Win32/VMalum.FXWU Virus

Status
Not open for further replies.
That looks a lot better

Remove

R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html

O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)

O15 - Trusted Zone: Home - Road Runner
O15 - Trusted Zone: Adobe
O15 - Trusted Zone: Annarie Purses
O15 - Trusted Zone: www3.benefitsweb.com
O15 - Trusted Zone: Golf Launchpad - Home Golf Simulator for PC, Mac and PlayStation3
O15 - Trusted Zone: Cheap Flights, Airline Tickets, Airfare, Hotels, Vacations, Rental Car & Cruises at CheapTickets
O15 - Trusted Zone: Cell Phones and cell phone plans - | Wireless from AT&T, formerly Cingular
O15 - Trusted Zone: City Guides by Citysearch
O15 - Trusted Zone: Costco.com: Offering thousands of items you won?t find in your local Costco.
O15 - Trusted Zone: Web Hosting by IPOWERWEB
O15 - Trusted Zone: Sale on Cameras and Accessories
O15 - Trusted Zone: Taylor De Cordoba


and then post another log.

Do you see any differences in your system?
 
Re: Win32/VMalum.FXWU Virus -New Malwarebyte log

Here is the latest and the greatest. I have my fingers crossed that all is well and stays that way. Thanks for all the help!!

Malwarebytes' Anti-Malware 1.40
Database version: 2713
Windows 5.1.2600 Service Pack 3

8/31/2009 6:43:30 AM
mbam-log-2009-08-31 (06-43-30).txt

Scan type: Quick Scan
Objects scanned: 158784
Time elapsed: 5 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
 
Re: Win32/VMalum.FXWU Virus - Hi jack This Log 09-08-31

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:24:21 PM, on 8/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\BUFFALO\LinkStation\LsBackup.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\WD\WD Anywhere Backup\MemeoBackup.exe
C:\Program Files\Memeo\AutoSync\MemeoAutoSync.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: EmailBHO - {647FD14A-C4F1-46F4-8FC3-0B40F54226F7} - C:\Program Files\jZip\WebmailPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [UpdReg] "C:\WINDOWS\UpdReg.EXE"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AudioHQU] C:\Program Files\Creative\SBAudigy2\AudioHQ\AHQTBU.EXE
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DesktopMaestro] C:\Program Files\Desktop Maestro\deskmech.exe /H
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1381341160-4190608193-2972498879-1009\..\Run: [Sonic RecordNow!] (User 'kodak')
O4 - HKUS\S-1-5-21-1381341160-4190608193-2972498879-1009\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'kodak')
O4 - HKUS\S-1-5-21-1381341160-4190608193-2972498879-500\..\Run: [Sonic RecordNow!] (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - Startup: BUFFALO EasyBackup.lnk = C:\Program Files\BUFFALO\LinkStation\LsBackup.exe
O4 - Startup: Memeo AutoSync Launcher.lnk = C:\Program Files\Memeo\AutoSync\MemeoLauncher.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WD Anywhere Backup Launcher.lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Travelaxe - {32A32D38-B8ED-4b3f-AFD0-EF23B697B5C1} - C:\Program Files\Travelaxe\Travelaxe.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} (ContactExtractor Class) - http://www.facebook.com/controls/contactx.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1134963415750
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.broderbund.com/IFW/Cabs/isetup.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/53/install/gtdownls.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - https://a248.e.akamai.net/f/248/546...img/operations/symbizpr/xcontrol/SymDlBrg.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://ak.imgag.com/imgag/cp/install/Crusher.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O16 - DPF: {FA945BB6-9D37-43FC-9B2A-AF09F56CBBF0} (moDiagCollectionActiveX Object) - http://yme.music.yahoo.com/qos/cabs/DiagCollectionControl.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: KodakDigitalDisplayService - Orb Networks, Inc. - C:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

--
End of file - 15523 bytes
 
Re: Win32/VMalum.FXWU Virus- Combo Fix Pt.1

ComboFix 09-08-31.03 - Ann Huntoon Gessen 08/31/2009 15:50.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1327 [GMT -7:00]
Running from: c:\documents and settings\Ann Huntoon Gessen\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

K:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.

2009-08-30 05:37 . 2009-08-30 05:37 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-08-30 05:33 . 2008-04-14 00:12 30749 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\vbajet32.dll
2009-08-30 05:33 . 2008-04-14 00:12 151583 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Msjint40.dll
2009-08-30 05:33 . 2008-04-14 00:12 102400 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Msjro.dll
2009-08-30 05:33 . 2008-04-14 00:11 57344 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Msadrh15.dll
2009-08-30 05:33 . 2008-04-14 00:11 536576 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Msado15.dll
2009-08-30 05:33 . 2008-04-14 00:11 200704 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Msadox.dll
2009-08-30 05:33 . 2008-04-14 00:11 380445 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Expsrv.dll
2009-08-30 05:33 . 2008-03-25 04:50 621344 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Mswstr10.dll
2009-08-30 05:33 . 2008-03-25 04:50 60192 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Msjter40.dll
2009-08-30 05:33 . 2008-03-25 04:50 248608 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Msjtes40.dll
2009-08-30 05:33 . 2008-03-25 04:50 355112 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Msjetoledb40.dll
2009-08-30 05:33 . 2008-03-25 04:50 1516568 ----a-w- c:\documents and settings\Administrator\Application Data\Creative\Media Database\JetFileBackup\Msjet40.dll
2009-08-30 05:31 . 2009-08-30 05:31 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-08-30 05:08 . 2009-08-30 05:08 -------- d-----w- c:\windows\system32\data
2009-08-29 22:21 . 2009-08-29 22:21 -------- d-----w- c:\documents and settings\Ann Huntoon Gessen\Application Data\Malwarebytes
2009-08-29 22:21 . 2009-08-03 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-29 22:21 . 2009-08-30 02:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-29 22:21 . 2009-08-29 22:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-29 22:21 . 2009-08-03 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-29 14:46 . 2009-08-29 14:46 -------- d-----w- c:\program files\Trend Micro
2009-08-27 17:38 . 2009-08-27 17:38 152576 ----a-w- c:\documents and settings\Ann Huntoon Gessen\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-24 01:47 . 2009-08-24 01:47 -------- d-----w- c:\program files\Common Files\Control Panels
2009-08-24 01:44 . 2009-08-24 01:44 -------- d-----w- c:\documents and settings\All Users\Application Data\ALM
2009-08-24 01:14 . 2009-08-24 01:14 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-08-22 01:51 . 2009-08-22 01:51 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-08-22 01:51 . 2009-08-24 01:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-12 03:17 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-09 11:22 . 2009-08-24 01:08 8224 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2009-08-05 09:01 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-31 03:41 . 2008-07-23 17:37 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-30 06:32 . 2004-01-12 22:40 -------- d-----w- c:\documents and settings\Ann Huntoon Gessen\Application Data\Creative
2009-08-30 05:33 . 2003-12-16 20:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\Creative
2009-08-30 02:56 . 2003-12-16 20:14 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-08-30 02:56 . 2003-12-16 20:14 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-08-27 17:41 . 2003-12-16 20:00 -------- d-----w- c:\program files\Java
2009-08-24 01:58 . 2004-02-02 23:18 351240 ----a-w- c:\documents and settings\Ann Huntoon Gessen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-24 01:51 . 2004-01-14 02:00 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-14 15:38 . 2008-04-03 14:11 -------- d-----w- c:\program files\Safari
2009-08-12 10:05 . 2008-12-09 22:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-08 05:35 . 2008-07-10 03:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-05 09:01 . 2002-12-12 06:14 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-25 22:14 . 2008-06-10 18:04 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-07-25 12:23 . 2009-02-21 03:28 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 14:24 . 2009-07-21 14:24 -------- d-----w- c:\program files\iTunes
2009-07-21 14:24 . 2004-06-27 23:04 -------- d-----w- c:\program files\iPod
2009-07-21 14:24 . 2007-07-13 14:48 -------- d-----w- c:\program files\Common Files\Apple
2009-07-21 14:06 . 2009-07-21 14:06 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-17 19:01 . 2002-08-29 11:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 06:43 . 2004-03-17 02:49 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 13:54 . 2009-07-09 13:54 -------- d-----w- c:\program files\Coupons
2009-07-03 17:09 . 2004-02-07 01:05 915456 ------w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2002-08-29 11:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2002-08-29 11:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2002-08-29 11:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2002-08-29 11:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2002-08-29 11:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2002-08-29 11:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2002-08-29 11:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2002-08-29 11:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2002-08-29 11:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2002-08-29 11:00 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2002-08-29 11:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 16:19 . 2002-08-29 11:00 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:27 . 2009-06-10 14:27 152576 ----a-w- c:\documents and settings\Ann Huntoon Gessen\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-10 14:13 . 2002-08-29 11:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2003-10-21 23:06 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2003-05-30 15:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2003-08-27 21:19 . 2004-05-24 20:46 36963 ----a-r- c:\program files\Common Files\SM1updtr.dll
.
 
Re: Win32/VMalum.FXWU Virus Combofix Pt.2

((((((((((((((((((((((((((((( SnapShot@2009-08-30_02.02.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-30 06:50 . 2001-08-17 20:35 36864 c:\windows\SYSTEM32\sfman32.dll
- 2003-12-16 20:07 . 2001-08-17 20:35 36864 c:\windows\SYSTEM32\sfman32.dll
+ 2009-08-30 05:07 . 2003-03-06 15:10 15840 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\pfmodnt.sys
+ 2009-08-30 05:07 . 2003-02-20 22:29 53674 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctdaught.dat
+ 2009-08-30 05:07 . 2008-04-14 00:12 23552 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\wdmaud.drv
+ 2009-08-30 05:07 . 2008-04-13 18:45 49408 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\stream.sys
+ 2009-08-30 05:07 . 2008-04-13 18:45 60160 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\drmk.sys
+ 2009-08-30 05:07 . 2001-08-17 20:35 36864 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Common\sfman32.dll
+ 2009-08-30 05:07 . 2003-02-20 22:20 65536 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Common\a3d.dll
+ 2007-04-09 19:33 . 2007-04-09 19:33 11776 c:\windows\SYSTEM32\inres.dll
+ 2002-12-12 06:14 . 2008-04-13 18:45 49408 c:\windows\SYSTEM32\DRIVERS\stream.sys
- 2002-12-12 06:14 . 2008-04-13 18:45 49408 c:\windows\SYSTEM32\DRIVERS\stream.sys
- 2003-12-16 20:07 . 2003-03-06 15:10 15840 c:\windows\SYSTEM32\DRIVERS\pfmodnt.sys
+ 2009-08-30 06:50 . 2003-03-06 15:10 15840 c:\windows\SYSTEM32\DRIVERS\pfmodnt.sys
+ 2009-06-25 08:25 . 2009-06-25 08:25 54272 c:\windows\SYSTEM32\DLLCACHE\wdigest.dll
+ 2002-12-12 06:14 . 2008-04-13 18:45 49408 c:\windows\SYSTEM32\DLLCACHE\stream.sys
- 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\SYSTEM32\DLLCACHE\secur32.dll
+ 2009-02-03 19:59 . 2009-06-25 08:25 56832 c:\windows\SYSTEM32\DLLCACHE\secur32.dll
+ 2009-06-24 11:18 . 2009-06-24 11:18 92928 c:\windows\SYSTEM32\DLLCACHE\ksecdd.sys
+ 2003-12-16 20:07 . 2008-04-13 18:45 60160 c:\windows\SYSTEM32\DLLCACHE\drmk.sys
+ 2003-12-16 20:07 . 2003-02-20 22:20 65536 c:\windows\SYSTEM32\DLLCACHE\a3d.dll
+ 2007-04-09 19:19 . 2007-04-09 19:19 26783 c:\windows\SYSTEM32\data\ctd20x.dat
+ 2007-04-09 18:25 . 2007-04-09 18:25 45568 c:\windows\SYSTEM32\ctppld.dll
+ 2009-08-30 06:50 . 2003-02-20 22:29 53674 c:\windows\SYSTEM32\ctdaught.dat
- 2003-12-16 20:07 . 2003-02-20 22:29 53674 c:\windows\SYSTEM32\ctdaught.dat
+ 2007-04-09 19:33 . 2007-04-09 19:33 86016 c:\windows\SYSTEM32\ctcoinst.dll
+ 2007-04-09 18:25 . 2007-04-09 18:25 48400 c:\windows\SYSTEM32\AddCat.exe
+ 2009-08-30 03:59 . 2009-08-30 03:59 49152 c:\windows\Installer\{5905F42D-3F5F-4916-ADA6-94A3646AEE76}\NewShortcut1.exe
+ 2009-08-30 03:59 . 2009-08-30 03:59 49152 c:\windows\Installer\{5905F42D-3F5F-4916-ADA6-94A3646AEE76}\ARPPRODUCTICON.exe
+ 2009-08-30 05:07 . 2003-02-20 22:24 6144 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctprxy2k.sys
+ 2009-08-30 05:07 . 2008-04-14 00:11 4096 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\ksuser.dll
- 2003-12-16 20:07 . 2003-02-20 22:24 6144 c:\windows\SYSTEM32\DRIVERS\ctprxy2k.sys
+ 2009-08-30 06:50 . 2003-02-20 22:24 6144 c:\windows\SYSTEM32\DRIVERS\ctprxy2k.sys
+ 2002-12-12 06:14 . 2008-04-14 00:11 4096 c:\windows\SYSTEM32\DLLCACHE\ksuser.dll
+ 2007-04-09 19:19 . 2007-04-09 19:19 2091 c:\windows\SYSTEM32\data\cts20x.dat
+ 2009-08-30 05:07 . 2003-03-26 21:32 141536 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\hap16v2k.sys
+ 2009-08-30 05:07 . 2003-03-26 21:31 823616 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ha10kx2k.sys
+ 2009-08-30 05:07 . 2003-02-20 22:24 116000 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\emupia2k.sys
+ 2009-08-30 05:07 . 2003-02-20 22:33 232723 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctstatic.dat
+ 2009-08-30 05:07 . 2003-02-20 22:24 135248 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctsfm2k.sys
+ 2009-08-30 05:07 . 2003-03-26 21:32 189504 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctoss2k.sys
+ 2009-08-30 05:07 . 2003-03-27 16:58 287920 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctdvda2k.sys
+ 2009-08-30 05:07 . 2003-02-20 22:44 190842 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctdlang.dat
+ 2009-08-30 05:07 . 2003-01-23 18:17 138716 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctbas2w.dat
+ 2009-08-30 05:07 . 2003-03-26 21:33 498688 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctaud2k.sys
+ 2009-08-30 05:07 . 2003-02-20 22:22 135040 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Win2K_XP\ctac32k.sys
+ 2009-08-30 05:07 . 2008-04-13 19:19 146048 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\portcls.sys
+ 2009-08-30 05:07 . 2008-04-13 19:16 141056 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\ks.sys
+ 2009-08-30 05:07 . 2003-02-20 22:26 655360 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Common\ctsblfx.dll
+ 2009-08-30 05:07 . 2003-02-20 22:25 495616 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Common\ctaudfx.dll
+ 2009-08-30 05:07 . 2003-02-20 22:25 126976 c:\windows\SYSTEM32\ReinstallBackups\0007\DriverFiles\Common\commonfx.dll
+ 2003-12-16 20:07 . 2008-04-13 19:19 146048 c:\windows\SYSTEM32\DRIVERS\portcls.sys
- 2003-12-16 20:07 . 2008-04-13 19:19 146048 c:\windows\SYSTEM32\DRIVERS\portcls.sys
- 2003-12-16 20:07 . 2003-03-26 21:32 141536 c:\windows\SYSTEM32\DRIVERS\hap16v2k.sys
+ 2009-08-30 06:50 . 2003-03-26 21:32 141536 c:\windows\SYSTEM32\DRIVERS\hap16v2k.sys
+ 2009-08-30 06:50 . 2003-03-26 21:31 823616 c:\windows\SYSTEM32\DRIVERS\ha10kx2k.sys
- 2003-12-16 20:07 . 2003-03-26 21:31 823616 c:\windows\SYSTEM32\DRIVERS\ha10kx2k.sys
- 2003-12-16 20:07 . 2003-02-20 22:24 116000 c:\windows\SYSTEM32\DRIVERS\emupia2k.sys
+ 2009-08-30 06:50 . 2003-02-20 22:24 116000 c:\windows\SYSTEM32\DRIVERS\emupia2k.sys
- 2003-12-16 20:07 . 2003-02-20 22:24 135248 c:\windows\SYSTEM32\DRIVERS\ctsfm2k.sys
+ 2009-08-30 06:50 . 2003-02-20 22:24 135248 c:\windows\SYSTEM32\DRIVERS\ctsfm2k.sys
+ 2009-08-30 06:50 . 2003-03-26 21:32 189504 c:\windows\SYSTEM32\DRIVERS\ctoss2k.sys
- 2003-12-16 20:07 . 2003-03-26 21:32 189504 c:\windows\SYSTEM32\DRIVERS\ctoss2k.sys
+ 2009-08-30 06:50 . 2003-03-26 21:33 498688 c:\windows\SYSTEM32\DRIVERS\ctaud2k.sys
- 2003-12-16 20:07 . 2003-03-26 21:33 498688 c:\windows\SYSTEM32\DRIVERS\ctaud2k.sys
- 2003-12-16 20:07 . 2003-02-20 22:22 135040 c:\windows\SYSTEM32\DRIVERS\ctac32k.sys
+ 2009-08-30 06:50 . 2003-02-20 22:22 135040 c:\windows\SYSTEM32\DRIVERS\ctac32k.sys
+ 2008-12-05 06:54 . 2009-06-25 08:25 147456 c:\windows\SYSTEM32\DLLCACHE\schannel.dll
+ 2003-12-16 20:07 . 2008-04-13 19:19 146048 c:\windows\SYSTEM32\DLLCACHE\portcls.sys
+ 2009-06-25 08:25 . 2009-06-25 08:25 136192 c:\windows\SYSTEM32\DLLCACHE\msv1_0.dll
+ 2009-04-15 08:35 . 2009-06-25 08:25 730112 c:\windows\SYSTEM32\DLLCACHE\lsasrv.dll
+ 2002-12-12 06:14 . 2008-04-13 19:16 141056 c:\windows\SYSTEM32\DLLCACHE\ks.sys
+ 2009-06-25 08:25 . 2009-06-25 08:25 301568 c:\windows\SYSTEM32\DLLCACHE\kerberos.dll
+ 2007-04-09 19:19 . 2007-04-09 19:19 233684 c:\windows\SYSTEM32\data\CTPM002W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CTPDXW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 232158 c:\windows\SYSTEM32\data\CTP4893W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 232158 c:\windows\SYSTEM32\data\CTP4891W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 232158 c:\windows\SYSTEM32\data\CTP4890W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4875W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4872W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4871W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4870W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4850W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 232158 c:\windows\SYSTEM32\data\CTP4840W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4832W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4831W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4830W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 267599 c:\windows\SYSTEM32\data\CTP4820W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 232158 c:\windows\SYSTEM32\data\CTP4790W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4780W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4760W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4670W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233024 c:\windows\SYSTEM32\data\CTP4620W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 233684 c:\windows\SYSTEM32\data\CTP1140W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 268778 c:\windows\SYSTEM32\data\CTP0930W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 269402 c:\windows\SYSTEM32\data\CTP0773W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 263543 c:\windows\SYSTEM32\data\CTP0760W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 265966 c:\windows\SYSTEM32\data\CTP073AW.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 265966 c:\windows\SYSTEM32\data\CTP0730W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 345761 c:\windows\SYSTEM32\data\CTP0679W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 345761 c:\windows\SYSTEM32\data\CTP0678W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 319757 c:\windows\SYSTEM32\data\CTP0669W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 319757 c:\windows\SYSTEM32\data\CTP0610W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 319757 c:\windows\SYSTEM32\data\CTP0600W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264060 c:\windows\SYSTEM32\data\CTP055AW.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264388 c:\windows\SYSTEM32\data\CTP0550W.DAT
+ 2007-04-09 19:20 . 2007-04-09 19:20 321377 c:\windows\SYSTEM32\data\CTP0531W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 232116 c:\windows\SYSTEM32\data\CTP0531L.DAT
+ 2007-04-09 19:20 . 2007-04-09 19:20 321377 c:\windows\SYSTEM32\data\CTP0530W.DAT
+ 2007-04-09 19:20 . 2007-04-09 19:20 232116 c:\windows\SYSTEM32\data\CTP0530L.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 263802 c:\windows\SYSTEM32\data\CTP046CW.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 263802 c:\windows\SYSTEM32\data\CTP046BW.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 263802 c:\windows\SYSTEM32\data\CTP046AW.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264130 c:\windows\SYSTEM32\data\CTP0469W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264130 c:\windows\SYSTEM32\data\CTP0468W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264130 c:\windows\SYSTEM32\data\CTP0466W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264130 c:\windows\SYSTEM32\data\CTP0465W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264130 c:\windows\SYSTEM32\data\CTP0464W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264060 c:\windows\SYSTEM32\data\CTP0463W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264130 c:\windows\SYSTEM32\data\CTP0462W.DAT
+ 2007-04-09 19:21 . 2007-04-09 19:21 264130 c:\windows\SYSTEM32\data\CTP0460W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 319757 c:\windows\SYSTEM32\data\CTP0400W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 320076 c:\windows\SYSTEM32\data\CTP0380W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 320076 c:\windows\SYSTEM32\data\CTP0360W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 320622 c:\windows\SYSTEM32\data\CTP0359W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 321552 c:\windows\SYSTEM32\data\CTP0358W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 322194 c:\windows\SYSTEM32\data\CTP0355W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 321529 c:\windows\SYSTEM32\data\CTP0352W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 323640 c:\windows\SYSTEM32\data\CTP0350W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 318254 c:\windows\SYSTEM32\data\CTP0320W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 318254 c:\windows\SYSTEM32\data\CTP0280W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 318341 c:\windows\SYSTEM32\data\CTP0249W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 319730 c:\windows\SYSTEM32\data\CTP0246W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 318254 c:\windows\SYSTEM32\data\CTP0245W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 319730 c:\windows\SYSTEM32\data\CTP0244W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 318800 c:\windows\SYSTEM32\data\CTP0243W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 319730 c:\windows\SYSTEM32\data\CTP0242W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 319070 c:\windows\SYSTEM32\data\CTP0240W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 275517 c:\windows\SYSTEM32\data\CTP0238W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 277159 c:\windows\SYSTEM32\data\CTP0232W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 275816 c:\windows\SYSTEM32\data\CTP0231W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 277159 c:\windows\SYSTEM32\data\CTP0230W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 236189 c:\windows\SYSTEM32\data\CTP0222W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 236189 c:\windows\SYSTEM32\data\CTP0221W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 276738 c:\windows\SYSTEM32\data\CTP0192W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 275169 c:\windows\SYSTEM32\data\CTP0191W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CTP017HW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CTP017GW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CTP017FW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CTP017EW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CTP017DW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CTP017CW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CTP017BW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CTP017AW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235259 c:\windows\SYSTEM32\data\CTP0170W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 276738 c:\windows\SYSTEM32\data\CTP0162W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 275427 c:\windows\SYSTEM32\data\CTP0161W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 232158 c:\windows\SYSTEM32\data\CTP0150W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235259 c:\windows\SYSTEM32\data\CTP0105W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235259 c:\windows\SYSTEM32\data\CTP0103W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235259 c:\windows\SYSTEM32\data\CTP0102W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235259 c:\windows\SYSTEM32\data\CTP0101W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235259 c:\windows\SYSTEM32\data\CTP0100W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 274587 c:\windows\SYSTEM32\data\CTP0095W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 276738 c:\windows\SYSTEM32\data\CTP0092W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 275169 c:\windows\SYSTEM32\data\CTP0091W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 276738 c:\windows\SYSTEM32\data\CTP0090W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 289409 c:\windows\SYSTEM32\data\CTP0073W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 289409 c:\windows\SYSTEM32\data\CTP0070W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235259 c:\windows\SYSTEM32\data\CTP0061W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235259 c:\windows\SYSTEM32\data\CTP0060W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 374041 c:\windows\SYSTEM32\data\CTEDSPW.DAT
+ 2007-04-09 19:20 . 2007-04-09 19:20 270927 c:\windows\SYSTEM32\data\CTEDSPUW.DAT
+ 2007-04-09 19:20 . 2007-04-09 19:20 270927 c:\windows\SYSTEM32\data\CTEDSPTW.DAT
+ 2007-04-09 19:20 . 2007-04-09 19:20 330665 c:\windows\SYSTEM32\data\CTEDSPPW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 294775 c:\windows\SYSTEM32\data\CTEDSPLW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 294775 c:\windows\SYSTEM32\data\CTEDSPKW.DAT
+ 2007-04-09 19:20 . 2007-04-09 19:20 348425 c:\windows\SYSTEM32\data\CTEDSPHW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 374041 c:\windows\SYSTEM32\data\CTEDSP2W.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 201502 c:\windows\SYSTEM32\data\CTEAPSW.DAT
+ 2007-04-09 19:19 . 2007-04-09 19:19 235142 c:\windows\SYSTEM32\data\CT0060W.DAT
+ 2009-08-30 06:50 . 2003-02-20 22:33 232723 c:\windows\SYSTEM32\ctstatic.dat
- 2003-12-16 20:07 . 2003-02-20 22:33 232723 c:\windows\SYSTEM32\ctstatic.dat
- 2003-12-16 20:07 . 2003-02-20 22:26 655360 c:\windows\SYSTEM32\ctsblfx.dll
+ 2009-08-30 06:50 . 2003-02-20 22:26 655360 c:\windows\SYSTEM32\ctsblfx.dll
+ 2007-04-09 19:33 . 2007-04-09 19:33 163328 c:\windows\SYSTEM32\ctdvinst.dll
- 2003-12-16 20:07 . 2003-02-20 22:44 190842 c:\windows\SYSTEM32\ctdlang.dat
+ 2009-08-30 06:50 . 2003-02-20 22:44 190842 c:\windows\SYSTEM32\ctdlang.dat
- 2003-12-16 20:07 . 2003-01-23 18:17 138716 c:\windows\SYSTEM32\ctbas2w.dat
+ 2009-08-30 06:50 . 2003-01-23 18:17 138716 c:\windows\SYSTEM32\ctbas2w.dat
+ 2009-08-30 06:50 . 2003-02-20 22:25 495616 c:\windows\SYSTEM32\ctaudfx.dll
- 2003-12-16 20:07 . 2003-02-20 22:25 495616 c:\windows\SYSTEM32\ctaudfx.dll
+ 2007-04-09 18:25 . 2007-04-09 18:25 444928 c:\windows\SYSTEM32\CTAPO32.dll
- 2003-12-16 20:07 . 2003-02-20 22:25 126976 c:\windows\SYSTEM32\commonfx.dll
+ 2009-08-30 06:50 . 2003-02-20 22:25 126976 c:\windows\SYSTEM32\commonfx.dll
+ 2007-04-12 15:10 . 2007-04-12 15:10 105728 c:\windows\SYSTEM32\APOMgrH.dll
 
Re: Win32/VMalum.FXWU Virus Combofix Pt.3

+ 2009-08-30 03:59 . 2009-08-30 03:59 275968 c:\windows\Installer\10edb0.msi
.
-- Snapshot reset to current date --
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-07-21 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-07-21 03:53 66912 ----a-w- c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"DesktopMaestro"="c:\program files\Desktop Maestro\deskmech.exe" [2008-08-01 3213200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2008-12-08 14088]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-08-08 177392]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2009-08-08 230664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-23 620152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"AudioHQU"="c:\program files\Creative\SBAudigy2\AudioHQ\AHQTBU.EXE" [2002-01-18 176128]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-21 366400]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]

c:\documents and settings\Ann Huntoon Gessen\Start Menu\Programs\Startup\
BUFFALO EasyBackup.lnk - c:\program files\BUFFALO\LinkStation\LsBackup.exe [2001-12-31 188416]
Memeo AutoSync Launcher.lnk - c:\program files\Memeo\AutoSync\MemeoLauncher.exe [2007-7-6 125976]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2009-8-23 295606]
Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2005-3-1 339968]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-5-12 73728]
WD Anywhere Backup Launcher.lnk - c:\windows\Installer\{649C4B1A-6A76-499A-9AEC-0C9530FA7D2C}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe [2008-7-20 9662]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-02-14 04:35 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax 4.3.lnk]
backup=c:\windows\pss\eFax 4.3.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
backup=c:\windows\pss\Event Reminder.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LimeWire 3.6.15 Pro.lnk]
backup=c:\windows\pss\LimeWire 3.6.15 Pro.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
backup=c:\windows\pss\NkbMonitor.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Oritron Network Media Server.lnk]
backup=c:\windows\pss\Oritron Network Media Server.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
backup=c:\windows\pss\TabUserW.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
backup=c:\windows\pss\ymetray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Ann Huntoon Gessen^Start Menu^Programs^Startup^eFax Live Menu 3.4.lnk]
backup=c:\windows\pss\eFax Live Menu 3.4.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ann Huntoon Gessen^Start Menu^Programs^Startup^eFax Tray Menu 3.4.lnk]
backup=c:\windows\pss\eFax Tray Menu 3.4.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ann Huntoon Gessen^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ann Huntoon Gessen^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Ann Huntoon Gessen\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ann Huntoon Gessen^Start Menu^Programs^Startup^PictureProject In Touch.lnk]
backup=c:\windows\pss\PictureProject In Touch.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"EPSONStatusAgent2"=2 (0x2)
"mnmsrvc"=3 (0x3)
"NPFMntor"=2 (0x2)
"aspnet_state"=3 (0x3)
"ACDaemon"=2 (0x2)
"TapiSrv"=3 (0x3)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"Wzcnfa20imi"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"VETMSGNT"=2 (0x2)
"TabletService"=2 (0x2)
"Symantec RemoteAssist"=3 (0x3)
"SQLAgent$MICROSOFTSMLBIZ"=3 (0x3)
"sprtsvc_medicsp2"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"Pwmaprrarxd"=3 (0x3)
"PPCtlPriv"=3 (0x3)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"MSSQLServerADHelper"=3 (0x3)
"MSSQL$MICROSOFTSMLBIZ"=2 (0x2)
"Microsoft Office Groove Audit Service"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"IAANTMon"=2 (0x2)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Faisler"=3 (0x3)
"Diskeeper"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"Adobe Version Cue CS3"=3 (0x3)
"Messenger"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Digital 5 Streaming Media\\D5MediaServer.exe"=
"c:\\Program Files\\Creative\\SB Wireless Music\\Media Server\\SBWMsvr.exe"=
"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=
"c:\\Program Files\\Java\\j2re1.4.2\\bin\\javaw.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1124498376\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\UPnP\\yupnpsrv.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Kodak\\Digital Display\\KodakDigitalDisplaySoftware.exe"=
"c:\\Program Files\\Kodak\\Digital Display\\OrbKodakLauncher\\DllStartupService.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:mad:xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R2 KodakDigitalDisplayService;KodakDigitalDisplayService;c:\program files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe [8/14/2008 2:10 PM 98304]
R3 hpusbfd;Hewlett-Packard USB Filter Class;c:\windows\SYSTEM32\DRIVERS\hpusbfd.sys [3/22/2005 12:28 PM 7552]
S3 EPUSBSTOR;EPSON USB Storage Driver;c:\windows\SYSTEM32\DRIVERS\epusbsto.sys [9/10/2001 10:00 AM 17976]
S3 pc100;Linksys EtherFast 10/100 PC Card NT Driver;c:\windows\SYSTEM32\DRIVERS\pc100nds.sys [6/13/2004 11:29 AM 30495]
S3 pcm100;Linksys EtherFast 10/100 Integrated PC Card NT Driver;c:\windows\SYSTEM32\DRIVERS\pcm100nd.sys [12/10/2001 3:53 PM 43008]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\SYSTEM32\DRIVERS\usbbc.sys [3/9/2004 2:56 PM 15576]
S4 AutoSyncService;Memeo AutoSync ;c:\program files\Memeo\AutoSync\MemeoService.exe [7/6/2007 6:28 PM 31768]
S4 Faisler;Faisler; [x]
S4 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [8/16/2007 10:10 PM 189704]
S4 Pwmaprrarxd;Pwmaprrarxd; [x]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/23/2009 3:42 PM 356920]
S4 sprtsvc_medicsp2;SupportSoft Sprocket Service (medicsp2);c:\program files\twc\medicsp2\bin\sprtsvc.exe [10/29/2007 9:47 AM 202280]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/10/2009 7:35 AM 24652]
S4 Wspiprmipr;Wspiprmipr; [x]
S4 Wzcnfa20imi;Wzcnfa20imi; [x]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-12 19:34]

2009-08-29 c:\windows\Tasks\CAAntiSpywareScan_Daily as Ann Huntoon Gessen at 12 08 PM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 05:10]

2009-08-31 c:\windows\Tasks\User_Feed_Synchronization-{53E3A94C-2864-4EA0-8180-8E8B6D0333EF}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:31]
.
 
Status
Not open for further replies.
Back
Top Bottom