looks like I got infected with the rootkit - trojan.TDSS
when first infected, I was unable to do or run anything ect... so I booted into safe mode and ran mbam. After rebooting, I still can not get rid of trojan.TDSS. I tried to run RootRepeal but kept getting error messages. I did run hijack this and combofix.
1st mbam log file, hijack this log file, combofix log file, and 2nd mbam log file follows.
Any help is much appreciated.
1st mbam log -
Malwarebytes' Anti-Malware 1.39 Database version: 2421 Windows 5.1.2600 Service Pack 2 7/15/2009 2:43:13 PM mbam-log-2009-07-15 (14-43-13).txt Scan type: Quick Scan Objects scanned: 95852 Time elapsed: 5 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: \\?\globalroot\systemroot\system32\geyekrkcxxccqt.dll (Trojan.TDSS) -> Delete on reboot. Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12951094 (Rogue.Multiple.H) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\All Users\Application Data\12951094 (Rogue.Multiple.H) -> Quarantined and deleted successfully. Files Infected: c:\documents and settings\all users\application data\12951094\12951094 (Rogue.Multiple.H) -> Quarantined and deleted successfully. c:\documents and settings\all users\application data\12951094\12951094.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully. \\?\globalroot\systemroot\system32\geyekrkcxxccqt.dll (Trojan.TDSS) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\nakrutchik.exe (Trojan.Dropper) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\ppc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HijackThis Log -
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:20:00 PM, on 7/15/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Autodesk Network License Manager\lmgrd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Autodesk Network License Manager\adskflex.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\R-Wipe&Clean\rwiped.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\MICROS~1\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/chsi.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI8C0D~1\Office12\GRA8E1~1.DLL
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [DT HPW] C:\Program Files\Portrait Displays\HP My Display\DTHtml.exe -startup_folder
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [RWipeD] C:\Program Files\R-Wipe&Clean\rwiped.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI8C0D~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O8 - Extra context menu item: SWF Capture tool - C:\Program Files\Eltima Software\Flash Decompiler\iebt.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI8C0D~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI8C0D~1\Office12\ONBttnIE.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI8C0D~1\Office12\REFIEBAR.DLL
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler\iebt.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\Program Files\Eltima Software\Flash Decompiler\iebt.dll (HKCU)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5677/mcfscan.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI8C0D~1\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\acaptuser32.dll
O20 - Winlogon Notify: Multi - C:\Program Files\Stardock\ThinkDesk\Multiplicity\MultiWin32.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FLEXlm Service 1 - Macrovision Corporation - C:\Autodesk Network License Manager\lmgrd.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Visual Studio Analyzer RPC bridge - Unknown owner - C:\Program Files\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe (file missing)
O23 - Service: Windows Defender Service (WinDefend) - Unknown owner - C:\Program Files\Windows Defender\MsMpEng.exe (file missing)
--
End of file - 11911 bytes
Combofix log -
ComboFix 09-07-14.08 - me 07/15/2009 20:43.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1414 [GMT -7:00]
Running from: c:\documents and settings\me\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
Overlay aborted ... Please run ComboFix once more
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1023072896-4139445909-1463264484-1000
c:\$recycle.bin\S-1-5-21-1170374297-2161096245-3617272062-1000
c:\$recycle.bin\S-1-5-21-1170374297-2161096245-3617272062-1001
c:\$recycle.bin\S-1-5-21-2173621283-3401230598-2509303900-1000
c:\$recycle.bin\S-1-5-21-2515028408-2413159130-2098404481-1000
c:\$recycle.bin\S-1-5-21-3311197150-222908312-1986303731-1000
c:\$recycle.bin\S-1-5-21-4008519400-45536793-3704034604-1000
c:\$recycle.bin\S-1-5-21-557742349-1574351555-2563274875-1000
c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft\Network\Downloader\qmgr0.dat
c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft\Network\Downloader\qmgr1.dat
c:\progra~1\COMMON~1\{4C599~1
c:\program files\deskbar
c:\recycler\NPROTECT
c:\recycler\S-1-5-21-1644491937-1788223648-839522115-500
c:\windows\fnts~1
c:\windows\Installer\111e88b7.msp
c:\windows\Installer\111e88b8.msp
c:\windows\Installer\111e88b9.msp
c:\windows\Installer\111e88ba.msp
c:\windows\Installer\111e88bb.msp
c:\windows\Installer\111e88bc.msp
c:\windows\Installer\111e88bd.msp
c:\windows\Installer\111e88be.msp
c:\windows\Installer\111e88bf.msp
c:\windows\Installer\1120859.msp
c:\windows\Installer\112085a.msp
c:\windows\Installer\112085b.msp
c:\windows\Installer\112085c.msp
c:\windows\Installer\112085d.msp
c:\windows\Installer\112085e.msp
c:\windows\Installer\112085f.msp
c:\windows\Installer\1120860.msp
c:\windows\Installer\1120861.msp
c:\windows\Installer\11d7055.msp
c:\windows\Installer\12b86602.msp
c:\windows\Installer\12b86603.msp
c:\windows\Installer\12b86604.msp
c:\windows\Installer\12b86605.msp
c:\windows\Installer\12b86606.msp
c:\windows\Installer\12b86607.msp
c:\windows\Installer\12b86608.msp
c:\windows\Installer\12b86609.msp
c:\windows\Installer\12b8660a.msp
c:\windows\Installer\1387fa3.msp
c:\windows\Installer\1387fa4.msp
c:\windows\Installer\1387fa5.msp
c:\windows\Installer\1387fa6.msp
c:\windows\Installer\1387fa7.msp
c:\windows\Installer\1387fa8.msp
c:\windows\Installer\1387fa9.msp
c:\windows\Installer\1387faa.msp
c:\windows\Installer\1387fab.msp
c:\windows\Installer\147af55.msp
c:\windows\Installer\147af56.msp
c:\windows\Installer\147af57.msp
c:\windows\Installer\147af58.msp
c:\windows\Installer\147af59.msp
c:\windows\Installer\147af5a.msp
c:\windows\Installer\147af5b.msp
c:\windows\Installer\147af5c.msp
c:\windows\Installer\147af5d.msp
c:\windows\Installer\152df43.msp
c:\windows\Installer\152df44.msp
c:\windows\Installer\152df45.msp
c:\windows\Installer\152df46.msp
c:\windows\Installer\152df47.msp
c:\windows\Installer\152df48.msp
c:\windows\Installer\152df49.msp
c:\windows\Installer\152df4a.msp
c:\windows\Installer\152df4b.msp
c:\windows\Installer\15865f5.msp
c:\windows\Installer\15865f6.msp
c:\windows\Installer\15865f7.msp
c:\windows\Installer\15865f8.msp
c:\windows\Installer\15865f9.msp
c:\windows\Installer\15865fa.msp
c:\windows\Installer\15865fb.msp
c:\windows\Installer\15865fc.msp
c:\windows\Installer\15865fd.msp
c:\windows\Installer\1644f9b6.msp
c:\windows\Installer\1644f9b7.msp
c:\windows\Installer\1644f9b8.msp
c:\windows\Installer\1644f9b9.msp
c:\windows\Installer\1644f9ba.msp
c:\windows\Installer\1644f9bb.msp
c:\windows\Installer\1644f9bc.msp
c:\windows\Installer\1644f9bd.msp
c:\windows\Installer\1644f9be.msp
c:\windows\Installer\16b9e2f.msp
c:\windows\Installer\16b9e30.msp
c:\windows\Installer\16b9e31.msp
c:\windows\Installer\16b9e32.msp
c:\windows\Installer\16b9e33.msp
c:\windows\Installer\16b9e34.msp
c:\windows\Installer\16b9e35.msp
c:\windows\Installer\16b9e36.msp
c:\windows\Installer\16b9e37.msp
c:\windows\Installer\17b74b0.msp
c:\windows\Installer\17b74b1.msp
c:\windows\Installer\17b74b2.msp
c:\windows\Installer\17b74b3.msp
c:\windows\Installer\17b74b4.msp
c:\windows\Installer\17b74b5.msp
c:\windows\Installer\17b74b6.msp
c:\windows\Installer\17b74b7.msp
c:\windows\Installer\17b74b8.msp
c:\windows\Installer\17dec0e8.msp
c:\windows\Installer\17dec0e9.msp
c:\windows\Installer\17dec0ea.msp
c:\windows\Installer\17dec0eb.msp
c:\windows\Installer\17dec0ec.msp
c:\windows\Installer\17dec0ed.msp
c:\windows\Installer\17dec0ee.msp
c:\windows\Installer\17dec0ef.msp
c:\windows\Installer\17dec0f0.msp
c:\windows\Installer\1a9b5b81.msp
c:\windows\Installer\1abc49c.msp
c:\windows\Installer\1abc49d.msp
c:\windows\Installer\1abc49e.msp
c:\windows\Installer\1abc49f.msp
c:\windows\Installer\1abc4a0.msp
c:\windows\Installer\1abc4a1.msp
c:\windows\Installer\1abc4a2.msp
c:\windows\Installer\1abc4a3.msp
c:\windows\Installer\1abc4a4.msp
c:\windows\Installer\1b6b4f7c.msp
c:\windows\Installer\1b6b4f7d.msp
c:\windows\Installer\1b6b4f7e.msp
c:\windows\Installer\1b6b4f7f.msp
c:\windows\Installer\1b6b4f80.msp
c:\windows\Installer\1b6b4f81.msp
c:\windows\Installer\1b6b4f82.msp
c:\windows\Installer\1b6b4f83.msp
c:\windows\Installer\1b6b4f84.msp
c:\windows\Installer\1d050c8d.msp
c:\windows\Installer\1d050c8e.msp
c:\windows\Installer\1d050c8f.msp
c:\windows\Installer\1d050c90.msp
c:\windows\Installer\1d050c91.msp
c:\windows\Installer\1d050c92.msp
c:\windows\Installer\1d050c93.msp
c:\windows\Installer\1d050c94.msp
c:\windows\Installer\1d050c95.msp
c:\windows\Installer\1d174.msi
c:\windows\Installer\1fce6fe.msp
c:\windows\Installer\1fce6ff.msp
c:\windows\Installer\1fce700.msp
c:\windows\Installer\1fce701.msp
c:\windows\Installer\1fce702.msp
c:\windows\Installer\1fce703.msp
c:\windows\Installer\1fce704.msp
c:\windows\Installer\1fce705.msp
c:\windows\Installer\1fce706.msp
c:\windows\Installer\2038d53.msp
c:\windows\Installer\2038d54.msp
c:\windows\Installer\2038d55.msp
c:\windows\Installer\2038d56.msp
c:\windows\Installer\2038d57.msp
c:\windows\Installer\2038d58.msp
c:\windows\Installer\2038d59.msp
c:\windows\Installer\2038d5a.msp
c:\windows\Installer\2038d5b.msp
c:\windows\Installer\2047cb5.msp
c:\windows\Installer\2047cb6.msp
c:\windows\Installer\2047cb7.msp
c:\windows\Installer\2047cb8.msp
c:\windows\Installer\2047cb9.msp
c:\windows\Installer\2047cba.msp
c:\windows\Installer\2047cbb.msp
c:\windows\Installer\2047cbc.msp
c:\windows\Installer\2047cbd.msp
c:\windows\Installer\2091af35.msp
c:\windows\Installer\2091af36.msp
c:\windows\Installer\2091af37.msp
c:\windows\Installer\2091af38.msp
c:\windows\Installer\2091af39.msp
c:\windows\Installer\2091af3a.msp
c:\windows\Installer\2091af3b.msp
c:\windows\Installer\2091af3c.msp
c:\windows\Installer\2091af3d.msp
c:\windows\Installer\222b7232.msp
c:\windows\Installer\222b7233.msp
c:\windows\Installer\222b7234.msp
c:\windows\Installer\222b7235.msp
c:\windows\Installer\222b7236.msp
c:\windows\Installer\222b7237.msp
c:\windows\Installer\222b7238.msp
c:\windows\Installer\222b7239.msp
c:\windows\Installer\222b723a.msp
c:\windows\Installer\223a6bc.msp
c:\windows\Installer\223a6bd.msp
c:\windows\Installer\223a6be.msp
c:\windows\Installer\223a6bf.msp
c:\windows\Installer\223a6c0.msp
c:\windows\Installer\223a6c1.msp
c:\windows\Installer\223a6c2.msp
c:\windows\Installer\223a6c3.msp
c:\windows\Installer\223a6c4.msp
c:\windows\Installer\2292758.msp
c:\windows\Installer\22d3f66.msp
c:\windows\Installer\22d3f67.msp
c:\windows\Installer\22d3f68.msp
c:\windows\Installer\22d3f69.msp
c:\windows\Installer\22d3f6a.msp
c:\windows\Installer\22d3f6b.msp
c:\windows\Installer\22d3f6c.msp
c:\windows\Installer\22d3f6d.msp
c:\windows\Installer\22d3f6e.msp
c:\windows\Installer\22e4117.msp
c:\windows\Installer\22e4118.msp
c:\windows\Installer\22e4119.msp
c:\windows\Installer\22e411a.msp
c:\windows\Installer\22e411b.msp
c:\windows\Installer\22e411c.msp
c:\windows\Installer\22e411d.msp
c:\windows\Installer\22e411e.msp
c:\windows\Installer\22e411f.msp
c:\windows\Installer\2305803f.msp
c:\windows\Installer\24c81.msp
c:\windows\Installer\24c82.msp
c:\windows\Installer\24c83.msp
c:\windows\Installer\24c84.msp
c:\windows\Installer\24c85.msp
c:\windows\Installer\24c86.msp
c:\windows\Installer\24c87.msp
c:\windows\Installer\24c88.msp
c:\windows\Installer\24c89.msp
c:\windows\Installer\25b7f2ac.msp
c:\windows\Installer\25b7f2ad.msp
c:\windows\Installer\25b7f2ae.msp
c:\windows\Installer\25b7f2af.msp
c:\windows\Installer\25b7f2b0.msp
c:\windows\Installer\25b7f2b1.msp
c:\windows\Installer\25b7f2b2.msp
c:\windows\Installer\25b7f2b3.msp
c:\windows\Installer\25b7f2b4.msp
c:\windows\Installer\2750074c.msp
c:\windows\Installer\2750074d.msp
c:\windows\Installer\2750074e.msp
c:\windows\Installer\2750074f.msp
c:\windows\Installer\27500750.msp
c:\windows\Installer\27500751.msp
c:\windows\Installer\27500752.msp
c:\windows\Installer\27500753.msp
c:\windows\Installer\27500754.msp
c:\windows\Installer\304b2454.msp
c:\windows\Installer\319d67b2.msp
c:\windows\Installer\319d67b3.msp
c:\windows\Installer\319d67b4.msp
c:\windows\Installer\319d67b5.msp
c:\windows\Installer\319d67b6.msp
c:\windows\Installer\319d67b7.msp
c:\windows\Installer\319d67b8.msp
c:\windows\Installer\319d67b9.msp
c:\windows\Installer\319d67ba.msp
c:\windows\Installer\3238f9c.msp
c:\windows\Installer\3238f9d.msp
c:\windows\Installer\3238f9e.msp
c:\windows\Installer\3238f9f.msp
c:\windows\Installer\3238fa0.msp
c:\windows\Installer\3238fa1.msp
c:\windows\Installer\3238fa2.msp
c:\windows\Installer\3238fa3.msp
c:\windows\Installer\3238fa4.msp
c:\windows\Installer\3424b.msp
c:\windows\Installer\3424c.msp
c:\windows\Installer\3424d.msp
c:\windows\Installer\3424e.msp
c:\windows\Installer\3424f.msp
c:\windows\Installer\34250.msp
c:\windows\Installer\34251.msp
c:\windows\Installer\34252.msp
c:\windows\Installer\34253.msp
c:\windows\Installer\3454cd1.msp
c:\windows\Installer\3454cd2.msp
c:\windows\Installer\3454cd3.msp
c:\windows\Installer\3454cd4.msp
c:\windows\Installer\3454cd5.msp
c:\windows\Installer\3454cd6.msp
c:\windows\Installer\3454cd7.msp
c:\windows\Installer\3454cd8.msp
c:\windows\Installer\3454cd9.msp
c:\windows\Installer\345b399f.msp
c:\windows\Installer\36c2f3fe.msp
c:\windows\Installer\36c2f3ff.msp
c:\windows\Installer\36c2f400.msp
c:\windows\Installer\36c2f401.msp
c:\windows\Installer\36c2f402.msp
c:\windows\Installer\36c2f403.msp
c:\windows\Installer\36c2f404.msp
c:\windows\Installer\36c2f405.msp
c:\windows\Installer\36c2f406.msp
c:\windows\Installer\379b5ef.msp
c:\windows\Installer\379b5f0.msp
c:\windows\Installer\379b5f1.msp
c:\windows\Installer\379b5f2.msp
c:\windows\Installer\379b5f3.msp
c:\windows\Installer\379b5f4.msp
c:\windows\Installer\379b5f5.msp
c:\windows\Installer\379b5f6.msp
c:\windows\Installer\379b5f7.msp
c:\windows\Installer\393782c.msp
c:\windows\Installer\393782d.msp
c:\windows\Installer\393782e.msp
c:\windows\Installer\393782f.msp
c:\windows\Installer\3937830.msp
c:\windows\Installer\3937831.msp
c:\windows\Installer\3937832.msp
c:\windows\Installer\3937833.msp
c:\windows\Installer\3937834.msp
c:\windows\Installer\3be942a0.msp
c:\windows\Installer\3be942a1.msp
c:\windows\Installer\3be942a2.msp
c:\windows\Installer\3be942a3.msp
c:\windows\Installer\3be942a4.msp
c:\windows\Installer\3be942a5.msp
c:\windows\Installer\3be942a6.msp
c:\windows\Installer\3be942a7.msp
c:\windows\Installer\3be942a8.msp
c:\windows\Installer\4051159.msp
c:\windows\Installer\405115a.msp
c:\windows\Installer\405115b.msp
c:\windows\Installer\405115c.msp
c:\windows\Installer\405115d.msp
c:\windows\Installer\405115e.msp
c:\windows\Installer\405115f.msp
c:\windows\Installer\4051160.msp
c:\windows\Installer\4051161.msp
c:\windows\Installer\410fa7b8.msp
c:\windows\Installer\410fa7b9.msp
c:\windows\Installer\410fa7ba.msp
c:\windows\Installer\410fa7bb.msp
c:\windows\Installer\410fa7bc.msp
c:\windows\Installer\410fa7bd.msp
c:\windows\Installer\410fa7be.msp
c:\windows\Installer\410fa7bf.msp
c:\windows\Installer\410fa7c0.msp
c:\windows\Installer\46360abd.msp
c:\windows\Installer\46360abe.msp
c:\windows\Installer\46360abf.msp
c:\windows\Installer\46360ac0.msp
c:\windows\Installer\46360ac1.msp
c:\windows\Installer\46360ac2.msp
c:\windows\Installer\46360ac3.msp
c:\windows\Installer\46360ac4.msp
c:\windows\Installer\46360ac5.msp
c:\windows\Installer\46684eb.msp
c:\windows\Installer\46684ec.msp
c:\windows\Installer\46684ed.msp
c:\windows\Installer\46684ee.msp
c:\windows\Installer\46684ef.msp
c:\windows\Installer\46684f0.msp
c:\windows\Installer\46684f1.msp
c:\windows\Installer\46684f2.msp
c:\windows\Installer\46684f3.msp
c:\windows\Installer\46c9c00.msp
c:\windows\Installer\46c9c01.msp
c:\windows\Installer\46c9c02.msp
c:\windows\Installer\46c9c03.msp
c:\windows\Installer\46c9c04.msp
c:\windows\Installer\46c9c05.msp
c:\windows\Installer\46c9c06.msp
c:\windows\Installer\46c9c07.msp
c:\windows\Installer\46c9c08.msp
c:\windows\Installer\4a5962f.msp
c:\windows\Installer\4a59630.msp
c:\windows\Installer\4a59631.msp
c:\windows\Installer\4a59632.msp
c:\windows\Installer\4a59633.msp
c:\windows\Installer\4a59634.msp
c:\windows\Installer\4a59635.msp
c:\windows\Installer\4a59636.msp
c:\windows\Installer\4a59637.msp
c:\windows\Installer\4b5ff17a.msp
c:\windows\Installer\4b5ff17b.msp
c:\windows\Installer\4b5ff17c.msp
c:\windows\Installer\4b5ff17d.msp
c:\windows\Installer\4b5ff17e.msp
c:\windows\Installer\4b5ff17f.msp
c:\windows\Installer\4b5ff180.msp
c:\windows\Installer\4b5ff181.msp
c:\windows\Installer\4b5ff182.msp
c:\windows\Installer\4e7d5b7.msp
c:\windows\Installer\4e7d5b8.msp
c:\windows\Installer\4e7d5b9.msp
c:\windows\Installer\4e7d5ba.msp
c:\windows\Installer\4e7d5bb.msp
c:\windows\Installer\4e7d5bc.msp
c:\windows\Installer\4e7d5bd.msp
c:\windows\Installer\4e7d5be.msp
c:\windows\Installer\4e7d5bf.msp
c:\windows\Installer\4f31260f.msp
c:\windows\Installer\4f75dca.msp
c:\windows\Installer\4f75dcb.msp
c:\windows\Installer\4f75dcc.msp
c:\windows\Installer\4f75dcd.msp
c:\windows\Installer\4f75dce.msp
c:\windows\Installer\4f75dcf.msp
c:\windows\Installer\4f75dd0.msp
c:\windows\Installer\4f75dd1.msp
c:\windows\Installer\4f75dd2.msp
c:\windows\Installer\5086546f.msp
c:\windows\Installer\50865470.msp
c:\windows\Installer\50865471.msp
c:\windows\Installer\50865472.msp
c:\windows\Installer\50865473.msp
c:\windows\Installer\50865474.msp
c:\windows\Installer\50865475.msp
c:\windows\Installer\50865476.msp
c:\windows\Installer\50865477.msp
c:\windows\Installer\51fcc02.msp
c:\windows\Installer\51fcc03.msp
c:\windows\Installer\51fcc04.msp
c:\windows\Installer\51fcc05.msp
c:\windows\Installer\51fcc06.msp
c:\windows\Installer\51fcc07.msp
c:\windows\Installer\51fcc08.msp
c:\windows\Installer\51fcc09.msp
c:\windows\Installer\51fcc0a.msp
c:\windows\Installer\521124e.msp
c:\windows\Installer\521124f.msp
c:\windows\Installer\5211250.msp
c:\windows\Installer\5211251.msp
c:\windows\Installer\5211252.msp
c:\windows\Installer\5211253.msp
c:\windows\Installer\5211254.msp
c:\windows\Installer\5211255.msp
c:\windows\Installer\5211256.msp
c:\windows\Installer\527608f.msi
c:\windows\Installer\5457901b.msp
c:\windows\Installer\55acb3da.msp
c:\windows\Installer\55acb3db.msp
c:\windows\Installer\55acb3dc.msp
c:\windows\Installer\55acb3dd.msp
c:\windows\Installer\55acb3de.msp
c:\windows\Installer\55acb3df.msp
c:\windows\Installer\55acb3e0.msp
c:\windows\Installer\55acb3e1.msp
c:\windows\Installer\55acb3e2.msp
c:\windows\Installer\5ad314cc.msp
c:\windows\Installer\5ad314cd.msp
c:\windows\Installer\5ad314ce.msp
c:\windows\Installer\5ad314cf.msp
c:\windows\Installer\5ad314d0.msp
c:\windows\Installer\5ad314d1.msp
c:\windows\Installer\5ad314d2.msp
c:\windows\Installer\5ad314d3.msp
c:\windows\Installer\5ad314d4.msp
c:\windows\Installer\5ff95cc7.msp
c:\windows\Installer\5ff95cc8.msp
c:\windows\Installer\5ff95cc9.msp
c:\windows\Installer\5ff95cca.msp
c:\windows\Installer\5ff95ccb.msp
c:\windows\Installer\5ff95ccc.msp
c:\windows\Installer\5ff95ccd.msp
c:\windows\Installer\5ff95cce.msp
c:\windows\Installer\5ff95ccf.msp
c:\windows\Installer\651fc8d4.msp
c:\windows\Installer\651fc8d5.msp
c:\windows\Installer\651fc8d6.msp
c:\windows\Installer\651fc8d7.msp
c:\windows\Installer\651fc8d8.msp
c:\windows\Installer\651fc8d9.msp
c:\windows\Installer\651fc8da.msp
c:\windows\Installer\651fc8db.msp
c:\windows\Installer\651fc8dc.msp
c:\windows\Installer\6a461a16.msp
c:\windows\Installer\6a461a17.msp
c:\windows\Installer\6a461a18.msp
c:\windows\Installer\6a461a19.msp
c:\windows\Installer\6a461a1a.msp
c:\windows\Installer\6a461a1b.msp
c:\windows\Installer\6a461a1c.msp
c:\windows\Installer\6a461a1d.msp
c:\windows\Installer\6a461a1e.msp
c:\windows\Installer\6d1dd49.msp
c:\windows\Installer\6d1dd4a.msp
c:\windows\Installer\6d1dd4b.msp
c:\windows\Installer\6d1dd4c.msp
c:\windows\Installer\6d1dd4d.msp
c:\windows\Installer\6d1dd4e.msp
c:\windows\Installer\6d1dd4f.msp
c:\windows\Installer\6d1dd50.msp
c:\windows\Installer\6d1dd51.msp
c:\windows\Installer\74d9699.msp
c:\windows\Installer\86baf88.msp
c:\windows\Installer\86baf89.msp
c:\windows\Installer\86baf8a.msp
c:\windows\Installer\86baf8b.msp
c:\windows\Installer\86baf8c.msp
c:\windows\Installer\86baf8d.msp
c:\windows\Installer\86baf8e.msp
c:\windows\Installer\86baf8f.msp
c:\windows\Installer\86baf90.msp
c:\windows\Installer\945fafc.msp
c:\windows\Installer\a2053.msp
c:\windows\Installer\a607b6c.msp
c:\windows\Installer\aa18b0.msi
c:\windows\Installer\b24313.msp
c:\windows\Installer\b24314.msp
c:\windows\Installer\b24315.msp
c:\windows\Installer\b24316.msp
c:\windows\Installer\b24317.msp
c:\windows\Installer\b24318.msp
c:\windows\Installer\b24319.msp
c:\windows\Installer\b2431a.msp
c:\windows\Installer\b2431b.msp
c:\windows\Installer\bf184.msi
c:\windows\Installer\c75ec29.msp
c:\windows\Installer\d84898.msp
c:\windows\Installer\d84899.msp
c:\windows\Installer\d8489a.msp
c:\windows\Installer\d8489b.msp
c:\windows\Installer\d8489c.msp
c:\windows\Installer\d8489d.msp
c:\windows\Installer\d8489e.msp
c:\windows\Installer\d8489f.msp
c:\windows\Installer\d848a0.msp
c:\windows\Installer\d920d9b.msp
c:\windows\Installer\d920d9c.msp
c:\windows\Installer\d920d9d.msp
c:\windows\Installer\d920d9e.msp
c:\windows\Installer\d920d9f.msp
c:\windows\Installer\d920da0.msp
c:\windows\Installer\d920da1.msp
c:\windows\Installer\d920da2.msp
c:\windows\Installer\d920da3.msp
c:\windows\Installer\efd96e3.msp
c:\windows\Installer\RadLinker.msi
c:\windows\RM.exe
c:\windows\system32\mdm.exe
c:\windows\Temp\1.exe
----- BITS: Possible infected sites -----
hxxp://78.157.143.163
hxxp://binuser.fileave.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.
2009-07-16 01:32 . 2009-07-16 01:32 -------- d-----w- c:\program files\Trend Micro
2009-07-16 00:39 . 2009-07-16 00:40 -------- d-s---w- C:\Combo-Fix
2009-07-16 00:03 . 2009-07-16 00:23 -------- d-----w- C:\123Qoobox
2009-07-15 22:26 . 2009-07-15 22:26 -------- d-----w- c:\program files\Sophos
2009-07-15 21:42 . 2009-07-15 21:42 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-25 00:19 . 2009-06-25 00:19 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\nView_Profiles
2009-06-25 00:17 . 2009-06-25 00:17 -------- d-----w- c:\program files\AGEIA Technologies
2009-06-25 00:17 . 2009-06-25 00:17 -------- d-----w- c:\windows\system32\AGEIA
2009-06-16 19:54 . 2009-06-16 19:54 -------- d-----w- c:\program files\PopCap Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-16 04:10 . 2007-03-03 01:08 -------- d-----w- c:\documents and settings\me\Application Data\DMCache
2009-07-16 04:10 . 2007-03-03 01:08 -------- d-----w- c:\docume~1\me\APPLIC~1\DMCache
2009-07-16 00:31 . 2005-06-10 11:42 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\McAfee
2009-07-15 21:10 . 2009-01-13 17:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-15 18:58 . 2007-02-21 05:24 -------- d-----w- c:\documents and settings\me\Application Data\R-Wipe&Clean
2009-07-15 18:58 . 2007-02-21 05:24 -------- d-----w- c:\docume~1\me\APPLIC~1\R-Wipe&Clean
2009-07-13 20:36 . 2009-01-13 17:13 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 20:36 . 2009-01-13 17:13 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 15:22 . 2009-02-22 00:26 -------- d-----w- c:\documents and settings\me\Application Data\Vidalia
2009-07-12 15:22 . 2009-02-22 00:26 -------- d-----w- c:\docume~1\me\APPLIC~1\Vidalia
2009-07-12 15:22 . 2009-02-22 00:38 -------- d-----w- c:\documents and settings\me\Application Data\tor
2009-07-12 15:22 . 2009-02-22 00:38 -------- d-----w- c:\docume~1\me\APPLIC~1\tor
2009-06-25 15:25 . 2007-01-24 06:56 -------- d-----w- c:\program files\CoffeeCup Software
2009-06-25 00:17 . 2005-06-10 12:01 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-20 21:50 . 2008-10-15 16:15 889360 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-19 18:58 . 2009-06-09 13:48 -------- d-----w- c:\documents and settings\me\Application Data\nHancer
2009-06-19 18:58 . 2009-06-09 13:48 -------- d-----w- c:\docume~1\me\APPLIC~1\nHancer
2009-06-17 02:02 . 2007-03-31 04:43 138016 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-17 02:02 . 2007-03-31 04:43 189392 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-06-12 14:42 . 2009-06-12 14:39 -------- d-----w- c:\program files\nLite
2009-06-10 22:53 . 2009-06-06 15:36 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\AA3DeployClient
2009-06-10 22:35 . 2005-09-03 18:16 1984 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-10 16:46 . 2007-04-10 04:13 -------- d-----w- c:\documents and settings\me\Application Data\IDM
2009-06-10 16:46 . 2007-04-10 04:13 -------- d-----w- c:\docume~1\me\APPLIC~1\IDM
2009-06-10 15:28 . 2009-06-10 15:28 3510272 ----a-w- c:\windows\system32\nvgames.dll
2009-06-10 15:28 . 2009-06-10 15:28 4022272 ----a-w- c:\windows\system32\nvdisps.dll
2009-06-10 15:28 . 2009-06-10 15:28 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-06-10 15:28 . 2009-06-10 15:28 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-06-10 15:28 . 2009-06-10 15:28 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-06-10 15:28 . 2009-06-10 15:28 13758464 ----a-w- c:\windows\system32\nvcpl.dll
2009-06-10 15:28 . 2009-06-10 15:28 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-06-10 13:57 . 2009-06-10 13:57 -------- d-----w- c:\documents and settings\me\Application Data\IGN_DLM
2009-06-10 13:57 . 2009-06-10 13:57 -------- d-----w- c:\docume~1\me\APPLIC~1\IGN_DLM
2009-06-10 13:39 . 2005-06-10 12:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-10 13:38 . 2005-06-10 12:07 -------- d-----w- c:\program files\Symantec
2009-06-10 13:28 . 2009-01-29 00:25 -------- d-----w- c:\program files\Jigsaw Puzzle Platinum Edition
2009-06-10 13:03 . 2009-06-10 13:03 9998336 ----a-w- c:\windows\system32\nvoglnt.dll
2009-06-10 13:03 . 2009-06-10 13:03 815104 ----a-w- c:\windows\system32\nvapi.dll
2009-06-10 13:03 . 2009-06-10 13:03 8087712 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-06-10 13:03 . 2009-06-10 13:03 671744 ----a-w- c:\windows\system32\nvcuvid.dll
2009-06-10 13:03 . 2009-06-10 13:03 5908608 ----a-w- c:\windows\system32\nv4_disp.dll
2009-06-10 13:03 . 2009-06-10 13:03 1720320 ----a-w- c:\windows\system32\nvcuda.dll
2009-06-10 13:03 . 2009-06-10 13:03 1580550 ----a-w- c:\windows\system32\nvdata.bin
2009-06-10 13:03 . 2009-06-10 13:03 151552 ----a-w- c:\windows\system32\nvcodins.dll
2009-06-10 13:03 . 2009-06-10 13:03 151552 ----a-w- c:\windows\system32\nvcod.dll
2009-06-10 13:03 . 2009-06-10 13:03 1310720 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-06-10 13:03 . 2006-12-31 04:30 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-06-09 13:49 . 2006-12-31 04:35 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\NVIDIA
2009-06-09 13:49 . 2009-06-09 13:47 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\nHancer
2009-06-09 13:34 . 2009-06-09 13:34 -------- d-----w- c:\program files\SystemRequirementsLab
2009-06-09 03:55 . 2008-05-08 05:01 -------- d-----w- c:\program files\UltraLeecher
2009-06-09 03:54 . 2005-09-28 00:06 -------- d-----w- c:\program files\TuneUp Utilities 2006
2009-06-09 03:53 . 2006-09-19 13:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-09 03:53 . 2006-09-19 13:35 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-06-09 03:46 . 2006-04-20 13:32 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft Help
2009-06-09 03:46 . 2006-04-20 13:32 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-06-09 03:44 . 2009-06-09 03:44 -------- d--h--w- c:\program files\Zero G Registry
2009-06-09 03:42 . 2007-10-06 16:57 -------- d-----w- c:\program files\IrfanView
2009-06-09 03:42 . 2005-06-10 12:01 -------- d-----w- c:\program files\Hewlett-Packard
2009-06-09 03:42 . 2006-09-15 06:03 -------- d-----w- c:\program files\IGN
2009-06-09 03:28 . 2005-06-10 12:01 -------- d-----w- c:\program files\Fraps
2009-06-09 03:27 . 2008-09-09 21:44 -------- d-----w- c:\program files\Exodus
2009-06-09 03:27 . 2005-08-12 06:52 -------- d-----w- c:\documents and settings\me\Application Data\Exodus
2009-06-09 03:27 . 2005-08-12 06:52 -------- d-----w- c:\docume~1\me\APPLIC~1\Exodus
2009-06-09 03:26 . 2007-03-30 02:30 -------- d-----w- c:\program files\DAZ
2009-06-09 03:23 . 2005-06-10 11:59 -------- d-----w- c:\program files\ASUS
2009-06-09 03:22 . 2005-06-10 12:00 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-09 03:22 . 2006-12-26 04:19 -------- d-----w- c:\documents and settings\me\Application Data\Lavasoft
2009-06-09 03:22 . 2006-12-26 04:19 -------- d-----w- c:\docume~1\me\APPLIC~1\Lavasoft
2009-06-09 03:21 . 2007-06-27 04:15 -------- d-----w- c:\program files\123Movies2PSP
2009-06-08 03:57 . 2006-10-15 10:01 4764 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2009-06-08 03:27 . 2009-06-08 03:27 906 ----a-w- C:\fix.bat
2009-06-06 02:32 . 2007-03-31 04:43 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-06-06 02:17 . 2009-06-06 02:16 -------- d-----w- c:\program files\America's Army test
2009-06-06 02:09 . 2005-10-21 17:09 -------- d-----w- c:\program files\MasterSplitter
2009-06-06 01:43 . 2008-03-08 22:17 142200 ----a-w- c:\documents and settings\me\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-06 01:43 . 2008-03-08 22:17 142200 ----a-w- c:\docume~1\me\LOCALS~1\APPLIC~1\GDIPFONTCACHEV1.DAT
2009-06-06 01:01 . 2009-06-06 00:36 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\AA2DeployClient
2009-06-04 23:39 . 2006-06-20 12:18 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-03 22:41 . 2008-05-08 05:02 37472 ----a-w- c:\windows\Fonts\INFOview.fon\infoview.fon
2009-06-03 22:41 . 2008-05-08 05:02 -------- d-----w- c:\windows\Fonts\INFOview.fon
2009-05-31 17:12 . 2009-05-31 17:12 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\MumboJumbo
2009-05-29 21:17 . 2009-05-29 21:17 -------- d-----w- c:\documents and settings\me\Application Data\EPSON
2009-05-29 21:17 . 2009-05-29 21:17 -------- d-----w- c:\docume~1\me\APPLIC~1\EPSON
2009-05-29 21:12 . 2009-05-29 21:12 -------- d-----w- c:\program files\epson
2009-05-28 18:59 . 2007-08-22 04:46 59160 ----a-w- c:\windows\system32\zlib.dll
2009-05-28 15:06 . 2009-05-28 15:06 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-28 15:06 . 2005-06-10 12:01 -------- d-----w- c:\program files\Java
2009-05-28 15:06 . 2009-05-28 15:06 152576 ----a-w- c:\documents and settings\me\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-27 01:24 . 2008-03-13 00:48 -------- d-----w- c:\program files\VMware
2009-05-27 01:24 . 2008-03-13 00:48 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\VMware
2009-05-27 01:03 . 2009-05-27 01:03 -------- d-----w- c:\program files\Electronic Arts
2009-05-05 20:35 . 2009-05-05 20:35 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-05-05 20:35 . 2009-05-05 20:35 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-04-28 16:55 . 2009-04-28 16:55 70936 ----a-w- c:\windows\system32\PhysXLoader.dll
2003-08-27 22:19 . 2005-01-30 19:29 36963 ----a-r- c:\program files\Common Files\SM1updtr.dll
2009-06-16 15:58 . 2009-02-22 00:34 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2002-08-01 02:55 . 2007-01-24 06:56 106 --sh--w- c:\windows\WSYS049.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2007-04-10 894720]
"RWipeD"="c:\program files\R-Wipe&Clean\rwiped.exe" [2007-02-15 32768]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2006-04-07 135168]
"DT HPW"="c:\program files\Portrait Displays\HP My Display\DTHtml.exe" [2007-06-29 278528]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 158208]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2005-07-23 28160]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CtHelper.exe [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\Ctxfihlp.exe [2008-07-11 19968]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-10-19 293888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 23:13 49152 ----a-w- c:\progra~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Multi]
2005-04-17 23:36 90112 ----a-w- c:\program files\Stardock\ThinkDesk\Multiplicity\MultiWin32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\acaptuser32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt\0sprestrt
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Home Server.lnk]
backup=c:\windows\pss\Windows Home Server.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^me^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^me^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=c:\windows\pss\MagicDisc.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ltme
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pjgj
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SolidWorks_CheckForUpdates
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3 (0x3)
"aliasdocserver"=2 (0x2)
"Norton Ghost"=3 (0x3)
"MskService"=2 (0x2)
"x10nets"=3 (0x3)
"Speed Disk service"=2 (0x2)
"RadClock"=2 (0x2)
"MCVSRte"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"wampmysqld"=3 (0x3)
"wampapache"=3 (0x3)
"TapiSrv"=3 (0x3)
"Symantec Core LC"=2 (0x2)
"svcWRSSSDK"=2 (0x2)
"SQLWriter"=2 (0x2)
"SolidWorks Licensing Service"=3 (0x3)
"SCardSvr"=3 (0x3)
"SandraTheSrv"=3 (0x3)
"SandraDataSrv"=3 (0x3)
"ose"=3 (0x3)
"O&O Defrag"=2 (0x2)
"NProtectService"=2 (0x2)
"Multiplicity"=2 (0x2)
"MSSQL$SQLEXPRESS"=2 (0x2)
"mnmsrvc"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"GuardDogEXE"=3 (0x3)
"GoToMyPC"=2 (0x2)
"DTSRVC"=2 (0x2)
"ColdFusion MX 7 Search Server"=3 (0x3)
"ColdFusion MX 7 Application Server"=3 (0x3)
"Bonjour Service"=2 (0x2)
"ATI Smart"=2 (0x2)
"Asset Management Daemon"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
"|MicServiceAP"=2 (0x2)
"|MicServiceA8"=2 (0x2)
"SwPrv"=3 (0x3)
"RSVP"=3 (0x3)
"RemoteRegistry"=2 (0x2)
"RDSessMgr"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"igndlm.exe"=c:\program files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe"
"Microsoft® Windows® Operating System"="c:\windows\system32\wuaumgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"MSConfig"=c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"Launch Ai Booster"="c:\program files\ASUS\Ai Booster\OverClk.exe"
"NVRaidService"=c:\windows\system32\nvraidservice.exe
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Software\wpctrl.exe"
"GrooveMonitor"="c:\program files\Microsoft Office7\Office12\GrooveMonitor.exe"
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe"
"TrueImageMonitor.exe"=c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
"Logitech Hardware Abstraction Layer"=KHALMNPR.EXE
"Copperhead"=c:\program files\Razer\Copperhead\razerhid.exe
"AcronisTimounterMonitor"=c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
"Microsoft® Windows® Operating System"="c:\windows\system32\wuaumgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\America's Army test\\System\\ArmyOps.exe"=
R0 ABIT-IO;ABIT-IO;c:\windows\system32\drivers\ABIT-IO.SYS [10/13/2005 2:18 AM 7680]
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [10/13/2005 2:19 AM 16640]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [7/29/2004 5:13 AM 46779]
R2 BCMNTIO;BCMNTIO;c:\progra~1\CheckIt\DIAGNO~1\BCMNTIO.sys [3/6/2005 5:19 PM 3744]
R2 FLEXlm Service 1;FLEXlm Service 1;c:\autodesk network license manager\lmgrd.exe [1/29/2005 12:46 PM 659456]
R2 GdFsHook;McAfee Privacy Service File Guardian;c:\windows\system32\drivers\gdfshk.sys [9/17/2003 7:00 AM 26816]
R2 GdTdi;McAfee Privacy Service Transport Filter;c:\windows\system32\drivers\gdtdi.sys [9/17/2003 7:00 AM 33330]
R2 LANPkt;Linksys LANPkt Protocol Driver;c:\windows\system32\drivers\LANPkt.sys [10/13/2005 5:32 AM 8568]
R2 MAPMEM;MAPMEM;c:\progra~1\CheckIt\DIAGNO~1\MAPMEM.sys [3/6/2005 5:19 PM 3904]
R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\pfmodnt.sys [11/17/2007 11:02 PM 15896]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [5/5/2009 1:35 PM 604416]
S0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [7/29/2004 4:33 AM 138780]
S1 atitray;atitray;\??\c:\program files\Ray Adams\ATI Tray Tools\atitray.sys --> c:\program files\Ray Adams\ATI Tray Tools\atitray.sys [?]
S2 WinDefend;Windows Defender Service;"c:\program files\Windows Defender\MsMpEng.exe" --> c:\program files\Windows Defender\MsMpEng.exe [?]
S3 Asushwio;Asushwio;c:\windows\system32\drivers\ASUSHWIO.SYS [1/15/2005 4:12 PM 5824]
S3 BS_DEF;BS_DEF;\??\c:\windows\BS_DEF.sys --> c:\windows\BS_DEF.sys [?]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [11/22/2008 10:18 PM 79360]
S3 CW50;CW50 Device;c:\windows\system32\drivers\CW50.sys [1/30/2005 12:38 PM 24059]
S3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [10/13/2005 5:32 AM 11351]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\3.tmp --> c:\windows\system32\3.tmp [?]
S3 Razerlow;Razer Copperhead Driver;c:\windows\system32\drivers\Razerlow.sys [4/15/2006 9:03 PM 19020]
S3 RTLVLANXP;Linksys VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLANXP.SYS [10/13/2005 5:32 AM 15360]
S3 SaiH8000;SaiH8000;c:\windows\system32\drivers\SaiH8000.sys [12/3/2004 4:54 PM 56704]
S3 UltraCrypt;UltraCrypt;\??\c:\program files\UltraLeecher\UltraCrypt.sys --> c:\program files\UltraLeecher\UltraCrypt.sys [?]
S4 ColdFusion MX 7 Application Server;ColdFusion MX 7 Application Server;c:\macromedia\runtime\bin\jrunsvc.exe [3/22/2006 2:00 PM 61440]
S4 ColdFusion MX 7 Search Server;ColdFusion MX 7 Search Server;c:\macromedia\verity\k2\_nti40\bin\k2admin.exe [3/22/2006 1:59 PM 2732608]
S4 GuardDogEXE;McAfee Privacy Service;"c:\program files\McAfee\McAfee Privacy Service\GUARDDOG.EXE" /SERVICE --> c:\program files\McAfee\McAfee Privacy Service\GUARDDOG.EXE [?]
S4 NProtectService;Norton Unerase Protection;c:\progra~1\NORTON~1\NORTON~1\NPROTECT.EXE --> c:\progra~1\NORTON~1\NORTON~1\NPROTECT.EXE [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKU-Default-Run-Spyware Doctor - (no file)
ShellExecuteHooks-{20d8bda1-1958-11d6-b00f-00b0d0c6b6a5} - (no file)
ShellExecuteHooks-{35B2861B-2B26-4691-9FF0-09083722C736} - (no file)
Notify-GoToMyPC - c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
Notify-AtiExtEvent - (no file)
Notify-qoMggfGV - qoMggfGV.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/chsi.html
mSearch Bar =
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Append to existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI8C0D~1\Office12\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
IE: SWF Capture tool - c:\program files\Eltima Software\Flash Decompiler\iebt.html
Trusted Zone: homeserver.com\sten
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\docume~1\me\APPLIC~1\Mozilla\Firefox\Profiles\zrm9qe1b.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\documents and settings\me\Application Data\Mozilla\Firefox\Profiles\zrm9qe1b.default\extensions\mozilla_cc@internetdownloadmanager.com\components\idmmzcc.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPJPI142_06.dll
FF - plugin: c:\program files\Java\j2re1.4.2_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Photosynth\npPhotosynthMozilla.dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-15 21:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1300)
geyekrkcxxccqt.dll 10000000 36864 \\?\globalroot\systemroot\system32\geyekrkcxxccqt.dll
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
c:\program files\Stardock\ThinkDesk\Multiplicity\MultiWin32.dll
- - - - - - - > 'explorer.exe'(3604)
geyekrkcxxccqt.dll 10000000 36864 \\?\globalroot\systemroot\system32\geyekrkcxxccqt.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\progra~1\COMMON~1\stardock\MCPCore.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\COMMON~1\stardock\SDMCP.exe
c:\windows\system32\PnkBstrA.exe
c:\autodesk network license manager\adskflex.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\Common Files\Portrait Displays\Shared\HookManager.exe
c:\progra~1\MICROS~1\rapimgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2009-07-16 21:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-16 04:16
Pre-Run: 13,925,093,376 bytes free
Post-Run: 14,021,410,816 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin /tutag=cbpve9 /kernel=tukernel.exe /usepmtimer
944 --- E O F --- 2008-10-15 15:56
Last mbam log
Malwarebytes' Anti-Malware 1.39 Database version: 2437 Windows 5.1.2600 Service Pack 2 7/15/2009 9:28:10 PM mbam-log-2009-07-15 (21-28-10).txt Scan type: Quick Scan Objects scanned: 96887 Time elapsed: 5 minute(s), 56 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: \\?\globalroot\systemroot\system32\geyekrkcxxccqt.dll (Trojan.TDSS) -> Delete on reboot. Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: \\?\globalroot\systemroot\system32\geyekrkcxxccqt.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
Sign In
Create Account
This topic is locked
Back to top












