Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully ... . Windows Vista Home Edition (6.0.6002) Service Pack 2 [32_bits] - x86 Family 6 Model 15 Stepping 11, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [MpsSvc] RUNNING (state:4) Windows Firewall -> Enabled Windows Defender -> Enabled User Account Control (UAC) -> Enabled . Internet Explorer 8.0.6001.18828 Mozilla Firefox 3.5.3 (en-US) . C:\ [Fixed-NTFS] .. ( Total:450 Go - Free:117 Go ) D:\ [Fixed-NTFS] .. ( Total:14 Go - Free:4 Go ) E:\ [CD_Rom] F:\ [CD_Rom] H:\ [CD_Rom] I:\ [Removable] J:\ [Removable] K:\ [Removable] L:\ [Removable] . Scan : 00:12.50 Path : C:\Users\TJ Connolly\Desktop\Download Folder\Rooter.exe User : TJ Connolly ( Administrator -> YES ) . ----------------------\\ Processes . Locked [System Process] (0) Locked System (4) ______ \SystemRoot\System32\smss.exe (432) ______ C:\Windows\system32\csrss.exe (520) ______ C:\Windows\system32\wininit.exe (580) ______ C:\Windows\system32\csrss.exe (592) ______ C:\Windows\system32\services.exe (624) ______ C:\Windows\system32\lsass.exe (636) ______ C:\Windows\system32\lsm.exe (648) ______ C:\Windows\system32\winlogon.exe (808) ______ C:\Windows\system32\svchost.exe (824) ______ C:\Windows\system32\nvvsvc.exe (912) ______ C:\Windows\system32\svchost.exe (940) ______ C:\Windows\System32\svchost.exe (1000) ______ C:\Windows\System32\svchost.exe (1028) ______ C:\Windows\System32\svchost.exe (1060) ______ C:\Windows\system32\svchost.exe (1072) Locked audiodg.exe (1172) ______ C:\Windows\system32\svchost.exe (1196) ______ C:\Windows\system32\SLsvc.exe (1212) ______ C:\Windows\system32\svchost.exe (1280) ______ C:\Windows\system32\WUDFHost.exe (1444) ______ C:\Windows\system32\svchost.exe (1552) ______ C:\Windows\system32\nvvsvc.exe (1604) ______ C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (1720) ______ C:\Program Files\Alwil Software\Avast4\ashServ.exe (1740) ______ C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (1828) ______ C:\Windows\system32\Dwm.exe (444) ______ C:\Windows\Explorer.EXE (1372) ______ C:\Windows\System32\spoolsv.exe (1536) ______ C:\Windows\system32\taskeng.exe (1672) ______ C:\Windows\system32\svchost.exe (1636) ______ C:\Program Files\Windows Defender\MSASCui.exe (2336) ______ C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe (2364) ______ C:\Program Files\Dell Support Center\bin\sprtcmd.exe (2392) ______ C:\Program Files\VMware\VMware Player\hqtray.exe (2452) ______ C:\Program Files\Alwil Software\Avast4\ashDisp.exe (2588) ______ C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (2620) ______ C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (2680) ______ C:\Program Files\Pure Networks\Network Magic\nmapp.exe (2756) ______ C:\Program Files\Java\jre6\bin\jusched.exe (2764) ______ C:\Program Files\Zune\ZuneLauncher.exe (2772) ______ C:\Windows\OEM03Mon.exe (2780) ______ C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (2792) ______ C:\Program Files\Windows Sidebar\sidebar.exe (2840) ______ C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (2848) ______ C:\Program Files\Windows Live\Messenger\msnmsgr.exe (2888) ______ C:\Program Files\Electronic Arts\EADM\Core.exe (2924) ______ C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe (2944) ______ C:\Windows\ehome\ehtray.exe (2952) ______ C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe (2968) ______ C:\Windows\ehome\ehmsas.exe (3028) ______ C:\Program Files\Skype\Phone\Skype.exe (3048) ______ C:\Program Files\Windows Media Player\wmpnscfg.exe (3080) ______ C:\Program Files\Windows Sidebar\sidebar.exe (3128) ______ C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe (3204) ______ C:\Program Files\Stardock\Impulse\Now\ImpulseNow.exe (3244) ______ C:\Program Files\Mozilla Thunderbird\thunderbird.exe (3340) ______ C:\Program Files\Xfire\Xfire.exe (3404) ______ C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe (2140) ______ C:\Program Files\Skype\Plugin Manager\skypePM.exe (1960) ______ C:\Program Files\Vidalia Bundle\Tor\tor.exe (2388) ______ C:\Windows\system32\taskeng.exe (4056) ______ C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe (1996) ______ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (3536) ______ C:\Program Files\Bonjour\mDNSResponder.exe (3044) ______ C:\Windows\system32\svchost.exe (1040) ______ C:\Windows\system32\dlbacoms.exe (1256) ______ C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe (2748) ______ C:\Program Files\CDBurnerXP\NMSAccessU.exe (2580) ______ C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe (1248) ______ C:\Windows\system32\PnkBstrA.exe (4132) ______ C:\Windows\system32\PnkBstrB.exe (4144) ______ C:\Windows\system32\svchost.exe (4156) ______ C:\Program Files\Dell Support Center\bin\sprtsvc.exe (4192) ______ C:\Windows\system32\STacSV.exe (4208) ______ C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (4304) ______ C:\Windows\system32\svchost.exe (4440) ______ C:\Program Files\Tenable\Nessus\nessusd.exe (4496) ______ C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe (4532) ______ C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe (4572) ______ C:\Windows\system32\vmnat.exe (5300) ______ C:\Windows\System32\svchost.exe (5336) ______ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (5448) ______ C:\Windows\system32\SearchIndexer.exe (5504) ______ C:\Windows\system32\WUDFHost.exe (5664) ______ C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (5984) ______ C:\Program Files\VMware\VMware Player\vmware-authd.exe (4868) ______ C:\Windows\system32\vmnetdhcp.exe (5096) ______ C:\Program Files\Windows Live\Contacts\wlcomm.exe (5156) ______ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (5492) ______ C:\Windows\system32\wbem\wmiprvse.exe (6128) ______ C:\Windows\system32\taskeng.exe (4892) ______ C:\Windows\system32\wbem\unsecapp.exe (5520) ______ C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (3160) ______ C:\Windows\system32\wbem\wmiprvse.exe (5316) ______ C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (5108) ______ C:\Program Files\Windows Media Player\wmpnetwk.exe (5628) ______ C:\Program Files\Spiceworks\bin\spicetray.exe (7620) ______ C:\Program Files\Spiceworks\bin\spiceworks.exe (7740) ______ C:\Program Files\Xfire\Xfire.exe (7024) ______ C:\Program Files\Mozilla Firefox\firefox.exe (1924) ______ C:\Windows\servicing\TrustedInstaller.exe (2912) ______ C:\Windows\system32\wbem\unsecapp.exe (1252) ______ C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe (7788) ______ C:\Program Files\EVEMon\EVEMon.exe (5660) ______ C:\Program Files\Winamp\winamp.exe (7712) ______ C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (7032) ______ C:\Windows\explorer.exe (3320) ______ C:\Users\TJ Connolly\Desktop\Download Folder\Rooter.exe (8012) ______ C:\Program Files\Stardock\Impulse\Impulse.exe (6312) . ----------------------\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:41094144) \Device\Harddisk0\Partition2 (Start_Offset:41943040 | Length:16106127360) \Device\Harddisk0\Partition3 --[ MBR ]-- (Start_Offset:16148070400 | Length:483958718464) . ----------------------\\ Scheduled Tasks . C:\Windows\Tasks\Ad-Aware Update (Weekly).job C:\Windows\Tasks\Google Software Updater.job C:\Windows\Tasks\SA.DAT C:\Windows\Tasks\SCHEDLGU.TXT C:\Windows\Tasks\User_Feed_Synchronization-{78F1AD74-E994-46A4-9E25-6596A5FCC8E5}.job . ----------------------\\ Registry . . ----------------------\\ Files & Folders . C . ----------------------\\ Scan completed at 00:12.55 . C:\Rooter$\Rooter_2.txt - (22/10/2009 | 00:12.55).c