Symptoms:
Google Results link to other sites than those I click (mostly ads)
Malwarebyte's Anti-Malware and Spybot S&D unable to start. The process is active in Task Manager, but it doesn't show.
I've tried:
Eset SS 3 (Which didn't see it)
Housecall (Which saw it but wasn't able to clean it)
Oh and ComboFix doesn't run on Win2k3. If anyone knows how to circumvent that, it would be extremely helpful.
Below are my HijackThis and OtViewit logs:
hijackthis said:
Scan saved at 9:43:19 PM, on 4/26/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Everything\Everything.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\No-IP\DUC20.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Opera 10 Preview\opera.exe
C:\Program Files\Mozilla Firefox 3.1 Beta 3\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [Everything] "C:\Program Files\Everything\Everything.exe" -startup
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunServices: [Windows Print Spooling] winrar.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [DefaultP17MIDI] MIDIDEF.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [DefaultP17] P17Def.Exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [SetDefaultMIDI] MIDIDef.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [DefaultP17MIDI] MIDIDEF.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [SetDefaultMIDI] MIDIDef.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [DefaultP17MIDI] MIDIDEF.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [SetDefaultMIDI] MIDIDef.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [DefaultP17MIDI] MIDIDEF.EXE (User 'Default user')
O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O13 - Gopher Prefix:
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Process Blocker - Softros Systems, Inc. - C:\Program Files\Process Blocker\Process Blocker.exe
--
End of file - 4470 bytes
Otviewit said:
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Server2003\Desktop
Windows Server 2003 DataCenter Edition Service Pack 2 (Version = 5.2.3790) - Type = NTServer
Internet Explorer (Version = 6.0.2900.2096)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.98 Mb Total Physical Memory | 574.10 Mb Available Physical Memory | 56.12% Memory free
2.42 Gb Paging File | 2.05 Gb Available in Paging File | 84.97% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.87 Gb Total Space | 49.61 Gb Free Space | 88.79% Space Free | Partition Type: NTFS
Drive D: | 149.04 Gb Total Space | 119.66 Gb Free Space | 80.29% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DELL
Current User Name: [censored]
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2009/01/14 00:34:00 | 00,598,016 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe
[2008/10/24 16:51:16 | 00,468,224 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe
[2009/01/14 00:34:00 | 00,598,016 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe
[2007/02/20 08:12:18 | 00,407,056 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
[2004/09/29 08:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
[2007/02/20 08:12:28 | 00,734,736 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
[2007/05/07 08:00:00 | 00,034,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
[2009/02/13 02:33:00 | 00,563,712 | ---- | M] () -- C:\Program Files\Everything\Everything.exe
[2008/10/24 16:50:00 | 01,451,264 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\egui.exe
[2009/04/26 17:50:47 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
[2009/02/13 12:29:50 | 01,172,992 | ---- | M] (Vitalwerks LLC) -- C:\Program Files\No-IP\DUC20.exe
[2006/10/18 17:46:20 | 00,064,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmplayer.exe
[2008/12/02 15:02:36 | 00,108,032 | ---- | M] (Opera Software) -- C:\Program Files\Opera 10 Preview\opera.exe
[2007/05/07 08:00:00 | 00,207,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
[2009/04/23 16:14:04 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox 3.1 Beta 3\firefox.exe
[2007/05/07 08:00:00 | 00,207,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
[2009/04/26 18:23:25 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Server2003\Desktop\OTViewIt.exe
========== (O23) Win32 Services ==========
[2005/09/23 03:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2009/01/14 00:34:00 | 00,598,016 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
[2009/01/13 17:05:00 | 00,593,920 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
[2005/09/23 03:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2007/05/07 08:00:00 | 00,164,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dfssvc.exe -- (Dfs [Disabled | Stopped])
[2008/10/24 16:56:30 | 00,019,200 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv [On_Demand | Stopped])
[2008/10/24 16:51:16 | 00,468,224 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn [Auto | Running])
[2007/05/07 08:00:00 | 00,040,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ismserv.exe -- (IsmServ [Disabled | Stopped])
[2007/05/07 08:00:00 | 00,094,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\llssrv.exe -- (LicenseService [Disabled | Stopped])
[2007/05/07 08:00:00 | 00,792,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntfrs.exe -- (NtFrs [Disabled | Stopped])
[2003/07/28 08:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2007/02/20 08:12:18 | 00,407,056 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDAgent.exe -- (PDAgent [Auto | Running])
[2007/02/20 08:12:28 | 00,734,736 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk\PDEngine.exe -- (PDEngine [On_Demand | Running])
[2004/09/29 08:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
[2008/11/21 18:27:52 | 00,142,040 | ---- | M] (Softros Systems, Inc.) -- C:\Program Files\Process Blocker\Process Blocker.exe -- (Process Blocker [On_Demand | Stopped])
[2007/05/07 08:00:00 | 00,067,072 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rsopprov.exe -- (RSoPProv [Disabled | Stopped])
[2007/05/07 08:00:00 | 00,071,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\tssdis.exe -- (Tssdis [Disabled | Stopped])
[2007/05/07 08:00:00 | 00,352,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\vds.exe -- (vds [Disabled | Stopped])
[2006/10/18 16:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services ==========
[2003/03/24 23:04:50 | 00,007,168 | ---- | M] (Acer Laboratories Inc.) -- C:\WINDOWS\system32\drivers\aliide.sys -- (AliIde [Boot | Running])
[2007/02/17 02:17:00 | 00,007,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\amdide.sys -- (AmdIde [Boot | Running])
[2009/01/14 03:14:01 | 03,455,488 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
[2003/03/24 18:25:20 | 01,078,656 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\drivers\BCMDM.sys -- (BCMModem [On_Demand | Running])
[2003/03/24 22:39:28 | 00,012,416 | ---- | M] (Brother Industries, Ltd.) -- C:\WINDOWS\system32\drivers\BrFiltLo.sys -- (BrFiltLo [Boot | Running])
[2003/03/24 22:39:28 | 00,004,608 | ---- | M] (Brother Industries, Ltd.) -- C:\WINDOWS\system32\drivers\BrFiltUp.sys -- (BrFiltUp [Boot | Running])
[2007/02/17 02:31:22 | 00,009,216 | ---- | M] (CMD Technology, Inc.) -- C:\WINDOWS\system32\drivers\cmdide.sys -- (CmdIde [Boot | Running])
[2007/02/16 22:34:58 | 00,017,920 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\crcdisk.sys -- (crcdisk [Boot | Running])
[2006/02/26 11:22:48 | 00,138,752 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k [On_Demand | Running])
[2007/02/01 01:57:54 | 00,068,376 | ---- | M] (Raxco Software, Inc.) -- C:\WINDOWS\System32\drivers\DefragFs.sys -- (DefragFS [Boot | Running])
[2007/05/07 08:00:00 | 00,034,816 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\dfs.sys -- (DfsDriver [Boot | Running])
[2007/02/17 02:51:02 | 00,207,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\Dot4.sys -- (Dot4 [Boot | Running])
[2003/03/24 23:03:04 | 00,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\Dot4usb.sys -- (dot4usb [Boot | Running])
[2006/10/31 09:15:24 | 00,165,760 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\e100b325.sys -- (E100B [On_Demand | Running])
[2008/10/24 16:45:32 | 00,039,944 | ---- | M] (ESET) -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon [Auto | Running])
[2008/10/24 16:46:24 | 00,053,256 | ---- | M] (ESET) -- C:\WINDOWS\system32\drivers\easdrv.sys -- (easdrv [System | Running])
[2008/10/24 16:53:20 | 00,073,224 | ---- | M] (ESET) -- C:\WINDOWS\system32\drivers\epfw.sys -- (epfw [Auto | Running])
[2008/10/24 16:53:24 | 00,031,240 | ---- | M] (ESET) -- C:\WINDOWS\system32\drivers\epfwndis.sys -- (Epfwndis [On_Demand | Running])
[2008/10/24 16:53:26 | 00,054,280 | ---- | M] (ESET) -- C:\WINDOWS\system32\drivers\epfwtdi.sys -- (epfwtdi [System | Running])
[2005/07/15 11:17:42 | 00,051,120 | ---- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
[2005/07/15 11:17:42 | 00,016,496 | ---- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
[2005/07/15 11:17:42 | 00,021,744 | ---- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZius12.sys -- (HPZius12 [Boot | Running])
[2007/02/17 03:26:58 | 00,017,408 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\kbdhid.sys -- (kbdhid [System | Stopped])
[2006/07/19 07:27:26 | 00,013,568 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd [On_Demand | Running])
[2006/12/14 22:41:56 | 00,041,248 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta [On_Demand | Running])
[2007/02/16 23:33:14 | 00,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Running])
[2006/02/26 11:22:48 | 00,106,496 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv [On_Demand | Running])
[2006/02/26 11:22:48 | 01,389,056 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\P17.sys -- (P17 [On_Demand | Running])
[2006/12/14 22:37:12 | 00,490,016 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\LV561AV.SYS -- (PID_0928 [On_Demand | Running])
[2006/11/07 18:02:36 | 00,021,760 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\point32.sys -- (Point32 [On_Demand | Running])
[2007/05/07 08:00:00 | 00,020,480 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2007/02/17 03:58:10 | 00,046,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\sbp2port.sys -- (sbp2port [Boot | Running])
[2007/05/07 08:00:00 | 00,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2006/08/15 11:48:00 | 00,732,928 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt [On_Demand | Running])
[2003/03/24 23:03:14 | 00,019,968 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\sermouse.sys -- (sermouse [On_Demand | Stopped])
[2003/03/24 23:16:26 | 00,006,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\smbhc.sys -- (SMBHC [System | Stopped])
[2006/08/15 11:48:00 | 00,260,352 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\system32\drivers\smwdm.sys -- (smwdm [On_Demand | Running])
[2003/03/24 23:07:18 | 00,009,216 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1 [Boot | Running])
[2009/04/26 18:02:24 | 00,102,664 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\system32\drivers\tmcomm.sys -- (tmcomm [Auto | Running])
[2007/02/17 00:07:52 | 00,024,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\vgapnp.sys -- (vga [On_Demand | Stopped])
[2006/11/08 09:23:52 | 00,102,912 | ---- | M] (VIA Technologies inc,.ltd) -- C:\WINDOWS\system32\drivers\viamraid.sys -- (viamraid [Boot | Running])
[2003/03/24 23:09:14 | 00,011,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wd.sys -- (Wd [Boot | Running])
[2007/05/07 08:00:00 | 00,169,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wlbs.sys -- (WLBS [On_Demand | Stopped])
[2007/02/17 04:09:38 | 00,011,264 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wmiacpi.sys -- (WmiAcpi [System | Stopped])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\SYSTEM32\blank.htm
"Start Page"=http://www.google.com
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://www.google.com/ie_rsearch.html
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\SYSTEM32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.google.com
"Start Page"=http://www.google.com
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=http://www.google.com/keyword/%s
"provider"=gogl
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL\g]
""=http://www.google.com/search?q=%s
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ==========
HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{22BF413B-C6D2-4d91-82A9-A0F997BA588C} (HKLM) -- C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice (ESET)
"Everything"="C:\Program Files\Everything\Everything.exe" -startup ()
"P17Helper"=Rundll32 P17.dll,P17Helper ()
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
========== (O4) RunServices Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Windows Print Spooling"=winrar.exe File not found
========== (O4) Startup Folders ==========
[2009/02/13 12:29:50 | 01,172,992 | ---- | M] (Vitalwerks LLC) -- C:\Documents and Settings\Server2003\Start Menu\Programs\Startup\No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\Software\policies\microsoft\internet explorer\Infodelivery\Restrictions]
"NoJITSetup"=1
"NoWebJITSetup"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"ShowSuperHidden"=1
"NoRemoteRecursiveEvents"=1
"MemCheckBoxInRunDlg"=1
"NoCDBurning"=1
"StartMenuFavorites"=0
"Start_ShowHelp"=0
"Start_ShowMyComputer"=1
"Start_ShowMyDocs"=1
"Start_ShowMyMusic"=0
"Start_ShowMyPics"=1
"Start_ShowRun"=1
"Start_ShowSearch"=0
"NoDriveTypeAutoRun"=177
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"disablecad"=1
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"scforceoption"=0
"shutdownwithoutlogon"=0
"undockwithoutlogon"=1
"verbosestatus"=1
"NoInternetOpenWith"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=255
"NoInternetIcon"=1
"ForceClassicControlPanel"=1
"NoResolveTrack"=1
"LinkResolveIgnoreLinkInfo"=1
"NoResolveSearch"=1
"ClearRecentDocsOnExit"=1
"NoStartBanner"=1
"NoSMConfigurePrograms"=1
"MemCheckBoxInRunDlg"=1
"NoSharedDocuments"=1
"NoActiveDesktop"=1
"NoRecentDocsMenu"=1
"NoSMHelp"=0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"DisableRegistryTools"=0
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2005/05/26 21:06:54 | 10,095,808 | ---- | M] (Microsoft Corporation)
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{77BF5300-1474-4EC7-9980-D32B190E9B07}: Button: Skype -- %ProgramFiles%\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2009/02/04 08:27:34 | 01,082,880 | ---- | M] (Skype Technologies S.A.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2003/07/14 18:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{77BF5300-1474-4EC7-9980-D32B190E9B07} [HKLM] -> %ProgramFiles%\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [Skype add-on (button)] -> [2009/02/04 08:27:34 | 01,082,880 | ---- | M] (Skype Technologies S.A.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 18:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_13
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_13
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_13
========== (O17) DNS Name Servers ==========
{18EFA5BA-F79F-44C6-85CE-CA9A435B7478} (Servers: | Description: )
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
AtiExtEvent: "DllName" = Ati2evxx.dll -- C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
========== IFEO "Debugger" Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = File not found
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2009/02/13 11:28:10 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
autorun.inf [[autorun] | ;jzkdocrfuyo | shellexecute="RECYCLER\S-8-0-43-100021053-100026924-100020910-5593.com c:\" | ;qbrrqwbhsekyheefpypbubeilhogmxqdzdvwqda | shell\Open\command="RECYCLER\S-8-0-43-100021053-100026924-100020910-5593.com c:\" | ;ylbkityarmgvkzxecqcjbfwxgseiybhjlubnlqgpvctrxmlxgqrjizvdcpnsltuqqnjphbegotcfurydebasdevaazmxspxifw | shell=Open | ]
[2009/04/19 22:13:29 | 00,000,340 | RHS- | M] () -- C:\autorun.inf -- [ NTFS ]
autorun.inf [[autorun] | ;ujxwenidqwzwvdgaqogcplslnscmphweycjqpteomcvzocfvcjgmzziqovh | shellexecute="RECYCLER\S-8-0-43-100021053-100026924-100020910-5593.com d:\" | ;pssmjjbgmzvttbzzwubggrovcuktlsamptlistoqjqramupgbidpgiraoangugkijahuwykmapzbxaev | shell\Open\command="RECYCLER\S-8-0-43-100021053-100026924-100020910-5593.com d:\" | ;enajiitdmvlvefbzfisbnajcbukoovyzdqdrfqdynjlansgzynmhzvnhzskevsxmwfqyaz | shell=Open | ]
[2009/04/19 22:13:29 | 00,000,401 | RHS- | M] () -- D:\autorun.inf -- [ NTFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8764462-25fe-11de-9662-0007e988a700}\Shell]
""=Autorun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8764462-25fe-11de-9662-0007e988a700}\Shell\AutoRun]
""=Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8764462-25fe-11de-9662-0007e988a700}\Shell\AutoRun\command]
""=C:\WINDOWS\system32\shell32.dll -- [2007/05/07 08:00:00 | 08,359,936 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a8764462-25fe-11de-9662-0007e988a700}\Shell\Open\command]
""=RECYCLER\S-1-3-91-100014821-100018072-100000857-2735.com g:\
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/04/26 21:35:38 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2009/04/26 21:35:23 | 00,389,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmd.execf
[2009/04/26 21:32:25 | 03,006,230 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\ComboFix.exe
[2009/04/26 19:02:05 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/26 19:02:05 | 00,000,728 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/26 19:02:03 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/26 19:02:01 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/26 18:25:41 | 38,250,496 | ---- | C] ( ) -- C:\Documents and Settings\Server2003\Desktop\setup_7.0.0.290_26.04.2009_08-50.exe
[2009/04/26 18:23:26 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Server2003\Desktop\OTViewIt.exe
[2009/04/26 18:23:02 | 00,000,000 | ---D | C] -- C:\_OTMoveIt
[2009/04/26 18:22:32 | 00,389,632 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Server2003\Desktop\OTMoveIt3.exe
[2009/04/26 18:04:33 | 00,102,664 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/04/26 17:56:58 | 00,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2009/04/26 17:50:39 | 00,000,000 | ---D | C] -- C:\Program Files\Java
[2009/04/26 17:48:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Server2003\Application Data\Sun
[2009/04/26 17:34:06 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/04/26 17:34:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/26 17:33:04 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Server2003\Desktop\mbam-setup.exe
[2009/04/26 17:30:21 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Server2003\Desktop\spybotsd162.exe
[2009/04/26 16:48:30 | 00,001,766 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\HijackThis.lnk
[2009/04/26 16:48:30 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/04/21 15:05:43 | 06,513,472 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\bozorgdasht-shahnaz-tar.wmv
[2009/04/19 02:00:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Server2003\Desktop\New Folder
[2009/04/18 22:36:05 | 00,001,737 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/04/18 12:56:19 | 00,000,000 | ---D | C] -- C:\spoolerlogs
[2009/04/12 13:08:15 | 00,057,344 | -HS- | C] () -- C:\Documents and Settings\Server2003\Desktop\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Server2003\Desktop\Thumbs.db:encryptable
[2009/04/12 12:57:50 | 02,933,719 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\DSC00582.JPG
[2009/04/12 12:57:43 | 03,028,070 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\DSC00581.JPG
[2009/04/12 12:57:36 | 03,348,850 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\DSC00580.JPG
[2009/04/12 12:57:29 | 03,123,322 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\DSC00578.JPG
[2009/04/12 11:21:47 | 03,156,293 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\MehdiHosseini-DjBeManFazBede128.mp3
[2009/04/12 02:13:43 | 11,581,120 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\royksopp2.mp3
[2009/04/12 02:13:33 | 07,463,485 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\R%f6yksopp - Vision One.mp3
[2009/04/10 19:23:02 | 00,041,808 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2009/04/08 17:01:54 | 03,448,207 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\05 - Takin Back My Love.mp3
[2009/04/08 16:12:59 | 00,039,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gxvxcserv.sys
[2009/04/07 21:50:36 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\Server2003\My Documents\End of War.doc
[2009/04/07 21:38:37 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\Server2003\My Documents\Sea Warfare.doc
[2009/04/07 21:14:50 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\Server2003\My Documents\Air Warfare.doc
[2009/04/07 20:47:32 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\Server2003\My Documents\Land Warfare.doc
[2009/04/07 20:31:45 | 00,020,480 | ---- | C] () -- C:\Documents and Settings\Server2003\My Documents\The Beginning of WWI.doc
[2009/04/05 20:34:58 | 00,000,250 | ---- | C] () -- C:\WINDOWS\tasks\Process Blocker ON.job
[2009/04/05 20:33:21 | 00,000,252 | ---- | C] () -- C:\WINDOWS\tasks\Process Blocker OFF.job
[2009/04/05 20:30:10 | 00,000,097 | ---- | C] () -- C:\WINDOWS\Process Blocker OFF.bat
[2009/04/05 20:28:18 | 00,000,098 | ---- | C] () -- C:\WINDOWS\Process Blocker ON.bat
[2009/04/05 20:22:02 | 00,000,000 | ---D | C] -- C:\Program Files\Process Blocker
[2009/04/05 18:02:06 | 00,000,340 | RHS- | C] () -- C:\autorun.inf
[2009/04/05 13:24:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2009/04/05 00:26:08 | 00,189,784 | ---- | C] () -- C:\WINDOWS\System32\PnkBstrB.xtr
[2009/04/05 00:07:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Server2003\Local Settings\Application Data\PunkBuster
[2009/04/05 00:04:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Server2003\Application Data\id Software
[2009/04/04 23:55:09 | 00,022,328 | ---- | C] () -- C:\Documents and Settings\Server2003\Application Data\PnkBstrK.sys
[2009/04/04 23:54:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\id Software
[2009/03/31 00:08:55 | 00,000,120 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\httpfedveblubdu.cnhlegolnEJxV.1XVVJWUUE6EBWZAf5.AUMqBmPMBWCTAhs5R-YSU52DU9QNUKkVUGjRU0zLU.URL
[2009/03/29 22:16:18 | 00,004,509 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\1078849292.html
[2009/03/29 20:23:55 | 00,000,002 | ---- | C] () -- C:\USBoot.phase-II
[2009/03/29 20:23:54 | 00,000,012 | ---- | C] () -- C:\USBoot.SystemRoot
[2009/03/29 20:21:54 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\amdide.sys
[2009/03/29 20:21:46 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\toside.sys
[2009/03/29 20:21:42 | 00,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\viaide.sys
[2009/03/29 20:20:39 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wd.sys
[2009/03/29 20:20:22 | 00,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mouhid.sys
[2009/03/29 20:20:14 | 00,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sermouse.sys
[2009/03/29 20:19:28 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kbdhid.sys
[2009/03/29 20:19:16 | 00,009,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkor.dll
[2009/03/29 20:18:58 | 00,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdjpn.dll
[2009/03/29 20:18:51 | 00,014,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\battc.sys
[2009/03/29 20:18:51 | 00,010,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\compbatt.sys
[2009/03/29 20:18:47 | 00,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wmiacpi.sys
[2009/03/29 20:18:43 | 00,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\smbhc.sys
[2009/03/29 20:18:42 | 00,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\smbclass.sys
[2009/03/29 20:16:56 | 00,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbohci.sys
[2009/03/29 20:16:34 | 00,046,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sbp2port.sys
[2009/03/29 20:14:30 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\Dot4usb.sys
[2009/03/29 20:14:26 | 00,207,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\Dot4.sys
[2009/03/29 20:14:19 | 00,012,416 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\drivers\BrFiltLo.sys
[2009/03/29 20:14:19 | 00,004,608 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\drivers\BrFiltUp.sys
[2009/03/29 20:13:45 | 00,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\arp1394.sys
[2009/03/29 20:13:45 | 00,061,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ohci1394.sys
[2009/03/29 20:13:45 | 00,058,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nic1394.sys
[2009/03/29 20:13:45 | 00,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\1394bus.sys
[2009/03/29 20:13:45 | 00,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\enum1394.sys
[2009/03/29 20:12:08 | 00,000,002 | ---- | C] () -- C:\USBoot.phase-I
[2009/03/29 20:12:05 | 02,430,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntkrnl.exe
[2009/03/29 20:12:04 | 02,469,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ntkrnlmp.exe
[2009/03/29 20:12:04 | 00,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\halmacpi.dll
[2009/03/29 20:12:04 | 00,118,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\halaacpi.dll
[2009/03/29 20:12:04 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\halacpi.dll
[2009/03/29 20:12:03 | 00,109,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\haleisa.dll
[2009/03/29 20:11:55 | 00,532,872 | ---- | C] () -- C:\WINDOWS\ubsvcgd.dat
[2009/03/29 20:11:49 | 00,451,784 | ---- | C] () -- C:\WINDOWS\ubdevgd.dat
[2009/03/29 20:06:21 | 00,398,824 | ---- | C] () -- C:\WINDOWS\System32\ubsvcgd.sys
[2009/03/29 20:06:21 | 00,234,984 | ---- | C] () -- C:\WINDOWS\System32\ubdevgd.dll
[2009/03/29 20:06:21 | 00,104,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ubarcgd.sys
[2009/03/29 20:06:21 | 00,042,344 | ---- | C] () -- C:\WINDOWS\System32\drivers\ubdrvgd.sys
[2009/03/29 20:06:19 | 00,006,326 | ---- | C] () -- C:\WINDOWS\!SysVol!.mrk
[2009/03/29 19:44:51 | 00,000,443 | ---- | C] () -- C:\Documents and Settings\Server2003\Desktop\NodEnabler 2.81.lnk
[2009/03/29 19:11:55 | 04,065,792 | ---- | C] (Geza Kovacs) -- C:\Documents and Settings\Server2003\Desktop\unetbootin-windows-319.exe
[2009/03/29 18:15:46 | 00,000,000 | -H-- | C] () -- C:\Documents and Settings\Server2003\My Documents\Default.rdp
[2009/03/29 18:07:47 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2009/03/29 17:25:37 | 00,000,683 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2009/03/29 17:25:36 | 00,000,000 | ---D | C] -- C:\Program Files\Opera 10 Preview
[2009/03/29 17:15:27 | 00,001,737 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox 3.1 Beta 3.lnk
[2009/03/29 17:15:24 | 00,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox 3.1 Beta 3
[2009/03/29 13:55:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Server2003\Desktop\Saved Websites
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/04/26 21:35:44 | 00,389,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\cmd.execf
[2009/04/26 21:32:51 | 03,006,230 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\ComboFix.exe
[2009/04/26 21:20:07 | 00,453,260 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/26 21:20:07 | 00,391,330 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/26 21:20:07 | 00,055,640 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/26 21:15:52 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/26 21:15:51 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/26 21:15:11 | 03,761,152 | -H-- | M] () -- C:\Documents and Settings\Server2003\Local Settings\Application Data\IconCache.db
[2009/04/26 21:09:00 | 00,532,872 | ---- | M] () -- C:\WINDOWS\ubsvcgd.dat
[2009/04/26 19:02:05 | 00,000,728 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/26 18:30:14 | 38,250,496 | ---- | M] ( ) -- C:\Documents and Settings\Server2003\Desktop\setup_7.0.0.290_26.04.2009_08-50.exe
[2009/04/26 18:23:25 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Server2003\Desktop\OTViewIt.exe
[2009/04/26 18:22:38 | 00,389,632 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Server2003\Desktop\OTMoveIt3.exe
[2009/04/26 18:02:24 | 00,102,664 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2009/04/26 17:51:14 | 00,451,784 | ---- | M] () -- C:\WINDOWS\ubdevgd.dat
[2009/04/26 17:33:34 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Server2003\Desktop\mbam-setup.exe
[2009/04/26 17:33:05 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Server2003\Desktop\spybotsd162.exe
[2009/04/26 16:48:30 | 00,001,766 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\HijackThis.lnk
[2009/04/26 12:00:02 | 00,000,250 | ---- | M] () -- C:\WINDOWS\tasks\Process Blocker ON.job
[2009/04/24 16:11:28 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/23 21:51:05 | 00,057,344 | -HS- | M] () -- C:\Documents and Settings\Server2003\Desktop\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Server2003\Desktop\Thumbs.db:encryptable
[2009/04/23 21:51:04 | 00,005,632 | ---- | M] () -- C:\Documents and Settings\Server2003\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/21 15:06:18 | 06,513,472 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\bozorgdasht-shahnaz-tar.wmv
[2009/04/20 21:31:44 | 10,728,12032 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2009/04/19 22:13:29 | 00,000,340 | RHS- | M] () -- C:\autorun.inf
[2009/04/18 22:36:05 | 00,001,737 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/04/18 21:17:31 | 00,039,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\gxvxcserv.sys
[2009/04/17 16:00:00 | 00,000,252 | ---- | M] () -- C:\WINDOWS\tasks\Process Blocker OFF.job
[2009/04/15 17:18:13 | 00,189,784 | ---- | M] () -- C:\WINDOWS\System32\PnkBstrB.xtr
[2009/04/15 00:21:50 | 00,000,020 | ---- | M] () -- C:\WINDOWS\System32\PDBootState
[2009/04/13 21:36:35 | 03,156,293 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\MehdiHosseini-DjBeManFazBede128.mp3
[2009/04/13 00:00:26 | 00,000,097 | ---- | M] () -- C:\WINDOWS\Process Blocker OFF.bat
[2009/04/12 13:46:21 | 11,581,120 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\royksopp2.mp3
[2009/04/12 11:26:44 | 03,448,207 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\05 - Takin Back My Love.mp3
[2009/04/12 02:14:29 | 07,463,485 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\R%f6yksopp - Vision One.mp3
[2009/04/11 00:04:02 | 02,933,719 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\DSC00582.JPG
[2009/04/10 23:41:28 | 03,028,070 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\DSC00581.JPG
[2009/04/10 21:21:40 | 03,348,850 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\DSC00580.JPG
[2009/04/10 21:18:56 | 03,123,322 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\DSC00578.JPG
[2009/04/10 19:23:02 | 00,041,808 | ---- | M] () -- C:\WINDOWS\System32\xfcodec.dll
[2009/04/07 21:50:36 | 00,019,968 | ---- | M] () -- C:\Documents and Settings\Server2003\My Documents\End of War.doc
[2009/04/07 21:38:37 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\Server2003\My Documents\Sea Warfare.doc
[2009/04/07 21:14:50 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\Server2003\My Documents\Air Warfare.doc
[2009/04/07 20:47:32 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\Server2003\My Documents\Land Warfare.doc
[2009/04/07 20:31:46 | 00,020,480 | ---- | M] () -- C:\Documents and Settings\Server2003\My Documents\The Beginning of WWI.doc
[2009/04/06 15:32:54 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/05 20:30:55 | 00,000,098 | ---- | M] () -- C:\WINDOWS\Process Blocker ON.bat
[2009/04/05 00:01:55 | 00,022,328 | ---- | M] () -- C:\Documents and Settings\Server2003\Application Data\PnkBstrK.sys
[2009/03/31 00:08:55 | 00,000,120 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\httpfedveblubdu.cnhlegolnEJxV.1XVVJWUUE6EBWZAf5.AUMqBmPMBWCTAhs5R-YSU52DU9QNUKkVUGjRU0zLU.URL
[2009/03/29 22:16:19 | 00,004,509 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\1078849292.html
[2009/03/29 20:23:55 | 00,000,002 | ---- | M] () -- C:\USBoot.phase-II
[2009/03/29 20:23:54 | 00,000,012 | ---- | M] () -- C:\USBoot.SystemRoot
[2009/03/29 20:12:08 | 00,000,002 | ---- | M] () -- C:\USBoot.phase-I
[2009/03/29 19:44:51 | 00,000,443 | ---- | M] () -- C:\Documents and Settings\Server2003\Desktop\NodEnabler 2.81.lnk
[2009/03/29 19:14:06 | 04,065,792 | ---- | M] (Geza Kovacs) -- C:\Documents and Settings\Server2003\Desktop\unetbootin-windows-319.exe
[2009/03/29 18:15:46 | 00,000,000 | -H-- | M] () -- C:\Documents and Settings\Server2003\My Documents\Default.rdp
[2009/03/29 17:25:37 | 00,000,683 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Opera.lnk
[2009/03/29 17:15:27 | 00,001,737 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox 3.1 Beta 3.lnk
[2009/03/29 13:55:04 | 00,000,600 | ---- | M] () -- C:\WINDOWS\Rtcw.INI
< End of report >

