Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hey Folks, need some help....website blocking malware of some kind..


  • Please log in to reply
21 replies to this topic

#1 ncdrawl

ncdrawl

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 10 June 2009 - 06:54 PM

DDS (Ver_09-05-14.01) - NTFSx86
Run by Teddy at 19:51:13.45 on Wed 06/10/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3326.2292 [GMT -4:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\AASP\1.00.40\aaCenter.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\JulaPAN.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Teddy\Downloads\hijackthis_sfx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Teddy\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearch Bar = Preserve
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\users\teddy\appdata\local\windows update\scvhost.exe,
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [JulaPAN.exe] JulaPAN.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab

================= FIREFOX ===================

FF - ProfilePath - c:\users\teddy\appdata\roaming\mozilla\firefox\profiles\fcdwzc5f.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\users\teddy\appdata\roaming\mozilla\firefox\profiles\fcdwzc5f.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll

============= SERVICES / DRIVERS ===============

R1 Jula.sys;Service for Juli@ Audio Driver EWDM;c:\windows\system32\drivers\Jula.sys [2009-3-29 48672]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\codemeter\runtime\bin\CodeMeter.exe [2008-12-17 1709376]
R3 JulaWDM.sys;Service for Juli@ WDM;c:\windows\system32\drivers\JulaWDM.sys [2009-3-29 35872]
S2 rqjpnc;Support Driver;c:\windows\system32\svchost.exe -k netsvcs [2008-3-27 21504]
S3 MagixASIODrv;MAGIX_ASIO_BoostDriver;c:\program files\magix\samplitude_10_pro\mxasio.sys [2009-2-8 4899]
S3 UsbFltr;Razer Copperhead Driver;c:\windows\system32\drivers\copperhd.sys [2005-11-2 11596]
S3 Winacusb;Winacusb;c:\windows\system32\drivers\winacusb.sys [2008-2-28 829952]

============== File Associations ===============

regfile=regedit.exe "%1" %*

=============== Created Last 30 ================

2009-06-10 19:33 4,096 a------- c:\windows\system32\097EB.tmp
2009-06-10 17:16 40,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-10 17:16 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-06-10 10:15 4,096 a------- c:\windows\system32\03E18.tmp
2009-06-10 03:53 4,096 a------- c:\windows\system32\0316B.tmp
2009-06-09 19:02 4,096 a------- c:\windows\system32\07F8B.tmp
2009-06-04 02:51 4,096 a------- c:\windows\system32\06DFE.tmp
2009-06-03 19:55 4,096 a------- c:\windows\system32\023C5.tmp
2009-06-03 18:49 4,096 a------- c:\windows\system32\08BF6.tmp
2009-06-02 13:01 <DIR> --d----- c:\program files\virtualdubmod
2009-06-02 12:56 31,232 a------- c:\windows\system\vdremote.dll
2009-06-02 12:56 25,088 a------- c:\windows\system\vdsvrlnk.dll
2009-05-28 09:29 889 a------- c:\windows\system32\dwuuaaph.exe
2009-05-27 21:29 155,648 a------- c:\windows\system32\ajcqtmor.exe

==================== Find3M ====================

2009-05-30 11:19 143,360 a------- c:\windows\inf\infstrng.dat
2009-05-30 11:19 51,200 a------- c:\windows\inf\infpub.dat
2009-05-30 11:19 86,016 a------- c:\windows\inf\infstor.dat
2009-05-09 01:37 737,280 a------- c:\windows\iun6002.exe
2009-04-29 16:23 87,608 a------- c:\users\teddy\appdata\roaming\inst.exe
2009-04-29 16:23 47,360 a------- c:\users\teddy\appdata\roaming\pcouffin.sys
2009-04-01 17:00 163,840 a------- c:\windows\system32\Updater.exe
2009-03-16 23:38 40,960 a------- c:\windows\apppatch\apihex86.dll
2009-03-16 23:38 13,824 a------- c:\windows\system32\apilogen.dll
2009-03-16 23:38 24,064 a------- c:\windows\system32\amxread.dll
2009-02-10 00:30 888,320 a------- c:\users\teddy\appdata\roaming\kernel33.dll
2009-02-10 00:30 153,092 a------- c:\users\teddy\appdata\roaming\1.exe
2008-10-23 19:28 691 a------- c:\users\teddy\appdata\roaming\GetValue.vbs
2008-10-23 19:28 35 a------- c:\users\teddy\appdata\roaming\SetValue.bat
2008-09-22 04:12 89 a------- c:\users\teddy\appdata\roaming\netstat.bat
2008-06-18 18:17 665,600 a------- c:\windows\inf\drvindex.dat
2008-03-27 04:05 174 a--sh--- c:\program files\desktop.ini
2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-02-13 04:49 168,509 a--shr-- c:\windows\system32\ygsjp.dll

============= FINISH: 19:51:27.68 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 ncdrawl

ncdrawl
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 12 June 2009 - 01:58 PM

shouldve given more background info... well, ive noticed my computer running slow lately..suspecting a virus issue, I tried to download MBAM, was blocked initially by the malware(had to go to a 3rd party hosting site to get it)..I was able to download it, but wasnt able to update at all!!!... ALL antivirus sites are blocked. microsoft update is blocked. all microsoft sites are blocked.

also, the fonts in my "error console" (the ones that say "XXX has stopped working would you like to 1.) close the program and look for a solution online 2.) close the program and log off..etc) have changed...i suspect this is a product of the malware too...

so I cannot download any A/V...and my computer is slow !

Hello ncdrawl,

We ask that once you have posted your log and are waiting, please DO NOT "bump" your thread or make further replies until it has been responded to by a member of the HJT Team. The reason we ask this or do not respond to your requests is because that would remove you from the active queue that Techs and Staff have access to. The malware staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response, there will be 1 reply. A team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond.

That is why I have made an edit to your last post, instead of a reply. Please do not multiple post here, as that only pushes you further down the queue and causes confusion to the staff.

Please be patient. It may take a while to get a response but your log will be reviewed and answered as soon as possible.

Thank you for understanding.

Regards,

The weatherman
(Moderator)

Edited by The weatherman, 14 June 2009 - 08:16 AM.


#3 RenatoMejias

RenatoMejias

  • Malware Response Team
  • 913 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:03 PM

Posted 19 June 2009 - 08:32 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below I will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE
Renato Victor Mejias
Malware help in portuguese
jetian6yw.jpg

#4 ncdrawl

ncdrawl
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 21 June 2009 - 12:13 AM

Thank you for your reply!! I have scanned with the malwarebytes program, but because I couldnt update the virus definitions, I feel that the scan was not optimal.

the info is posted/attached below.
(EDIT, I forgot to disconnect from the web when I ran the first DDS scan, so I rescanned and reposted the correct info below)



DDS (Ver_09-05-14.01) - NTFSx86
Run by Teddy at 1:20:56.66 on Sun 06/21/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13

============== Pseudo HJT Report ===============

uSearch Bar = Preserve
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\users\teddy\appdata\local\windows update\scvhost.exe,
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [JulaPAN.exe] JulaPAN.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab

================= FIREFOX ===================

FF - ProfilePath - c:\users\teddy\appdata\roaming\mozilla\firefox\profiles\fcdwzc5f.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\users\teddy\appdata\roaming\mozilla\firefox\profiles\fcdwzc5f.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll

============= SERVICES / DRIVERS ===============


============== File Associations ===============

regfile=regedit.exe "%1" %*

=============== Created Last 30 ================

2009-06-20 14:09 4,096 a------- c:\windows\system32\01A14.tmp
2009-06-20 07:16 4,096 a------- c:\windows\system32\01DDC.tmp
2009-06-17 23:37 4,096 a------- c:\windows\system32\01F90.tmp
2009-06-17 09:39 4,096 a------- c:\windows\system32\0751F.tmp
2009-06-17 00:01 4,096 a------- c:\windows\system32\0193A.tmp
2009-06-16 14:21 4,096 a------- c:\windows\system32\01534.tmp
2009-06-15 01:27 4,096 a------- c:\windows\system32\0C947.tmp
2009-06-14 19:58 <DIR> --d----- c:\program files\JRE
2009-06-14 18:25 4,096 a------- c:\windows\system32\0A717.tmp
2009-06-13 14:19 4,096 a------- c:\windows\system32\07389.tmp
2009-06-12 15:25 4,096 a------- c:\windows\system32\08499.tmp
2009-06-12 00:47 4,096 a------- c:\windows\system32\08738.tmp
2009-06-11 10:01 15,688 a------- c:\windows\system32\lsdelete.exe
2009-06-11 04:05 4,096 a------- c:\windows\system32\07722.tmp
2009-06-11 04:01 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-06-11 03:58 <DIR> -cd-h--- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-06-11 03:58 <DIR> -cd-h--- c:\progra~2\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-06-11 03:57 <DIR> --d----- c:\program files\Lavasoft
2009-06-11 03:51 78,336 a------- c:\windows\system32\Agent.OMZ.Fix.exe
2009-06-10 19:33 4,096 a------- c:\windows\system32\097EB.tmp
2009-06-10 17:16 40,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-10 17:16 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-06-10 10:15 4,096 a------- c:\windows\system32\03E18.tmp
2009-06-10 03:53 4,096 a------- c:\windows\system32\0316B.tmp
2009-06-09 19:02 4,096 a------- c:\windows\system32\07F8B.tmp
2009-06-04 02:51 4,096 a------- c:\windows\system32\06DFE.tmp
2009-06-03 19:55 4,096 a------- c:\windows\system32\023C5.tmp
2009-06-03 18:49 4,096 a------- c:\windows\system32\08BF6.tmp
2009-06-02 13:01 <DIR> --d----- c:\program files\virtualdubmod
2009-06-02 12:56 31,232 a------- c:\windows\system\vdremote.dll
2009-06-02 12:56 25,088 a------- c:\windows\system\vdsvrlnk.dll
2009-05-28 09:29 889 a------- c:\windows\system32\dwuuaaph.exe
2009-05-27 21:29 155,648 a------- c:\windows\system32\ajcqtmor.exe

==================== Find3M ====================

2009-06-11 03:52 691 a------- c:\users\teddy\appdata\roaming\GetValue.vbs
2009-06-11 03:52 35 a------- c:\users\teddy\appdata\roaming\SetValue.bat
2009-05-30 11:19 143,360 a------- c:\windows\inf\infstrng.dat
2009-05-30 11:19 51,200 a------- c:\windows\inf\infpub.dat
2009-05-30 11:19 86,016 a------- c:\windows\inf\infstor.dat
2009-05-09 01:37 737,280 a------- c:\windows\iun6002.exe
2009-04-29 16:23 87,608 a------- c:\users\teddy\appdata\roaming\inst.exe
2009-04-29 16:23 47,360 a------- c:\users\teddy\appdata\roaming\pcouffin.sys
2009-04-01 17:00 163,840 a------- c:\windows\system32\Updater.exe
2009-02-10 00:30 888,320 a------- c:\users\teddy\appdata\roaming\kernel33.dll
2009-02-10 00:30 153,092 a------- c:\users\teddy\appdata\roaming\1.exe
2008-09-22 04:12 89 a------- c:\users\teddy\appdata\roaming\netstat.bat
2008-06-18 18:17 665,600 a------- c:\windows\inf\drvindex.dat
2008-03-27 04:05 174 a--sh--- c:\program files\desktop.ini
2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-02-13 04:49 168,509 a--shr-- c:\windows\system32\ygsjp.dll

============= FINISH: 1:21:32.54 ===============

Attached Files


Edited by ncdrawl, 21 June 2009 - 12:26 AM.


#5 RenatoMejias

RenatoMejias

  • Malware Response Team
  • 913 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:03 PM

Posted 21 June 2009 - 11:42 AM

Hi ncdrawl,

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.
Renato Victor Mejias
Malware help in portuguese
jetian6yw.jpg

#6 ncdrawl

ncdrawl
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 21 June 2009 - 06:58 PM

Sir, I did not know if you wanted me to copy and paste the text or attach the .zip of the log...so I did both.




ComboFix 09-06-20.04 - Teddy 06/21/2009 19:38.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3326.2520 [GMT -4:00]
Running from: c:\users\Teddy\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-51003140-4199384537-3980697693-500
c:\$recycle.bin\S-1-5-21-51003140-4199384537-3980697693-500\desktop.ini
c:\users\Teddy\AppData\Roaming\1.exe
c:\users\Teddy\AppData\Roaming\inst.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\bwmqykgr.ini
c:\windows\system32\dnmlkfdq.ini
c:\windows\system32\iawhttky.ini
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\iewptubh.ini
c:\windows\system32\o4Patch.exe
c:\windows\system32\pbhxupih.ini
c:\windows\system32\Process.exe
c:\windows\system32\qhuqprcy.ini
c:\windows\system32\rcsxlubt.ini
c:\windows\system32\SrchSTS.exe
c:\windows\system32\Updater.exe
.
---- Previous Run -------
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_TDSSserv


((((((((((((((((((((((((( Files Created from 2009-05-21 to 2009-06-21 )))))))))))))))))))))))))))))))
.

2009-06-22 03:23 . 2009-06-22 03:23 -------- d-sh--w- C:\found.002
2009-06-21 23:42 . 2009-06-21 23:44 -------- d-----w- c:\users\Teddy\AppData\Local\temp
2009-06-14 23:58 . 2009-06-14 23:58 -------- d-----w- c:\program files\JRE
2009-06-11 14:01 . 2009-06-11 08:01 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-11 07:58 . 2009-06-11 07:58 -------- dc-h--w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-06-11 07:58 . 2009-01-18 21:43 2892112 -c--a-w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
2009-06-11 07:57 . 2009-06-11 07:57 -------- d-----w- c:\program files\Lavasoft
2009-06-10 21:16 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-10 21:16 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-02 17:01 . 2009-06-02 17:14 -------- d-----w- c:\program files\virtualdubmod
2009-06-02 16:56 . 2009-05-07 19:20 31232 ----a-w- c:\windows\system\vdremote.dll
2009-06-02 16:56 . 2009-05-07 19:19 25088 ----a-w- c:\windows\system\vdsvrlnk.dll
2009-05-28 13:29 . 2009-05-28 13:29 889 ----a-w- c:\windows\system32\dwuuaaph.exe
2009-05-28 01:29 . 2009-05-28 01:29 155648 ----a-w- c:\windows\system32\ajcqtmor.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-22 03:32 . 2009-01-25 19:04 -------- d-----w- c:\users\Teddy\AppData\Roaming\foobar2000
2009-06-22 03:32 . 2008-08-29 21:32 -------- d-----w- c:\users\Teddy\AppData\Roaming\IrfanView
2009-06-22 03:32 . 2008-03-11 05:01 -------- d-----w- c:\users\Teddy\AppData\Roaming\uTorrent
2009-06-21 23:44 . 2009-06-21 23:44 4096 ----a-w- c:\windows\system32\07C9E.tmp
2009-06-21 23:34 . 2009-06-21 23:34 4096 ----a-w- c:\windows\system32\05697.tmp
2009-06-21 15:33 . 2008-04-18 18:56 -------- d-----w- c:\users\Teddy\AppData\Roaming\Vso
2009-06-20 11:16 . 2009-06-20 11:16 4096 ----a-w- c:\windows\system32\01DDC.tmp
2009-06-18 20:30 . 2009-03-29 08:30 1 ----a-w- c:\users\Teddy\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-18 14:08 . 2009-02-24 00:59 -------- d-----w- c:\program files\AllToAVI
2009-06-18 03:37 . 2009-06-18 03:37 4096 ----a-w- c:\windows\system32\01F90.tmp
2009-06-17 13:39 . 2009-06-17 13:39 4096 ----a-w- c:\windows\system32\0751F.tmp
2009-06-17 05:13 . 2008-02-28 06:09 54360 ----a-w- c:\users\Teddy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-17 04:01 . 2009-06-17 04:01 4096 ----a-w- c:\windows\system32\0193A.tmp
2009-06-16 18:21 . 2009-06-16 18:21 4096 ----a-w- c:\windows\system32\01534.tmp
2009-06-15 05:27 . 2009-06-15 05:27 4096 ----a-w- c:\windows\system32\0C947.tmp
2009-06-15 00:02 . 2009-03-29 08:28 -------- d-----w- c:\program files\OpenOffice.org 3
2009-06-14 22:25 . 2009-06-14 22:25 4096 ----a-w- c:\windows\system32\0A717.tmp
2009-06-14 01:28 . 2008-10-23 06:56 -------- d-----w- c:\programdata\vsosdk
2009-06-13 18:19 . 2009-06-13 18:19 4096 ----a-w- c:\windows\system32\07389.tmp
2009-06-12 19:25 . 2009-06-12 19:25 4096 ----a-w- c:\windows\system32\08499.tmp
2009-06-12 16:24 . 2008-04-10 21:05 -------- d-----w- c:\users\Teddy\AppData\Roaming\GrabIt
2009-06-12 04:47 . 2009-06-12 04:47 4096 ----a-w- c:\windows\system32\08738.tmp
2009-06-11 08:05 . 2009-06-11 08:05 4096 ----a-w- c:\windows\system32\07722.tmp
2009-06-11 07:57 . 2008-03-31 07:30 -------- d-----w- c:\programdata\Lavasoft
2009-06-11 07:52 . 2008-10-23 22:59 691 ----a-w- c:\users\Teddy\AppData\Roaming\GetValue.vbs
2009-06-11 07:52 . 2008-10-23 22:59 35 ----a-w- c:\users\Teddy\AppData\Roaming\SetValue.bat
2009-06-11 07:52 . 2008-10-23 22:59 35 ----a-w- c:\users\Teddy\AppData\Roaming\SetValue.bat
2009-06-10 23:33 . 2009-06-10 23:33 4096 ----a-w- c:\windows\system32\097EB.tmp
2009-06-10 21:17 . 2008-10-23 22:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-10 14:15 . 2009-06-10 14:15 4096 ----a-w- c:\windows\system32\03E18.tmp
2009-06-10 07:53 . 2009-06-10 07:53 4096 ----a-w- c:\windows\system32\0316B.tmp
2009-06-09 23:02 . 2009-06-09 23:02 4096 ----a-w- c:\windows\system32\07F8B.tmp
2009-06-04 06:51 . 2009-06-04 06:51 4096 ----a-w- c:\windows\system32\06DFE.tmp
2009-06-03 23:55 . 2009-06-03 23:55 4096 ----a-w- c:\windows\system32\023C5.tmp
2009-06-03 23:49 . 2009-03-24 21:24 -------- d-----w- c:\users\Teddy\AppData\Roaming\U3
2009-06-03 22:49 . 2009-06-03 22:49 4096 ----a-w- c:\windows\system32\08BF6.tmp
2009-06-01 07:12 . 2009-01-25 19:03 -------- d-----w- c:\program files\foobar2000
2009-05-31 11:47 . 2008-02-28 22:24 -------- d-----w- c:\programdata\NVIDIA
2009-05-30 15:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-30 08:10 . 2008-04-18 18:27 -------- d-----w- c:\users\Teddy\AppData\Roaming\Download Manager
2009-05-26 09:19 . 2008-12-09 18:04 -------- d-----w- c:\program files\World of Warcraft
2009-05-26 04:34 . 2008-03-04 20:40 -------- d-----w- c:\program files\Java
2009-05-26 00:21 . 2008-12-08 20:39 -------- d-----w- c:\program files\xnews
2009-05-12 07:38 . 2008-10-19 07:29 -------- d-----w- c:\users\Teddy\AppData\Roaming\Folding@home-gpu
2009-05-09 05:38 . 2009-05-09 05:38 -------- d-----w- c:\program files\Common Files\Digidesign
2009-05-09 05:37 . 2009-05-09 05:38 737280 ----a-w- c:\windows\iun6002.exe
2009-05-09 05:22 . 2009-05-09 05:22 -------- d-----w- c:\program files\VSTPlugins
2009-05-07 22:33 . 2008-10-07 22:09 -------- d-----w- c:\program files\GrabIt
2009-04-29 20:23 . 2008-04-18 18:56 47360 ----a-w- c:\users\Teddy\AppData\Roaming\pcouffin.sys
2009-04-29 20:23 . 2008-04-18 18:56 47360 ----a-w- c:\users\Teddy\AppData\Roaming\pcouffin.sys
2009-04-29 20:23 . 2009-04-29 20:23 -------- d-----w- c:\program files\VSO
2009-04-24 00:06 . 2008-03-08 23:22 -------- d-----w- c:\programdata\DVD Shrink
2009-04-02 03:41 . 2009-01-30 00:11 8192 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl1.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-04-02 03:41 . 2009-01-30 00:11 30208 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-04-02 03:41 . 2009-01-30 00:11 14848 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl4.A961A077_4BD0_4C98_86BC_EE4A98CE550D.exe
2009-03-29 06:32 . 2008-03-11 20:52 1 ----a-w- c:\users\Teddy\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2008-09-14 08:20 . 2009-03-22 17:43 4688384 ----a-w- c:\program files\mozilla firefox\plugins\avcodec-51.dll
2008-09-14 08:20 . 2009-03-22 17:43 546304 ----a-w- c:\program files\mozilla firefox\plugins\libfreetype-6.dll
2009-02-13 08:49 . 2009-04-17 07:37 168509 --sha-r- c:\windows\System32\ygsjp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 92704]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-11 518488]
"JulaPAN.exe"="JulaPAN.exe" - c:\windows\System32\JulaPAN.exe [2009-02-04 481824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PlexTools Professional LE.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PlexTools Professional LE.lnk
backup=c:\windows\pss\PlexTools Professional LE.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CodeMeter Control Center.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
backup=c:\windows\pss\CodeMeter Control Center.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3185887781-3781085259-3947595314-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"= c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D33F7806-2CB4-454F-8CFE-56C3A33EAB2E}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{2ACFAA90-548A-4BBA-99A8-64BCCAB26309}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{96B7D768-2F8D-4932-A072-0F774C7905D6}"= UDP:13000:UTORRENT
"{41DB5475-3CF4-4641-A297-9EC7F3FF85EA}"= TCP:13000:UTORRENT
"{99C171B3-7399-4937-BFAE-885B8A447023}"= UDP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{8C35EE07-CBEA-46F0-8866-C7C32EB9A75C}"= TCP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{84717142-2F61-47F7-ACEA-75431BD8C278}"= UDP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{2FA31306-7FF6-457A-B70E-5723ADFE6089}"= TCP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"TCP Query User{2C3C48D0-2603-4ACF-A1E8-33C66B01319F}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{95B451FA-2140-446E-9183-1E04C514CE97}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{ADD7BB4B-D829-451C-83B0-741C5F19C678}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{DED1E21D-37A5-44C5-8995-255F40076CC1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D5250D3C-5D03-4C6B-8C6C-4E32BD98247E}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C363D80F-C842-4A1F-AB04-8730915520BE}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C0B24070-3B36-4553-AEEF-8F81FB8BE089}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A4799BD8-732F-4D38-9FE2-96EE426DFE88}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FF001CE8-1298-4A56-9B69-45D87A354AA8}"= UDP:c:\program files\World of Warcraft\WoW.exe:WoW
"{258A1CD6-BE09-4C14-AE19-D5E44C8C81A9}"= TCP:c:\program files\World of Warcraft\WoW.exe:WoW
"{F10A77FC-0EC7-4AD9-A1CB-0F35300C9E91}"= UDP:3724:wow
"{DB57C509-C923-4703-BD4A-A90DFA12A8B0}"= UDP:6112:wow
"{2D0238DA-4AF8-47CB-98F7-72EE184DD103}"= UDP:2965:jbmpgf
"{CEDB34AB-B7F1-4DE7-B77F-440112C1C20D}"= UDP:2965:jbmpgf

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"= c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [6/11/2009 04:01 64160]
R1 Jula.sys;Service for Juli@ Audio Driver EWDM;c:\windows\System32\drivers\Jula.sys [3/29/2009 17:16 48672]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [12/17/2008 05:00 1709376]
R3 JulaWDM.sys;Service for Juli@ WDM;c:\windows\System32\drivers\JulaWDM.sys [3/29/2009 17:16 35872]
S2 rqjpnc;Support Driver;c:\windows\system32\svchost.exe -k netsvcs [3/27/2008 03:39 21504]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 17:34 1005904]
S3 MagixASIODrv;MAGIX_ASIO_BoostDriver;c:\program files\MAGIX\Samplitude_10_Pro\mxasio.sys [2/8/2009 21:42 4899]
S3 UsbFltr;Razer Copperhead Driver;c:\windows\System32\drivers\copperhd.sys [11/2/2005 11:54 11596]
S3 Winacusb;Winacusb;c:\windows\System32\drivers\winacusb.sys [2/28/2008 18:44 829952]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
rqjpnc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
%SystemRoot%\system32\soundschemes2.exe /AddRegistration
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-TDSSwicc.sys


.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\users\Teddy\AppData\Roaming\Mozilla\Firefox\Profiles\fcdwzc5f.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\users\Teddy\AppData\Roaming\Mozilla\Firefox\Profiles\fcdwzc5f.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-21 19:44
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\rqjpnc]
"ServiceDll"="c:\windows\system32\ygsjp.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3185887781-3781085259-3947595314-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BC1DBFD0-09FF-12CB-A3C1-5DB73117E131}*]
"hahdnmpdhldjlfhb"=hex:6a,61,66,6c,67,6e,6b,6f,68,6a,66,69,6d,69,69,6d,65,65,
66,6b,00,00
"iabeofgpiefbdfbapl"=hex:6a,61,66,6c,67,6e,6b,6f,68,6a,66,69,6d,69,69,6d,65,65,
66,6b,00,01
"kapebjapllnlkjndjaggfe"=hex:62,62,6a,66,65,6e,68,68,6a,6c,61,63,66,6b,61,65,
64,64,6f,6a,62,6c,6d,65,69,69,67,66,6d,6b,61,6f,62,68,67,69,00,00

[HKEY_USERS\S-1-5-21-3185887781-3781085259-3947595314-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E9AD8944-04D7-927C-C958-3861DF7F9E16}*]
"iafhidpijjmjallafd"=hex:69,61,6b,64,6e,6e,6a,6e,63,66,62,64,63,70,6e,62,64,6f,
00,00
"hapgognmkdhmidbg"=hex:6a,61,6b,64,66,65,61,6e,6d,6f,6e,61,68,69,62,64,6f,6d,
6f,6e,00,00
"kahfkhbhcfaijpadddkppk"=hex:62,62,6e,66,6e,61,6b,64,6b,61,68,6a,61,70,6a,6e,
69,63,6b,6d,6b,62,61,6d,62,65,61,62,61,68,6e,70,66,63,6b,6a,00,00

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\ASUS\AASP\1.00.40\aaCenter.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\wbem\WMIADAP.exe
.
**************************************************************************
.
Completion time: 2009-06-21 19:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-21 23:49

Pre-Run: 96,043,995,136 bytes free
Post-Run: 95,839,649,792 bytes free

267 --- E O F --- 2009-05-30 15:20

Attached Files

  • Attached File  log.zip   5.65KB   3 downloads


#7 RenatoMejias

RenatoMejias

  • Malware Response Team
  • 913 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:03 PM

Posted 21 June 2009 - 07:45 PM

Hi,

Don't need attach anything.

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::

c:\windows\system32\dwuuaaph.exe
c:\windows\system32\ajcqtmor.exe
c:\windows\system32\07C9E.tmp
c:\windows\system32\05697.tmp
c:\windows\system32\01DDC.tmp
c:\windows\system32\01F90.tmp
c:\windows\system32\0751F.tmp
c:\windows\system32\0193A.tmp
c:\windows\system32\01534.tmp
c:\windows\system32\0C947.tmp
c:\windows\system32\0A717.tmp
c:\windows\system32\07389.tmp
c:\windows\system32\08499.tmp
c:\windows\system32\08738.tmp
c:\windows\system32\07722.tmp
c:\windows\system32\097EB.tmp
c:\windows\system32\03E18.tmp
c:\windows\system32\0316B.tmp
c:\windows\system32\07F8B.tmp
c:\windows\system32\06DFE.tmp
c:\windows\system32\023C5.tmp
c:\windows\system32\08BF6.tmp
c:\windows\System32\ygsjp.dll

DirLook::

c:\programdata\vsosdk

Driver::

rqjpnc

NetSvc::

rqjpnc

FireFox::

FF - ProfilePath - c:\users\Teddy\AppData\Roaming\Mozilla\Firefox\Profiles\fcdwzc5f.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\users\Teddy\AppData\Roaming\Mozilla\Firefox\Profiles\fcdwzc5f.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll

RegNull::

[HKEY_USERS\S-1-5-21-3185887781-3781085259-3947595314-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{BC1DBFD0-09FF-12CB-A3C1-5DB73117E131}*]


[HKEY_USERS\S-1-5-21-3185887781-3781085259-3947595314-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E9AD8944-04D7-927C-C958-3861DF7F9E16}*]


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Renato Victor Mejias
Malware help in portuguese
jetian6yw.jpg

#8 ncdrawl

ncdrawl
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 21 June 2009 - 08:10 PM

ComboFix 09-06-20.04 - Teddy 06/21/2009 21:00.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3326.2602 [GMT -4:00]
Running from: c:\users\Teddy\Desktop\ComboFix.exe
Command switches used :: c:\users\Teddy\Desktop\CFScript.txt
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

FILE ::
"c:\windows\system32\01534.tmp"
"c:\windows\system32\0193A.tmp"
"c:\windows\system32\01DDC.tmp"
"c:\windows\system32\01F90.tmp"
"c:\windows\system32\023C5.tmp"
"c:\windows\system32\0316B.tmp"
"c:\windows\system32\03E18.tmp"
"c:\windows\system32\05697.tmp"
"c:\windows\system32\06DFE.tmp"
"c:\windows\system32\07389.tmp"
"c:\windows\system32\0751F.tmp"
"c:\windows\system32\07722.tmp"
"c:\windows\system32\07C9E.tmp"
"c:\windows\system32\07F8B.tmp"
"c:\windows\system32\08499.tmp"
"c:\windows\system32\08738.tmp"
"c:\windows\system32\08BF6.tmp"
"c:\windows\system32\097EB.tmp"
"c:\windows\system32\0A717.tmp"
"c:\windows\system32\0C947.tmp"
"c:\windows\system32\ajcqtmor.exe"
"c:\windows\system32\dwuuaaph.exe"
"c:\windows\System32\ygsjp.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Teddy\AppData\Roaming\Mozilla\Firefox\Profiles\fcdwzc5f.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
c:\windows\system32\01534.tmp
c:\windows\system32\0193A.tmp
c:\windows\system32\01DDC.tmp
c:\windows\system32\01F90.tmp
c:\windows\system32\023C5.tmp
c:\windows\system32\0316B.tmp
c:\windows\system32\03E18.tmp
c:\windows\system32\05697.tmp
c:\windows\system32\06DFE.tmp
c:\windows\system32\07389.tmp
c:\windows\system32\0751F.tmp
c:\windows\system32\07722.tmp
c:\windows\system32\07C9E.tmp
c:\windows\system32\07F8B.tmp
c:\windows\system32\08499.tmp
c:\windows\system32\08738.tmp
c:\windows\system32\08BF6.tmp
c:\windows\system32\097EB.tmp
c:\windows\system32\0A717.tmp
c:\windows\system32\0C947.tmp
c:\windows\system32\ajcqtmor.exe
c:\windows\system32\dwuuaaph.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_rqjpnc


((((((((((((((((((((((((( Files Created from 2009-05-22 to 2009-06-22 )))))))))))))))))))))))))))))))
.

2009-06-22 03:23 . 2009-06-22 03:23 -------- d-sh--w- C:\found.002
2009-06-22 01:02 . 2009-06-22 01:04 -------- d-----w- c:\users\Teddy\AppData\Local\temp
2009-06-22 00:52 . 2009-06-22 00:52 -------- d-----w- c:\program files\Boilsoft Video Joiner
2009-06-14 23:58 . 2009-06-14 23:58 -------- d-----w- c:\program files\JRE
2009-06-11 14:01 . 2009-06-11 08:01 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-11 07:58 . 2009-06-11 07:58 -------- dc-h--w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-06-11 07:58 . 2009-01-18 21:43 2892112 -c--a-w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
2009-06-11 07:57 . 2009-06-11 07:57 -------- d-----w- c:\program files\Lavasoft
2009-06-10 21:16 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-10 21:16 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-02 17:01 . 2009-06-02 17:14 -------- d-----w- c:\program files\virtualdubmod
2009-06-02 16:56 . 2009-05-07 19:20 31232 ----a-w- c:\windows\system\vdremote.dll
2009-06-02 16:56 . 2009-05-07 19:19 25088 ----a-w- c:\windows\system\vdsvrlnk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-22 03:32 . 2009-01-25 19:04 -------- d-----w- c:\users\Teddy\AppData\Roaming\foobar2000
2009-06-22 03:32 . 2008-08-29 21:32 -------- d-----w- c:\users\Teddy\AppData\Roaming\IrfanView
2009-06-22 03:32 . 2008-03-11 05:01 -------- d-----w- c:\users\Teddy\AppData\Roaming\uTorrent
2009-06-22 00:47 . 2009-06-22 00:47 4096 ----a-w- c:\windows\system32\0754E.tmp
2009-06-21 15:33 . 2008-04-18 18:56 -------- d-----w- c:\users\Teddy\AppData\Roaming\Vso
2009-06-18 20:30 . 2009-03-29 08:30 1 ----a-w- c:\users\Teddy\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-18 14:08 . 2009-02-24 00:59 -------- d-----w- c:\program files\AllToAVI
2009-06-17 05:13 . 2008-02-28 06:09 54360 ----a-w- c:\users\Teddy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-15 00:02 . 2009-03-29 08:28 -------- d-----w- c:\program files\OpenOffice.org 3
2009-06-14 01:28 . 2008-10-23 06:56 -------- d-----w- c:\programdata\vsosdk
2009-06-12 16:24 . 2008-04-10 21:05 -------- d-----w- c:\users\Teddy\AppData\Roaming\GrabIt
2009-06-11 07:57 . 2008-03-31 07:30 -------- d-----w- c:\programdata\Lavasoft
2009-06-11 07:52 . 2008-10-23 22:59 691 ----a-w- c:\users\Teddy\AppData\Roaming\GetValue.vbs
2009-06-11 07:52 . 2008-10-23 22:59 35 ----a-w- c:\users\Teddy\AppData\Roaming\SetValue.bat
2009-06-11 07:52 . 2008-10-23 22:59 35 ----a-w- c:\users\Teddy\AppData\Roaming\SetValue.bat
2009-06-10 21:17 . 2008-10-23 22:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-03 23:49 . 2009-03-24 21:24 -------- d-----w- c:\users\Teddy\AppData\Roaming\U3
2009-06-01 07:12 . 2009-01-25 19:03 -------- d-----w- c:\program files\foobar2000
2009-05-31 11:47 . 2008-02-28 22:24 -------- d-----w- c:\programdata\NVIDIA
2009-05-30 15:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-30 08:10 . 2008-04-18 18:27 -------- d-----w- c:\users\Teddy\AppData\Roaming\Download Manager
2009-05-26 09:19 . 2008-12-09 18:04 -------- d-----w- c:\program files\World of Warcraft
2009-05-26 04:34 . 2008-03-04 20:40 -------- d-----w- c:\program files\Java
2009-05-26 00:21 . 2008-12-08 20:39 -------- d-----w- c:\program files\xnews
2009-05-12 07:38 . 2008-10-19 07:29 -------- d-----w- c:\users\Teddy\AppData\Roaming\Folding@home-gpu
2009-05-09 05:38 . 2009-05-09 05:38 -------- d-----w- c:\program files\Common Files\Digidesign
2009-05-09 05:37 . 2009-05-09 05:38 737280 ----a-w- c:\windows\iun6002.exe
2009-05-09 05:22 . 2009-05-09 05:22 -------- d-----w- c:\program files\VSTPlugins
2009-05-07 22:33 . 2008-10-07 22:09 -------- d-----w- c:\program files\GrabIt
2009-04-29 20:23 . 2008-04-18 18:56 47360 ----a-w- c:\users\Teddy\AppData\Roaming\pcouffin.sys
2009-04-29 20:23 . 2008-04-18 18:56 47360 ----a-w- c:\users\Teddy\AppData\Roaming\pcouffin.sys
2009-04-29 20:23 . 2009-04-29 20:23 -------- d-----w- c:\program files\VSO
2009-04-24 00:06 . 2008-03-08 23:22 -------- d-----w- c:\programdata\DVD Shrink
2009-04-02 03:41 . 2009-01-30 00:11 8192 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl1.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-04-02 03:41 . 2009-01-30 00:11 30208 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-04-02 03:41 . 2009-01-30 00:11 14848 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl4.A961A077_4BD0_4C98_86BC_EE4A98CE550D.exe
2009-03-29 06:32 . 2008-03-11 20:52 1 ----a-w- c:\users\Teddy\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2008-09-14 08:20 . 2009-03-22 17:43 4688384 ----a-w- c:\program files\mozilla firefox\plugins\avcodec-51.dll
2008-09-14 08:20 . 2009-03-22 17:43 546304 ----a-w- c:\program files\mozilla firefox\plugins\libfreetype-6.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\vsosdk ----

2009-06-14 01:28 . 2009-06-14 01:28 47 ----a-w- c:\programdata\vsosdk\95BC209E76615B2700DC3DCD2FA88E93770462FF8FF473714FAFF01F7F6A8BF5.vsoact
2008-10-23 06:56 . 2008-10-23 06:56 47 ----a-w- c:\programdata\vsosdk\123C1010C8D6410C97B7D19381D68EC9C0A3FC5012971684FD22C9F9F731A8EE.vsoact


((((((((((((((((((((((((((((( SnapShot@2009-06-21_23.44.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-02-28 22:25 . 2009-06-22 00:48 46944 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:03 . 2009-06-22 00:48 63184 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:00 . 2009-06-21 23:44 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:00 . 2009-06-22 00:47 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:00 . 2009-06-22 00:47 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:00 . 2009-06-21 23:44 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-02-28 06:11 . 2009-06-22 00:48 8754 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3185887781-3781085259-3947595314-1000_UserData.bin
- 2006-11-02 10:33 . 2009-06-21 23:40 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-06-22 00:52 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-06-21 23:40 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-06-22 00:52 101144 c:\windows\System32\perfc009.dat
- 2006-11-02 13:00 . 2009-06-21 23:44 114688 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:00 . 2009-06-22 00:47 114688 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 92704]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-11 518488]
"JulaPAN.exe"="JulaPAN.exe" - c:\windows\System32\JulaPAN.exe [2009-02-04 481824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PlexTools Professional LE.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PlexTools Professional LE.lnk
backup=c:\windows\pss\PlexTools Professional LE.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CodeMeter Control Center.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
backup=c:\windows\pss\CodeMeter Control Center.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3185887781-3781085259-3947595314-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"= c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D33F7806-2CB4-454F-8CFE-56C3A33EAB2E}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{2ACFAA90-548A-4BBA-99A8-64BCCAB26309}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{96B7D768-2F8D-4932-A072-0F774C7905D6}"= UDP:13000:UTORRENT
"{41DB5475-3CF4-4641-A297-9EC7F3FF85EA}"= TCP:13000:UTORRENT
"{99C171B3-7399-4937-BFAE-885B8A447023}"= UDP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{8C35EE07-CBEA-46F0-8866-C7C32EB9A75C}"= TCP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{84717142-2F61-47F7-ACEA-75431BD8C278}"= UDP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{2FA31306-7FF6-457A-B70E-5723ADFE6089}"= TCP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"TCP Query User{2C3C48D0-2603-4ACF-A1E8-33C66B01319F}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{95B451FA-2140-446E-9183-1E04C514CE97}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{ADD7BB4B-D829-451C-83B0-741C5F19C678}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{DED1E21D-37A5-44C5-8995-255F40076CC1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D5250D3C-5D03-4C6B-8C6C-4E32BD98247E}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C363D80F-C842-4A1F-AB04-8730915520BE}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C0B24070-3B36-4553-AEEF-8F81FB8BE089}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A4799BD8-732F-4D38-9FE2-96EE426DFE88}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FF001CE8-1298-4A56-9B69-45D87A354AA8}"= UDP:c:\program files\World of Warcraft\WoW.exe:WoW
"{258A1CD6-BE09-4C14-AE19-D5E44C8C81A9}"= TCP:c:\program files\World of Warcraft\WoW.exe:WoW
"{F10A77FC-0EC7-4AD9-A1CB-0F35300C9E91}"= UDP:3724:wow
"{DB57C509-C923-4703-BD4A-A90DFA12A8B0}"= UDP:6112:wow
"{2D0238DA-4AF8-47CB-98F7-72EE184DD103}"= UDP:2965:jbmpgf
"{CEDB34AB-B7F1-4DE7-B77F-440112C1C20D}"= UDP:2965:jbmpgf

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"= c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [6/11/2009 04:01 64160]
R1 Jula.sys;Service for Juli@ Audio Driver EWDM;c:\windows\System32\drivers\Jula.sys [3/29/2009 17:16 48672]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [12/17/2008 05:00 1709376]
R3 JulaWDM.sys;Service for Juli@ WDM;c:\windows\System32\drivers\JulaWDM.sys [3/29/2009 17:16 35872]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 17:34 1005904]
S3 MagixASIODrv;MAGIX_ASIO_BoostDriver;c:\program files\MAGIX\Samplitude_10_Pro\mxasio.sys [2/8/2009 21:42 4899]
S3 UsbFltr;Razer Copperhead Driver;c:\windows\System32\drivers\copperhd.sys [11/2/2005 11:54 11596]
S3 Winacusb;Winacusb;c:\windows\System32\drivers\winacusb.sys [2/28/2008 18:44 829952]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
%SystemRoot%\system32\soundschemes2.exe /AddRegistration
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\users\Teddy\AppData\Roaming\Mozilla\Firefox\Profiles\fcdwzc5f.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-21 21:04
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\ASUS\AASP\1.00.40\aaCenter.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2009-06-22 21:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-22 01:07
ComboFix2.txt 2009-06-21 23:49

Pre-Run: 95,935,557,632 bytes free
Post-Run: 95,844,093,952 bytes free

272 --- E O F --- 2009-05-30 15:20

#9 RenatoMejias

RenatoMejias

  • Malware Response Team
  • 913 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:03 PM

Posted 22 June 2009 - 10:03 PM

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Renato Victor Mejias
Malware help in portuguese
jetian6yw.jpg

#10 ncdrawl

ncdrawl
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 23 June 2009 - 08:23 AM

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Tuesday, June 23, 2009
Operating System: Microsoft Windows Vista Ultimate Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Tuesday, June 23, 2009 06:19:56
Records in database: 2382141
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan statistics:
Files scanned: 122175
Threat name: 4
Infected objects: 25
Suspicious objects: 0
Duration of the scan: 01:38:21


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\Users\Teddy\AppData\Roaming\1.exe.vir Infected: Backdoor.Win32.Shark.bvg 1
C:\Qoobox\Quarantine\C\Windows\System32\01534.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\0193A.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\01DDC.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\01F90.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\023C5.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\0316B.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\03E18.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\05697.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\06DFE.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\07389.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\0751F.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\07722.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\07C9E.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\07F8B.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\08499.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\08738.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\08BF6.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\097EB.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\0A717.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\0C947.tmp.vir Infected: Net-Worm.Win32.Kido.jq 1
C:\Qoobox\Quarantine\C\Windows\System32\Updater.exe.vir Infected: Backdoor.Win32.MoSucker.30.by 1
C:\Qoobox\Quarantine\C\Windows\System32\_ygsjp_.dll.zip Infected: Net-Worm.Win32.Kido.ih 1
C:\Qoobox\Quarantine\[4]-Submit_2009-06-21_21.00.33.zip Infected: Net-Worm.Win32.Kido.ih 1
C:\Windows\System32\ygsjp.dll Infected: Net-Worm.Win32.Kido.ih 1

The selected area was scanned.

#11 RenatoMejias

RenatoMejias

  • Malware Response Team
  • 913 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:03 PM

Posted 23 June 2009 - 08:48 PM

Hi,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::

C:\Windows\System32\ygsjp.dll


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Renato Victor Mejias
Malware help in portuguese
jetian6yw.jpg

#12 ncdrawl

ncdrawl
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 23 June 2009 - 11:34 PM

ComboFix 09-06-23.01 - Teddy 06/24/2009 0:27.3 - NTFSx86
Running from: c:\users\Teddy\Desktop\ComboFix.exe
Command switches used :: c:\users\Teddy\Desktop\CFScript.txt
.

((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-06-24 )))))))))))))))))))))))))))))))
.

2009-06-24 04:30 . 2009-06-24 04:30 -------- d-----w- c:\users\Teddy\AppData\Local\temp
2009-06-23 15:41 . 2009-06-23 15:41 41439382 ----a-w- c:\users\Teddy\walking_01.zip
2009-06-23 05:34 . 2009-06-23 05:43 -------- d-----w- c:\users\Teddy\AppData\Roaming\ImgBurn
2009-06-23 05:26 . 2009-06-23 05:26 -------- d-----w- c:\program files\ImgBurn
2009-06-22 03:23 . 2009-06-22 03:23 -------- d-sh--w- C:\found.002
2009-06-22 02:27 . 2009-06-22 02:27 3561743 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-14 23:58 . 2009-06-14 23:58 -------- d-----w- c:\program files\JRE
2009-06-11 08:01 . 2009-06-22 02:23 -------- dc----w- c:\windows\system32\DRVSTORE
2009-06-11 07:58 . 2009-06-22 02:23 -------- dc-h--w- c:\programdata\~0
2009-06-11 07:58 . 2009-01-18 21:43 2892112 -c----w- c:\programdata\~0\Ad-AwareAE.exe
2009-06-11 07:57 . 2009-06-22 02:23 -------- d-----w- c:\program files\Lavasoft
2009-06-10 21:16 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-10 21:16 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-02 17:01 . 2009-06-02 17:14 -------- d-----w- c:\program files\virtualdubmod
2009-06-02 16:56 . 2009-05-07 19:20 31232 ----a-w- c:\windows\system\vdremote.dll
2009-06-02 16:56 . 2009-05-07 19:19 25088 ----a-w- c:\windows\system\vdsvrlnk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 00:50 . 2009-03-18 06:00 -------- d-----w- c:\programdata\PopCap Games
2009-06-24 00:50 . 2009-03-18 06:00 -------- d-----w- c:\program files\PopCap Games
2009-06-24 00:31 . 2009-06-24 00:31 4096 ----a-w- c:\windows\system32\0DAF7.tmp
2009-06-23 21:15 . 2009-01-25 19:04 -------- d-----w- c:\users\Teddy\AppData\Roaming\foobar2000
2009-06-23 21:01 . 2008-03-11 05:01 -------- d-----w- c:\users\Teddy\AppData\Roaming\uTorrent
2009-06-22 03:32 . 2008-08-29 21:32 -------- d-----w- c:\users\Teddy\AppData\Roaming\IrfanView
2009-06-22 02:27 . 2008-10-23 22:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-22 02:23 . 2008-03-31 07:30 -------- d-----w- c:\programdata\Lavasoft
2009-06-22 00:47 . 2009-06-22 00:47 4096 ----a-w- c:\windows\system32\0754E.tmp
2009-06-21 15:33 . 2008-04-18 18:56 -------- d-----w- c:\users\Teddy\AppData\Roaming\Vso
2009-06-18 20:30 . 2009-03-29 08:30 1 ----a-w- c:\users\Teddy\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-18 14:08 . 2009-02-24 00:59 -------- d-----w- c:\program files\AllToAVI
2009-06-17 05:13 . 2008-02-28 06:09 54360 ----a-w- c:\users\Teddy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-15 00:02 . 2009-03-29 08:28 -------- d-----w- c:\program files\OpenOffice.org 3
2009-06-14 01:28 . 2008-10-23 06:56 -------- d-----w- c:\programdata\vsosdk
2009-06-12 16:24 . 2008-04-10 21:05 -------- d-----w- c:\users\Teddy\AppData\Roaming\GrabIt
2009-06-11 07:52 . 2008-10-23 22:59 691 ----a-w- c:\users\Teddy\AppData\Roaming\GetValue.vbs
2009-06-11 07:52 . 2008-10-23 22:59 35 ----a-w- c:\users\Teddy\AppData\Roaming\SetValue.bat
2009-06-11 07:52 . 2008-10-23 22:59 35 ----a-w- c:\users\Teddy\AppData\Roaming\SetValue.bat
2009-06-03 23:49 . 2009-03-24 21:24 -------- d-----w- c:\users\Teddy\AppData\Roaming\U3
2009-06-01 07:12 . 2009-01-25 19:03 -------- d-----w- c:\program files\foobar2000
2009-05-31 11:47 . 2008-02-28 22:24 -------- d-----w- c:\programdata\NVIDIA
2009-05-30 15:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-30 08:10 . 2008-04-18 18:27 -------- d-----w- c:\users\Teddy\AppData\Roaming\Download Manager
2009-05-26 09:19 . 2008-12-09 18:04 -------- d-----w- c:\program files\World of Warcraft
2009-05-26 04:34 . 2008-03-04 20:40 -------- d-----w- c:\program files\Java
2009-05-26 00:21 . 2008-12-08 20:39 -------- d-----w- c:\program files\xnews
2009-05-12 07:38 . 2008-10-19 07:29 -------- d-----w- c:\users\Teddy\AppData\Roaming\Folding@home-gpu
2009-05-09 05:38 . 2009-05-09 05:38 -------- d-----w- c:\program files\Common Files\Digidesign
2009-05-09 05:37 . 2009-05-09 05:38 737280 ----a-w- c:\windows\iun6002.exe
2009-05-09 05:22 . 2009-05-09 05:22 -------- d-----w- c:\program files\VSTPlugins
2009-05-07 22:33 . 2008-10-07 22:09 -------- d-----w- c:\program files\GrabIt
2009-04-29 20:23 . 2008-04-18 18:56 47360 ----a-w- c:\users\Teddy\AppData\Roaming\pcouffin.sys
2009-04-29 20:23 . 2008-04-18 18:56 47360 ----a-w- c:\users\Teddy\AppData\Roaming\pcouffin.sys
2009-04-29 20:23 . 2009-04-29 20:23 -------- d-----w- c:\program files\VSO
2009-04-02 03:41 . 2009-01-30 00:11 8192 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl1.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-04-02 03:41 . 2009-01-30 00:11 30208 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-04-02 03:41 . 2009-01-30 00:11 14848 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl4.A961A077_4BD0_4C98_86BC_EE4A98CE550D.exe
2009-03-29 06:32 . 2008-03-11 20:52 1 ----a-w- c:\users\Teddy\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2008-09-14 08:20 . 2009-03-22 17:43 4688384 ----a-w- c:\program files\mozilla firefox\plugins\avcodec-51.dll
2008-09-14 08:20 . 2009-03-22 17:43 546304 ----a-w- c:\program files\mozilla firefox\plugins\libfreetype-6.dll
2009-02-13 08:49 . 2009-04-17 07:37 168509 --sha-r- c:\windows\System32\ygsjp.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-21_23.44.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-22 02:40 . 2009-05-12 22:35 71680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.22874_none_a8fbc5698d994fda\iesetup.dll
+ 2009-06-22 02:40 . 2009-05-12 22:35 55808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.22874_none_a8fbc5698d994fda\iernonce.dll
+ 2009-06-22 02:40 . 2009-05-09 05:34 71680 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18783_none_a86658687484b2aa\iesetup.dll
+ 2009-06-22 02:40 . 2009-05-09 05:34 55808 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18783_none_a86658687484b2aa\iernonce.dll
+ 2009-06-22 02:40 . 2009-05-12 22:49 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.22874_none_e51403c2d0f31852\WininetPlugin.dll
+ 2009-06-22 02:40 . 2009-05-12 22:36 25600 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.22874_none_e51403c2d0f31852\jsproxy.dll
+ 2009-06-22 02:40 . 2009-05-09 05:50 64512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18783_none_e47e96c1b7de7b22\WininetPlugin.dll
+ 2009-06-22 02:40 . 2009-05-09 05:35 25600 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18783_none_e47e96c1b7de7b22\jsproxy.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 18944 c:\windows\winsxs\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.21051_none_372af3e22ffed0a6\ehtrace.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 18944 c:\windows\winsxs\x86_microsoft-windows-ehome-ehtrace_31bf3856ad364e35_6.0.6000.16856_none_36a6806716dc7c4d\ehtrace.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 21504 c:\windows\winsxs\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.21051_none_2e4be1e29e60eb10\ehdebug.dll
+ 2009-06-22 02:40 . 2009-04-30 12:41 21504 c:\windows\winsxs\x86_microsoft-windows-ehome-ehdebug_31bf3856ad364e35_6.0.6000.16856_none_2dc76e67853e96b7\ehdebug.dll
+ 2009-06-22 02:40 . 2009-04-30 12:09 77824 c:\windows\winsxs\msil_ehiextens_31bf3856ad364e35_6.0.6000.21051_none_fc39e70a22fc10d2\ehiExtens.dll
+ 2009-06-22 02:40 . 2009-04-30 12:55 77824 c:\windows\winsxs\msil_ehiextens_31bf3856ad364e35_6.0.6000.16856_none_fbb5738f09d9bc79\ehiExtens.dll
+ 2008-02-28 22:25 . 2009-06-22 02:16 46944 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:03 . 2009-06-22 02:16 63216 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:00 . 2009-06-24 00:50 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:00 . 2009-06-21 23:44 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:00 . 2009-06-21 23:44 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:00 . 2009-06-24 00:50 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-22 02:40 . 2009-04-30 12:17 6656 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22423_none_34a0ebecf3254d51\McrMgr.dll
+ 2008-03-27 07:41 . 2008-01-19 03:34 6656 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18254_none_33f7ddc1da1f1d8a\McrMgr.dll
+ 2009-06-22 02:40 . 2009-04-30 12:02 6656 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.21051_none_3298132af61913a0\McrMgr.dll
+ 2009-06-22 02:40 . 2009-04-30 12:44 6656 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16856_none_32139fafdcf6bf47\McrMgr.dll
+ 2008-03-01 17:46 . 2009-06-22 02:13 2740 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-02-28 06:11 . 2009-06-22 02:16 8906 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3185887781-3781085259-3947595314-1000_UserData.bin
+ 2009-06-22 02:41 . 2009-06-24 00:31 4096 c:\windows\SoftwareDistribution\PostRebootEventCache\{963DC417-FA1B-4077-BECA-D1FD63B8572B}.bin
+ 2009-06-22 02:15 . 2009-06-22 02:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-06-22 02:15 . 2009-06-22 02:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-06-22 02:40 . 2009-04-30 12:19 293376 c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.22423_none_dc743bad703abfa3\psisdecd.dll
+ 2009-06-22 02:40 . 2009-04-30 12:37 293376 c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6001.18254_none_dbcb2d8257348fdc\psisdecd.dll
+ 2009-06-22 02:40 . 2009-04-30 12:06 292352 c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.21051_none_da6b62eb732e85f2\psisdecd.dll
+ 2009-06-22 02:40 . 2009-04-30 12:52 292352 c:\windows\winsxs\x86_microsoft-windows-v..e-filters-tvdigital_31bf3856ad364e35_6.0.6000.16856_none_d9e6ef705a0c3199\psisdecd.dll
+ 2009-06-22 02:40 . 2009-04-30 12:19 428544 c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.22423_none_e0ef19f3a791bbf8\EncDec.dll
+ 2009-06-22 02:40 . 2009-04-30 12:37 428544 c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6001.18254_none_e0460bc88e8b8c31\EncDec.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 428032 c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.21051_none_dee64131aa858247\EncDec.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 428032 c:\windows\winsxs\x86_microsoft-windows-tvencdec_31bf3856ad364e35_6.0.6000.16856_none_de61cdb691632dee\EncDec.dll
+ 2009-06-22 02:39 . 2009-04-23 12:24 784896 c:\windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6002.22120_none_b65513a45b6873a4\rpcrt4.dll
+ 2009-06-22 02:39 . 2009-04-23 12:15 784896 c:\windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6002.18024_none_b5cf780142473936\rpcrt4.dll
+ 2009-06-22 02:39 . 2009-04-23 12:39 784896 c:\windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6001.22417_none_b48073ae5e33b3f0\rpcrt4.dll
+ 2009-06-22 02:39 . 2009-04-23 12:43 784896 c:\windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6001.18247_none_b3d66539452e6ad2\rpcrt4.dll
+ 2009-06-22 02:39 . 2009-04-23 12:33 788992 c:\windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6000.21045_none_b2779aec61277a3f\rpcrt4.dll
+ 2009-06-22 02:39 . 2009-04-23 13:01 788992 c:\windows\winsxs\x86_microsoft-windows-rpc-local_31bf3856ad364e35_6.0.6000.16850_none_b1de54a148164471\rpcrt4.dll
+ 2009-06-22 02:39 . 2009-04-23 12:22 623616 c:\windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6002.22120_none_3275d288a9023d20\localspl.dll
+ 2009-06-22 02:39 . 2009-04-23 12:14 623616 c:\windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6002.18024_none_31f036e58fe102b2\localspl.dll
+ 2009-06-22 02:39 . 2009-04-23 12:39 636928 c:\windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6001.22417_none_30a13292abcd7d6c\localspl.dll
+ 2009-06-22 02:39 . 2009-04-23 12:42 636928 c:\windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6001.18247_none_2ff7241d92c8344e\localspl.dll
+ 2009-06-22 02:39 . 2009-04-23 12:29 697856 c:\windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6000.21045_none_2e9859d0aec143bb\localspl.dll
+ 2009-06-22 02:39 . 2009-04-23 12:56 696832 c:\windows\winsxs\x86_microsoft-windows-p..ooler-core-localspl_31bf3856ad364e35_6.0.6000.16850_none_2dff138595b00ded\localspl.dll
+ 2009-06-22 02:40 . 2009-05-12 22:35 164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.22874_none_47cd7ce4dd3f0fb5\ieui.dll
+ 2009-06-22 02:40 . 2009-05-09 05:34 164352 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18783_none_47380fe3c42a7285\ieui.dll
+ 2009-06-22 02:40 . 2009-05-12 20:35 173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.22874_none_a8fbc5698d994fda\ie4uinit.exe
+ 2009-06-22 02:40 . 2009-05-09 03:36 173056 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_8.0.6001.18783_none_a86658687484b2aa\ie4uinit.exe
+ 2009-06-22 02:40 . 2009-05-12 22:48 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.22874_none_2aceba9ebba436af\sqmapi.dll
+ 2009-06-22 02:40 . 2009-05-09 05:48 129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18783_none_2a394d9da28f997f\sqmapi.dll
+ 2009-06-22 02:40 . 2009-05-12 22:35 197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.22874_none_2ab8403ac959093f\IEShims.dll
+ 2009-06-22 02:40 . 2009-05-09 05:34 197632 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_8.0.6001.18783_none_2a22d339b0446c0f\IEShims.dll
+ 2009-06-22 02:40 . 2009-05-12 22:35 246272 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.22874_none_7359f4a479b0a2d1\ieproxy.dll
+ 2009-06-22 02:40 . 2009-05-09 05:34 246272 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_8.0.6001.18783_none_72c487a3609c05a1\ieproxy.dll
+ 2009-06-22 02:39 . 2009-05-09 13:09 102912 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.22873_none_84199871600b10ee\iecompat.dll
+ 2009-06-22 02:39 . 2009-05-09 03:37 102912 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.18783_none_83852bba46f58d15\iecompat.dll
+ 2009-06-22 02:40 . 2009-05-12 22:34 385536 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.22874_none_577b7cbe869d3919\iedkcs32.dll
+ 2009-06-22 02:40 . 2009-05-09 05:34 385536 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_8.0.6001.18783_none_56e60fbd6d889be9\iedkcs32.dll
+ 2009-06-22 02:40 . 2009-05-12 22:49 915456 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.22874_none_e51403c2d0f31852\wininet.dll
+ 2009-06-22 02:40 . 2009-05-09 05:50 915456 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18783_none_e47e96c1b7de7b22\wininet.dll
+ 2009-06-22 02:40 . 2009-04-30 10:34 253952 c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.22423_none_4bdfc1ce6de6cf39\ehvid.exe
+ 2009-06-22 02:40 . 2009-04-30 10:28 253952 c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6001.18254_none_4b36b3a354e09f72\ehvid.exe
+ 2009-06-22 02:40 . 2009-04-30 10:19 253952 c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.21051_none_49d6e90c70da9588\ehvid.exe
+ 2009-06-22 02:40 . 2009-04-30 10:42 253952 c:\windows\winsxs\x86_microsoft-windows-ehome-ehvid_31bf3856ad364e35_6.0.6000.16856_none_4952759157b8412f\ehvid.exe
+ 2009-06-22 02:40 . 2009-04-30 12:16 522240 c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.22423_none_cf3b1fcee292dd5c\ehui.dll
+ 2009-06-22 02:40 . 2009-04-30 12:33 522240 c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6001.18254_none_ce9211a3c98cad95\ehui.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 521728 c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.21051_none_cd32470ce586a3ab\ehui.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 517632 c:\windows\winsxs\x86_microsoft-windows-ehome-ehui_31bf3856ad364e35_6.0.6000.16856_none_ccadd391cc644f52\ehui.dll
+ 2009-06-22 02:40 . 2009-04-30 12:16 105472 c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.22423_none_273f9b1b7b253f90\ehPresenter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:33 105472 c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6001.18254_none_26968cf0621f0fc9\ehPresenter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 105472 c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.21051_none_2536c2597e1905df\ehPresenter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:41 105472 c:\windows\winsxs\x86_microsoft-windows-ehome-ehpresenter_31bf3856ad364e35_6.0.6000.16856_none_24b24ede64f6b186\ehPresenter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:01 278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.22126_none_3019d864cf578034\ehPlayer.dll
+ 2009-06-22 02:40 . 2009-04-30 11:47 278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6002.18030_none_2f7f69f1b6476451\ehPlayer.dll
+ 2009-06-22 02:40 . 2009-04-30 12:16 278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.22423_none_2e30659ed233df0b\ehPlayer.dll
+ 2009-06-22 02:40 . 2009-04-30 12:33 278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6001.18254_none_2d875773b92daf44\ehPlayer.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 278528 c:\windows\winsxs\x86_microsoft-windows-ehome-ehplayer_31bf3856ad364e35_6.0.6000.21051_none_2c278cdcd527a55a\ehPlayer.dll
+ 2009-06-22 02:40 . 2009-04-30 12:16 373248 c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.22423_none_2fb2ddfc834d299c\ehglid.dll
+ 2009-06-22 02:40 . 2009-04-30 12:33 373248 c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6001.18254_none_2f09cfd16a46f9d5\ehglid.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 372736 c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.21051_none_2daa053a8640efeb\ehglid.dll
+ 2009-06-22 02:40 . 2009-04-30 12:41 372224 c:\windows\winsxs\x86_microsoft-windows-ehome-ehglid_31bf3856ad364e35_6.0.6000.16856_none_2d2591bf6d1e9b92\ehglid.dll
+ 2009-06-22 02:40 . 2009-04-30 11:47 173056 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.22423_none_34a0ebecf3254d51\McrMgr.exe
+ 2009-06-22 02:40 . 2009-04-30 12:00 173056 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18254_none_33f7ddc1da1f1d8a\McrMgr.exe
+ 2009-06-22 02:40 . 2009-04-30 11:31 173056 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.21051_none_3298132af61913a0\McrMgr.exe
+ 2009-06-22 02:40 . 2009-04-30 12:09 173056 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6000.16856_none_32139fafdcf6bf47\McrMgr.exe
+ 2009-06-22 02:40 . 2009-04-30 12:16 254464 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.22423_none_152e7b96b8dde8f3\ehReplay.dll
+ 2009-06-22 02:40 . 2009-04-30 12:33 254464 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6001.18254_none_14856d6b9fd7b92c\ehReplay.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 254464 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.21051_none_1325a2d4bbd1af42\ehReplay.dll
+ 2009-06-22 02:40 . 2009-04-30 12:41 252416 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-ehreplay_31bf3856ad364e35_6.0.6000.16856_none_12a12f59a2af5ae9\ehReplay.dll
+ 2009-06-22 02:40 . 2009-04-30 12:19 180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.22423_none_ce9aa784e2f278f7\cbva.dll
+ 2009-06-22 02:40 . 2009-04-30 12:37 180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6001.18254_none_cdf19959c9ec4930\cbva.dll
+ 2009-06-22 02:40 . 2009-04-30 11:59 180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.21051_none_cc91cec2e5e63f46\cbva.dll
+ 2009-06-22 02:40 . 2009-04-30 12:40 180224 c:\windows\winsxs\x86_microsoft-windows-ehome-cbva_31bf3856ad364e35_6.0.6000.16856_none_cc0d5b47ccc3eaed\cbva.dll
+ 2009-06-22 02:40 . 2009-04-30 12:06 212992 c:\windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.22126_none_27de1592e29b9884\Microsoft.MediaCenter.dll
+ 2009-06-22 02:40 . 2009-04-30 11:54 212992 c:\windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6002.18030_none_2743a71fc98b7ca1\Microsoft.MediaCenter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:21 212992 c:\windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.22423_none_25f4a2cce577f75b\Microsoft.MediaCenter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 212992 c:\windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6001.18254_none_254b94a1cc71c794\Microsoft.MediaCenter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:09 225280 c:\windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.21051_none_23ebca0ae86bbdaa\Microsoft.MediaCenter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:56 225280 c:\windows\winsxs\msil_microsoft.mediacenter_31bf3856ad364e35_6.0.6000.16856_none_2367568fcf496951\Microsoft.MediaCenter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:06 188416 c:\windows\winsxs\msil_mcstore_31bf3856ad364e35_6.0.6002.22126_none_c7f9169954229812\mcstore.dll
+ 2009-06-22 02:40 . 2009-04-30 11:54 188416 c:\windows\winsxs\msil_mcstore_31bf3856ad364e35_6.0.6002.18030_none_c75ea8263b127c2f\mcstore.dll
+ 2009-06-22 02:40 . 2009-04-30 12:21 188416 c:\windows\winsxs\msil_mcstore_31bf3856ad364e35_6.0.6001.22423_none_c60fa3d356fef6e9\mcstore.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 188416 c:\windows\winsxs\msil_mcstore_31bf3856ad364e35_6.0.6001.18254_none_c56695a83df8c722\mcstore.dll
+ 2009-06-22 02:40 . 2009-04-30 12:09 212992 c:\windows\winsxs\msil_mcstore_31bf3856ad364e35_6.0.6000.21051_none_c406cb1159f2bd38\mcstore.dll
+ 2009-06-22 02:40 . 2009-04-30 12:55 212992 c:\windows\winsxs\msil_mcstore_31bf3856ad364e35_6.0.6000.16856_none_c382579640d068df\mcstore.dll
+ 2009-06-22 02:40 . 2009-04-30 12:06 532480 c:\windows\winsxs\msil_ehrecobj_31bf3856ad364e35_6.0.6002.22126_none_8d41cc615e8201b1\ehRecObj.dll
+ 2009-06-22 02:40 . 2009-04-30 11:54 532480 c:\windows\winsxs\msil_ehrecobj_31bf3856ad364e35_6.0.6002.18030_none_8ca75dee4571e5ce\ehRecObj.dll
+ 2009-06-22 02:40 . 2009-04-30 12:21 532480 c:\windows\winsxs\msil_ehrecobj_31bf3856ad364e35_6.0.6001.22423_none_8b58599b615e6088\ehRecObj.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 532480 c:\windows\winsxs\msil_ehrecobj_31bf3856ad364e35_6.0.6001.18254_none_8aaf4b70485830c1\ehRecObj.dll
+ 2009-06-22 02:40 . 2009-04-30 12:09 532480 c:\windows\winsxs\msil_ehrecobj_31bf3856ad364e35_6.0.6000.21051_none_894f80d9645226d7\ehRecObj.dll
+ 2009-06-22 02:40 . 2009-04-30 12:55 532480 c:\windows\winsxs\msil_ehrecobj_31bf3856ad364e35_6.0.6000.16856_none_88cb0d5e4b2fd27e\ehRecObj.dll
+ 2009-06-22 02:40 . 2009-04-30 12:09 135168 c:\windows\winsxs\msil_ehexthost_31bf3856ad364e35_6.0.6000.21051_none_bd56e025daf6b2dd\ehexthost.exe
+ 2009-06-22 02:40 . 2009-04-30 12:55 135168 c:\windows\winsxs\msil_ehexthost_31bf3856ad364e35_6.0.6000.16856_none_bcd26caac1d45e84\ehexthost.exe
+ 2009-06-22 02:40 . 2009-04-30 12:06 839680 c:\windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6002.22126_none_de03aef7e5372a6c\ehepg.dll
+ 2009-06-22 02:40 . 2009-04-30 11:54 839680 c:\windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6002.18030_none_dd694084cc270e89\ehepg.dll
+ 2009-06-22 02:40 . 2009-04-30 12:21 839680 c:\windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6001.22423_none_dc1a3c31e8138943\ehepg.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 839680 c:\windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6001.18254_none_db712e06cf0d597c\ehepg.dll
+ 2009-06-22 02:40 . 2009-04-30 12:09 876544 c:\windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6000.21051_none_da11636feb074f92\ehepg.dll
+ 2009-06-22 02:40 . 2009-04-30 12:55 876544 c:\windows\winsxs\msil_ehepg_31bf3856ad364e35_6.0.6000.16856_none_d98ceff4d1e4fb39\ehepg.dll
- 2006-11-02 10:33 . 2009-06-21 23:40 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-06-24 00:33 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-06-24 00:33 101144 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-06-21 23:40 101144 c:\windows\System32\perfc009.dat
- 2006-11-02 13:00 . 2009-06-21 23:44 114688 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:00 . 2009-06-24 00:50 114688 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-06-22 02:39 . 2009-04-21 11:42 2034688 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6002.22119_none_bb61c0cdb0cab623\win32k.sys
+ 2009-06-22 02:39 . 2009-04-21 11:39 2034688 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6002.18023_none_bac7525a97ba9a40\win32k.sys
+ 2009-06-22 02:39 . 2009-04-21 13:26 2034176 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.22416_none_b9784e07b3a714fa\win32k.sys
+ 2009-06-22 02:39 . 2009-04-21 11:55 2033152 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.18246_none_b8ce3f929aa1cbdc\win32k.sys
+ 2009-06-22 02:39 . 2009-04-21 11:55 2030080 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6000.21044_none_b76f7545b69adb49\win32k.sys
+ 2009-06-22 02:39 . 2009-04-21 12:04 2028032 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6000.16849_none_b6eb01ca9d7886f0\win32k.sys
+ 2009-05-30 14:51 . 2009-04-14 07:03 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22435_none_f2f64e4f84abbcec\OESpamFilter.dat
+ 2009-05-30 14:51 . 2009-04-14 07:03 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18259_none_f25b10ee6b9abd39\OESpamFilter.dat
+ 2009-05-30 14:51 . 2009-04-14 07:03 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21056_none_f0fb46578794b34f\OESpamFilter.dat
+ 2009-05-30 14:51 . 2009-04-14 07:03 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16860_none_f060ffc26e84642a\OESpamFilter.dat
+ 2009-06-22 02:40 . 2009-04-30 12:02 1244672 c:\windows\winsxs\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.21051_none_3d9893fe7ba30b35\mcmde.dll
+ 2009-06-22 02:40 . 2009-04-30 12:44 1244672 c:\windows\winsxs\x86_microsoft-windows-m..mediadeliveryengine_31bf3856ad364e35_6.0.6000.16856_none_3d1420836280b6dc\mcmde.dll
+ 2009-06-22 02:40 . 2009-05-12 22:35 1985024 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.22874_none_2aceba9ebba436af\iertutil.dll
+ 2009-06-22 02:40 . 2009-05-09 05:34 1985024 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18783_none_2a394d9da28f997f\iertutil.dll
+ 2009-06-22 02:40 . 2009-05-12 22:39 5936128 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.22874_none_f66e22e151498188\mshtml.dll
+ 2009-06-22 02:40 . 2009-05-09 05:38 5936128 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.18783_none_f5d8b5e03834e458\mshtml.dll
+ 2009-06-22 02:40 . 2009-05-12 22:48 1207808 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.22874_none_980e282105e9f1bf\urlmon.dll
+ 2009-06-22 02:40 . 2009-05-09 05:49 1207808 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.18783_none_9778bb1fecd5548f\urlmon.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 1498112 c:\windows\winsxs\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.21051_none_3a793943475c584d\ehuihlp.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 1497088 c:\windows\winsxs\x86_microsoft-windows-ehome-ehuihlp_31bf3856ad364e35_6.0.6000.16856_none_39f4c5c82e3a03f4\ehuihlp.dll
+ 2009-06-22 02:40 . 2009-04-30 12:17 1384960 c:\windows\winsxs\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.22423_none_3685ee5032972d7f\Mcx2Filter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:34 1384960 c:\windows\winsxs\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6001.18254_none_35dce0251990fdb8\Mcx2Filter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:03 1384960 c:\windows\winsxs\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.21051_none_347d158e358af3ce\Mcx2Filter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:44 1384960 c:\windows\winsxs\x86_microsoft-windows-e..-devices-mcx2filter_31bf3856ad364e35_6.0.6000.16856_none_33f8a2131c689f75\Mcx2Filter.dll
+ 2009-06-22 02:40 . 2009-04-30 12:06 1970176 c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.22126_none_3582bc9f6d832c6e\Microsoft.MediaCenter.UI.dll
+ 2009-06-22 02:40 . 2009-04-30 11:54 1970176 c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6002.18030_none_34e84e2c5473108b\Microsoft.MediaCenter.UI.dll
+ 2009-06-22 02:40 . 2009-04-30 12:21 1970176 c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.22423_none_339949d9705f8b45\Microsoft.MediaCenter.UI.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 1970176 c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6001.18254_none_32f03bae57595b7e\Microsoft.MediaCenter.UI.dll
+ 2009-06-22 02:40 . 2009-04-30 12:09 2363392 c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.21051_none_3190711773535194\Microsoft.MediaCenter.UI.dll
+ 2009-06-22 02:40 . 2009-04-30 12:56 2355200 c:\windows\winsxs\msil_microsoft.mediacenter.ui_31bf3856ad364e35_6.0.6000.16856_none_310bfd9c5a30fd3b\Microsoft.MediaCenter.UI.dll
+ 2009-06-22 02:40 . 2009-04-30 12:06 1249280 c:\windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.22126_none_52f46defac2f2f54\Microsoft.MediaCenter.Shell.dll
+ 2009-06-22 02:40 . 2009-04-30 11:54 1249280 c:\windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6002.18030_none_5259ff7c931f1371\Microsoft.MediaCenter.Shell.dll
+ 2009-06-22 02:40 . 2009-04-30 12:21 1249280 c:\windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.22423_none_510afb29af0b8e2b\Microsoft.MediaCenter.Shell.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 1253376 c:\windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6001.18254_none_5061ecfe96055e64\Microsoft.MediaCenter.Shell.dll
+ 2009-06-22 02:40 . 2009-04-30 12:09 1282048 c:\windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.21051_none_4f022267b1ff547a\Microsoft.MediaCenter.Shell.dll
+ 2009-06-22 02:40 . 2009-04-30 12:56 1208320 c:\windows\winsxs\msil_microsoft.mediacenter.shell_31bf3856ad364e35_6.0.6000.16856_none_4e7daeec98dd0021\Microsoft.MediaCenter.Shell.dll
+ 2009-06-22 02:40 . 2009-04-30 12:06 4059136 c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6002.22126_none_8df6ca3857eab8be\ehshell.dll
+ 2009-06-22 02:40 . 2009-04-30 11:54 4059136 c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6002.18030_none_8d5c5bc53eda9cdb\ehshell.dll
+ 2009-06-22 02:40 . 2009-04-30 12:21 4059136 c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6001.22423_none_8c0d57725ac71795\ehshell.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 4059136 c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6001.18254_none_8b64494741c0e7ce\ehshell.dll
+ 2009-06-22 02:40 . 2009-04-30 12:09 4395008 c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6000.21051_none_8a047eb05dbadde4\ehshell.dll
+ 2009-06-22 02:40 . 2009-04-30 12:55 4382720 c:\windows\winsxs\msil_ehshell_31bf3856ad364e35_6.0.6000.16856_none_89800b354498898b\ehshell.dll
- 2006-11-02 10:22 . 2009-06-14 23:51 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-06-22 02:38 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-06-24 04:26 . 2009-06-24 04:26 6512640 c:\windows\ERDNT\Hiv-backup\schema.dat
+ 2009-06-22 02:40 . 2009-05-12 22:35 11064832 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.22874_none_47cd7ce4dd3f0fb5\ieframe.dll
+ 2009-06-22 02:40 . 2009-05-09 05:34 11064832 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18783_none_47380fe3c42a7285\ieframe.dll
+ 2009-06-22 02:40 . 2009-04-30 12:02 10111488 c:\windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.22126_none_546c7a3e66c6e86b\ehres.dll
+ 2009-06-22 02:40 . 2009-04-30 11:47 10111488 c:\windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6002.18030_none_53d20bcb4db6cc88\ehres.dll
+ 2009-06-22 02:40 . 2009-04-30 12:16 10111488 c:\windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.22423_none_5283077869a34742\ehres.dll
+ 2009-06-22 02:40 . 2009-04-30 12:33 10111488 c:\windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6001.18254_none_51d9f94d509d177b\ehres.dll
+ 2009-06-22 02:40 . 2009-04-30 12:00 10111488 c:\windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.21051_none_507a2eb66c970d91\ehres.dll
+ 2009-06-22 02:40 . 2009-04-30 12:42 10101760 c:\windows\winsxs\x86_microsoft-windows-ehome-ehres_31bf3856ad364e35_6.0.6000.16856_none_4ff5bb3b5374b938\ehres.dll
+ 2006-11-02 10:24 . 2009-06-01 16:51 23635392 c:\windows\System32\mrt.exe
+ 2008-03-27 07:38 . 2009-06-22 02:41 173435972 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 92704]
"JulaPAN.exe"="JulaPAN.exe" - c:\windows\System32\JulaPAN.exe [2009-02-04 481824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PlexTools Professional LE.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PlexTools Professional LE.lnk
backup=c:\windows\pss\PlexTools Professional LE.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CodeMeter Control Center.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
backup=c:\windows\pss\CodeMeter Control Center.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3185887781-3781085259-3947595314-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"= c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D33F7806-2CB4-454F-8CFE-56C3A33EAB2E}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{2ACFAA90-548A-4BBA-99A8-64BCCAB26309}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{96B7D768-2F8D-4932-A072-0F774C7905D6}"= UDP:13000:UTORRENT
"{41DB5475-3CF4-4641-A297-9EC7F3FF85EA}"= TCP:13000:UTORRENT
"{99C171B3-7399-4937-BFAE-885B8A447023}"= UDP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{8C35EE07-CBEA-46F0-8866-C7C32EB9A75C}"= TCP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{84717142-2F61-47F7-ACEA-75431BD8C278}"= UDP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{2FA31306-7FF6-457A-B70E-5723ADFE6089}"= TCP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"TCP Query User{2C3C48D0-2603-4ACF-A1E8-33C66B01319F}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{95B451FA-2140-446E-9183-1E04C514CE97}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{ADD7BB4B-D829-451C-83B0-741C5F19C678}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{DED1E21D-37A5-44C5-8995-255F40076CC1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D5250D3C-5D03-4C6B-8C6C-4E32BD98247E}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C363D80F-C842-4A1F-AB04-8730915520BE}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C0B24070-3B36-4553-AEEF-8F81FB8BE089}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A4799BD8-732F-4D38-9FE2-96EE426DFE88}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FF001CE8-1298-4A56-9B69-45D87A354AA8}"= UDP:c:\program files\World of Warcraft\WoW.exe:WoW
"{258A1CD6-BE09-4C14-AE19-D5E44C8C81A9}"= TCP:c:\program files\World of Warcraft\WoW.exe:WoW
"{F10A77FC-0EC7-4AD9-A1CB-0F35300C9E91}"= UDP:3724:wow
"{DB57C509-C923-4703-BD4A-A90DFA12A8B0}"= UDP:6112:wow
"{2D0238DA-4AF8-47CB-98F7-72EE184DD103}"= UDP:2965:jbmpgf
"{CEDB34AB-B7F1-4DE7-B77F-440112C1C20D}"= UDP:2965:jbmpgf

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"= c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server

R3 ALSysIO;ALSysIO;c:\users\Teddy\AppData\Local\Temp\ALSysIO.sys [x]
R3 MagixASIODrv;MAGIX_ASIO_BoostDriver;c:\program files\MAGIX\Samplitude_10_Pro\mxasio.sys [2002-04-16 4899]
R3 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [x]
R3 TascamFireOneSrv;Tascam FireOne Audio Driver (WDM);c:\windows\system32\drivers\FireOne.sys [x]
R3 UsbFltr;Razer Copperhead Driver;c:\windows\system32\drivers\copperhd.sys [2005-11-02 11596]
R3 Winacusb;Winacusb;c:\windows\system32\DRIVERS\winacusb.sys [2006-07-27 829952]
S1 Jula.sys;Service for Juli@ Audio Driver EWDM;c:\windows\system32\DRIVERS\Jula.sys [2009-02-04 48672]
S2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [2008-12-17 1709376]
S3 JulaWDM.sys;Service for Juli@ WDM;c:\windows\system32\DRIVERS\JulaWDM.sys [2009-02-04 35872]


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
xnmlcxldj

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
%SystemRoot%\system32\soundschemes2.exe /AddRegistration
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\users\Teddy\AppData\Roaming\Mozilla\Firefox\Profiles\fcdwzc5f.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-24 00:30
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\users\Teddy\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\xnmlcxldj]
"ServiceDll"="c:\windows\system32\ygsjp.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-06-24 0:31
ComboFix-quarantined-files.txt 2009-06-24 04:31
ComboFix2.txt 2009-06-22 01:07
ComboFix3.txt 2009-06-21 23:49

Pre-Run: 91,401,113,600 bytes free
Post-Run: 91,388,764,160 bytes free

384 --- E O F --- 2009-06-22 02:43

#13 RenatoMejias

RenatoMejias

  • Malware Response Team
  • 913 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:03 PM

Posted 24 June 2009 - 07:36 PM

Hi,

How the computer is running now?
Renato Victor Mejias
Malware help in portuguese
jetian6yw.jpg

#14 ncdrawl

ncdrawl
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 24 June 2009 - 07:41 PM

Hi,

How the computer is running now?


Hi, Renato.

Actually, on the last Combo Fix run, I forgot to include the string "File::" in the script that you gave me, so I think it did not work, so I did it again...here is that log.. it seems to be doing much better! look clean?

ComboFix 09-06-23.01 - Teddy 06/24/2009 20:30.4 - NTFSx86
Running from: c:\users\Teddy\Desktop\ComboFix.exe
Command switches used :: c:\users\Teddy\Desktop\CFScript.txt

FILE ::
"c:\windows\System32\ygsjp.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_xnmlcxldj


((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 )))))))))))))))))))))))))))))))
.

2009-06-24 04:31 . 2009-06-25 00:35 -------- d-----w- c:\users\Teddy\AppData\Local\temp
2009-06-23 15:41 . 2009-06-23 15:41 41439382 ----a-w- c:\users\Teddy\walking_01.zip
2009-06-23 05:34 . 2009-06-23 05:43 -------- d-----w- c:\users\Teddy\AppData\Roaming\ImgBurn
2009-06-23 05:26 . 2009-06-23 05:26 -------- d-----w- c:\program files\ImgBurn
2009-06-22 03:23 . 2009-06-22 03:23 -------- d-sh--w- C:\found.002
2009-06-22 02:27 . 2009-06-22 02:27 3561743 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-14 23:58 . 2009-06-14 23:58 -------- d-----w- c:\program files\JRE
2009-06-11 08:01 . 2009-06-22 02:23 -------- dc----w- c:\windows\system32\DRVSTORE
2009-06-11 07:57 . 2009-06-22 02:23 -------- d-----w- c:\program files\Lavasoft
2009-06-10 21:16 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-10 21:16 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-02 17:01 . 2009-06-02 17:14 -------- d-----w- c:\program files\virtualdubmod
2009-06-02 16:56 . 2009-05-07 19:20 31232 ----a-w- c:\windows\system\vdremote.dll
2009-06-02 16:56 . 2009-05-07 19:19 25088 ----a-w- c:\windows\system\vdsvrlnk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-25 00:35 . 2009-06-25 00:35 4096 ----a-w- c:\windows\system32\02367.tmp
2009-06-24 20:57 . 2009-06-24 20:57 4096 ----a-w- c:\windows\system32\0B74D.tmp
2009-06-24 16:16 . 2008-03-11 05:01 -------- d-----w- c:\users\Teddy\AppData\Roaming\uTorrent
2009-06-24 15:19 . 2009-01-25 19:04 -------- d-----w- c:\users\Teddy\AppData\Roaming\foobar2000
2009-06-24 12:37 . 2009-03-29 08:30 1 ----a-w- c:\users\Teddy\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-24 00:50 . 2009-03-18 06:00 -------- d-----w- c:\programdata\PopCap Games
2009-06-24 00:50 . 2009-03-18 06:00 -------- d-----w- c:\program files\PopCap Games
2009-06-24 00:31 . 2009-06-24 00:31 4096 ----a-w- c:\windows\system32\0DAF7.tmp
2009-06-22 03:32 . 2008-08-29 21:32 -------- d-----w- c:\users\Teddy\AppData\Roaming\IrfanView
2009-06-22 02:27 . 2008-10-23 22:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-22 02:23 . 2008-03-31 07:30 -------- d-----w- c:\programdata\Lavasoft
2009-06-22 00:47 . 2009-06-22 00:47 4096 ----a-w- c:\windows\system32\0754E.tmp
2009-06-21 15:33 . 2008-04-18 18:56 -------- d-----w- c:\users\Teddy\AppData\Roaming\Vso
2009-06-18 14:08 . 2009-02-24 00:59 -------- d-----w- c:\program files\AllToAVI
2009-06-17 05:13 . 2008-02-28 06:09 54360 ----a-w- c:\users\Teddy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-15 00:02 . 2009-03-29 08:28 -------- d-----w- c:\program files\OpenOffice.org 3
2009-06-14 01:28 . 2008-10-23 06:56 -------- d-----w- c:\programdata\vsosdk
2009-06-12 16:24 . 2008-04-10 21:05 -------- d-----w- c:\users\Teddy\AppData\Roaming\GrabIt
2009-06-11 07:52 . 2008-10-23 22:59 691 ----a-w- c:\users\Teddy\AppData\Roaming\GetValue.vbs
2009-06-11 07:52 . 2008-10-23 22:59 35 ----a-w- c:\users\Teddy\AppData\Roaming\SetValue.bat
2009-06-11 07:52 . 2008-10-23 22:59 35 ----a-w- c:\users\Teddy\AppData\Roaming\SetValue.bat
2009-06-03 23:49 . 2009-03-24 21:24 -------- d-----w- c:\users\Teddy\AppData\Roaming\U3
2009-06-01 07:12 . 2009-01-25 19:03 -------- d-----w- c:\program files\foobar2000
2009-05-31 11:47 . 2008-02-28 22:24 -------- d-----w- c:\programdata\NVIDIA
2009-05-30 15:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-30 08:10 . 2008-04-18 18:27 -------- d-----w- c:\users\Teddy\AppData\Roaming\Download Manager
2009-05-26 09:19 . 2008-12-09 18:04 -------- d-----w- c:\program files\World of Warcraft
2009-05-26 04:34 . 2008-03-04 20:40 -------- d-----w- c:\program files\Java
2009-05-26 00:21 . 2008-12-08 20:39 -------- d-----w- c:\program files\xnews
2009-05-12 07:38 . 2008-10-19 07:29 -------- d-----w- c:\users\Teddy\AppData\Roaming\Folding@home-gpu
2009-05-09 05:38 . 2009-05-09 05:38 -------- d-----w- c:\program files\Common Files\Digidesign
2009-05-09 05:37 . 2009-05-09 05:38 737280 ----a-w- c:\windows\iun6002.exe
2009-05-09 05:22 . 2009-05-09 05:22 -------- d-----w- c:\program files\VSTPlugins
2009-05-07 22:33 . 2008-10-07 22:09 -------- d-----w- c:\program files\GrabIt
2009-04-29 20:23 . 2008-04-18 18:56 47360 ----a-w- c:\users\Teddy\AppData\Roaming\pcouffin.sys
2009-04-29 20:23 . 2008-04-18 18:56 47360 ----a-w- c:\users\Teddy\AppData\Roaming\pcouffin.sys
2009-04-29 20:23 . 2009-04-29 20:23 -------- d-----w- c:\program files\VSO
2009-04-02 03:41 . 2009-01-30 00:11 8192 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl1.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-04-02 03:41 . 2009-01-30 00:11 30208 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl.108DF49C_3AB4_4A7D_B6FD_8B6286B317FA.exe
2009-04-02 03:41 . 2009-01-30 00:11 14848 ----a-r- c:\users\Teddy\AppData\Roaming\Microsoft\Installer\{5B0C582F-761C-4F23-B79F-9F3C2345E9F2}\IconTmpl4.A961A077_4BD0_4C98_86BC_EE4A98CE550D.exe
2009-03-29 06:32 . 2008-03-11 20:52 1 ----a-w- c:\users\Teddy\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2008-09-14 08:20 . 2009-03-22 17:43 4688384 ----a-w- c:\program files\mozilla firefox\plugins\avcodec-51.dll
2008-09-14 08:20 . 2009-03-22 17:43 546304 ----a-w- c:\program files\mozilla firefox\plugins\libfreetype-6.dll
2009-02-13 08:49 . 2009-04-17 07:37 168509 --sha-r- c:\windows\System32\ygsjp.dll
.

((((((((((((((((((((((((((((( SnapShot_2009-06-24_04.30.33 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-02-28 22:25 . 2009-06-22 02:16 46944 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-02-28 22:25 . 2009-06-24 20:59 46944 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:03 . 2009-06-24 20:59 63240 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:00 . 2009-06-24 00:50 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:00 . 2009-06-25 00:35 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:00 . 2009-06-25 00:35 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:00 . 2009-06-24 00:50 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-02-28 06:11 . 2009-06-22 02:16 8906 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3185887781-3781085259-3947595314-1000_UserData.bin
+ 2008-02-28 06:11 . 2009-06-24 20:59 8906 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3185887781-3781085259-3947595314-1000_UserData.bin
- 2006-11-02 10:33 . 2009-06-24 00:33 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-06-24 21:03 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-06-24 00:33 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-06-24 21:03 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 13:00 . 2009-06-25 00:35 114688 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 13:00 . 2009-06-24 00:50 114688 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 10:22 . 2009-06-24 16:17 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2009-06-22 02:38 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 92704]
"JulaPAN.exe"="JulaPAN.exe" - c:\windows\System32\JulaPAN.exe [2009-02-04 481824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PlexTools Professional LE.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\PlexTools Professional LE.lnk
backup=c:\windows\pss\PlexTools Professional LE.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^CodeMeter Control Center.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
backup=c:\windows\pss\CodeMeter Control Center.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^Teddy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\users\Teddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3185887781-3781085259-3947595314-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"= c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D33F7806-2CB4-454F-8CFE-56C3A33EAB2E}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{2ACFAA90-548A-4BBA-99A8-64BCCAB26309}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{96B7D768-2F8D-4932-A072-0F774C7905D6}"= UDP:13000:UTORRENT
"{41DB5475-3CF4-4641-A297-9EC7F3FF85EA}"= TCP:13000:UTORRENT
"{99C171B3-7399-4937-BFAE-885B8A447023}"= UDP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{8C35EE07-CBEA-46F0-8866-C7C32EB9A75C}"= TCP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{84717142-2F61-47F7-ACEA-75431BD8C278}"= UDP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"{2FA31306-7FF6-457A-B70E-5723ADFE6089}"= TCP:c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:CodeMeter Runtime Server
"TCP Query User{2C3C48D0-2603-4ACF-A1E8-33C66B01319F}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{95B451FA-2140-446E-9183-1E04C514CE97}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{ADD7BB4B-D829-451C-83B0-741C5F19C678}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{DED1E21D-37A5-44C5-8995-255F40076CC1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D5250D3C-5D03-4C6B-8C6C-4E32BD98247E}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C363D80F-C842-4A1F-AB04-8730915520BE}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C0B24070-3B36-4553-AEEF-8F81FB8BE089}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A4799BD8-732F-4D38-9FE2-96EE426DFE88}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FF001CE8-1298-4A56-9B69-45D87A354AA8}"= UDP:c:\program files\World of Warcraft\WoW.exe:WoW
"{258A1CD6-BE09-4C14-AE19-D5E44C8C81A9}"= TCP:c:\program files\World of Warcraft\WoW.exe:WoW
"{F10A77FC-0EC7-4AD9-A1CB-0F35300C9E91}"= UDP:3724:wow
"{DB57C509-C923-4703-BD4A-A90DFA12A8B0}"= UDP:6112:wow
"{2D0238DA-4AF8-47CB-98F7-72EE184DD103}"= UDP:2965:jbmpgf
"{CEDB34AB-B7F1-4DE7-B77F-440112C1C20D}"= UDP:2965:jbmpgf

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\CodeMeter\\Runtime\\bin\\CodeMeter.exe"= c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server

R1 Jula.sys;Service for Juli@ Audio Driver EWDM;c:\windows\System32\drivers\Jula.sys [3/29/2009 17:16 48672]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\CodeMeter\Runtime\bin\CodeMeter.exe [12/17/2008 05:00 1709376]
R3 JulaWDM.sys;Service for Juli@ WDM;c:\windows\System32\drivers\JulaWDM.sys [3/29/2009 17:16 35872]
S2 xnmlcxldj;Server Installer;c:\windows\system32\svchost.exe -k netsvcs [3/27/2008 03:39 21504]
S3 MagixASIODrv;MAGIX_ASIO_BoostDriver;c:\program files\MAGIX\Samplitude_10_Pro\mxasio.sys [2/8/2009 21:42 4899]
S3 UsbFltr;Razer Copperhead Driver;c:\windows\System32\drivers\copperhd.sys [11/2/2005 11:54 11596]
S3 Winacusb;Winacusb;c:\windows\System32\drivers\winacusb.sys [2/28/2008 18:44 829952]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
xnmlcxldj

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
%SystemRoot%\system32\soundschemes2.exe /AddRegistration
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\users\Teddy\AppData\Roaming\Mozilla\Firefox\Profiles\fcdwzc5f.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-24 20:35
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\users\Teddy\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\xnmlcxldj]
"ServiceDll"="c:\windows\system32\ygsjp.dll"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\System32\rundll32.exe
c:\program files\ASUS\AASP\1.00.40\aaCenter.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2009-06-25 20:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-25 00:38
ComboFix2.txt 2009-06-24 04:31
ComboFix3.txt 2009-06-22 01:07
ComboFix4.txt 2009-06-21 23:49

Pre-Run: 91,169,550,336 bytes free
Post-Run: 90,968,186,880 bytes free

233 --- E O F --- 2009-06-22 02:43

#15 ncdrawl

ncdrawl
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:05:03 PM

Posted 24 June 2009 - 07:44 PM

Hey Renato...I am still not able to go to antivirus websites though...




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users