Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

addware and trojans [CLOSED]


  • This topic is locked This topic is locked

#1
SatanicSarahX

SatanicSarahX

    Member

  • Member
  • PipPip
  • 85 posts
well i posted a topic ages ago but it wasnt reaplyed sorry if i did something wrong

but here i am again except now its 1000 times worse

pc shuts down

pop ups

slow peformance

lots or errors

kaspersky anitvirus isnt working due to it




here is a hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:10:12 AM, on 23/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\NASDAK\OmniMouse Driver\4.0\MOUSE32A.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\mrofinu.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\1RcNmqyH.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: mysidesearch search enhancer - {6d7d80ab-7333-21e7-82ba-bed96a50c916} - C:\WINDOWS\system32\dbkxksakiuslmbp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: targetedbanner browser optimizer - {e7c69d52-3002-87ea-8b20-0518188f2aa1} - C:\WINDOWS\system32\rsxuwzxjfdqxlrln.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\NASDAK\OmniMouse Driver\4.0\MOUSE32A.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [{FB-B1-1B-B8-DW}] C:\windows\system32\rwwnw64d.exe DWram02
O4 - HKLM\..\Run: [{6c6127e4-db02-537e-1ec6-29eaafb13c40}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\rsxuwzxjfdqxlrln.dll" DllStart
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PSwitch] C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Deewoo.lnk = ? (User 'SYSTEM')
O4 - S-1-5-18 Startup: DW_Start.lnk = C:\WINDOWS\system32\rqwnw64s.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: Deewoo.lnk = ? (User 'Default user')
O4 - .DEFAULT Startup: DW_Start.lnk = C:\WINDOWS\system32\rqwnw64s.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Deewoo.lnk = ?
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\rqwnw64s.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1215069195210
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.su...ows-i586-jc.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: khfEWMgh - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe

--
End of file - 8741 bytes





and

here is the virus scan i cant complete it all
beacuse it shuts down my pc



Malwarebytes' Anti-Malware 1.22
Database version: 978
Windows 5.1.2600 Service Pack 2

12:09:50 AM 23/07/2008
mbam-log-7-23-2008 (00-09-50).txt

Scan type: Full Scan (C:\|)
Objects scanned: 14341
Time elapsed: 4 minute(s), 14 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
c:\WINDOWS\system32\rqwnw64s.exe (Adware.Agent) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1e404d48-670a-4085-a6a0-d195793ddd33} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9f593aac-ca4c-4a41-a7ff-a00812192d61} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{749ec66f-a838-4b38-b8e5-e65d905fff74} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1e404d48-670a-4085-a6a0-d195793ddd33} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{dd4a65c7-61d7-445f-bcf1-5065f765eaf9} (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{dd4a65c7-61d7-445f-bcf1-5065f765eaf9} (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\rqwnw64s.exe (Adware.Agent) -> Quarantined and deleted successfully.
  • 0

Advertisements


#2
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello SatanicSarahX,

Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingc...to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
  • 0

#3
SatanicSarahX

SatanicSarahX

    Member

  • Topic Starter
  • Member
  • PipPip
  • 85 posts
here it is hope i did it right







ComboFix 08-07-21.2 - Sarah 2008-07-23 0:41:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.568 [GMT 10:00]
Running from: C:\Documents and Settings\Sarah\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\Deewoo.lnk
C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\DW_Start.lnk
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\mrofinu.exe
C:\WINDOWS\system32\_000110_.tmp.dll
C:\WINDOWS\system32\CMMGR32.EXE
C:\WINDOWS\system32\gside.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rsxuwzxjfdqxlrln.dll
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\system32\zxdnt3d.cfg

.
((((((((((((((((((((((((( Files Created from 2008-06-22 to 2008-07-22 )))))))))))))))))))))))))))))))
.

2008-07-23 00:46 . 2008-07-23 00:46 16,128,512 --a------ C:\WINDOWS\RTHDCPL.exe.kav
2008-07-23 00:46 . 2008-07-23 00:46 388,608 --a------ C:\WINDOWS\system32\CF3696.exe.kav
2008-07-23 00:46 . 2008-07-23 00:46 289,792 --a------ C:\WINDOWS\system32\vssvc.exe.kav
2008-07-23 00:37 . 2008-07-23 00:46 388,608 --a------ C:\WINDOWS\system32\CF3232.exe
2008-07-22 23:55 . 2008-07-23 00:46 920 --ahs---- C:\WINDOWS\klif.spi
2008-07-22 23:20 . 2008-07-22 23:20 152,159 --a------ C:\WINDOWS\system32\g0.exe
2008-07-22 23:06 . 2008-07-20 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-22 22:26 . 2008-07-22 22:26 90,922 --a------ C:\WINDOWS\system32\dbkxksakiuslmbp.dll-uninst.exe
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\wnet
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\vdf1
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\confg
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\carH04
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\Temp\btxv15
2008-07-22 22:19 . 2008-07-23 00:41 <DIR> d-------- C:\Temp
2008-07-22 22:19 . 2008-07-22 22:19 64,841 --a------ C:\WINDOWS\system32\entaddmlggaoim.exe
2008-07-22 19:40 . 2008-07-22 21:45 82,434 --a------ C:\WINDOWS\system32\1RcNmqyH.exe
2008-07-22 00:02 . 2008-07-22 00:21 <DIR> d-------- C:\Program Files\Proxy Switcher Standard
2008-07-20 22:42 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-07-20 22:42 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-07-20 13:35 . 2008-07-20 13:35 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\WNR
2008-07-15 07:30 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-07-15 07:30 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-07-15 07:26 . 2004-06-15 15:00 116,736 --a------ C:\WINDOWS\system32\CNMLM61.DLL
2008-07-15 07:26 . 2004-06-15 15:00 7,680 --a------ C:\WINDOWS\system32\CNMVS61.DLL
2008-07-15 07:25 . 2004-06-05 01:34 86,016 -ra------ C:\WINDOWS\system32\CNMCP61.exe
2008-07-15 07:23 . 2008-07-15 07:23 <DIR> d--h----- C:\BJPrinter
2008-07-11 09:26 . 2008-07-11 09:26 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-07-11 09:26 . 2008-07-11 09:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-07-11 03:50 . 2008-07-22 00:42 <DIR> d-------- C:\Program Files\uTorrent
2008-07-11 03:50 . 2008-07-22 00:28 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\uTorrent
2008-07-08 15:59 . 2008-07-19 17:39 <DIR> d-------- C:\Program Files\Cheat Engine
2008-07-08 15:59 . 2007-12-26 17:30 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2008-07-08 15:59 . 2007-12-26 17:30 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
2008-07-08 14:18 . 2008-07-11 03:42 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Hamachi
2008-07-08 14:17 . 2008-07-08 14:18 <DIR> d-------- C:\Program Files\Hamachi
2008-07-08 14:17 . 2008-07-08 14:17 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2008-07-08 13:10 . 2008-07-21 15:45 19,456 --a------ C:\WINDOWS\system32\h0Y2JNV8.dll
2008-07-08 12:58 . 2008-07-08 12:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-07-08 12:56 . 2004-08-04 00:56 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-07-08 12:56 . 2004-08-04 00:56 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax
2008-07-08 12:56 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-07-08 12:56 . 2004-08-03 23:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
2008-07-08 12:56 . 2004-08-03 23:10 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2008-07-08 12:56 . 2004-08-03 23:10 11,136 --a--c--- C:\WINDOWS\system32\dllcache\slip.sys
2008-07-08 12:56 . 2004-08-03 23:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-07-08 12:56 . 2004-08-03 23:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-07-08 12:55 . 2008-07-08 12:55 <DIR> d-------- C:\Program Files\IVT Corporation
2008-07-08 12:54 . 2008-07-08 12:54 <DIR> d-------- C:\Program Files\NCH Software
2008-07-08 12:52 . 2004-08-04 00:56 152,576 --a------ C:\WINDOWS\system32\irftp.exe
2008-07-08 12:51 . 2008-07-08 12:51 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-07-08 12:51 . 2008-07-08 12:51 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\NCH Swift Sound
2008-07-07 00:26 . 2008-07-07 00:26 <DIR> d-------- C:\Program Files\Netropa
2008-07-07 00:26 . 2000-06-08 03:09 28,672 --a------ C:\WINDOWS\system32\msiosd32.dll
2008-07-07 00:26 . 2001-12-20 10:02 6,656 --a------ C:\WINDOWS\system32\drivers\Msikbd2k.sys
2008-07-07 00:26 . 2008-07-23 00:47 245 --a------ C:\WINDOWS\MSIOSD.INI
2008-07-07 00:26 . 2008-07-07 00:26 0 --a------ C:\WINDOWS\WININIT.INI
2008-07-07 00:25 . 2008-07-07 00:25 <DIR> d-------- C:\Program Files\NASDAK
2008-07-07 00:25 . 2000-05-10 15:29 6,205 --a------ C:\WINDOWS\system32\LWBHMVXD.VXD
2008-07-07 00:00 . 2008-07-07 00:00 <DIR> d--h----- C:\WINDOWS\PIF
2008-07-06 23:43 . 2008-07-06 23:43 <DIR> d-------- C:\Program Files\COMODO
2008-07-06 23:43 . 2008-07-06 23:43 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Comodo
2008-07-06 23:43 . 2008-07-08 12:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-07-06 23:43 . 2008-07-06 23:43 143,104 --a------ C:\WINDOWS\system32\guard32.dll
2008-07-06 23:43 . 2008-07-06 23:43 87,056 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-07-06 23:43 . 2008-07-06 23:43 24,208 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-07-06 23:34 . 2008-07-06 23:34 <DIR> d-------- C:\Program Files\BigPond
2008-07-06 22:43 . 2008-07-11 21:34 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-07-06 22:43 . 2008-07-11 21:34 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-07-06 22:42 . 2008-07-06 22:42 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-07-06 22:42 . 2008-07-23 00:46 2,275,872 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-06 22:42 . 2008-07-23 00:47 483,360 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-06 22:42 . 2008-07-23 00:46 19,908 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-06 22:42 . 2008-07-23 00:46 3,780 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-06 22:40 . 2008-07-06 22:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-06 19:12 . 2008-07-20 17:28 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\LimeWire
2008-07-06 14:21 . 2008-07-06 14:21 <DIR> d-------- C:\WINDOWS\Sun
2008-07-06 14:16 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-06 14:15 . 2008-07-06 14:16 <DIR> d-------- C:\Program Files\Java
2008-07-06 14:13 . 2008-07-06 14:13 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-06 14:11 . 2008-07-12 19:42 <DIR> d-------- C:\Program Files\LimeWire
2008-07-05 17:13 . 2008-04-23 14:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-07-05 17:13 . 2007-04-17 19:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-07-05 17:13 . 2007-03-08 15:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-07-05 17:13 . 2008-04-23 14:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-07-05 17:13 . 2008-04-23 14:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-07-05 17:13 . 2008-04-23 14:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-07-05 17:13 . 2008-04-23 14:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-07-05 17:13 . 2008-04-23 14:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-07-05 17:13 . 2008-04-22 17:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-07-05 14:20 . 2008-07-05 14:20 0 --a------ C:\WINDOWS\system32\1RcNmqyH.exe.a_a
2008-07-05 11:31 . 2008-07-13 22:40 <DIR> d-------- C:\Documents and Settings\Sarah\Contacts
2008-07-05 11:15 . 2008-07-05 11:15 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-07-05 11:03 . 2008-07-05 16:45 <DIR> d-------- C:\WINDOWS\ie8updates
2008-07-05 10:42 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-05 10:42 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-07-05 10:42 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-05 10:40 . 2008-07-05 10:40 268 --ah----- C:\sqmdata01.sqm
2008-07-05 10:40 . 2008-07-05 10:40 244 --ah----- C:\sqmnoopt01.sqm
2008-07-05 02:37 . 2008-07-05 02:37 268 --ah----- C:\sqmdata00.sqm
2008-07-05 02:37 . 2008-07-05 02:37 244 --ah----- C:\sqmnoopt00.sqm
2008-07-05 02:32 . 2008-07-05 02:35 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-05 02:31 . 2008-07-05 02:36 <DIR> d-------- C:\Program Files\Windows Live
2008-07-05 02:31 . 2008-07-05 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-04 00:45 . 2008-07-04 00:45 364,544 --a------ C:\WINDOWS\system32\dbkxksakiuslmbp.dll
2008-07-04 00:11 . 2008-07-04 00:11 <DIR> d-------- C:\Deckard
2008-07-03 22:20 . 2008-07-03 22:20 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-07-03 22:20 . 2008-07-23 00:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-03 19:42 . 2008-07-20 05:31 <DIR> d-------- C:\Program Files\Paint Shop Pro 6
2008-07-03 19:42 . 1999-08-13 06:00 317,952 --a------ C:\WINDOWS\system32\Roboex32.dll
2008-07-03 19:42 . 1999-06-23 11:46 54,272 --a------ C:\WINDOWS\system32\Serial.ocx
2008-07-03 19:42 . 1999-06-23 11:46 53,760 --a------ C:\WINDOWS\system32\Infrared.ocx
2008-07-03 19:42 . 1999-06-23 11:46 51,712 --a------ C:\WINDOWS\system32\USB.ocx
2008-07-03 19:42 . 1999-08-13 06:00 47,104 --a------ C:\WINDOWS\system32\Wh2Robo.dll
2008-07-03 18:30 . 2008-06-13 23:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-07-03 18:30 . 2008-06-13 23:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-03 18:21 . 2008-07-03 18:21 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-03 18:19 . 2008-07-06 14:06 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-03 18:19 . 2008-07-03 18:19 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-03 18:19 . 2008-07-03 18:19 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\SUPERAntiSpyware.com
2008-07-03 18:19 . 2008-07-03 18:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-03 18:18 . 2008-07-22 23:07 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Malwarebytes
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-03 18:18 . 2008-07-20 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-10 23:28 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-06 14:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-06 14:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-03 06:45 --------- d-----w C:\Program Files\Intel
2008-07-03 06:41 --------- d-----w C:\Program Files\Realtek
2008-07-03 06:40 327,680 ----a-w C:\WINDOWS\HideWin.exe
2008-07-03 06:31 --------- d-----w C:\Program Files\microsoft frontpage
.

------- Sigcheck -------

2008-04-14 10:12 26112 80e366761caa8338bc2f4056780d6765 C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ctfmon.exe
2004-08-04 22:00 26112 67d7c7e1cc9979d54d063c1a67858d38 C:\WINDOWS\system32\ctfmon.exe
2004-08-04 22:00 26112 93f965ab17e83f1284147f0c4e724612 C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6d7d80ab-7333-21e7-82ba-bed96a50c916}]
2008-07-04 00:45 364544 --a------ C:\WINDOWS\system32\dbkxksakiuslmbp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 22:00 26112]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"PSwitch"="C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe" [2008-07-23 00:46 1303552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-05 23:11 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-05 23:13 159744]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-05 23:10 204800]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"LWBMOUSE"="C:\Program Files\NASDAK\OmniMouse Driver\4.0\MOUSE32A.EXE" [2001-11-09 16:47 399872]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2003-06-04 01:32 163840]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 18:21 201992]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 17:28 16139264 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-04 19:22 1835008 C:\WINDOWS\SkyTel.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 22:00 110592 C:\WINDOWS\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 22:00 26112]

C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-07-06 14:06 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-06 14:06 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^Sarah^Start Menu^Programs^Startup^hamachi.lnk]
path=C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\hamachi.lnk
backup=C:\WINDOWS\pss\hamachi.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]
--a------ 2008-07-06 23:43 1655552 C:\Program Files\COMODO\Firewall\cfp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-07-22 23:56 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2008-07-06 14:06 1518832 C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Hamachi\\hamachi.exe"=
"C:\\Program Files\\Proxy Switcher Standard\\ProxySwitcher.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-07-06 23:43]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-07-06 23:43]
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 10:02]
R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 07:41]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [2007-07-03 20:33]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 20:07]
S3 DBKDRVR54;DBKDRVR54;C:\Program Files\Cheat Engine\dbk32.sys [2007-12-27 05:45]
.
Contents of the 'Scheduled Tasks' folder
"2008-07-22 14:37:01 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 23:00:01 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 00:00:01 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 01:00:01 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 02:00:01 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 03:00:01 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 04:00:02 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 05:00:01 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 06:00:02 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 07:00:02 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 08:00:02 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 15:00:02 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 09:00:01 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 10:00:01 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 11:00:02 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 12:00:02 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 13:00:02 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 14:46:07 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 15:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 16:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 17:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 18:00:00 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 16:00:03 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 19:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\1RcNmqyH.exe

"2008-07-21 20:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 21:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 22:00:00 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 23:00:00 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 00:00:00 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 01:00:00 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 02:00:00 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 03:00:00 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 04:00:00 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 17:00:02 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 05:00:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 06:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 07:00:00 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 08:00:00 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 09:00:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 10:00:10 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 11:00:10 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 12:00:10 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 13:54:48 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 18:00:01 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 19:00:01 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 20:00:01 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 21:00:03 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 22:00:02 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-{FB-B1-1B-B8-DW} - C:\windows\system32\rwwnw64d.exe
HKLM-Run-{6c6127e4-db02-537e-1ec6-29eaafb13c40} - C:\WINDOWS\system32\rsxuwzxjfdqxlrln.dll
Notify-khfEWMgh - (no file)


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-23 00:47:06
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\scardsvr.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\vssvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\carH04\carH041066.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-07-23 0:52:04 - machine was rebooted [Sarah]
ComboFix-quarantined-files.txt 2008-07-22 14:51:52

Pre-Run: 55,443,345,408 bytes free
Post-Run: 56,309,817,344 bytes free

376 --- E O F --- 2008-07-06 00:51:12
  • 0

#4
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello SatanicSarahX

. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

::File

C:\WINDOWS\RTHDCPL.exe.kav
C:\WINDOWS\system32\CF3696.exe.kav
C:\WINDOWS\system32\vssvc.exe.kav
C:\WINDOWS\system32\CF3232.exe
C:\WINDOWS\system32\g0.exe
C:\WINDOWS\system32\dbkxksakiuslmbp.dll-uninst.exe
C:\WINDOWS\system32\entaddmlggaoim.exe
C:\WINDOWS\system32\1RcNmqyH.exe
C:\WINDOWS\system32\h0Y2JNV8.dll
C:\WINDOWS\system32\1RcNmqyH.exe.a_a
C:\WINDOWS\system32\dbkxksakiuslmbp.dll
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
C:\WINDOWS\Tasks\At49.job
C:\WINDOWS\system32\3Tj00v3Q.exe
C:\WINDOWS\system32\1RcNmqyH.exe


::Folder

C:\WINDOWS\system32\carH04
C:\Temp\btxv15

::DirLook

C:\WINDOWS\system32\wnet
C:\WINDOWS\system32\vdf1



3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Thunderbird1988
  • 0

#5
SatanicSarahX

SatanicSarahX

    Member

  • Topic Starter
  • Member
  • PipPip
  • 85 posts
ComboFix 08-07-21.2 - Sarah 2008-07-23 9:51:30.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.512 [GMT 10:00]
Running from: C:\Documents and Settings\Sarah\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Sarah\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\pac.txt

.
((((((((((((((((((((((((( Files Created from 2008-06-22 to 2008-07-22 )))))))))))))))))))))))))))))))
.

2008-07-23 00:46 . 2008-07-23 00:46 16,128,512 --a------ C:\WINDOWS\RTHDCPL.exe.kav
2008-07-23 00:46 . 2008-07-23 00:46 388,608 --a------ C:\WINDOWS\system32\CF3696.exe.kav
2008-07-23 00:46 . 2008-07-23 00:46 289,792 --a------ C:\WINDOWS\system32\vssvc.exe.kav
2008-07-22 23:55 . 2008-07-23 09:50 1,080 --ahs---- C:\WINDOWS\klif.spi
2008-07-22 23:20 . 2008-07-22 23:20 152,159 --a------ C:\WINDOWS\system32\g0.exe
2008-07-22 23:06 . 2008-07-20 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-22 22:26 . 2008-07-22 22:26 90,922 --a------ C:\WINDOWS\system32\dbkxksakiuslmbp.dll-uninst.exe
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\wnet
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\vdf1
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\confg
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\carH04
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\Temp\btxv15
2008-07-22 22:19 . 2008-07-23 00:41 <DIR> d-------- C:\Temp
2008-07-22 22:19 . 2008-07-22 22:19 64,841 --a------ C:\WINDOWS\system32\entaddmlggaoim.exe
2008-07-22 19:40 . 2008-07-23 01:00 38,912 --a------ C:\WINDOWS\system32\1RcNmqyH.exe
2008-07-22 00:02 . 2008-07-22 00:21 <DIR> d-------- C:\Program Files\Proxy Switcher Standard
2008-07-20 22:42 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-07-20 22:42 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-07-20 13:35 . 2008-07-20 13:35 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\WNR
2008-07-15 07:30 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-07-15 07:30 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-07-15 07:26 . 2004-06-15 15:00 116,736 --a------ C:\WINDOWS\system32\CNMLM61.DLL
2008-07-15 07:26 . 2004-06-15 15:00 7,680 --a------ C:\WINDOWS\system32\CNMVS61.DLL
2008-07-15 07:25 . 2004-06-05 01:34 86,016 -ra------ C:\WINDOWS\system32\CNMCP61.exe
2008-07-15 07:23 . 2008-07-15 07:23 <DIR> d--h----- C:\BJPrinter
2008-07-11 09:26 . 2008-07-11 09:26 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-07-11 09:26 . 2008-07-11 09:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-07-11 03:50 . 2008-07-22 00:42 <DIR> d-------- C:\Program Files\uTorrent
2008-07-11 03:50 . 2008-07-22 00:28 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\uTorrent
2008-07-08 15:59 . 2008-07-19 17:39 <DIR> d-------- C:\Program Files\Cheat Engine
2008-07-08 15:59 . 2007-12-26 17:30 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2008-07-08 15:59 . 2007-12-26 17:30 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
2008-07-08 14:18 . 2008-07-11 03:42 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Hamachi
2008-07-08 14:17 . 2008-07-08 14:18 <DIR> d-------- C:\Program Files\Hamachi
2008-07-08 14:17 . 2008-07-08 14:17 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2008-07-08 13:10 . 2008-07-21 15:45 19,456 --a------ C:\WINDOWS\system32\h0Y2JNV8.dll
2008-07-08 12:58 . 2008-07-08 12:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-07-08 12:56 . 2004-08-04 00:56 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-07-08 12:56 . 2004-08-04 00:56 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax
2008-07-08 12:56 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-07-08 12:56 . 2004-08-03 23:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
2008-07-08 12:56 . 2004-08-03 23:10 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2008-07-08 12:56 . 2004-08-03 23:10 11,136 --a--c--- C:\WINDOWS\system32\dllcache\slip.sys
2008-07-08 12:56 . 2004-08-03 23:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-07-08 12:56 . 2004-08-03 23:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-07-08 12:55 . 2008-07-08 12:55 <DIR> d-------- C:\Program Files\IVT Corporation
2008-07-08 12:54 . 2008-07-08 12:54 <DIR> d-------- C:\Program Files\NCH Software
2008-07-08 12:52 . 2004-08-04 00:56 152,576 --a------ C:\WINDOWS\system32\irftp.exe
2008-07-08 12:51 . 2008-07-08 12:51 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-07-08 12:51 . 2008-07-08 12:51 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\NCH Swift Sound
2008-07-07 00:26 . 2008-07-07 00:26 <DIR> d-------- C:\Program Files\Netropa
2008-07-07 00:26 . 2000-06-08 03:09 28,672 --a------ C:\WINDOWS\system32\msiosd32.dll
2008-07-07 00:26 . 2001-12-20 10:02 6,656 --a------ C:\WINDOWS\system32\drivers\Msikbd2k.sys
2008-07-07 00:26 . 2008-07-23 09:52 245 --a------ C:\WINDOWS\MSIOSD.INI
2008-07-07 00:26 . 2008-07-07 00:26 0 --a------ C:\WINDOWS\WININIT.INI
2008-07-07 00:25 . 2008-07-07 00:25 <DIR> d-------- C:\Program Files\NASDAK
2008-07-07 00:25 . 2000-05-10 15:29 6,205 --a------ C:\WINDOWS\system32\LWBHMVXD.VXD
2008-07-07 00:00 . 2008-07-07 00:00 <DIR> d--h----- C:\WINDOWS\PIF
2008-07-06 23:43 . 2008-07-06 23:43 <DIR> d-------- C:\Program Files\COMODO
2008-07-06 23:43 . 2008-07-06 23:43 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Comodo
2008-07-06 23:43 . 2008-07-08 12:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-07-06 23:43 . 2008-07-06 23:43 143,104 --a------ C:\WINDOWS\system32\guard32.dll
2008-07-06 23:43 . 2008-07-06 23:43 87,056 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-07-06 23:43 . 2008-07-06 23:43 24,208 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-07-06 23:34 . 2008-07-06 23:34 <DIR> d-------- C:\Program Files\BigPond
2008-07-06 22:43 . 2008-07-11 21:34 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-07-06 22:43 . 2008-07-11 21:34 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-07-06 22:42 . 2008-07-06 22:42 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-07-06 22:42 . 2008-07-23 00:56 2,283,040 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-06 22:42 . 2008-07-23 09:52 507,936 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-06 22:42 . 2008-07-23 00:56 19,964 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-06 22:42 . 2008-07-23 09:52 3,864 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-06 22:40 . 2008-07-06 22:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-06 19:12 . 2008-07-20 17:28 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\LimeWire
2008-07-06 14:21 . 2008-07-06 14:21 <DIR> d-------- C:\WINDOWS\Sun
2008-07-06 14:16 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-06 14:15 . 2008-07-06 14:16 <DIR> d-------- C:\Program Files\Java
2008-07-06 14:13 . 2008-07-06 14:13 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-06 14:11 . 2008-07-12 19:42 <DIR> d-------- C:\Program Files\LimeWire
2008-07-05 17:13 . 2008-04-23 14:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-07-05 17:13 . 2007-04-17 19:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-07-05 17:13 . 2007-03-08 15:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-07-05 17:13 . 2008-04-23 14:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-07-05 17:13 . 2008-04-23 14:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-07-05 17:13 . 2008-04-23 14:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-07-05 17:13 . 2008-04-23 14:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-07-05 17:13 . 2008-04-23 14:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-07-05 17:13 . 2008-04-22 17:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-07-05 14:20 . 2008-07-05 14:20 0 --a------ C:\WINDOWS\system32\1RcNmqyH.exe.a_a
2008-07-05 11:31 . 2008-07-13 22:40 <DIR> d-------- C:\Documents and Settings\Sarah\Contacts
2008-07-05 11:15 . 2008-07-05 11:15 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-07-05 11:03 . 2008-07-05 16:45 <DIR> d-------- C:\WINDOWS\ie8updates
2008-07-05 10:42 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-05 10:42 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-07-05 10:42 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-05 10:40 . 2008-07-05 10:40 268 --ah----- C:\sqmdata01.sqm
2008-07-05 10:40 . 2008-07-05 10:40 244 --ah----- C:\sqmnoopt01.sqm
2008-07-05 02:37 . 2008-07-05 02:37 268 --ah----- C:\sqmdata00.sqm
2008-07-05 02:37 . 2008-07-05 02:37 244 --ah----- C:\sqmnoopt00.sqm
2008-07-05 02:32 . 2008-07-05 02:35 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-05 02:31 . 2008-07-05 02:36 <DIR> d-------- C:\Program Files\Windows Live
2008-07-05 02:31 . 2008-07-05 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-04 00:45 . 2008-07-04 00:45 364,544 --a------ C:\WINDOWS\system32\dbkxksakiuslmbp.dll
2008-07-04 00:11 . 2008-07-04 00:11 <DIR> d-------- C:\Deckard
2008-07-03 22:20 . 2008-07-03 22:20 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-07-03 22:20 . 2008-07-23 00:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-03 19:42 . 2008-07-20 05:31 <DIR> d-------- C:\Program Files\Paint Shop Pro 6
2008-07-03 19:42 . 1999-08-13 06:00 317,952 --a------ C:\WINDOWS\system32\Roboex32.dll
2008-07-03 19:42 . 1999-06-23 11:46 54,272 --a------ C:\WINDOWS\system32\Serial.ocx
2008-07-03 19:42 . 1999-06-23 11:46 53,760 --a------ C:\WINDOWS\system32\Infrared.ocx
2008-07-03 19:42 . 1999-06-23 11:46 51,712 --a------ C:\WINDOWS\system32\USB.ocx
2008-07-03 19:42 . 1999-08-13 06:00 47,104 --a------ C:\WINDOWS\system32\Wh2Robo.dll
2008-07-03 18:30 . 2008-06-13 23:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-07-03 18:30 . 2008-06-13 23:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-03 18:21 . 2008-07-03 18:21 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-03 18:19 . 2008-07-06 14:06 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-03 18:19 . 2008-07-03 18:19 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-03 18:19 . 2008-07-03 18:19 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\SUPERAntiSpyware.com
2008-07-03 18:19 . 2008-07-03 18:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-03 18:18 . 2008-07-22 23:07 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Malwarebytes
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-03 18:18 . 2008-07-20 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-03 17:50 . 2008-07-03 17:50 <DIR> d-------- C:\d8b53d83b0c7c5ebb3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-22 14:46 23,552 ----a-w C:\WINDOWS\system32\sort.exe
2008-07-10 23:28 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-06 14:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-06 14:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-03 06:45 --------- d-----w C:\Program Files\Intel
2008-07-03 06:41 --------- d-----w C:\Program Files\Realtek
2008-07-03 06:40 327,680 ----a-w C:\WINDOWS\HideWin.exe
2008-07-03 06:31 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-25 08:22 206,088 ----a-w C:\WINDOWS\system32\klogon.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.

------- Sigcheck -------

2008-04-14 10:12 26112 80e366761caa8338bc2f4056780d6765 C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ctfmon.exe
2004-08-04 22:00 26112 67d7c7e1cc9979d54d063c1a67858d38 C:\WINDOWS\system32\ctfmon.exe
2004-08-04 22:00 26112 93f965ab17e83f1284147f0c4e724612 C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((( [email protected]_ 0.51.31.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-06-26 12:10:26 328,192 ----a-w C:\WINDOWS\inf\unregmp2.exe
+ 2008-07-22 14:59:18 317,440 ----a-w C:\WINDOWS\inf\unregmp2.exe
- 2006-10-12 11:09:53 256,512 ----a-w C:\WINDOWS\msagent\agentsvr.exe
+ 2006-10-12 11:09:53 267,264 ----a-w C:\WINDOWS\msagent\agentsvr.exe
- 2000-08-30 22:00:00 41,472 ----a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-30 22:00:00 28,672 ----a-w C:\WINDOWS\Nircmd.exe
- 2008-07-03 07:16:47 44,096 ----a-w C:\WINDOWS\system32\3Tj00v3Q.exe
+ 2008-07-22 15:00:01 33,280 ----a-w C:\WINDOWS\system32\3Tj00v3Q.exe
- 2004-08-04 12:00:00 98,304 ----a-w C:\WINDOWS\system32\cscript.exe
+ 2004-08-04 12:00:00 143,360 ----a-w C:\WINDOWS\system32\cscript.exe
- 2006-08-21 09:14:58 23,040 ----a-w C:\WINDOWS\system32\fltmc.exe
+ 2006-08-21 09:14:58 33,792 ----a-w C:\WINDOWS\system32\fltmc.exe
- 2008-04-22 07:39:58 70,656 ------w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-04-22 07:39:58 81,408 ------w C:\WINDOWS\system32\ie4uinit.exe
- 2008-04-22 07:39:58 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-04-22 07:39:58 24,576 ----a-w C:\WINDOWS\system32\ieudinit.exe
- 2005-05-10 23:45:48 75,776 ----a-w C:\WINDOWS\system32\telnet.exe
+ 2005-05-10 23:45:48 86,528 ----a-w C:\WINDOWS\system32\telnet.exe
- 2004-08-04 12:00:00 240,128 ----a-w C:\WINDOWS\system32\usmt\migwiz.exe
+ 2004-08-04 12:00:00 250,880 ----a-w C:\WINDOWS\system32\usmt\migwiz.exe
- 2000-08-30 22:00:00 65,092 ----a-w C:\WINDOWS\VFind.exe
+ 2000-08-30 22:00:00 97,860 ----a-w C:\WINDOWS\VFind.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6d7d80ab-7333-21e7-82ba-bed96a50c916}]
2008-07-04 00:45 364544 --a------ C:\WINDOWS\system32\dbkxksakiuslmbp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 22:00 26112]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"PSwitch"="C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe" [2008-07-23 00:46 1303552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-05 23:11 98304]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-05 23:10 204800]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"LWBMOUSE"="C:\Program Files\NASDAK\OmniMouse Driver\4.0\MOUSE32A.EXE" [2001-11-09 16:47 399872]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2003-06-04 01:32 163840]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 18:21 201992]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 17:28 16139264 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-04-04 19:22 1835008 C:\WINDOWS\SkyTel.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 22:00 110592 C:\WINDOWS\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 22:00 26112]

C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-07-06 14:06 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-06 14:06 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^Sarah^Start Menu^Programs^Startup^hamachi.lnk]
path=C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\hamachi.lnk
backup=C:\WINDOWS\pss\hamachi.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]
--a------ 2008-07-06 23:43 1655552 C:\Program Files\COMODO\Firewall\cfp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-07-22 23:56 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a------ 2008-07-06 14:06 1518832 C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Hamachi\\hamachi.exe"=
"C:\\Program Files\\Proxy Switcher Standard\\ProxySwitcher.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 18:29]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-07-06 23:43]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-07-06 23:43]
R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2001-12-20 10:02]
R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2001-08-06 07:41]
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [2007-07-03 20:33]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 20:07]
S3 DBKDRVR54;DBKDRVR54;C:\Program Files\Cheat Engine\dbk32.sys [2007-12-27 05:45]
.
Contents of the 'Scheduled Tasks' folder
"2008-07-22 14:37:01 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 23:00:01 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 00:00:01 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 01:00:01 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 02:00:01 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 03:00:01 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 04:00:02 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 05:00:01 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 06:00:02 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 07:00:02 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 08:00:02 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 15:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 09:00:01 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 10:00:01 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 11:00:02 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 12:00:02 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 13:00:02 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 14:46:07 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 15:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 16:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 17:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 18:00:00 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 16:00:03 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 19:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\1RcNmqyH.exe

"2008-07-21 20:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 21:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 22:00:00 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 23:00:00 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 00:00:00 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 01:00:00 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 02:00:00 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 03:00:00 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 04:00:00 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 17:00:02 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-22 05:00:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 06:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 07:00:00 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 08:00:00 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 09:00:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 10:00:10 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 11:00:10 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 12:00:10 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-22 13:54:48 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\1RcNmqyH.exe
"2008-07-21 18:00:01 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 19:00:01 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 20:00:01 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 21:00:03 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
"2008-07-21 22:00:02 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\3Tj00v3Q.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-23 09:52:42
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-23 9:54:21
ComboFix-quarantined-files.txt 2008-07-22 23:54:02
ComboFix2.txt 2008-07-22 14:52:05

Pre-Run: 56,284,135,424 bytes free
Post-Run: 56,284,303,360 bytes free

367 --- E O F --- 2008-07-06 00:51:12



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:00:43 AM, on 23/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\NASDAK\OmniMouse Driver\4.0\MOUSE32A.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\carH04\carH041066.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Sarah\Desktop\DXwnd.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\1RcNmqyH.exe
C:\WINDOWS\system32\3Tj00v3Q.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: mysidesearch search enhancer - {6d7d80ab-7333-21e7-82ba-bed96a50c916} - C:\WINDOWS\system32\dbkxksakiuslmbp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\NASDAK\OmniMouse Driver\4.0\MOUSE32A.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PSwitch] C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1215069195210
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.su...ows-i586-jc.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe

--
End of file - 7498 bytes
  • 0

#6
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello SatanicSarahX,

Could you please follow the stes in my previous post again.

Please make sure you copy/paste the contents of the entire quotebox into notepad, that when you save it the text file is called CFScript and that you drag the file into Combofix.

Thunderbird1988
  • 0

#7
SatanicSarahX

SatanicSarahX

    Member

  • Topic Starter
  • Member
  • PipPip
  • 85 posts
ComboFix 08-07-21.2 - Sarah 2008-07-23 19:07:28.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.589 [GMT 10:00]
Running from: C:\Documents and Settings\Sarah\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Sarah\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Sarah\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Program Files\Temporary
C:\WINDOWS\17PHolmes1001186.exe
C:\WINDOWS\b152.exe
C:\WINDOWS\b155.exe
C:\WINDOWS\b156.exe
C:\WINDOWS\b157.exe
C:\WINDOWS\mrofinu1001186.exe
C:\WINDOWS\mrofinu1001186.exe.tmp

.
((((((((((((((((((((((((( Files Created from 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))
.

2008-07-23 14:04 . 2008-07-23 14:04 <DIR> d-------- C:\Program Files\Skra
2008-07-23 00:46 . 2008-07-23 00:46 16,128,512 --a------ C:\WINDOWS\RTHDCPL.exe.kav
2008-07-22 23:20 . 2008-07-22 23:20 152,159 --a------ C:\WINDOWS\system32\g0.exe
2008-07-22 23:06 . 2008-07-20 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-22 22:26 . 2008-07-22 22:26 90,922 --a------ C:\WINDOWS\system32\dbkxksakiuslmbp.dll-uninst.exe
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\wnet
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\vdf1
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\WINDOWS\system32\confg
2008-07-22 22:19 . 2008-07-23 13:39 <DIR> d-------- C:\WINDOWS\system32\carH04
2008-07-22 22:19 . 2008-07-22 22:19 <DIR> d-------- C:\Temp\btxv15
2008-07-22 22:19 . 2008-07-23 00:41 <DIR> d-------- C:\Temp
2008-07-22 22:19 . 2008-07-22 22:19 64,841 --a------ C:\WINDOWS\system32\entaddmlggaoim.exe
2008-07-22 19:40 . 2008-07-23 01:00 115,200 --a------ C:\WINDOWS\system32\1RcNmqyH.exe
2008-07-22 00:02 . 2008-07-22 00:21 <DIR> d-------- C:\Program Files\Proxy Switcher Standard
2008-07-20 22:42 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-07-20 22:42 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-07-20 13:35 . 2008-07-20 13:35 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\WNR
2008-07-15 07:30 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-07-15 07:30 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-07-15 07:26 . 2004-06-15 15:00 116,736 --a------ C:\WINDOWS\system32\CNMLM61.DLL
2008-07-15 07:26 . 2004-06-15 15:00 7,680 --a------ C:\WINDOWS\system32\CNMVS61.DLL
2008-07-15 07:25 . 2004-06-05 01:34 86,016 -ra------ C:\WINDOWS\system32\CNMCP61.exe
2008-07-15 07:23 . 2008-07-15 07:23 <DIR> d--h----- C:\BJPrinter
2008-07-11 09:26 . 2008-07-11 09:26 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-07-11 09:26 . 2008-07-11 09:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-07-11 03:50 . 2008-07-22 00:42 <DIR> d-------- C:\Program Files\uTorrent
2008-07-11 03:50 . 2008-07-22 00:28 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\uTorrent
2008-07-08 15:59 . 2008-07-19 17:39 <DIR> d-------- C:\Program Files\Cheat Engine
2008-07-08 15:59 . 2007-12-26 17:30 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2008-07-08 15:59 . 2007-12-26 17:30 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
2008-07-08 14:18 . 2008-07-11 03:42 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Hamachi
2008-07-08 14:17 . 2008-07-08 14:18 <DIR> d-------- C:\Program Files\Hamachi
2008-07-08 14:17 . 2008-07-08 14:17 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2008-07-08 13:10 . 2008-07-21 15:45 19,456 --a------ C:\WINDOWS\system32\h0Y2JNV8.dll
2008-07-08 12:58 . 2008-07-08 12:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-07-08 12:56 . 2004-08-04 00:56 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-07-08 12:56 . 2004-08-04 00:56 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax
2008-07-08 12:56 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-07-08 12:56 . 2004-08-03 23:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
2008-07-08 12:56 . 2004-08-03 23:10 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2008-07-08 12:56 . 2004-08-03 23:10 11,136 --a--c--- C:\WINDOWS\system32\dllcache\slip.sys
2008-07-08 12:56 . 2004-08-03 23:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-07-08 12:56 . 2004-08-03 23:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
2008-07-08 12:55 . 2008-07-08 12:55 <DIR> d-------- C:\Program Files\IVT Corporation
2008-07-08 12:54 . 2008-07-08 12:54 <DIR> d-------- C:\Program Files\NCH Software
2008-07-08 12:52 . 2004-08-04 00:56 196,096 --a------ C:\WINDOWS\system32\irftp.exe
2008-07-08 12:51 . 2008-07-08 12:51 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-07-08 12:51 . 2008-07-08 12:51 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\NCH Swift Sound
2008-07-07 00:26 . 2008-07-07 00:26 <DIR> d-------- C:\Program Files\Netropa
2008-07-07 00:26 . 2000-06-08 03:09 28,672 --a------ C:\WINDOWS\system32\msiosd32.dll
2008-07-07 00:26 . 2001-12-20 10:02 6,656 --a------ C:\WINDOWS\system32\drivers\Msikbd2k.sys
2008-07-07 00:26 . 2008-07-23 19:09 245 --a------ C:\WINDOWS\MSIOSD.INI
2008-07-07 00:26 . 2008-07-07 00:26 0 --a------ C:\WINDOWS\WININIT.INI
2008-07-07 00:25 . 2008-07-07 00:25 <DIR> d-------- C:\Program Files\NASDAK
2008-07-07 00:25 . 2000-05-10 15:29 6,205 --a------ C:\WINDOWS\system32\LWBHMVXD.VXD
2008-07-07 00:00 . 2008-07-07 00:00 <DIR> d--h----- C:\WINDOWS\PIF
2008-07-06 23:43 . 2008-07-06 23:43 <DIR> d-------- C:\Program Files\COMODO
2008-07-06 23:43 . 2008-07-06 23:43 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Comodo
2008-07-06 23:43 . 2008-07-08 12:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-07-06 23:43 . 2008-07-06 23:43 143,104 --a------ C:\WINDOWS\system32\guard32.dll
2008-07-06 23:43 . 2008-07-06 23:43 87,056 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-07-06 23:43 . 2008-07-06 23:43 24,208 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-07-06 23:34 . 2008-07-06 23:34 <DIR> d-------- C:\Program Files\BigPond
2008-07-06 22:43 . 2008-07-11 21:34 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-07-06 22:43 . 2008-07-11 21:34 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-07-06 22:42 . 2008-07-06 22:42 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-07-06 22:42 . 2008-07-23 13:44 2,308,128 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-06 22:42 . 2008-07-23 13:58 548,896 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-06 22:42 . 2008-07-23 13:44 20,160 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-06 22:42 . 2008-07-23 13:58 4,004 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-06 22:40 . 2008-07-06 22:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-07-06 19:12 . 2008-07-20 17:28 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\LimeWire
2008-07-06 14:21 . 2008-07-06 14:21 <DIR> d-------- C:\WINDOWS\Sun
2008-07-06 14:16 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-06 14:15 . 2008-07-06 14:16 <DIR> d-------- C:\Program Files\Java
2008-07-06 14:13 . 2008-07-06 14:13 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-06 14:11 . 2008-07-12 19:42 <DIR> d-------- C:\Program Files\LimeWire
2008-07-05 17:13 . 2008-04-23 14:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-07-05 17:13 . 2007-04-17 19:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-07-05 17:13 . 2007-03-08 15:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-07-05 17:13 . 2008-04-23 14:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-07-05 17:13 . 2008-04-23 14:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-07-05 17:13 . 2008-04-23 14:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-07-05 17:13 . 2008-04-23 14:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-07-05 17:13 . 2008-04-23 14:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-07-05 17:13 . 2008-04-22 17:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-07-05 14:20 . 2008-07-05 14:20 0 --a------ C:\WINDOWS\system32\1RcNmqyH.exe.a_a
2008-07-05 11:31 . 2008-07-13 22:40 <DIR> d-------- C:\Documents and Settings\Sarah\Contacts
2008-07-05 11:15 . 2008-07-05 11:15 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-07-05 11:03 . 2008-07-05 16:45 <DIR> d-------- C:\WINDOWS\ie8updates
2008-07-05 10:42 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-05 10:42 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-07-05 10:42 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-05 10:40 . 2008-07-05 10:40 268 --ah----- C:\sqmdata01.sqm
2008-07-05 10:40 . 2008-07-05 10:40 244 --ah----- C:\sqmnoopt01.sqm
2008-07-05 02:37 . 2008-07-05 02:37 268 --ah----- C:\sqmdata00.sqm
2008-07-05 02:37 . 2008-07-05 02:37 244 --ah----- C:\sqmnoopt00.sqm
2008-07-05 02:32 . 2008-07-05 02:35 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-05 02:31 . 2008-07-05 02:36 <DIR> d-------- C:\Program Files\Windows Live
2008-07-05 02:31 . 2008-07-05 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-04 00:45 . 2008-07-04 00:45 364,544 --a------ C:\WINDOWS\system32\dbkxksakiuslmbp.dll
2008-07-04 00:11 . 2008-07-04 00:11 <DIR> d-------- C:\Deckard
2008-07-03 22:20 . 2008-07-03 22:20 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-07-03 22:20 . 2008-07-23 13:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-03 19:42 . 2008-07-20 05:31 <DIR> d-------- C:\Program Files\Paint Shop Pro 6
2008-07-03 19:42 . 1999-08-13 06:00 317,952 --a------ C:\WINDOWS\system32\Roboex32.dll
2008-07-03 19:42 . 1999-06-23 11:46 54,272 --a------ C:\WINDOWS\system32\Serial.ocx
2008-07-03 19:42 . 1999-06-23 11:46 53,760 --a------ C:\WINDOWS\system32\Infrared.ocx
2008-07-03 19:42 . 1999-06-23 11:46 51,712 --a------ C:\WINDOWS\system32\USB.ocx
2008-07-03 19:42 . 1999-08-13 06:00 47,104 --a------ C:\WINDOWS\system32\Wh2Robo.dll
2008-07-03 18:30 . 2008-06-13 23:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-07-03 18:30 . 2008-06-13 23:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-03 18:21 . 2008-07-03 18:21 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-03 18:19 . 2008-07-06 14:06 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-03 18:19 . 2008-07-03 18:19 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-03 18:19 . 2008-07-03 18:19 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\SUPERAntiSpyware.com
2008-07-03 18:19 . 2008-07-03 18:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-03 18:18 . 2008-07-22 23:07 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Malwarebytes
2008-07-03 18:18 . 2008-07-03 18:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-03 18:18 . 2008-07-20 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-03 17:50 . 2008-07-03 17:50 <DIR> d-------- C:\d8b53d83b0c7c5ebb3
2008-07-03 17:48 . 2008-07-03 17:48 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-07-03 17:48 . 2008-07-03 17:48 <DIR> d-------- C:\Documents and Settings\Sarah\Application Data\Nexon

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-23 04:00 72,192 ----a-w C:\WINDOWS\system32\tasklist.exe
2008-07-23 04:00 72,192 ----a-w C:\WINDOWS\system32\taskkill.exe
2008-07-23 04:00 61,440 ----a-w C:\WINDOWS\system32\tlntadmn.exe
2008-07-23 04:00 108,544 ----a-w C:\WINDOWS\system32\telnet.exe
2008-07-23 03:59 50,176 ----a-w C:\WINDOWS\system32\utilman.exe
2008-07-23 03:59 347,136 ----a-w C:\WINDOWS\system32\tourstart.exe
2008-07-23 03:59 259,584 ----a-w C:\WINDOWS\system32\tracerpt.exe
2008-07-23 03:59 16,896 ----a-w C:\WINDOWS\system32\upnpcont.exe
2008-07-23 03:58 65,536 ----a-w C:\WINDOWS\system32\wextract.exe
2008-07-23 03:58 5,632 ----a-w C:\WINDOWS\system32\winver.exe
2008-07-23 03:58 433,664 ----a-w C:\WINDOWS\system32\wiaacmgr.exe
2008-07-23 03:57 98,304 ----a-w C:\WINDOWS\system32\cscript.exe
2008-07-23 03:57 75,264 ----a-w C:\WINDOWS\system32\locator.exe
2008-07-23 03:57 5,632 ----a-w C:\WINDOWS\system32\cisvc.exe
2008-07-23 03:57 33,280 ----a-w C:\WINDOWS\system32\clipsrv.exe
2008-07-23 03:57 32,768 ----a-w C:\WINDOWS\system32\mnmsrvc.exe
2008-07-23 03:57 32,256 ----a-w C:\WINDOWS\system32\wpnpinst.exe
2008-07-23 03:57 32,256 ----a-w C:\WINDOWS\system32\wpabaln.exe
2008-07-23 03:57 30,720 ----a-w C:\WINDOWS\system32\xcopy.exe
2008-07-23 03:57 165,888 ----a-w C:\WINDOWS\system32\wuauclt1.exe
2008-07-23 03:57 13,824 ----a-w C:\WINDOWS\system32\wscntfy.exe
2008-07-23 03:57 114,688 ----a-w C:\WINDOWS\system32\wscript.exe
2008-07-23 03:57 10,752 ----a-w C:\WINDOWS\system32\dumprep.exe
2008-07-23 03:56 89,600 ----a-w C:\WINDOWS\system32\smlogsvc.exe
2008-07-23 03:56 57,344 ----a-w C:\WINDOWS\system32\rdsaddin.exe
2008-07-23 03:56 50,176 ----a-w C:\WINDOWS\system32\reg.exe
2008-07-23 03:56 35,840 ----a-w C:\WINDOWS\system32\rcimlby.exe
2008-07-23 03:56 140,800 ----a-w C:\WINDOWS\system32\sessmgr.exe
2008-07-23 03:55 73,216 ----a-w C:\WINDOWS\system32\tlntsvr.exe
2008-07-23 03:55 679,936 ----a-w C:\WINDOWS\system32\sstext3d.scr
2008-07-23 03:55 538,624 ----a-w C:\WINDOWS\system32\spider.exe
2008-07-23 03:55 18,432 ----a-w C:\WINDOWS\system32\ups.exe
2008-07-23 03:54 24,576 ----a-w C:\WINDOWS\system32\userinit.exe
2008-07-23 03:53 106,496 ----a-r C:\WINDOWS\system32\igfxzoom.exe
2008-07-23 03:43 16,128,512 ----a-r C:\WINDOWS\RTHDCPL.exe
2008-07-23 03:40 114,688 ----a-r C:\WINDOWS\system32\hkcmd.exe
2008-07-23 03:37 94,208 ----a-r C:\WINDOWS\system32\igfxpers.exe
2008-07-23 00:52 78,848 ----a-w C:\WINDOWS\system32\msiexec.exe
2008-07-23 00:52 66,560 ----a-w C:\WINDOWS\system32\fltmc.exe
2008-07-22 14:46 289,792 ----a-w C:\WINDOWS\system32\vssvc.exe
2008-07-22 14:46 23,552 ----a-w C:\WINDOWS\system32\sort.exe
2008-07-10 23:28 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-06 14:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-06 14:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-03 06:45 --------- d-----w C:\Program Files\Intel
2008-07-03 06:41 --------- d-----w C:\Program Files\Realtek
2008-07-03 06:40 327,680 ----a-w C:\WINDOWS\HideWin.exe
2008-07-03 06:31 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-25 08:22 206,088 ----a-w C:\WINDOWS\system32\klogon.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.

------- Sigcheck -------

2008-07-23 13:47 15360 6067cf744c3dcb0d9be247d2801e9d10 C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ctfmon.exe
2008-07-23 13:47 58880 04f35444f51b75acb74bbf01d2cc32b4 C:\WINDOWS\SoftwareDistribution\Download\64ed0a1c038340f7dcd71548187888e1\ctfmon.exe
2004-08-04 22:00 26112 67d7c7e1cc9979d54d063c1a67858d38 C:\WINDOWS\system32\ctfmon.exe
2008-07-23 13:57 15360 32122dcc1643ecb578a1c947d92f639b C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((( [email protected]_ 0.51.31.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-03 15:06:34 1,667,584 -c----w C:\WINDOWS\$NtUninstallKB887472$\msmsgs.exe
- 2004-08-04 12:00:00 57,856 -c----w C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
- 2004-08-04 12:00:00 75,264 -c----w C:\WINDOWS\$NtUninstallKB896428$\telnet.exe
- 2004-08-04 12:00:00 7,680 -c----w C:\WINDOWS\$NtUninstallKB902400$\migregdb.exe
- 2004-08-04 12:00:00 34,304 -c--a-w C:\WINDOWS\ie7\ie4uinit.exe
+ 2004-08-04 12:00:00 45,056 -c--a-w C:\WINDOWS\ie7\ie4uinit.exe
- 2004-08-04 12:00:00 93,184 -c--a-w C:\WINDOWS\ie7\iexplore.exe
+ 2004-08-04 12:00:00 136,704 -c--a-w C:\WINDOWS\ie7\iexplore.exe
- 2007-08-13 08:39:06 54,784 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
+ 2007-08-13 08:39:06 65,536 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
- 2007-08-13 08:43:56 622,080 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
+ 2007-08-13 08:43:56 632,832 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
- 2007-06-26 12:10:26 328,192 ----a-w C:\WINDOWS\inf\unregmp2.exe
+ 2008-07-22 14:59:18 317,440 ----a-w C:\WINDOWS\inf\unregmp2.exe
- 2006-10-12 11:09:53 256,512 ----a-w C:\WINDOWS\msagent\agentsvr.exe
+ 2008-07-23 00:52:50 300,032 ----a-w C:\WINDOWS\msagent\agentsvr.exe
- 2004-08-04 12:00:00 90,624 ----a-w C:\WINDOWS\mui\muisetup.exe
+ 2004-08-04 12:00:00 134,144 ----a-w C:\WINDOWS\mui\muisetup.exe
- 2000-08-30 22:00:00 41,472 ----a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-30 22:00:00 28,672 ----a-w C:\WINDOWS\Nircmd.exe
- 2006-10-10 12:44:50 557,568 ----a-w C:\WINDOWS\SoftwareDistribution\Download\0facce6115ab861022eae3087e064a2a\SP2QFE\xpnetdg.exe
- 2008-04-14 00:12:11 184,320 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\accwiz.exe
- 2008-04-14 00:12:12 4,096 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\actmovie.exe
- 2008-04-14 00:12:12 16,439 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\admin.exe
- 2008-04-14 00:12:12 256,512 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\agentsvr.exe
- 2008-04-14 00:12:12 98,304 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ahui.exe
- 2008-04-14 00:12:12 44,544 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\alg.exe
- 2008-04-13 16:10:01 24,576 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\aspnet_regiis.exe
- 2008-04-13 16:10:01 32,768 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\aspnet_state.exe
- 2008-04-13 16:10:01 32,768 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\aspnet_wp.exe
- 2008-04-14 00:12:12 30,208 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\asr_fmt.exe
- 2008-04-14 00:12:12 25,088 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\at.exe
- 2008-04-14 00:12:12 11,264 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\atmadm.exe
- 2008-04-14 00:12:12 12,288 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\attrib.exe
- 2008-04-14 00:12:12 14,336 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\auditusr.exe
- 2008-04-14 00:12:12 16,439 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\author.exe
- 2008-04-14 00:12:13 71,680 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\blastcln.exe
- 2008-04-14 00:12:13 142,848 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\bootcfg.exe
- 2008-04-14 00:12:13 19,968 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cacls.exe
- 2007-06-27 12:53:18 94,208 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\caspol.exe
- 2008-04-14 00:12:14 188,480 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cfgwiz.exe
- 2008-04-14 00:12:14 56,832 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cipher.exe
- 2008-04-14 00:12:14 5,632 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cisvc.exe
- 2008-04-14 00:12:14 64,000 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cleanmgr.exe
- 2008-04-14 00:12:14 20,480 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cliconfg.exe
- 2008-04-14 00:12:14 102,912 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\clipbrd.exe
- 2008-04-14 00:12:14 33,280 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\clipsrv.exe
- 2008-04-14 00:12:14 389,120 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cmd.exe
- 2008-04-14 00:12:14 25,600 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cmdl32.exe
- 2008-04-14 00:12:15 39,936 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cmmon32.exe
- 2008-04-14 00:12:15 63,488 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cmstp.exe
- 2008-04-14 00:12:15 9,728 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\comrepl.exe
- 2008-04-14 00:12:15 6,144 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\comrereg.exe
- 2008-04-14 00:12:15 1,032,192 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\conf.exe
- 2008-04-14 00:12:15 27,648 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\conime.exe
- 2008-04-13 16:10:13 49,152 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\csc.exe
- 2008-04-14 00:12:15 139,264 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\cscript.exe
- 2008-04-14 00:12:16 42,496 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\davcdata.exe
- 2008-04-14 00:12:16 6,144 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dcomcnfg.exe
- 2008-04-14 00:12:16 30,208 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ddeshare.exe
- 2008-04-14 00:12:16 25,088 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\defrag.exe
- 2008-04-14 00:12:16 82,944 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dfrgfat.exe
- 2008-04-14 00:12:16 105,472 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dfrgntfs.exe
- 2008-04-14 00:12:17 539,136 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dialer.exe
- 2008-04-14 00:12:17 87,040 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\diantz.exe
- 2008-04-14 00:12:17 163,840 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\diskpart.exe
- 2008-04-14 00:12:17 5,120 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dllhost.exe
- 2008-04-14 00:12:17 224,768 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dmadmin.exe
- 2008-04-14 00:12:17 15,872 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dmremote.exe
- 2008-04-14 00:12:17 29,696 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dplaysvr.exe
- 2008-04-14 00:12:17 17,920 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dpnsvr.exe
- 2008-04-14 00:12:18 83,456 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dpvsetup.exe
- 2008-04-14 00:12:18 62,976 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\drvqry.exe
- 2008-04-14 00:12:18 10,752 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dumprep.exe
- 2008-04-14 00:12:18 17,920 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dvdupgrd.exe
- 2008-04-14 00:12:18 180,224 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dwwin.exe
- 2008-04-14 00:12:18 1,298,432 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\dxdiag.exe
- 2008-04-14 00:12:19 193,024 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\eudcedit.exe
- 2008-04-14 00:12:19 50,688 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\evcreate.exe
- 2008-04-14 00:12:19 24,064 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\evntcmd.exe
- 2008-04-14 00:12:19 92,160 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\evntwin.exe
- 2008-04-14 00:12:19 82,944 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\evtrig.exe
- 2008-04-14 00:12:19 1,033,728 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\explorer.exe
- 2008-04-14 00:12:19 24,064 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\extrac32.exe
- 2008-04-14 00:12:20 20,992 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\faxpatch.exe
- 2008-04-14 00:12:20 27,136 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\findstr.exe
- 2008-04-14 00:12:20 23,040 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fltmc.exe
- 2008-04-14 00:12:20 20,992 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fontview.exe
- 2008-04-14 00:12:20 7,680 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\forcedos.exe
- 2008-04-14 00:12:20 15,120 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fp98sadm.exe
- 2008-04-14 00:12:20 109,840 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fp98swin.exe
- 2008-04-14 00:12:20 24,632 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fpadmcgi.exe
- 2008-04-14 00:12:20 188,494 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fpcount.exe
- 2008-04-14 00:12:20 20,538 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fpremadm.exe
- 2008-04-14 00:12:20 28,728 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fpsrvadm.exe
- 2008-04-14 00:12:20 193,024 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fsquirt.exe
- 2008-04-14 00:12:20 42,496 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ftp.exe
- 2008-04-14 00:12:21 142,848 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fxsclnt.exe
- 2008-04-14 00:12:21 229,376 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fxscover.exe
- 2008-04-14 00:12:21 267,776 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\fxssvc.exe
- 2008-04-14 00:12:21 59,904 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\getmac.exe
- 2008-04-14 00:12:21 120,832 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\gprslt.exe
- 2008-04-14 00:12:21 39,424 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\grpconv.exe
- 2008-04-14 00:12:21 15,872 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\help.exe
- 2008-04-14 00:12:21 769,024 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\helpctr.exe
- 2008-04-14 00:12:21 744,448 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\helpsvc.exe
- 2008-04-14 00:12:21 10,752 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\hh.exe
- 2008-04-14 00:12:21 18,432 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\hscupd.exe
- 2008-04-14 00:12:22 214,528 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\icwconn1.exe
- 2008-04-14 00:12:22 86,016 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\icwconn2.exe
- 2008-04-14 00:12:22 24,576 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\icwrmind.exe
- 2008-04-14 00:12:22 34,304 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ie4uinit.exe
- 2008-04-14 00:12:22 18,432 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\iedw.exe
- 2007-12-17 11:58:35 8,192 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ieexec.exe
- 2008-04-14 00:12:22 93,184 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\iexplore.exe
- 2008-04-14 00:12:22 114,688 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\iexpress.exe
- 2008-04-14 00:12:22 30,720 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\iisrstas.exe
- 2008-04-13 16:10:32 184,320 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ilasm.exe
- 2008-04-14 00:12:22 150,528 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\imapi.exe
- 2008-04-14 00:12:22 15,360 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\inetin51.exe
- 2008-04-14 00:12:22 20,480 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\inetwiz.exe
- 2007-06-27 12:54:28 24,576 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\installutil.exe
- 2008-04-14 00:12:12 32,768 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ip\asr_pfu.exe
- 2008-04-13 18:43:32 9,728 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ip\comsdupd.exe
- 2008-04-14 00:12:34 18,944 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ip\secedit.exe
- 2008-04-13 18:43:31 12,800 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ip\spiisupd.exe
- 2008-04-14 00:12:22 55,808 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ipconfig.exe
- 2008-04-14 00:12:23 53,248 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ipv6.exe
- 2008-04-14 00:12:23 23,552 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ipxroute.exe
- 2008-04-14 00:12:23 151,552 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\irftp.exe
- 2007-06-27 12:54:35 40,960 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\jsc.exe
- 2004-08-04 12:00:00 480,256 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\cintsetp.exe
- 2004-08-04 12:00:00 57,399 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\cplexe.exe
- 2004-08-04 12:00:00 307,257 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\imjpdct.exe
- 2004-08-04 12:00:00 155,705 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\imjpdsvr.exe
- 2004-08-04 12:00:00 196,665 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\imjpinst.exe
- 2004-08-04 12:00:00 208,952 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\imjpmig.exe
- 2004-08-04 12:00:00 233,527 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\imjprw.exe
- 2004-08-04 12:00:00 262,200 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\imjputy.exe
- 2004-08-04 12:00:00 59,392 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\imscinst.exe
- 2008-04-13 16:43:36 70,144 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\pintlphr.exe
- 2004-08-04 12:00:00 44,032 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\tintlphr.exe
- 2004-08-04 12:00:00 455,168 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lang\tintsetp.exe
- 2008-04-14 00:12:23 677,888 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lhmstsc.exe
- 2008-04-14 00:12:24 75,264 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\locator.exe
- 2008-04-14 00:12:24 59,392 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\logman.exe
- 2008-04-14 00:12:43 220,672 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\logon.scr
- 2008-04-14 00:12:24 514,560 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\logonui.exe
- 2008-04-14 00:12:24 13,312 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\lsass.exe
- 2008-04-14 00:12:24 72,704 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\magnify.exe
- 2008-04-14 00:12:25 57,344 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\makecab.exe
- 2008-04-14 00:12:25 103,936 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\migload.exe
- 2008-04-14 00:12:25 7,680 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\migregdb.exe
- 2008-04-14 00:12:25 245,248 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\migwiz.exe
- 2008-04-14 00:12:25 241,152 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\migwiza.exe
- 2008-04-14 00:12:25 1,414,656 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mmc.exe
- 2008-04-14 00:12:25 33,792 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mmcperf.exe
- 2008-04-14 00:12:25 32,768 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mnmsrvc.exe
- 2008-04-14 00:12:26 143,360 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mobsync.exe
- 2008-04-14 00:12:26 16,384 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mofcomp.exe
- 2008-04-14 00:12:27 3,558,912 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\moviemk.exe
- 2008-04-14 00:12:27 123,392 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mplay32.exe
- 2008-04-14 00:12:27 4,639 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mplayer2.exe
- 2008-04-14 00:12:27 19,968 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mqbkup.exe
- 2008-04-14 00:12:27 4,608 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mqsvc.exe
- 2008-04-14 00:12:27 117,248 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mqtgsvc.exe
- 2008-04-14 00:12:27 169,984 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\msconfig.exe
- 2008-04-14 00:12:27 6,144 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\msdtc.exe
- 2008-04-14 00:12:27 29,184 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mshta.exe
- 2008-04-14 00:12:28 78,848 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\msiexec.exe
- 2008-04-14 00:12:28 60,416 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\msimn.exe
- 2008-04-14 00:12:28 40,960 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\msiregmv.exe
- 2008-04-14 00:12:28 1,695,232 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\msmsgs.exe
- 2008-04-14 00:12:28 29,184 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\msoobe.exe
- 2008-04-14 00:12:28 343,040 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mspaint.exe
- 2008-04-14 00:12:29 12,288 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mstinit.exe
- 2008-04-14 00:12:29 119,808 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\mtstocom.exe
- 2008-04-14 00:12:29 90,624 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\muisetup.exe
- 2008-04-14 00:12:29 176,640 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\napstat.exe
- 2008-04-14 00:12:29 53,760 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\narrator.exe
- 2008-04-14 00:12:29 42,496 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\net.exe
- 2008-04-14 00:12:29 124,928 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\net1.exe
- 2008-04-14 00:12:29 111,104 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\netdde.exe
- 2008-04-14 00:16:51 329,728 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\netsetup.exe
- 2008-04-14 00:12:29 86,016 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\netsh.exe
- 2008-04-14 00:12:29 36,864 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\netstat.exe
- 2008-04-13 16:11:06 147,456 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ngen.exe
- 2008-04-14 00:12:29 69,120 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\notepad.exe
- 2008-04-14 00:12:29 15,360 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\nppagent.exe
- 2008-04-14 00:12:29 76,800 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\nslookup.exe
- 2008-04-14 00:12:30 1,200,640 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ntbackup.exe
- 2008-04-14 00:12:30 420,864 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ntvdm.exe
- 2008-04-14 00:12:30 32,768 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\odbcad32.exe
- 2008-04-14 00:12:30 69,632 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\odbcconf.exe
- 2008-04-14 00:12:30 60,416 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\oemig50.exe
- 2008-04-14 00:12:31 51,200 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\oobebaln.exe
- 2008-04-14 00:12:31 67,584 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\opnfiles.exe
- 2008-04-14 00:12:31 215,552 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\osk.exe
- 2008-04-14 00:12:31 58,368 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\packager.exe
- 2008-04-14 00:12:31 15,872 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\perfmon.exe
- 2008-04-14 00:12:31 281,088 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\pinball.exe
- 2008-04-14 00:12:31 17,920 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ping.exe
- 2008-04-14 00:12:31 49,152 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\powercfg.exe
- 2008-04-14 00:12:31 109,568 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\progman.exe
- 2008-04-14 00:12:32 50,176 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\proquota.exe
- 2008-04-14 00:12:32 9,216 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\proxycfg.exe
- 2008-04-14 00:12:32 19,968 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\qprocess.exe
- 2008-04-14 00:12:32 56,832 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rasphone.exe
- 2008-04-14 00:12:32 35,840 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rcimlby.exe
- 2008-04-14 00:12:32 21,504 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rcp.exe
- 2008-04-14 00:12:32 62,976 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rdpclip.exe
- 2008-04-14 00:12:32 13,824 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rdsaddin.exe
- 2008-04-14 00:12:32 67,072 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rdshost.exe
- 2008-04-14 00:12:32 50,176 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\reg.exe
- 2007-06-27 12:57:33 28,672 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\regasm.exe
- 2008-04-14 00:12:32 146,432 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\regedit.exe
- 2007-06-27 12:57:41 11,264 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\regsvcs.exe
- 2008-04-14 00:12:32 11,776 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\regsvr32.exe
- 2008-04-14 00:12:33 13,824 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rexec.exe
- 2008-04-14 00:12:33 14,848 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rsh.exe
- 2008-04-14 00:12:33 107,520 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rsnotify.exe
- 2008-04-14 00:12:33 380,416 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rstrui.exe
- 2008-04-14 00:12:33 77,312 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rtcshare.exe
- 2008-04-14 00:12:33 33,280 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\rundll32.exe
- 2008-04-14 00:12:33 14,336 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\runonce.exe
- 2008-04-14 00:12:33 13,312 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\savedump.exe
- 2008-04-14 00:12:33 95,744 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\scardsvr.exe
- 2008-04-14 00:12:34 36,352 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\scrcons.exe
- 2008-04-14 00:12:43 9,216 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\scrnsave.scr
- 2008-04-14 00:12:34 121,856 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sctasks.exe
- 2008-04-14 00:12:34 77,312 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sdbinst.exe
- 2008-04-14 00:12:34 108,544 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\services.exe
- 2008-04-14 00:12:34 141,312 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sessmgr.exe
- 2008-04-14 00:12:34 31,232 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sethc.exe
- 2008-04-14 00:12:34 23,040 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\setup.exe
- 2008-04-14 00:12:34 73,216 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\setup50.exe
- 2008-04-14 00:12:35 32,768 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\setupn.exe
- 2008-04-14 00:12:35 45,056 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\shmgrate.exe
- 2008-04-14 00:12:35 77,824 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\shrpubw.exe
- 2008-04-14 00:12:35 16,437 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\shtml.exe
- 2008-04-14 00:12:35 19,456 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\shutdown.exe
- 2008-04-14 00:12:35 70,144 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sigverif.exe
- 2008-04-14 00:12:35 26,112 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\skeys.exe
- 2008-04-14 00:12:35 32,866 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\slrundll.exe
- 2008-04-14 00:12:35 73,796 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\slserv.exe
- 2008-04-14 00:12:35 8,192 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\smbinst.exe
- 2008-04-14 00:12:35 236,544 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\smi2smir.exe
- 2008-04-14 00:12:35 89,600 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\smlogsvc.exe
- 2008-04-14 00:12:36 131,584 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sndrec32.exe
- 2008-04-14 00:12:36 33,280 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\snmp.exe
- 2008-04-14 00:12:36 8,704 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\snmptrap.exe
- 2008-04-14 00:12:36 24,576 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sort.exe
- 2008-04-14 00:12:36 7,680 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\spdwnwxp.exe
- 2008-04-14 00:12:36 538,624 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\spider.exe
- 2008-04-13 19:42:38 11,264 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\spnpinst.exe
- 2008-04-14 00:12:36 57,856 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\spoolsv.exe
- 2008-04-14 00:12:36 20,992 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\spupdwxp.exe
- 2008-04-14 00:12:43 704,512 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ss3dfo.scr
- 2008-04-14 00:12:43 19,968 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ssbezier.scr
- 2008-04-14 00:12:43 393,216 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ssflwbox.scr
- 2008-04-14 00:12:44 20,992 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ssmarque.scr
- 2008-04-14 00:12:44 47,104 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ssmypics.scr
- 2008-04-14 00:12:44 18,944 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ssmyst.scr
- 2008-04-14 00:12:44 610,304 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sspipes.scr
- 2008-04-14 00:12:44 14,336 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ssstars.scr
- 2008-04-14 00:12:44 679,936 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sstext3d.scr
- 2008-04-14 00:12:36 14,848 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\stimon.exe
- 2008-04-14 00:12:36 16,449 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\stub_fpsrvadm.exe
- 2008-04-14 00:12:36 65,601 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\stub_fpsrvwin.exe
- 2008-04-14 00:12:36 14,336 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\svchost.exe
- 2008-04-14 00:12:36 71,680 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sysinfo.exe
- 2008-04-14 00:12:37 106,496 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\sysocmgr.exe
- 2008-04-14 00:12:37 76,288 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\taskkill.exe
- 2008-04-14 00:12:37 77,824 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tasklist.exe
- 2008-04-14 00:12:37 135,680 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\taskmgr.exe
- 2008-04-14 00:12:37 32,827 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tcptest.exe
- 2008-04-14 00:12:37 75,776 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\telnet.exe
- 2008-04-14 00:12:37 61,440 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tlntadmn.exe
- 2008-04-14 00:12:37 78,336 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tlntsess.exe
- 2008-04-14 00:12:38 73,216 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tlntsvr.exe
- 2008-04-14 00:12:38 347,136 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tourstrt.exe
- 2008-04-14 00:12:38 82,944 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tp4mon.exe
- 2008-04-14 00:12:38 259,584 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tracerpt.exe
- 2008-04-14 00:12:38 12,288 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tracert.exe
- 2008-04-14 00:12:38 60,416 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\tzchange.exe
- 2008-04-13 19:42:22 8,192 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\update\fixccs.exe
- 2008-04-13 19:42:32 6,656 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\update\nv4prep.exe
- 2008-04-13 19:42:38 11,264 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\update\spnpinst.exe
- 2008-04-14 00:12:38 150,528 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\uploadm.exe
- 2008-04-14 00:12:38 16,896 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\upnpcont.exe
- 2008-04-14 00:12:38 18,432 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\ups.exe
- 2008-04-14 00:12:38 26,112 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\userinit.exe
- 2008-04-14 00:12:38 50,176 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\utilman.exe
- 2007-06-27 12:59:58 716,800 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\vbc.exe
- 2008-04-14 00:12:38 28,672 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\verclsid.exe
- 2008-04-14 00:12:38 289,792 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\vssvc.exe
- 2008-04-14 00:12:38 46,080 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\wab.exe
- 2008-04-14 00:12:39 30,208 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\wabmig.exe
- 2008-04-14 00:12:39 116,224 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\wbemtest.exe
- 2008-04-14 00:12:39 65,024 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\wextract.exe
- 2008-04-14 00:12:39 433,664 ----a-w C:\WINDOWS\SoftwareDistribution\Download\3c0bacd63e67d049a438275fd7b87f25\wiaacmgr.exe<
  • 0

#8
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\RTHDCPL.exe.kav
    C:\WINDOWS\system32\CF3696.exe.kav
    C:\WINDOWS\system32\vssvc.exe.kav
    C:\WINDOWS\system32\CF3232.exe
    C:\WINDOWS\system32\g0.exe
    C:\WINDOWS\system32\dbkxksakiuslmbp.dll-uninst.exe
    C:\WINDOWS\system32\entaddmlggaoim.exe
    C:\WINDOWS\system32\1RcNmqyH.exe
    C:\WINDOWS\system32\h0Y2JNV8.dll
    C:\WINDOWS\system32\1RcNmqyH.exe.a_a
    C:\WINDOWS\system32\dbkxksakiuslmbp.dll
    C:\WINDOWS\Tasks\At1.job
    C:\WINDOWS\Tasks\At2.job
    C:\WINDOWS\Tasks\At3.job
    C:\WINDOWS\Tasks\At4.job
    C:\WINDOWS\Tasks\At5.job
    C:\WINDOWS\Tasks\At6.job
    C:\WINDOWS\Tasks\At7.job
    C:\WINDOWS\Tasks\At8.job
    C:\WINDOWS\Tasks\At9.job
    C:\WINDOWS\Tasks\At10.job
    C:\WINDOWS\Tasks\At11.job
    C:\WINDOWS\Tasks\At12.job
    C:\WINDOWS\Tasks\At13.job
    C:\WINDOWS\Tasks\At14.job
    C:\WINDOWS\Tasks\At15.job
    C:\WINDOWS\Tasks\At16.job
    C:\WINDOWS\Tasks\At17.job
    C:\WINDOWS\Tasks\At18.job
    C:\WINDOWS\Tasks\At19.job
    C:\WINDOWS\Tasks\At20.job
    C:\WINDOWS\Tasks\At21.job
    C:\WINDOWS\Tasks\At22.job
    C:\WINDOWS\Tasks\At23.job
    C:\WINDOWS\Tasks\At24.job
    C:\WINDOWS\Tasks\At25.job
    C:\WINDOWS\Tasks\At26.job
    C:\WINDOWS\Tasks\At27.job
    C:\WINDOWS\Tasks\At28.job
    C:\WINDOWS\Tasks\At29.job
    C:\WINDOWS\Tasks\At30.job
    C:\WINDOWS\Tasks\At31.job
    C:\WINDOWS\Tasks\At32.job
    C:\WINDOWS\Tasks\At33.job
    C:\WINDOWS\Tasks\At34.job
    C:\WINDOWS\Tasks\At35.job
    C:\WINDOWS\Tasks\At36.job
    C:\WINDOWS\Tasks\At37.job
    C:\WINDOWS\Tasks\At38.job
    C:\WINDOWS\Tasks\At39.job
    C:\WINDOWS\Tasks\At40.job
    C:\WINDOWS\Tasks\At41.job
    C:\WINDOWS\Tasks\At42.job
    C:\WINDOWS\Tasks\At43.job
    C:\WINDOWS\Tasks\At44.job
    C:\WINDOWS\Tasks\At45.job
    C:\WINDOWS\Tasks\At46.job
    C:\WINDOWS\Tasks\At47.job
    C:\WINDOWS\Tasks\At48.job
    C:\WINDOWS\Tasks\At49.job
    C:\WINDOWS\system32\3Tj00v3Q.exe
    C:\WINDOWS\system32\1RcNmqyH.exe
    C:\WINDOWS\system32\carH04
    C:\Temp\btxv15


  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report and a new Hijackthislog in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Thunderbird1988

Edited by Thunderbird1988, 23 July 2008 - 09:32 AM.

  • 0

#9
SatanicSarahX

SatanicSarahX

    Member

  • Topic Starter
  • Member
  • PipPip
  • 85 posts
C:\WINDOWS\RTHDCPL.exe.kav moved successfully.
File/Folder C:\WINDOWS\system32\CF3696.exe.kav not found.
File/Folder C:\WINDOWS\system32\vssvc.exe.kav not found.
File/Folder C:\WINDOWS\system32\CF3232.exe not found.
C:\WINDOWS\system32\g0.exe moved successfully.
C:\WINDOWS\system32\dbkxksakiuslmbp.dll-uninst.exe moved successfully.
C:\WINDOWS\system32\entaddmlggaoim.exe moved successfully.
C:\WINDOWS\system32\1RcNmqyH.exe moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\h0Y2JNV8.dll
C:\WINDOWS\system32\h0Y2JNV8.dll NOT unregistered.
C:\WINDOWS\system32\h0Y2JNV8.dll moved successfully.
C:\WINDOWS\system32\1RcNmqyH.exe.a_a moved successfully.
C:\WINDOWS\system32\dbkxksakiuslmbp.dll unregistered successfully.
C:\WINDOWS\system32\dbkxksakiuslmbp.dll moved successfully.
C:\WINDOWS\Tasks\At1.job moved successfully.
C:\WINDOWS\Tasks\At2.job moved successfully.
C:\WINDOWS\Tasks\At3.job moved successfully.
C:\WINDOWS\Tasks\At4.job moved successfully.
C:\WINDOWS\Tasks\At5.job moved successfully.
C:\WINDOWS\Tasks\At6.job moved successfully.
C:\WINDOWS\Tasks\At7.job moved successfully.
C:\WINDOWS\Tasks\At8.job moved successfully.
C:\WINDOWS\Tasks\At9.job moved successfully.
C:\WINDOWS\Tasks\At10.job moved successfully.
C:\WINDOWS\Tasks\At11.job moved successfully.
C:\WINDOWS\Tasks\At12.job moved successfully.
C:\WINDOWS\Tasks\At13.job moved successfully.
C:\WINDOWS\Tasks\At14.job moved successfully.
C:\WINDOWS\Tasks\At15.job moved successfully.
C:\WINDOWS\Tasks\At16.job moved successfully.
C:\WINDOWS\Tasks\At17.job moved successfully.
C:\WINDOWS\Tasks\At18.job moved successfully.
C:\WINDOWS\Tasks\At19.job moved successfully.
C:\WINDOWS\Tasks\At20.job moved successfully.
C:\WINDOWS\Tasks\At21.job moved successfully.
C:\WINDOWS\Tasks\At22.job moved successfully.
C:\WINDOWS\Tasks\At23.job moved successfully.
C:\WINDOWS\Tasks\At24.job moved successfully.
C:\WINDOWS\Tasks\At25.job moved successfully.
C:\WINDOWS\Tasks\At26.job moved successfully.
C:\WINDOWS\Tasks\At27.job moved successfully.
C:\WINDOWS\Tasks\At28.job moved successfully.
C:\WINDOWS\Tasks\At29.job moved successfully.
C:\WINDOWS\Tasks\At30.job moved successfully.
C:\WINDOWS\Tasks\At31.job moved successfully.
C:\WINDOWS\Tasks\At32.job moved successfully.
C:\WINDOWS\Tasks\At33.job moved successfully.
C:\WINDOWS\Tasks\At34.job moved successfully.
C:\WINDOWS\Tasks\At35.job moved successfully.
C:\WINDOWS\Tasks\At36.job moved successfully.
C:\WINDOWS\Tasks\At37.job moved successfully.
C:\WINDOWS\Tasks\At38.job moved successfully.
C:\WINDOWS\Tasks\At39.job moved successfully.
C:\WINDOWS\Tasks\At40.job moved successfully.
C:\WINDOWS\Tasks\At41.job moved successfully.
C:\WINDOWS\Tasks\At42.job moved successfully.
C:\WINDOWS\Tasks\At43.job moved successfully.
C:\WINDOWS\Tasks\At44.job moved successfully.
C:\WINDOWS\Tasks\At45.job moved successfully.
C:\WINDOWS\Tasks\At46.job moved successfully.
C:\WINDOWS\Tasks\At47.job moved successfully.
C:\WINDOWS\Tasks\At48.job moved successfully.
File/Folder C:\WINDOWS\Tasks\At49.job not found.
C:\WINDOWS\system32\3Tj00v3Q.exe moved successfully.
File/Folder C:\WINDOWS\system32\1RcNmqyH.exe not found.
C:\WINDOWS\system32\carH04 moved successfully.
C:\Temp\btxv15 moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07242008_021126







Malwarebytes' Anti-Malware 1.22
Database version: 984
Windows 5.1.2600 Service Pack 2

2:19:08 AM 24/07/2008
mbam-log-7-24-2008 (02-19-08).txt

Scan type: Quick Scan
Objects scanned: 41271
Time elapsed: 5 minute(s), 24 second(s)

Memory Processes Infected: 3
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
C:\WINDOWS\17PHolmes1001186.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\17PHolmes1001186.exe (Trojan.Downloader) -> Unloaded process successfully.
C:\WINDOWS\17PHolmes1001186.exe (Trojan.Downloader) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runner1 (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\17PHolmes1001186.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1001186.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu1001186.exe.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\DIL42.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\DIL50.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\DIL52.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\DIL57.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\DIL5E.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\DIL60.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\DIL62.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\DIL64.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\DIL66.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sarah\Local Settings\Temporary Internet Files\Content.IE5\CVG9YTAZ\17PHolmes[1].cmt (Trojan.Downloader) -> Quarantined and deleted successfully.




also with the anitvirus
all the dected items are in quarantine

should i leave them there or delite all?

Edited by SatanicSarahX, 23 July 2008 - 10:21 AM.

  • 0

#10
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello SatanicSarahX,

Please leave them in quarantaine.

Could you please post a new Hijackthislog?

Thunderbird1988
  • 0

Advertisements


#11
SatanicSarahX

SatanicSarahX

    Member

  • Topic Starter
  • Member
  • PipPip
  • 85 posts
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:39:28 AM, on 24/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\NASDAK\OmniMouse Driver\4.0\MOUSE32A.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\OSK.exe
C:\WINDOWS\system32\MSSWCHX.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Skra\Skra.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\NASDAK\OmniMouse Driver\4.0\MOUSE32A.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PSwitch] C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1215069195210
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.su...ows-i586-jc.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe

--
End of file - 7349 bytes
  • 0

#12
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello SatanicSarahX,

Your hijackthislog is clean. How is the computer running?

Thunderbird1988
  • 0

#13
SatanicSarahX

SatanicSarahX

    Member

  • Topic Starter
  • Member
  • PipPip
  • 85 posts
yes much better =]

is there anyhting else i can do as one final scan or something to make sure there is nothing?


ty heaps
  • 0

#14
Thunderbird1988

Thunderbird1988

    Member 2k

  • Member
  • PipPipPipPipPip
  • 2,416 posts
Hello SatanicSarahX

Well yes, we can do that. :)

Please run the F-Secure Online Scanner

Note: This Scanner is for Internet Explorer Only!
  • Follow the Instruction Here for installation.
  • Accept the License Agreement.
  • Once the ActiveX installs,Click Full System Scan
  • Once the download completes,the scan will begin automatically.
  • The scan will take some time to finish,so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and Copy&Paste the entire report in your next reply.

Thunderbird1988
  • 0

#15
SatanicSarahX

SatanicSarahX

    Member

  • Topic Starter
  • Member
  • PipPip
  • 85 posts
sorry took me long to reply but something has trigered some virus on my pc


omg i suck i dunno why this is happening beacuse i diddnt think i did download something that had
a virus

if you dont want to help ill just reformat it
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP