ComboFix 09-08-10.06 - Pestend 13/08/2009 17:01.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1593 [GMT 10:00]
Running from: c:\documents and settings\Pestend\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft\Internet Explorer\DLLs\c.cgm
c:\windows\10439spz659.bin
c:\windows\11513wo5m2z19.bin
c:\windows\11757hac5tooz907.exe
c:\windows\119579py7cz.bin
c:\windows\122179z5421.exe
c:\windows\128dvir1529z.exe
c:\windows\12f3addw95ez321.cpl
c:\windows\1366szambot95.ocx
c:\windows\13z01w9r51b0.cpl
c:\windows\13z679py175.ocx
c:\windows\1409zvi9u5655.dll
c:\windows\14397zpamb5t4d59.dll
c:\windows\14999hzcktool5b8.bin
c:\windows\14z6b9ckdoor59.cpl
c:\windows\15351hacktoo934z.dll
c:\windows\15429z9rm22d5.dll
c:\windows\15521vi9us1z8.dll
c:\windows\15603h9cktozl212.bin
c:\windows\159edownloader58z.ocx
c:\windows\159z1hack5ool3e8.bin
c:\windows\15z749ormbc.ocx
c:\windows\16095noz-a59irusb0.cpl
c:\windows\16235szambot493.cpl
c:\windows\16685wzr91d1.bin
c:\windows\169399aczt5ol210.dll
c:\windows\16daszar952295.dll
c:\windows\16z1sp5rse9143.dll
c:\windows\17569tr5j7c0z.exe
c:\windows\175z89p5mbot7a5.ocx
c:\windows\17834spa5bzt9a7.dll
c:\windows\17fzsparse12905.bin
c:\windows\18125s5ambz9593.cpl
c:\windows\1818zack9o5l20.cpl
c:\windows\190bzh5eat2687.exe
c:\windows\19151virus40z9.cpl
c:\windows\19157z59j522.exe
c:\windows\192zt9r5at9657.cpl
c:\windows\19435spy2a9z.bin
c:\windows\19504spam5zt75b.bin
c:\windows\19591vir9s55z.exe
c:\windows\19716spz975.bin
c:\windows\19z235acktool5d1.ocx
c:\windows\19z9spyware1225.dll
c:\windows\1a09backdoorz753.bin
c:\windows\1a35d5wnlzader1493.cpl
c:\windows\1af99ddza5e1922.exe
c:\windows\1b05spyzare1769.dll
c:\windows\1cc0spywzre25299.ocx
c:\windows\1e1ab9ckdoor142z5.ocx
c:\windows\1e439i51z44.bin
c:\windows\1eatzr5at31999.cpl
c:\windows\1f54threat12z949.bin
c:\windows\1f639pywzre1585.cpl
c:\windows\1fa9v5z3039.dll
c:\windows\1z21s9eal32745.cpl
c:\windows\1z534spambo57649.ocx
c:\windows\201zhack5ool495.cpl
c:\windows\2046zacktool9fc5.cpl
c:\windows\20847s5azbot79.dll
c:\windows\21126n5t-9-viruzd8.cpl
c:\windows\22475hack95ol6ez.cpl
c:\windows\22552spamboz1d9.ocx
c:\windows\22699vi59z2dd.exe
c:\windows\228795acktooz9ce.bin
c:\windows\22c7th5eaz96082.ocx
c:\windows\22z345roj92.cpl
c:\windows\23012h5zk9ool478.bin
c:\windows\23051s9ambot77cz.bin
c:\windows\23555ownz9ader2112.dll
c:\windows\236zir9s5d5.cpl
c:\windows\238049ot-a-virzs45a.cpl
c:\windows\23a5st9az16285.exe
c:\windows\241285ir9s57z.bin
c:\windows\24942virus55z.ocx
c:\windows\25094hacktoo9ze7.ocx
c:\windows\25319hacztool578.cpl
c:\windows\25457ha5ztool95d.ocx
c:\windows\25758sp9m5ot1za.dll
c:\windows\259669py75z.cpl
c:\windows\261849zt5a-virus44.dll
c:\windows\26187spzm5ot96b.cpl
c:\windows\2626ste5l59z.exe
c:\windows\2659zh5eat716.dll
c:\windows\269btzie95811.cpl
c:\windows\26z69s5ya0.ocx
c:\windows\2714s59rse29z2.ocx
c:\windows\2739hazkt9ol55f.ocx
c:\windows\2745sze9l252.dll
c:\windows\27589virus7z5.dll
c:\windows\27757hacktool497z.dll
c:\windows\27788notza9v5rus309.bin
c:\windows\27919zackt9ol567.ocx
c:\windows\27962wozm5c5.dll
c:\windows\27a6spy59rz2845.dll
c:\windows\2834s9ar5e305z.ocx
c:\windows\2851zworm149.cpl
c:\windows\28525troj9z5.cpl
c:\windows\285h9cktooz147.dll
c:\windows\29270zroj4d75.bin
c:\windows\29521worm5c2z.cpl
c:\windows\29554t9zj67a.bin
c:\windows\295z5hacktool4b5.dll
c:\windows\296995ot-a-virus3zb.ocx
c:\windows\29725roz751.exe
c:\windows\29727n5tza-vir9s245.bin
c:\windows\2985z5ckdoor1937.dll
c:\windows\298zhacktool95.cpl
c:\windows\29z21vi5uscc.ocx
c:\windows\29z54spy61.dll
c:\windows\2bcfsp9z5re2914.exe
c:\windows\2d05baczdo9r910.ocx
c:\windows\2d0bdownloaze92250.exe
c:\windows\2d5asp9zare1853.exe
c:\windows\2f2cbac9door2568z.exe
c:\windows\2z04a5dwar9525.dll
c:\windows\2z351n5t-a-virus99.exe
c:\windows\2z942vir9555.bin
c:\windows\30449spambzt55.bin
c:\windows\3048addwa9e825z.bin
c:\windows\30534zirus79d.bin
c:\windows\30656hac9tool43z5.ocx
c:\windows\30c3b9ckd5or1z20.ocx
c:\windows\31155wormz979.bin
c:\windows\313abz9kdo5r2496.ocx
c:\windows\31879vi5uz4eb.cpl
c:\windows\3209back5oorz012.cpl
c:\windows\3225w9rm3z7.dll
c:\windows\3245spzrse31099.ocx
c:\windows\3257hacktoz95f7.exe
c:\windows\327ethz9at4556.exe
c:\windows\3280zownl95der2931.ocx
c:\windows\3459zhre9t54830.ocx
c:\windows\34c7tzr5at94956.cpl
c:\windows\35177n9t-azvirus713.cpl
c:\windows\35c9spazse1130.cpl
c:\windows\35cfthzeat99532.bin
c:\windows\3919zir95665.exe
c:\windows\395cthiefz9.cpl
c:\windows\3980stealz15.ocx
c:\windows\39905hzef2077.exe
c:\windows\3a11t5rea93z677.cpl
c:\windows\3a69sz5al543.dll
c:\windows\3a899zyware2150.exe
c:\windows\3af2spy5a9z466.cpl
c:\windows\3b91baczdoor1458.exe
c:\windows\3bd8adzw5re1493.cpl
c:\windows\3bz29hief5951.bin
c:\windows\3c039ddzare21055.dll
c:\windows\3c79do5nzoad9r2076.bin
c:\windows\3c99bzck5oor2489.ocx
c:\windows\3d59thief6z.dll
c:\windows\3de7ste5z16339.bin
c:\windows\3e31vi525z59.cpl
c:\windows\3e95szeal601.exe
c:\windows\4229not-z-v5rus19a.bin
c:\windows\4240a5zware2289.exe
c:\windows\42ffzt9al5513.dll
c:\windows\432zworm955.exe
c:\windows\4550tzi9f2299.cpl
c:\windows\455not59-vizus6ab.dll
c:\windows\458ds9azse171.cpl
c:\windows\45dfbazkdoo93108.dll
c:\windows\469d5hrezt15775.bin
c:\windows\472av95190z.exe
c:\windows\4799spyw5ze903.exe
c:\windows\479bsp5zse3165.bin
c:\windows\47zadown5oa9er1038.bin
c:\windows\48c9thief5z17.cpl
c:\windows\48e5threzt20449.dll
c:\windows\491z5hief421.exe
c:\windows\493zv5r1796.bin
c:\windows\4965szy1e95.cpl
c:\windows\497dzhreat57039.exe
c:\windows\4992spazse1095.exe
c:\windows\49zbaddwar5549.bin
c:\windows\4af4a9dwar51234z.exe
c:\windows\4c3zvi59199.dll
c:\windows\4czf9ackdoor35.ocx
c:\windows\4dazhief17559.bin
c:\windows\4z549irus35f.dll
c:\windows\5038ad9wa5e2399z.exe
c:\windows\5039backd9o52567z.ocx
c:\windows\5047virzs499.dll
c:\windows\5055threa95289z.cpl
c:\windows\5147th9ef1855z.bin
c:\windows\51758spambot6za9.cpl
c:\windows\51893not-a-vzru975b.bin
c:\windows\53019py7bz.ocx
c:\windows\53459own5oazer1185.cpl
c:\windows\53d4thizf829.ocx
c:\windows\54277hacztool392.exe
c:\windows\542s9arse529z.ocx
c:\windows\5488sz5wa9e2093.ocx
c:\windows\5492zpy7f.dll
c:\windows\549959zy88.exe
c:\windows\5504spyware19z9.dll
c:\windows\5517trojz93.cpl
c:\windows\5555tz9j1a2.ocx
c:\windows\55a95tzal14939.cpl
c:\windows\55z25troj12b9.ocx
c:\windows\55z7backdoo9805.exe
c:\windows\56404sp9zbot559.ocx
c:\windows\56e3s9ezl1155.dll
c:\windows\56z2wo955f3.exe
c:\windows\5805backd9orz6.bin
c:\windows\58499hacztool297.dll
c:\windows\584cste9l4z5.ocx
c:\windows\585et9zea58827.dll
c:\windows\587az9i5f3064.ocx
c:\windows\58zspyware28999.ocx
c:\windows\590vir9s519z.ocx
c:\windows\5923adzware9596.bin
c:\windows\5925steal9z15.cpl
c:\windows\59356worm4dz.ocx
c:\windows\5965t5rzat31997.exe
c:\windows\59687spamzotc9.cpl
c:\windows\5972spamb5t9zd.ocx
c:\windows\59739not-a-vizu9464.ocx
c:\windows\5976back9ooz625.bin
c:\windows\59909z520a.ocx
c:\windows\59dspywzre1551.exe
c:\windows\59z25py3bb.cpl
c:\windows\5aa5thr5zt90449.cpl
c:\windows\5ab3v9r25z9.cpl
c:\windows\5b089parse61z5.exe
c:\windows\5ba1downloa9er1500z.exe
c:\windows\5c2t5reat95z76.exe
c:\windows\5cf0do9zloader2343.cpl
c:\windows\5e2dzown5oader796.ocx
c:\windows\5ed3s5ezl9063.dll
c:\windows\5f91backdoz51637.dll
c:\windows\5z108sp9684.cpl
c:\windows\6052vizus9175.exe
c:\windows\614zt9oj5445.ocx
c:\windows\6350spy98z.dll
c:\windows\638dvir598z.cpl
c:\windows\6453thizf962.bin
c:\windows\6588w5rm5b9z.exe
c:\windows\65c8szeal6039.dll
c:\windows\65ebvir1z519.bin
c:\windows\6695bazkdoor2193.bin
c:\windows\6716vi5usz9f.exe
c:\windows\6790zownlo59er1154.bin
c:\windows\68baspazse159.exe
c:\windows\68dfz5dware996.cpl
c:\windows\69205hiez1910.exe
c:\windows\6922notz5-virus384.cpl
c:\windows\6942th5ef1484z.dll
c:\windows\6958sparsz5038.cpl
c:\windows\695ethreatz6379.exe
c:\windows\6997s5y165z.dll
c:\windows\69aathief5z32.ocx
c:\windows\6dz35p9ware2020.dll
c:\windows\6e9aspzw5re541.exe
c:\windows\6z0baddwar51994.exe
c:\windows\6z65t9i5f1503.dll
c:\windows\70705ackdoor9z32.bin
c:\windows\7173downl9z5er2583.dll
c:\windows\73e5back9oor3z05.cpl
c:\windows\741zvir25819.exe
c:\windows\743dsteaz2995.exe
c:\windows\7529not-a-5iruz529.ocx
c:\windows\756aspzr9e2963.exe
c:\windows\757doz9loader3104.exe
c:\windows\75fc9py5are1755z.bin
c:\windows\763bbzckdo9r26455.bin
c:\windows\7729downloa95rz88.exe
c:\windows\780ztroj9c5.dll
c:\windows\78159tealz795.cpl
c:\windows\79159ddwarz2066.bin
c:\windows\7920add5are855z.cpl
c:\windows\795z9irus21f5.cpl
c:\windows\79ecspars530z5.bin
c:\windows\7c9ebac5door2z9.ocx
c:\windows\7fc19parse59z6.dll
c:\windows\7z2eth5ef439.bin
c:\windows\7z9059ckdoor644.dll
c:\windows\8086v9z5s465.cpl
c:\windows\833z5py7429.ocx
c:\windows\84355iru93z8.bin
c:\windows\8898wzrm3d95.dll
c:\windows\910295roj7z.exe
c:\windows\9115virz865.ocx
c:\windows\91bfzpyware1950.exe
c:\windows\920z0hacktool1e5.dll
c:\windows\92225spy37z.bin
c:\windows\92dbthie51241z.exe
c:\windows\92f5vir27z6.exe
c:\windows\92z9no5-a-virus49e.exe
c:\windows\950zthief3061.ocx
c:\windows\9646trzj459.exe
c:\windows\96559acktooz732.cpl
c:\windows\9685zhie5279.cpl
c:\windows\96edvir5z5.dll
c:\windows\9835worz579.bin
c:\windows\9864threzt25974.dll
c:\windows\99021not-a-5izus602.exe
c:\windows\99762hazkto5l165.exe
c:\windows\9a63addw5rz2149.bin
c:\windows\9be4threaz35617.exe
c:\windows\9ccthreatz825.bin
c:\windows\9d97thrza529959.exe
c:\windows\9z239sp5776.ocx
c:\windows\9z41st5al333.dll
c:\windows\a9bspzwa5e751.ocx
c:\windows\d89th5ef96z.cpl
c:\windows\e03down5oaz9r1571.cpl
c:\windows\e1495izf823.dll
c:\windows\e33stealz965.ocx
c:\windows\ecb9hie5z895.dll
c:\windows\fe4vzr1975.dll
c:\windows\system32\1039zo9m475.exe
c:\windows\system32\10425wo9m6dcz.bin
c:\windows\system32\10515hac5zool79f.exe
c:\windows\system32\10523zackt9ol5cf.cpl
c:\windows\system32\1052ztroj394.cpl
c:\windows\system32\10599troj2zf5.bin
c:\windows\system32\105zsteal359.ocx
c:\windows\system32\108199i5us7z1.dll
c:\windows\system32\10z48sp57839.cpl
c:\windows\system32\10z54spam9ot1c6.ocx
c:\windows\system32\11138nzt-5-viru91ba.dll
c:\windows\system32\111709r5j6az.dll
c:\windows\system32\113bb9c5dozr2957.bin
c:\windows\system32\11535v9ruz310.dll
c:\windows\system32\11623vi59z38e.ocx
c:\windows\system32\11962vi5z967d.dll
c:\windows\system32\11bfzownloade995.cpl
c:\windows\system32\12250woz549c.dll
c:\windows\system32\12629spyz495.cpl
c:\windows\system32\126835pambot1f9z.bin
c:\windows\system32\12957sp5z98.cpl
c:\windows\system32\13129not-a-viru5z0d.dll
c:\windows\system32\1313195yz2e.cpl
c:\windows\system32\13695trojz695.dll
c:\windows\system32\13783haczt9ol655.exe
c:\windows\system32\1397zworm2a5.dll
c:\windows\system32\13992wzr9e5.exe
c:\windows\system32\13a35t9al3z9.dll
c:\windows\system32\1437tr9jz53.cpl
c:\windows\system32\14905troz3d8.dll
c:\windows\system32\15025vir9s6z6.exe
c:\windows\system32\1502zw9rm414.ocx
c:\windows\system32\15146spamboz4a89.cpl
c:\windows\system32\1527virus3z9.bin
c:\windows\system32\152add9a5e278z.bin
c:\windows\system32\15592s9amboz706.dll
c:\windows\system32\15876worm9z.bin
c:\windows\system32\158zthie59594.cpl
c:\windows\system32\15z5download9r2673.ocx
c:\windows\system32\16299s9z60a5.bin
c:\windows\system32\16961spambot5z9.cpl
c:\windows\system32\16c9thzef205.exe
c:\windows\system32\17391not-5-zirus49b9.cpl
c:\windows\system32\173bth5zat305479.dll
c:\windows\system32\17569hackt95z592.bin
c:\windows\system32\1759a9dware94z.dll
c:\windows\system32\17818s951z4.ocx
c:\windows\system32\17856viru94b5z.exe
c:\windows\system32\17994worm5z8.ocx
c:\windows\system32\18257hzcktoo54769.cpl
c:\windows\system32\18594s9y704z.exe
c:\windows\system32\18663s5ambotzb89.bin
c:\windows\system32\19319sp5mbzt589.bin
c:\windows\system32\19375vizus290.dll
c:\windows\system32\19408sp549z.cpl
c:\windows\system32\1952st9al68z.ocx
c:\windows\system32\195709zy213.ocx
c:\windows\system32\19577wo5m10cz.cpl
c:\windows\system32\1958virz08.ocx
c:\windows\system32\196199py15z.bin
c:\windows\system32\1972vi95z511.exe
c:\windows\system32\19734w5rm9z2.dll
c:\windows\system32\19735troj1z1.bin
c:\windows\system32\197z5pywar92549.dll
c:\windows\system32\19z5t5reat21907.cpl
c:\windows\system32\19z8d9wnl5ader1895.cpl
c:\windows\system32\1a62do5nloader1395z.ocx
c:\windows\system32\1b1fth95f3z9.cpl
c:\windows\system32\1b85bz9kdoor148.dll
c:\windows\system32\1c94addwa9e2z995.ocx
c:\windows\system32\1e25v9z584.bin
c:\windows\system32\1f84th5ez917488.ocx
c:\windows\system32\1f9fstz5l1965.bin
c:\windows\system32\1faad9w5loadzr2728.cpl
c:\windows\system32\1z079parse2599.bin
c:\windows\system32\1z215t5o9621.cpl
c:\windows\system32\1z368sp9m5ot638.exe
c:\windows\system32\20319tr5zc19.cpl
c:\windows\system32\20529troj9bz.dll
c:\windows\system32\2059zorm739.cpl
c:\windows\system32\20729not-a5zi9usbc.bin
c:\windows\system32\2088z9orm3a45.dll
c:\windows\system32\210729zrus5bf.exe
c:\windows\system32\21652z9oj2b2.dll
c:\windows\system32\2172a5zware9373.bin
c:\windows\system32\2252th9ef250z.ocx
c:\windows\system32\226b95czdoor792.bin
c:\windows\system32\22998sp5mbot2c9z.ocx
c:\windows\system32\234185zy592.bin
c:\windows\system32\23448hacktozl596.bin
c:\windows\system32\23552not-a-v9ruz515.dll
c:\windows\system32\23744vizuse95.bin
c:\windows\system32\237hz9k5ool1d4.bin
c:\windows\system32\23815not-a-9izus5e8.dll
c:\windows\system32\23926vzrus59d.cpl
c:\windows\system32\2395zvirus506.cpl
c:\windows\system32\23z91virus9a5.bin
c:\windows\system32\24497zr9j753.bin
c:\windows\system32\246bspywarz5943.exe
c:\windows\system32\24z93t9oj358.dll
c:\windows\system32\2504not-a-z9rus4e2.dll
c:\windows\system32\25079tro977z.dll
c:\windows\system32\2520dowzl9ader853.bin
c:\windows\system32\25340v9zus559.ocx
c:\windows\system32\25453zot-a-virus6e69.ocx
c:\windows\system32\25564woz91135.exe
c:\windows\system32\255729roz342.exe
c:\windows\system32\25703tzo5439.bin
c:\windows\system32\259athiefz901.dll
c:\windows\system32\25z86hackt9ol4af.cpl
c:\windows\system32\261309izus154.exe
c:\windows\system32\2634vzr55439.exe
c:\windows\system32\26486s9y2z5.bin
c:\windows\system32\2668st5z92006.exe
c:\windows\system32\2785zor94a5.bin
c:\windows\system32\28529spambotz1.bin
c:\windows\system32\28593h95ktozla9.ocx
c:\windows\system32\28c1z5r1296.dll
c:\windows\system32\2917baczd5or2349.cpl
c:\windows\system32\2954zacktool23f.exe
c:\windows\system32\296575i9usz8a.cpl
c:\windows\system32\29c5vzr1094.exe
c:\windows\system32\29z54wor926b.exe
c:\windows\system32\29z6s9yware25695.dll
c:\windows\system32\29zadownload5r1859.exe
c:\windows\system32\2b56addwa9e9z2.ocx
c:\windows\system32\2d559parse2272z.bin
c:\windows\system32\2d72b9cz5oor2075.dll
c:\windows\system32\2ecftz95at19040.ocx
c:\windows\system32\2fe2t5reat94z89.bin
c:\windows\system32\2ffft5reat91z31.ocx
c:\windows\system32\2z161troj593.bin
c:\windows\system32\2z89h5cktoole49.bin
c:\windows\system32\2zd5th9ea5741.cpl
c:\windows\system32\3049zhack5ool6a9.cpl
c:\windows\system32\3163995oj364z.exe
c:\windows\system32\318z5spa5bo969b.bin
c:\windows\system32\31911h9cktoolz5.exe
c:\windows\system32\3290z5irus7c9.bin
c:\windows\system32\3299ztroj2e5.exe
c:\windows\system32\32b0th9eat235z6.bin
c:\windows\system32\32f1zow9load5r3111.ocx
c:\windows\system32\32z55vir9s1f25.dll
c:\windows\system32\3495hacktzol22e.bin
c:\windows\system32\34z9thief32465.cpl
c:\windows\system32\35078zr9j2b1.ocx
c:\windows\system32\35396n9t-a-virzs57d.bin
c:\windows\system32\35z79worm519.ocx
c:\windows\system32\3807hacz5ool3a9.dll
c:\windows\system32\3874vir5z598.ocx
c:\windows\system32\3905downlzader917.ocx
c:\windows\system32\39506s5ambzt295.exe
c:\windows\system32\3976threat315z9.ocx
c:\windows\system32\397csp5rs92267z.dll
c:\windows\system32\3999v5rus46z.exe
c:\windows\system32\39ca5hizf384.exe
c:\windows\system32\3a45dzwnlo9der1051.cpl
c:\windows\system32\3a7sparze594.exe
c:\windows\system32\3d24thief359z.cpl
c:\windows\system32\3d9azpyw5re9452.bin
c:\windows\system32\3dc7viz91985.exe
c:\windows\system32\3ec69tea5716z.dll
c:\windows\system32\3f70sp5rse1599z.exe
c:\windows\system32\3z119v5rus247.bin
c:\windows\system32\3z503spy53f9.exe
c:\windows\system32\3ze3backdo592058.exe
c:\windows\system32\401zv9r565.exe
c:\windows\system32\4065ba9kdoorz345.exe
c:\windows\system32\409bzpywar52317.exe
c:\windows\system32\40eeaddw9rz5390.ocx
c:\windows\system32\411av5r942z.exe
c:\windows\system32\42za9hief2575.exe
c:\windows\system32\4549tzief2909.cpl
c:\windows\system32\4581hac9tool83z.bin
c:\windows\system32\4593spy5z39.cpl
c:\windows\system32\459abackdoorz35.exe
c:\windows\system32\467h5ckt9olzf7.cpl
c:\windows\system32\46e3s5ywaze1973.ocx
c:\windows\system32\47d3v5rz92.exe
c:\windows\system32\4805thrz9t3462.exe
c:\windows\system32\4819zh9ef650.exe
c:\windows\system32\4852spy6z19.exe
c:\windows\system32\49025hreat25z4.cpl
c:\windows\system32\4954b5ckd9zr469.cpl
c:\windows\system32\4a2fszars930025.bin
c:\windows\system32\4b7ba5d9are1039z.dll
c:\windows\system32\4e58zddware31949.bin
c:\windows\system32\4e85th9efz045.exe
c:\windows\system32\4z55tr9j568.dll
c:\windows\system32\4z9evi51267.bin
c:\windows\system32\5035addware98z2.cpl
c:\windows\system32\506zthreat91617.exe
c:\windows\system32\508059zrm324.cpl
c:\windows\system32\5093sparse2095z.exe
c:\windows\system32\5104s59rse1409z.ocx
c:\windows\system32\51059ir6z6.cpl
c:\windows\system32\5147vir9s3a1z.exe
c:\windows\system32\52589vizus3f3.bin
c:\windows\system32\5259haczt9ol5b5.bin
c:\windows\system32\5260trojz92.bin
c:\windows\system32\528z9r527.bin
c:\windows\system32\52e9vir160z5.ocx
c:\windows\system32\52easp9wa5e18z0.cpl
c:\windows\system32\53392t9oj120z.ocx
c:\windows\system32\5359thi5f2z47.dll
c:\windows\system32\54200szambot196.bin
c:\windows\system32\5424vir9148z.ocx
c:\windows\system32\544z6not-a-virus2e9.ocx
c:\windows\system32\5545steal16z79.cpl
c:\windows\system32\5599backdoorz790.bin
c:\windows\system32\55afsp9rsz154.ocx
c:\windows\system32\55cz5par9e2633.bin
c:\windows\system32\56063worz9c1.cpl
c:\windows\system32\5645spa59ot566z.exe
c:\windows\system32\56559pamzot15b.cpl
c:\windows\system32\5675s9z5l661.cpl
c:\windows\system32\569fsteal1z145.dll
c:\windows\system32\56d89zyware5580.bin
c:\windows\system32\56fa9parse1837z.cpl
c:\windows\system32\5752spzrse18349.exe
c:\windows\system32\580z1troj9bf.exe
c:\windows\system32\5866ziru591.exe
c:\windows\system32\58z31hac9tool276.ocx
c:\windows\system32\5919vi5z984.bin
c:\windows\system32\5929sz5ware9110.dll
c:\windows\system32\5935hacktozl30f.cpl
c:\windows\system32\5937wo9m1z0.ocx
c:\windows\system32\5955thrzat552.exe
c:\windows\system32\59742troz468.exe
c:\windows\system32\598z2virus2f5.bin
c:\windows\system32\59d2threaz20542.bin
c:\windows\system32\59dzsteal860.ocx
c:\windows\system32\59ezspyw9re13205.dll
c:\windows\system32\5ad5thr95tz7047.dll
c:\windows\system32\5b8adowz9o5der1250.exe
c:\windows\system32\5be359izf2911.cpl
c:\windows\system32\5c90spy5are1057z.ocx
c:\windows\system32\5cf5szyw9re1349.cpl
c:\windows\system32\5d4fs5azse21339.exe
c:\windows\system32\5d58th9ezt13994.exe
c:\windows\system32\5e35downloader399z.dll
c:\windows\system32\5ed9ir6z5.exe
c:\windows\system32\5faczir1918.bin
c:\windows\system32\5z2dspars91856.exe
c:\windows\system32\5z49thief386.exe
c:\windows\system32\5z51wor5398.ocx
c:\windows\system32\60a7zpar9e7485.ocx
c:\windows\system32\61389ot-z-5irus39b.bin
c:\windows\system32\614bspa5ze15129.ocx
c:\windows\system32\622zdownlo5der1909.ocx
c:\windows\system32\6251h9czt5ol1c5.ocx
c:\windows\system32\62f0addwarz2759.cpl
c:\windows\system32\62z2v9r3259.cpl
c:\windows\system32\62z9threa59604.dll
c:\windows\system32\638bt5rezt184369.exe
c:\windows\system32\64c0bzckdoo92395.dll
c:\windows\system32\656ct5izf549.dll
c:\windows\system32\6590ste9l1712z.cpl
c:\windows\system32\65b3tzief296.exe
c:\windows\system32\6659spy129z.exe
c:\windows\system32\6714noz-a-viru549b.dll
c:\windows\system32\6814add59re97z.ocx
c:\windows\system32\689zspa5bot1c.cpl
c:\windows\system32\690aspyzar59862.ocx
c:\windows\system32\6935threz56248.dll
c:\windows\system32\699zb5ck9oor819.exe
c:\windows\system32\69e9spyw5rez073.cpl
c:\windows\system32\6a99spars523z9.exe
c:\windows\system32\6ad7addw9ze205.bin
c:\windows\system32\6d9zs5yware1459.cpl
c:\windows\system32\6ec7baczdo59231.cpl
c:\windows\system32\6edfzte59455.dll
c:\windows\system32\6ee7s9eal5z55.exe
c:\windows\system32\6ezfthie93256.cpl
c:\windows\system32\6fczvir5609.exe
c:\windows\system32\6z29not9a-viru5575.exe
c:\windows\system32\70f5ba9kd5or16z0.dll
c:\windows\system32\7161h9cztool457.exe
c:\windows\system32\72e1addw9rez965.dll
c:\windows\system32\72f5zhr95t29859.bin
c:\windows\system32\7453downlzader1591.ocx
c:\windows\system32\746zvir5s79d.ocx
c:\windows\system32\7495tzreat15368.exe
c:\windows\system32\749fspywa5z2523.cpl
c:\windows\system32\7509t5izf442.cpl
c:\windows\system32\75c4s9arsez39.dll
c:\windows\system32\766zd9wnl5ader2338.exe
c:\windows\system32\76z9b9ckdoor2053.cpl
c:\windows\system32\7792adzware1865.cpl
c:\windows\system32\7855zackdoo9279.ocx
c:\windows\system32\7859thiez2568.exe
c:\windows\system32\789z95r2591.ocx
c:\windows\system32\78cbthrea98795z.exe
c:\windows\system32\7933backdoor509z.bin
c:\windows\system32\7944spazb9t537.ocx
c:\windows\system32\799thze5t7926.bin
c:\windows\system32\79e7thrzat63865.bin
c:\windows\system32\79f5thief3571z.dll
c:\windows\system32\7aa2zp9w5re135.dll
c:\windows\system32\7cd3a5dwa9ez540.dll
c:\windows\system32\7cz9ir5633.bin
c:\windows\system32\7d7fdzwn5oad9r202.exe
c:\windows\system32\7db9stea935z9.dll
c:\windows\system32\7dcb9ack5ozr68.dll
c:\windows\system32\7decb9ckdoo5z831.ocx
c:\windows\system32\7f56dow9loadez3158.exe
c:\windows\system32\7z0edownlo9d5r2974.exe
c:\windows\system32\7z355pambot64c9.ocx
c:\windows\system32\7z53h9cktool4ce.bin
c:\windows\system32\8045viru965z.ocx
c:\windows\system32\85z6sp9694.exe
c:\windows\system32\8755v9rzs5cd.dll
c:\windows\system32\8902vzru55fa.ocx
c:\windows\system32\895worz189.cpl
c:\windows\system32\8975no5-z-9irus1ce.exe
c:\windows\system32\9033not-a-5irzs411.bin
c:\windows\system32\92799hac5tooz7dc.exe
c:\windows\system32\92869ackzo5l6c0.exe
c:\windows\system32\92889s5amboz494.exe
c:\windows\system32\9288wozm7359.exe
c:\windows\system32\93535spy5bz.ocx
c:\windows\system32\944585py64az.bin
c:\windows\system32\948zvir5s962.ocx
c:\windows\system32\950zspy15a.bin
c:\windows\system32\9512not-azvi9us7b4.bin
c:\windows\system32\9535szyw5re1313.bin
c:\windows\system32\9542stealz2.cpl
c:\windows\system32\95430szambot7d85.ocx
c:\windows\system32\9544sza9bot706.exe
c:\windows\system32\95a4addware194z.exe
c:\windows\system32\95e6vzr867.cpl
c:\windows\system32\95efvir29z8.exe
c:\windows\system32\9609sparse569z.dll
c:\windows\system32\9670addzare24615.cpl
c:\windows\system32\977azpa5se944.ocx
c:\windows\system32\97819tr5j662z.exe
c:\windows\system32\9814ztroj525.ocx
c:\windows\system32\9845spywarz535.cpl
c:\windows\system32\98464zo5m282.bin
c:\windows\system32\9931backdo5r2623z.ocx
c:\windows\system32\9939spyzare1965.cpl
c:\windows\system32\995znot-a9virus14c.exe
c:\windows\system32\99z49pambot775.exe
c:\windows\system32\9a0spyw5rez98.exe
c:\windows\system32\9c3d9wnloazer815.exe
c:\windows\system32\9cc0thief25z3.dll
c:\windows\system32\9cccs5arse28z2.cpl
c:\windows\system32\9cez5pyware927.exe
c:\windows\system32\9d55zparse560.exe
c:\windows\system32\9e43steal1z205.bin
c:\windows\system32\9e4zspars51842.exe
c:\windows\system32\9ee4szyw5re2297.bin
c:\windows\system32\9fzbthreat32585.ocx
c:\windows\system32\a3vz5392.dll
c:\windows\system32\a985pyw9re553z.bin
c:\windows\system32\b78s5za92687.exe
c:\windows\system32\bbddo5nl9ader2460z.dll
c:\windows\system32\bz0ba9kdo5r822.bin
c:\windows\system32\drivers\ESQULesnpkawwrwwpeyxrklchkqmtuclxqyep.sys
c:\windows\system32\e25spar9e2569z.bin
c:\windows\system32\e95thief5006z.cpl
c:\windows\system32\ESQULgpvsjvcsfhaiwcknltmkxoblmfwtuvxy.dll
c:\windows\system32\ESQULlkaduvbljotqpfctavaljshwlattfeyo.dll
c:\windows\system32\f9czhief2586.cpl
c:\windows\system32\temp#01.exe
c:\windows\system32\z0695ckdoor1674.exe
c:\windows\system32\z0982not-a-v5rus94.exe
c:\windows\system32\z1389hreat16385.bin
c:\windows\system32\z285threa923965.ocx
c:\windows\system32\z315spy59.bin
c:\windows\system32\z355virus1e9.ocx
c:\windows\system32\z3739spamb5t996.cpl
c:\windows\system32\z3859arse1976.ocx
c:\windows\system32\z3891sp59bot7c1.dll
c:\windows\system32\z3d29hief5699.ocx
c:\windows\system32\z4715s5a9bot33c.cpl
c:\windows\system32\z521spyware1927.bin
c:\windows\system32\z593steal584.bin
c:\windows\system32\z6579hreat25784.ocx
c:\windows\system32\z695addware348.dll
c:\windows\system32\z775h9cktool257.bin
c:\windows\system32\z7999worm158.ocx
c:\windows\system32\z799sp5rs91088.ocx
c:\windows\system32\z9053not-a-vir5s7749.ocx
c:\windows\system32\z9155spy64c.bin
c:\windows\system32\z956s9arse1816.bin
c:\windows\system32\z9ac9pyware9535.bin
c:\windows\system32\za12sp9rse2756.exe
c:\windows\system32\zdfd5par9e1261.dll
c:\windows\system32\zf259ir591.ocx
c:\windows\system32\zf6cs5arse936.dll
c:\windows\z1755hreat1519.ocx
c:\windows\z192worm195.ocx
c:\windows\z225ot-a9virus39e.exe
c:\windows\z2420vir5s491.bin
c:\windows\z3341virus259.dll
c:\windows\z355vir198.cpl
c:\windows\z4175s5y695.dll
c:\windows\z495troj23.bin
c:\windows\z52wo9m5c6.exe
c:\windows\z53825acktool90d.cpl
c:\windows\z558spamb9t142.ocx
c:\windows\z559worm536.ocx
c:\windows\z5a55teal1898.cpl
c:\windows\z6359spy5c29.bin
c:\windows\z70s9ywar53044.dll
c:\windows\z74at9r5at14647.ocx
c:\windows\z8977wo5m97c.cpl
c:\windows\z952spa95e862.cpl
c:\windows\za849d5ware41.bin
c:\windows\za84addware59539.dll
c:\windows\zee059ief2504.bin
c:\windows\zf3ca5dwar92938.dll
c:\windows\zf52vir1499.cpl
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ESQULserv.sys
-------\Legacy_ESQULserv.sys
-------\Service_ESQULserv.sys
((((((((((((((((((((((((( Files Created from 2009-07-13 to 2009-08-13 )))))))))))))))))))))))))))))))
.
2009-11-24 20:05 . 2009-11-24 20:05 6629 ----a-w- c:\windows\36675ack9zor.bin
2009-08-13 06:07 . 2009-08-13 06:07 -------- d-----w- c:\windows\system32\URTTEMP
2009-08-13 01:32 . 2009-08-13 06:06 -------- d-----w- c:\documents and settings\Pestend\Application Data\Reg Tool
2009-08-13 01:32 . 2009-08-13 01:42 -------- d-----w- C:\reg tool
2009-08-13 01:31 . 2009-08-13 01:31 -------- d-----w- c:\program files\Downloaded Installers
2009-08-11 13:57 . 2009-08-11 13:57 -------- d-----w- c:\documents and settings\Pestend\Application Data\Malwarebytes
2009-08-09 22:30 . 2009-08-09 22:30 -------- d-----w- c:\program files\Trend Micro
2009-08-09 06:01 . 2009-08-12 05:00 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-09 05:25 . 2009-08-03 03:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-09 05:25 . 2009-08-11 13:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-09 05:25 . 2009-08-09 05:25 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-08-09 05:25 . 2009-08-03 03:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-09 05:19 . 2009-08-09 05:19 152576 ----a-w- c:\documents and settings\Pestend\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-04 07:47 . 2009-08-04 07:47 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\FLEXnet
2009-08-04 05:08 . 2009-08-04 05:08 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\ALM
2009-08-04 04:51 . 2008-04-06 19:38 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
2009-08-04 04:51 . 2008-04-06 19:38 45392 ----a-r- c:\windows\system32\AdobePDF.dll
2009-08-04 04:42 . 2009-08-04 04:42 -------- d-----w- c:\program files\Adobe Media Player
2009-08-04 04:35 . 2009-08-04 04:35 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-07-21 05:21 . 2004-08-30 04:25 438272 ----a-w- c:\windows\system32\vp6vfw.dll
2009-07-21 05:21 . 2005-01-21 02:20 118832 ----a-w- c:\windows\system32\SHW32.DLL
2009-07-21 05:03 . 2009-07-21 05:03 -------- d-----w- c:\program files\EA SPORTS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-13 07:15 . 2008-09-16 06:49 16608 ----a-w- c:\windows\gdrv.sys
2009-08-12 04:37 . 2008-11-09 02:26 34 ----a-w- c:\windows\system32\BD2140.DAT
2009-08-11 10:46 . 2008-09-16 07:37 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\NOS
2009-08-11 10:36 . 2008-09-16 07:37 -------- d-----w- c:\program files\NOS
2009-08-09 12:56 . 2008-09-16 07:42 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-09 10:13 . 2008-09-16 07:31 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-09 05:20 . 2008-12-04 05:31 -------- d-----w- c:\program files\Java
2009-08-08 23:14 . 2008-09-16 07:40 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\avg8
2009-08-04 07:48 . 2008-09-16 06:22 120528 ----a-w- c:\documents and settings\Pestend\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-24 19:23 . 2008-12-04 05:31 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 05:21 . 2008-09-16 05:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-18 14:40 . 2008-11-12 02:46 -------- d-----w- c:\documents and settings\Pestend\Application Data\U3
2009-07-12 03:23 . 2009-07-12 03:13 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Norton
2009-07-12 03:13 . 2008-09-15 12:43 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Symantec
2009-07-12 03:13 . 2009-07-12 03:13 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\NortonInstaller
2009-07-07 23:47 . 2008-11-12 05:24 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-07 08:48 . 2009-03-09 04:22 -------- d-----w- c:\program files\Kodak
2009-07-07 08:44 . 2008-11-20 09:43 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Apple Computer
2009-07-06 09:34 . 2008-09-21 13:07 -------- d-----w- c:\documents and settings\Pestend\Application Data\dvdcss
2009-06-29 16:12 . 2007-07-27 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2007-07-27 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2007-07-27 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 23:44 . 2008-11-12 05:24 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-25 23:44 . 2008-11-12 05:24 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-22 00:58 . 2009-03-09 04:20 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Kodak
2009-06-16 14:36 . 2007-07-27 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2007-07-27 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 22:48 . 2008-12-04 05:33 34 ----a-w- c:\documents and settings\Pestend\jagex_runescape_preferences.dat
2009-06-11 21:42 . 2009-06-11 21:42 390664 ----a-w- c:\documents and settings\Pestend\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-03 19:09 . 2007-07-27 12:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-01 12:46 . 2009-02-02 12:12 15688 ----a-w- c:\windows\system32\lsdelete.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Reg Tool"="c:\reg tool\Reg Tool.exe" [2009-08-10 37614856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"GEST"="c:\program files\GIGABYTE\GEST\RUN.exe" [2008-10-19 236040]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2008-01-07 864256]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-25 1948440]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-06 520024]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-28 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-02-13 16857600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoThumbnailCache"= 1 (0x1)
"RestrictRun"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-25 23:44 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/02/2009 9:32 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/11/2008 3:24 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/11/2008 3:24 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/11/2008 3:24 PM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/11/2008 3:24 PM 298776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [19/01/2009 7:34 AM 1029456]
R3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\gsvr.exe [16/09/2008 4:50 PM 55816]
S3 pohci13F;pohci13F;\??\c:\docume~1\ARRONE~1\LOCALS~1\Temp\pohci13F.sys --> c:\docume~1\ARRONE~1\LOCALS~1\Temp\pohci13F.sys [?]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
mWindow Title = Microsoft Internet Explorer
uInternet Connection Wizard,ShellNext = iexplore
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-13 17:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1482476501-220523388-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c9,6e,45,f5,4e,15,09,c6,4e,73,67,4a,65,52,c5,7c,ff,c3,a5,20,0d,
c0,45,b3,fb,b8,9e,75,19,87,c8,6d,15,e4,be,bc,e1,da,0c,8d,94,13,0e,c1,0c,61,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1364)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\rundll32.exe
c:\program files\Lexmark 1200 Series\lxczbmon.exe
.
**************************************************************************
.
Completion time: 2009-08-13 17:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-13 07:16
Pre-Run: 127,885,320,192 bytes free
Post-Run: 129,269,108,736 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
943 --- E O F --- 2009-07-29 17:01