Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Winmds.exe Virus. Help Please.


  • This topic is locked This topic is locked
33 replies to this topic

#1 Kanye

Kanye

  • Members
  • 97 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:38 PM

Posted 18 August 2007 - 04:49 PM

This topic is co-existent with this one. Please help me and look over my log. As you can see, the winmds.exe processes are there. No matter how many times I terminate them, they re-appear.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:46:43 PM, on 8/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winmds.exe
C:\WINDOWS\system32\winmds.exe
C:\WINDOWS\system32\winmds.exe
C:\WINDOWS\system32\winmds.exe
C:\WINDOWS\system32\winmds.exe
C:\WINDOWS\system32\winmds.exe
C:\WINDOWS\system32\winmds.exe
C:\WINDOWS\system32\winmds.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{12D5ED7F-7C96-447A-A26B-1007BD6EADEF}: NameServer = 206.248.154.22 69.28.199.126
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe

--
End of file - 2939 bytes

BC AdBot (Login to Remove)

 


m

#2 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:38 AM

Posted 19 August 2007 - 06:07 PM

Hello there and welcome to Bleeping Computer's security forum.
My name is David, I will be helping you with your log today.

It is a good idea to print off these instructions. There is a possibility some of the instructions will need to be carried out where internet access is not available. It is important that you complete the instructions in the right order, and that you don't miss out any steps.

Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Open hijackthis, click 'config' (bottom right) Choose the tab 'misc Tools' on top.
Choose 'delete a file on reboot'. In the field, copy and paste the filepath a few lines below.
Click open. Hijackthis will tell you that this file will be deleted on next reboot and if you want to reboot now.
When asked if you want to reboot now, say Yes:
C:\WINDOWS\system32\winmds.exe

Allow the PC to reboot, if it doesn't do it automatically, please reboot manually.

Please download Combofix to your desktop.
Doubleclick combofix.exe to launch the application.

Follow the prompts that will be displayed on the screen.
Don't click on the window while the fix is running, because that will cause your system to hang.
When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.

#3 Kanye

Kanye
  • Topic Starter

  • Members
  • 97 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:38 PM

Posted 23 August 2007 - 03:14 PM

Thanks for the reply. I successfully deleted the winmds.exe file with HJT, but I don't know if it will respawn again, though it hasn't yet. Here's the ComboFix log:


ComboFix 07-08-17.2 - "Richie" 2007-08-23 15:51:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.130 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\12gA0LRv.exe
C:\WINDOWS\Tasks.\At1.job
C:\WINDOWS\Tasks.\At10.job
C:\WINDOWS\Tasks.\At11.job
C:\WINDOWS\Tasks.\At12.job
C:\WINDOWS\Tasks.\At13.job
C:\WINDOWS\Tasks.\At14.job
C:\WINDOWS\Tasks.\At15.job
C:\WINDOWS\Tasks.\At16.job
C:\WINDOWS\Tasks.\At17.job
C:\WINDOWS\Tasks.\At18.job
C:\WINDOWS\Tasks.\At19.job
C:\WINDOWS\Tasks.\At2.job
C:\WINDOWS\Tasks.\At20.job
C:\WINDOWS\Tasks.\At21.job
C:\WINDOWS\Tasks.\At22.job
C:\WINDOWS\Tasks.\At23.job
C:\WINDOWS\Tasks.\At24.job
C:\WINDOWS\Tasks.\At3.job
C:\WINDOWS\Tasks.\At4.job
C:\WINDOWS\Tasks.\At5.job
C:\WINDOWS\Tasks.\At6.job
C:\WINDOWS\Tasks.\At7.job
C:\WINDOWS\Tasks.\At8.job
C:\WINDOWS\Tasks.\At9.job


((((((((((((((((((((((((( Files Created from 2007-07-23 to 2007-08-23 )))))))))))))))))))))))))))))))


2007-08-23 15:49 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-19 00:24 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-08-18 17:55 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-08-18 17:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-18 17:46 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-16 10:05 <DIR> d-------- C:\Program Files\CCleaner
2007-08-14 17:47 1,572,864 --a------ C:\DOCUME~1\Richie\ntuser.dat
2007-08-14 11:13 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Uniblue
2007-08-14 10:25 <DIR> d---s---- C:\DOCUME~1\Richie\UserData
2007-08-14 10:23 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Google
2007-08-14 10:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-13 18:42 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-13 17:02 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2007-08-13 13:53 <DIR> d-------- C:\Program Files\Webroot
2007-08-13 13:53 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Webroot
2007-08-12 14:10 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\MSN6
2007-08-12 14:10 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
2007-08-12 13:21 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-08-11 11:36 <DIR> d-------- C:\Program Files\FrostWire
2007-08-10 23:14 854 --a------ C:\WINDOWS\mozver.dat
2007-08-10 17:35 <DIR> d-------- C:\DOCUME~1\Richie\Incomplete
2007-08-10 17:33 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\FrostWire
2007-08-10 15:11 0 --a------ C:\WINDOWS\nsreg.dat
2007-08-10 14:58 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-08-10 14:56 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\WinRAR
2007-08-10 14:49 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Comodo
2007-08-10 14:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo
2007-08-10 14:48 <DIR> d-------- C:\Program Files\Comodo
2007-08-10 14:42 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-10 14:42 <DIR> d-------- C:\DOCUME~1\Richie\Contacts
2007-08-10 14:41 <DIR> d-------- C:\Program Files\MSN Messenger
2007-08-10 14:00 <DIR> d-------- C:\WINDOWS\pss
2007-08-10 13:55 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-08-10 13:55 <DIR> d-------- C:\WINDOWS\Prefetch
2007-08-10 13:35 9,728 --------- C:\WINDOWS\system32\comsdupd.exe
2007-08-10 13:35 63,663 --------- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2007-08-10 13:35 56,623 --------- C:\WINDOWS\system32\drivers\ati1btxx.sys
2007-08-10 13:35 44,928 --------- C:\WINDOWS\system32\drivers\agpcpq.sys
2007-08-10 13:35 43,008 --------- C:\WINDOWS\system32\drivers\amdagp.sys
2007-08-10 13:35 42,752 --------- C:\WINDOWS\system32\drivers\alim1541.sys
2007-08-10 13:35 40,832 --------- C:\WINDOWS\system32\drivers\irbus.sys
2007-08-10 13:35 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2007-08-10 13:35 37,376 --------- C:\WINDOWS\system32\drivers\amdk7.sys
2007-08-10 13:35 36,463 --------- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2007-08-10 13:35 34,735 --------- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2007-08-10 13:35 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2007-08-10 13:35 32,768 --------- C:\WINDOWS\system32\asr_pfu.exe
2007-08-10 13:35 30,671 --------- C:\WINDOWS\system32\drivers\ati1raxx.sys
2007-08-10 13:35 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2007-08-10 13:35 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2007-08-10 13:35 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2007-08-10 13:35 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2007-08-10 13:35 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2007-08-10 13:35 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll
2007-08-10 13:35 29,455 --------- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2007-08-10 13:35 26,367 --------- C:\WINDOWS\system32\drivers\ati1snxx.sys
2007-08-10 13:35 21,343 --------- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2007-08-10 13:35 12,800 --------- C:\WINDOWS\system32\spiisupd.exe
2007-08-10 13:35 12,047 --------- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2007-08-10 13:35 11,615 --------- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2007-08-10 13:34 95,424 --------- C:\WINDOWS\system32\drivers\slnthal.sys
2007-08-10 13:34 937,984 --------- C:\WINDOWS\system32\winbrand.dll
2007-08-10 13:34 88,064 --------- C:\WINDOWS\system32\p2pnetsh.dll
2007-08-10 13:34 870,784 --------- C:\WINDOWS\system32\ati3d1ag.dll
2007-08-10 13:34 86,016 --------- C:\WINDOWS\system32\p2pgasvc.dll
2007-08-10 13:34 86,016 --------- C:\WINDOWS\system32\mdmxsdk.dll
2007-08-10 13:34 81,920 --------- C:\WINDOWS\system32\ieencode.dll
2007-08-10 13:34 8,192 --------- C:\WINDOWS\system32\smbinst.exe
2007-08-10 13:34 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-08-10 13:34 78,464 --------- C:\WINDOWS\system32\drivers\usbvideo.sys
2007-08-10 13:34 75,776 --------- C:\WINDOWS\system32\strmfilt.dll
2007-08-10 13:34 73,832 --------- C:\WINDOWS\system32\slcoinst.dll
2007-08-10 13:34 73,796 --------- C:\WINDOWS\system32\slserv.exe
2007-08-10 13:34 73,216 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2007-08-10 13:34 71,680 --------- C:\WINDOWS\system32\blastcln.exe
2007-08-10 13:34 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-08-10 13:34 7,680 --------- C:\WINDOWS\system32\kbdsmsno.dll
2007-08-10 13:34 7,680 --------- C:\WINDOWS\system32\kbdsmsfi.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\kbdukx.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\kbdno1.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\kbdfi1.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\hccoin.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-08-10 13:34 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2007-08-10 13:34 67,584 --------- C:\WINDOWS\system32\drivers\sdbus.sys
2007-08-10 13:34 63,488 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2007-08-10 13:34 60,416 --------- C:\WINDOWS\system32\fwcfg.dll
2007-08-10 13:34 6,656 --------- C:\WINDOWS\system32\kbdinmal.dll
2007-08-10 13:34 6,656 --------- C:\WINDOWS\system32\kbdinben.dll
2007-08-10 13:34 6,144 --------- C:\WINDOWS\system32\kbdmlt48.dll
2007-08-10 13:34 6,144 --------- C:\WINDOWS\system32\kbdmlt47.dll
2007-08-10 13:34 6,144 --------- C:\WINDOWS\system32\kbdinbe1.dll
2007-08-10 13:34 6,016 --------- C:\WINDOWS\system32\drivers\smbali.sys
2007-08-10 13:34 59,648 --------- C:\WINDOWS\system32\drivers\rfcomm.sys
2007-08-10 13:34 57,856 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2007-08-10 13:34 526,848 --------- C:\WINDOWS\system32\p2psvc.dll
2007-08-10 13:34 52,224 --------- C:\WINDOWS\system32\mspmsnsv.dll
2007-08-10 13:34 52,224 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2007-08-10 13:34 516,768 --------- C:\WINDOWS\system32\ativvaxx.dll
2007-08-10 13:34 50,688 --------- C:\WINDOWS\system32\btpanui.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-10 13:45 2722 --a------ C:\WINDOWS\pchealth\HELPCTR\PackageStore\SkuStore.bin
2007-08-10 13:40 8972 --a------ C:\WINDOWS\pchealth\HELPCTR\Config\Cntstore.bin


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-08-10 14:48]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2004-08-25 13:52]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a-squared]
"C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTV Agent]
C:\Program Files\HTV\HTV.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

R3 laguna;laguna;C:\WINDOWS\system32\DRIVERS\cl546xm.sys
R3 wdm_opl3sax;YAMAHA OPL3-SAx Audio Driver (WDM);C:\WINDOWS\system32\drivers\opl3sax.sys
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys


Contents of the 'Scheduled Tasks' folder
2007-08-13 20:57:02 C:\WINDOWS\Tasks\At100.job - C:\WINDOWS\system32\winmds.exe
2007-08-13 20:57:02 C:\WINDOWS\Tasks\At101.job - C:\WINDOWS\system32\winmds.exe
2007-08-13 20:57:02 C:\WINDOWS\Tasks\At102.job - C:\WINDOWS\system32\winmds.exe
2007-08-13 20:57:02 C:\WINDOWS\Tasks\At103.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At104.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At105.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:00 C:\WINDOWS\Tasks\At106.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:01 C:\WINDOWS\Tasks\At107.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At108.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At109.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:00 C:\WINDOWS\Tasks\At110.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At111.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:00 C:\WINDOWS\Tasks\At112.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:00 C:\WINDOWS\Tasks\At113.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At114.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At115.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At116.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At117.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At118.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At119.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At120.job
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At121.job - C:\WINDOWS\system32\winmds.exe
2007-08-15 16:41:01 C:\WINDOWS\Tasks\At122.job - C:\WINDOWS\system32\winmds.exe
2007-08-15 16:41:01 C:\WINDOWS\Tasks\At123.job - C:\WINDOWS\system32\winmds.exe
2007-08-15 16:41:01 C:\WINDOWS\Tasks\At124.job - C:\WINDOWS\system32\winmds.exe
2007-08-15 16:41:01 C:\WINDOWS\Tasks\At125.job - C:\WINDOWS\system32\winmds.exe
2007-08-15 16:41:01 C:\WINDOWS\Tasks\At126.job - C:\WINDOWS\system32\winmds.exe
2007-08-15 16:41:01 C:\WINDOWS\Tasks\At127.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At128.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At129.job
2007-08-21 13:00:00 C:\WINDOWS\Tasks\At130.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:01 C:\WINDOWS\Tasks\At131.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At132.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At133.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:00 C:\WINDOWS\Tasks\At134.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At135.job
2007-08-23 19:00:01 C:\WINDOWS\Tasks\At136.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:00 C:\WINDOWS\Tasks\At137.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At138.job
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At139.job
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At140.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At141.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At142.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At143.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At144.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At145.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 14:56:21 C:\WINDOWS\Tasks\At146.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 14:56:21 C:\WINDOWS\Tasks\At147.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 14:56:21 C:\WINDOWS\Tasks\At148.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 14:56:21 C:\WINDOWS\Tasks\At149.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 14:56:21 C:\WINDOWS\Tasks\At150.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 14:56:21 C:\WINDOWS\Tasks\At151.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At152.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At153.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:00 C:\WINDOWS\Tasks\At154.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:02 C:\WINDOWS\Tasks\At155.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At156.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At157.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:01 C:\WINDOWS\Tasks\At158.job
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At159.job
2007-08-23 19:00:02 C:\WINDOWS\Tasks\At160.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:00 C:\WINDOWS\Tasks\At161.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At162.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At163.job
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At164.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At165.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At166.job
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At167.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At168.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At169.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 21:12:55 C:\WINDOWS\Tasks\At170.job
2007-08-16 21:12:55 C:\WINDOWS\Tasks\At171.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 21:12:55 C:\WINDOWS\Tasks\At172.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 21:12:55 C:\WINDOWS\Tasks\At173.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 21:12:55 C:\WINDOWS\Tasks\At174.job - C:\WINDOWS\system32\winmds.exe
2007-08-16 21:12:55 C:\WINDOWS\Tasks\At175.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At176.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At177.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:00 C:\WINDOWS\Tasks\At178.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:03 C:\WINDOWS\Tasks\At179.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At180.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At181.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:01 C:\WINDOWS\Tasks\At182.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At183.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:03 C:\WINDOWS\Tasks\At184.job
2007-08-23 20:00:00 C:\WINDOWS\Tasks\At185.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At186.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At187.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At188.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At189.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At190.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At191.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At192.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At193.job - C:\WINDOWS\system32\winmds.exe
2007-08-18 16:25:50 C:\WINDOWS\Tasks\At194.job - C:\WINDOWS\system32\winmds.exe
2007-08-18 16:25:50 C:\WINDOWS\Tasks\At195.job - C:\WINDOWS\system32\winmds.exe
2007-08-18 16:25:50 C:\WINDOWS\Tasks\At196.job - C:\WINDOWS\system32\winmds.exe
2007-08-18 16:25:50 C:\WINDOWS\Tasks\At197.job
2007-08-18 16:25:50 C:\WINDOWS\Tasks\At198.job - C:\WINDOWS\system32\winmds.exe
2007-08-18 16:25:50 C:\WINDOWS\Tasks\At199.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At200.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At201.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:00 C:\WINDOWS\Tasks\At202.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:03 C:\WINDOWS\Tasks\At203.job
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At204.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At205.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:01 C:\WINDOWS\Tasks\At206.job
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At207.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:04 C:\WINDOWS\Tasks\At208.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:01 C:\WINDOWS\Tasks\At209.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At210.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At211.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At212.job
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At213.job
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At214.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At215.job
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At216.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At217.job - C:\WINDOWS\system32\winmds.exe
2007-08-19 18:10:41 C:\WINDOWS\Tasks\At218.job - C:\WINDOWS\system32\winmds.exe
2007-08-19 18:10:41 C:\WINDOWS\Tasks\At219.job - C:\WINDOWS\system32\winmds.exe
2007-08-19 18:10:41 C:\WINDOWS\Tasks\At220.job - C:\WINDOWS\system32\winmds.exe
2007-08-19 18:10:41 C:\WINDOWS\Tasks\At221.job - C:\WINDOWS\system32\winmds.exe
2007-08-19 18:10:41 C:\WINDOWS\Tasks\At222.job - C:\WINDOWS\system32\winmds.exe
2007-08-19 18:10:41 C:\WINDOWS\Tasks\At223.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At224.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At225.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:00 C:\WINDOWS\Tasks\At226.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:04 C:\WINDOWS\Tasks\At227.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At228.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At229.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:02 C:\WINDOWS\Tasks\At230.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At231.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:04 C:\WINDOWS\Tasks\At232.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:01 C:\WINDOWS\Tasks\At233.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At234.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At235.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At236.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At237.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At238.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At239.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At240.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At241.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 00:26:33 C:\WINDOWS\Tasks\At242.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 00:26:33 C:\WINDOWS\Tasks\At243.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 00:26:33 C:\WINDOWS\Tasks\At244.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 00:26:33 C:\WINDOWS\Tasks\At245.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 00:26:33 C:\WINDOWS\Tasks\At246.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 00:26:33 C:\WINDOWS\Tasks\At247.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At248.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At249.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At25.job
2007-08-21 13:00:01 C:\WINDOWS\Tasks\At250.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:04 C:\WINDOWS\Tasks\At251.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At252.job
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At253.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:03 C:\WINDOWS\Tasks\At254.job
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At255.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:05 C:\WINDOWS\Tasks\At256.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:01 C:\WINDOWS\Tasks\At257.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At258.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At259.job - C:\WINDOWS\system32\winmds.exe
2007-08-11 18:03:58 C:\WINDOWS\Tasks\At26.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At260.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At261.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At262.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At263.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At264.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At265.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 16:12:01 C:\WINDOWS\Tasks\At266.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 16:12:01 C:\WINDOWS\Tasks\At267.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 16:12:01 C:\WINDOWS\Tasks\At268.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 16:12:01 C:\WINDOWS\Tasks\At269.job - C:\WINDOWS\system32\winmds.exe
2007-08-11 18:03:58 C:\WINDOWS\Tasks\At27.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 16:12:01 C:\WINDOWS\Tasks\At270.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 16:12:01 C:\WINDOWS\Tasks\At271.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At272.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At273.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:01 C:\WINDOWS\Tasks\At274.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:04 C:\WINDOWS\Tasks\At275.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At276.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At277.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:03 C:\WINDOWS\Tasks\At278.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At279.job - C:\WINDOWS\system32\winmds.exe
2007-08-11 18:03:58 C:\WINDOWS\Tasks\At28.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:05 C:\WINDOWS\Tasks\At280.job
2007-08-23 20:00:01 C:\WINDOWS\Tasks\At281.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At282.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At283.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At284.job
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At285.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At286.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At287.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At288.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At289.job - C:\WINDOWS\system32\winmds.exe
2007-08-11 18:03:58 C:\WINDOWS\Tasks\At29.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 22:27:40 C:\WINDOWS\Tasks\At290.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 22:27:40 C:\WINDOWS\Tasks\At291.job
2007-08-20 22:27:40 C:\WINDOWS\Tasks\At292.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 22:27:40 C:\WINDOWS\Tasks\At293.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 22:27:40 C:\WINDOWS\Tasks\At294.job - C:\WINDOWS\system32\winmds.exe
2007-08-20 22:27:40 C:\WINDOWS\Tasks\At295.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At296.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At297.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:01 C:\WINDOWS\Tasks\At298.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:04 C:\WINDOWS\Tasks\At299.job - C:\WINDOWS\system32\winmds.exe
2007-08-11 18:03:58 C:\WINDOWS\Tasks\At30.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At300.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At301.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:04 C:\WINDOWS\Tasks\At302.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At303.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:06 C:\WINDOWS\Tasks\At304.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:02 C:\WINDOWS\Tasks\At305.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At306.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At307.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At308.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At309.job - C:\WINDOWS\system32\winmds.exe
2007-08-11 18:03:58 C:\WINDOWS\Tasks\At31.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At310.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At311.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At312.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At313.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 11:10:39 C:\WINDOWS\Tasks\At314.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 11:10:39 C:\WINDOWS\Tasks\At315.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 11:10:39 C:\WINDOWS\Tasks\At316.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 11:10:39 C:\WINDOWS\Tasks\At317.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 11:10:39 C:\WINDOWS\Tasks\At318.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 11:10:39 C:\WINDOWS\Tasks\At319.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At32.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At320.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At321.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:01 C:\WINDOWS\Tasks\At322.job
2007-08-21 14:00:05 C:\WINDOWS\Tasks\At323.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At324.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At325.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:05 C:\WINDOWS\Tasks\At326.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At327.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:07 C:\WINDOWS\Tasks\At328.job
2007-08-23 20:00:02 C:\WINDOWS\Tasks\At329.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At33.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At330.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At331.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At332.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At333.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At334.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At335.job
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At336.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At337.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At338.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At339.job
2007-08-21 13:00:01 C:\WINDOWS\Tasks\At34.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At340.job
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At341.job
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At342.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At343.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:00 C:\WINDOWS\Tasks\At344.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At345.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At346.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At347.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 17:25:52 C:\WINDOWS\Tasks\At348.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At349.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:05 C:\WINDOWS\Tasks\At35.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:05 C:\WINDOWS\Tasks\At350.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At351.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:07 C:\WINDOWS\Tasks\At352.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:02 C:\WINDOWS\Tasks\At353.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At354.job
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At355.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At356.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:01 C:\WINDOWS\Tasks\At357.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At358.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At359.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At36.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:01 C:\WINDOWS\Tasks\At360.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At361.job
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At362.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At363.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At364.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At365.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At366.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At367.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:01 C:\WINDOWS\Tasks\At368.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At369.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At37.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At370.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At371.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 23:56:50 C:\WINDOWS\Tasks\At372.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At373.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:06 C:\WINDOWS\Tasks\At374.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At375.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:07 C:\WINDOWS\Tasks\At376.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:02 C:\WINDOWS\Tasks\At377.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At378.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At379.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:06 C:\WINDOWS\Tasks\At38.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At380.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:01 C:\WINDOWS\Tasks\At381.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At382.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At383.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:01 C:\WINDOWS\Tasks\At384.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At385.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At386.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At387.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At388.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At389.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At39.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At390.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At391.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At392.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At393.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At394.job
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At395.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At396.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At397.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:07 C:\WINDOWS\Tasks\At398.job
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At399.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:08 C:\WINDOWS\Tasks\At40.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:08 C:\WINDOWS\Tasks\At400.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:02 C:\WINDOWS\Tasks\At401.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At402.job
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At403.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At404.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At405.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At406.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At407.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:26:00 C:\WINDOWS\Tasks\At408.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:02 C:\WINDOWS\Tasks\At41.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At42.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At43.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At44.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:01 C:\WINDOWS\Tasks\At45.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At46.job
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At47.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:01 C:\WINDOWS\Tasks\At48.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At49.job - C:\WINDOWS\system32\winmds.exe
2007-08-12 20:28:41 C:\WINDOWS\Tasks\At50.job - C:\WINDOWS\system32\winmds.exe
2007-08-12 20:28:41 C:\WINDOWS\Tasks\At51.job - C:\WINDOWS\system32\winmds.exe
2007-08-12 20:28:41 C:\WINDOWS\Tasks\At52.job - C:\WINDOWS\system32\winmds.exe
2007-08-12 20:28:41 C:\WINDOWS\Tasks\At53.job - C:\WINDOWS\system32\winmds.exe
2007-08-12 20:28:41 C:\WINDOWS\Tasks\At54.job - C:\WINDOWS\system32\winmds.exe
2007-08-12 20:28:41 C:\WINDOWS\Tasks\At55.job
2007-08-23 11:00:01 C:\WINDOWS\Tasks\At56.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At57.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:01 C:\WINDOWS\Tasks\At58.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:05 C:\WINDOWS\Tasks\At59.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At60.job
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At61.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:07 C:\WINDOWS\Tasks\At62.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At63.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:09 C:\WINDOWS\Tasks\At64.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:03 C:\WINDOWS\Tasks\At65.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At66.job
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At67.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At68.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:01 C:\WINDOWS\Tasks\At69.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At70.job
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At71.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:01 C:\WINDOWS\Tasks\At72.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:00 C:\WINDOWS\Tasks\At73.job - C:\WINDOWS\system32\winmds.exe
2007-08-13 04:00:24 C:\WINDOWS\Tasks\At74.job - C:\WINDOWS\system32\winmds.exe
2007-08-13 04:00:24 C:\WINDOWS\Tasks\At75.job
2007-08-13 04:00:24 C:\WINDOWS\Tasks\At76.job - C:\WINDOWS\system32\winmds.exe
2007-08-13 04:00:24 C:\WINDOWS\Tasks\At77.job
2007-08-13 04:00:24 C:\WINDOWS\Tasks\At78.job - C:\WINDOWS\system32\winmds.exe
2007-08-13 04:00:24 C:\WINDOWS\Tasks\At79.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 11:00:01 C:\WINDOWS\Tasks\At80.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 12:00:00 C:\WINDOWS\Tasks\At81.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 13:00:01 C:\WINDOWS\Tasks\At82.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 14:00:05 C:\WINDOWS\Tasks\At83.job - C:\WINDOWS\system32\winmds.exe
2007-08-21 15:00:00 C:\WINDOWS\Tasks\At84.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 16:00:00 C:\WINDOWS\Tasks\At85.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 17:00:07 C:\WINDOWS\Tasks\At86.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 18:00:00 C:\WINDOWS\Tasks\At87.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 19:00:10 C:\WINDOWS\Tasks\At88.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 20:00:03 C:\WINDOWS\Tasks\At89.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At90.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At91.job
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At92.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 00:00:01 C:\WINDOWS\Tasks\At93.job
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At94.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At95.job - C:\WINDOWS\system32\winmds.exe
2007-08-23 03:00:01 C:\WINDOWS\Tasks\At96.job - C:\WINDOWS\system32\winmds.exe
2007-08-22 04:00:01 C:\WINDOWS\Tasks\At97.job - C:\WINDOWS\system32\winmds.exe
2007-08-13 20:57:06 C:\WINDOWS\Tasks\At98.job
2007-08-13 20:57:06 C:\WINDOWS\Tasks\At99.job - C:\WINDOWS\system32\winmds.exe
2007-08-14 15:13:09 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
2007-08-14 15:13:06 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-23 16:01:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-23 16:08:58
C:\ComboFix-quarantined-files.txt ... 2007-08-23 16:08

--- E O F ---



And here's a fresh HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:13:49 PM, on 8/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{12D5ED7F-7C96-447A-A26B-1007BD6EADEF}: NameServer = 206.248.154.22 69.28.199.126
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe

--
End of file - 2614 bytes



#4 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:38 AM

Posted 23 August 2007 - 03:29 PM

Ok, click start > run and type: C:\WINDOWS\Tasks
Choose all the tasks that look like At96.job, At368.job etc and delete them.
Do not delete the 2 legitimate Uniblue entries, these are safe to leave.

Please open notepad and and copy and paste next bold in it:
(don't forget to copy and paste REGEDIT4)

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HTV Agent]

Save this as "fix.reg" Choose to save as *all files and place it on your desktop.
It should look like this: Posted Image
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.

Reboot a post a new combofix log.

#5 Kanye

Kanye
  • Topic Starter

  • Members
  • 97 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:38 PM

Posted 23 August 2007 - 05:03 PM

Ok here's the new combofix log:

ComboFix 07-08-17.2 - "Richie" 2007-08-23 17:52:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.189 [GMT -4:00]


((((((((((((((((((((((((( Files Created from 2007-07-23 to 2007-08-23 )))))))))))))))))))))))))))))))


2007-08-23 15:49 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-19 00:24 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-08-18 17:55 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-08-18 17:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-18 17:46 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-16 10:05 <DIR> d-------- C:\Program Files\CCleaner
2007-08-14 17:47 1,572,864 --a------ C:\DOCUME~1\Richie\ntuser.dat
2007-08-14 11:13 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Uniblue
2007-08-14 10:25 <DIR> d---s---- C:\DOCUME~1\Richie\UserData
2007-08-14 10:23 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Google
2007-08-14 10:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-13 18:42 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-13 17:02 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2007-08-13 13:53 <DIR> d-------- C:\Program Files\Webroot
2007-08-13 13:53 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Webroot
2007-08-12 14:10 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\MSN6
2007-08-12 14:10 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
2007-08-12 13:21 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-08-11 11:36 <DIR> d-------- C:\Program Files\FrostWire
2007-08-10 23:14 854 --a------ C:\WINDOWS\mozver.dat
2007-08-10 17:35 <DIR> d-------- C:\DOCUME~1\Richie\Incomplete
2007-08-10 17:33 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\FrostWire
2007-08-10 15:11 0 --a------ C:\WINDOWS\nsreg.dat
2007-08-10 14:58 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-08-10 14:56 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\WinRAR
2007-08-10 14:49 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Comodo
2007-08-10 14:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo
2007-08-10 14:48 <DIR> d-------- C:\Program Files\Comodo
2007-08-10 14:42 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-10 14:42 <DIR> d-------- C:\DOCUME~1\Richie\Contacts
2007-08-10 14:41 <DIR> d-------- C:\Program Files\MSN Messenger
2007-08-10 14:00 <DIR> d-------- C:\WINDOWS\pss
2007-08-10 13:55 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-08-10 13:55 <DIR> d-------- C:\WINDOWS\Prefetch
2007-08-10 13:35 9,728 --------- C:\WINDOWS\system32\comsdupd.exe
2007-08-10 13:35 63,663 --------- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2007-08-10 13:35 56,623 --------- C:\WINDOWS\system32\drivers\ati1btxx.sys
2007-08-10 13:35 44,928 --------- C:\WINDOWS\system32\drivers\agpcpq.sys
2007-08-10 13:35 43,008 --------- C:\WINDOWS\system32\drivers\amdagp.sys
2007-08-10 13:35 42,752 --------- C:\WINDOWS\system32\drivers\alim1541.sys
2007-08-10 13:35 40,832 --------- C:\WINDOWS\system32\drivers\irbus.sys
2007-08-10 13:35 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2007-08-10 13:35 37,376 --------- C:\WINDOWS\system32\drivers\amdk7.sys
2007-08-10 13:35 36,463 --------- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2007-08-10 13:35 34,735 --------- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2007-08-10 13:35 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2007-08-10 13:35 32,768 --------- C:\WINDOWS\system32\asr_pfu.exe
2007-08-10 13:35 30,671 --------- C:\WINDOWS\system32\drivers\ati1raxx.sys
2007-08-10 13:35 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2007-08-10 13:35 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2007-08-10 13:35 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2007-08-10 13:35 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2007-08-10 13:35 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2007-08-10 13:35 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll
2007-08-10 13:35 29,455 --------- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2007-08-10 13:35 26,367 --------- C:\WINDOWS\system32\drivers\ati1snxx.sys
2007-08-10 13:35 21,343 --------- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2007-08-10 13:35 12,800 --------- C:\WINDOWS\system32\spiisupd.exe
2007-08-10 13:35 12,047 --------- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2007-08-10 13:35 11,615 --------- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2007-08-10 13:34 95,424 --------- C:\WINDOWS\system32\drivers\slnthal.sys
2007-08-10 13:34 937,984 --------- C:\WINDOWS\system32\winbrand.dll
2007-08-10 13:34 88,064 --------- C:\WINDOWS\system32\p2pnetsh.dll
2007-08-10 13:34 870,784 --------- C:\WINDOWS\system32\ati3d1ag.dll
2007-08-10 13:34 86,016 --------- C:\WINDOWS\system32\p2pgasvc.dll
2007-08-10 13:34 86,016 --------- C:\WINDOWS\system32\mdmxsdk.dll
2007-08-10 13:34 81,920 --------- C:\WINDOWS\system32\ieencode.dll
2007-08-10 13:34 8,192 --------- C:\WINDOWS\system32\smbinst.exe
2007-08-10 13:34 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-08-10 13:34 78,464 --------- C:\WINDOWS\system32\drivers\usbvideo.sys
2007-08-10 13:34 75,776 --------- C:\WINDOWS\system32\strmfilt.dll
2007-08-10 13:34 73,832 --------- C:\WINDOWS\system32\slcoinst.dll
2007-08-10 13:34 73,796 --------- C:\WINDOWS\system32\slserv.exe
2007-08-10 13:34 73,216 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2007-08-10 13:34 71,680 --------- C:\WINDOWS\system32\blastcln.exe
2007-08-10 13:34 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-08-10 13:34 7,680 --------- C:\WINDOWS\system32\kbdsmsno.dll
2007-08-10 13:34 7,680 --------- C:\WINDOWS\system32\kbdsmsfi.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\kbdukx.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\kbdno1.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\kbdfi1.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\hccoin.dll
2007-08-10 13:34 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-08-10 13:34 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2007-08-10 13:34 67,584 --------- C:\WINDOWS\system32\drivers\sdbus.sys
2007-08-10 13:34 63,488 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2007-08-10 13:34 60,416 --------- C:\WINDOWS\system32\fwcfg.dll
2007-08-10 13:34 6,656 --------- C:\WINDOWS\system32\kbdinmal.dll
2007-08-10 13:34 6,656 --------- C:\WINDOWS\system32\kbdinben.dll
2007-08-10 13:34 6,144 --------- C:\WINDOWS\system32\kbdmlt48.dll
2007-08-10 13:34 6,144 --------- C:\WINDOWS\system32\kbdmlt47.dll
2007-08-10 13:34 6,144 --------- C:\WINDOWS\system32\kbdinbe1.dll
2007-08-10 13:34 6,016 --------- C:\WINDOWS\system32\drivers\smbali.sys
2007-08-10 13:34 59,648 --------- C:\WINDOWS\system32\drivers\rfcomm.sys
2007-08-10 13:34 57,856 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2007-08-10 13:34 526,848 --------- C:\WINDOWS\system32\p2psvc.dll
2007-08-10 13:34 52,224 --------- C:\WINDOWS\system32\mspmsnsv.dll
2007-08-10 13:34 52,224 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2007-08-10 13:34 516,768 --------- C:\WINDOWS\system32\ativvaxx.dll
2007-08-10 13:34 50,688 --------- C:\WINDOWS\system32\btpanui.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-10 13:45 2722 --a------ C:\WINDOWS\pchealth\HELPCTR\PackageStore\SkuStore.bin
2007-08-10 13:40 8972 --a------ C:\WINDOWS\pchealth\HELPCTR\Config\Cntstore.bin


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-08-10 14:48]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2004-08-25 13:52]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a-squared]
"C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

R3 laguna;laguna;C:\WINDOWS\system32\DRIVERS\cl546xm.sys
R3 wdm_opl3sax;YAMAHA OPL3-SAx Audio Driver (WDM);C:\WINDOWS\system32\drivers\opl3sax.sys
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys


Contents of the 'Scheduled Tasks' folder
2007-08-14 15:13:09 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
2007-08-14 15:13:06 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-23 17:56:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************

Completion time: 2007-08-23 18:01:01
C:\ComboFix-quarantined-files.txt ... 2007-08-23 18:00
C:\ComboFix2.txt ... 2007-08-23 16:08

--- E O F ---


By the way, can I delete the fix.reg file? (It worked)

#6 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:38 AM

Posted 24 August 2007 - 03:48 AM

You can go ahead and delete that fix.reg now.

Please perform this online scan: Kaspersky Webscan
Note that this scanner will only work on Internet Explorer, so please use this browser for the scan.
Read the Requirements and Privacy statement, then select "Accept"
A dialogue box will appearing asking "Do you want to install this software?" Name: kavwebscan_unicode.cab
Select "Install" to download the ActiveX controls that allows ActiveScan to run.

When the download is complete it will say ready, click "Next"
Select a target to scan: Click on "My Computer"
When the scan is complete choose to save the results as "Save as Text"
Post the Kaspersky scan results in your next reply, along with a new Hijackthis log.

#7 Kanye

Kanye
  • Topic Starter

  • Members
  • 97 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:38 PM

Posted 24 August 2007 - 12:50 PM

Kaspersky Log:

KASPERSKY ONLINE SCANNER REPORT
Friday, August 24, 2007 1:47:36 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 24/08/2007
Kaspersky Anti-Virus database records: 389536
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 15145
Number of viruses found 1
Number of infected objects 2
Number of suspicious objects 0
Duration of the scan process 01:38:51

Infected Object Name Virus Name Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Richie\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\cert8.db Object is locked skipped
C:\Documents and Settings\Richie\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Richie\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\history.dat Object is locked skipped
C:\Documents and Settings\Richie\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\key3.db Object is locked skipped
C:\Documents and Settings\Richie\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\parent.lock Object is locked skipped
C:\Documents and Settings\Richie\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Richie\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Richie\Application Data\Webroot\Spy Sweeper\Logs\SpySweeperLog.txt Object is locked skipped
C:\Documents and Settings\Richie\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Application Data\Microsoft\Windows Live Contacts\richiiee@hotmail.com\real\members.stg Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Application Data\Mozilla\Firefox\Profiles\urx3qen7.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\History\History.IE5\MSHist012007082420070825\index.dat Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Temp\~DF3BBF.tmp Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Temp\~DFA375.tmp Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Temp\~DFA3AC.tmp Object is locked skipped
C:\Documents and Settings\Richie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Richie\ntuser.dat Object is locked skipped
C:\Documents and Settings\Richie\NTUSER.DAT.LOG Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\12gA0LRv.exe.vir Infected: Backdoor.Win32.Agent.ark skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{5A92E897-9B75-4CB2-9A2C-B751062DBF9F}\RP21\A0002556.exe Infected: Backdoor.Win32.Agent.ark skipped
C:\System Volume Information\_restore{5A92E897-9B75-4CB2-9A2C-B751062DBF9F}\RP21\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.


HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:50:17 PM, on 8/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{12D5ED7F-7C96-447A-A26B-1007BD6EADEF}: NameServer = 206.248.154.22 69.28.199.126
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe

--
End of file - 2754 bytes



Good news: The winmds.exe program doesn't respawn and duplicate itself anymore. And should I close the Kaspersky scan now?

Edited by Kanye, 24 August 2007 - 12:51 PM.


#8 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:38 AM

Posted 24 August 2007 - 03:04 PM

Hi there, you can close the Kaspersky scan now, we don't need it anymore.

Go ahead and delete this folder: C:\QooBox

We need to purge your infected system restore points.
On the Desktop, right-click My Computer, then click Properties.
Click the System Restore tab near the top of the window.
Check Turn off System Restore, click Apply, and then click OK.
More information on how to disable your system restore can be found here.

We want to create a new, clean restore point. Please first reboot your computer.
On the Desktop, right-click My Computer, then click Properties.
Click the System Restore tab near the top of the window.
Uncheck "Turn off System Restore", click Apply, and then click OK.

Click Start > All Programs > Accessories > System Tools, and select System Restore.
In the System Restore wizard, select the box next the text labeled "Create a restore point" and click the Next button.
Type a description for your new restore point - Something like "After trojan/spyware cleanup".
Click Create, and after it has created the restore point, click "Close".
Further instructions on creating a restore point can be found here

Reboot a final time and let me know how the system is running.
I see a clean Hijackthis log now! :thumbsup:

#9 Kanye

Kanye
  • Topic Starter

  • Members
  • 97 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:38 PM

Posted 24 August 2007 - 03:51 PM

Okay I did all that and everything seems fine now. No more winmds.exe, and no more lag. Thanks a lot. :thumbsup:

Edited by Kanye, 24 August 2007 - 03:51 PM.


#10 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:38 AM

Posted 24 August 2007 - 03:53 PM

Glad I could help! :flowers:
The latest log is looking clean!
Follow this list and your potential for being infected again will be reduced dramatically.

Use an Anti Virus Software -
* It is very important that your computer has an anti-virus software running on your machine.
* This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
* Click here for more information on -> Computer Safety On line - Anti-Virus
* I would recommend Grisoft's AVG or AVAST.
* These are the more secure and better ones.

Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall -
* I can not stress how important it is that you use a Firewall on your computer.
* Without a firewall your computer is susceptible to being hacked and taken over.
* Simply using a Firewall in its default configuration can lower your risk greatly.
* For an article on Firewalls and a listing of some available ones see the link below:
* Click here for more information on -> Computer Safety On line - Software Firewalls
* I would recommend ZoneAlarm as a firewall as it's easy to use.

Visit Microsoft's Windows Update Site Frequently -
* It is important that you visit http://www.windowsupdate.com regularly.
* This will ensure your computer has always the latest security updates available installed on your computer.
* If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Next, if they're not already present, I would recommend the download and installation of some or all of the following programs (all free), and the updating of them regularly

Install Spybot© - Search and Destroy- Install and download Spybot - Search and Destroy with its TeaTimer option.
* This will provide real-time spyware & hijacker protection on your computer alongside your virus protection.
* You should also scan your computer with program on a regular basis just as you would an anti virus software.
* A tutorial on installing & using this product can be found here:
* Click here for more info -->Instructions for - Spybot S & D and Ad-aware

Install Lavasofts© Ad-Aware - Install and download Ad-Aware.
* You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot.
* A tutorial on installing & using this product can be found here:
* Click here for more info -->Instructions for - Spybot S & D and Ad-aware

Install Javacools© SpywareBlaster -
* SpywareBlaster will added a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs.
* A article on anti-malware products with links for this program and others can be found here:
* Click here for more info -->Computer Safety on line - Anti-Malware

Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.
:thumbsup: If you wish to learn how to use HijackThis to remove malware, you might like to join the Malware Removal Training Program!

If you have any addition questions just ask...
David

#11 Kanye

Kanye
  • Topic Starter

  • Members
  • 97 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:38 PM

Posted 02 September 2007 - 09:37 PM

Oh my God, it's back! And this time it randomly stops my internet connection! The winmds.exe processes are there again and the winmds.exe file is back in my system32 folder, help!

#12 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:38 AM

Posted 03 September 2007 - 04:54 AM

Looks like we are back to square one. Please post a new Hijackthis log and a new combofix log.
We will probably have to get you a better antivirus installed, to protect you in the future.

#13 Kanye

Kanye
  • Topic Starter

  • Members
  • 97 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:38 PM

Posted 05 September 2007 - 03:40 PM

Ok here's the HJT log, Combofox I will post in a moment.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:37:07 PM, on 9/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winmds.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} - http://download.sopcast.com/download/SOPCORE.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{12D5ED7F-7C96-447A-A26B-1007BD6EADEF}: NameServer = 206.248.154.22 69.28.199.126
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe

--
End of file - 3067 bytes

There it is, but it hasn't multiplied yet. I also noticed when it recreates itself, a MSDOS window pops up for a split second and then I lose my internet connection and the winmds is there. I traced it and found out that the MSDOS file was being ran from C:\Documents and Settings\Richie\Local Settings\Temp. The file that automatically runs to create the winmds files and processes is named random numbers and letters. This one is called "5s4OB7jv", but every time is automatically runs itself after a few hours, it's name is something totally different, for instance "g68fg9b" or something; it changes everytime. I delete the file but it keeps coming back randomly as well under a new random code of letters and numbers, and everytime it starts itself, I lose my internet and have to re-connect. Just thought that info might help.

Edited by Kanye, 05 September 2007 - 03:42 PM.


#14 Kanye

Kanye
  • Topic Starter

  • Members
  • 97 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:09:38 PM

Posted 05 September 2007 - 06:43 PM

And the Combofix log.

ComboFix 07-08-30.3 - "Richie" 2007-09-05 18:43:09.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.164 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\bvb2vtIh.exe
C:\WINDOWS\Tasks.\At1.job
C:\WINDOWS\Tasks.\At10.job
C:\WINDOWS\Tasks.\At11.job
C:\WINDOWS\Tasks.\At12.job
C:\WINDOWS\Tasks.\At13.job
C:\WINDOWS\Tasks.\At14.job
C:\WINDOWS\Tasks.\At15.job
C:\WINDOWS\Tasks.\At16.job
C:\WINDOWS\Tasks.\At17.job
C:\WINDOWS\Tasks.\At18.job
C:\WINDOWS\Tasks.\At19.job
C:\WINDOWS\Tasks.\At2.job
C:\WINDOWS\Tasks.\At20.job
C:\WINDOWS\Tasks.\At21.job
C:\WINDOWS\Tasks.\At22.job
C:\WINDOWS\Tasks.\At23.job
C:\WINDOWS\Tasks.\At24.job
C:\WINDOWS\Tasks.\At3.job
C:\WINDOWS\Tasks.\At4.job
C:\WINDOWS\Tasks.\At5.job
C:\WINDOWS\Tasks.\At6.job
C:\WINDOWS\Tasks.\At7.job
C:\WINDOWS\Tasks.\At8.job
C:\WINDOWS\Tasks.\At9.job


((((((((((((((((((((((((( Files Created from 2007-08-05 to 2007-09-05 )))))))))))))))))))))))))))))))


2007-09-05 17:26 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-05 16:31 11,342 --a------ C:\WINDOWS\system32\winmds.exe
2007-09-01 17:58 0 --a------ C:\WINDOWS\DOSSTART.BAT
2007-09-01 17:57 <DIR> d-------- C:\DOCUME~1\Richie\WINDOWS
2007-08-30 14:33 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\PCToolsFirewallPlus
2007-08-30 14:29 55,904 --a------ C:\WINDOWS\system32\drivers\pctfw.sys
2007-08-30 14:29 100,448 --a------ C:\WINDOWS\system32\drivers\pctfw1.sys
2007-08-30 14:28 <DIR> d-------- C:\Program Files\PC Tools Firewall Plus
2007-08-29 16:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-08-27 13:45 <DIR> d-------- C:\WINDOWS\Profiles
2007-08-27 13:45 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\InterTrust
2007-08-27 10:48 <DIR> d-------- C:\Program Files\foobar2000
2007-08-27 10:48 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\foobar2000
2007-08-26 21:14 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\TVU Networks
2007-08-26 18:04 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\LimeWire
2007-08-24 11:29 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-08-18 17:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-18 17:46 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-16 10:05 <DIR> d-------- C:\Program Files\CCleaner
2007-08-14 11:13 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Uniblue
2007-08-14 10:25 <DIR> d---s---- C:\DOCUME~1\Richie\UserData
2007-08-14 10:23 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Google
2007-08-14 10:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-13 18:42 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-13 17:02 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2007-08-13 13:53 <DIR> d-------- C:\Program Files\Webroot
2007-08-13 13:53 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Webroot
2007-08-12 14:10 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\MSN6
2007-08-12 14:10 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
2007-08-12 13:21 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-08-11 11:36 <DIR> d-------- C:\Program Files\FrostWire
2007-08-10 23:14 854 --a------ C:\WINDOWS\mozver.dat
2007-08-10 17:35 <DIR> d-------- C:\DOCUME~1\Richie\Incomplete
2007-08-10 17:33 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\FrostWire
2007-08-10 15:11 0 --a------ C:\WINDOWS\nsreg.dat
2007-08-10 14:58 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-08-10 14:56 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\WinRAR
2007-08-10 14:49 <DIR> d-------- C:\DOCUME~1\Richie\APPLIC~1\Comodo
2007-08-10 14:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo
2007-08-10 14:48 <DIR> d-------- C:\Program Files\Comodo
2007-08-10 14:42 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-10 14:42 <DIR> d-------- C:\DOCUME~1\Richie\Contacts
2007-08-10 14:41 <DIR> d-------- C:\Program Files\MSN Messenger
2007-08-10 14:00 <DIR> d-------- C:\WINDOWS\pss
2007-08-10 13:36 96,768 -----c--- C:\WINDOWS\system32\dllcache\dpcdll.dll
2007-08-10 13:18 <DIR> d----c--- C:\WINDOWS\ServicePackFiles
2007-08-10 13:08 2,897,920 --------- C:\WINDOWS\system32\xpsp2res.dll
2007-08-10 13:00 15,872 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-08-10 12:53 <DIR> d-------- C:\WINDOWS\EHome
2007-08-10 12:28 <DIR> d--hs---- C:\WINDOWS\Installer
2007-08-10 12:16 7,680 --a--c--- C:\WINDOWS\system32\dllcache\inetmgr.exe
2007-08-10 12:16 7,168 --a--c--- C:\WINDOWS\system32\dllcache\wamregps.dll
2007-08-10 12:16 6,144 --a--c--- C:\WINDOWS\system32\dllcache\ftpsapi2.dll
2007-08-10 12:16 5,632 --a--c--- C:\WINDOWS\system32\dllcache\iisrstap.dll
2007-08-10 12:16 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpsnap.dll
2007-08-10 12:16 19,968 --a--c--- C:\WINDOWS\system32\dllcache\inetsloc.dll
2007-08-10 12:16 175,104 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpadm.dll
2007-08-10 12:16 169,984 --a--c--- C:\WINDOWS\system32\dllcache\iisui.dll
2007-08-10 12:16 14,336 --a--c--- C:\WINDOWS\system32\dllcache\iisreset.exe
2007-08-10 12:15 <DIR> d-------- C:\WINDOWS\system32\xircom
2007-08-10 12:15 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-08-10 12:09 <DIR> d--hs---- C:\DOCUME~1\ALLUSE~1\DRM
2007-08-10 12:07 <DIR> d-------- C:\WINDOWS\system32\Macromed
2007-08-10 12:07 <DIR> d-------- C:\WINDOWS\srchasst
2007-08-10 12:06 520,192 --a--c--- C:\WINDOWS\system32\dllcache\wmpvis.dll
2007-08-10 12:06 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2007-08-10 12:06 319,551 --a--c--- C:\WINDOWS\system32\dllcache\wmmres.dll
2007-08-10 12:06 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-08-10 12:06 163,906 --a--c--- C:\WINDOWS\system32\dllcache\wmmutil.dll
2007-08-10 12:06 110,657 --a--c--- C:\WINDOWS\system32\dllcache\wmmfilt.dll
2007-08-10 12:02 21,640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-08-10 11:58 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2007-08-10 11:58 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2007-08-10 11:58 53,248 --a--c--- C:\WINDOWS\system32\dllcache\fwdprov.dll
2007-08-10 11:58 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2007-08-10 11:58 273,920 --a--c--- C:\WINDOWS\system32\dllcache\msiprov.dll
2007-08-10 11:58 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2007-08-10 11:58 185,344 --a------ C:\WINDOWS\system32\cmprops.dll
2007-08-10 11:58 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2007-08-10 11:58 120,320 --a--c--- C:\WINDOWS\system32\dllcache\dsprov.dll
2007-08-10 07:48 117,760 --a------ C:\WINDOWS\system32\drivers\e100b325.sys
2007-08-10 07:43 <DIR> dr------- C:\DOCUME~1\ALLUSE~1\Documents
2007-08-10 07:43 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-08-10 07:43 <DIR> d-------- C:\WINDOWS\system32\CatRoot


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2007-04-28 08:13]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2004-08-25 13:52]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\a-squared]
"C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

R3 laguna;laguna;C:\WINDOWS\system32\DRIVERS\cl546xm.sys
R3 wdm_opl3sax;YAMAHA OPL3-SAx Audio Driver (WDM);C:\WINDOWS\system32\drivers\opl3sax.sys
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys


Contents of the 'Scheduled Tasks' folder
2007-09-03 23:07:38 C:\WINDOWS\Tasks\At100.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 23:07:38 C:\WINDOWS\Tasks\At101.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 23:07:38 C:\WINDOWS\Tasks\At102.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 23:07:38 C:\WINDOWS\Tasks\At103.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 23:07:38 C:\WINDOWS\Tasks\At104.job
2007-09-03 23:07:38 C:\WINDOWS\Tasks\At105.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 13:00:01 C:\WINDOWS\Tasks\At106.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 14:00:00 C:\WINDOWS\Tasks\At107.job
2007-09-04 15:00:00 C:\WINDOWS\Tasks\At108.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:00:00 C:\WINDOWS\Tasks\At109.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 17:00:05 C:\WINDOWS\Tasks\At110.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:00:00 C:\WINDOWS\Tasks\At111.job
2007-09-05 19:00:00 C:\WINDOWS\Tasks\At112.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:00:00 C:\WINDOWS\Tasks\At113.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 21:00:52 C:\WINDOWS\Tasks\At114.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 22:01:20 C:\WINDOWS\Tasks\At115.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 23:00:00 C:\WINDOWS\Tasks\At116.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 00:00:00 C:\WINDOWS\Tasks\At117.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 01:00:00 C:\WINDOWS\Tasks\At118.job
2007-09-05 02:00:00 C:\WINDOWS\Tasks\At119.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 03:00:00 C:\WINDOWS\Tasks\At120.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 01:07:49 C:\WINDOWS\Tasks\At121.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 01:07:49 C:\WINDOWS\Tasks\At122.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 01:07:49 C:\WINDOWS\Tasks\At123.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 01:07:49 C:\WINDOWS\Tasks\At124.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 01:07:49 C:\WINDOWS\Tasks\At125.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 01:07:49 C:\WINDOWS\Tasks\At126.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 01:07:49 C:\WINDOWS\Tasks\At127.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 01:07:49 C:\WINDOWS\Tasks\At128.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 01:07:49 C:\WINDOWS\Tasks\At129.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 13:00:02 C:\WINDOWS\Tasks\At130.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 14:00:00 C:\WINDOWS\Tasks\At131.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 15:00:00 C:\WINDOWS\Tasks\At132.job
2007-09-05 16:00:00 C:\WINDOWS\Tasks\At133.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 17:00:05 C:\WINDOWS\Tasks\At134.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:00:00 C:\WINDOWS\Tasks\At135.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 19:00:00 C:\WINDOWS\Tasks\At136.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:00:00 C:\WINDOWS\Tasks\At137.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 21:27:03 C:\WINDOWS\Tasks\At138.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 22:13:23 C:\WINDOWS\Tasks\At139.job
2007-09-04 23:00:00 C:\WINDOWS\Tasks\At140.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 00:00:00 C:\WINDOWS\Tasks\At141.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 01:00:00 C:\WINDOWS\Tasks\At142.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 02:00:00 C:\WINDOWS\Tasks\At143.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 03:00:00 C:\WINDOWS\Tasks\At144.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At145.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At146.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At147.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At148.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At149.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At150.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At151.job
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At152.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At153.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At154.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At155.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At156.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At157.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 17:00:05 C:\WINDOWS\Tasks\At158.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:00:01 C:\WINDOWS\Tasks\At159.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 19:00:00 C:\WINDOWS\Tasks\At160.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:00:00 C:\WINDOWS\Tasks\At161.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 21:26:52 C:\WINDOWS\Tasks\At162.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 22:01:25 C:\WINDOWS\Tasks\At163.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At164.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At165.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At166.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At167.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:15:17 C:\WINDOWS\Tasks\At168.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At169.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At170.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At171.job
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At172.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At173.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At174.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At175.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At176.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At177.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At178.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At179.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At180.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At181.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At182.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At183.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 19:00:00 C:\WINDOWS\Tasks\At184.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:00:00 C:\WINDOWS\Tasks\At185.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 21:26:48 C:\WINDOWS\Tasks\At186.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 22:01:18 C:\WINDOWS\Tasks\At187.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At188.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At189.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At190.job
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At191.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:15:57 C:\WINDOWS\Tasks\At192.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:23 C:\WINDOWS\Tasks\At193.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:23 C:\WINDOWS\Tasks\At194.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:23 C:\WINDOWS\Tasks\At195.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:23 C:\WINDOWS\Tasks\At196.job
2007-09-05 20:31:23 C:\WINDOWS\Tasks\At197.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:23 C:\WINDOWS\Tasks\At198.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:23 C:\WINDOWS\Tasks\At199.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At200.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At201.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At202.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At203.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At204.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At205.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At206.job
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At207.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At208.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At209.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 21:26:56 C:\WINDOWS\Tasks\At210.job
2007-09-05 22:01:12 C:\WINDOWS\Tasks\At211.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At212.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At213.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At214.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At215.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:31:24 C:\WINDOWS\Tasks\At216.job - C:\WINDOWS\system32\winmds.exe
2007-09-02 23:57:37 C:\WINDOWS\Tasks\At25.job
2007-09-02 23:57:37 C:\WINDOWS\Tasks\At26.job - C:\WINDOWS\system32\winmds.exe
2007-09-02 23:57:37 C:\WINDOWS\Tasks\At27.job - C:\WINDOWS\system32\winmds.exe
2007-09-02 23:57:37 C:\WINDOWS\Tasks\At28.job - C:\WINDOWS\system32\winmds.exe
2007-09-02 23:57:37 C:\WINDOWS\Tasks\At29.job - C:\WINDOWS\system32\winmds.exe
2007-09-02 23:57:37 C:\WINDOWS\Tasks\At30.job - C:\WINDOWS\system32\winmds.exe
2007-09-02 23:57:37 C:\WINDOWS\Tasks\At31.job - C:\WINDOWS\system32\winmds.exe
2007-09-02 23:57:37 C:\WINDOWS\Tasks\At32.job - C:\WINDOWS\system32\winmds.exe
2007-09-02 23:57:37 C:\WINDOWS\Tasks\At33.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 13:00:02 C:\WINDOWS\Tasks\At34.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 14:00:00 C:\WINDOWS\Tasks\At35.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 15:00:00 C:\WINDOWS\Tasks\At36.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:00:00 C:\WINDOWS\Tasks\At37.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 17:00:05 C:\WINDOWS\Tasks\At38.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:00:01 C:\WINDOWS\Tasks\At39.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 19:00:00 C:\WINDOWS\Tasks\At40.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:00:00 C:\WINDOWS\Tasks\At41.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 21:27:01 C:\WINDOWS\Tasks\At42.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 22:01:16 C:\WINDOWS\Tasks\At43.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 23:00:00 C:\WINDOWS\Tasks\At44.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 00:00:00 C:\WINDOWS\Tasks\At45.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 01:00:00 C:\WINDOWS\Tasks\At46.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 02:00:00 C:\WINDOWS\Tasks\At47.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 03:00:00 C:\WINDOWS\Tasks\At48.job
2007-09-03 02:49:32 C:\WINDOWS\Tasks\At49.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 02:49:32 C:\WINDOWS\Tasks\At50.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 02:49:32 C:\WINDOWS\Tasks\At51.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 02:49:32 C:\WINDOWS\Tasks\At52.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 02:49:32 C:\WINDOWS\Tasks\At53.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 02:49:32 C:\WINDOWS\Tasks\At54.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 02:49:32 C:\WINDOWS\Tasks\At55.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 02:49:32 C:\WINDOWS\Tasks\At56.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 02:49:32 C:\WINDOWS\Tasks\At57.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 13:00:02 C:\WINDOWS\Tasks\At58.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 14:00:00 C:\WINDOWS\Tasks\At59.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 15:00:00 C:\WINDOWS\Tasks\At60.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:00:00 C:\WINDOWS\Tasks\At61.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 17:00:05 C:\WINDOWS\Tasks\At62.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:00:02 C:\WINDOWS\Tasks\At63.job
2007-09-05 19:00:00 C:\WINDOWS\Tasks\At64.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 20:00:00 C:\WINDOWS\Tasks\At65.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 22:01:22 C:\WINDOWS\Tasks\At66.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 22:00:07 C:\WINDOWS\Tasks\At67.job
2007-09-04 23:00:00 C:\WINDOWS\Tasks\At68.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 00:00:00 C:\WINDOWS\Tasks\At69.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 01:00:00 C:\WINDOWS\Tasks\At70.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 02:00:00 C:\WINDOWS\Tasks\At71.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 03:00:00 C:\WINDOWS\Tasks\At72.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 18:29:14 C:\WINDOWS\Tasks\At73.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 18:29:14 C:\WINDOWS\Tasks\At74.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 18:29:14 C:\WINDOWS\Tasks\At75.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 18:29:14 C:\WINDOWS\Tasks\At76.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 18:29:14 C:\WINDOWS\Tasks\At77.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 18:29:14 C:\WINDOWS\Tasks\At78.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 18:29:14 C:\WINDOWS\Tasks\At79.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 18:29:14 C:\WINDOWS\Tasks\At80.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 18:29:14 C:\WINDOWS\Tasks\At81.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 13:00:03 C:\WINDOWS\Tasks\At82.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 14:00:00 C:\WINDOWS\Tasks\At83.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 15:00:00 C:\WINDOWS\Tasks\At84.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 16:00:00 C:\WINDOWS\Tasks\At85.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 17:00:05 C:\WINDOWS\Tasks\At86.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 18:00:03 C:\WINDOWS\Tasks\At87.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 19:00:00 C:\WINDOWS\Tasks\At88.job
2007-09-05 20:00:00 C:\WINDOWS\Tasks\At89.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 21:40:24 C:\WINDOWS\Tasks\At90.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 22:01:29 C:\WINDOWS\Tasks\At91.job - C:\WINDOWS\system32\winmds.exe
2007-09-04 23:00:00 C:\WINDOWS\Tasks\At92.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 00:00:00 C:\WINDOWS\Tasks\At93.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 01:00:00 C:\WINDOWS\Tasks\At94.job
2007-09-05 02:00:01 C:\WINDOWS\Tasks\At95.job - C:\WINDOWS\system32\winmds.exe
2007-09-05 03:00:00 C:\WINDOWS\Tasks\At96.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 23:07:39 C:\WINDOWS\Tasks\At97.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 23:07:39 C:\WINDOWS\Tasks\At98.job - C:\WINDOWS\system32\winmds.exe
2007-09-03 23:07:39 C:\WINDOWS\Tasks\At99.job - C:\WINDOWS\system32\winmds.exe
2007-08-14 15:13:09 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
2007-08-14 15:13:06 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-05 18:53:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-05 19:02:06
C:\ComboFix-quarantined-files.txt ... 2007-09-05 19:02

--- E O F ---



#15 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:03:38 AM

Posted 06 September 2007 - 03:06 PM

Ok, before we do anything, you need to improve the protection on your PC.
You are missing one important program on that computer - an antivirus!
This is somewhat suicidal in today's digital world.

You need to install an antivirus program as soon as you can and run a complete scan of the computer.
AVG and Avast are excellent, free antivirus programs..
Never install more than one antivirus on your system - several together can cause problems and decrease performance.
After installing one and running a scan, post a new Hijackthis log.

Edited by D-Trojanator, 06 September 2007 - 03:06 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users