Combo Fix:
ComboFix 08-05-21.3 - Thavamalar 2008-05-24 14:04:54.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.198 [GMT -4:00]
Running from: C:\Documents and Settings\Thavamalar\Desktop\ComboFix.exe
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Thavamalar\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
.
((((((((((((((((((((((((( Files Created from 2008-04-24 to 2008-05-24 )))))))))))))))))))))))))))))))
.
2008-05-24 10:57 . 2008-05-24 10:57 123 --a------ C:\WINDOWS\system32\msexcr.ini
2008-05-24 09:20 . 2008-05-24 09:20 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-24 09:20 . 2008-05-24 09:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-24 09:17 . 2008-05-24 09:17 <DIR> d-------- C:\_OTMoveIt
2008-05-21 23:33 . 2008-05-21 23:33 268 --ah----- C:\sqmdata03.sqm
2008-05-21 23:33 . 2008-05-21 23:33 244 --ah----- C:\sqmnoopt02.sqm
2008-05-21 18:41 . 2008-05-21 18:41 <DIR> d-------- C:\VundoFix Backups
2008-05-13 16:42 . 2008-05-13 16:42 <DIR> d-------- C:\Program Files\?ssembly
2008-05-13 16:40 . 2008-05-13 16:40 861 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-05-13 16:39 . 2008-05-13 16:39 <DIR> d-------- C:\Documents and Settings\Thavamalar\Application Data\?ssembly
2008-05-13 16:38 . 2008-05-19 19:32 <DIR> d-------- C:\WINDOWS\system32\podll
2008-05-13 16:38 . 2008-05-14 08:15 <DIR> d-------- C:\WINDOWS\system32\gcom
2008-05-13 16:38 . 2008-05-13 16:38 <DIR> d-------- C:\WINDOWS\system32\DFE
2008-05-13 16:38 . 2008-05-13 16:38 <DIR> d-------- C:\WINDOWS\system32\?ssembly
2008-05-13 16:38 . 2008-05-13 16:39 401,972 --a------ C:\WINDOWS\system32\g73.exe
2008-05-13 16:37 . 2008-05-13 16:37 <DIR> d-------- C:\WINDOWS\system32\dFrnx01
2008-05-13 16:37 . 2008-05-24 08:01 <DIR> d-------- C:\Temp
2008-05-13 16:37 . 2008-05-13 16:37 <DIR> d-------- C:\Program Files\Common Files\?ssembly
2008-05-11 18:13 . 2008-05-14 01:23 <DIR> d-------- C:\Program Files\DivX
2008-05-10 08:55 . 2008-05-14 08:19 211 --a------ C:\WINDOWS\wininit.ini
2008-05-09 22:37 . 2008-05-09 22:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-08 20:46 . 2008-05-08 20:46 <DIR> d-------- C:\WINDOWS\system32\ViBE
2008-05-08 19:26 . 2008-05-08 20:46 <DIR> d-------- C:\WINDOWS\system32\xIT2
2008-05-08 19:26 . 2008-05-19 19:30 <DIR> d-------- C:\WINDOWS\system32\1019b
2008-05-08 19:12 . 2008-05-08 19:12 <DIR> d-------- C:\WINDOWS\system32\bkEur01
2008-05-08 19:12 . 2008-05-08 19:26 <DIR> d-------- C:\WINDOWS\system32\ad1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 18:24 --------- d-----w C:\Documents and Settings\Thavamalar\Application Data\teamspeak2
2008-05-08 23:27 --------- d-----w C:\Documents and Settings\Thavamalar\Application Data\DMCache
2008-04-16 00:55 --------- d-----w C:\Program Files\Vstplugins
2008-04-16 00:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony
2008-04-16 00:53 --------- d-----w C:\Program Files\Sony Setup
2008-04-15 18:06 --------- d-----w C:\Documents and Settings\Thavamalar\Application Data\IDM
2008-04-15 02:42 --------- d-----w C:\Program Files\DNA
2008-04-13 22:35 --------- d-----w C:\Program Files\Microsoft Bootvis
2008-04-10 03:11 --------- d-----w C:\Program Files\Alwil Software
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
.
((((((((((((((((((((((((((((( snapshot@2008-05-24_ 8.11.39.64 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-24 12:08:05 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-24 18:02:00 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0cd3edf1-a2a7-24ef-f7a6-bc5a9dda91fc}]
C:\WINDOWS\system32\{be24d6d6-8fdc-35f6-c21e-5fd5cbf95398}.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{462AA99E-E538-45C2-BACB-997BFE943B10}]
C:\WINDOWS\system32\mlJDvVlj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72B52281-D133-4091-8E2F-FD91E8F6601F}]
C:\WINDOWS\system32\pmnkLCRj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9F60E186-8840-4CC0-B7DD-95773A4015B4}]
C:\WINDOWS\system32\mlJCUOij.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bb8253ee-a22d-480a-957e-e55ee763c78a}]
C:\WINDOWS\system32\mqbdpfnk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BD1652DC-4F6C-4B28-A23E-B179BA5DFBE1}]
C:\WINDOWS\system32\tuvSkiff.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-12 14:59 15360]
"SpybotSD TeaTimer"="D:\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-03-03 22:44 4595712]
"nwiz"="nwiz.exe" [2003-03-03 22:44 323584 C:\WINDOWS\system32\nwiz.exe]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 17:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-03-01 00:00 315392]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 14:24 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 14:11 114688]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 13:29 40960]
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 15:59 88107 C:\WINDOWS\AGRSMMSG.exe]
"BMf3075b31"="C:\WINDOWS\system32\xikfosxt.dll" [ ]
"{46-68-80-02-DW}"="c:\windows\system32\jnwnw64p.exe" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
"vidc.ffds"= D:\Program Files\ffdshow\ffdshow.ax
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2006-02-19 03:41 49152 D:\Program Files\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 2008-02-20 10:13 2594224 D:\Image\Crack\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
--a--c--- 2002-06-18 01:01 155648 C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Recovery]
--a--c--- 2003-04-20 01:08 28672 C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIOSurvey]
--a--c--- 2003-03-17 14:52 1056768 c:\program files\sony\vaio survey\surveysa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZTgServerSwitch]
--a--c--- 2002-07-14 15:50 11406 c:\program files\support.com\client\lserver\server.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZZZ]
--a--c--- 2003-01-21 13:27 24576 C:\WINDOWS\Sonysys\Eflyer\EFlyer_Popup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"WLSetupSvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\ijji\\ENGLISH\\u_sf.exe"=
"D:\\Program Files\\Firefox\\firefox.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 14:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 14:35]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-03-31 01:45:00 C:\WINDOWS\Tasks\shutdown.job"
- C:\WINDOWS\system32\shutdown.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-24 14:06:25
Windows 5.1.2600 Service Pack 3, v.3311 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-24 14:08:08
ComboFix-quarantined-files.txt 2008-05-24 18:08:01
ComboFix2.txt 2008-05-24 12:12:05
Pre-Run: 928,505,856 bytes free
Post-Run: 926,392,320 bytes free
157 --- E O F --- 2008-05-15 02:38:24
OTMOVEIT:
Explorer killed successfully
C:\WINDOWS\system32\{be24d6d6-8fdc-35f6-c21e-5fd5cbf95398}.dll-uninst.exe moved successfully.
C:\WINDOWS\system32\gside.exe moved successfully.
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe moved successfully.
C:\WINDOWS\system32\msexcr.ini moved successfully.
< purity >
C:\WINDOWS\system32\Αdobe moved successfully.
C:\WINDOWS\system32\Аdobe moved successfully.
C:\WINDOWS\system32\АppPatch moved successfully.
C:\WINDOWS\system32\АрpPatch moved successfully.
C:\WINDOWS\system32\ΑppPatch moved successfully.
C:\WINDOWS\system32\ΑрpPatch moved successfully.
C:\WINDOWS\system32\AрpPatch moved successfully.
C:\WINDOWS\system32\aѕsembly moved successfully.
C:\WINDOWS\system32\аѕsembly moved successfully.
C:\WINDOWS\system32\Fοnts moved successfully.
C:\WINDOWS\system32\Fоnts moved successfully.
C:\WINDOWS\system32\Mіcrosoft.NET moved successfully.
C:\WINDOWS\system32\Μicrosoft.NET moved successfully.
C:\WINDOWS\system32\Μіcrosoft.NET moved successfully.
C:\WINDOWS\system32\Мicrosoft.NET moved successfully.
C:\WINDOWS\system32\Міcrosoft.NET moved successfully.
C:\WINDOWS\system32\Mіcrosoft moved successfully.
C:\WINDOWS\system32\Μicrosoft moved successfully.
C:\WINDOWS\system32\Μіcrosoft moved successfully.
C:\WINDOWS\system32\Мicrosoft moved successfully.
C:\WINDOWS\system32\Міcrosoft moved successfully.
C:\WINDOWS\system32\Οracle moved successfully.
C:\WINDOWS\system32\Оracle moved successfully.
C:\WINDOWS\system32\sеcurity moved successfully.
C:\WINDOWS\system32\ѕecurity moved successfully.
C:\WINDOWS\system32\ѕеcurity moved successfully.
C:\WINDOWS\system32\Sуmantec moved successfully.
C:\WINDOWS\system32\Ѕymantec moved successfully.
C:\WINDOWS\system32\Ѕуmantec moved successfully.
C:\WINDOWS\system32\ѕymbols moved successfully.
C:\WINDOWS\system32\sуmbols moved successfully.
C:\WINDOWS\system32\ѕуmbols moved successfully.
C:\WINDOWS\system32\ѕуstem moved successfully.
C:\WINDOWS\system32\sуstem moved successfully.
C:\WINDOWS\system32\ѕystem moved successfully.
C:\WINDOWS\system32\ѕystem32 moved successfully.
C:\WINDOWS\system32\sуstem32 moved successfully.
C:\WINDOWS\system32\ѕуstem32 moved successfully.
C:\WINDOWS\system32\Tаsks moved successfully.
C:\WINDOWS\system32\Τasks moved successfully.
C:\WINDOWS\system32\Τаsks moved successfully.
C:\WINDOWS\system32\Тasks moved successfully.
C:\WINDOWS\system32\Таsks moved successfully.
C:\WINDOWS\system32\WіnSxS moved successfully.
C:\Program Files\Αdobe moved successfully.
C:\Program Files\Аdobe moved successfully.
C:\Program Files\АppPatch moved successfully.
C:\Program Files\АрpPatch moved successfully.
C:\Program Files\AрpPatch moved successfully.
C:\Program Files\aѕsembly moved successfully.
C:\Program Files\аѕsembly moved successfully.
C:\Program Files\Fοnts moved successfully.
C:\Program Files\Fоnts moved successfully.
C:\Program Files\Mіcrosoft.NET moved successfully.
C:\Program Files\Мicrosoft.NET moved successfully.
C:\Program Files\Міcrosoft.NET moved successfully.
C:\Program Files\Mіcrosoft moved successfully.
C:\Program Files\Мicrosoft moved successfully.
C:\Program Files\Міcrosoft moved successfully.
C:\Program Files\Оracle moved successfully.
C:\Program Files\sеcurity moved successfully.
C:\Program Files\ѕecurity moved successfully.
C:\Program Files\ѕеcurity moved successfully.
C:\Program Files\Sуmantec moved successfully.
C:\Program Files\Ѕymantec moved successfully.
C:\Program Files\Ѕуmantec moved successfully.
C:\Program Files\ѕymbols moved successfully.
C:\Program Files\sуmbols moved successfully.
C:\Program Files\ѕуmbols moved successfully.
C:\Program Files\ѕуstem moved successfully.
C:\Program Files\sуstem moved successfully.
C:\Program Files\ѕystem moved successfully.
C:\Program Files\ѕystem32 moved successfully.
C:\Program Files\sуstem32 moved successfully.
C:\Program Files\ѕуstem32 moved successfully.
C:\Program Files\Tаsks moved successfully.
C:\Program Files\Τаsks moved successfully.
C:\Program Files\Тasks moved successfully.
C:\Program Files\Common Files\Αdobe moved successfully.
C:\Program Files\Common Files\Аdobe moved successfully.
C:\Program Files\Common Files\АppPatch moved successfully.
C:\Program Files\Common Files\АрpPatch moved successfully.
C:\Program Files\Common Files\ΑppPatch moved successfully.
C:\Program Files\Common Files\ΑрpPatch moved successfully.
C:\Program Files\Common Files\AрpPatch moved successfully.
C:\Program Files\Common Files\aѕsembly moved successfully.
C:\Program Files\Common Files\аѕsembly moved successfully.
C:\Program Files\Common Files\Fοnts moved successfully.
C:\Program Files\Common Files\Fоnts moved successfully.
C:\Program Files\Common Files\Mіcrosoft.NET moved successfully.
C:\Program Files\Common Files\Μicrosoft.NET moved successfully.
C:\Program Files\Common Files\Μіcrosoft.NET moved successfully.
C:\Program Files\Common Files\Мicrosoft.NET moved successfully.
C:\Program Files\Common Files\Міcrosoft.NET moved successfully.
C:\Program Files\Common Files\Mіcrosoft moved successfully.
C:\Program Files\Common Files\Μicrosoft moved successfully.
C:\Program Files\Common Files\Μіcrosoft moved successfully.
C:\Program Files\Common Files\Мicrosoft moved successfully.
C:\Program Files\Common Files\Міcrosoft moved successfully.
C:\Program Files\Common Files\Οracle moved successfully.
C:\Program Files\Common Files\Оracle moved successfully.
C:\Program Files\Common Files\sеcurity moved successfully.
C:\Program Files\Common Files\ѕecurity moved successfully.
C:\Program Files\Common Files\ѕеcurity moved successfully.
C:\Program Files\Common Files\Sуmantec moved successfully.
C:\Program Files\Common Files\Ѕymantec moved successfully.
C:\Program Files\Common Files\Ѕуmantec moved successfully.
C:\Program Files\Common Files\ѕymbols moved successfully.
C:\Program Files\Common Files\sуmbols moved successfully.
C:\Program Files\Common Files\ѕуmbols moved successfully.
C:\Program Files\Common Files\ѕуstem moved successfully.
C:\Program Files\Common Files\sуstem moved successfully.
C:\Program Files\Common Files\ѕystem moved successfully.
C:\Program Files\Common Files\ѕystem32 moved successfully.
C:\Program Files\Common Files\sуstem32 moved successfully.
C:\Program Files\Common Files\ѕуstem32 moved successfully.
C:\Program Files\Common Files\Tаsks moved successfully.
C:\Program Files\Common Files\Τasks moved successfully.
C:\Program Files\Common Files\Τаsks moved successfully.
C:\Program Files\Common Files\Тasks moved successfully.
C:\Program Files\Common Files\Таsks moved successfully.
C:\Program Files\Common Files\WіnSxS moved successfully.
C:\Documents and Settings\Thavamalar\My Documents\Fοnts moved successfully.
C:\Documents and Settings\Thavamalar\My Documents\Fоnts moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Αdobe moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Аdobe moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\АppPatch moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\АрpPatch moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ΑppPatch moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ΑрpPatch moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\AрpPatch moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\aѕsembly moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\аѕsembly moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Fοnts moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Fоnts moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Mіcrosoft.NET moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Μicrosoft.NET moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Μіcrosoft.NET moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Мicrosoft.NET moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Міcrosoft.NET moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Mіcrosoft moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Μicrosoft moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Μіcrosoft moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Мicrosoft moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Міcrosoft moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Οracle moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Оracle moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\sеcurity moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ѕecurity moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ѕеcurity moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Sуmantec moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Ѕymantec moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Ѕуmantec moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ѕymbols moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\sуmbols moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ѕуmbols moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ѕуstem moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\sуstem moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ѕystem moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ѕystem32 moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\sуstem32 moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\ѕуstem32 moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Tаsks moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Τasks moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Τаsks moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Тasks moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\Таsks moved successfully.
C:\Documents and Settings\Thavamalar\Application Data\WіnSxS moved successfully.
Explorer started successfully
OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05242008_091714
Kaspersky:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 24, 2008 1:58:43 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 3, v.3311 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 24/05/2008
Kaspersky Anti-Virus database records: 799624
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 56935
Number of viruses found: 6
Number of infected objects: 19
Number of suspicious objects: 0
Duration of the scan process: 01:33:42
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Thavamalar\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\cert8.db Object is locked skipped
C:\Documents and Settings\Thavamalar\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\history.dat Object is locked skipped
C:\Documents and Settings\Thavamalar\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\key3.db Object is locked skipped
C:\Documents and Settings\Thavamalar\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\parent.lock Object is locked skipped
C:\Documents and Settings\Thavamalar\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Thavamalar\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Thavamalar\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Thavamalar\Desktop\Snootae Bot 2.0\SnootaeBotFontChecker.exe Infected: Trojan.Win32.Shutdowner.fr skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_5CF0_3485_F034_6802\dfsr.db Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_5CF0_3485_F034_6802\fsr.log Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_5CF0_3485_F034_6802\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_5CF0_3485_F034_6802\tmp.edb Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Microsoft\Windows Live Contacts\
[email protected]\real\members.stg Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yu3ki3.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\History\History.IE5\MSHist012008052420080525\index.dat Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Temp\~DFD36.tmp Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Temp\~DFD4C.tmp Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Thavamalar\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Thavamalar\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Thavamalar\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP233\A0024023.dll Infected: Trojan.Win32.BHO.cgy skipped
C:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP237\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{558F8FAF-0D96-4358-B326-3703FFA0FECC}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\bkEur01\bkEur011065.exe Infected: Trojan-Downloader.Win32.VB.edw skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\DFE\roEbdll2.exe/stream/data0007/stream/Script Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\DFE\roEbdll2.exe/stream/data0007/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\DFE\roEbdll2.exe/stream/data0007 Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\DFE\roEbdll2.exe/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\DFE\roEbdll2.exe NSIS: infected - 4 skipped
C:\WINDOWS\system32\dFrnx01\dFrnx011065.exe Infected: Trojan-Downloader.Win32.VB.ehl skipped
C:\WINDOWS\system32\g73.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.Agent.byy skipped
C:\WINDOWS\system32\g73.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.byy skipped
C:\WINDOWS\system32\g73.exe NSIS: infected - 2 skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\ViBE\srkawe3.exe/stream/data0007/stream/Script Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\ViBE\srkawe3.exe/stream/data0007/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\ViBE\srkawe3.exe/stream/data0007 Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\ViBE\srkawe3.exe/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\ViBE\srkawe3.exe NSIS: infected - 4 skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_540.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\Snootae Bot 2.0.rar/Snootae Bot 2.0/SnootaeBotFontChecker.exe Infected: Trojan.Win32.Shutdowner.fr skipped
D:\Snootae Bot 2.0.rar RAR: infected - 1 skipped
D:\System Volume Information\_restore{543848E5-A971-4387-BA47-9852573A650F}\RP237\change.log Object is locked skipped
Scan process completed.