Sophos Anti-Rootkit Version 1.5.0 © 2009 Sophos Plc
Started logging on 26/11/2009 at 22:51:18 PM
User "Anthony" on computer "ANTHONY-PC"
Windows version 6.0 SP 2.0 Service Pack 2 build 6002 SM=0x100 PT=0x1 WOW64
Info: Starting registry scan.
Hidden: registry item \HKEY_USERS\S-1-5-21-367350868-1995089442-3628444069-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9B1F01C7-96F0-18D5-E8BD-18C5EBE098C6}\bbmpipgemijacfbcgecidoigeblpmphcbego
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Windows\System32\config\RegBack\COMPONENTS.LOG1
Hidden: file C:\Windows\Temp\TMP0000000650EE1B079E09AC60
Hidden: file C:\Windows\Temp\TMP00000098C99F4B26A8739094
Hidden: file C:\Windows\System32\drivers\sptd.sys
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\@hotmail.com\SharingMetadata\st@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\01\10-{02394ADA-C443-4385-9891-E087BE189A07}-v1-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v10-Downloaded.frx
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\hotmail.com\SharingMetadata\s@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\11\11-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v11-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v11-Downloaded.frx
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\@hotmail.com\SharingMetadata\@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\12\12-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v12-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v12-Downloaded.frx
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\.com\SharingMetadata\s@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\14\14-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v14-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v14-Downloaded.frx
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\.com\SharingMetadata\s@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\12\12-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v12-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v12-Downloaded.frx
Hidden: file C:\Program Files (x86)\rcv4\winwood\87\ROCKWELL.wav
Hidden: file C:\Windows\Temp\TMP000000012DC2E2DAC8041FA1
Stopped logging on 27/11/2009 at 0:45:32 AM
Sophos Anti-Rootkit Version 1.5.0 © 2009 Sophos Plc
Started logging on 28/11/2009 at 10:28:31 AM
User "Anthony" on computer "ANTHONY-PC"
Windows version 6.0 SP 2.0 Service Pack 2 build 6002 SM=0x100 PT=0x1 WOW64
Info: Starting registry scan.
Hidden: registry item \HKEY_USERS\S-1-5-21-367350868-1995089442-3628444069-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{9B1F01C7-96F0-18D5-E8BD-18C5EBE098C6}\bbmpipgemijacfbcgecidoigeblpmphcbego
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Windows\System32\config\RegBack\COMPONENTS.LOG1
Hidden: file C:\Windows\Temp\TMP0000000650EE1B079E09AC60
Hidden: file C:\Windows\Temp\TMP00000098C99F4B26A8739094
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Windows Live Contacts\{25c5c49f-fca0-4a38-bee0-8e985eebe2dd}\DBStore\tempedb.edb
Hidden: file C:\Windows\System32\drivers\sptd.sys
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0015.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0016.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0020.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0021.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0022.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0023.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0024.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0025.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0026.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0027.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0028.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0029.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0030.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0031.JPG
Hidden: file C:\Users\Anthony\Desktop\ALL FOLDERS\canon\2008_08_08\IMG_0032.JPG
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\@hotmail.com\SharingMetadata\steven900917@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\01\10-{02394ADA-C443-4385-9891-E087BE189A07}-v1-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v10-Downloaded.frx
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\hotmail.com\SharingMetadata\st@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\11\11-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v11-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v11-Downloaded.frx
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\@hotmail.com\SharingMetadata\steven900917@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\12\12-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v12-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v12-Downloaded.frx
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\@hotmail.com\SharingMetadata\s7@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\14\14-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v14-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v14-Downloaded.frx
Hidden: file C:\Users\Anthony\AppData\Local\Microsoft\Messenger\@hotmail.com\SharingMetadata\@hotmail.com\DFSR\Staging\CS{02394ADA-C443-4385-9891-E087BE189A07}\12\12-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v12-{DC177EA2-66AB-457D-A0FA-72F8D6DD2137}-v12-Downloaded.frx
Hidden: file C:\Windows\Temp\TMP000000012DC2E2DAC8041FA1
Stopped logging on 28/11/2009 at 12:32:37 PM
This post has been edited by boopme: 28 November 2009 - 04:11 PM