Kaspersky log:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, July 17, 2008 4:06:08 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/07/2008
Kaspersky Anti-Virus database records: 963176
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 217861
Number of viruses found: 42
Number of infected objects: 137
Number of suspicious objects: 0
Duration of the scan process: 04:16:22
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\arch22776.jar-68c62f3c-547a31f3.zip/RunString.class Infected: Trojan.Java.ClassLoader.d skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\arch22776.jar-68c62f3c-547a31f3.zip/Parser.class Infected: Trojan.Java.ClassLoader.d skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\arch22776.jar-68c62f3c-547a31f3.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\arch22776.jar-68c62f3c-547a31f3.zip/Colors.class Infected: Trojan-Downloader.Java.OpenStream.b skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\arch22776.jar-68c62f3c-547a31f3.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-11faa9ed-7df0dee9.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-11faa9ed-7df0dee9.zip/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-11faa9ed-7df0dee9.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-11faa9ed-7df0dee9.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-11faa9ed-7df0dee9.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-7eb4d059-3605edf7.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-7eb4d059-3605edf7.zip/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-7eb4d059-3605edf7.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-7eb4d059-3605edf7.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\classload.jar-7eb4d059-3605edf7.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\count.jar-f336957-3d7b3728.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\count.jar-f336957-3d7b3728.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\count.jar-f336957-3d7b3728.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\count.jar-f336957-3d7b3728.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\javainstaller.jar-31f0c089-6c4ae1fe.zip/javainstaller/InstallerApplet.class Infected: Trojan-Downloader.Java.OpenStream.w skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\javainstaller.jar-31f0c089-6c4ae1fe.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\javainstaller.jar-4514e5ea-6ada9779.zip/javainstaller/InstallerApplet.class Infected: Trojan-Downloader.Java.OpenStream.w skipped
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\javainstaller.jar-4514e5ea-6ada9779.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\Jeanne\cert8.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\Jeanne\formhistory.dat Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\Jeanne\history.dat Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\Jeanne\key3.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\Jeanne\parent.lock Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\Jeanne\search.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\Jeanne\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Desktop\other\SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Owner\Desktop\other\SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Owner\Desktop\other\SetupRevelationV2.exe WiseSFX: infected - 2 skipped
C:\Documents and Settings\Owner\Desktop\tmps\43516.exe/WISE0018.BIN Infected: Trojan-Downloader.Win32.Small.bke skipped
C:\Documents and Settings\Owner\Desktop\tmps\43516.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Owner\Desktop\tmps\43516.exe WiseSFX: infected - 2 skipped
C:\Documents and Settings\Owner\Desktop\tmps\43516.exe WiseSFXDropper: infected - 2 skipped
C:\Documents and Settings\Owner\Desktop\tmps\¤p³¾.com/4.sfx.exe/4.exe Infected: Trojan-PSW.Win32.Nilage.bfn skipped
C:\Documents and Settings\Owner\Desktop\tmps\¤p³¾.com/4.sfx.exe Infected: Trojan-PSW.Win32.Nilage.bfn skipped
C:\Documents and Settings\Owner\Desktop\tmps\¤p³¾.com RAR: infected - 2 skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\Jeanne\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\Jeanne\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\Jeanne\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\Jeanne\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012008071720080718\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\My Documents\AIM Logs\shippouchan\SatinCordite\2005-04-28 [Thursday]\RevelationV2.zip/SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Owner\My Documents\AIM Logs\shippouchan\SatinCordite\2005-04-28 [Thursday]\RevelationV2.zip/SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Owner\My Documents\AIM Logs\shippouchan\SatinCordite\2005-04-28 [Thursday]\RevelationV2.zip/SetupRevelationV2.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Documents and Settings\Owner\My Documents\AIM Logs\shippouchan\SatinCordite\2005-04-28 [Thursday]\RevelationV2.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Owner\My Documents\My Music\iTunes\iTunes Library.itl Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\hp\region\EN_US-ie.reg Infected: Trojan.WinREG.StartPage skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\Program Files\SnadBoy's Revelation v2\Revelation.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\Program Files\SnadBoy's Revelation v2\RevelationHelper.dll Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\omuw\omuwa.exe.vir Infected: Trojan-Downloader.Win32.TSUpdate.l skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\omuw\omuwl.exe.vir Infected: Trojan-Downloader.Win32.TSUpdate.r skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\omuw\omuwm.exe.vir Infected: Trojan-Downloader.Win32.TSUpdate.n skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\omuw\omuwp.exe.vir Infected: Trojan-Downloader.Win32.TSUpdate.f skipped
C:\QooBox\Quarantine\C\Program Files\Outerinfo\FF\components\FF.dll.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\QooBox\Quarantine\C\Program Files\YSTEM3~1\rundll.exe.vir Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\QooBox\Quarantine\C\WINDOWS\444.470.vir Infected: Trojan.Win32.DNSChanger.eys skipped
C:\QooBox\Quarantine\C\WINDOWS\lfn.exe.vir Infected: Hoax.Win32.Renos.vajj skipped
C:\QooBox\Quarantine\C\WINDOWS\portsv.exe.vir Infected: Trojan.Win32.Agent.sdd skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ayvsoijf.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.bql skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\botunlcr.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.bql skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\clbdll.dll.vir Infected: Rootkit.Win32.Clbd.ez skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\djiwyg.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.bqh skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\ati1ttxxx.sys.zip/ati1ttxxx.sys Infected: Rootkit.Win32.Agent.aol skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\ati1ttxxx.sys.zip ZIP: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gtazpz.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.bqh skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\imp32\keysrve.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.bp skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\jownw64j.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.bp skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\OBDE\idexpnd.exe.vir Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\olixds01\olixds011065.exe.vir Infected: Trojan-Downloader.Win32.VB.eyc skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\owznmgre.dll.vir Infected: not-a-virus:AdWare.Win32.PurityScan.if skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\provdll\globsetup.exe.vir Infected: Trojan.Win32.DNSChanger.eyr skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\qcntpkdm.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.bv skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\rsgycqew.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.bqh skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\rwwnw64d.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.bp skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\sfig\mcirev2.exe.vir Infected: Trojan.Win32.Agent.lom skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vsnbflfa.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.bqh skipped
C:\SDFix\backups\backups.zip/backups/asappsrv.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\SDFix\backups\backups.zip/backups/b103.exe Infected: not-a-virus:AdWare.Win32.Rond.d skipped
C:\SDFix\backups\backups.zip/backups/b104.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\SDFix\backups\backups.zip/backups/b104.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\SDFix\backups\backups.zip/backups/b104.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\SDFix\backups\backups.zip/backups/b104.exe Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\SDFix\backups\backups.zip/backups/command.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\SDFix\backups\backups.zip/backups/mrofinu1000106.exe Infected: Trojan-Downloader.Win32.Homles.br skipped
C:\SDFix\backups\backups.zip/backups/mrofinu572.exe Infected: Trojan-Downloader.Win32.Homles.br skipped
C:\SDFix\backups\backups.zip/backups/mrofinu572.exe.tmp Infected: Trojan-Downloader.Win32.Homles.br skipped
C:\SDFix\backups\backups.zip/backups/netmon.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\SDFix\backups\backups.zip/backups/rwwnw64d.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bp skipped
C:\SDFix\backups\backups.zip/backups/uoyzsydz.exe Infected: Hoax.Win32.Renos.vajj skipped
C:\SDFix\backups\backups.zip/backups/Yazzle1281OinAdmin.exe Infected: Trojan.Win32.Scapur.k skipped
C:\SDFix\backups\backups.zip/backups/Yazzle1281OinUninstaller.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\SDFix\backups\backups.zip/backups/Yazzle1281OinUninstaller.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\SDFix\backups\backups.zip/backups/yazzsnet.exe/data0003 Infected: Trojan.Win32.Scapur.k skipped
C:\SDFix\backups\backups.zip/backups/yazzsnet.exe Infected: Trojan.Win32.Scapur.k skipped
C:\SDFix\backups\backups.zip ZIP: infected - 18 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP42\A0006568.exe Infected: Trojan-Downloader.Win32.Homles.br skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP43\A0006570.exe Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP43\A0007527.exe Infected: Trojan-Downloader.Win32.TSUpdate.n skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP43\A0007528.exe Infected: Trojan-Downloader.Win32.TSUpdate.l skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP43\snapshot\MFEX-1.DAT Infected: Trojan-Downloader.Win32.TSUpdate.n skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP43\snapshot\MFEX-2.DAT Infected: Trojan-Downloader.Win32.TSUpdate.l skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008742.exe Infected: not-a-virus:AdWare.Win32.PurityScan.id skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008744.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008754.dll Infected: not-a-virus:AdWare.Win32.PurityScan.if skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008811.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008812.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008814.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008815.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008815.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008818.exe Infected: not-a-virus:AdWare.Win32.Rond.d skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008819.exe/stream/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008819.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008819.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008819.exe NSIS: infected - 3 skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008820.exe Infected: Trojan-Downloader.Win32.Homles.br skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008821.exe Infected: Trojan-Downloader.Win32.Homles.br skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008822.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008867.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bp skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP44\A0008868.exe Infected: Hoax.Win32.Renos.vajj skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011136.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011137.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011142.exe Infected: Hoax.Win32.Renos.vajj skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011143.dll Infected: Rootkit.Win32.Clbd.ez skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011145.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bp skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011147.exe Infected: Trojan.Win32.Agent.sdd skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011148.exe Infected: not-a-virus:AdWare.Win32.PurityScan.id skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011152.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bv skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011153.dll Infected: not-a-virus:AdWare.Win32.PurityScan.if skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011154.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bql skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011155.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bql skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011157.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bqh skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011159.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bqh skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011162.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bqh skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011163.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bqh skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011172.exe Infected: Trojan-Downloader.Win32.TSUpdate.l skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011174.exe Infected: Trojan-Downloader.Win32.TSUpdate.r skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011176.exe Infected: Trojan-Downloader.Win32.TSUpdate.n skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP47\A0011177.exe Infected: Trojan-Downloader.Win32.TSUpdate.f skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP48\A0011300.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bp skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP48\A0011301.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP48\A0011302.exe Infected: Trojan-Downloader.Win32.VB.eyc skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP48\A0011303.exe Infected: Trojan.Win32.DNSChanger.eyr skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP48\A0011304.exe Infected: Trojan.Win32.Agent.lom skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP48\A0011307.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bp skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP48\A0011316.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bp skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP48\A0011324.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bv skipped
C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP50\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\RTacDbg.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{80E736D4-E08D-40B8-A6E5-2DF5278E2E9A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP50\change.log Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP50\change.log Object is locked skipped
Scan process completed.
ComboFix log:
ComboFix 08-07-14.2 - Owner 2008-07-17 0:20:38.11 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.221 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\iphone-011.ico
C:\WINDOWS\system32\Jamster.ico
C:\WINDOWS\system32\pinkip.ico
C:\WINDOWS\system32\vnmgirkpzh.dll
C:\WINDOWS\system32\vnmgirkpzh.dll-uninst.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\iphone-011.ico
C:\WINDOWS\system32\Jamster.ico
C:\WINDOWS\system32\pinkip.ico
C:\WINDOWS\system32\vnmgirkpzh.dll-uninst.exe
C:\WINDOWS\system32\vnmgirkpzh.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-17 to 2008-07-17 )))))))))))))))))))))))))))))))
.
2008-07-14 21:15 . 2008-07-15 13:16 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-14 21:15 . 2008-07-14 21:15 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-14 09:31 . 2008-07-14 09:31 <DIR> d-------- C:\Deckard
2008-07-13 10:42 . 2008-07-13 10:42 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-13 10:36 . 2008-07-13 17:37 <DIR> d-------- C:\SDFix
2008-07-13 01:43 . 2008-07-13 01:43 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-12 00:36 . 2003-04-10 07:05 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-07-12 00:36 . 2003-04-10 06:50 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-07-12 00:36 . 2003-04-10 06:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-07-12 00:36 . 2003-04-10 07:08 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-07-12 00:36 . 2003-04-10 06:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-07-12 00:36 . 2003-04-10 06:53 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2008-07-12 00:36 . 2008-07-12 00:36 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-11 23:55 . 2008-07-11 23:55 <DIR> d-------- C:\VundoFix Backups
2008-07-11 23:00 . 2008-07-11 23:00 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-07-11 22:49 . 2002-08-29 08:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-06-30 17:38 . 2007-05-04 20:40 215,040 --a------ C:\WINDOWS\system32\drivers\RTL8187B.sys
2008-06-30 17:37 . 2008-06-30 17:37 <DIR> d-------- C:\WINDOWS\OPTIONS
2008-06-30 17:37 . 2008-06-30 17:37 <DIR> d-------- C:\Program Files\TRENDnet
2008-06-20 06:44 . 2008-06-20 06:44 138,368 --a--c--- C:\WINDOWS\system32\dllcache\afd.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 04:28 --------- d-----w C:\Documents and Settings\Owner\Application Data\DNA
2008-07-17 04:28 --------- d-----w C:\Documents and Settings\Owner\Application Data\BitTorrent
2008-07-14 21:30 --------- d-----w C:\Program Files\STOPzilla!
2008-07-14 21:30 --------- d-----w C:\Program Files\Common Files\STOPzilla!
2008-07-12 03:01 --------- d-----w C:\Program Files\Starcraft
2008-07-01 03:26 --------- d-----w C:\Documents and Settings\Owner\Application Data\Aim
2008-06-30 21:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:04 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2007-01-29 01:41 88,592 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2003-04-10 10:51 32 --sha-w C:\WINDOWS\{DA550BF1-5AE0-4007-B9B0-C9FF520E8090}.dat
2004-09-06 18:13 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys
2003-04-10 10:51 32 --sha-w C:\WINDOWS\system32\{1BADA6CB-9766-4CB8-9EA3-38879756A4DF}.dat
.
((((((((((((((((((((((((((((( snapshot@2008-07-14_21.31.47.32 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-14 22:34:33 32,648 ----a-w C:\WINDOWS\system32\tablet.dat
+ 2008-07-15 17:08:28 32,648 ----a-w C:\WINDOWS\system32\tablet.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ztlbqu"="C:\Program Files\Common Files\a?sembly\c?rss.exe" [?]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-09 19:17 289088]
"AIM"="C:\Program Files\AIM\aim.exe" [2003-08-01 11:31 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 16:51 118784]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 00:42 212992]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-12-02 17:11 54296]
"ccRegVfy"="c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2003-12-02 17:11 58392]
"QuickFinder Scheduler"="C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE" [2001-10-01 21:36 77887]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-05-22 01:28 188416]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 01:31 208952]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2002-08-29 08:00 59392]
"DeadAIM"="C:\Program Files\AIM\\DeadAIM.ocm" [2003-02-24 17:11 266313]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 15:54 241664]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 16:55 155648]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE" [2003-05-26 16:00 99840]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-02-05 22:13 95960]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11 49152]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 17:44 61440]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 11:01 155648]
"{bca9887c-d68a-b6f9-f7eb-a55adcefdbe6}"="C:\WINDOWS\system32\dpzzjbtqctxxm.dll" [BU]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 14:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Deewoo.lnk - C:\QooBox\Quarantine\C\WINDOWS\system32\qcntpkdm.exe.vir [2008-07-14 21:27:06 192580]
DW_Start.lnk - C:\QooBox\Quarantine\C\WINDOWS\system32\rwwnw64d.exe.vir [2008-07-14 21:14:54 49199]
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [2003-04-10 06:53:45 552960]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-08-27 23:04:27 110592]
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2004-09-20 13:31:48 1466384]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 05:19:24 237568]
Photo Loader supervisory.lnk - C:\Program Files\CASIO\Photo Loader\Plauto.exe [2007-10-05 23:27:50 229376]
Planex Wireless Utility.lnk - C:\Program Files\Planex\Common\RaUI.exe [2007-08-26 21:56:14 688128]
TabUserW.exe.lnk - C:\WINDOWS\system32\WTablet\TabUserW.exe [2005-04-28 22:06:59 114688]
Wireless Configuration Utility HW.14.lnk - C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe [2007-07-09 15:43:00 634880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 06:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 00:34 24576 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i263_32.drv
"vidc.XVID"= xvid.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= msaud32_divx.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Semagic.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Semagic.lnk
backup=C:\WINDOWS\pss\Semagic.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
--a--c--- 2002-01-23 10:20 675840 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
--a------ 2003-08-01 11:31 61440 C:\Program Files\AIM\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2005-01-29 17:32 12598440 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra--c--- 2005-08-09 20:14 155648 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\mshta.exe"=
"C:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\DC++\\DCPlusPlus.exe"=
"C:\\Documents and Settings\\Owner\\Desktop\\tmps\\PDMan%5FClient13.exe"=
"C:\\WINDOWS\\system32\\fscagent.exe"=
"C:\\WINDOWS\\system32\\clubbox.exe"=
"C:\\ijji\\ENGLISH\\Gunbound Revolution\\GunBound.gme"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 NPPTNT;NPPTNT;C:\WINDOWS\System32\npptNT.sys [2003-07-22 02:14]
R3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-05-04 20:40]
R3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-02 09:57]
S3 w600bus;Sony Ericsson W600 driver (WDM);C:\WINDOWS\system32\DRIVERS\w600bus.sys [2005-08-15 17:04]
S3 w600mdfl;Sony Ericsson W600 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w600mdfl.sys [2005-08-15 17:04]
S3 w600mdm;Sony Ericsson W600 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\w600mdm.sys [2005-08-15 17:04]
S3 w600mgmt;Sony Ericsson W600 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\w600mgmt.sys [2005-08-15 17:04]
S3 w600obex;Sony Ericsson W600 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\w600obex.sys [2005-08-15 17:04]
*Newly Created Service* - CATCHME
*Newly Created Service* - SJYPKT
.
Contents of the 'Scheduled Tasks' folder
"2008-07-14 23:42:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2003-08-26 00:36:56 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-17 00:28:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll
.
Completion time: 2008-07-17 0:39:50
ComboFix-quarantined-files.txt 2008-07-17 04:39:26
ComboFix2.txt 2008-07-15 17:29:36
ComboFix3.txt 2008-07-15 01:32:29
ComboFix4.txt 2008-04-27 14:59:22
Pre-Run: 7,214,583,808 bytes free
Post-Run: 7,200,256,000 bytes free
206 --- E O F --- 2008-07-09 23:36:31
Thanks. ^__^v