Registry key exists: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} (matches Adware.Virtumonde.193)
Registry key exists: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} (matches Adware.Virtumonde.193)
Registry key exists: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} (matches Adware.Virtumonde.200)
Registry key exists: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} (matches Adware.Virtumonde.200)
Registry key exists: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} (matches Agent.100)
Registry key exists: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} (matches Agent.100)
Trojan Hunter will not clear anything unless I buy their software. I am reluctant to do so because I am uncertain that it will be able to clear it. So then I downloaded HiJackThis, which led me to generating a report, which led me to this forum. I have periodically run ccleaner as well to clear up the registry. I looked at the startup items using the Startup Control Panel aplet and disabled the ones that appeared unnecessary. I did find some that seemed to not belong and could find little information on - these are listed amongst the items on the HKLM / Run tab:
name: 90c1020b, path: rundll32.exe "C:\WINDOWS\system32\zaputesu.dll",b
name: CPM93f23197, path: Rundll32.exe "c:\windows\system32\gizibena.dll",a
name: rohigisama, path: Rundll32.exe "C:\WINDOWS\system32\sivuferi.dll",s
I disabled all three using the Startup Control Panel aplet and restarted. After the restart, I looked at the control panel again and found that the CPM93f23197 and rohigisama entries now have one listed that is unchecked and a new identical line that is checked.
Next I followed the directions for generating the dds log and the text file to attach. Thank you in advance for any assistance you can provide.
The dds log is as follows:
DDS (Ver_09-02-01.01) - NTFSx86
Run by Family at 17:51:49.51 on Thu 02/12/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2559.1917 [GMT -8:00]
AV: Kaspersky Internet Security *On-access scanning enabled* (Updated)
FW: Kaspersky Internet Security *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\ALL PROGRAMS INSTALLED\ADOBE ACROBAT 8\Acrobat\Acrotray.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
E:\ALL PROGRAMS INSTALLED\Zune\ZuneLauncher.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
E:\ALL PROGRAMS INSTALLED\TrojanHunter 5.0\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\rundll32.exe
E:\ALL PROGRAMS INSTALLED\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
E:\ALL PROGRAMS INSTALLED\firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Documents and Settings\Family\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/?rs=1
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - e:\all programs installed\snag it 7.0\snagit 7\SnagItBHO.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
BHO: {59776df8-5c8f-4bca-e5a4-378d128c1595}: {5951c821-d873-4a5e-acb4-f8c58fd67795} - c:\windows\system32\vctkay.dll
BHO: {609d1be3-f970-428e-9ea1-446b1e2969b1} - c:\windows\system32\yojuyala.dll
BHO: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\4.1.805.4472\swg.dll
BHO: {C568B2DE-6B81-4992-AC24-AD8740FEB0D8} - No File
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - e:\all programs installed\snag it 7.0\snagit 7\SnagItIEAddin.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - e:\all programs installed\creative suite 3\/Adobe Contribute CS3/contributeieplugin.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll
EB: Encarta &Researcher: {9455301c-cf6b-11d3-a266-00c04f689c50} - c:\program files\common files\microsoft shared\encarta researcher\EROPROJ.DLL
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: &Research: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - e:\allpro~1\office~1\office12\REFIEBAR.DLL
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Acrobat Assistant 8.0] "e:\all programs installed\adobe acrobat 8\acrobat\Acrotray.exe"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Zune Launcher] "e:\all programs installed\zune\ZuneLauncher.exe"
mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe"
mRun: [THGuard] "e:\all programs installed\trojanhunter 5.0\THGuard.exe"
mRun: [CPM93f23197] Rundll32.exe "c:\windows\system32\gizibena.dll",a
mRun: [rohigisama] Rundll32.exe "c:\windows\system32\sivuferi.dll",s
IE: Add to Banner Ad Blocker - c:\program files\kaspersky lab\kaspersky internet security 2009\ie_banner_deny.htm
IE: Append to existing PDF - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - e:\all programs installed\adobe acrobat 8\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - e:\allpro~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - e:\allpro~1\office~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - e:\allpro~1\office~1\office12\REFIEBAR.DLL
IE: {9455301C-CF6B-11D3-A266-00C04F689C50} - {9455301C-CF6B-11D3-A266-00C04F689C50} - c:\program files\common files\microsoft shared\encarta researcher\EROPROJ.DLL
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://download.macromedia.com/pub/shockwave/cabs/authorware/awswaxf.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1205470030218
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - e:\all programs installed\office 2007\office12\GrooveSystemServices.dll
Handler: msero - {B0D92A71-886B-453B-A649-1B91F93801E7} - c:\program files\common files\microsoft shared\encarta researcher\MSERO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: klogon - c:\windows\system32\klogon.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Notify: yayvWpom - yayvWpom.dll
AppInit_DLLs: kvozfx.dll ypvcxv.dll c:\progra~1\kasper~1\kasper~1\mzvkbd.dll c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll c:\progra~1\kasper~1\kasper~1\adialhk.dll c:\progra~1\kasper~1\kasper~1\kloehk.dll c:\windows\system32\wahemoyu.dll c:\windows\system32\gizibena.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\gizibena.dll
STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\gizibena.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - e:\all programs installed\office 2007\office12\GrooveShellExtensions.dll
SEH: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - No File
LSA: Authentication Packages = msv1_0 c:\windows\system32\hgGywVME
LSA: Notification Packages = scecli c:\windows\system32\wahemoyu.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\family\applic~1\mozilla\firefox\profiles\q2e42d22.default\
FF - plugin: c:\program files\google\google updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: e:\all programs installed\adobe acrobat 8\acrobat\browser\nppdf32.dll
============= SERVICES / DRIVERS ===============
R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2008-7-21 121872]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-1-26 213520]
R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe [2008-7-29 206088]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-4-30 24592]
S3 USB-100;Linksys EtherFast 10/100 Compact USB Network Adapter;c:\windows\system32\drivers\USB100M.SYS [2008-3-13 27519]
=============== Created Last 30 ================
2009-02-12 16:45 81,920 a------- c:\windows\system32\Startup.cpl
2009-02-12 08:38 1,535,970 ---sh--- c:\windows\system32\usetupaz.ini
2009-02-12 08:38 144,093 a--sh--- c:\windows\system32\ghuykp.dll
2009-02-11 20:38 1,656,090 ---sh--- c:\windows\system32\itovodot.ini
2009-02-11 20:37 143,031 a--sh--- c:\windows\system32\pktcmn.dll
2009-02-11 08:37 143,189 a--sh--- c:\windows\system32\hwmwgl.dll
2009-02-11 08:37 1,656,090 ---sh--- c:\windows\system32\akuyaral.ini
2009-02-10 20:37 1,648,524 ---sh--- c:\windows\system32\abasotiz.ini
2009-02-10 20:37 140,924 a--sh--- c:\windows\system32\ezlkrd.dll
2009-02-10 20:37 2,713 ---sh--- c:\windows\system32\musesiwo.dll
2009-02-10 08:37 142,958 a--sh--- c:\windows\system32\appdqh.dll
2009-02-10 08:37 1,648,524 ---sh--- c:\windows\system32\aresayum.ini
2009-02-09 18:13 2,713 ---sh--- c:\windows\system32\gafilumu.dll
2009-02-09 18:13 1,640,608 ---sh--- c:\windows\system32\ehojobop.ini
2009-02-09 18:12 142,076 a--sh--- c:\windows\system32\vctkay.dll
2009-02-08 09:25 1,640,608 ---sh--- c:\windows\system32\ezadopub.ini
2009-02-08 09:25 2,713 ---sh--- c:\windows\system32\wasefotu.dll
2009-02-08 09:25 140,381 a--sh--- c:\windows\system32\xbtpji.dll
2009-02-07 21:25 1,634,237 ---sh--- c:\windows\system32\ezusohay.ini
2009-02-07 21:25 140,582 a--sh--- c:\windows\system32\mvictz.dll
2009-02-07 09:25 1,634,246 ---sh--- c:\windows\system32\ezehumul.ini
2009-02-07 09:24 141,936 a--sh--- c:\windows\system32\gijfxq.dll
2009-02-06 10:01 1,624,160 ---sh--- c:\windows\system32\iledagoz.ini
2009-02-06 09:19 2,713 ---sh--- c:\windows\system32\neletato.dll
2009-02-06 09:18 141,982 a--sh--- c:\windows\system32\ycgfaa.dll
2009-02-06 01:01 142,639 a--sh--- c:\windows\system32\suzqhz.dll
2009-02-05 13:07 1,622,634 ---sh--- c:\windows\system32\evofewew.ini
2009-02-05 13:01 142,647 a--sh--- c:\windows\system32\ruicoi.dll
2009-02-04 23:19 142,559 a--sh--- c:\windows\system32\bmttes.dll
2009-02-04 23:19 1,660,914 ---sh--- c:\windows\system32\atesokeg.ini
2009-02-04 11:19 142,549 a--sh--- c:\windows\system32\keqdfz.dll
2009-02-04 11:19 1,660,914 ---sh--- c:\windows\system32\otowiyuh.ini
2009-02-03 23:19 133,740 a--sh--- c:\windows\system32\gmnfrn.dll
2009-02-03 11:19 133,880 a--sh--- c:\windows\system32\cyjwhx.dll
2009-02-03 11:19 1,646,354 ---sh--- c:\windows\system32\arudigim.ini
2009-02-02 23:18 133,885 a--sh--- c:\windows\system32\iqgkqa.dll
2009-02-02 23:18 1,624,041 ---sh--- c:\windows\system32\oyenopag.ini
2009-02-02 22:18 1,624,041 ---sh--- c:\windows\system32\apakazoy.ini
2009-02-02 22:18 134,449 a--sh--- c:\windows\system32\knqrrf.dll
2009-02-02 10:18 1,624,041 ---sh--- c:\windows\system32\onisoyov.ini
2009-02-02 10:18 134,487 a--sh--- c:\windows\system32\qnvtyz.dll
2009-02-01 22:18 135,448 a--sh--- c:\windows\system32\cltzic.dll
2009-02-01 22:18 1,463,187 ---sh--- c:\windows\system32\ubezifit.ini
2009-02-01 10:18 1,463,187 ---sh--- c:\windows\system32\imawekiv.ini
2009-02-01 10:18 135,354 a--sh--- c:\windows\system32\gggcaw.dll
2009-02-01 09:17 1,463,187 ---sh--- c:\windows\system32\usayojis.ini
2009-01-31 21:17 1,463,187 ---sh--- c:\windows\system32\uruwotoz.ini
2009-01-31 21:17 2,713 ---sh--- c:\windows\system32\pifotamo.dll
2009-01-31 21:17 135,406 a--sh--- c:\windows\system32\ptwdtg.dll
2009-01-31 16:50 36,352 a------- c:\windows\system32\awttsSkh.dll
2009-01-31 16:50 36,352 a------- c:\windows\system32\efcDVmLb.dll
2009-01-31 09:17 1,463,187 ---sh--- c:\windows\system32\utizamiy.ini
2009-01-31 09:17 0 a------- c:\windows\system32\ukanedep.tmp
2009-01-31 09:17 2,713 ---sh--- c:\windows\system32\zibipudo.dll
2009-01-31 09:17 135,256 a--sh--- c:\windows\system32\wgmilb.dll
2009-01-30 21:17 1,463,196 ---sh--- c:\windows\system32\ukanedep.ini
2009-01-30 21:17 135,281 a--sh--- c:\windows\system32\hvvefy.dll
2009-01-30 09:16 135,246 a--sh--- c:\windows\system32\rehqej.dll
2009-01-30 09:16 1,463,187 ---sh--- c:\windows\system32\umidomav.ini
2009-01-29 20:15 1,463,190 ---sh--- c:\windows\system32\umarobom.ini
2009-01-29 20:15 135,390 a--sh--- c:\windows\system32\xordge.dll
2009-01-29 09:05 133,445 a------- c:\windows\system32\fjekei.dll
2009-01-29 08:14 1,463,190 ---sh--- c:\windows\system32\ipahidud.ini
2009-01-28 20:14 135,413 a--sh--- c:\windows\system32\zndohw.dll
2009-01-28 20:14 1,463,190 ---sh--- c:\windows\system32\ilowoyuw.ini
2009-01-28 20:14 2,713 ---sh--- c:\windows\system32\yegawogo.dll
2009-01-28 08:14 1,463,208 ---sh--- c:\windows\system32\imijuseh.ini
2009-01-28 08:14 133,408 a--sh--- c:\windows\system32\doviqt.dll
2009-01-27 20:14 1,464,327 ---sh--- c:\windows\system32\ejikegag.ini
2009-01-27 20:14 133,317 a--sh--- c:\windows\system32\dpfbvq.dll
2009-01-26 22:27 101,287 a------- c:\windows\system32\drivers\klin.dat
2009-01-26 22:27 89,601 a------- c:\windows\system32\drivers\klick.dat
2009-01-26 22:26 <DIR> --d----- c:\program files\Kaspersky Lab
2009-01-26 22:26 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab
2009-01-26 21:25 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-01-26 19:26 36,352 a------- c:\windows\system32\wvUooPHB.dll
2009-01-26 15:47 1,462,525 ---sh--- c:\windows\system32\ogoruweh.ini
2009-01-26 15:47 142,071 a--sh--- c:\windows\system32\rsaxad.dll
2009-01-26 13:59 140,916 a--sh--- c:\windows\system32\vhezvb.dll
2009-01-26 07:13 36,352 a------- c:\windows\system32\awtUolLF.dll
2009-01-26 07:13 36,352 a------- c:\windows\system32\qoMGWPfg.dll
2009-01-26 01:59 1,384,658 ---sh--- c:\windows\system32\alefuzeg.ini
2009-01-26 01:59 134,436 a--sh--- c:\windows\system32\xoaluz.dll
2009-01-25 13:58 1,646,354 ---sh--- c:\windows\system32\anuvubij.ini
2009-01-25 01:58 134,268 a--sh--- c:\windows\system32\yzavjf.dll
2009-01-25 01:58 1,384,676 ---sh--- c:\windows\system32\amuwuloh.ini
2009-01-24 21:41 36,864 a------- c:\windows\system32\opnlJBuS.dll
2009-01-24 21:41 36,864 a------- c:\windows\system32\urqNFyAS.dll
2009-01-24 13:59 1,384,676 ---sh--- c:\windows\system32\orufujud.ini
2009-01-24 12:12 36,864 a------- c:\windows\system32\efcCrsRh.dll
2009-01-24 12:12 36,864 a------- c:\windows\system32\vtUOEuVO.dll
2009-01-24 01:59 1,384,649 ---sh--- c:\windows\system32\ayisalup.ini
2009-01-23 13:57 134,378 a--sh--- c:\windows\system32\qjeuvg.dll
2009-01-22 18:56 134,339 a--sh--- c:\windows\system32\naobys.dll
2009-01-22 18:56 1,389,511 ---sh--- c:\windows\system32\amupuyad.ini
2009-01-22 06:57 1,389,502 ---sh--- c:\windows\system32\anikabaz.ini
2009-01-21 18:56 86 a------- c:\windows\wininit.ini
2009-01-21 18:56 1,389,502 ---sh--- c:\windows\system32\alobeley.ini
2009-01-21 06:56 1,389,502 ---sh--- c:\windows\system32\oyomutad.ini
2009-01-20 18:55 1,387,077 ---sh--- c:\windows\system32\ojakomig.ini
2009-01-20 06:56 1,366,413 ---sh--- c:\windows\system32\avihimip.ini
2009-01-19 18:56 1,361,851 ---sh--- c:\windows\system32\azeseper.ini
2009-01-19 06:55 1,358,531 ---sh--- c:\windows\system32\ekayutih.ini
2009-01-18 00:53 1,358,169 ---sh--- c:\windows\system32\efetenew.ini
2009-01-17 12:56 1,358,169 ---sh--- c:\windows\system32\ojekipok.ini
2009-01-17 00:56 1,358,147 ---sh--- c:\windows\system32\okuhepih.ini
2009-01-16 12:52 1,358,165 ---sh--- c:\windows\system32\alorudas.ini
2009-01-15 23:52 1,331,400 ---sh--- c:\windows\system32\ovulenod.ini
2009-01-15 11:51 1,331,400 ---sh--- c:\windows\system32\ojipokul.ini
2009-01-14 23:51 1,321,994 ---sh--- c:\windows\system32\iheyugup.ini
2009-01-14 11:51 1,321,994 ---sh--- c:\windows\system32\ayarahej.ini
2009-01-13 23:51 1,302,227 ---sh--- c:\windows\system32\ahubolup.ini
2009-01-13 22:05 1,305,407 a--sh--- c:\windows\system32\asegiwuz.ini
==================== Find3M ====================
2009-02-12 08:38 144,093 a--sh--- c:\windows\system32\zevopawe.dll
2009-02-12 08:38 109,872 a--sh--- c:\windows\system32\gizibena.dll
2009-02-12 08:38 95,418 a--sh--- c:\windows\system32\zaputesu.dll
2009-02-11 20:37 143,031 a--sh--- c:\windows\system32\hepotiza.dll
2009-02-11 20:37 108,705 a--sh--- c:\windows\system32\mefokugi.dll
2009-02-11 20:37 102,510 -------- c:\windows\system32\todovoti.dll
2009-02-11 08:37 143,189 a--sh--- c:\windows\system32\tojihiji.dll
2009-02-11 08:37 108,223 a--sh--- c:\windows\system32\giyesewu.dll
2009-02-11 08:37 102,121 -------- c:\windows\system32\larayuka.dll
2009-02-10 20:37 140,924 a--sh--- c:\windows\system32\juwefisi.dll
2009-02-10 20:37 108,303 a--sh--- c:\windows\system32\nularehi.dll
2009-02-10 20:37 102,122 -------- c:\windows\system32\zitosaba.dll
2009-02-10 08:37 142,958 a--sh--- c:\windows\system32\honumopi.dll
2009-02-10 08:37 108,328 a--sh--- c:\windows\system32\gogoheri.dll
2009-02-10 08:37 102,021 -------- c:\windows\system32\muyasera.dll
2009-02-09 18:12 142,076 a--sh--- c:\windows\system32\vosevodi.dll
2009-02-09 18:12 102,001 -------- c:\windows\system32\pobojohe.dll
2009-02-09 18:12 109,299 a--sh--- c:\windows\system32\hafedeku.dll
2009-02-08 21:25 103,067 a--sh--- c:\windows\system32\hiwiwepu.dll
2009-02-08 09:25 140,381 a--sh--- c:\windows\system32\fiwomuzu.dll
2009-02-08 09:25 108,836 a--sh--- c:\windows\system32\gesiwoha.dll
2009-02-07 21:25 140,582 a--sh--- c:\windows\system32\bizuzuti.dll
2009-02-07 21:25 107,663 a--sh--- c:\windows\system32\neyuvena.dll
2009-02-07 09:24 141,936 a--sh--- c:\windows\system32\beziseno.dll
2009-02-07 09:24 103,098 -------- c:\windows\system32\lumuheze.dll
2009-02-07 09:24 109,246 a--sh--- c:\windows\system32\lodayija.dll
2009-02-06 09:18 141,982 a--sh--- c:\windows\system32\juhiruma.dll
2009-02-06 09:18 108,691 a--sh--- c:\windows\system32\hisakite.dll
2009-02-06 09:18 103,085 -------- c:\windows\system32\zogadeli.dll
2009-02-06 01:01 101,549 a--sh--- c:\windows\system32\rofegivu.dll
2009-02-06 01:01 142,639 a--sh--- c:\windows\system32\legidonu.dll
2009-02-06 01:01 109,805 a--sh--- c:\windows\system32\sumavabu.dll
2009-02-05 13:01 142,647 a--sh--- c:\windows\system32\benituyo.dll
2009-02-05 13:01 109,173 a--sh--- c:\windows\system32\denufudu.dll
2009-02-05 13:01 101,523 a--sh--- c:\windows\system32\wewefove.dll
2009-02-04 23:19 142,559 a--sh--- c:\windows\system32\vulayinu.dll
2009-02-04 23:19 107,757 a--sh--- c:\windows\system32\fosuzopu.dll
2009-02-04 23:19 101,570 a--sh--- c:\windows\system32\gekoseta.dll
2009-02-04 11:19 142,549 a--sh--- c:\windows\system32\hekazemo.dll
2009-02-04 11:19 109,282 a--sh--- c:\windows\system32\vemogefi.dll
2009-02-04 11:19 101,468 -------- c:\windows\system32\huyiwoto.dll
2009-02-04 07:00 33,808 a------- c:\windows\system32\drivers\klbg.sys
2009-02-03 23:19 133,740 a--sh--- c:\windows\system32\sizulase.dll
2009-02-03 23:19 91,855 -------- c:\windows\system32\jibuvuna.dll
2009-02-03 23:19 98,935 a--sh--- c:\windows\system32\dejegima.dll
2009-02-03 11:19 133,880 a--sh--- c:\windows\system32\mililezu.dll
2009-02-03 11:19 99,425 a--sh--- c:\windows\system32\hahomehe.dll
2009-02-03 11:19 93,432 -------- c:\windows\system32\migidura.dll
2009-02-02 23:18 133,885 a--sh--- c:\windows\system32\mitudeju.dll
2009-02-02 23:18 99,609 a--sh--- c:\windows\system32\hesoyebu.dll
2009-02-02 23:18 93,433 -------- c:\windows\system32\gaponeyo.dll
2009-02-02 22:18 91,927 -------- c:\windows\system32\yozakapa.dll
2009-02-02 22:18 64,157 a--sh--- c:\windows\system32\sufafufo.dll
2009-02-02 22:18 134,449 a--sh--- c:\windows\system32\wejerafi.dll
2009-02-02 22:18 98,457 a--sh--- c:\windows\system32\kapidoma.dll
2009-02-02 10:18 93,455 -------- c:\windows\system32\voyosino.dll
2009-02-02 10:18 134,487 a--sh--- c:\windows\system32\sodejaro.dll
2009-02-02 10:18 98,934 a--sh--- c:\windows\system32\ralanagu.dll
2009-02-01 22:18 135,448 a--sh--- c:\windows\system32\nobafuno.dll
2009-02-01 22:18 86,213 -------- c:\windows\system32\tifizebu.dll
2009-02-01 22:18 99,071 a--sh--- c:\windows\system32\rapomapu.dll
2009-02-01 10:18 86,151 -------- c:\windows\system32\vikewami.dll
2009-02-01 10:18 135,354 a--sh--- c:\windows\system32\pizureke.dll
2009-02-01 10:18 100,491 a--sh--- c:\windows\system32\lanimaye.dll
2009-02-01 09:17 64,795 a--sh--- c:\windows\system32\guwakeba.dll
2009-02-01 09:17 100,498 a--sh--- c:\windows\system32\kaleguli.dll
2009-02-01 09:17 86,818 -------- c:\windows\system32\sijoyasu.dll
2009-01-31 21:17 135,406 a--sh--- c:\windows\system32\yijazowi.dll
2009-01-31 21:17 99,103 a--sh--- c:\windows\system32\hezigotu.dll
2009-01-31 21:17 86,831 -------- c:\windows\system32\zotowuru.dll
2009-01-31 09:17 86,829 -------- c:\windows\system32\yimazitu.dll
2009-01-31 09:17 135,256 a--sh--- c:\windows\system32\rezakaju.dll
2009-01-31 09:17 98,936 a--sh--- c:\windows\system32\muwatibi.dll
2009-01-30 21:17 135,281 a--sh--- c:\windows\system32\yoyamama.dll
2009-01-30 21:17 100,649 a--sh--- c:\windows\system32\gizisuyo.dll
2009-01-30 21:17 86,262 -------- c:\windows\system32\pedenaku.dll
2009-01-30 09:16 135,246 a--sh--- c:\windows\system32\lahofipe.dll
2009-01-30 09:16 99,127 a--sh--- c:\windows\system32\vefukufe.dll
2009-01-30 09:16 86,302 -------- c:\windows\system32\vamodimu.dll
2009-01-30 08:16 66,161 a--sh--- c:\windows\system32\pegizoto.dll.tmp
2009-01-29 20:15 135,390 a--sh--- c:\windows\system32\bohomipu.dll
2009-01-29 20:15 98,903 a--sh--- c:\windows\system32\kafehera.dll
2009-01-29 20:15 86,721 -------- c:\windows\system32\moboramu.dll
2009-01-29 09:05 133,445 a------- c:\windows\system32\nakojofa.dll
2009-01-29 08:14 100,668 a--sh--- c:\windows\system32\rufebapu.dll
2009-01-29 08:14 86,315 -------- c:\windows\system32\dudihapi.dll
2009-01-28 20:14 135,413 a--sh--- c:\windows\system32\genajiwe.dll
2009-01-28 20:14 100,506 a--sh--- c:\windows\system32\zumidiba.dll
2009-01-28 20:14 86,180 -------- c:\windows\system32\wuyowoli.dll
2009-01-28 08:14 133,408 a--sh--- c:\windows\system32\yivozizi.dll
2009-01-28 08:14 100,575 a--sh--- c:\windows\system32\segorado.dll
2009-01-28 08:14 86,266 -------- c:\windows\system32\hesujimi.dll
2009-01-27 23:17 100,582 a--sh--- c:\windows\system32\zubotoze.dll
2009-01-27 23:16 99,446 a--sh--- c:\windows\system32\zayitigi.dll
2009-01-27 23:16 66,118 a--sh--- c:\windows\system32\wuyedifu.dll
2009-01-27 23:16 66,118 a--sh--- c:\windows\system32\tuhiwuba.dll.tmp
2009-01-27 23:16 66,118 a--sh--- c:\windows\system32\tofegahe.dll.tmp
2009-01-27 23:16 66,161 a--sh--- c:\windows\system32\seholima.dll.tmp
2009-01-27 23:16 66,161 a--sh--- c:\windows\system32\sagufeho.dll
2009-01-27 23:16:08 A--SH--- 101,532 c:\windows\system32\pupigowu.dll
0000-00-00 00:00 108,032 a--sh--- c:\windows\system32\nujidaku.dll
0000-00-00 00:00 64,157 a--sh--- c:\windows\system32\sivuferi.dll
0000-00-00 00:00 81,920 a--sh--- c:\windows\system32\subalavi.dll
0000-00-00 00:00 64,157 a--sh--- c:\windows\system32\wahemoyu.dll
0000-00-00 00:00 64,157 a--sh--- c:\windows\system32\yojuyala.dll
============= FINISH: 17:53:17.45 ===============