ComboFix 09-02-04.04 - Owner 2009-02-05 19:24:44.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2547 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090205-1] *On-access scanning enabled* (Updated)
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
FILE ::
c:\documents and settings\All Users\Application Data\A81B14F4A2.sys
c:\windows\system32\10f3aa2c.dll
c:\windows\system32\1a9f280.dll
c:\windows\system32\1abd7a4a.dll
c:\windows\system32\34386752.dll
c:\windows\system32\57175b0.dll
c:\windows\system32\5e7504.dll
c:\windows\system32\vghd.scr
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\A81B14F4A2.sys
c:\documents and settings\Owner\Application Data\vghd
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backabout.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backcalendar.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backcollection.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backdelete.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backdownload_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backdownload_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backenterpassword.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\background.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backplaylists.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backregister_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backregister_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backscreensaver.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backsettings_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backsettings_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backwarnbox.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\backwarnbox_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_add_playlist_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_add_playlist_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_add_playlist_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_add_playlist_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_buy_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_buy_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_buy_off_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_buy_off_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_buy_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_buy_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancel_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancel_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancel_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancel_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancel_small.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancel_small_click.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancel_small_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancel_small_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancelregister_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancelregister_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancelregister_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_cancelregister_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_confirm_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_confirm_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_confirm_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_confirm_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_off_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_off_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_playlist_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_playlist_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_playlist_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_delete_playlist_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_download_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_download_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_download_off_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_download_off_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_download_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_download_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_downloadtrailer_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_downloadtrailer_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_downloadtrailer_off_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_downloadtrailer_off_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_downloadtrailer_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_downloadtrailer_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_enable_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_enable_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_enable_off_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_enable_off_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_enable_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_enable_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_finish_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_finish_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_finish_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_finish_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_no_click.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_no_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_no_on.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_no_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_ok_playlist_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_ok_playlist_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_ok_playlist_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_ok_playlist_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_ok_small.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_ok_small_click.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset1_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset1_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset1_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset1_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset2_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset2_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset2_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset2_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset3_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset3_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset3_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset3_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset4_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset4_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset4_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preset4_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preview_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preview_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preview_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_preview_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_previewsmall_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_previewsmall_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_previewsmall_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_previewsmall_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_products.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_resetdisabled_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_resetdisabled_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_resetdisabled_off_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_resetdisabled_off_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_resetdisabled_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_resetdisabled_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_select_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_select_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_select_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_select_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_show_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_show_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_show_off_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_show_off_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_show_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_show_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_skins.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_toggle_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_toggle_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_toggle_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_toggle_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_whatsnew_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_whatsnew_click_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_whatsnew_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_whatsnew_on_us.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_yes_click.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_yes_click_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_yes_on.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\button_yes_on_fr.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\calendar_comingsoon.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\calendar_nocard.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\checkbox.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\down_about.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\down_calendar.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\down_collection.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\down_downloads.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\down_settings.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\down_settings2.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\empty_girl.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\favorite.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\favorite_selected.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\list_disabled.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\list_enabled.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\logo.BMP
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\plus.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\radio.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\register_sticker.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\scr00001.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\scr00003.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\scr00004.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\scr00005.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\scr1.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\scr3.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\scr4.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\scr5.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\slider.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\Thumbs.db
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\tip_background.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\tooltip_button.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\tooltip_button_click.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\tooltip_check_off.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\tooltip_check_on.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\tooltip_close.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\up_about.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\up_calendar.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\up_collection.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\up_downloads.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\up_settings.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\up_settings2.bmp
c:\documents and settings\Owner\Application Data\vghd\Data\skins\VirtuaGirlHD\classic skin\vgirl.pack
c:\windows\system32\10f3aa2c.dll
c:\windows\system32\1a9f280.dll
c:\windows\system32\1abd7a4a.dll
c:\windows\system32\34386752.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\57175b0.dll
c:\windows\system32\5e7504.dll
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vghd.scr
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.
2009-02-05 18:04 . 2009-02-05 18:22 5,491 --a------ C:\dfx.rtf
2009-02-05 15:06 . 2009-02-05 15:06 <DIR> d-------- c:\documents and settings\Owner\Application Data\Sunbelt
2009-02-05 15:06 . 2009-02-05 15:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sunbelt
2009-02-05 15:04 . 2009-02-05 15:04 <DIR> d-------- c:\program files\Sunbelt Software
2009-02-05 15:04 . 2008-10-09 10:21 202,928 --a------ c:\windows\system32\drivers\sbtis.sys
2009-02-05 14:27 . 2009-02-05 18:11 <DIR> d--h----- C:\$AVG8.VAULT$
2009-02-05 14:26 . 2009-02-05 14:27 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-02-05 14:26 . 2009-02-05 14:26 <DIR> d-------- c:\program files\AVG
2009-02-05 14:26 . 2009-02-05 14:26 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-02-05 14:26 . 2009-02-05 14:26 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-02-05 14:26 . 2009-02-05 14:26 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-02-05 12:17 . 2009-02-05 12:17 <DIR> d-------- c:\program files\Alwil Software
2009-02-05 11:23 . 2009-02-05 11:38 2,204 --a------ c:\windows\evpovqfm
2009-02-04 11:54 . 2009-02-04 11:54 250 --a------ c:\windows\gmer.ini
2009-02-03 10:59 . 2009-02-03 10:59 <DIR> d-------- c:\documents and settings\Administrator
2009-02-03 10:50 . 2009-02-05 14:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-02-02 15:09 . 2009-01-18 16:30 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-02 15:08 . 2009-02-05 12:12 <DIR> d-------- c:\program files\Lavasoft
2009-02-02 15:08 . 2009-02-05 12:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-02 15:08 . 2009-02-05 12:12 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\~0
2009-02-02 14:48 . 2009-02-02 14:48 <DIR> d-------- c:\documents and settings\Owner\Application Data\Corel
2009-02-02 14:48 . 2009-02-02 14:48 2,516 --ahs---- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-02-02 14:41 . 2009-02-02 14:41 <DIR> d-------- c:\program files\Common Files\Protexis
2009-02-02 14:41 . 2009-02-02 14:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Corel
2009-02-02 14:38 . 2009-02-02 14:38 <DIR> d-------- c:\program files\Common Files\Corel
2009-02-02 14:36 . 2009-02-02 14:36 <DIR> d-------- c:\program files\Corel
2009-02-02 14:26 . 2009-02-02 14:26 <DIR> d-------- c:\program files\Trend Micro
2009-02-02 07:57 . 2009-02-02 07:57 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-02-02 07:57 . 2009-02-05 11:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-01 12:37 . 2009-02-01 12:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2009-02-01 12:36 . 2009-02-01 12:36 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2009-02-01 12:34 . 2009-02-01 12:34 <DIR> d-------- c:\program files\Rosetta Stone
2009-02-01 12:34 . 2009-02-01 13:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Rosetta Stone
2009-02-01 12:32 . 2009-02-01 12:32 <DIR> d-------- c:\program files\VirusTotalUploader
2009-01-31 12:45 . 2009-01-31 12:45 <DIR> d-------- c:\documents and settings\Owner\Application Data\Purple Ghost Software, Inc
2009-01-31 12:45 . 2009-01-31 12:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\Purple Ghost Software, Inc
2009-01-31 12:44 . 2009-01-31 12:44 <DIR> d-------- c:\program files\Purple Ghost
2009-01-30 17:06 . 2007-11-14 15:18 553 --a------ c:\windows\USetup.iss
2009-01-30 17:05 . 2009-01-30 17:05 <DIR> d-------- c:\program files\Realtek
2009-01-30 17:05 . 2008-08-05 20:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys
2009-01-30 17:05 . 2006-01-04 15:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys
2009-01-30 17:05 . 2008-08-25 16:17 528,384 --a------ c:\windows\RtlExUpd.dll
2009-01-30 17:05 . 2008-10-27 18:12 34,816 --a------ c:\windows\system32\RtkCoInstXP.dll
2009-01-29 14:20 . 2009-01-29 14:25 <DIR> d-------- c:\documents and settings\Owner\Application Data\Teeworlds
2009-01-28 07:54 . 2009-01-28 07:54 <DIR> d-------- c:\documents and settings\Owner\Application Data\Rogue.140F0B534E676AD25491A378BD6D96164D40676E.1
2009-01-28 07:50 . 2009-01-28 07:50 <DIR> d-------- c:\program files\Rogue
2009-01-28 07:50 . 2009-01-28 07:50 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-01-23 15:47 . 2008-10-10 04:52 4,379,984 --a------ c:\windows\system32\D3DX9_40.dll
2009-01-23 15:47 . 2008-07-10 11:00 3,851,784 --a------ c:\windows\system32\D3DX9_39.dll
2009-01-23 15:47 . 2008-10-27 10:04 514,384 --a------ c:\windows\system32\XAudio2_3.dll
2009-01-23 15:47 . 2008-07-30 06:20 509,448 --a------ c:\windows\system32\XAudio2_2.dll
2009-01-23 15:47 . 2008-10-27 10:04 70,992 --a------ c:\windows\system32\XAPOFX1_2.dll
2009-01-23 15:47 . 2008-07-30 06:20 68,616 --a------ c:\windows\system32\XAPOFX1_1.dll
2009-01-23 15:47 . 2008-10-27 10:04 23,376 --a------ c:\windows\system32\X3DAudio1_5.dll
2009-01-18 13:50 . 2009-01-18 13:58 <DIR> d-------- c:\program files\Visual Assist X
2009-01-18 13:41 . 2009-01-18 13:41 <DIR> d-------- c:\program files\Greatis
2009-01-15 14:45 . 2009-01-15 14:56 0 --a------ c:\windows\system32\drivers\EagleNt.sys
2009-01-15 13:18 . 2009-01-15 13:31 3 --a------ c:\windows\sbacknt.bin
2009-01-15 13:03 . 2009-01-15 13:03 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\Xfire
2009-01-13 08:37 . 2008-06-20 06:51 361,600 -----c--- c:\windows\system32\dllcache\tcpip.sys
2009-01-13 08:37 . 2008-06-20 12:46 245,248 -----c--- c:\windows\system32\dllcache\mswsock.dll
2009-01-13 08:37 . 2008-06-20 06:08 225,856 -----c--- c:\windows\system32\dllcache\tcpip6.sys
2009-01-13 08:37 . 2008-06-20 12:46 147,968 -----c--- c:\windows\system32\dllcache\dnsapi.dll
2009-01-08 02:53 . 2009-01-20 17:31 1,733 --a------ c:\windows\TSearch.INI
2009-01-06 16:56 . 2009-01-06 16:56 <DIR> d-------- c:\program files\Mozilla ActiveX Control v1.7.12
2009-01-06 16:56 . 2009-01-06 16:56 <DIR> d-------- c:\documents and settings\Owner\Application Data\MozillaControl
2009-01-06 16:51 . 2009-01-06 16:51 54,784 --a------ c:\windows\system32\ieframe.oca
2009-01-06 16:49 . 2009-01-06 16:49 29,184 --a------ c:\windows\system32\msinet.oca
2009-01-06 16:47 . 2009-01-06 16:47 115,920 --a------ c:\windows\system32\msinet.ocx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-05 23:56 --------- d-----w c:\program files\Steam
2009-02-05 23:01 33,824 ----a-w c:\windows\system32\drivers\oreans32.sys
2009-02-05 16:38 --------- d-----w c:\documents and settings\Owner\Application Data\Orbit
2009-02-05 16:07 --------- d-----w c:\program files\Common Files\Adobe
2009-02-01 20:23 --------- d-----w c:\program files\Cheat Engine
2009-01-31 17:25 --------- d-----w c:\program files\CCleaner
2009-01-31 17:13 --------- d-----w c:\documents and settings\Owner\Application Data\Xfire
2009-01-31 16:02 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-31 16:02 --------- d-----w c:\program files\Novalogic
2009-01-29 20:46 --------- d-----w c:\documents and settings\Owner\Application Data\FileZilla
2009-01-22 16:22 --------- d-----w c:\program files\IDA
2009-01-18 18:51 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-17 19:01 --------- d-----w c:\documents and settings\Owner\Application Data\VisualAssist
2009-01-16 00:14 --------- d-----w c:\documents and settings\Owner\Application Data\OpenOffice.org2
2009-01-16 00:11 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-14 21:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 21:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-05 03:19 --------- d-----w c:\program files\Hewlett-Packard
2009-01-05 03:19 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-01-05 03:18 --------- d-----w c:\program files\HP
2009-01-05 03:18 --------- d-----w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-01-05 02:56 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-05 02:56 --------- d-----w c:\documents and settings\Owner\Application Data\InstallShield
2009-01-05 02:56 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2009-01-05 02:55 --------- d-----w c:\documents and settings\Owner\Application Data\Move Networks
2009-01-05 02:50 --------- d-----w c:\program files\Xfire
2009-01-02 23:55 182,200 ----a-w c:\windows\system32\drivers\UsbSnoop.sys
2008-12-30 03:35 --------- d-----w c:\program files\iPhoneBrowser
2008-12-30 01:53 --------- d-----w c:\program files\Sol Edit
2008-12-30 01:33 --------- d-----w c:\program files\SourceTec
2008-12-30 01:33 --------- d-----w c:\program files\Common Files\SourceTec
2008-12-30 01:32 --------- d-----w c:\program files\GamesBar
2008-12-30 01:18 --------- d-----w c:\documents and settings\All Users\Application Data\GamesBar
2008-12-26 20:40 --------- d-----w c:\program files\Oberon Media
2008-12-26 07:26 --------- d-----w c:\documents and settings\All Users\Application Data\Souptoys
2008-12-26 06:06 --------- d-----w c:\program files\
010 Editor v3
2008-12-26 05:02 --------- d-----w c:\documents and settings\Owner\Application Data\Logitech
2008-12-26 04:55 --------- d-----w c:\documents and settings\All Users\Application Data\LogiShrd
2008-12-26 04:54 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-26 04:54 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-12-26 04:54 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2008-12-26 04:54 --------- d-----w c:\program files\Common Files\Logishrd
2008-12-26 04:53 --------- d-----w c:\program files\Logitech
2008-12-26 04:53 --------- d-----w c:\documents and settings\All Users\Application Data\Logitech
2008-12-26 04:12 --------- d-----w c:\documents and settings\Owner\Application Data\TeamViewer
2008-12-26 04:11 --------- d-----w c:\program files\TeamViewer
2008-12-26 04:08 --------- d-----w c:\program files\RSP OGG Vorbis Player .Net 1.0.0
2008-12-26 00:55 --------- d-----w c:\documents and settings\All Users\Application Data\Adobe Systems
2008-12-26 00:49 --------- d-----w c:\program files\Common Files\Adobe Systems Shared
2008-12-25 23:30 182 ----a-w c:\documents and settings\Owner\Application Data\SnapiiHistory.dat
2008-12-25 23:12 --------- d-----w c:\program files\Common Files\Oberon Media
2008-12-25 21:04 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE
2008-12-25 20:59 --------- d-----w c:\documents and settings\Owner\Application Data\Activision
2008-12-25 20:59 --------- d-----w c:\documents and settings\All Users\Application Data\Activision
2008-12-25 20:54 --------- d-----w c:\program files\D-Tools
2008-12-25 18:23 --------- d-----w c:\program files\Mars
2008-12-25 18:23 --------- d-----w c:\program files\DIFX
2008-12-25 17:30 --------- d-----w c:\program files\Activision
2008-12-25 07:07 --------- d-----w c:\documents and settings\Owner\Application Data\Apple Computer
2008-12-25 07:06 --------- d-----w c:\program files\QuickTime
2008-12-25 06:59 --------- d-----w c:\program files\iTunes
2008-12-25 06:59 --------- d-----w c:\program files\iPod
2008-12-25 06:59 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-25 00:28 --------- d-----w c:\program files\Game Extractor
2008-12-24 23:31 --------- d-----w c:\program files\IrfanView
2008-12-24 21:54 --------- d-----w c:\program files\Souptoys
2008-12-24 21:30 --------- d-----w c:\program files\BreakPoint Software
2008-12-24 20:33 --------- d-----w c:\documents and settings\Owner\Application Data\Souptoys
2008-12-24 19:17 --------- d-----w c:\program files\Teamspeak2_RC2
2008-12-24 17:32 --------- d-----w c:\documents and settings\Owner\Application Data\teamspeak2
2008-12-22 18:46 --------- d-----w c:\program files\Common Files\Apple
2008-12-21 06:28 --------- d-----w c:\program files\Screenie
2008-12-21 06:27 --------- d-----w c:\documents and settings\Owner\Application Data\Screenie
2008-12-21 04:31 --------- d-----w c:\program files\Wide Angle Software
2008-12-20 19:29 --------- d-----w c:\program files\Oni
2008-12-20 15:06 --------- d-----w c:\program files\FileZilla FTP Client
2008-12-20 06:06 --------- d-----w c:\program files\Swiigle
2008-12-20 06:02 --------- d-----w c:\program files\Eltima Software
2008-12-20 04:11 --------- d-----w c:\program files\Bonjour
2008-12-20 04:11 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-20 04:10 --------- d-----w c:\program files\Apple Software Update
2008-12-20 04:09 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-12-19 19:04 --------- d-----w c:\documents and settings\Owner\Application Data\Datarescue
2008-12-19 01:04 --------- d-----w c:\documents and settings\Owner\Application Data\DivX
2008-12-19 00:32 --------- d-----w c:\program files\DivX
2008-12-18 20:22 --------- d-----w c:\program files\RocketDock
2008-12-18 17:35 --------- d-----w c:\program files\Orbitdownloader
2008-12-18 16:20 --------- d-----w c:\documents and settings\Owner\Application Data\Media Player Classic
2008-12-18 16:19 --------- d-----w c:\program files\K-Lite Codec Pack
2008-12-17 21:51 --------- d-----w c:\program files\FileZilla Server
2008-12-17 21:45 --------- d-----w c:\documents and settings\All Users\Application Data\NexonUS
2008-12-17 19:27 --------- d-----w c:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-17 19:27 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-17 16:56 --------- d-----w c:\program files\PE Explorer
2008-12-17 16:56 --------- d-----w c:\documents and settings\Owner\Application Data\PE Explorer
2008-12-16 19:03 --------- d-----w c:\program files\Yahoo!
2008-12-16 18:08 --------- d-----w c:\program files\Icon Remover
2008-12-16 18:08 --------- d-----w c:\documents and settings\Owner\Application Data\Icon Remover
2008-12-16 17:58 --------- d-----w c:\program files\Everstrike Software
2008-12-16 07:31 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
.
((((((((((((((((((((((((((((( SnapShot@2009-02-05_10.43.38.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-05 20:04:49 297,086 ----a-r c:\windows\Installer\{CEF980E6-BC32-49FA-85D8-6742173D8E5D}\ARPPRODUCTICON.exe
+ 2009-02-05 20:04:49 335,872 ----a-r c:\windows\Installer\{CEF980E6-BC32-49FA-85D8-6742173D8E5D}\NewShortcut2_339C927BB4B547F9804FDF51F01D2D57.exe
+ 2009-02-05 20:04:49 335,872 ----a-r c:\windows\Installer\{CEF980E6-BC32-49FA-85D8-6742173D8E5D}\NewShortcut21_339C927BB4B547F9804FDF51F01D2D57.exe
+ 2008-11-26 17:21:30 1,236,208 ----a-w c:\windows\system32\aswBoot.exe
+ 2008-11-26 17:15:10 97,480 ----a-w c:\windows\system32\AvastSS.scr
- 2009-02-04 12:33:23 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-05 16:18:16 16,384 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-04 12:33:23 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-05 16:18:16 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-04 12:33:23 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-05 16:18:16 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-26 17:15:35 26,944 ----a-w c:\windows\system32\drivers\aavmker4.sys
+ 2008-11-26 17:17:25 20,560 ----a-w c:\windows\system32\drivers\aswFsBlk.sys
+ 2008-11-26 17:18:25 93,296 ----a-w c:\windows\system32\drivers\aswmon.sys
+ 2008-11-26 17:18:18 94,032 ----a-w c:\windows\system32\drivers\aswmon2.sys
+ 2008-11-26 17:16:29 23,152 ----a-w c:\windows\system32\drivers\aswRdr.sys
+ 2008-11-26 17:17:36 111,184 ----a-w c:\windows\system32\drivers\aswSP.sys
+ 2008-11-26 17:16:38 50,864 ----a-w c:\windows\system32\drivers\aswTdi.sys
+ 2009-02-05 19:26:31 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys
+ 2008-10-23 09:09:24 92,464 ----a-w c:\windows\system32\drivers\SBREDrv.sys
+ 2008-10-28 21:28:12 65,320 ----a-w c:\windows\system32\sbbd.exe
+ 2006-01-09 14:36:06 40,960 ----a-w c:\windows\system32\swsc.exe
+ 2007-01-10 22:03:04 493,400 ----a-w c:\windows\system32\XceedZip.dll
+ 2009-02-06 00:29:26 16,384 ----atw c:\windows\temp\Perflib_Perfdata_600.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-05 1601304]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2008-10-28 955688]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 c:\windows\RTHDCPL.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 16:41 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-05 14:26 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Orbit.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
backup=c:\windows\pss\Orbit.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Xfire.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 c:\program files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Icon Remover]
--a------ 2008-03-25 20:45 742400 c:\program files\Icon Remover\IconRemover.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
--a------ 2007-09-02 13:58 495616 c:\program files\RocketDock\RocketDock.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-12-15 20:40 1410296 c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Steam\\steamapps\\macdragon1\\half-life\\hl.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Steam\\steamapps\\macdragon1\\counter-strike source\\hl2.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\Visual Studio 2008\\Projects\\ChatServer\\ChatServer\\bin\\Debug\\ChatServer.exe"=
"c:\\Program Files\\IDA\\idag.exe"=
"c:\\Program Files\\IDA\\idag64.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Steam\\steamapps\\macdragon1\\day of defeat source\\hl2.exe"=
"c:\\Documents and Settings\\Owner\\Desktop\\BHD\\DFBHD.EXE"=
"c:\\Program Files\\Steam\\steamapps\\macdragon1\\age of chivalry\\hl2.exe"=
"c:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Activision\\Quantum of Solace\\JB_LiveEngine_s.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fear2spdemo\\FEAR2SPDemo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"<NO NAME>"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-02 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-05 111184]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-05 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-05 107272]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [2009-02-05 202928]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-05 20560]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-05 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-05 298264]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2008-12-25 10384]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-07-20 84992]
S2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [2008-10-28 886056]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2008-10-23 92464]
S3 usbsnoop;USB Snoopy Filter Driver;c:\windows\system32\drivers\UsbSnoop.sys [2009-01-02 182200]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
2009-02-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-01-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{6E992806-9974-4EBC-A6F9-8235A5022CC0} - (no file)
.
------- Supplementary Scan -------
.
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} - hxxp://ares.netgame.com/download/mglaunch_USAv1002.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\3ldgoiop.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPHoldemFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-05 19:31:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(760)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\FileZilla Server\FileZilla server.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-02-05 19:34:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-06 00:33:58
ComboFix2.txt 2009-02-05 15:44:08
Pre-Run: 140,858,634,240 bytes free
Post-Run: 140,960,313,344 bytes free
604 --- E O F --- 2009-01-15 18:06:55