gimp1967
Newbie


Posts: 7
|
 |
Vundo Infected
« on: Apr 16th, 2008, 12:49pm » |
Quote Modify
|
ComboFix 08-04-15.5 - me 2008-04-16 13:09:13.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1036 [GMT -4:00] Running from: C:\Users\me\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Users\me\AppData\Roaming\inst.exe C:\WINDOWS\System32\NpXIkUvw.ini C:\WINDOWS\System32\NpXIkUvw.ini2 C:\Windows\system32\opnolMCu.dll C:\Windows\system32\wvUkIXpN.dll . ((((((((((((((((((((((((( Files Created from 2008-03-16 to 2008-04-16 ))))))))))))))))))))))))))))))) . 2008-04-16 12:58 . 2008-04-16 12:58 <DIR> d-------- C:\Program Files\Trend Micro 2008-04-16 12:34 . 2008-04-16 12:34 <DIR> d-------- C:\Program Files\CCleaner 2008-04-15 17:38 . 2008-04-15 17:38 <DIR> d-------- C:\Users\me\AppData\Roaming\Sahmon Games 2008-04-11 11:53 . 2008-04-11 11:53 <DIR> d-------- C:\Program Files\ffdshow 2008-04-10 16:53 . 2008-04-10 16:53 <DIR> d-------- C:\Program Files\3DGroove 2008-04-09 16:25 . 2008-04-09 16:25 <DIR> dr------- C:\WINDOWS\System32\config\systemprofile\Music 2008-04-08 16:43 . 2008-04-08 16:43 <DIR> d-------- C:\Program Files\Virtools 2008-04-08 13:43 . 2008-04-08 13:43 <DIR> d-------- C:\Program Files\APC 2008-04-03 16:22 . 2008-04-03 16:23 <DIR> d-------- C:\Program Files\QuickTime 2008-04-01 17:24 . 2008-04-01 17:24 <DIR> d-------- C:\Users\me\AppData\Roaming\ACD Systems 2008-04-01 15:24 . 2008-04-01 15:24 <DIR> d-------- C:\Users\All Users\ACD Systems 2008-04-01 15:24 . 2008-04-01 15:24 <DIR> d-------- C:\ProgramData\ACD Systems 2008-04-01 15:24 . 2008-04-01 15:24 <DIR> d-------- C:\Program Files\ACD Systems 2008-04-01 15:04 . 2008-04-01 15:24 <DIR> d-------- C:\Program Files\Common Files\ACD Systems 2008-03-31 20:39 . 2008-03-31 20:39 <DIR> d-------- C:\Users\me\AppData\Roaming\ICAClient 2008-03-31 20:36 . 2008-03-31 20:36 <DIR> d-------- C:\Program Files\Citrix 2008-03-29 13:02 . 2008-04-08 14:45 <DIR> d-------- C:\Program Files\HollywoodPoker 2008-03-27 21:59 . 2008-03-27 21:59 <DIR> d-------- C:\Users\All Users\Lavasoft 2008-03-27 21:59 . 2008-03-27 21:59 <DIR> d-------- C:\ProgramData\Lavasoft 2008-03-27 21:59 . 2008-03-27 21:59 <DIR> d-------- C:\Program Files\Lavasoft 2008-03-27 21:58 . 2008-03-27 21:58 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-03-26 13:00 . 2008-04-10 14:14 <DIR> d-------- C:\Program Files\Microsoft Silverlight 2008-03-21 23:25 . 2008-03-21 23:25 <DIR> d-------- C:\Users\me\AppData\Roaming\Canon 2008-03-20 13:26 . 2008-04-05 12:20 <DIR> d-------- C:\Users\me\AppData\Roaming\dvdcss 2008-03-19 12:25 . 2008-03-19 12:25 <DIR> d-------- C:\Users\me\AppData\Roaming\vlc 2008-03-19 11:21 . 2008-03-19 11:21 <DIR> d-------- C:\Program Files\VideoLAN 2008-03-18 19:05 . 2008-03-18 19:05 <DIR> d-------- C:\Program Files\7-Zip 2008-03-18 13:46 . 2008-03-18 13:46 <DIR> d-------- C:\Users\me\AppData\Roaming\WildTangent 2008-03-18 13:30 . 2008-03-18 13:30 <DIR> d-------- C:\Program Files\TheWeatherNetwork 2008-03-17 16:54 . 2008-03-17 16:54 <DIR> d-------- C:\Users\me\AppData\Roaming\Apple Computer 2008-03-17 16:53 . 2008-03-17 16:54 <DIR> d-------- C:\Program Files\iTunes 2008-03-17 16:53 . 2008-03-17 16:53 <DIR> d-------- C:\Program Files\iPod 2008-03-17 16:53 . 2008-03-17 16:53 <DIR> d-------- C:\Program Files\Bonjour 2008-03-17 16:52 . 2008-03-17 16:53 <DIR> d-------- C:\Users\All Users\Apple Computer 2008-03-17 16:52 . 2008-03-17 16:53 <DIR> d-------- C:\ProgramData\Apple Computer 2008-03-17 16:52 . 2008-03-17 16:52 <DIR> d-------- C:\Program Files\Apple Software Update 2008-03-17 16:51 . 2008-03-17 16:51 <DIR> d-------- C:\Users\All Users\Apple 2008-03-17 16:51 . 2008-03-17 16:51 <DIR> d-------- C:\ProgramData\Apple 2008-03-17 16:51 . 2008-03-17 16:51 <DIR> d-------- C:\Program Files\Common Files\Apple 2008-03-17 16:40 . 2008-03-17 16:40 <DIR> d-------- C:\Program Files\Easy CD-DA Extractor 11 2008-03-17 16:02 . 2008-03-17 16:05 <DIR> d-------- C:\Users\me\AppData\Roaming\Darwin 2008-03-17 14:12 . 2008-03-17 14:12 <DIR> d-------- C:\Program Files\Google 2008-03-17 14:09 . 2008-04-16 10:30 <DIR> d-------- C:\Program Files\TrojanHunter 5.0 2008-03-17 12:20 . 2008-03-17 12:20 <DIR> dr------- C:\WINDOWS\System32\config\systemprofile\Pictures 2008-03-17 12:13 . 2008-03-17 12:14 <DIR> dr------- C:\WINDOWS\System32\config\systemprofile\Documents 2008-03-16 22:29 . 2008-03-16 22:29 <DIR> d-------- C:\Users\me\AppData\Roaming\PlayFirst 2008-03-16 22:29 . 2008-03-16 22:29 <DIR> d-------- C:\Users\All Users\PlayFirst 2008-03-16 22:29 . 2008-03-16 22:29 <DIR> d-------- C:\ProgramData\PlayFirst 2008-03-16 22:27 . 2008-03-16 22:27 <DIR> d-------- C:\Users\All Users\WLInstaller 2008-03-16 22:27 . 2008-03-16 22:27 <DIR> d-------- C:\ProgramData\WLInstaller 2008-03-16 22:27 . 2008-03-16 22:30 <DIR> d-------- C:\Program Files\Windows Live 2008-03-16 22:27 . 2008-03-16 22:30 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller 2008-03-16 22:20 . 2008-03-16 22:20 <DIR> d-------- C:\Program Files\UltraISO 2008-03-16 22:20 . 2008-03-16 22:20 <DIR> d-------- C:\Program Files\Common Files\EZB Systems 2008-03-16 22:16 . 2008-04-16 10:25 <DIR> d-------- C:\Users\me\AppData\Roaming\Vso 2008-03-16 22:16 . 2008-03-16 22:16 <DIR> d-------- C:\Program Files\VSO 2008-03-16 22:16 . 2008-03-16 22:16 47,360 --a------ C:\Users\me\AppData\Roaming\pcouffin.sys 2008-03-16 22:04 . 2008-03-16 22:04 <DIR> d-------- C:\Users\me\AppData\Roaming\Logitech 2008-03-16 22:01 . 2008-03-16 22:01 <DIR> d-------- C:\Users\me\AppData\Roaming\InstallShield 2008-03-16 21:29 . 2008-04-16 10:30 <DIR> d-------- C:\Program Files\The KMPlayer 2008-03-16 21:18 . 2008-03-28 19:39 <DIR> d-------- C:\Users\me\AppData\Roaming\OpenOffice.org2 2008-03-16 21:14 . 2008-03-16 21:14 <DIR> d-------- C:\Program Files\OpenOffice.org 2.3 2008-03-16 21:02 . 2008-04-16 13:23 <DIR> d-------- C:\Users\me\AppData\Roaming\uTorrent 2008-03-16 21:02 . 2008-03-16 21:02 <DIR> d--h----- C:\Users\All Users\CanonBJ 2008-03-16 21:02 . 2008-03-16 21:02 <DIR> d--h----- C:\ProgramData\CanonBJ 2008-03-16 21:02 . 2008-03-16 21:05 <DIR> d-------- C:\Program Files\uTorrent 2008-03-16 21:00 . 2008-03-16 21:00 <DIR> d--h----- C:\Program Files\CanonBJ 2008-03-16 20:55 . 2008-03-27 21:53 <DIR> d-------- C:\Users\me\AppData\Roaming\Winamp 2008-03-16 20:55 . 2008-03-27 21:53 <DIR> d-------- C:\Program Files\Winamp 2008-03-16 20:54 . 2008-03-17 17:30 <DIR> d-------- C:\Program Files\Java 2008-03-16 20:53 . 2008-03-16 20:53 <DIR> d-------- C:\Program Files\Common Files\Java 2008-03-16 20:52 . 2008-04-13 21:27 <DIR> d-------- C:\Users\All Users\Adobe 2008-03-16 20:51 . 2008-04-07 16:24 <DIR> d-------- C:\Program Files\Common Files\Adobe 2008-03-16 20:42 . 2008-03-16 20:42 <DIR> d-------- C:\Program Files\Tasty Planet 2008-03-16 20:42 . 2008-03-16 20:42 <DIR> d-------- C:\Program Files\ReflexiveArcade 2008-03-16 20:31 . 2008-03-16 20:35 <DIR> d-------- C:\Users\All Users\PopCap Games 2008-03-16 20:31 . 2008-03-16 20:35 <DIR> d-------- C:\ProgramData\PopCap Games 2008-03-16 20:31 . 2008-03-16 20:35 <DIR> d-------- C:\Program Files\PopCap Games 2008-03-16 20:25 . 2008-03-16 20:25 <DIR> d-------- C:\Users\me\AppData\Roaming\XemiComputers 2008-03-16 20:25 . 2008-03-16 20:25 <DIR> d-------- C:\Users\All Users\XemiComputers 2008-03-16 20:25 . 2008-03-16 20:25 <DIR> d-------- C:\ProgramData\XemiComputers 2008-03-16 20:25 . 2008-03-16 20:25 <DIR> d-------- C:\Program Files\XemiComputers 2008-03-16 19:38 . 2008-03-16 19:38 <DIR> d-------- C:\Users\me\AppData\Roaming\eMule 2008-03-16 19:38 . 2008-03-16 19:38 <DIR> d-------- C:\Users\All Users\eMule 2008-03-16 19:38 . 2008-03-16 19:38 <DIR> d-------- C:\ProgramData\eMule 2008-03-16 19:38 . 2008-03-16 19:38 <DIR> d-------- C:\Program Files\eMule 2008-03-16 19:16 . 2008-03-16 19:16 <DIR> d-------- C:\Users\me\AppData\Roaming\TrojanHunter 2008-03-16 18:59 . 2008-03-16 20:01 <DIR> d-------- C:\Users\All Users\NVIDIA 2008-03-16 18:59 . 2008-03-16 20:01 <DIR> d-------- C:\ProgramData\NVIDIA 2008-03-16 18:51 . 2008-03-16 22:01 <DIR> d-------- C:\Users\All Users\Logitech 2008-03-16 18:51 . 2008-03-16 19:01 <DIR> d-------- C:\Users\All Users\Logishrd 2008-03-16 18:51 . 2008-03-16 22:01 <DIR> d-------- C:\ProgramData\Logitech 2008-03-16 18:51 . 2008-03-16 19:01 <DIR> d-------- C:\ProgramData\Logishrd 2008-03-16 18:51 . 2008-03-16 22:01 <DIR> d-------- C:\Program Files\Logitech 2008-03-16 18:46 . 2008-03-16 22:02 <DIR> d-------- C:\Program Files\Common Files\logishrd 2008-03-16 18:22 . 2008-03-16 18:22 <DIR> d-------- C:\Program Files\MSXML 4.0 2008-03-16 18:10 . 2008-03-16 18:10 <DIR> d-------- C:\Program Files\Click-N-Type 2008-03-16 17:55 . 2008-04-16 10:31 <DIR> dr------- C:\Users\me\Searches 2008-03-16 17:55 . 2008-04-16 10:31 <DIR> dr------- C:\Users\me\Contacts 2008-03-16 17:49 . 2008-03-16 17:55 <DIR> d-------- C:\Users\me\AppData\Roaming\Hewlett-Packard . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-16 17:21 0 ----a-w C:\Windows\system32\drivers\lvuvc.hs 2008-04-16 14:33 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-04-16 14:30 --------- d-----w C:\ProgramData\Microsoft Help 2008-04-16 14:30 --------- d-----w C:\Program Files\Microsoft Works 2008-04-10 21:50 7,680 ----a-w C:\Windows\System32\ff_vfw.dll 2008-04-10 19:38 174 --sha-w C:\Program Files\desktop.ini 2008-04-10 19:28 --------- d-----w C:\Program Files\Windows Sidebar 2008-04-10 19:28 --------- d-----w C:\Program Files\Windows Photo Gallery 2008-04-10 19:28 --------- d-----w C:\Program Files\Windows Mail 2008-04-10 19:28 --------- d-----w C:\Program Files\Windows Journal 2008-04-10 19:28 --------- d-----w C:\Program Files\Windows Defender 2008-04-10 19:28 --------- d-----w C:\Program Files\Windows Collaboration 2008-04-10 19:28 --------- d-----w C:\Program Files\Windows Calendar 2008-04-10 19:05 82,432 ----a-w C:\Windows\System32\axaltocm.dll 2008-04-10 19:05 101,888 ----a-w C:\Windows\System32\ifxcardm.dll 2008-04-08 17:43 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-04-08 17:42 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-03-25 20:15 50,536 ----a-w C:\Windows\system32\drivers\WpsHelper.sys 2008-03-25 00:08 --------- d-----w C:\ProgramData\Symantec 2008-03-18 17:49 --------- d-----w C:\ProgramData\WildTangent 2008-03-17 02:59 --------- d-----w C:\Program Files\Yahoo! 2008-03-17 02:52 --------- d-----w C:\Program Files\Roxio 2008-03-17 02:52 --------- d-----w C:\Program Files\Common Files\Sonic Shared 2008-03-17 02:51 --------- d-----w C:\Program Files\Real 2008-03-17 02:51 --------- d-----w C:\Program Files\Common Files\Real 2008-03-17 02:16 47,360 ----a-w C:\Windows\system32\drivers\pcouffin.sys 2008-03-17 02:03 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2008-03-17 00:04 806 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF 2008-03-17 00:04 136,496 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS 2008-03-17 00:04 10,652 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT 2008-03-17 00:04 --------- d-----w C:\Program Files\Symantec 2008-03-16 22:06 1,857 --sha-r C:\Windows\system32\drivers\103C_HP_CPC_RY880AAR-ABA a6077c_YC_0Pavi_QMX2714_E72NAv3PrA2_49_ILEONITE_SASUSTek Computer INC._V5.00_B5.17_T070420_WUH0_L409_M2046_J204_7Intel_8Core2 4400_92_#070802_N808627DC_Z14F12F20_G10DE01DD.MRK 2008-03-16 21:55 --------- d-----w C:\ProgramData\Hewlett-Packard 2008-03-16 21:44 --------- d-sh--w C:\ProgramData\Templates 2008-03-16 21:44 --------- d-sh--w C:\ProgramData\Start Menu 2008-03-16 21:44 --------- d-sh--w C:\ProgramData\Favorites 2008-03-16 21:44 --------- d-sh--w C:\ProgramData\Documents 2008-03-16 21:44 --------- d-sh--w C:\ProgramData\Desktop 2008-03-16 21:44 --------- d-sh--w C:\ProgramData\Application Data 2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll 2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe 2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe 2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll 2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll 2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll 2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll 2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys 2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe 2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe 2008-02-22 05:05 615,992 ----a-w C:\Windows\System32\ci.dll 2008-02-22 05:01 826,880 ----a-w C:\Windows\System32\wininet.dll 2008-02-22 04:57 295,936 ----a-w C:\Windows\System32\gdi32.dll 2008-02-19 08:24 7,808 ----a-w C:\Windows\system32\drivers\psi_mf.sys 2008-01-25 07:55 229,376 ----a-w C:\Windows\System32\UCI32M27.dll 2008-01-19 07:43 376,376 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll 2008-01-19 07:43 3,600,440 ----a-w C:\Windows\System32\ntkrnlpa.exe 2008-01-19 07:43 3,548,728 ----a-w C:\Windows\System32\ntoskrnl.exe 2008-01-19 07:42 94,776 ----a-w C:\Windows\System32\MigAutoPlay.exe 2008-01-19 07:42 51,768 ----a-w C:\Windows\System32\PSHED.DLL 2008-01-19 07:42 247,352 ----a-w C:\Windows\System32\clfs.sys 2008-01-19 07:42 177,208 ----a-w C:\Windows\System32\halmacpi.dll 2008-01-19 07:42 141,880 ----a-w C:\Windows\System32\halacpi.dll 2008-01-19 07:41 24,120 ----a-w C:\Windows\System32\BOOTVID.DLL 2008-01-19 07:41 21,560 ----a-w C:\Windows\System32\kdusb.dll 2008-01-19 07:41 19,512 ----a-w C:\Windows\System32\kdcom.dll 2008-01-19 07:38 46,080 ----a-w C:\Windows\System32\NAPCRYPT.DLL 2008-01-19 07:38 4,595,712 ----a-w C:\Windows\System32\AuthFWSnapin.dll 2008-01-19 07:38 242,744 ----a-w C:\Windows\System32\rsaenh.dll 2008-01-19 07:38 155,704 ----a-w C:\Windows\System32\dssenh.dll 2008-01-19 07:38 131,640 ----a-w C:\Windows\System32\basecsp.dll 2008-01-19 07:38 103,936 ----a-w C:\Windows\System32\NAPHLPR.DLL 2008-01-19 07:38 1,203,792 ----a-w C:\Windows\System32\ntdll.dll 2008-01-19 07:36 996,352 ----a-w C:\Windows\System32\WMNetMgr.dll 2008-01-19 07:35 98,304 ----a-w C:\Windows\System32\mssitlb.dll 2008-01-19 07:34 98,816 ----a-w C:\Windows\System32\mfps.dll 2008-01-19 07:33 98,304 ----a-w C:\Windows\System32\makecab.exe 2008-01-19 07:32 879,616 ----a-w C:\Windows\System32\Bubbles.scr 2008-01-19 07:32 704,512 ----a-w C:\Windows\System32\PhotoScreensaver.scr 2008-01-19 07:32 5,714,432 ----a-w C:\Windows\System32\logon.scr 2008-01-19 07:32 258,048 ----a-w C:\Windows\System32\winspool.drv 2008-01-19 07:32 221,184 ----a-w C:\Windows\System32\Mystify.scr 2008-01-19 07:32 220,672 ----a-w C:\Windows\System32\Ribbons.scr 2008-01-19 07:32 21,504 ----a-w C:\Windows\System32\msacm32.drv 2008-01-19 07:32 166,912 ----a-w C:\Windows\System32\wdmaud.drv 2008-01-19 07:32 1,370,624 ----a-w C:\Windows\System32\Aurora.scr 2008-01-19 07:31 7,680 ----a-w C:\Windows\System32\spwizres.dll 2008-01-19 07:31 57,856 ----a-w C:\Windows\System32\nlsbres.dll 2008-01-19 07:31 118,272 ----a-w C:\Windows\System32\RDPENCDD.dll 2008-01-19 07:30 17,920 ----a-w C:\Windows\System32\netevent.dll 2008-01-19 07:29 705,536 ----a-w C:\Windows\System32\imagesp1.dll 2008-01-19 07:29 58,880 ----a-w C:\Windows\System32\msobjs.dll 2008-01-19 07:28 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll 2008-01-19 07:26 36,864 ----a-w C:\Windows\System32\cdd.dll 2008-01-19 06:06 8,147,456 ----a-w C:\Windows\System32\wmploc.DLL 2008-01-19 06:01 14,336 ----a-w C:\Windows\System32\tsddd.dll 2008-01-19 06:01 134,656 ----a-w C:\Windows\System32\rdpdd.dll 2008-01-19 05:52 56,320 ----a-w C:\Windows\System32\vga256.dll 2008-01-19 05:52 21,504 ----a-w C:\Windows\System32\vga64k.dll 2008-01-19 05:52 11,776 ----a-w C:\Windows\System32\framebuf.dll 2008-01-19 05:52 10,752 ----a-w C:\Windows\System32\vga.dll .
|
| « Last Edit: Apr 16th, 2008, 12:59pm by gimp1967 » |
IP Logged |
|
|
|