ComboFix 09-01-02.01 - Cynthia 2009-01-04 22:14:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1506 [GMT -5:00]
Running from: c:\documents and settings\Cynthia\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((( Files Created from 2008-12-05 to 2009-01-05 )))))))))))))))))))))))))))))))
.
2008-12-30 11:57 . 2008-12-30 11:57 <DIR> d-------- c:\program files\Bonjour
2008-12-26 21:36 . 2008-12-26 21:38 <DIR> d-------- c:\documents and settings\Cynthia\Application Data\vlc
2008-12-26 19:58 . 2008-12-26 21:40 <DIR> d-------- c:\documents and settings\Cynthia\Application Data\mIRC
2008-12-25 16:59 . 2008-12-25 16:59 <DIR> d-------- c:\program files\BitTornado
2008-12-25 16:59 . 2008-12-25 16:59 <DIR> d-------- c:\documents and settings\Cynthia\Application Data\.BitTornado
2008-12-25 09:59 . 2008-12-25 09:59 <DIR> d-------- c:\program files\Common Files\Remote Control Software Common
2008-12-25 09:59 . 2008-12-25 10:01 <DIR> d-------- c:\documents and settings\Cynthia\logitech
2008-12-25 09:58 . 2008-12-25 09:58 <DIR> d-------- c:\program files\Logitech
2008-12-25 09:58 . 2008-12-25 09:58 <DIR> d-------- c:\program files\Common Files\Remote Control USB Driver
2008-12-25 09:58 . 2008-12-25 09:58 <DIR> d-------- c:\documents and settings\Cynthia\Application Data\InstallShield
2008-12-20 22:28 . 2008-12-20 22:28 <DIR> d-------- C:\rsit
2008-12-20 13:34 . 2009-01-04 21:27 <DIR> d-------- c:\program files\HJT
2008-12-20 11:49 . 2008-12-20 11:49 <DIR> d-------- c:\program files\Panda Security
2008-12-20 11:49 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2008-12-19 23:38 . 2008-12-19 23:38 <DIR> d-------- c:\program files\Ares
2008-12-17 21:50 . 2008-12-17 21:50 <DIR> d-------- c:\program files\Sunbelt Software
2008-12-17 21:46 . 2008-12-17 21:46 <DIR> d-------- c:\program files\Avira
2008-12-17 21:46 . 2008-12-17 21:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-17 21:33 . 2008-12-18 16:21 <DIR> d-------- c:\program files\SUPERAntiSpyware
2008-12-17 21:33 . 2008-12-18 16:21 <DIR> d-------- c:\documents and settings\Cynthia\Application Data\SUPERAntiSpyware.com
2008-12-17 21:33 . 2008-12-17 21:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-17 21:31 . 2008-12-17 21:44 14,042,553 --a------ c:\windows\system32\RAW
2008-12-17 19:46 . 2008-12-17 19:46 <DIR> d--hs---- C:\found.000
2008-12-17 18:17 . 2008-12-17 18:17 <DIR> d-------- c:\documents and settings\Cynthia\Application Data\Malwarebytes
2008-12-17 18:17 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-17 18:16 . 2008-12-17 18:17 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-17 18:16 . 2008-12-17 18:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-17 18:16 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-16 08:26 . 2008-12-16 08:26 120 --a------ c:\windows\system32\afahahiy.tmp
2008-12-15 17:09 . 2008-12-15 17:09 8,192 --ahs---- c:\windows\Thumbs.db
2008-12-13 10:10 . 2008-12-13 10:10 1,589,605 ---hs---- c:\windows\system32\idufatap.tmp
2008-12-12 20:28 . 2008-12-12 20:28 <DIR> d-------- C:\Temp
2008-12-12 11:18 . 2008-12-12 11:18 87,336 --a------ c:\windows\system32\dns-sd.exe
2008-12-12 11:11 . 2008-12-12 11:11 61,440 --a------ c:\windows\system32\dnssd.dll
2008-12-11 19:48 . 2008-12-11 19:48 196,444 --a------ c:\windows\system32\dat32vn.exe
2008-12-11 19:48 . 2008-12-11 19:48 190,675 --a------ c:\windows\system32\dat32bn.exe
2008-12-11 19:48 . 2008-12-11 19:48 47,581 --a------ c:\windows\system32\wzdrafjdoecy.exe
2008-12-11 19:48 . 2008-12-11 19:48 39,936 ---h----- c:\windows\jmm.exe
2008-12-11 19:48 . 2008-12-11 19:48 9,728 ---h----- c:\windows\20081203051514-downloader_silent.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 16:56 --------- d-----w c:\program files\Common Files\Adobe
2008-12-27 02:02 --------- d-----w c:\documents and settings\Cynthia\Application Data\dvdcss
2008-12-27 01:48 --------- d-----w c:\program files\mIRC
2008-12-26 15:04 --------- d-----w c:\program files\SG2
2008-12-25 14:58 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-23 02:03 --------- d-----w c:\documents and settings\Andrew\Application Data\mIRC
2008-12-18 21:21 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-18 08:07 --------- d-----w c:\program files\Google
2008-12-18 02:35 --------- d-----w c:\documents and settings\Andrew\Application Data\Lavasoft
2008-12-13 06:40 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-02 17:32 --------- d-----w c:\program files\QuickTime
2008-12-02 17:12 --------- d-----w c:\program files\iTunes
2008-12-02 17:12 --------- d-----w c:\program files\iPod
2008-12-02 17:12 --------- d-----w c:\program files\Common Files\Apple
2008-12-02 17:12 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-02 17:00 --------- d-----w c:\program files\Safari
2008-11-24 01:32 --------- d-----w c:\documents and settings\Cynthia\Application Data\CopyTrans
2008-11-20 08:34 --------- d-----w c:\program files\WindSolutions
2008-11-20 08:34 --------- d-----w c:\documents and settings\Cynthia\Application Data\iCloner
2008-11-20 08:34 --------- d-----w c:\documents and settings\All Users\Application Data\CopyTransControlCenter
2008-11-20 08:33 --------- d-----w c:\documents and settings\Cynthia\Application Data\CopyTransControlCenter
2008-11-16 17:50 --------- d-----w c:\program files\AIM6
2008-11-16 17:09 --------- d-----w c:\program files\Common Files\Software Update Utility
2008-11-16 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-16 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\acccore
2008-11-16 16:03 --------- d-----w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-09 05:54 --------- d-----w c:\program files\IrfanView
2008-11-07 19:23 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 13:11 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ------w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-03-05 01:24 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-03-09 02:24 400 ----a-w c:\documents and settings\Nick\score.dat
2008-12-02 16:50 638,976 ----a-w c:\program files\mozilla firefox\components\nsadsoftinc.dll
2007-10-03 23:34 80 --sh--r c:\windows\system32\F7EF99F7EE.dll
2008-09-30 13:22 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008093020081001\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 1207080]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-04-23 95800]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"Google Update"="c:\documents and settings\Cynthia\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-16 7323648]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb06.exe" [2002-07-11 188416]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 c:\windows\stsystra.exe]
c:\documents and settings\Andrew\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2006-12-22 2746104]
c:\documents and settings\Nick\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
c:\documents and settings\Cynthia\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\palmOne\HOTSYNC.EXE [2004-04-13 299008]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-27 24576]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-02-20 282624]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 16423]
Run BBDTMngr.exe.lnk - c:\program files\Bright Bug Software\Shared\Screen Savers\BBDTMngr.exe [2004-11-20 176128]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Nick\\Desktop\\RedFaction\\RF.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Documents and Settings\\Cynthia\\Desktop\\Unused Desktop Shortcuts\\Ares.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiadap.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\VS7DEBUG\\MDM.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25714:TCP"= 25714:TCP:BitComet 25714 TCP
"25714:UDP"= 25714:UDP:BitComet 25714 UDP
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-12-20 28544]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-11 24652]
S0 hrhkrko;hrhkrko;c:\windows\system32\drivers\grdv.sys --> c:\windows\system32\drivers\grdv.sys [?]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\drivers\IcdUsb2.sys [2007-09-02 39048]
S3 UD;UD;c:\docume~1\Cynthia\LOCALS~1\Temp\UD.exe --> c:\docume~1\Cynthia\LOCALS~1\Temp\UD.exe [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2aecd6c4-d121-11dd-90bb-001676c7ec29}]
\Shell\Shell00\Command - J:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f61d696a-07f4-11dd-9037-001676c7ec29}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1991672920-3934449333-2286609329-1009.job
- c:\documents and settings\Cynthia\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 14:38]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Nick\Start Menu\Programs\IMVU\Run IMVU.lnk
O16 -: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://72.10.224.30/activex/AMC.cab
c:\windows\Downloaded Program Files\setup.inf
FF - ProfilePath - c:\documents and settings\Cynthia\Application Data\Mozilla\Firefox\Profiles\74nf7eas.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: keyword.URL - hxxp://www9.yoog.com/search.php?q=
FF - component: c:\program files\Mozilla Firefox\components\nsadsoftinc.dll
FF - plugin: c:\documents and settings\Cynthia\Local Settings\Application Data\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
[color=\"red\"]ATTENTION: FIREFOX POLICES IS IN FORCE [/color]
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: keyword.URL - hxxp://www9.yoog.com/search.php?q=
FF - user.js: keyword.enabled - true
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-04 22:15:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2009-01-04 22:17:24
ComboFix-quarantined-files.txt 2009-01-05 03:16:07
ComboFix2.txt 2009-01-05 02:06:34
Pre-Run: 149,287,124,992 bytes free
Post-Run: 149,291,479,040 bytes free
252 --- E O F --- 2008-12-18 08:00:36
Malwarebytes' Anti-Malware 1.32
Database version: 1616
Windows 5.1.2600 Service Pack 3
1/4/2009 10:22:53 PM
mbam-log-2009-01-04 (22-22-53).txt
Scan type: Quick Scan
Objects scanned: 66522
Time elapsed: 3 minute(s), 46 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\hikepohe.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\takihiru.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fagesefa.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\components\nsadsoftinc.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dat32bn.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dat32vn.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.