\system32\GroupPolicyManifest\29.serial.zip.kwd
c:\windows\system32\GroupPolicyManifest\30.mpgvideo.mpg
c:\windows\system32\GroupPolicyManifest\30.mpgvideo.mpg.kwd
c:\windows\system32\iasacct32.dll
c:\windows\system32\nsm93.dll
c:\windows\system32\yfkbqhzgnwujzbcc.exe
c:\windows\system32\zvgwtrftxemk.exe
c:\windows\Tasks\zwvxfijk.job
C:\xcrashdump.dat
.
((((((((((((((((((((((((( Files Created from 2008-12-19 to 2009-01-19 )))))))))))))))))))))))))))))))
.
2009-01-18 11:06 . 2009-01-18 11:06 d——– c:\program files\Windows Media Connect 2
2009-01-18 11:04 . 2009-01-18 11:05 d——– c:\windows\system32\drivers\UMDF
2009-01-18 11:04 . 2009-01-18 11:05 d——– C:\cad06a32d6eb28737f269d
2009-01-17 21:44 . 2009-01-17 21:44 d——– c:\program files\iTunes
2009-01-17 21:44 . 2009-01-17 21:44 d——– c:\program files\iPod
2009-01-17 21:44 . 2009-01-17 21:44 d——– c:\program files\Common Files\Apple
2009-01-17 21:44 . 2009-01-17 21:44 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-17 21:43 . 2009-01-17 21:43 d——– C:\VundoFix Backups
2009-01-17 21:43 . 2009-01-17 21:43 d——– c:\documents and settings\Administrator\Application Data\uTorrent
2009-01-17 21:43 . 2009-01-17 21:43 d——– c:\documents and settings\Administrator\Application Data\LimeWire
2009-01-17 21:43 . 2009-01-17 21:43 d–h—– c:\documents and settings\Administrator\Application Data\ijjigame
2009-01-17 21:43 . 2009-01-17 21:43 d——– c:\documents and settings\Administrator\Application Data\FrostWire
2009-01-17 19:35 . 2009-01-17 19:35 d——– c:\documents and settings\NetworkService\Application Data\Webroot
2009-01-17 19:14 . 2009-01-17 19:14 d——– c:\documents and settings\Administrator\PrivacIE
2009-01-17 19:00 . 2009-01-17 21:44 d—-c— c:\windows\ie8
2009-01-17 18:03 . 2009-01-17 21:44 d——– c:\program files\iPod(2)
2009-01-17 18:02 . 2009-01-17 21:44 d——– c:\program files\iTunes(2)
2009-01-17 18:01 . 2009-01-17 21:44 d——– c:\program files\QuickTime
2009-01-17 18:01 . 2009-01-17 21:44 d——– c:\program files\Apple Software Update
2009-01-17 18:00 . 2009-01-17 21:44 d——– c:\program files\Common Files\Apple(2)
2009-01-17 12:52 . 2009-01-16 11:41 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-16 14:12 . 2009-01-17 12:51 d——– c:\program files\LimeWire
2009-01-16 12:32 . 2009-01-18 21:41 d——– c:\program files\DNA
2009-01-16 12:32 . 2009-01-18 21:41 d——– c:\documents and settings\Administrator\Application Data\DNA
2009-01-16 11:42 . 2009-01-16 11:41 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-15 18:16 . 2009-01-15 18:16 d——– c:\documents and settings\Administrator\Application Data\Apple Computer
2009-01-15 18:15 . 2008-04-17 13:12 107,368 –a—— c:\windows\system32\GEARAspi.dll
2009-01-15 18:15 . 2008-04-17 13:12 15,464 –a—— c:\windows\system32\drivers\GEARAspiWDM.sys
2009-01-15 18:13 . 2009-01-15 18:13 d——– c:\program files\Bonjour
2009-01-15 18:11 . 2009-01-17 21:44 d——– c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-15 18:09 . 2009-01-17 18:00 d—-c— c:\windows\system32\DRVSTORE
2009-01-15 18:08 . 2009-01-15 18:08 d——– c:\documents and settings\All Users\Application Data\Apple
2009-01-15 18:04 . 2009-01-16 11:41 d——– c:\program files\Java
2009-01-15 17:56 . 2009-01-16 14:12 d——– c:\program files\FrostWire
2009-01-14 22:08 . 2001-08-17 13:56 7,552 –a—— c:\windows\system32\drivers\SONYPVU1.SYS
2009-01-14 22:08 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-01-13 13:31 . 2009-01-13 13:31 127 –a—— c:\windows\system32\MRT.INI
2008-12-29 16:55 . 2008-12-29 16:55 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2008-12-29 16:54 . 2008-12-29 16:54 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-29 16:54 . 2008-12-29 16:54 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-29 16:54 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 16:54 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-29 16:04 . 2008-12-29 16:04 d——– c:\program files\Trend Micro
2008-12-27 19:34 . 2008-12-27 19:34 d——– c:\program files\Common Files\Adobe Systems Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-17 21:08 ——— d—–w c:\documents and settings\Administrator\Application Data\MSNInstaller
2009-01-17 20:06 ——— d—–w c:\program files\GemMaster
2009-01-17 19:53 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-29 08:32 ——— d—–w c:\program files\MySpace
2008-12-28 02:33 ——— d—–w c:\program files\Common Files\Adobe
2008-12-18 21:16 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-04-25 17:17 34,352 —-a-w c:\documents and settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2007-10-10 04:49 418 —-a-w c:\documents and settings\Administrator\Application Data\wklnhst.dat
2008-07-10 12:52 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008071020080711\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-18_11.17.26.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-10-19 03:03:58 100,864 -c—-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-18 08:09:22 100,864 -c—-w c:\windows\system32\dllcache\logagent.exe
- 2006-10-19 04:47:18 222,208 -c—-w c:\windows\system32\dllcache\WMASF.dll
+ 2007-10-28 00:40:30 222,720 -c—-w c:\windows\system32\dllcache\wmasf.dll
- 2006-10-19 04:47:20 937,984 -c—-w c:\windows\system32\dllcache\WMNetMgr.dll
+ 2008-06-18 12:03:08 938,496 -c—-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-10-19 04:47:22 2,450,944 -c–a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-18 12:03:14 2,458,112 -c–a-w c:\windows\system32\dllcache\WMVCore.dll
- 2006-10-19 03:03:58 100,864 —-a-w c:\windows\system32\logagent.exe
+ 2008-06-18 08:09:22 100,864 —-a-w c:\windows\system32\logagent.exe
- 2006-09-26 00:58:48 14,640 ——w c:\windows\system32\spmsg.dll
+ 2007-07-27 16:41:40 16,760 ——w c:\windows\system32\spmsg.dll
- 2006-10-19 04:47:18 222,208 —-a-w c:\windows\system32\wmasf.dll
+ 2007-10-28 00:40:30 222,720 —-a-w c:\windows\system32\wmasf.dll
- 2006-10-19 04:47:20 937,984 —-a-w c:\windows\system32\WMNetMgr.dll
+ 2008-06-18 12:03:08 938,496 —-a-w c:\windows\system32\WMNetmgr.dll
- 2006-10-19 04:47:22 2,450,944 —-a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 12:03:14 2,458,112 —-a-w c:\windows\system32\WMVCore.dll
+ 2009-01-19 04:36:21 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_2d4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-01-16 342848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-07-02 163840]
"IndicatorUtility"="c:\program files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2005-08-09 81920]
"LoadFUJ02E3"="c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2005-06-08 69632]
"LoadFujitsuQuickTouch"="c:\program files\Fujitsu\Application Panel\QuickTouch.exe" [2005-11-01 242688]
"LoadBtnHnd"="c:\program files\Fujitsu\BtnHnd\BtnHnd.exe" [2005-11-01 61440]
"RemoteControl"="c:\program files\CyberLink Codec\PDVDServ.exe" [2004-07-15 32768]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 517768]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-16 136600]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-03-01 4865600]
"AGRSMMSG"="AGRSMMSG.exe" [2005-11-16 c:\windows\AGRSMMSG.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-08 c:\windows\RTHDCPL.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-27 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\drivers\fuj02e3.sys [2005-12-16 4864]
R4 FlashDrv;FlashDrv;c:\progra~1\Fujitsu\FlashAid\FlashDrv.sys [2005-12-16 7196]
S3 AVUSBPVR;AVerMedia USB MPEG-2 Capture Device;c:\windows\system32\drivers\avusbpvr.sys [2005-12-16 1947264]
.
- - - - ORPHANS REMOVED - - - -
BHO-{2d3c4809-aaa3-1b3c-defb-dd9a2a898c6c} - c:\windows\system32\nsm93.dll
Notify-3c64f36c517 - c:\windows\System32\iasacct32.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.csi.edu/
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\5hpmvgdy.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPSFDMGR.dll
—- FIREFOX POLICIES —-
FF - user.js: keyword.enabled - true
FF - user.js: browser.search.defaultenginename - Yoog Search
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-18 21:40:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(944)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\WRLogonNTF.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\ati2evxx.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Apoint2K\Hidfind.exe
c:\program files\Apoint2K\ApntEx.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Webroot\Spy Sweeper\ssu.exe
.
**************************************************************************
.
Completion time: 2009-01-18 21:45:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-19 04:45:17
ComboFix2.txt 2009-01-18 18:18:18
Pre-Run: 52,706,779,136 bytes free
Post-Run: 52,692,955,136 bytes free
435 — E O F — 2009-01-18 22:52:09