Arrite. It worked! thanks alot
ComboFix 08-05-25.5 - Rashid 2008-05-26 19:59:17.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.120 [GMT -4:00]
Running from: C:\Documents and Settings\Rashid\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\LocalService\Application Data\.rdr.ini
C:\Documents and Settings\LocalService\Local Settings\Application Data\n.ini
C:\Documents and Settings\NetworkService\Application Data\.rdr.ini
C:\Documents and Settings\NetworkService\Start Menu\Programs\Outerinfo
C:\Documents and Settings\NetworkService\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\NetworkService\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\Rashid\Application Data\.rdr.ini
C:\Documents and Settings\Rashid\Application Data\ASEMBL~1
C:\Documents and Settings\Rashid\Application Data\macromedia\Flash Player\#SharedObjects\9R2D7Q4F\www.broadcaster.com
C:\Documents and Settings\Rashid\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Rashid\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Rashid\Application Data\MANTEC~1
C:\Documents and Settings\Rashid\Application Data\PPPATC~1
C:\Documents and Settings\Rashid\Application Data\RACLE~1
C:\Documents and Settings\Rashid\Application Data\TSKS~1
C:\Documents and Settings\Rashid\My Documents\APPATC~1
C:\Documents and Settings\Rashid\My Documents\APPATC~1\Romana Resume edited.doc
C:\Documents and Settings\Rashid\My Documents\PPPATC~1
C:\Documents and Settings\Rashid\My Documents\PPPATC~2
C:\Documents and Settings\Rashid\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Rashid\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Rashid\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\Rashid\Start Menu\Programs\Startup\ta_start.lnk
C:\Program Files\Common Files\{3CE85~1
C:\Program Files\Common Files\{3CE85~1\Bar888.dll.lzma
C:\Program Files\Common Files\{9CE85~1
C:\Program Files\Common Files\crosof~1
C:\Program Files\Common Files\crosof~1.net
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\fnts~1\M?crosoft\
C:\Program Files\Common Files\ppatch~1
C:\Program Files\Common Files\racle~1
C:\Program Files\Common Files\scurit~1
C:\Program Files\Common Files\wnsxs~1
C:\Program Files\Common Files\ymante~1
C:\Program Files\Common Files\ymbols~1
C:\Program Files\crosof~1.net
C:\Program Files\E404 Helper
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\
00E55886.urr
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\budyicon\fwpbuddy.png
C:\Program Files\MyWebSearch\bar\Cache\
0000AEDD
C:\Program Files\MyWebSearch\bar\Cache\
00011076
C:\Program Files\MyWebSearch\bar\Cache\
0001AEC9
C:\Program Files\MyWebSearch\bar\Cache\
0001B716
C:\Program Files\MyWebSearch\bar\Cache\
00028F65
C:\Program Files\MyWebSearch\bar\Cache\
0002B54C
C:\Program Files\MyWebSearch\bar\Cache\
00036E5B
C:\Program Files\MyWebSearch\bar\Cache\
00040E44
C:\Program Files\MyWebSearch\bar\Cache\
0004178B
C:\Program Files\MyWebSearch\bar\Cache\
0006FCC1
C:\Program Files\MyWebSearch\bar\Cache\
00087344
C:\Program Files\MyWebSearch\bar\Cache\
0008BBE6
C:\Program Files\MyWebSearch\bar\Cache\
0008F814
C:\Program Files\MyWebSearch\bar\Cache\
000B3F93
C:\Program Files\MyWebSearch\bar\Cache\
000D10BA
C:\Program Files\MyWebSearch\bar\Cache\
00123AA0
C:\Program Files\MyWebSearch\bar\Cache\
001DB5C6
C:\Program Files\MyWebSearch\bar\Cache\
002C73B3.bin
C:\Program Files\MyWebSearch\bar\Cache\
002C7430.bin
C:\Program Files\MyWebSearch\bar\Cache\
002C749D.bin
C:\Program Files\MyWebSearch\bar\Cache\
002C7578.bin
C:\Program Files\MyWebSearch\bar\Cache\
002C7624.bin
C:\Program Files\MyWebSearch\bar\Cache\
004387E7
C:\Program Files\MyWebSearch\bar\Cache\
00B5CB10
C:\Program Files\MyWebSearch\bar\Cache\
00B6F576
C:\Program Files\MyWebSearch\bar\Cache\
00CA9DB0
C:\Program Files\MyWebSearch\bar\Cache\
00CB8EB7
C:\Program Files\MyWebSearch\bar\Cache\
00F39A9C.bin
C:\Program Files\MyWebSearch\bar\Cache\
0154F854
C:\Program Files\MyWebSearch\bar\Cache\
015C7AF0
C:\Program Files\MyWebSearch\bar\Cache\
01715BC9
C:\Program Files\MyWebSearch\bar\Cache\
017308AE
C:\Program Files\MyWebSearch\bar\Cache\
0181C94A
C:\Program Files\MyWebSearch\bar\Cache\
018BBD34.bin
C:\Program Files\MyWebSearch\bar\Cache\
018BBECA.bin
C:\Program Files\MyWebSearch\bar\Cache\
018BBF09.bin
C:\Program Files\MyWebSearch\bar\Cache\
018BBF86
C:\Program Files\MyWebSearch\bar\Cache\
018F6481
C:\Program Files\MyWebSearch\bar\Cache\
01ABE542
C:\Program Files\MyWebSearch\bar\Cache\
01D626A4
C:\Program Files\MyWebSearch\bar\Cache\
0238C20D
C:\Program Files\MyWebSearch\bar\Cache\
024619B3
C:\Program Files\MyWebSearch\bar\Cache\
02473739
C:\Program Files\MyWebSearch\bar\Cache\
026BA41C
C:\Program Files\MyWebSearch\bar\Cache\
0297FFA4
C:\Program Files\MyWebSearch\bar\Cache\
03E678B4
C:\Program Files\MyWebSearch\bar\Cache\13D0B3E0
C:\Program Files\MyWebSearch\bar\Cache\13D0B632
C:\Program Files\MyWebSearch\bar\Cache\13D0B71C.bin
C:\Program Files\MyWebSearch\bar\Cache\13D0B8C2.bin
C:\Program Files\MyWebSearch\bar\Cache\13D0B97E.bin
C:\Program Files\MyWebSearch\bar\Cache\13D0BA1A.bin
C:\Program Files\MyWebSearch\bar\Cache\13D0C303.bin
C:\Program Files\MyWebSearch\bar\Cache\13D0CF48.bin
C:\Program Files\MyWebSearch\bar\Cache\13D0CF96.bin
C:\Program Files\MyWebSearch\bar\Cache\13D0D080.bin
C:\Program Files\MyWebSearch\bar\Cache\13D0D18A
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\pppatc~1
C:\Program Files\Temporary
C:\Program Files\WinAble
C:\Program Files\Windows NT\profsybywuu.html
C:\Program Files\wintouch
C:\Program Files\wintouch\wintouch.cfg
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\temp\tn3
C:\Think-Adz.lnk
C:\WINDOWS\180ax.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\Casino.ico
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\crosof~1
C:\WINDOWS\curity~1
C:\WINDOWS\default.htm
C:\WINDOWS\didduid.ini
C:\WINDOWS\dobe~1
C:\WINDOWS\flt.dll
C:\WINDOWS\fnts~1
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\Installer\id53.exe
C:\WINDOWS\mspphe.dll
C:\WINDOWS\ORUN32.EXE
C:\WINDOWS\pack.epk
C:\WINDOWS\pbar.dll
C:\WINDOWS\pppatc~1
C:\WINDOWS\racle~1
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\satmat.exe
C:\WINDOWS\sks~1
C:\WINDOWS\Spyware Remover.ico
C:\WINDOWS\ssembl~1
C:\WINDOWS\stcloader.exe
C:\WINDOWS\susp.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\acjqggiq.ini
C:\WINDOWS\system32\afbyysyh.ini
C:\WINDOWS\system32\agpegxgy.ini
C:\WINDOWS\system32\anwfeylm.ini
C:\WINDOWS\system32\aqmchbwo.ini
C:\WINDOWS\system32\asks~1
C:\WINDOWS\system32\atgalepe.ini
C:\WINDOWS\system32\baoprqkq.ini
C:\WINDOWS\system32\bbijwhbf.ini
C:\WINDOWS\system32\bdobtxdt.ini
C:\WINDOWS\system32\bewpqjtf.ini
C:\WINDOWS\system32\bfmnqbdk.ini
C:\WINDOWS\system32\bnmcrosq.ini
C:\WINDOWS\system32\bntrslll.ini
C:\WINDOWS\system32\bqjcpewh.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\bylqlmhl.ini
C:\WINDOWS\system32\cixfcdoc.ini
C:\WINDOWS\system32\CMMGR32.EXE
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\configs
C:\WINDOWS\system32\cqgrjwcx.ini
C:\WINDOWS\system32\crosof~1.net
C:\WINDOWS\system32\crosof~1.net\??crosoft.NET\
C:\WINDOWS\system32\csuqhmjw.ini
C:\WINDOWS\system32\cvgfkuni.ini
C:\WINDOWS\system32\deebkdvi.ini
C:\WINDOWS\system32\dgvuouva.ini
C:\WINDOWS\system32\djrflxps.ini
C:\WINDOWS\system32\dkbbimuv.ini
C:\WINDOWS\system32\dpemnipr.ini
C:\WINDOWS\system32\dqxkbacn.ini
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\dsrhmwqr.ini
C:\WINDOWS\system32\dxgdnqps.ini
C:\WINDOWS\system32\dyihjvaj.ini
C:\WINDOWS\system32\eluuhfht.ini
C:\WINDOWS\system32\epyegnhn.ini
C:\WINDOWS\system32\eqksboja.ini
C:\WINDOWS\system32\evjtprhj.ini
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f06WtR
C:\WINDOWS\system32\F2
C:\WINDOWS\system32\F3
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\fdnmqvga.ini
C:\WINDOWS\system32\fhrxdqhh.ini
C:\WINDOWS\system32\fqiivoln.ini
C:\WINDOWS\system32\fybqdjxw.ini
C:\WINDOWS\system32\gbqvgbat.ini
C:\WINDOWS\system32\gcjlgkrk.ini
C:\WINDOWS\system32\gexbbjka.ini
C:\WINDOWS\system32\ghrmoaie.ini
C:\WINDOWS\system32\gkboomef.ini
C:\WINDOWS\system32\gkhxotgd.ini
C:\WINDOWS\system32\glicowix.ini
C:\WINDOWS\system32\gmaifehm.ini
C:\WINDOWS\system32\gmdmtgbt.ini
C:\WINDOWS\system32\gryokpmr.ini
C:\WINDOWS\system32\gsbliwnn.ini
C:\WINDOWS\system32\gsblyafw.ini
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\hfspcltr.ini
C:\WINDOWS\system32\hfvkjrii.ini
C:\WINDOWS\system32\hkyjeenl.ini
C:\WINDOWS\system32\hmsinvir.ini
C:\WINDOWS\system32\hqucvhbi.ini
C:\WINDOWS\system32\hunhckvw.ini
C:\WINDOWS\system32\hvhldblk.ini
C:\WINDOWS\system32\ibfgtast.ini
C:\WINDOWS\system32\igpolyfy.ini
C:\WINDOWS\system32\iljbewun.ini
C:\WINDOWS\system32\iukvbwrx.ini
C:\WINDOWS\system32\iuogflai.ini
C:\WINDOWS\system32\ivqsqnss.ini
C:\WINDOWS\system32\jcnorowp.ini
C:\WINDOWS\system32\jefriprf.ini
C:\WINDOWS\system32\jjjlm.bak1
C:\WINDOWS\system32\jjjlm.bak2
C:\WINDOWS\system32\jjjlm.ini
C:\WINDOWS\system32\jnyxvljy.ini
C:\WINDOWS\system32\juscuiof.ini
C:\WINDOWS\system32\kbrrkcow.ini
C:\WINDOWS\system32\kifgrvcy.ini
C:\WINDOWS\system32\kjcfijwd.ini
C:\WINDOWS\system32\kjuxpriu.ini
C:\WINDOWS\system32\klvbvpyk.ini
C:\WINDOWS\system32\kqywinnr.ini
C:\WINDOWS\system32\krkfspdu.ini
C:\WINDOWS\system32\krwxqwbr.ini
C:\WINDOWS\system32\kthebagl.ini
C:\WINDOWS\system32\kucmdqmf.ini
C:\WINDOWS\system32\kxnsggad.ini
C:\WINDOWS\system32\lahhnxoy.ini
C:\WINDOWS\system32\legskype.ini
C:\WINDOWS\system32\lfd32.ini
C:\WINDOWS\system32\ljfwrjwd.ini
C:\WINDOWS\system32\lkrpthgr.ini
C:\WINDOWS\system32\llbyakrk.ini
C:\WINDOWS\system32\lufwdpec.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mcroso~1
C:\WINDOWS\system32\mfkocppj.ini
C:\WINDOWS\system32\mhitjyob.ini
C:\WINDOWS\system32\mjjvwbpo.ini
C:\WINDOWS\system32\mmppserp.ini
C:\WINDOWS\system32\mnmokfnx.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\mxuupblj.ini
C:\WINDOWS\system32\mythgsbm.ini
C:\WINDOWS\system32\nedeqkfv.ini
C:\WINDOWS\system32\niuvjaty.ini
C:\WINDOWS\system32\nqfwwnwy.ini
C:\WINDOWS\system32\nucqomom.ini
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\system32\olfwoggk.ini
C:\WINDOWS\system32\oowkbjmg.ini
C:\WINDOWS\system32\owewwopq.ini
C:\WINDOWS\system32\pdbjhktq.ini
C:\WINDOWS\system32\peaapuij.ini
C:\WINDOWS\system32\phljjmmv.ini
C:\WINDOWS\system32\plvtujhi.ini
C:\WINDOWS\system32\prfxnque.ini
C:\WINDOWS\system32\ptudgjru.ini
C:\WINDOWS\system32\pwyfxahj.ini
C:\WINDOWS\system32\qgoihjff.ini
C:\WINDOWS\system32\qmmibmqu.ini
C:\WINDOWS\system32\qwdufrhn.ini
C:\WINDOWS\system32\rdwsqcjy.ini
C:\WINDOWS\system32\rlrqwpgq.ini
C:\WINDOWS\system32\ruxywcrv.ini
C:\WINDOWS\system32\sfgikueb.ini
C:\WINDOWS\system32\soarlltx.ini
C:\WINDOWS\system32\sstem~1
C:\WINDOWS\system32\sstem3~1
C:\WINDOWS\system32\stem32~1
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\svvssnng.ini
C:\WINDOWS\system32\sxjkdlne.ini
C:\WINDOWS\system32\tbdlqggj.ini
C:\WINDOWS\system32\tumorrlj.ini
C:\WINDOWS\system32\tyhwndsy.ini
C:\WINDOWS\system32\ucvkvckx.ini
C:\WINDOWS\system32\uexemmjt.ini
C:\WINDOWS\system32\uiweasic.ini
C:\WINDOWS\system32\unsvchosts.exe
C:\WINDOWS\system32\vknohco.dat
C:\WINDOWS\system32\vknohco_nav.dat
C:\WINDOWS\system32\vknohco_navps.dat
C:\WINDOWS\system32\vkqsldti.ini
C:\WINDOWS\system32\vnmnkmam.ini
C:\WINDOWS\system32\vptidoew.ini
C:\WINDOWS\system32\vscftgof.ini
C:\WINDOWS\system32\vuynfbkq.ini
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wbirlcuh.ini
C:\WINDOWS\system32\wdkenstn.ini
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wnlocnxx.ini
C:\WINDOWS\system32\wnmdtyny.ini
C:\WINDOWS\system32\wnsintsv32.exe
C:\WINDOWS\system32\wsxwapje.ini
C:\WINDOWS\system32\wtcsujkl.ini
C:\WINDOWS\system32\wwstsisv.ini
C:\WINDOWS\system32\xblrxtdj.ini
C:\WINDOWS\system32\xegbmfsu.ini
C:\WINDOWS\system32\xkcijwpu.ini
C:\WINDOWS\system32\xklhbqrb.ini
C:\WINDOWS\system32\xselgklc.ini
C:\WINDOWS\system32\xvinnnma.ini
C:\WINDOWS\system32\ybiqxjlb.ini
C:\WINDOWS\system32\yeegjotj.ini
C:\WINDOWS\system32\yefwqvel.ini
C:\WINDOWS\system32\yinalwin.ini
C:\WINDOWS\system32\yjgkwpus.ini
C:\WINDOWS\system32\yklsenlq.ini
C:\WINDOWS\system32\ymloduej.ini
C:\WINDOWS\system32\ywxxgtrb.ini
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\ymante~1
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CLIENT_IP-IPX
-------\Legacy_DOMAINSERVICE
-------\Legacy_NETWORK_MONITOR
-------\Legacy_NNSERV
-------\Legacy_SYMAVC32
-------\Legacy_XLAVBA8
-------\Service_NNServ
-------\Service_symavc32
-------\Service_xlavba8
((((((((((((((((((((((((( Files Created from 2008-04-26 to 2008-05-26 )))))))))))))))))))))))))))))))
.
2008-05-25 01:41 . 2008-05-25 01:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-25 01:40 . 2008-05-25 13:50 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-25 01:40 . 2008-05-25 01:40 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-25 01:40 . 2008-05-25 01:40 <DIR> d-------- C:\Documents and Settings\Rashid\Application Data\SUPERAntiSpyware.com
2008-05-25 01:33 . 2008-05-25 01:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-25 00:39 . 2008-05-25 00:39 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-25 00:39 . 2008-05-25 00:39 <DIR> d-------- C:\Documents and Settings\Rashid\Application Data\Malwarebytes
2008-05-25 00:39 . 2008-05-25 00:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-25 00:39 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-25 00:39 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-25 00:37 . 2008-05-25 00:37 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-20 00:44 . 2008-05-20 00:46 <DIR> d-------- C:\90c6895b3daf69ced2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-26 23:56 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-26 23:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-05-26 23:33 --------- d-----w C:\Documents and Settings\Rashid\Application Data\ZoomBrowser EX
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-05 21:13 4,184 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-01-17 00:04 88 --sh--r C:\WINDOWS\system32\356C853FB8.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-07 00:05 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-02-24 12:00 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll" [2008-02-07 00:05 349552]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll [2008-02-07 00:05 349552]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ftqgufvk"="C:\WINDOWS\?dobe\m?config.exe" [ ]
"Lmxpx"="C:\Documents and Settings\Rashid\My Documents\?ppPatch\m?config.exe" [ ]
"Aim6"="" []
"Sen"="C:\PROGRA~1\COMMON~1\FNTS~1\winlogon.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-06 21:48 68856]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-06-07 14:08 4670968]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48 32881]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 19:05 1117184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 10:44 81920]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 10:44 249856]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 20:49 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 20:50 114688]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 20:46 77824]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20 122940]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 21:47 51048]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-02-07 02:49 718704]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-16 18:03 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-10 08:53 219136]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 17:18 443968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 05:00 53760 C:\WINDOWS\system32\narrator.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"{9CE85F2C-0AE9-1033-0404-060718200001}"= "C:\Program Files\Common Files\{9CE85F2C-0AE9-1033-0404-060718200001}\Update.exe" mc-110-12-0000627
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\run]
"{9CE85F2C-0AE9-1033-0404-060718200001}"= "C:\Program Files\Common Files\{9CE85F2C-0AE9-1033-0404-060718200001}\Update.exe" mc-110-12-0000627
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljjj]
C:\WINDOWS\system32\mljjj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrqpml]
rqrqpml.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Rashid^Start Menu^Programs^Startup^findfast.exe]
path=C:\Documents and Settings\Rashid\Start Menu\Programs\Startup\findfast.exe
backup=C:\WINDOWS\pss\findfast.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Rashid^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Rashid\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Rashid^Start Menu^Programs^Startup^Think-Adz.lnk]
path=C:\Documents and Settings\Rashid\Start Menu\Programs\Startup\Think-Adz.lnk
backup=C:\WINDOWS\pss\Think-Adz.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
--a------ 2005-07-12 01:17 50776 C:\Program Files\America Online 9.0\AOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
--a------ 2004-10-18 17:42 79448 C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2005-04-18 14:38 71256 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
--a------ 2008-01-08 09:49 579072 C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\clkhost]
C:\WINDOWS\xlaherx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cncfezaz]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\cncfezaz.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dumprep]
C:\WINDOWS\system32\spools.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\froody]
C:\WINDOWS\system32\timoty.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\g4356cbvy63]
C:\WINDOWS\g4356cbvy63
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
C:\Program Files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GPLv3]
C:\WINDOWS\system32\avuouvgd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-05-09 20:24 50760 C:\Program Files\Common Files\AOL\1157199342\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\i34yuc387]
C:\WINDOWS\i34yuc387
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
--a------ 2006-03-27 11:57 126104 C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISMModule4]
C:\Program Files\ISM\ISMModule4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\izabsdyf]
regsvr32 /u C:\Documents and Settings\All Users\Application Data\izabsdyf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsft Windows Adapter 5.1.3013]
C:\Documents and Settings\Rashid\Application Data\ulyj.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ooze view does send]
C:\Documents and Settings\All Users\Application Data\DENT AXIS OOZE VIEW\OnceType.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2007-10-23 17:18 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\poll memo junk ping]
C:\Documents and Settings\All Users\Application Data\16 new ping long\for hole draw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qqwr]
C:\PROGRA~1\COMMON~1\qqwr\qqwrm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-06-16 18:03 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2006-06-16 18:03 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegPowerClean]
C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rlrft]
C:\WINDOWS\?ssembly\s?oolsv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ROAD ITCH AMOK PING]
C:\Documents and Settings\All Users\Application Data\Long slow road itch\Support media.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rtvxtxhg]
C:\WINDOWS\??curity\i?xplore.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6w]
C:\WINDOWS\pvenxs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShareSearcher]
c:\wsusupd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spoolsv]
C:\WINDOWS\system32\spoolvs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\that third]
C:\DOCUME~1\Rashid\APPLIC~1\FILETW~1\linkclose.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Cleaner]
C:\Program Files\Ultimate Cleaner\UltimateCleaner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Defender]
C:\Program Files\Ultimate Defender\UltimateDefender.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Undefined]
C:\WINDOWS\system32\winter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\version]
C:\WINDOWS\system32\timoty.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vknohco]
c:\windows\system32\vknohco.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsService]
C:\WINDOWS\system32\wockrrbk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPop]
C:\Program Files\WinPop\winpop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTouch]
C:\Program Files\WinTouch\WinTouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wkkjrzf]
C:\Documents and Settings\Rashid\My Documents\?ppPatch\?pool32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-06-07 14:08 4670968 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{85-5F-F2-2C-ZN}]
C:\WINDOWS\system32\lmdsrngp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1157199342\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"C:\\Program Files\\Common Files\\AOL\\1157199342\\EE\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1157199342\\EE\\aim6.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msrr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-05-27 00:00:01 C:\WINDOWS\Tasks\B229E45795E688D7.job"
- c:\docume~1\rashid\applic~1\filetw~1\RectOozeTons.exe
"2008-05-26 23:51:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-27 00:01:02 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Rashid.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-26 20:03:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-05-26 20:05:21
ComboFix-quarantined-files.txt 2008-05-27 00:04:14
Pre-Run: 91,938,521,088 bytes free
Post-Run: 91,941,183,488 bytes free
683 --- E O F --- 2008-05-15 19:27:38