Her er de to resterende logs:
ComboFix 08-07-10.1 - Big S 2008-07-11 14:41:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1458 [GMT 2:00]
Running from: C:\Documents and Settings\Big S\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\HklVwyxx.ini
C:\WINDOWS\system32\HklVwyxx.ini2
C:\WINDOWS\system32\iamcccnw.dll
C:\WINDOWS\system32\iuowjrdl.dll
C:\WINDOWS\system32\jourvicy.dll
C:\WINDOWS\system32\ldrjwoui.ini
C:\WINDOWS\system32\qvlgmhwi.ini
C:\WINDOWS\system32\tabbdkeo.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-11 to 2008-07-11 )))))))))))))))))))))))))))))))
.
2008-07-11 14:10 . 2008-07-11 14:10 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-07-11 14:10 . 2008-07-11 14:10 <DIR> d-------- C:\Documents and Settings\Big S\Application Data\SUPERAntiSpyware.com
2008-07-11 14:10 . 2008-07-11 14:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-10 19:18 . 2008-07-11 13:29 110,517 --a------ C:\WINDOWS\BMfb73aec0.xml
2008-07-10 14:32 . 2008-07-10 14:32 <DIR> d-------- C:\Program Files\CAPCOM
2008-07-09 08:59 . 2008-07-09 08:58 29,760 --a------ C:\WINDOWS\system32\k6Hm0EF1.exe
2008-07-08 23:01 . 2008-07-08 23:01 96 --ah----- C:\WINDOWS\system32\HsInfo.dat
2008-07-08 21:27 . 2008-07-08 21:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-07-08 21:25 . 2004-08-09 05:04 73,728 --a------ C:\WINDOWS\system32\ISUSPM.cpl
2008-07-06 00:29 . 2008-07-06 00:29 268 --ah----- C:\sqmdata19.sqm
2008-07-06 00:29 . 2008-07-06 00:29 244 --ah----- C:\sqmnoopt19.sqm
2008-07-05 16:42 . 2008-07-05 16:42 268 --ah----- C:\sqmdata18.sqm
2008-07-05 16:42 . 2008-07-05 16:42 244 --ah----- C:\sqmnoopt18.sqm
2008-07-05 00:58 . 2008-07-05 00:58 268 --ah----- C:\sqmdata17.sqm
2008-07-05 00:58 . 2008-07-05 00:58 244 --ah----- C:\sqmnoopt17.sqm
2008-06-30 17:07 . 2008-06-30 17:07 <DIR> d-------- C:\Program Files\Blaze Media Pro
2008-06-30 17:06 . 2008-06-30 17:07 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\{71502C40-CE33-4AB6-9416-0A620783FB71}
2008-06-30 16:54 . 2008-06-30 20:37 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-25 17:58 . 2008-07-11 14:13 <DIR> d-------- C:\Program Files\NetSoftware
2008-06-23 19:38 . 2008-06-23 19:38 <DIR> d-------- C:\Program Files\Xvid
2008-06-23 19:38 . 2007-06-28 18:52 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-06-23 19:38 . 2007-06-28 18:54 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-06-23 19:38 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2008-06-20 11:03 . 2008-06-20 11:03 268 --ah----- C:\sqmdata16.sqm
2008-06-20 11:03 . 2008-06-20 11:03 244 --ah----- C:\sqmnoopt16.sqm
2008-06-15 09:01 . 2006-03-17 02:38 28,672 --------- C:\WINDOWS\system32\verclsid.exe
2008-06-11 10:28 . 2008-01-07 14:29 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-06-11 10:27 . 2008-06-11 10:27 <DIR> d-------- C:\Documents and Settings\Big S\Application Data\ESET
2008-06-11 10:26 . 2008-06-11 10:26 <DIR> d-------- C:\Program Files\ESET
2008-06-11 10:14 . 2008-06-11 10:14 <DIR> d-------- C:\Program Files\AVG
2008-06-11 10:14 . 2008-06-12 10:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-11 09:18 . 2008-06-13 15:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 09:18 . 2008-06-13 15:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-11 12:45 --------- d-----w C:\Program Files\Steam
2008-07-11 12:04 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-10 16:59 --------- d-----w C:\Documents and Settings\Big S\Application Data\uTorrent
2008-07-09 18:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-08 19:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-05 18:52 --------- d-----w C:\Program Files\World of Warcraft
2008-06-20 10:44 360,960 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:32 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-12 14:19 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-06-12 14:19 22,328 ----a-w C:\Documents and Settings\Big S\Application Data\PnkBstrK.sys
2008-06-11 08:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-06-10 16:36 --------- d-----w C:\Program Files\Teamspeak2_RC2
2008-06-10 16:36 --------- d-----w C:\Documents and Settings\Big S\Application Data\teamspeak2
2008-06-01 13:34 --------- d-----w C:\Program Files\Common Files\BioWare
2008-06-01 07:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Codemasters
2008-06-01 07:30 --------- d-----w C:\Program Files\OpenAL
2008-06-01 07:14 --------- d-----w C:\Program Files\Codemasters
2008-05-31 20:03 --------- d-----w C:\Program Files\Bonjour
2008-05-27 20:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\media center programs
2008-05-27 19:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Funcom
2008-05-24 21:19 --------- d-----w C:\Program Files\Ventrilo
2008-05-21 12:48 --------- d-----w C:\Program Files\Apple Software Update
2008-05-12 14:09 --------- d-----w C:\Program Files\Veoh Networks
2007-10-18 04:16 16,384 --sha-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
2007-10-18 04:16 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
2007-10-18 04:16 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012007101720071018\index.dat
2007-10-18 04:16 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-03-28 07:45 1271032]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-05-08 16:53 3640368]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 09:47 31016]
"Launch LgDevAgt"="C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe" [2007-12-13 18:59 346648]
"Launch LGDCore"="C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-12-13 18:57 2095640]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-08-09 05:03 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 05:03 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16:49 16126464 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-07-17 18:39 55824 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
SetPointII.lnk - C:\Program Files\Logitech\SetPoint II\SetpointII.exe [2007-08-30 19:13:06 319488]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytoosl"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Steam\\SteamApps\\bigbaddemon\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"C:\\Program Files\\World of Warcraft\\Repair.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-11-09 03:17]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 16:12]
S3 PciCon;PciCon;D:\PciCon.sys []
S3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-01-23 23:25]
S3 UsbFltr;Razer Copperhead Driver;C:\WINDOWS\system32\drivers\copperhd.sys [2005-11-02 19:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-07-09 19:20:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-10 22:12:02 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 07:00:01 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 08:00:01 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-11 09:00:01 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 10:00:03 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 11:00:03 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 12:00:02 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 13:00:01 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 14:00:02 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 15:00:01 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 16:00:03 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-09 06:59:12 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 17:00:02 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 18:00:02 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 19:00:01 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 20:00:01 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-10 21:00:02 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-09 06:59:12 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-09 06:59:12 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-09 06:59:12 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-09 06:59:12 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-09 06:59:12 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-09 06:59:12 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
"2008-07-09 06:59:12 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\k6Hm0EF1.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DAEMON Tools - C:\Program Files\DAEMON Tools\daemon.exe
HKLM-Run-NetSoftware - C:\Program Files\NetSoftware\Starter.exe
ShellExecuteHooks-{009E3F04-D7A2-456A-AE04-EB9ABF822FE4} - C:\DOCUME~1\BIGS~1\LOCALS~1\Temp\orzow.dll
Notify-WgaLogon - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-11 14:45:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-07-11 14:47:59 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-11 12:47:57
Pre-Run: 329,052,606,464 bytes free
Post-Run: 328,975,278,080 bytes free
245 --- E O F --- 2008-07-09 18:32:02
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 07/11/2008 at 02:32 PM
Application Version : 4.0.1154
Core Rules Database Version : 3502
Trace Rules Database Version: 1493
Scan type : Complete Scan
Total Scan Time : 00:16:10
Memory items scanned : 230
Memory threats detected : 2
Registry items scanned : 5409
Registry threats detected : 49
File items scanned : 16145
File threats detected : 18
Trojan.Vundo-Variant/Small-GEN
C:\WINDOWS\SYSTEM32\URQRKDUS.DLL
C:\WINDOWS\SYSTEM32\URQRKDUS.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77244082-D27E-416C-9661-FAD640973FCE}
HKCR\CLSID\{77244082-D27E-416C-9661-FAD640973FCE}
HKCR\CLSID\{77244082-D27E-416C-9661-FAD640973FCE}\InprocServer32
HKCR\CLSID\{77244082-D27E-416C-9661-FAD640973FCE}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{77244082-D27E-416C-9661-FAD640973FCE}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\urqRKDus
C:\WINDOWS\SYSTEM32\MLJAPMFE.DLL
C:\WINDOWS\SYSTEM32\TUVWOFDU.DLL
C:\WINDOWS\SYSTEM32\VTUMLBXW.DLL
Adware.Vundo Variant/Resident
C:\WINDOWS\SYSTEM32\XXYWVLKH.DLL
C:\WINDOWS\SYSTEM32\XXYWVLKH.DLL
Adware.URLBlaze
HKLM\Software\Classes\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}
HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}
HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}
HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\InprocServer32
HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\InprocServer32#ThreadingModel
HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\ProgID
HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\Programmable
HKCR\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\VersionIndependentProgID
C:\PROGRAM FILES\NETSOFTWARE\IEHELPER.DLL
Trojan.Vundo-Variant/Small
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92F7262A-58AD-447B-81B9-23DADA3B1166}
HKCR\CLSID\{92F7262A-58AD-447B-81B9-23DADA3B1166}
HKCR\CLSID\{92F7262A-58AD-447B-81B9-23DADA3B1166}\InprocServer32
HKCR\CLSID\{92F7262A-58AD-447B-81B9-23DADA3B1166}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\XXYAYXPQ.DLL
C:\WINDOWS\SYSTEM32\XXYWXQGX.DLL
Adware.Tracking Cookie
C:\Documents and Settings\Big S\Cookies\big_s@msnportal.112.2o7[1].txt
C:\Documents and Settings\Big S\Cookies\big_s@2o7[2].txt
C:\Documents and Settings\Big S\Cookies\big_s@mediaplex[1].txt
C:\Documents and Settings\Big S\Cookies\big_s@apmebf[1].txt
Adware.WhenU
HKLM\Software\WhenUSearch
HKLM\Software\WhenUSearch#InstallDir
HKLM\Software\WhenUSearch#Version
HKLM\Software\WhenUSearch#pats_url
HKLM\Software\WhenUSearch#pat_chunks_url
HKLM\Software\WhenUSearch#update_url
HKLM\Software\WhenUSearch#ziptomsa_url
HKLM\Software\WhenUSearch#iptomsa_url
HKLM\Software\WhenUSearch#coupondataurl
HKLM\Software\WhenUSearch#InstallTime
HKLM\Software\WhenUSearch#zip
HKLM\Software\WhenUSearch\Partners
HKLM\Software\WhenUSearch\Partners\desktop
HKLM\Software\WhenUSearch\Partners\desktop#LastPartner
HKLM\Software\WhenUSearch\Partners\desktop#SetupCmdLine
HKLM\Software\WhenUSearch\Partners\desktop#Partner
HKLM\Software\WhenUSearch\Partners\desktop#InstallTime
HKLM\Software\WhenUSearch\Partners\desktop#PartnerDesc
HKLM\Software\WhenUSearch\WHSE
HKLM\Software\WhenUSearch\WHSE#Installed_rs
HKLM\Software\WhenUSearch\WHSE#uiver_rs
HKLM\Software\WhenUSearch\WHSE#exitsurvey_url
HKLM\Software\WhenUSearch\WHSE#Partner
HKLM\Software\WhenUSearch\WHSE#LastPartner
HKLM\Software\WhenUSearch\WHSE#InstallTime
HKLM\Software\WhenUSearch\WHSE#SetupCmdLine
HKLM\Software\WhenUSearch\WHSE#showSplash
C:\Program Files\Common Files\WhenU\DTAdapter.exe
C:\Program Files\Common Files\WhenU\DTPlugin.dll
C:\Program Files\Common Files\WhenU
Adware.Vundo Variant/Rel
HKLM\SOFTWARE\Microsoft\aoprndtws
HKLM\SOFTWARE\Microsoft\FCOVM
HKLM\SOFTWARE\Microsoft\RemoveRP
HKU\S-1-5-21-1202660629-1637723038-725345543-1003\Software\Microsoft\rdfa
Trojan.Unclassified-Packed/Suspicious
C:\DOCUMENTS AND SETTINGS\BIG S\DESKTOP\BACKUPS\BACKUP-20080711-135824-962.DLL
C:\DOCUMENTS AND SETTINGS\BIG S\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\TECTMT2R\3077AHNTDKSR[1].DLL
Trojan.Downloader-CREW
C:\SYSTEM VOLUME INFORMATION\_RESTORE{614E9E20-E69F-4483-BCAB-3DEAAA053695}\RP262\A0093154.DLL