Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojans and Popups :( [RESOLVED]


  • This topic is locked This topic is locked

#1
DRugg

DRugg

    Member

  • Member
  • PipPip
  • 19 posts
Hello, I recently got this computer from a buddy that is building a new one. It has a few problems with it, I get lots of pop ups and it seems to slow down. Sometimes I have a hard time viewing web pages as well. I have a .dll file that is wrecking havoc on it but I can not get it to delete. I have an Anti-virus program (Zone-Alarm) and it helps quite a bit with the pop ups but not so much with the critical trojan downloaders and/or vendos. I have the HijackThis Program and heres the list it saved for me:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:36:20 AM, on 5/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [d430f9be] rundll32.exe "C:\WINDOWS\system32\pkhnkcna.dll",b
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [BMd703ca22] Rundll32.exe "C:\WINDOWS\system32\wrecppci.dll",s
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Security Service (JKSQ) - Unknown owner - C:\WINDOWS\system32\svcd\svchost.exe (file missing)
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
O24 - Desktop Component 0: (no name) - (no file)

--
End of file - 3608 bytes


Also, I got the Malwarebyte program that this site recommended and here's its list:

Malwarebytes' Anti-Malware 1.12
Database version: 760

Scan type: Quick Scan
Objects scanned: 38241
Time elapsed: 5 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 21
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 13
Files Infected: 23

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\jkkjh.dll (Trojan.Vundo) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{664c8430-d29c-4bc8-b30f-8f9235a00d8c} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{664c8430-d29c-4bc8-b30f-8f9235a00d8c} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Adware.Search Toolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Adware.Search Toolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{a394e835-c8d6-4b4b-884b-d2709059f3be} (Trojan.Network.Monitor) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920} (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ntload (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\Software\kernelexe (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo (Adware.PurityScan) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService (Adware.CommAd) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Network Monitor (Trojan.Service) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{e180f496-8a4b-44e2-9fe0-0364e345db7f} (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\{59a40ac9-e67d-4155-b31d-4b7330fcd2d6} (Adware.PurityScan) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{ca4f0d8d-5f2b-4f16-838a-8d52249eab21} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BMd703ca22 (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.starsdoor.com (Backdoor.Bot) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\jkkjh -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\jkkjh -> No action taken.

Folders Infected:
C:\Program Files\Outerinfo (Adware.Outerinfo) -> No action taken.
C:\Program Files\Outerinfo\FF (Adware.Outerinfo) -> No action taken.
C:\Program Files\Outerinfo\FF\components (Adware.Outerinfo) -> No action taken.
C:\Program Files\Network Monitor (Trojan.DNSChanger) -> No action taken.
C:\Program Files\InetGet2 (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\e9 (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\t8 (Trojan.Downloader) -> No action taken.
C:\Program Files\Temporary (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\nGpxx01 (Trojan.Downloader) -> No action taken.
C:\Program Files\QdrDrive (Adware.AdBand) -> No action taken.
C:\Program Files\Router (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\NetworkService\Application Data\NetMon (Trojan.NetMon) -> No action taken.
C:\Documents and Settings\LocalService\Application Data\NetMon (Trojan.NetMon) -> No action taken.

Files Infected:
C:\WINDOWS\system32\jkkjh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\hjkkj.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\hjkkj.ini2 (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\atmtd.dll (Adware.TargetSaver) -> No action taken.
C:\WINDOWS\system32\atmtd.dll._ (Adware.TargetSaver) -> No action taken.
C:\WINDOWS\system32\syscfg32.exe (BackDoor.Sdbot) -> No action taken.
C:\WINDOWS\uninstall_nmon.vbs (Malware.Trace) -> No action taken.
C:\sysbtqm.exe (BackDoor.Sdbot) -> No action taken.
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Temp\outerinfo.ico (Malware.Trace) -> No action taken.
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Temp\uninstall.exe (Trojan.Downloader) -> No action taken.
C:\Program Files\Outerinfo\Terms.rtf (Adware.Outerinfo) -> No action taken.
C:\Program Files\Outerinfo\FF\chrome.manifest (Adware.Outerinfo) -> No action taken.
C:\Program Files\Outerinfo\FF\install.rdf (Adware.Outerinfo) -> No action taken.
C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt (Adware.Outerinfo) -> No action taken.
C:\WINDOWS\system32\e9\farstadcom2.exe (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt (Trojan.NetMon) -> No action taken.
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt (Trojan.NetMon) -> No action taken.
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt (Trojan.NetMon) -> No action taken.
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt (Trojan.NetMon) -> No action taken.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\gebxywu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\drivers\core.cache.dsk (Malware.Trace) -> No action taken.
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Tempmbroit.exe (Trojan.FakeAlert) -> No action taken.

Please help, it is greatly appreciated. These problems got my gray hairs a poppin'. :)

Thank you for your time and energy.

<3
  • 0

Advertisements


#2
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there DRugg,

Please follow my instructions in the order they were given, if you come across something you don't understand or don't feel comfortable doing, don't hesitate to ask and I will get you sorted out :)
If you cannot complete a step in my instructions, please skip it and continue with the rest of my instructions and tell me in your next reply which one you were having trouble with.

Preperation

ZoneAlarm is a firewall not an antivirus. Meaning you have no Anti Virus program installed. These programs are necessary in keeping your computer free of malware, without it you are very likely to get re-infected within a very short period of time.
I would like you to download one of these free programs I have listed here for you.
Note: Make sure to only install ONE program, as having more can cause confliction between these programs, which in turn lowers your protection and slows down your computer.

I will also need you to temporarily disable ZoneAlarm as it can conflict with the fixes we want to do, we will re-enable it afterwards.

ZoneAlarm's OS Firewall

1. Go to the Program tab, then click "Main".
2. Press the first "Custom" button from the top.
3. Uncheck "Enable OS Firewall".
4. Click OK.

Running ComboFix

Please go here to install the recovery console and for a guide on using combofix.
Please note: Installing the Recovery Console plays a vital part in making this process of cleaning your computer safe, please don't overlook this!

Download ComboFix from one of the locations below, and save it to your Desktop.

Link 1
Link 2
Link 3

Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
  • 0

#3
DRugg

DRugg

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Hi Mike, thanks for the help.

Here's the combo fix log:

ComboFix 08-05-15.3 - D Mother[bleep]ing Rugg 2008-05-18 15:13:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1503 [GMT -4:00]
Running from: C:\Documents and Settings\D Mother[bleep]ing Rugg\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\D Mother[bleep]ing Rugg\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\FNTS~1
C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\FNTS~1\e?plorer.exe.vzr
C:\Program Files\Common Files\pppatc~1
C:\Program Files\Drmupgds
C:\Program Files\smbols~1
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\fnts~1
C:\WINDOWS\fnts~1\F?nts\
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ancknhkp.ini
C:\WINDOWS\system32\aqisuown.ini
C:\WINDOWS\system32\bfktrrgu.ini
C:\WINDOWS\system32\bhendaip.ini
C:\WINDOWS\system32\bkmoopob.exe
C:\WINDOWS\system32\brvdfjhi.ini
C:\WINDOWS\system32\btvqabxa.ini
C:\WINDOWS\system32\cbvajrsh.ini
C:\WINDOWS\system32\cdnopcpa.ini
C:\WINDOWS\system32\cgjwgwog.ini
C:\WINDOWS\system32\cibirqig.ini
C:\WINDOWS\system32\cjqlcion.ini
C:\WINDOWS\system32\ckcgkyjj.ini
C:\WINDOWS\system32\clurxewp.ini
C:\WINDOWS\system32\cmvmlkiy.ini
C:\WINDOWS\system32\crascweg.ini
C:\WINDOWS\system32\cyewqhsg.ini
C:\WINDOWS\system32\ddnphfmd.ini
C:\WINDOWS\system32\dglivvoo.ini
C:\WINDOWS\system32\diamsjjg.ini
C:\WINDOWS\system32\dmuscche.ini
C:\WINDOWS\system32\dtlcghrt.ini
C:\WINDOWS\system32\eaeofipx.ini
C:\WINDOWS\system32\epqhllst.ini
C:\WINDOWS\system32\euslupxs.ini
C:\WINDOWS\system32\eykcacan.ini
C:\WINDOWS\system32\frfkhvfk.ini
C:\WINDOWS\system32\fvlpliex.ini
C:\WINDOWS\system32\fwmfdssj.ini
C:\WINDOWS\system32\gdlmbdpd.ini
C:\WINDOWS\system32\gioredhv.ini
C:\WINDOWS\system32\gkpslhmi.ini
C:\WINDOWS\system32\gmwtluiy.ini
C:\WINDOWS\system32\gpqtjakm.ini
C:\WINDOWS\system32\gqtmmxcw.ini
C:\WINDOWS\system32\gtmpmjgs.ini
C:\WINDOWS\system32\gvhbdwfj.ini
C:\WINDOWS\system32\gyupilul.ini
C:\WINDOWS\system32\hdxoadxp.ini
C:\WINDOWS\system32\hjkkj.ini
C:\WINDOWS\system32\hjkkj.ini2
C:\WINDOWS\system32\hxtvvfep.ini
C:\WINDOWS\system32\ibyrcghq.ini
C:\WINDOWS\system32\ihudaimm.ini
C:\WINDOWS\system32\ijupkrkq.ini
C:\WINDOWS\system32\ijynuedw.ini
C:\WINDOWS\system32\iohqbgbt.ini
C:\WINDOWS\system32\jbkwpyly.ini
C:\WINDOWS\system32\jkkjh.dll
C:\WINDOWS\system32\jmchonay.ini
C:\WINDOWS\system32\jvxrqsxt.ini
C:\WINDOWS\system32\jyjdddax.ini
C:\WINDOWS\system32\kmhhewvr.ini
C:\WINDOWS\system32\kntcuefp.ini
C:\WINDOWS\system32\koseynjq.ini
C:\WINDOWS\system32\krwipdfc.ini
C:\WINDOWS\system32\lgdkgnsm.ini
C:\WINDOWS\system32\liyeccjy.ini
C:\WINDOWS\system32\lmgahjet.ini
C:\WINDOWS\system32\lnyesesd.ini
C:\WINDOWS\system32\lotwsuci.ini
C:\WINDOWS\system32\lpfcunkg.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdrvsqdu.ini
C:\WINDOWS\system32\mildqcyi.ini
C:\WINDOWS\system32\miskgepk.ini
C:\WINDOWS\system32\mmokhdmx.ini
C:\WINDOWS\system32\mnfrnwtg.ini
C:\WINDOWS\system32\mnkvkatm.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msudkwoy.ini
C:\WINDOWS\system32\mtqolliw.ini
C:\WINDOWS\system32\napdhyfs.ini
C:\WINDOWS\system32\nbbyqdjd.ini
C:\WINDOWS\system32\nfhdomfg.ini
C:\WINDOWS\system32\ngsyfjrg.ini
C:\WINDOWS\system32\nohmfyyk.ini
C:\WINDOWS\system32\noueijnm.ini
C:\WINDOWS\system32\npuqmsul.ini
C:\WINDOWS\system32\nravbklq.ini
C:\WINDOWS\system32\nvuioiet.ini
C:\WINDOWS\system32\oawkfplj.ini
C:\WINDOWS\system32\obgdyeqe.ini
C:\WINDOWS\system32\odmkhgdh.ini
C:\WINDOWS\system32\odwgyapn.ini
C:\WINDOWS\system32\ogmuexwh.ini
C:\WINDOWS\system32\ogmwjjvh.ini
C:\WINDOWS\system32\oljnytox.ini
C:\WINDOWS\system32\onkgbcof.exe
C:\WINDOWS\system32\owwjrtkg.ini
C:\WINDOWS\system32\p2
C:\WINDOWS\system32\pdfhhait.ini
C:\WINDOWS\system32\pexhaqlm.ini
C:\WINDOWS\system32\pkhnkcna.dll
C:\WINDOWS\system32\pthbbqtx.ini
C:\WINDOWS\system32\qciklfhh.ini
C:\WINDOWS\system32\qerjqxnt.ini
C:\WINDOWS\system32\qiliftfw.ini
C:\WINDOWS\system32\qkkuuunp.ini
C:\WINDOWS\system32\qkscjwyb.ini
C:\WINDOWS\system32\qplijgbt.ini
C:\WINDOWS\system32\rgqsnwit.ini
C:\WINDOWS\system32\rhuwylbf.ini
C:\WINDOWS\system32\rklfeayx.ini
C:\WINDOWS\system32\rnpsoygt.ini
C:\WINDOWS\system32\rsujdlcx.ini
C:\WINDOWS\system32\rwuipego.ini
C:\WINDOWS\system32\ryvjqhsg.ini
C:\WINDOWS\system32\sihsyuwh.ini
C:\WINDOWS\system32\siurwxcu.ini
C:\WINDOWS\system32\sojaxiox.ini
C:\WINDOWS\system32\srfinanl.ini
C:\WINDOWS\system32\tahdgjse.ini
C:\WINDOWS\system32\tcplwhpc.ini
C:\WINDOWS\system32\tkyvvxpj.ini
C:\WINDOWS\system32\tuptafxh.ini
C:\WINDOWS\system32\txmcvjcl.ini
C:\WINDOWS\system32\ufgytetn.ini
C:\WINDOWS\system32\uhghgdyf.ini
C:\WINDOWS\system32\uoegcybe.ini
C:\WINDOWS\system32\uqlnadir.ini
C:\WINDOWS\system32\uykxqhof.ini
C:\WINDOWS\system32\vabmmtbv.ini
C:\WINDOWS\system32\vaqqshxx.ini
C:\WINDOWS\system32\vgeeriej.ini
C:\WINDOWS\system32\vmgtdxrb.ini
C:\WINDOWS\system32\vmtvkocn.ini
C:\WINDOWS\system32\vpscfxbm.ini
C:\WINDOWS\system32\vqqfylov.ini
C:\WINDOWS\system32\vrfteilk.ini
C:\WINDOWS\system32\wahmriqw.ini
C:\WINDOWS\system32\walfbpit.ini
C:\WINDOWS\system32\wcoxdmtt.ini
C:\WINDOWS\system32\wdjselnl.ini
C:\WINDOWS\system32\wjqiqfnd.ini
C:\WINDOWS\system32\wmvlbxoe.ini
C:\WINDOWS\system32\wpfuadxt.ini
C:\WINDOWS\system32\wrecppci.dll
C:\WINDOWS\system32\wuuvlvyy.ini
C:\WINDOWS\system32\xrcxjrpv.ini
C:\WINDOWS\system32\xrqsmwtd.ini
C:\WINDOWS\system32\xvjspfix.ini
C:\WINDOWS\system32\ybucoyiq.ini
C:\WINDOWS\system32\ygycewkg.ini
C:\WINDOWS\system32\yjvlyfed.ini
C:\WINDOWS\system32\ymiavhra.ini
C:\WINDOWS\system32\yphofjwo.ini
C:\WINDOWS\system32\yqxghlpp.ini

----- BITS: Possible infected sites -----

hxxp://downloads.networkmagic.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CMDSERVICE
-------\Legacy_NETWORK_MONITOR
-------\Legacy_NTLOAD


((((((((((((((((((((((((( Files Created from 2008-04-18 to 2008-05-18 )))))))))))))))))))))))))))))))
.

2008-05-18 15:18 . 2008-05-18 15:18 <DIR> d-------- C:\Temp\tn3
2008-05-18 15:14 . 2008-05-18 15:14 93,248 --a------ C:\WINDOWS\system32\pcaivhgr.dll.vir
2008-05-18 15:14 . 2008-05-18 15:14 92,736 --a------ C:\WINDOWS\system32\wehhxokk.dll.vir
2008-05-18 15:14 . 2008-05-18 15:14 92,736 --a------ C:\WINDOWS\system32\alhmnrah.dll.vir
2008-05-18 15:14 . 2008-05-18 15:14 87,104 --a------ C:\WINDOWS\system32\fbhqfgsu.dll.vir
2008-05-18 00:36 . 2008-05-18 00:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-18 00:31 . 2008-05-18 00:31 100,928 --a------ C:\WINDOWS\system32\lol
2008-05-18 00:14 . 2008-05-18 00:22 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-18 00:14 . 2008-05-18 00:14 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Malwarebytes
2008-05-18 00:14 . 2008-05-18 00:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-18 00:14 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-18 00:14 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-18 00:13 . 2008-05-18 00:13 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-17 23:52 . 2008-05-17 23:52 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-17 23:52 . 2008-05-18 15:13 1,024 --ah----- C:\Documents and Settings\Administrator\NtUser.dat.LOG
2008-05-17 23:17 . 2008-05-17 23:17 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-05-17 23:11 . 2008-05-17 23:42 <DIR> d-------- C:\VundoFix Backups
2008-04-27 21:28 . 2008-04-27 21:28 94,784 --a------ C:\WINDOWS\system32\qlkbvarn.dll.vzr
2008-04-26 02:25 . 2008-01-08 17:16 23,992 --a------ C:\WINDOWS\system32\drivers\pnarp.sys
2008-04-26 02:24 . 2008-04-26 02:24 <DIR> d-------- C:\Program Files\Common Files\Pure Networks Shared
2008-04-26 02:24 . 2008-01-08 17:16 25,272 --a------ C:\WINDOWS\system32\drivers\purendis.sys
2008-04-24 05:20 . 2008-04-24 05:20 <DIR> d--h----- C:\WINDOWS\PIF
2008-04-24 05:20 . 2008-04-24 05:20 <DIR> d-------- C:\Program Files\7-Zip
2008-04-22 20:37 . 2008-04-22 20:37 87,616 --a------ C:\WINDOWS\system32\xpifoeae.dll.vzr
2008-04-20 21:01 . 2008-04-26 16:53 <DIR> d-------- C:\Program Files\City of Heroes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-18 19:19 5,169,952 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-18 19:17 70,244 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-18 05:17 2,251,264 ----a-w C:\WINDOWS\Internet Logs\xDB50.tmp
2008-05-18 05:17 1,025,536 ----a-w C:\WINDOWS\Internet Logs\xDB4F.tmp
2008-05-18 04:43 702,976 ----a-w C:\WINDOWS\Internet Logs\xDB4E.tmp
2008-05-18 03:38 2,129,408 ----a-w C:\WINDOWS\Internet Logs\xDB4D.tmp
2008-05-07 16:01 15,962,793 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-05-04 09:42 184,832 ----a-w C:\WINDOWS\Internet Logs\xDB4C.tmp
2008-04-27 04:59 118,272 ----a-w C:\WINDOWS\Internet Logs\xDB4B.tmp
2008-04-26 08:19 101,376 ----a-w C:\WINDOWS\Internet Logs\xDB4A.tmp
2008-04-26 06:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pure Networks
2008-04-26 06:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-26 00:43 48,128 ----a-w C:\WINDOWS\Internet Logs\xDB49.tmp
2008-04-25 10:35 204,288 ----a-w C:\WINDOWS\Internet Logs\xDB48.tmp
2008-04-24 10:54 94,720 ----a-w C:\WINDOWS\Internet Logs\xDB47.tmp
2008-04-23 09:26 49,664 ----a-w C:\WINDOWS\Internet Logs\xDB46.tmp
2008-04-22 05:36 49,152 ----a-w C:\WINDOWS\Internet Logs\xDB45.tmp
2008-04-21 09:49 403,456 ----a-w C:\WINDOWS\Internet Logs\xDB44.tmp
2008-04-19 03:39 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-18 06:13 312,832 ----a-w C:\WINDOWS\Internet Logs\xDB43.tmp
2008-04-13 11:19 --------- d-----w C:\Program Files\Warcraft III
2008-04-13 08:12 --------- d--h--w C:\Program Files\Zero G Registry
2008-04-13 08:11 --------- d-----w C:\Program Files\Ubisoft
2008-04-11 06:27 43,008 ----a-w C:\WINDOWS\Internet Logs\xDB42.tmp
2008-04-10 06:08 2,127,872 ----a-w C:\WINDOWS\Internet Logs\xDB41.tmp
2008-04-10 06:08 1,611,264 ----a-w C:\WINDOWS\Internet Logs\xDB40.tmp
2008-04-08 21:58 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-08 06:24 164,352 ----a-w C:\WINDOWS\Internet Logs\xDB3F.tmp
2008-04-06 10:08 2,073,600 ----a-w C:\WINDOWS\Internet Logs\xDB3E.tmp
2008-04-06 10:08 117,248 ----a-w C:\WINDOWS\Internet Logs\xDB3D.tmp
2008-04-04 09:41 128,512 ----a-w C:\WINDOWS\Internet Logs\xDB3C.tmp
2008-04-03 08:31 48,128 ----a-w C:\WINDOWS\Internet Logs\xDB3B.tmp
2008-04-02 07:00 158,208 ----a-w C:\WINDOWS\Internet Logs\xDB3A.tmp
2008-03-31 12:36 74,240 ----a-w C:\WINDOWS\Internet Logs\xDB39.tmp
2008-03-31 01:58 --------- d-----w C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Atari
2008-03-31 01:57 --------- d-----w C:\Program Files\The Witcher Demo
2008-03-31 01:47 186,880 ----a-w C:\WINDOWS\Internet Logs\xDB38.tmp
2008-03-29 15:52 6,112 ----a-w C:\Program Files\install.log
2008-03-28 22:24 16,770,128 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_03_28_05_25_53_full.dmp.zip
2008-03-28 10:25 39,424 ----a-w C:\WINDOWS\Internet Logs\xDB36.tmp
2008-03-28 10:25 2,014,208 ----a-w C:\WINDOWS\Internet Logs\xDB37.tmp
2008-03-28 10:23 2,018,816 ----a-w C:\WINDOWS\Internet Logs\xDB35.tmp
2008-03-27 19:20 2,013,696 ----a-w C:\WINDOWS\Internet Logs\xDB34.tmp
2008-03-27 06:55 102,912 ----a-w C:\WINDOWS\Internet Logs\xDB33.tmp
2008-03-27 02:03 2,012,160 ----a-w C:\WINDOWS\Internet Logs\xDB32.tmp
2008-03-25 04:37 55,296 ----a-w C:\WINDOWS\Internet Logs\xDB31.tmp
2008-03-24 10:49 67,072 ----a-w C:\WINDOWS\Internet Logs\xDB30.tmp
2008-03-22 12:24 131,072 ----a-w C:\WINDOWS\Internet Logs\xDB2F.tmp
2008-03-19 07:09 223,744 ----a-w C:\WINDOWS\Internet Logs\xDB2E.tmp
2008-03-18 04:49 157,184 ----a-w C:\WINDOWS\Internet Logs\xDB2D.tmp
2008-03-17 16:18 40,448 ----a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
2008-03-17 16:18 1,997,312 ----a-w C:\WINDOWS\Internet Logs\xDB2C.tmp
2008-03-16 08:26 337,920 ----a-w C:\WINDOWS\Internet Logs\xDB2A.tmp
2008-03-15 04:48 267,776 ----a-w C:\WINDOWS\Internet Logs\xDB29.tmp
2008-03-14 06:01 361,472 ----a-w C:\WINDOWS\Internet Logs\xDB28.tmp
2008-03-14 04:11 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-03-13 04:10 176,128 ----a-w C:\WINDOWS\Internet Logs\xDB27.tmp
2008-03-12 04:39 335,360 ----a-w C:\WINDOWS\Internet Logs\xDB26.tmp
2008-03-10 01:58 83,968 ----a-w C:\WINDOWS\Internet Logs\xDB25.tmp
2008-03-08 12:29 123,904 ----a-w C:\WINDOWS\Internet Logs\xDB24.tmp
2008-03-06 05:28 62,464 ----a-w C:\WINDOWS\Internet Logs\xDB23.tmp
2008-03-05 06:08 168,960 ----a-w C:\WINDOWS\Internet Logs\xDB22.tmp
2008-03-02 11:07 64,512 ----a-w C:\WINDOWS\Internet Logs\xDB21.tmp
2008-03-01 10:50 92,160 ----a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2008-02-29 13:34 68,608 ----a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2008-02-29 06:41 89,088 ----a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2008-02-28 05:27 124,416 ----a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2008-02-26 04:55 246,784 ----a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2008-02-23 01:45 136,704 ----a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2008-02-22 07:54 287,744 ----a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2008-02-21 03:34 238,592 ----a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2008-02-20 07:26 166,400 ----a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2008-02-19 18:37 69,632 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-02-19 01:40 73,216 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-02-18 06:16 260,608 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-02-06 23:59 10 ----a-w C:\Program Files\.autoreg
2005-07-29 21:24 472 --sha-r C:\WINDOWS\ZHJldw\tJL5xT.vbs
.
<pre>
----a-w			77,824 2008-01-14 14:51:46  C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt .exe
----a-w			90,112 2008-01-14 14:51:45  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart .exe
----a-w		   451,896 2008-04-26 08:22:30  C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth .exe
----a-w		   184,408 2008-01-14 14:51:45  C:\Program Files\Executive Software\Diskeeper\DkIcon .exe
----a-w		   132,496 2008-01-14 14:51:46  C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
----a-w		   991,232 2008-01-14 13:27:07  C:\Program Files\PCPitstop\Exterminate\Reminder .exe
----a-w		   451,896 2008-04-26 08:22:31  C:\Program Files\Pure Networks\Network Magic\nmapp .exe
----a-w		   286,720 2008-01-14 14:51:46  C:\Program Files\QuickTime\qttask		  .exe
----a-w		 2,021,608 2008-04-08 21:42:50  C:\Program Files\Registry Mechanic\RegMech .exe
----a-w		 1,885,464 2008-02-08 15:07:26  C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster .exe
----a-w		   919,016 2008-05-18 18:49:15  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
----a-w		   155,648 2008-01-14 14:51:45  C:\WINDOWS\system32\NeroCheck .exe
</pre>


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61339EC4-5A21-7EFC-0415-5900CEBA80BA}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{812bc80b-fed1-4d68-9852-42fdc5d20a82}]
C:\WINDOWS\system32\byxntoqq.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-29 23:49 16269312 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-15 22:04 2879488 C:\WINDOWS\SkyTel.exe]
"RegistryMechanic"="C:\Program Files\Registry Mechanic\RegMech.exe" [ ]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [ ]
"nmctxth"="C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [ ]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [ ]
"Malwarebytes Anti-Malware Reboot"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifcddd]
iifcddd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjjhf]
jkkjjhf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\deltamarine\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Warcraft III\\War3.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\dookiecrisp\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"C:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"67:UDP"= 67:UDP:DHCP Discovery Service
"6112:TCP"= 6112:TCP:WC3

R1 tdtcpp;tdtcpp;C:\WINDOWS\system32\drivers\tdtcpp.sys [2008-01-13 01:18]
S2 JKSQ;Security Service;C:\WINDOWS\system32\svcd\svchost.exe []

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-18 15:18:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
.
**************************************************************************
.
Completion time: 2008-05-18 15:21:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-18 19:21:08

Pre-Run: 101,780,856,832 bytes free
Post-Run: 106,938,761,216 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

378

And here's the HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:26:44 PM, on 5/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: (no name) - {61339EC4-5A21-7EFC-0415-5900CEBA80BA} - blank (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: {28a02d5c-df24-2589-86d4-1defb08cb218} - {812bc80b-fed1-4d68-9852-42fdc5d20a82} - C:\WINDOWS\system32\byxntoqq.dll (file missing)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: iifcddd - iifcddd.dll (file missing)
O20 - Winlogon Notify: jkkjjhf - jkkjjhf.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Security Service (JKSQ) - Unknown owner - C:\WINDOWS\system32\svcd\svchost.exe (file missing)
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
O24 - Desktop Component 0: (no name) - (no file)

--
End of file - 4008 bytes


Again thank you for the help. I'm still getting pop-ups.
  • 0

#4
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there DRuggs,

Please follow my instructions in the order they were given, if you come across something you don't understand or don't feel comfortable doing, don't hesitate to ask and I will get you sorted out :)
If you cannot complete a step in my instructions, please skip it and continue with the rest of my instructions and tell me in your next reply which one you were having trouble with.

Step 1. Making a CFscript

Please make sure your realtime protection programs are DISABLED.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\pcaivhgr.dll.vir
C:\WINDOWS\system32\wehhxokk.dll.vir
C:\WINDOWS\system32\alhmnrah.dll.vir
C:\WINDOWS\system32\fbhqfgsu.dll.vir
C:\WINDOWS\system32\qlkbvarn.dll.vzr
C:\WINDOWS\system32\xpifoeae.dll.vzr
C:\WINDOWS\Internet Logs\xDB50.tmp
C:\WINDOWS\Internet Logs\xDB4F.tmp
C:\WINDOWS\Internet Logs\xDB4E.tmp
C:\WINDOWS\Internet Logs\xDB4D.tmp
C:\WINDOWS\Internet Logs\tvDebug.zip
C:\WINDOWS\Internet Logs\xDB4C.tmp
C:\WINDOWS\Internet Logs\xDB4B.tmp
C:\WINDOWS\Internet Logs\xDB4A.tmp
C:\WINDOWS\Internet Logs\xDB49.tmp
C:\WINDOWS\Internet Logs\xDB48.tmp
C:\WINDOWS\Internet Logs\xDB47.tmp
C:\WINDOWS\Internet Logs\xDB46.tmp
C:\WINDOWS\Internet Logs\xDB45.tmp
C:\WINDOWS\Internet Logs\xDB44.tmp
C:\WINDOWS\Internet Logs\xDB43.tmp
C:\WINDOWS\Internet Logs\xDB42.tmp
C:\WINDOWS\Internet Logs\xDB41.tmp
C:\WINDOWS\Internet Logs\xDB40.tmp
C:\WINDOWS\Internet Logs\xDB3F.tmp
C:\WINDOWS\Internet Logs\xDB3E.tmp
C:\WINDOWS\Internet Logs\xDB3D.tmp
C:\WINDOWS\Internet Logs\xDB3C.tmp
C:\WINDOWS\Internet Logs\xDB3B.tmp
C:\WINDOWS\Internet Logs\xDB3A.tmp
C:\WINDOWS\Internet Logs\xDB39.tmp
C:\WINDOWS\Internet Logs\xDB38.tmp
C:\Program Files\install.log
C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_03_28_05_25_53_full.dmp.zip
C:\WINDOWS\Internet Logs\xDB36.tmp
C:\WINDOWS\Internet Logs\xDB37.tmp
C:\WINDOWS\Internet Logs\xDB35.tmp
C:\WINDOWS\Internet Logs\xDB34.tmp
C:\WINDOWS\Internet Logs\xDB33.tmp
C:\WINDOWS\Internet Logs\xDB32.tmp
C:\WINDOWS\Internet Logs\xDB31.tmp
C:\WINDOWS\Internet Logs\xDB30.tmp
C:\WINDOWS\Internet Logs\xDB2F.tmp
C:\WINDOWS\Internet Logs\xDB2E.tmp
C:\WINDOWS\Internet Logs\xDB2D.tmp
C:\WINDOWS\Internet Logs\xDB2B.tmp
C:\WINDOWS\Internet Logs\xDB2C.tmp
C:\WINDOWS\Internet Logs\xDB2A.tmp
C:\WINDOWS\Internet Logs\xDB29.tmp
C:\WINDOWS\Internet Logs\xDB28.tmp
C:\WINDOWS\Internet Logs\xDB27.tmp
C:\WINDOWS\Internet Logs\xDB26.tmp
C:\WINDOWS\Internet Logs\xDB25.tmp
C:\WINDOWS\Internet Logs\xDB24.tmp
C:\WINDOWS\Internet Logs\xDB23.tmp
C:\WINDOWS\Internet Logs\xDB22.tmp
C:\WINDOWS\Internet Logs\xDB21.tmp
C:\WINDOWS\Internet Logs\xDB20.tmp
C:\WINDOWS\Internet Logs\xDB1F.tmp
C:\WINDOWS\Internet Logs\xDB1E.tmp
C:\WINDOWS\Internet Logs\xDB1D.tmp
C:\WINDOWS\Internet Logs\xDB1C.tmp
C:\WINDOWS\Internet Logs\xDB1B.tmp
C:\WINDOWS\Internet Logs\xDB19.tmp
C:\WINDOWS\Internet Logs\xDB18.tmp
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB16.tmp
C:\WINDOWS\Internet Logs\xDB15.tmp
C:\WINDOWS\Internet Logs\xDB14.tmp
C:\WINDOWS\system32\byxntoqq.dll
C:\windows\system32\jkkjjhf.dll
C:\windows\system32\iifcddd.dll
C:\WINDOWS\system32\drivers\tdtcpp.sys

Folder::
C:\Temp\tn3
C:\WINDOWS\system32\lol
C:\Program Files\.autoreg
C:\WINDOWS\ZHJldw
C:\WINDOWS\system32\svcd

RenV::
----a-w			77,824 2008-01-14 14:51:46  C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt .exe
----a-w			90,112 2008-01-14 14:51:45  C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart .exe
----a-w		   451,896 2008-04-26 08:22:30  C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth .exe
----a-w		   184,408 2008-01-14 14:51:45  C:\Program Files\Executive Software\Diskeeper\DkIcon .exe
----a-w		   132,496 2008-01-14 14:51:46  C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
----a-w		   991,232 2008-01-14 13:27:07  C:\Program Files\PCPitstop\Exterminate\Reminder .exe
----a-w		   451,896 2008-04-26 08:22:31  C:\Program Files\Pure Networks\Network Magic\nmapp .exe
----a-w		   286,720 2008-01-14 14:51:46  C:\Program Files\QuickTime\qttask		  .exe
----a-w		 2,021,608 2008-04-08 21:42:50  C:\Program Files\Registry Mechanic\RegMech .exe
----a-w		 1,885,464 2008-02-08 15:07:26  C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster .exe
----a-w		   919,016 2008-05-18 18:49:15  C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
----a-w		   155,648 2008-01-14 14:51:45  C:\WINDOWS\system32\NeroCheck .exe

Driver::
JKSQ
tdtcpp

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\Browser Helper Objects\{61339EC4-5A21-7EFC-0415-5900CEBA80BA}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\Browser Helper Objects\{812bc80b-fed1-4d68-9852-42fdc5d20a82}]

[-HKEY_CLASSES_ROOT\CLSID\{61339EC4-5A21-7EFC-0415-5900CEBA80BA}]

[-HKEY_CLASSES_ROOT\CLSID\{812bc80b-fed1-4d68-9852-42fdc5d20a82}]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifcddd]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjjhf]

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Edited by Mike, 19 May 2008 - 10:14 AM.

  • 0

#5
DRugg

DRugg

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Thanks for all the help Mike, it's much appreciated. Here's my New ComboFix log:

ComboFix 08-05-15.3 - D Mother[bleep]ing Rugg 2008-05-20 0:08:12.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1561 [GMT -4:00]
Running from: C:\Documents and Settings\D Mother[bleep]ing Rugg\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\D Mother[bleep]ing Rugg\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


FILE ::
C:\Program Files\install.log
C:\WINDOWS\Internet Logs\tvDebug.zip
C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_03_28_05_25_53_full.dmp.zip
C:\WINDOWS\Internet Logs\xDB14.tmp
C:\WINDOWS\Internet Logs\xDB15.tmp
C:\WINDOWS\Internet Logs\xDB16.tmp
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB18.tmp
C:\WINDOWS\Internet Logs\xDB19.tmp
C:\WINDOWS\Internet Logs\xDB1B.tmp
C:\WINDOWS\Internet Logs\xDB1C.tmp
C:\WINDOWS\Internet Logs\xDB1D.tmp
C:\WINDOWS\Internet Logs\xDB1E.tmp
C:\WINDOWS\Internet Logs\xDB1F.tmp
C:\WINDOWS\Internet Logs\xDB20.tmp
C:\WINDOWS\Internet Logs\xDB21.tmp
C:\WINDOWS\Internet Logs\xDB22.tmp
C:\WINDOWS\Internet Logs\xDB23.tmp
C:\WINDOWS\Internet Logs\xDB24.tmp
C:\WINDOWS\Internet Logs\xDB25.tmp
C:\WINDOWS\Internet Logs\xDB26.tmp
C:\WINDOWS\Internet Logs\xDB27.tmp
C:\WINDOWS\Internet Logs\xDB28.tmp
C:\WINDOWS\Internet Logs\xDB29.tmp
C:\WINDOWS\Internet Logs\xDB2A.tmp
C:\WINDOWS\Internet Logs\xDB2B.tmp
C:\WINDOWS\Internet Logs\xDB2C.tmp
C:\WINDOWS\Internet Logs\xDB2D.tmp
C:\WINDOWS\Internet Logs\xDB2E.tmp
C:\WINDOWS\Internet Logs\xDB2F.tmp
C:\WINDOWS\Internet Logs\xDB30.tmp
C:\WINDOWS\Internet Logs\xDB31.tmp
C:\WINDOWS\Internet Logs\xDB32.tmp
C:\WINDOWS\Internet Logs\xDB33.tmp
C:\WINDOWS\Internet Logs\xDB34.tmp
C:\WINDOWS\Internet Logs\xDB35.tmp
C:\WINDOWS\Internet Logs\xDB36.tmp
C:\WINDOWS\Internet Logs\xDB37.tmp
C:\WINDOWS\Internet Logs\xDB38.tmp
C:\WINDOWS\Internet Logs\xDB39.tmp
C:\WINDOWS\Internet Logs\xDB3A.tmp
C:\WINDOWS\Internet Logs\xDB3B.tmp
C:\WINDOWS\Internet Logs\xDB3C.tmp
C:\WINDOWS\Internet Logs\xDB3D.tmp
C:\WINDOWS\Internet Logs\xDB3E.tmp
C:\WINDOWS\Internet Logs\xDB3F.tmp
C:\WINDOWS\Internet Logs\xDB40.tmp
C:\WINDOWS\Internet Logs\xDB41.tmp
C:\WINDOWS\Internet Logs\xDB42.tmp
C:\WINDOWS\Internet Logs\xDB43.tmp
C:\WINDOWS\Internet Logs\xDB44.tmp
C:\WINDOWS\Internet Logs\xDB45.tmp
C:\WINDOWS\Internet Logs\xDB46.tmp
C:\WINDOWS\Internet Logs\xDB47.tmp
C:\WINDOWS\Internet Logs\xDB48.tmp
C:\WINDOWS\Internet Logs\xDB49.tmp
C:\WINDOWS\Internet Logs\xDB4A.tmp
C:\WINDOWS\Internet Logs\xDB4B.tmp
C:\WINDOWS\Internet Logs\xDB4C.tmp
C:\WINDOWS\Internet Logs\xDB4D.tmp
C:\WINDOWS\Internet Logs\xDB4E.tmp
C:\WINDOWS\Internet Logs\xDB4F.tmp
C:\WINDOWS\Internet Logs\xDB50.tmp
C:\WINDOWS\system32\alhmnrah.dll.vir
C:\WINDOWS\system32\byxntoqq.dll
C:\WINDOWS\system32\drivers\tdtcpp.sys
C:\WINDOWS\system32\fbhqfgsu.dll.vir
C:\windows\system32\iifcddd.dll
C:\windows\system32\jkkjjhf.dll
C:\WINDOWS\system32\pcaivhgr.dll.vir
C:\WINDOWS\system32\qlkbvarn.dll.vzr
C:\WINDOWS\system32\wehhxokk.dll.vir
C:\WINDOWS\system32\xpifoeae.dll.vzr
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\.autoreg\
C:\Program Files\install.log
C:\temp\tn3
C:\WINDOWS\Internet Logs\tvDebug.zip
C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_03_28_05_25_53_full.dmp.zip
C:\WINDOWS\Internet Logs\xDB14.tmp
C:\WINDOWS\Internet Logs\xDB15.tmp
C:\WINDOWS\Internet Logs\xDB16.tmp
C:\WINDOWS\Internet Logs\xDB17.tmp
C:\WINDOWS\Internet Logs\xDB18.tmp
C:\WINDOWS\Internet Logs\xDB19.tmp
C:\WINDOWS\Internet Logs\xDB1B.tmp
C:\WINDOWS\Internet Logs\xDB1C.tmp
C:\WINDOWS\Internet Logs\xDB1D.tmp
C:\WINDOWS\Internet Logs\xDB1E.tmp
C:\WINDOWS\Internet Logs\xDB1F.tmp
C:\WINDOWS\Internet Logs\xDB20.tmp
C:\WINDOWS\Internet Logs\xDB21.tmp
C:\WINDOWS\Internet Logs\xDB22.tmp
C:\WINDOWS\Internet Logs\xDB23.tmp
C:\WINDOWS\Internet Logs\xDB24.tmp
C:\WINDOWS\Internet Logs\xDB25.tmp
C:\WINDOWS\Internet Logs\xDB26.tmp
C:\WINDOWS\Internet Logs\xDB27.tmp
C:\WINDOWS\Internet Logs\xDB28.tmp
C:\WINDOWS\Internet Logs\xDB29.tmp
C:\WINDOWS\Internet Logs\xDB2A.tmp
C:\WINDOWS\Internet Logs\xDB2B.tmp
C:\WINDOWS\Internet Logs\xDB2C.tmp
C:\WINDOWS\Internet Logs\xDB2D.tmp
C:\WINDOWS\Internet Logs\xDB2E.tmp
C:\WINDOWS\Internet Logs\xDB2F.tmp
C:\WINDOWS\Internet Logs\xDB30.tmp
C:\WINDOWS\Internet Logs\xDB31.tmp
C:\WINDOWS\Internet Logs\xDB32.tmp
C:\WINDOWS\Internet Logs\xDB33.tmp
C:\WINDOWS\Internet Logs\xDB34.tmp
C:\WINDOWS\Internet Logs\xDB35.tmp
C:\WINDOWS\Internet Logs\xDB36.tmp
C:\WINDOWS\Internet Logs\xDB37.tmp
C:\WINDOWS\Internet Logs\xDB38.tmp
C:\WINDOWS\Internet Logs\xDB39.tmp
C:\WINDOWS\Internet Logs\xDB3A.tmp
C:\WINDOWS\Internet Logs\xDB3B.tmp
C:\WINDOWS\Internet Logs\xDB3C.tmp
C:\WINDOWS\Internet Logs\xDB3D.tmp
C:\WINDOWS\Internet Logs\xDB3E.tmp
C:\WINDOWS\Internet Logs\xDB3F.tmp
C:\WINDOWS\Internet Logs\xDB40.tmp
C:\WINDOWS\Internet Logs\xDB41.tmp
C:\WINDOWS\Internet Logs\xDB42.tmp
C:\WINDOWS\Internet Logs\xDB43.tmp
C:\WINDOWS\Internet Logs\xDB44.tmp
C:\WINDOWS\Internet Logs\xDB45.tmp
C:\WINDOWS\Internet Logs\xDB46.tmp
C:\WINDOWS\Internet Logs\xDB47.tmp
C:\WINDOWS\Internet Logs\xDB48.tmp
C:\WINDOWS\Internet Logs\xDB49.tmp
C:\WINDOWS\Internet Logs\xDB4A.tmp
C:\WINDOWS\Internet Logs\xDB4B.tmp
C:\WINDOWS\Internet Logs\xDB4C.tmp
C:\WINDOWS\Internet Logs\xDB4D.tmp
C:\WINDOWS\Internet Logs\xDB4E.tmp
C:\WINDOWS\Internet Logs\xDB4F.tmp
C:\WINDOWS\Internet Logs\xDB50.tmp
C:\WINDOWS\system32\alhmnrah.dll.vir
C:\WINDOWS\system32\drivers\tdtcpp.sys
C:\WINDOWS\system32\fbhqfgsu.dll.vir
C:\WINDOWS\system32\pcaivhgr.dll.vir
C:\WINDOWS\system32\qlkbvarn.dll.vzr
C:\WINDOWS\system32\svcd
C:\WINDOWS\system32\wehhxokk.dll.vir
C:\WINDOWS\system32\xpifoeae.dll.vzr
C:\WINDOWS\ZHJldw
C:\WINDOWS\ZHJldw\asappsrv.dll.vzr
C:\WINDOWS\ZHJldw\tJL5xT.vbs

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_JKSQ
-------\Legacy_TDTCPP
-------\Service_JKSQ
-------\Service_tdtcpp


((((((((((((((((((((((((( Files Created from 2008-04-20 to 2008-05-20 )))))))))))))))))))))))))))))))
.

2008-05-18 22:11 . 2008-05-18 22:17 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-18 22:02 . 2008-05-19 23:52 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-18 22:02 . 2008-05-18 22:02 <DIR> d-------- C:\Program Files\AVG
2008-05-18 22:02 . 2008-05-18 22:02 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\AVGTOOLBAR
2008-05-18 22:02 . 2008-05-18 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-18 22:02 . 2008-05-18 22:02 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-18 22:02 . 2008-05-18 22:02 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-18 22:02 . 2008-05-18 22:02 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-18 00:36 . 2008-05-18 00:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-18 00:14 . 2008-05-18 00:22 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-18 00:14 . 2008-05-18 00:14 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Malwarebytes
2008-05-18 00:14 . 2008-05-18 00:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-18 00:14 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-18 00:14 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-18 00:13 . 2008-05-18 00:13 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-17 23:52 . 2008-05-18 22:03 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-17 23:52 . 2008-05-19 03:35 1,024 --ah----- C:\Documents and Settings\Administrator\NtUser.dat.LOG
2008-05-17 23:17 . 2008-05-17 23:17 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-05-17 23:11 . 2008-05-17 23:42 <DIR> d-------- C:\VundoFix Backups
2008-04-26 02:25 . 2008-01-08 17:16 23,992 --a------ C:\WINDOWS\system32\drivers\pnarp.sys
2008-04-26 02:24 . 2008-04-26 02:24 <DIR> d-------- C:\Program Files\Common Files\Pure Networks Shared
2008-04-26 02:24 . 2008-01-08 17:16 25,272 --a------ C:\WINDOWS\system32\drivers\purendis.sys
2008-04-24 05:20 . 2008-04-24 05:20 <DIR> d--h----- C:\WINDOWS\PIF
2008-04-24 05:20 . 2008-04-24 05:20 <DIR> d-------- C:\Program Files\7-Zip
2008-04-20 21:01 . 2008-04-26 16:53 <DIR> d-------- C:\Program Files\City of Heroes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 04:13 5,601,824 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-20 04:10 75,884 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-20 04:08 --------- d-----w C:\Program Files\QuickTime
2008-05-19 09:55 36,864 ----a-w C:\WINDOWS\Internet Logs\xDB52.tmp
2008-05-19 09:37 1,156,608 ----a-w C:\WINDOWS\Internet Logs\xDB51.tmp
2008-04-26 06:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pure Networks
2008-04-26 06:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-19 03:39 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-13 11:19 --------- d-----w C:\Program Files\Warcraft III
2008-04-13 08:12 --------- d--h--w C:\Program Files\Zero G Registry
2008-04-13 08:11 --------- d-----w C:\Program Files\Ubisoft
2008-04-08 21:58 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-05 02:58 87,104 ----a-w C:\WINDOWS\system32\fbhqfgsu.dll
2008-03-31 01:58 --------- d-----w C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Atari
2008-03-31 01:57 --------- d-----w C:\Program Files\The Witcher Demo
2008-03-24 23:37 93,248 ----a-w C:\WINDOWS\system32\pcaivhgr.dll
2008-03-18 19:46 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-03-14 04:11 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-03-14 04:11 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-02-06 23:59 10 ----a-w C:\Program Files\.autoreg
.

((((((((((((((((((((((((((((( [email protected]_15.20.54.81 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-18 19:17:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-20 04:11:35 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-19 02:02:53 26,184 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-01-14 14:51:45 155,648 ----a-w C:\WINDOWS\system32\NeroCheck.exe
- 2008-04-21 00:48:25 4,212 ---ha-w C:\WINDOWS\system32\zllictbl.dat
+ 2008-05-18 19:21:18 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
- 2008-05-18 18:59:26 103,852 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2008-05-20 03:51:39 103,852 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
- 2008-05-18 19:13:36 66,252,288 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-05-20 04:08:17 66,252,288 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-05-20 04:12:15 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_580.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-18 22:02 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-18 22:02 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-29 23:49 16269312 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-15 22:04 2879488 C:\WINDOWS\SkyTel.exe]
"RegistryMechanic"="C:\Program Files\Registry Mechanic\RegMech.exe" [2008-04-08 17:42 2021608]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-05-18 14:49 919016]
"nmctxth"="C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-04-26 04:22 451896]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [2008-04-26 04:22 451896]
"Malwarebytes Anti-Malware Reboot"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [ ]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-18 22:02 1177368]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\deltamarine\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Warcraft III\\War3.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\dookiecrisp\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"C:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"67:UDP"= 67:UDP:DHCP Discovery Service
"6112:TCP"= 6112:TCP:WC3

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-18 22:02]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-18 22:02]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-18 22:02]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-18 22:02]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-20 00:12:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-05-20 0:16:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-20 04:16:26
ComboFix2.txt 2008-05-18 19:21:12

Pre-Run: 106,618,568,704 bytes free
Post-Run: 106,637,045,760 bytes free

308


And here's the HiJackThis log as well:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:20:20 AM, on 5/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
O24 - Desktop Component 0: (no name) - (no file)

--
End of file - 4491 bytes


Again, thanks a lot for the help. This computer seems to be already running 100% better.
  • 0

#6
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there DRugg,

Looking better. I'm glad to here its running better.

Step 1. Making a CFscript

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://www.geekstogo.com/forum/Trojans-Popups-t198537.html

Collect::
C:\WINDOWS\system32\pcaivhgr.dll

File::
C:\WINDOWS\Internet Logs\xDB52.tmp
C:\WINDOWS\Internet Logs\xDB51.tmp
C:\WINDOWS\system32\fbhqfgsu.dll
3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image

5. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
6. ComboFix may need to reboot to finish its work. Let it.

7. When CF has finished running, it will generate the ComboFix.log which will appear on your screen.

8. If CF-Submit.htm is detected, ComboFix will generate this message box:

Posted Image

Clicking OK will cause the machine's browser to load CF-Submit.htm

Posted Image

9. Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
10. Once the file has been submitted, please DELETE both files on your desktop.

11. Post the following reports/logs into your next reply:
  • Combofix.txt

Step 2. Running MalwareByte's Anti-Malware

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

In your next reply

Please post the log from Combofix.
Please post the log from MalwareBytes' Anti-Malware
Please post a new hijack this log.

If the logs are to big to fit in one reply please spread them out over multiple replies.

Edited by Mike, 20 May 2008 - 11:40 AM.

  • 0

#7
DRugg

DRugg

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Uh one problem, neither files were made on my desktop. Not after I ran ComboFix. It didn't prompt me to restart even. But I restarted the computer anyways and still no files. But here's the log ComboFix produced after it was finished running anyhows:

ComboFix 08-05-15.3 - D Mother[bleep]ing Rugg 2008-05-23 9:07:10.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1597 [GMT -4:00]
Running from: C:\Documents and Settings\D Mother[bleep]ing Rugg\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\D Mother[bleep]ing Rugg\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\Internet Logs\xDB51.tmp
C:\WINDOWS\Internet Logs\xDB52.tmp
C:\WINDOWS\system32\fbhqfgsu.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Internet Logs\xDB51.tmp
C:\WINDOWS\Internet Logs\xDB52.tmp

.
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.

2008-05-23 08:10 . 2008-05-23 08:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-05-23 08:09 . 2008-05-23 08:09 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-05-23 08:08 . 2008-05-23 08:08 <DIR> d-------- C:\Program Files\ATI
2008-05-20 19:02 . 2008-05-20 19:03 <DIR> d-------- C:\Program Files\Funcom
2008-05-20 12:57 . 2008-05-20 12:57 <DIR> d-------- C:\Program Files\IObit
2008-05-20 11:48 . 2008-05-20 11:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-05-20 11:18 . 2008-05-20 11:18 <DIR> d-------- C:\Program Files\ACW
2008-05-20 10:58 . 2008-05-20 11:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SlySoft
2008-05-20 10:58 . 2008-05-20 10:58 40 ---hs---- C:\Documents and Settings\All Users\Application Data\.zreglib
2008-05-20 10:56 . 2008-05-20 10:58 24 ---hs---- C:\WINDOWS\S5EC1A2D7.tmp
2008-05-20 10:55 . 2008-05-20 10:55 <DIR> d-------- C:\Program Files\SlySoft
2008-05-20 01:37 . 2008-05-20 01:37 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\SystemRequirementsLab
2008-05-18 22:11 . 2008-05-20 17:49 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-18 22:02 . 2008-05-23 08:42 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-18 22:02 . 2008-05-18 22:02 <DIR> d-------- C:\Program Files\AVG
2008-05-18 22:02 . 2008-05-18 22:02 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\AVGTOOLBAR
2008-05-18 22:02 . 2008-05-18 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-18 22:02 . 2008-05-18 22:02 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-18 22:02 . 2008-05-18 22:02 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-18 22:02 . 2008-05-18 22:02 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-18 00:36 . 2008-05-18 00:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-18 00:14 . 2008-05-18 00:22 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-18 00:14 . 2008-05-18 00:14 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Malwarebytes
2008-05-18 00:14 . 2008-05-18 00:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-18 00:14 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-18 00:14 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-18 00:13 . 2008-05-18 00:13 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-17 23:52 . 2008-05-18 22:03 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-17 23:52 . 2008-05-20 12:57 1,024 --ah----- C:\Documents and Settings\Administrator\NtUser.dat.LOG
2008-05-17 23:17 . 2008-05-17 23:17 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-05-17 23:11 . 2008-05-17 23:42 <DIR> d-------- C:\VundoFix Backups
2008-05-12 11:09 . 2008-05-12 11:09 47,104 --a------ C:\WINDOWS\system32\amdpcom32.dll
2008-05-12 11:03 . 2008-05-12 11:03 19,968 --a------ C:\WINDOWS\system32\atiadlxx.dll
2008-04-26 02:25 . 2008-01-08 17:16 23,992 --a------ C:\WINDOWS\system32\drivers\pnarp.sys
2008-04-26 02:24 . 2008-04-26 02:24 <DIR> d-------- C:\Program Files\Common Files\Pure Networks Shared
2008-04-26 02:24 . 2008-01-08 17:16 25,272 --a------ C:\WINDOWS\system32\drivers\purendis.sys
2008-04-24 05:20 . 2008-04-24 05:20 <DIR> d--h----- C:\WINDOWS\PIF
2008-04-24 05:20 . 2008-04-24 05:20 <DIR> d-------- C:\Program Files\7-Zip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-23 13:08 7,125,024 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-23 12:08 96,704 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-23 12:07 --------- d-----w C:\Program Files\ATI Technologies
2008-05-20 18:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-20 18:22 40,960 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-05-20 18:02 70,656 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-05-20 15:02 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-20 15:02 --------- d-----w C:\Program Files\Ahead
2008-05-20 13:46 99,840 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-05-20 04:08 --------- d-----w C:\Program Files\QuickTime
2008-05-12 16:30 3,007,488 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-05-12 15:56 397,312 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-05-12 15:54 305,152 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-05-12 15:53 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-05-12 15:45 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-05-12 15:45 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-05-12 15:45 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-05-12 15:45 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-05-12 15:44 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-05-12 15:43 540,672 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-05-12 15:43 10,153,984 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-05-12 15:41 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-05-12 15:32 3,203,168 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-05-12 15:22 1,999,616 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-05-12 15:05 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-05-12 15:05 327,680 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-05-12 15:03 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-05-12 15:02 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-05-12 15:02 241,664 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-05-12 14:57 548,864 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-05-12 14:49 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2008-04-26 20:53 --------- d-----w C:\Program Files\City of Heroes
2008-04-26 06:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pure Networks
2008-04-19 03:39 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-13 11:19 --------- d-----w C:\Program Files\Warcraft III
2008-04-13 08:12 --------- d--h--w C:\Program Files\Zero G Registry
2008-04-13 08:11 --------- d-----w C:\Program Files\Ubisoft
2008-04-08 21:58 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-31 01:58 --------- d-----w C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Atari
2008-03-31 01:57 --------- d-----w C:\Program Files\The Witcher Demo
2008-03-18 19:46 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-03-14 04:11 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-03-14 04:11 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-02-06 23:59 10 ----a-w C:\Program Files\.autoreg
.

------- Sigcheck -------

2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\dllcache\svchost.exe

2004-08-04 00:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\system32\user32.dll
2004-08-04 00:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\system32\dllcache\user32.dll

2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\dllcache\ws2_32.dll

2004-08-04 00:56 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\system32\wininet.dll
2004-08-04 00:56 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\system32\dllcache\wininet.dll

2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\dllcache\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\drivers\tcpip.sys

2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\dllcache\winlogon.exe

2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\dllcache\ndis.sys
2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys

2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\dllcache\ip6fw.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys

2004-08-04 01:05 2015232 fb142b7007ca2eea76966c6c5cc12150 C:\WINDOWS\system32\ntkrnlpa.exe

2004-08-03 23:18 2148352 626309040459c3915997ef98ec1c8d40 C:\WINDOWS\system32\ntoskrnl.exe

2004-08-04 00:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\explorer.exe
2004-08-04 00:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\system32\dllcache\explorer.exe

2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\services.exe
2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\dllcache\services.exe

2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\lsass.exe
2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\dllcache\lsass.exe

2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe
2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((( [email protected]_15.20.54.81 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-22 03:24:24 135,168 ----a-w C:\WINDOWS\assembly\GAC\AxInterop.MSComctlLib\2.0.0.0__90ba9c70f846762e\AxInterop.MSComctlLib.DLL
+ 2008-05-23 12:07:47 135,168 ----a-w C:\WINDOWS\assembly\GAC\AxInterop.MSComctlLib\2.0.0.0__90ba9c70f846762e\AxInterop.MSComctlLib.DLL
- 2007-07-22 03:24:24 212,992 ----a-w C:\WINDOWS\assembly\GAC\AxInterop.MSForms\2.0.0.0__90ba9c70f846762e\AxInterop.MSForms.DLL
+ 2008-05-23 12:07:47 212,992 ----a-w C:\WINDOWS\assembly\GAC\AxInterop.MSForms\2.0.0.0__90ba9c70f846762e\AxInterop.MSForms.DLL
- 2007-07-22 03:24:23 15,360 ----a-w C:\WINDOWS\assembly\GAC\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.DLL
+ 2008-05-23 12:07:44 15,360 ----a-w C:\WINDOWS\assembly\GAC\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.DLL
- 2007-07-22 03:24:23 143,360 ----a-w C:\WINDOWS\assembly\GAC\ICSharpCode.SharpZipLib\0.84.0.0__1b03e6acf1164f73\ICSharpCode.SharpZipLib.DLL
+ 2008-05-23 12:07:44 143,360 ----a-w C:\WINDOWS\assembly\GAC\ICSharpCode.SharpZipLib\0.84.0.0__1b03e6acf1164f73\ICSharpCode.SharpZipLib.DLL
- 2007-07-22 03:24:24 225,280 ----a-w C:\WINDOWS\assembly\GAC\Interop.MSComctlLib\2.0.0.0__90ba9c70f846762e\Interop.MSComctlLib.DLL
+ 2008-05-23 12:07:48 225,280 ----a-w C:\WINDOWS\assembly\GAC\Interop.MSComctlLib\2.0.0.0__90ba9c70f846762e\Interop.MSComctlLib.DLL
- 2007-07-22 03:24:24 360,448 ----a-w C:\WINDOWS\assembly\GAC\Interop.MSForms\2.0.0.0__90ba9c70f846762e\Interop.MSForms.DLL
+ 2008-05-23 12:07:48 360,448 ----a-w C:\WINDOWS\assembly\GAC\Interop.MSForms\2.0.0.0__90ba9c70f846762e\Interop.MSForms.DLL
- 2007-07-22 03:24:24 49,152 ----a-w C:\WINDOWS\assembly\GAC\Interop.NewIWshRuntimeLibrary\1.0.0.0__90ba9c70f846762e\Interop.NewIWshRuntimeLibrary.DLL
+ 2008-05-23 12:07:48 49,152 ----a-w C:\WINDOWS\assembly\GAC\Interop.NewIWshRuntimeLibrary\1.0.0.0__90ba9c70f846762e\Interop.NewIWshRuntimeLibrary.DLL
- 2007-07-22 03:24:23 13,312 ----a-w C:\WINDOWS\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.DLL
+ 2008-05-23 12:07:44 13,312 ----a-w C:\WINDOWS\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.DLL
- 2007-07-22 03:24:23 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.DLL
+ 2008-05-23 12:07:44 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.DLL
+ 2008-05-23 12:07:48 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3005.17473__90ba9c70f846762e\AEM.Actions.CCAA.Shared.DLL
+ 2008-05-23 12:07:48 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3005.17563__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.DLL
+ 2008-05-23 12:07:48 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3005.17512__90ba9c70f846762e\AEM.Plugin.EEU.Shared.DLL
+ 2008-05-23 12:07:48 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3005.17562__90ba9c70f846762e\AEM.Plugin.GD.Shared.DLL
+ 2008-05-23 12:07:48 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3005.17490__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.DLL
+ 2008-05-23 12:07:48 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3005.17534__90ba9c70f846762e\AEM.Plugin.REG.Shared.DLL
+ 2008-05-23 12:07:48 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.EEU.Shared\2.0.3005.17560__90ba9c70f846762e\AEM.Plugin.Source.EEU.Shared.DLL
+ 2008-05-23 12:07:48 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.GD.Shared\2.0.3005.17561__90ba9c70f846762e\AEM.Plugin.Source.GD.Shared.DLL
+ 2008-05-23 12:07:44 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3054.18949__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.DLL
+ 2008-05-23 12:07:48 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3005.17516__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.DLL
+ 2008-05-23 12:07:44 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3005.17489__90ba9c70f846762e\AEM.Server.Shared.DLL
+ 2008-05-23 12:07:42 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.Server\2.0.3054.18596__90ba9c70f846762e\AEM.Server.DLL
+ 2008-05-23 12:07:44 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.UI.Shared\2.0.3005.17552__90ba9c70f846762e\AEM.UI.Shared.DLL
+ 2008-05-23 12:07:42 61,440 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AEM.UI\2.0.3054.18908__90ba9c70f846762e\AEM.UI.DLL
+ 2008-05-23 12:07:44 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\APM.Foundation\2.0.3005.17511__90ba9c70f846762e\APM.Foundation.DLL
+ 2008-05-23 12:07:42 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\APM.Server\2.0.3054.18594__90ba9c70f846762e\APM.Server.DLL
- 2007-07-22 03:24:22 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.DLL
+ 2008-05-23 12:07:42 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.DLL
+ 2008-05-23 12:07:42 65,536 ----a-w C:\WINDOWS\assembly\GAC_MSIL\ATIDEMOS\2.0.3054.18598__90ba9c70f846762e\ATIDEMOS.DLL
- 2007-07-22 03:24:24 6,656 ----a-w C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.DLL
+ 2008-05-23 12:07:48 6,656 ----a-w C:\WINDOWS\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.DLL
- 2007-07-22 03:24:24 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AxInterop.SHDocVw\1.1.0.0__90ba9c70f846762e\AxInterop.SHDocVw.DLL
+ 2008-05-23 12:07:48 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\AxInterop.SHDocVw\1.1.0.0__90ba9c70f846762e\AxInterop.SHDocVw.DLL
+ 2008-05-23 12:07:42 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CCC.Implementation\2.0.3054.18909__90ba9c70f846762e\CCC.Implementation.DLL
- 2007-07-22 03:24:24 49,152 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CCC\2.0.0.0__90ba9c70f846762e\CCC.EXE
+ 2008-05-23 12:07:47 49,152 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CCC\2.0.0.0__90ba9c70f846762e\CCC.EXE
+ 2008-05-23 12:07:49 90,112 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.AForce.Graphics.Dashboard\2.0.3054.18949__90ba9c70f846762e\CLI.Aspect.AForce.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:49 12,288 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.AForce.Graphics.Runtime\2.0.3054.18948__90ba9c70f846762e\CLI.Aspect.AForce.Graphics.Runtime.DLL
+ 2008-05-23 12:07:44 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.AForce.Graphics.Shared\2.0.3005.17561__90ba9c70f846762e\CLI.Aspect.AForce.Graphics.Shared.DLL
+ 2008-05-23 12:07:44 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3005.17514__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.DLL
+ 2008-05-23 12:07:42 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormatSelection.Graphics.Dashboard.Shared.Private\2.0.3005.17517__90ba9c70f846762e\CLI.Aspect.CustomFormatSelection.Graphics.Dashboard.Shared.Private.DLL
+ 2008-05-23 12:07:49 98,304 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.CustomFormatSelection.Graphics.Dashboard\2.0.3054.18762__90ba9c70f846762e\CLI.Aspect.CustomFormatSelection.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:49 479,232 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3054.18785__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:49 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3054.18791__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3005.17535__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.DLL
+ 2008-05-23 12:07:49 663,552 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3054.18840__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:53 65,536 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3054.18837__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3005.17539__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.DLL
+ 2008-05-23 12:07:54 688,128 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3054.18864__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.DLL
+ 2008-05-23 12:07:49 446,464 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3054.18777__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:49 61,440 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3054.18783__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3005.17535__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.DLL
+ 2008-05-23 12:07:49 401,408 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3054.18829__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:49 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3054.18827__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3005.17521__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.DLL
+ 2008-05-23 12:07:49 307,200 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3054.18692__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.DLL
+ 2008-05-23 12:07:50 282,624 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Dashboard.Shared\2.0.3054.18769__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Dashboard.Shared.DLL
+ 2008-05-23 12:07:54 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3054.18782__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3005.17506__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.DLL
+ 2008-05-23 12:07:50 901,120 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3054.18885__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:54 77,824 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3054.18882__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 65,536 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3005.17541__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.DLL
+ 2008-05-23 12:07:54 364,544 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3054.18892__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.DLL
+ 2008-05-23 12:07:50 585,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3054.18683__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:50 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3054.18690__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3005.17531__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.DLL
+ 2008-05-23 12:07:50 438,272 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3054.18632__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:54 1,679,360 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3054.18653__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.DLL
+ 2008-05-23 12:07:50 118,784 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3054.18814__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:50 36,864 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3054.18812__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3005.17537__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.DLL
+ 2008-05-23 12:07:54 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3054.18630__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3005.17522__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.DLL
+ 2008-05-23 12:07:50 217,088 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3054.18676__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:54 196,608 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3054.18668__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.DLL
+ 2008-05-23 12:07:50 249,856 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Dashboard\2.0.3054.18707__90ba9c70f846762e\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:50 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Runtime\2.0.3054.18714__90ba9c70f846762e\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Shared\2.0.3005.17532__90ba9c70f846762e\CLI.Aspect.IntegratedUMAFrameBuffer.Graphics.Shared.DLL
+ 2008-05-23 12:07:50 802,816 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3054.18793__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:50 73,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3054.18792__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 49,152 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3005.17536__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.DLL
+ 2008-05-23 12:07:51 401,408 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3054.18871__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.DLL
+ 2008-05-23 12:07:51 204,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU.Graphics.Dashboard\2.0.3054.18797__90ba9c70f846762e\CLI.Aspect.MultiVPU.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:51 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU.Graphics.Runtime\2.0.3054.18794__90ba9c70f846762e\CLI.Aspect.MultiVPU.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU.Graphics.Shared\2.0.3005.17534__90ba9c70f846762e\CLI.Aspect.MultiVPU.Graphics.Shared.DLL
+ 2008-05-23 12:07:51 204,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU2.Graphics.Dashboard\2.0.3054.18806__90ba9c70f846762e\CLI.Aspect.MultiVPU2.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:51 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU2.Graphics.Runtime\2.0.3054.18803__90ba9c70f846762e\CLI.Aspect.MultiVPU2.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU2.Graphics.Shared\2.0.3005.17536__90ba9c70f846762e\CLI.Aspect.MultiVPU2.Graphics.Shared.DLL
+ 2008-05-23 12:07:51 208,896 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU3.Graphics.Dashboard\2.0.3054.18914__90ba9c70f846762e\CLI.Aspect.MultiVPU3.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:51 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU3.Graphics.Runtime\2.0.3054.18911__90ba9c70f846762e\CLI.Aspect.MultiVPU3.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU3.Graphics.Shared\2.0.3005.17555__90ba9c70f846762e\CLI.Aspect.MultiVPU3.Graphics.Shared.DLL
+ 2008-05-23 12:07:51 147,456 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU4.Graphics.Dashboard\2.0.3054.18968__90ba9c70f846762e\CLI.Aspect.MultiVPU4.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:51 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU4.Graphics.Runtime\2.0.3054.18966__90ba9c70f846762e\CLI.Aspect.MultiVPU4.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.MultiVPU4.Graphics.Shared\2.0.3005.17520__90ba9c70f846762e\CLI.Aspect.MultiVPU4.Graphics.Shared.DLL
+ 2008-05-23 12:07:51 479,232 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive2.Graphics.Dashboard\2.0.3054.18716__90ba9c70f846762e\CLI.Aspect.OverDrive2.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:51 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive2.Graphics.Runtime\2.0.3054.18715__90ba9c70f846762e\CLI.Aspect.OverDrive2.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive2.Graphics.Shared\2.0.3005.17533__90ba9c70f846762e\CLI.Aspect.OverDrive2.Graphics.Shared.DLL
+ 2008-05-23 12:07:51 1,032,192 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive3.Graphics.Dashboard\2.0.3054.18739__90ba9c70f846762e\CLI.Aspect.OverDrive3.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:51 61,440 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive3.Graphics.Runtime\2.0.3054.18730__90ba9c70f846762e\CLI.Aspect.OverDrive3.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive3.Graphics.Shared\2.0.3005.17533__90ba9c70f846762e\CLI.Aspect.OverDrive3.Graphics.Shared.DLL
+ 2008-05-23 12:07:52 442,368 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Dashboard\2.0.3054.18960__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:52 65,536 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Runtime\2.0.3054.18959__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 57,344 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.OverDrive5.Graphics.Shared\2.0.3005.17553__90ba9c70f846762e\CLI.Aspect.OverDrive5.Graphics.Shared.DLL
+ 2008-05-23 12:07:52 167,936 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlay3.Graphics.Dashboard\2.0.3054.18836__90ba9c70f846762e\CLI.Aspect.PowerPlay3.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:52 49,152 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlay3.Graphics.Runtime\2.0.3054.18836__90ba9c70f846762e\CLI.Aspect.PowerPlay3.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlay3.Graphics.Shared\2.0.3005.17538__90ba9c70f846762e\CLI.Aspect.PowerPlay3.Graphics.Shared.DLL
+ 2008-05-23 12:07:52 139,264 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlay4.Graphics.Dashboard\2.0.3054.18939__90ba9c70f846762e\CLI.Aspect.PowerPlay4.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:52 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlay4.Graphics.Runtime\2.0.3054.18939__90ba9c70f846762e\CLI.Aspect.PowerPlay4.Graphics.Runtime.DLL
+ 2008-05-23 12:07:45 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlay4.Graphics.Shared\2.0.3005.17557__90ba9c70f846762e\CLI.Aspect.PowerPlay4.Graphics.Shared.DLL
+ 2008-05-23 12:07:52 147,456 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3054.18922__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:52 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3054.18921__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.DLL
+ 2008-05-23 12:07:46 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3005.17556__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.DLL
+ 2008-05-23 12:07:52 172,032 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerXpress.Graphics.Dashboard\2.0.3054.18957__90ba9c70f846762e\CLI.Aspect.PowerXpress.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:52 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerXpress.Graphics.Runtime\2.0.3054.18957__90ba9c70f846762e\CLI.Aspect.PowerXpress.Graphics.Runtime.DLL
+ 2008-05-23 12:07:46 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.PowerXpress.Graphics.Shared\2.0.3005.17558__90ba9c70f846762e\CLI.Aspect.PowerXpress.Graphics.Shared.DLL
+ 2008-05-23 12:07:52 348,160 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3054.18848__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:52 61,440 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3054.18846__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.DLL
+ 2008-05-23 12:07:46 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3005.17540__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.DLL
+ 2008-05-23 12:07:52 90,112 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3054.18855__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.DLL
+ 2008-05-23 12:07:53 282,624 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.SmartGart.Graphics.Dashboard\2.0.3054.18699__90ba9c70f846762e\CLI.Aspect.SmartGart.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:53 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.SmartGart.Graphics.Runtime\2.0.3054.18706__90ba9c70f846762e\CLI.Aspect.SmartGart.Graphics.Runtime.DLL
+ 2008-05-23 12:07:46 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.SmartGart.Graphics.Shared\2.0.3005.17532__90ba9c70f846762e\CLI.Aspect.SmartGart.Graphics.Shared.DLL
+ 2008-05-23 12:07:46 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3005.17556__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.DLL
+ 2008-05-23 12:07:53 483,328 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3054.18924__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.DLL
+ 2008-05-23 12:07:53 167,936 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VeryLargeDesktop.Graphics.Dashboard\2.0.3054.18821__90ba9c70f846762e\CLI.Aspect.VeryLargeDesktop.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:53 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VeryLargeDesktop.Graphics.Runtime\2.0.3054.18820__90ba9c70f846762e\CLI.Aspect.VeryLargeDesktop.Graphics.Runtime.DLL
+ 2008-05-23 12:07:46 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VeryLargeDesktop.Graphics.Shared\2.0.3005.17538__90ba9c70f846762e\CLI.Aspect.VeryLargeDesktop.Graphics.Shared.DLL
+ 2008-05-23 12:07:53 102,400 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Dashboard\2.0.3054.18660__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:53 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Runtime\2.0.3054.18659__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Runtime.DLL
+ 2008-05-23 12:07:46 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.VPURecover.Graphics.Shared\2.0.3005.17531__90ba9c70f846762e\CLI.Aspect.VPURecover.Graphics.Shared.DLL
+ 2008-05-23 12:07:53 135,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3054.18932__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:53 98,304 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.WorkstationConfig2.Graphics.Dashboard\2.0.3054.18969__90ba9c70f846762e\CLI.Aspect.WorkstationConfig2.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:53 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.WorkstationConfig2.Graphics.Runtime\2.0.3054.18970__90ba9c70f846762e\CLI.Aspect.WorkstationConfig2.Graphics.Runtime.DLL
+ 2008-05-23 12:07:46 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Aspect.WorkstationConfig2.Graphics.Shared\2.0.3005.17558__90ba9c70f846762e\CLI.Aspect.WorkstationConfig2.Graphics.Shared.DLL
+ 2008-05-23 12:07:46 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3005.17521__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.DLL
+ 2008-05-23 12:07:53 73,728 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3054.18623__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.DLL
+ 2008-05-23 12:07:42 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3005.17542__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.DLL
+ 2008-05-23 12:07:54 253,952 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3054.18608__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.DLL
+ 2008-05-23 12:07:46 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3005.17493__90ba9c70f846762e\CLI.Caste.Graphics.Shared.DLL
+ 2008-05-23 12:07:46 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3005.17530__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.DLL
+ 2008-05-23 12:07:54 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3054.18645__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.DLL
+ 2008-05-23 12:07:42 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.AutoRemoval\2.0.3054.18881__90ba9c70f846762e\CLI.Component.Autoremoval.DLL
+ 2008-05-23 12:07:42 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3005.17499__90ba9c70f846762e\CLI.Component.Client.Shared.Private.DLL
+ 2008-05-23 12:07:46 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3005.17479__90ba9c70f846762e\CLI.Component.Client.Shared.DLL
+ 2008-05-23 12:07:42 65,536 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.HotKeyManager.Resources\2.0.3054.18752__90ba9c70f846762e\CLI.Component.Dashboard.HotKeyManager.Resources.DLL
+ 2008-05-23 12:07:42 204,800 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.HotKeyManager\2.0.3054.18745__90ba9c70f846762e\CLI.Component.Dashboard.HotKeyManager.DLL
+ 2008-05-23 12:07:43 65,536 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.ProfileManager.Resources\2.0.3054.18761__90ba9c70f846762e\CLI.Component.Dashboard.ProfileManager.Resources.DLL
+ 2008-05-23 12:07:42 208,896 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.ProfileManager\2.0.3054.18754__90ba9c70f846762e\CLI.Component.Dashboard.ProfileManager.DLL
+ 2008-05-23 12:07:43 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3005.17508__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.DLL
+ 2008-05-23 12:07:46 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3005.17491__90ba9c70f846762e\CLI.Component.Dashboard.Shared.DLL
+ 2008-05-23 12:07:42 1,511,424 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3054.18617__90ba9c70f846762e\CLI.Component.Dashboard.DLL
+ 2008-05-23 12:07:43 622,592 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Eeu\2.0.3054.18874__90ba9c70f846762e\CLI.Component.Eeu.DLL
+ 2008-05-23 12:07:43 57,344 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Erecord\2.0.3054.18723__90ba9c70f846762e\CLI.Component.Erecord.DLL
+ 2008-05-23 12:07:43 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Help\2.0.3054.18906__90ba9c70f846762e\CLI.Component.Help.DLL
+ 2008-05-23 12:07:43 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Icomponent\2.0.3054.18667__90ba9c70f846762e\CLI.Component.Icomponent.DLL
+ 2008-05-23 12:07:43 487,424 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Launchpad\2.0.3054.18958__90ba9c70f846762e\CLI.Component.Launchpad.DLL
+ 2008-05-23 12:07:43 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Load\2.0.3054.18906__90ba9c70f846762e\CLI.Component.Load.DLL
+ 2008-05-23 12:07:53 118,784 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.PowerXpressHybrid\2.0.3054.18976__90ba9c70f846762e\CLI.Component.PowerXpressHybrid.DLL
+ 2008-05-23 12:07:44 7,168 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3054.18597__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.DLL
+ 2008-05-23 12:07:43 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3005.17514__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.DLL
+ 2008-05-23 12:07:46 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3005.17488__90ba9c70f846762e\CLI.Component.Runtime.Shared.DLL
+ 2008-05-23 12:07:43 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3054.18597__90ba9c70f846762e\CLI.Component.Runtime.DLL
+ 2008-05-23 12:07:43 49,152 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3054.18600__90ba9c70f846762e\CLI.Component.SkinFactory.DLL
+ 2008-05-23 12:07:43 417,792 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3054.18900__90ba9c70f846762e\CLI.Component.Systemtray.DLL
+ 2008-05-23 12:07:43 24,576 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3005.17513__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.DLL
+ 2008-05-23 12:07:46 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3005.17496__90ba9c70f846762e\CLI.Component.Wizard.Shared.DLL
+ 2008-05-23 12:07:43 491,520 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3054.18639__90ba9c70f846762e\CLI.Component.Wizard.DLL
+ 2008-05-23 12:07:43 40,960 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3005.17475__90ba9c70f846762e\CLI.Foundation.Private.DLL
+ 2008-05-23 12:07:46 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3005.17608__90ba9c70f846762e\CLI.Foundation.XManifest.DLL
+ 2008-05-23 12:07:46 53,248 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Foundation\2.0.3005.17468__90ba9c70f846762e\CLI.Foundation.DLL
+ 2008-05-23 12:07:43 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI.Implementation\2.0.3054.18593__90ba9c70f846762e\CLI.Implementation.DLL
- 2007-07-22 03:24:24 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI\2.0.0.0__90ba9c70f846762e\CLI.EXE
+ 2008-05-23 12:07:47 49,152 ----a-w C:\WINDOWS\assembly\GAC_MSIL\CLI\2.0.0.0__90ba9c70f846762e\CLI.EXE
- 2007-07-22 03:24:24 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.DLL
+ 2008-05-23 12:07:47 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.DLL
- 2007-07-22 03:24:24 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.DLL
+ 2008-05-23 12:07:47 45,056 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.DLL
+ 2008-05-23 12:07:47 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0702\2.0.2594.25693__90ba9c70f846762e\DEM.Graphics.I0702.DLL
+ 2008-05-23 12:07:47 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0703\2.0.2651.18802__90ba9c70f846762e\DEM.Graphics.I0703.DLL
+ 2008-05-23 12:07:47 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.DLL
+ 2008-05-23 12:07:47 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.Graphics\2.0.3005.17519__90ba9c70f846762e\DEM.Graphics.DLL
+ 2008-05-23 12:07:47 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3005.17518__90ba9c70f846762e\DEM.OS.I0602.DLL
+ 2008-05-23 12:07:47 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\DEM.OS\2.0.3005.17517__90ba9c70f846762e\DEM.OS.DLL
- 2007-07-22 03:24:24 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__90ba9c70f846762e\Interop.SHDocVw.DLL
+ 2008-05-23 12:07:48 131,072 ----a-w C:\WINDOWS\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__90ba9c70f846762e\Interop.SHDocVw.DLL
+ 2008-05-23 12:07:44 11,264 ----a-w C:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Implementation\2.0.3054.18964__90ba9c70f846762e\LOCALIZATION.Foundation.Implementation.DLL
+ 2008-05-23 12:07:44 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3005.17481__90ba9c70f846762e\LOCALIZATION.Foundation.Private.DLL
+ 2008-05-23 12:07:44 20,480 ----a-w C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3005.17511__90ba9c70f846762e\LOG.Foundation.Implementation.Private.DLL
+ 2008-05-23 12:07:44 61,440 ----a-w C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3054.18907__90ba9c70f846762e\LOG.Foundation.Implementation.DLL
+ 2008-05-23 12:07:44 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3005.17484__90ba9c70f846762e\LOG.Foundation.Private.DLL
+ 2008-05-23 12:07:47 32,768 ----a-w C:\WINDOWS\assembly\GAC_MSIL\LOG.Foundation\2.0.3005.17465__90ba9c70f846762e\LOG.Foundation.DLL
+ 2008-05-23 12:07:44 86,016 ----a-w C:\WINDOWS\assembly\GAC_MSIL\LOG\2.0.3054.18908__90ba9c70f846762e\LOG.EXE
+ 2008-05-23 12:07:47 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\MOM.Foundation\2.0.3005.17510__90ba9c70f846762e\MOM.Foundation.DLL
+ 2008-05-23 12:07:44 102,400 ----a-w C:\WINDOWS\assembly\GAC_MSIL\MOM.Implementation\2.0.3054.18910__90ba9c70f846762e\MOM.Implementation.DLL
- 2007-07-22 03:24:24 49,152 ----a-w C:\WINDOWS\assembly\GAC_MSIL\MOM\2.0.0.0__90ba9c70f846762e\MOM.EXE
+ 2008-05-23 12:07:47 49,152 ----a-w C:\WINDOWS\assembly\GAC_MSIL\MOM\2.0.0.0__90ba9c70f846762e\MOM.EXE
+ 2008-05-23 12:07:47 28,672 ----a-w C:\WINDOWS\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3005.17466__90ba9c70f846762e\NEWAEM.Foundation.DLL
+ 2008-05-23 12:07:44 19,456 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PCKGHLP.Foundation.Implementation\2.0.3054.18950__90ba9c70f846762e\PCKGHLP.Foundation.Implementation.DLL
+ 2008-05-23 12:07:44 16,384 ----a-w C:\WINDOWS\assembly\GAC_MSIL\PCKGHLP.Foundation.Private\2.0.3005.17554__90ba9c70f846762e\PCKGHLP.Foundation.Private.DLL
+ 2008-05-20 15:49:34 58,880 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\6ec70143b941b74db937a4ae953a82be\DriversHQ.DriverDetective.ExceptionLogging.ni.dll
+ 2008-05-20 15:49:23 2,232,320 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\710b46a72f432c448954d333d3f828bc\DriversHQ.DriverDetective.Client.ni.exe
+ 2008-05-20 15:49:34 188,416 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\d3540bedc949854ab0e88f484ea7e599\DriversHQ.DriverDetective.Common.ni.dll
+ 2008-05-20 15:49:29 225,280 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\ec521639d2c9fb49837f58963b5d8981\DriversHQ.DriverDetective.Client.Communication.ni.dll
+ 2008-05-20 15:49:35 253,952 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\3e1803e9c44d4d4095f0cad9c4ad2ce6\Microsoft.ApplicationBlocks.Updater.ni.dll
+ 2008-05-20 15:49:39 2,441,216 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\4e66eeb5304a6e41ac1ddc299d1fdaac\Microsoft.JScript.ni.dll
+ 2008-05-20 15:49:40 356,352 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\8e7b0bc58d28144e9a555d8b009cbc12\Microsoft.Practices.ObjectBuilder.ni.dll
+ 2008-05-20 15:49:35 368,640 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\ccf46c2035d81d499797ef7e0ca8e9ef\Microsoft.Practices.EnterpriseLibrary.Common.ni.dll
+ 2008-05-20 15:49:40 167,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\e11cb3544a1f5248a4f98dc111be3213\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.ni.dll
+ 2008-05-20 15:49:29 17,920 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\79de9b1b224a3c4badbe3ac80d8ed5b3\Microsoft.VisualC.ni.dll
+ 2008-05-20 15:49:39 77,824 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\e17006ffc565124086e61bd5a7c69c14\Microsoft.Vsa.ni.dll
+ 2008-05-20 15:49:28 167,936 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\fe1f75daee4f97499c864c0873574fb4\System.Configuration.Install.ni.dll
+ 2008-05-20 15:49:33 1,183,744 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\a7cc18319879124c9fb418d8e37d9414\System.Data.OracleClient.ni.dll
+ 2008-05-20 15:49:27 2,703,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\45d63ab97efb0c4688ddf3cfb30b0d56\System.Data.SqlXml.ni.dll
+ 2008-05-20 15:49:37 1,060,864 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\13de1ddee1866a4b847556de119a276b\System.Management.ni.dll
+ 2008-05-20 15:49:31 815,104 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0ac8544e9feded4aa9f2b105c7113d6f\System.Runtime.Remoting.ni.dll
+ 2008-05-20 15:49:27 339,968 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\38ba785354fffd46818b81ff203eb718\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2008-05-20 15:49:33 233,472 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e6d0a97b99b58749aa0bc02bdcd7863d\System.ServiceProcess.ni.dll
+ 2008-05-20 15:49:41 139,264 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\20a4adf24f50b34983e80412e6dd0b2b\XPBurnComponent.ni.dll
- 2008-05-18 19:17:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-23 12:09:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-23 12:07:33 10,134 ----a-r C:\WINDOWS\Installer\{106B839C-DBA9-0AA9-07E9-9A2597151FF6}\ARPPRODUCTICON.exe
+ 2008-05-23 12:07:31 10,134 ----a-r C:\WINDOWS\Installer\{3389299C-9F50-D0C4-197C-A8804303B79F}\ARPPRODUCTICON.exe
+ 2008-05-23 12:07:28 10,134 ----a-r C:\WINDOWS\Installer\{37A17F53-D058-267B-C256-19FB6DDF3843}\ARPPRODUCTICON.exe
+ 2008-05-23 12:07:39 10,134 ----a-r C:\WINDOWS\Installer\{559BA5B3-E3E1-C8A0-E301-5F50531BD44C}\ARPPRODUCTICON.exe
+ 2008-05-23 12:08:05 10,134 ----a-r C:\WINDOWS\Installer\{72736F5F-520D-472A-88CC-7B02872FD34E}\ARPPRODUCTICON.exe
+ 2008-05-23 12:07:40 10,134 ----a-r C:\WINDOWS\Installer\{79E88160-A5E4-F7D2-1314-DEB8AADD9C29}\ARPPRODUCTICON.exe
+ 2008-05-23 12:07:40 9,158 ----a-r C:\WINDOWS\Installer\{79E88160-A5E4-F7D2-1314-DEB8AADD9C29}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2008-05-23 12:07:37 10,134 ----a-r C:\WINDOWS\Installer\{83735930-0FB1-D871-8832-B5A9E27C93CA}\ARPPRODUCTICON.exe
+ 2008-05-23 12:07:31 10,134 ----a-r C:\WINDOWS\Installer\{B55EF832-4613-A19B-A222-DDB8B6CE1B52}\ARPPRODUCTICON.exe
+ 2008-05-23 12:07:33 10,134 ----a-r C:\WINDOWS\Installer\{CED5BB5B-2A24-2F7F-61B1-2B557484084B}\ARPPRODUCTICON.exe
+ 2008-05-23 12:07:35 10,134 ----a-r C:\WINDOWS\Installer\{D1268F56-DE79-19A8-C8EC-961D48FFD2FE}\ARPPRODUCTICON.exe
+ 2008-05-23 12:07:33 10,134 ----a-r C:\WINDOWS\Installer\{DEB6C5B9-D5BB-D8AC-20F7-F1E0F8A67D5A}\ARPPRODUCTICON.exe
- 2008-02-07 07:03:44 1,664 ----a-w C:\WINDOWS\mozver.dat
+ 2008-05-20 04:37:20 2,300 ----a-w C:\WINDOWS\mozver.dat
+ 2007-10-12 19:14:00 3,734,536 ----a-w C:\WINDOWS\system\d3dx9_36.dll
- 2007-06-05 17:40:44 149,278 ----a-w C:\WINDOWS\system32\atiicdxx.dat
+ 2008-03-06 14:24:57 168,883 ----a-w C:\WINDOWS\system32\atiicdxx.dat
- 2007-06-27 01:30:45 3,107,788 ----a-w C:\WINDOWS\system32\ativva5x.dat
+ 2008-05-12 15:22:31 3,107,788 ----a-w C:\WINDOWS\system32\ativva5x.dat
- 2007-06-27 01:30:45 972,072 ----a-w C:\WINDOWS\system32\ativva6x.dat
+ 2008-05-12 15:22:31 887,724 ----a-w C:\WINDOWS\system32\ativva6x.dat
- 2007-06-27 01:30:45 3,107,788 ----a-w C:\WINDOWS\system32\ativvaxx.dat
+ 2008-05-12 15:22:31 3,107,788 ----a-w C:\WINDOWS\system32\ativvaxx.dat
+ 2008-05-19 02:02:53 26,184 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
- 2007-06-11 20:34:34 2,115,816 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2008-03-25 00:21:00 2,889,088 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
- 2007-06-11 20:34:40 190,696 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-03-25 00:21:00 218,496 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2007-06-27 01:10:32 376,832 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2cqag.dll
+ 2007-06-27 01:58:35 269,312 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2dvag.dll
+ 2007-06-27 01:50:54 43,520 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2edxx.dll
+ 2007-06-27 01:15:32 49,152 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2erec.dll
+ 2007-06-27 01:50:42 118,784 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2evxx.dll
+ 2007-06-27 01:49:21 483,328 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2evxx.exe
+ 2007-06-27 01:51:01 26,112 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\Ati2mdxx.exe
+ 2007-06-27 01:58:17 2,303,488 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati2mtag.sys
+ 2007-06-27 01:41:08 2,940,992 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ati3duag.dll
+ 2007-06-27 01:48:32 53,248 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ATIDDC.DLL
+ 2007-06-27 01:59:38 344,064 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ATIDEMGX.dll
+ 2007-06-05 17:40:44 149,278 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atiicdxx.dat
+ 2007-06-27 01:56:43 307,200 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atiiiexx.dll
+ 2007-06-27 01:17:35 266,240 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atikvmag.dll
+ 2007-06-27 01:44:55 8,232,960 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atioglx2.dll
+ 2007-06-27 01:19:33 5,435,392 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atioglxx.dll
+ 2007-06-27 01:14:30 176,128 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atiok3x2.dll
+ 2007-06-27 01:51:21 143,360 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atipdlxx.dll
+ 2007-06-27 01:16:12 17,408 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\atitvo32.dll
+ 2001-11-09 15:01:04 24,064 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ativcoxx.dll
+ 2007-06-27 01:30:45 3,107,788 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ativva5x.dat
+ 2007-06-27 01:30:45 972,072 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ativva6x.dat
+ 2007-06-27 01:30:45 3,107,788 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ativvaxx.dat
+ 2007-06-27 01:31:03 1,519,744 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\ativvaxx.dll
+ 2007-06-27 01:51:09 122,880 ----a-w C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\Oemdspif.dll
+ 2007-06-27 01:10:32 376,832 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2cqag.dll
+ 2007-06-27 01:58:35 269,312 ----a-w C:\WI
  • 0

#8
DRugg

DRugg

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Got cut off there here's the rest of ComboFix:

+ 2007-06-27 01:58:35 269,312 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2dvag.dll
+ 2007-06-27 01:50:54 43,520 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2edxx.dll
+ 2008-05-12 15:02:59 49,152 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2erec.dll
+ 2007-06-27 01:50:42 118,784 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2evxx.dll
+ 2007-06-27 01:49:21 483,328 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2evxx.exe
+ 2008-05-12 15:45:14 26,112 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\Ati2mdxx.exe
+ 2008-05-12 16:30:02 3,007,488 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati2mtag.sys
+ 2007-06-27 01:41:08 2,940,992 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ati3duag.dll
+ 2008-05-12 15:41:56 53,248 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ATIDDC.DLL
+ 2007-06-27 01:59:38 344,064 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ATIDEMGX.dll
+ 2008-03-06 14:24:57 168,883 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atiicdxx.dat
+ 2008-05-12 15:53:34 307,200 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atiiiexx.dll
+ 2007-06-27 01:17:35 266,240 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atikvmag.dll
+ 2008-05-12 15:43:14 10,153,984 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atioglx2.dll
+ 2008-05-12 15:05:13 5,439,488 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atioglxx.dll
+ 2007-06-27 01:14:30 176,128 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atiok3x2.dll
+ 2007-06-27 01:51:21 143,360 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atipdlxx.dll
+ 2008-05-12 15:03:46 17,408 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\atitvo32.dll
+ 2001-11-09 15:01:04 24,064 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ativcoxx.dll
+ 2008-05-12 15:22:31 3,107,788 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ativva5x.dat
+ 2008-05-12 15:22:31 887,724 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ativva6x.dat
+ 2008-05-12 15:22:31 3,107,788 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ativvaxx.dat
+ 2007-06-27 01:31:03 1,519,744 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\ativvaxx.dll
+ 2008-05-12 15:45:23 139,264 ----a-w C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\Oemdspif.dll
- 2008-04-21 00:48:25 4,212 ---ha-w C:\WINDOWS\system32\zllictbl.dat
+ 2008-05-18 19:21:18 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
- 2008-05-18 18:59:26 103,852 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2008-05-23 12:11:40 109,620 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
- 2008-05-18 19:13:36 66,252,288 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-05-20 04:08:17 66,252,288 ----a-w C:\WINDOWS\system32\ZoneLabs\zlqrtdb.dat
+ 2008-05-23 12:10:02 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_674.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-18 22:02 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-18 22:02 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-29 23:49 16269312 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-15 22:04 2879488 C:\WINDOWS\SkyTel.exe]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-05-18 14:49 919016]
"nmctxth"="C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-04-26 04:22 451896]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [2008-04-26 04:22 451896]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-18 22:02 1177368]
"ATIModeChange"="Ati2mdxx.exe" [2008-05-12 11:45 26112 C:\WINDOWS\system32\Ati2mdxx.exe]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"ATICustomerCare"="C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" [2007-10-04 18:38 307200]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\deltamarine\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Warcraft III\\War3.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\dookiecrisp\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"C:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"67:UDP"= 67:UDP:DHCP Discovery Service
"6112:TCP"= 6112:TCP:WC3

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-18 22:02]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-18 22:02]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-18 22:02]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-18 22:02]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-23 09:08:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-23 9:08:56
ComboFix-quarantined-files.txt 2008-05-23 13:08:52
ComboFix2.txt 2008-05-20 04:16:30
ComboFix3.txt 2008-05-18 19:21:12

Pre-Run: 73,161,883,648 bytes free
Post-Run: 73,162,977,280 bytes free

515
  • 0

#9
DRugg

DRugg

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
And here's the Malwarebytes Log:

Malwarebytes' Anti-Malware 1.12
Database version: 781

Scan type: Quick Scan
Objects scanned: 36244
Time elapsed: 2 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\drivers\core.cache.dsk (Malware.Trace) -> Quarantined and deleted successfully.
  • 0

#10
DRugg

DRugg

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
And finally, here's the HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:39:32 AM, on 5/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
O24 - Desktop Component 0: (no name) - (no file)

--
End of file - 4729 bytes


Thanks for the help once again, Mike!!
  • 0

#11
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi DRugg,

Your logs are looking much better now. Weird thing is that file seemed to have disappeared...

Step 1. Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u6-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.
Step 2. Fixes

Please open HijackThis again and choose "Do a system scan only". Please put a check next to each of the following entries (if still present):

O24 - Desktop Component 0: (no name) - (no file)

Now please close all open windows except HJT and press "Fix checked".

Step 3. Running Kaspersky Online Virusscaner

Before running a new scan let's clean out the temporary folders.

Download ATF Cleaner to your Desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:
  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:
  • Click Opera at the top and choose Select All from the list.
  • Close ALL Internet browsers (very important).
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Please run a free online scan with Kaspersky AntiVirus (works only with MS Internet Explorer 5.0 or higher).
Go to http://www.kaspersky.com/virusscanner and click the "Kaspersky Online Scanner" button (NOT "Kaspersky File Scanner").
  • In the new window that opens, click the "Accept" button to accept the user agreement, install the ActiveX control, and download the program.
  • When you get the Windows dialog asking if you want to install this software, click the "Install" button.
  • When the "Update progress" line changes to "Ready" and the "NEXT ->" button lights up with a green arrow, click it.
  • Click on the "Scan Settings" button, and in the next window select the "extended" database, and click Ok.
  • Under "Please select a target to scan:", click My Computer to start the scan.
When the scan is finished, click the "Save as Text" button, and save the file as kavscan.txt to your Desktop, close the Kaspersky On-line Scanner window, and post the text in kavscan.txt in your next reply.

In your next reply

Please post the log from ComboFix.
Please post the log from Kaspersky.

How is your computer running now? If you have any problems, please give me a quick description.

If the logs are to big to fit in one reply please spread them out over multiple replies.

Edited by Mike, 23 May 2008 - 10:24 AM.

  • 0

#12
DRugg

DRugg

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
ComboFix 08-05-15.3 - D Mother[bleep]ing Rugg 2008-05-23 23:05:20.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1376 [GMT -4:00]
Running from: C:\Documents and Settings\D Mother[bleep]ing Rugg\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-04-24 to 2008-05-24 )))))))))))))))))))))))))))))))
.

2008-05-23 21:50 . 2008-05-23 21:50 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-23 21:50 . 2008-05-23 21:50 <DIR> d-------- C:\WINDOWS\LastGood
2008-05-23 21:50 . 2008-05-23 21:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-23 21:30 . 2008-05-23 21:30 <DIR> d-------- C:\Program Files\Sun
2008-05-23 21:18 . 2008-05-23 21:33 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\.SunDownloadManager
2008-05-23 08:10 . 2008-05-23 08:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-05-23 08:09 . 2008-05-23 08:09 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-05-23 08:08 . 2008-05-23 08:08 <DIR> d-------- C:\Program Files\ATI
2008-05-20 19:02 . 2008-05-20 19:03 <DIR> d-------- C:\Program Files\Funcom
2008-05-20 12:57 . 2008-05-20 12:57 <DIR> d-------- C:\Program Files\IObit
2008-05-20 11:48 . 2008-05-20 11:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-05-20 11:18 . 2008-05-20 11:18 <DIR> d-------- C:\Program Files\ACW
2008-05-20 10:58 . 2008-05-20 11:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SlySoft
2008-05-20 10:58 . 2008-05-20 10:58 40 ---hs---- C:\Documents and Settings\All Users\Application Data\.zreglib
2008-05-20 10:56 . 2008-05-20 10:58 24 ---hs---- C:\WINDOWS\S5EC1A2D7.tmp
2008-05-20 10:55 . 2008-05-20 10:55 <DIR> d-------- C:\Program Files\SlySoft
2008-05-20 01:37 . 2008-05-20 01:37 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\SystemRequirementsLab
2008-05-18 22:11 . 2008-05-23 12:21 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-18 22:02 . 2008-05-23 08:42 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-18 22:02 . 2008-05-18 22:02 <DIR> d-------- C:\Program Files\AVG
2008-05-18 22:02 . 2008-05-23 21:14 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\AVGTOOLBAR
2008-05-18 22:02 . 2008-05-18 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-18 22:02 . 2008-05-18 22:02 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-18 22:02 . 2008-05-18 22:02 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-18 22:02 . 2008-05-18 22:02 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-18 00:36 . 2008-05-18 00:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-18 00:14 . 2008-05-23 09:30 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-18 00:14 . 2008-05-18 00:14 <DIR> d-------- C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Malwarebytes
2008-05-18 00:14 . 2008-05-18 00:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-18 00:14 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-18 00:14 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-18 00:13 . 2008-05-18 00:13 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-17 23:52 . 2008-05-18 22:03 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-17 23:52 . 2008-05-20 12:57 1,024 --ah----- C:\Documents and Settings\Administrator\NtUser.dat.LOG
2008-05-17 23:17 . 2008-05-17 23:17 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-05-17 23:11 . 2008-05-17 23:42 <DIR> d-------- C:\VundoFix Backups
2008-05-12 11:09 . 2008-05-12 11:09 47,104 --a------ C:\WINDOWS\system32\amdpcom32.dll
2008-05-12 11:03 . 2008-05-12 11:03 19,968 --a------ C:\WINDOWS\system32\atiadlxx.dll
2008-04-26 02:25 . 2008-01-08 17:16 23,992 --a------ C:\WINDOWS\system32\drivers\pnarp.sys
2008-04-26 02:24 . 2008-04-26 02:24 <DIR> d-------- C:\Program Files\Common Files\Pure Networks Shared
2008-04-26 02:24 . 2008-01-08 17:16 25,272 --a------ C:\WINDOWS\system32\drivers\purendis.sys
2008-04-24 05:20 . 2008-04-24 05:20 <DIR> d--h----- C:\WINDOWS\PIF
2008-04-24 05:20 . 2008-04-24 05:20 <DIR> d-------- C:\Program Files\7-Zip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-24 03:06 8,169,760 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-24 01:34 --------- d-----w C:\Program Files\Java
2008-05-23 22:37 104,552 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-23 12:07 --------- d-----w C:\Program Files\ATI Technologies
2008-05-20 18:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-20 18:22 40,960 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2008-05-20 18:02 70,656 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2008-05-20 15:02 --------- d-----w C:\Program Files\Common Files\Ahead
2008-05-20 15:02 --------- d-----w C:\Program Files\Ahead
2008-05-20 13:46 99,840 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2008-05-20 04:08 --------- d-----w C:\Program Files\QuickTime
2008-05-12 16:30 3,007,488 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-05-12 15:56 397,312 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-05-12 15:54 305,152 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-05-12 15:53 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-05-12 15:45 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-05-12 15:45 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-05-12 15:45 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-05-12 15:45 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-05-12 15:44 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-05-12 15:43 540,672 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-05-12 15:43 10,153,984 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-05-12 15:41 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-05-12 15:32 3,203,168 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-05-12 15:22 1,999,616 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-05-12 15:05 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-05-12 15:05 327,680 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-05-12 15:03 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-05-12 15:02 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
2008-05-12 15:02 241,664 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-05-12 14:57 548,864 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-05-12 14:49 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2008-04-26 20:53 --------- d-----w C:\Program Files\City of Heroes
2008-04-26 06:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pure Networks
2008-04-19 03:39 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-13 11:19 --------- d-----w C:\Program Files\Warcraft III
2008-04-13 08:12 --------- d--h--w C:\Program Files\Zero G Registry
2008-04-13 08:11 --------- d-----w C:\Program Files\Ubisoft
2008-04-08 21:58 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-31 01:58 --------- d-----w C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Atari
2008-03-31 01:57 --------- d-----w C:\Program Files\The Witcher Demo
2008-03-18 19:46 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-03-14 04:11 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-03-14 04:11 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-02-06 23:59 10 ----a-w C:\Program Files\.autoreg
.

------- Sigcheck -------

2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\dllcache\svchost.exe

2004-08-04 00:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\system32\user32.dll
2004-08-04 00:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\system32\dllcache\user32.dll

2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\dllcache\ws2_32.dll

2004-08-04 00:56 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\system32\wininet.dll
2004-08-04 00:56 656384 c0823fc5469663ba63e7db88f9919d70 C:\WINDOWS\system32\dllcache\wininet.dll

2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\dllcache\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\system32\drivers\tcpip.sys

2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\dllcache\winlogon.exe

2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\dllcache\ndis.sys
2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys

2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\dllcache\ip6fw.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys

2004-08-04 01:05 2015232 fb142b7007ca2eea76966c6c5cc12150 C:\WINDOWS\system32\ntkrnlpa.exe

2004-08-03 23:18 2148352 626309040459c3915997ef98ec1c8d40 C:\WINDOWS\system32\ntoskrnl.exe

2004-08-04 00:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\explorer.exe
2004-08-04 00:56 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\system32\dllcache\explorer.exe

2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\services.exe
2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\dllcache\services.exe

2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\lsass.exe
2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\dllcache\lsass.exe

2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe
2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((( snapshot_2008-05-23_ 9.08.41.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-23 12:09:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-24 01:05:27 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2007-07-12 05:22:00 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-03-25 05:28:39 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2007-07-12 05:22:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-03-25 05:28:43 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2007-07-12 06:22:38 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-03-25 06:37:01 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-05-23 12:11:40 109,620 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2008-05-24 01:08:57 110,768 ----a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\sfdb.dat
+ 2008-05-24 01:06:02 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_2ac.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-18 22:02 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-18 22:02 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-18 22:02 2050816]

[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-29 23:49 16269312 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-15 22:04 2879488 C:\WINDOWS\SkyTel.exe]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-05-18 14:49 919016]
"nmctxth"="C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-04-26 04:22 451896]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [2008-04-26 04:22 451896]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-18 22:02 1177368]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"ATICustomerCare"="C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe" [2007-10-04 18:38 307200]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\deltamarine\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Warcraft III\\War3.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\dookiecrisp\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"C:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"67:UDP"= 67:UDP:DHCP Discovery Service
"6112:TCP"= 6112:TCP:WC3

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-18 22:02]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-18 22:02]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-18 22:02]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-18 22:02]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-23 23:06:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-23 23:06:48
ComboFix-quarantined-files.txt 2008-05-24 03:06:45
ComboFix2.txt 2008-05-23 13:08:57
ComboFix3.txt 2008-05-20 04:16:30
ComboFix4.txt 2008-05-18 19:21:12

Pre-Run: 72,674,816,000 bytes free
Post-Run: 72,661,565,440 bytes free

214
  • 0

#13
DRugg

DRugg

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Here's the Kavscan log :

The computer seems to be running 1000x better atm no pop ups or wierd crashes.

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, May 23, 2008 11:04:43 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 24/05/2008
Kaspersky Anti-Virus database records: 799443
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\

Scan Statistics:
Total number of scanned objects: 49650
Number of viruses found: 1
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 00:40:05

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg8\emc\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgui.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpriv.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmapp_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmctxth_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmsrvc_exe.txt Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\cert8.db Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\history.dat Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\key3.db Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\parent.lock Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\search.sqlite Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Application Data\Mozilla\Firefox\Profiles\a4fnljbj.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\History\History.IE5\MSHist012008052320080524\index.dat Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\D Mother[bleep]ing Rugg\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{7FC4A052-9024-4400-A699-13C1E9831A81}\RP109\A0031265.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{7FC4A052-9024-4400-A699-13C1E9831A81}\RP109\A0031265.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{7FC4A052-9024-4400-A699-13C1E9831A81}\RP154\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_2ac.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
  • 0

#14
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there DRugg,

Please delete this file: C:\WINDOWS\S5EC1A2D7.tmp

And your logs look clean :)

Step 1. Removing ComboFix

Click START then RUN
Now type Combofix /u in the runbox and click OK
Posted Image
Notice the space between the x and / -- That needs to be there.

Now please download OTCleanIt.
  • Save it to your desktop.
  • Double Click on OTCleanIt.exe, a window will appear.
  • Please press the CleanUp! Button.
This will remove the tools we used during the process of cleaning your computer.

Step 2. Configuring Automatic Updates

Click the Automatic Updates tab. Choose the update option that best suits your needs, but be sure that Automatic Updates is not turned off. Windows XP will now notify you and download important updates and security patches as they become available.
Click "OK" to save your new settings and close the System Properties dialogue.

Step 3. Preventing future infection

Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems.

In order to protect yourself against spyware, you should consider installing and running the following free programs:

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
http://www.spywarewa...uc/resource.htm

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.o...oducts/firefox/

Also make sure to run your antivirus software regularly, and to keep it up-to-date.

There are many programs that can be used for your protection, most falling within the three main categories of anti-virus, anti-spyware and firewall. Please be careful to never run more than one program of the same category in resident mode, as conflicts between the different programs can actually decrease your protection.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Hopefully this should take care of your problems! Good luck. :)

Please post back and tell me if everything is OK, so that I may mark this thread as Resolved.
  • 0

#15
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP