Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.61.1033.18.3326.2238 [GMT 10:00]
Running from: c:\users\dimi\Desktop\ComboFix.exe
Command switches used :: c:\users\dimi\Desktop\CFScript.txt
AV: Trend Micro Internet Security Pro *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\vuze
c:\program files\vuze\plugins\azemp\mplayer\config
c:\program files\vuze\plugins\azupnpav\azupnpav_0.2.17.jar
c:\program files\vuze\plugins\azupnpav\azupnpav_0.2.17.zip
c:\program files\vuze\plugins\azupnpav\plugin.properties_0.2.17
c:\users\dimi\AppData\Local\Temp\ppcrlui_5908_2
c:\users\dimi\AppData\Roaming\Azureus
c:\users\dimi\AppData\Roaming\Azureus\.certs
c:\users\dimi\AppData\Roaming\Azureus\.keystore
c:\users\dimi\AppData\Roaming\Azureus\.lock
c:\users\dimi\AppData\Roaming\Azureus\active\7852C377D576AD415D26CD91A7F9705AF06D16B6.dat
c:\users\dimi\AppData\Roaming\Azureus\active\7852C377D576AD415D26CD91A7F9705AF06D16B6.dat.bak
c:\users\dimi\AppData\Roaming\Azureus\active\B6CFBF55DAAA7C024EB8D6E9C21266DCE9335F87.dat
c:\users\dimi\AppData\Roaming\Azureus\active\B6CFBF55DAAA7C024EB8D6E9C21266DCE9335F87.dat.bak
c:\users\dimi\AppData\Roaming\Azureus\active\CDF7C389D3E3A72606AF36B06B4B6A7E5FBA9196.dat
c:\users\dimi\AppData\Roaming\Azureus\active\CDF7C389D3E3A72606AF36B06B4B6A7E5FBA9196.dat.bak
c:\users\dimi\AppData\Roaming\Azureus\active\F310EA4305A35E5D2A005E1CD999F0131294E12A.dat
c:\users\dimi\AppData\Roaming\Azureus\active\F310EA4305A35E5D2A005E1CD999F0131294E12A.dat.bak
c:\users\dimi\AppData\Roaming\Azureus\azureus.config
c:\users\dimi\AppData\Roaming\Azureus\azureus.config.bak
c:\users\dimi\AppData\Roaming\Azureus\azureus.statistics
c:\users\dimi\AppData\Roaming\Azureus\azureus.statistics.bad
c:\users\dimi\AppData\Roaming\Azureus\azureus.statistics.bad1
c:\users\dimi\AppData\Roaming\Azureus\azureus.statistics.bak
c:\users\dimi\AppData\Roaming\Azureus\azureus.statistics.bak.bad
c:\users\dimi\AppData\Roaming\Azureus\cache\1191085919.ico
c:\users\dimi\AppData\Roaming\Azureus\cnetworks.config
c:\users\dimi\AppData\Roaming\Azureus\devices.config
c:\users\dimi\AppData\Roaming\Azureus\devices.config.bak
c:\users\dimi\AppData\Roaming\Azureus\dht\addresses.dat
c:\users\dimi\AppData\Roaming\Azureus\dht\contacts.dat
c:\users\dimi\AppData\Roaming\Azureus\dht\diverse.dat
c:\users\dimi\AppData\Roaming\Azureus\dht\general.dat
c:\users\dimi\AppData\Roaming\Azureus\dht\net3\addresses.dat
c:\users\dimi\AppData\Roaming\Azureus\dht\net3\contacts.dat
c:\users\dimi\AppData\Roaming\Azureus\dht\net3\diverse.dat
c:\users\dimi\AppData\Roaming\Azureus\dht\net3\version.dat
c:\users\dimi\AppData\Roaming\Azureus\dht\version.dat
c:\users\dimi\AppData\Roaming\Azureus\downloads.config
c:\users\dimi\AppData\Roaming\Azureus\downloads.config.bad
c:\users\dimi\AppData\Roaming\Azureus\downloads.config.bad1
c:\users\dimi\AppData\Roaming\Azureus\downloads.config.bak
c:\users\dimi\AppData\Roaming\Azureus\downloads.config.bak.bad
c:\users\dimi\AppData\Roaming\Azureus\friends.config
c:\users\dimi\AppData\Roaming\Azureus\friends.config.bak
c:\users\dimi\AppData\Roaming\Azureus\ipfilter.cache
c:\users\dimi\AppData\Roaming\Azureus\logs\alerts_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\clientid_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\CNetworks_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\debug_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\Devices_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\MetaSearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\MetaSearch_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\MetaSearch_Engine_3.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\MetaSearch_Engine_4.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\MetaSearch_Engine_5.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\NetStatus_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_alerts_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_AutoSpeedSearchHistory_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_clientid_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_CNetworks_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_debug_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_Devices_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_MetaSearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_MetaSearch_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_MetaSearch_Engine_3.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_MetaSearch_Engine_4.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_MetaSearch_Engine_5.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_NetStatus_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_seltrace_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_Subscriptions_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_thread_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_thread_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_v3.ads_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_v3.CMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_v3.emp_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_v3.emp_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_v3.Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_v3.Friends_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_v3.MD_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_v3.PMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_v3.Stream_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243335951225_WP_xsearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_alerts_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_AutoSpeedSearchHistory_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_clientid_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_CNetworks_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_debug_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_Devices_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_MetaSearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_MetaSearch_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_MetaSearch_Engine_3.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_MetaSearch_Engine_4.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_MetaSearch_Engine_5.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_NetStatus_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_seltrace_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_Subscriptions_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_thread_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_thread_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_v3.ads_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_v3.CMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_v3.emp_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_v3.emp_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_v3.Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_v3.Friends_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_v3.MD_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_v3.PMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_v3.Stream_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243338753546_WP_xsearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_alerts_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_AutoSpeedSearchHistory_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_clientid_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_CNetworks_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_debug_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_Devices_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_MetaSearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_MetaSearch_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_MetaSearch_Engine_3.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_MetaSearch_Engine_4.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_MetaSearch_Engine_5.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_NetStatus_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_seltrace_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_Subscriptions_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_thread_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_thread_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_v3.ads_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_v3.CMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_v3.emp_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_v3.emp_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_v3.Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_v3.Friends_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_v3.MD_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_v3.PMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_v3.Stream_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339622059_WP_xsearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_alerts_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_AutoSpeedSearchHistory_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_clientid_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_CNetworks_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_debug_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_Devices_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_MetaSearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_MetaSearch_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_MetaSearch_Engine_3.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_MetaSearch_Engine_4.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_MetaSearch_Engine_5.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_NetStatus_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_seltrace_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_Subscriptions_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_thread_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_thread_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_v3.ads_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_v3.CMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_v3.emp_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_v3.emp_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_v3.Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_v3.Friends_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_v3.MD_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_v3.PMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_v3.Stream_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243339997631_WP_xsearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_alerts_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_AutoSpeedSearchHistory_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_clientid_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_CNetworks_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_debug_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_Devices_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_MetaSearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_MetaSearch_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_MetaSearch_Engine_3.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_MetaSearch_Engine_4.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_MetaSearch_Engine_5.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_NetStatus_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_seltrace_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_Subscriptions_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_thread_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_thread_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_v3.ads_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_v3.CMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_v3.emp_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_v3.emp_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_v3.Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_v3.Friends_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_v3.MD_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_v3.PMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_v3.Stream_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243414665100_WP_xsearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_alerts_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_AutoSpeedSearchHistory_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_clientid_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_CNetworks_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_debug_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_Devices_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_MetaSearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_MetaSearch_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_MetaSearch_Engine_3.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_MetaSearch_Engine_4.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_MetaSearch_Engine_5.txt
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_NetStatus_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_seltrace_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_Subscriptions_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_thread_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_thread_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_v3.ads_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_v3.CMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_v3.emp_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_v3.emp_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_v3.Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_v3.Friends_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_v3.MD_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_v3.PMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_v3.Stream_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\save\1243425128375_WP_xsearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\seltrace_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\Subscriptions_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\thread_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\thread_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\v3.ads_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\v3.CMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\v3.emp_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\v3.emp_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\v3.Friends_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\v3.Friends_2.log
c:\users\dimi\AppData\Roaming\Azureus\logs\v3.MD_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\v3.PMsgr_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\v3.Stream_1.log
c:\users\dimi\AppData\Roaming\Azureus\logs\WP_xsearch_1.log
c:\users\dimi\AppData\Roaming\Azureus\metasearch.config
c:\users\dimi\AppData\Roaming\Azureus\metasearch.config.bak
c:\users\dimi\AppData\Roaming\Azureus\net\pm_4804.dat
c:\users\dimi\AppData\Roaming\Azureus\net\pm_default.dat
c:\users\dimi\AppData\Roaming\Azureus\plugins\azump\azump_1.3.jar
c:\users\dimi\AppData\Roaming\Azureus\plugins\azump\azump_1.3.zip
c:\users\dimi\AppData\Roaming\Azureus\plugins\azump\mplayer.exe
c:\users\dimi\AppData\Roaming\Azureus\plugins\azump\mplayer\config
c:\users\dimi\AppData\Roaming\Azureus\plugins\azupnpav\cd.dat
c:\users\dimi\AppData\Roaming\Azureus\sidebarauto.config
c:\users\dimi\AppData\Roaming\Azureus\sidebarauto.config.bak
c:\users\dimi\AppData\Roaming\Azureus\subs\07ABDD32A54D704B48FE.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\0C329A68DF4256DC4A85.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\19D197C718E86D5B1B15.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\23874448F3148CDD35E7.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\447229A3A371779E8871.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\4F5D92DCB17E8F9148BB.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\581765478D3517627C73.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\678B76E0C5A2B67655E1.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\7076DB20A5F225DDB82C.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\81136BEEE66A32A5CB53.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\8DE6E5753F5ADF094F49.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\9167E16C9B7944056AC7.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\9536237799C938A1CC7D.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\95B34C1A1F40931D0972.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\E61C34CDF3E87D7329ED.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\E67D8443DF3B6D5C02B4.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\E8139A68B1EC9E7A6DAD.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\E9DEE0D514B263FD12F8.vuze
c:\users\dimi\AppData\Roaming\Azureus\subs\F9D47A2DDBCD971A50C5.vuze
c:\users\dimi\AppData\Roaming\Azureus\subscriptions.config
c:\users\dimi\AppData\Roaming\Azureus\subscriptions.config.bak
c:\users\dimi\AppData\Roaming\Azureus\tables.config
c:\users\dimi\AppData\Roaming\Azureus\tables.config.bak
c:\users\dimi\AppData\Roaming\Azureus\timingstats.dat
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17238.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17239.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17240.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17241.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17242.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17243.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17244.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17245.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17246.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17247.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17248.tmp
c:\users\dimi\AppData\Roaming\Azureus\tmp\AZU17249.tmp
c:\users\dimi\AppData\Roaming\Azureus\torrents\Adobe_Photoshop_CS4_Extended___Keygen__amp__Activation_Patch.torrent
c:\users\dimi\AppData\Roaming\Azureus\torrents\AZU34884.tmp
c:\users\dimi\AppData\Roaming\Azureus\torrents\AZU59073.tmp
c:\users\dimi\AppData\Roaming\Azureus\torrents\Body Combat 36 video.torrent
c:\users\dimi\AppData\Roaming\Azureus\torrents\Body Combat 39 -AVI.torrent
c:\users\dimi\AppData\Roaming\Azureus\torrents\VA.-.Ministry.Of.Sound.Sessions.Six.3CDs.%282009%29.LanzamientosMp3.es.torrent
c:\users\dimi\AppData\Roaming\Azureus\tracker.config
c:\users\dimi\AppData\Roaming\Azureus\tracker.config.bad
c:\users\dimi\AppData\Roaming\Azureus\tracker.config.bad1
c:\users\dimi\AppData\Roaming\Azureus\tracker.config.bak
c:\users\dimi\AppData\Roaming\Azureus\tracker.config.bak.bad
c:\users\dimi\AppData\Roaming\Azureus\unsentdata.config
c:\users\dimi\AppData\Roaming\Azureus\unsentdata.config.bak
c:\users\dimi\AppData\Roaming\Azureus\update.log
c:\users\dimi\AppData\Roaming\Azureus\update.properties
c:\users\dimi\AppData\Roaming\Azureus\v3.Friends.dat
c:\users\dimi\AppData\Roaming\Azureus\v3.Friends.dat.bak
c:\users\dimi\AppData\Roaming\Azureus\VuzeActivities.config
c:\users\dimi\AppData\Roaming\Azureus\VuzeActivities.config.bak
c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
.
((((((((((((((((((((((((( Files Created from 2009-05-06 to 2009-06-06 )))))))))))))))))))))))))))))))
.
2009-06-06 06:30 . 2009-06-06 06:36 -------- d-s---w- \ComboFix
2009-06-02 12:01 . 2009-06-06 06:31 -------- d-----w- \Qoobox
2009-06-02 08:00 . 2009-06-02 08:00 -------- d-----w- c:\users\dimi\AppData\Roaming\WinPatrol
2009-06-02 08:00 . 2008-03-11 20:59 74 ----a-w- c:\users\dimi\AppData\Roaming\WinPatrol\Autoexec.bat
2009-06-02 08:00 . 2006-09-18 21:43 10 ----a-w- c:\users\dimi\AppData\Roaming\WinPatrol\Config.sys
2009-06-02 07:59 . 2009-06-02 07:59 -------- d-----w- c:\program files\BillP Studios
2009-05-30 05:37 . 2009-06-02 12:00 -------- d-----w- c:\users\dimi\AppData\Local\Microsoft Games
2009-05-28 23:34 . 2009-05-28 23:34 -------- d-----w- c:\users\dimi\Logitech
2009-05-28 23:33 . 2009-05-28 23:33 -------- d-----w- c:\program files\Common Files\Remote Control Software Common
2009-05-28 23:32 . 2009-05-28 23:32 -------- d-----w- c:\program files\Common Files\Remote Control USB Driver
2009-05-28 14:23 . 2009-05-28 21:25 -------- d-----w- C:\SysClean-WORM_DOWNAD
2009-05-28 14:23 . 2009-05-28 21:25 -------- d-----w- \SysClean-WORM_DOWNAD
2009-05-28 13:23 . 2009-05-28 13:29 77824 ----a-w- c:\windows\system32\kdfapi.dll
2009-05-28 13:23 . 2009-05-28 13:29 53248 ----a-w- c:\windows\system32\Kdfhok.dll
2009-05-28 13:23 . 2009-05-28 13:29 192512 ----a-w- c:\windows\system32\kdfvmgr.exe
2009-05-28 13:23 . 2009-05-28 13:29 387288 ----a-w- c:\windows\system32\kdfmgr.exe
2009-05-27 10:30 . 2009-05-27 12:26 10752 ----a-w- c:\windows\DCEBoot.exe
2009-05-25 03:56 . 2009-05-25 03:56 529224 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-05-24 11:17 . 2009-05-24 11:17 2855 ----a-w- c:\users\dimi\AppData\Roaming\Microsoft\Windows\Recent\[SUMOTorrent.com]_The_Total_Transformation_Program.pif
2009-05-24 11:17 . 2009-05-24 11:17 -------- d--h--w- c:\windows\PIF
2009-05-23 11:30 . 2009-05-23 11:30 -------- d-----w- c:\users\dimi\AppData\Roaming\CopyTransPhoto
2009-05-23 11:26 . 2009-05-23 11:26 -------- d-----w- c:\users\dimi\AppData\Roaming\iCloner
2009-05-23 11:11 . 2009-05-23 11:11 -------- d-----w- c:\program files\WindSolutions
2009-05-23 11:11 . 2009-05-23 11:11 -------- d-----w- c:\programdata\WindSolutions
2009-05-23 10:55 . 2009-05-23 11:11 -------- d-----w- c:\users\dimi\AppData\Roaming\WindSolutions
2009-05-21 10:32 . 2009-05-21 10:32 -------- d-----w- c:\users\dimi\AppData\Roaming\Canon
2009-05-21 10:30 . 2009-05-21 10:30 -------- d-----w- c:\users\dimi\AppData\Roaming\muvee Technologies
2009-05-20 14:07 . 2009-03-06 02:17 36368 ----a-w- c:\windows\system32\drivers\tmpreflt.sys
2009-05-20 14:07 . 2009-03-06 02:17 205328 ----a-w- c:\windows\system32\drivers\tmxpflt.sys
2009-05-20 14:07 . 2009-03-06 02:17 1195512 ----a-w- c:\windows\system32\drivers\vsapint.sys
2009-05-20 13:05 . 2009-05-20 13:05 -------- d-----w- c:\windows\LocalSSL
2009-05-20 13:03 . 2009-05-20 13:33 -------- d-----w- c:\programdata\Trend Micro
2009-05-20 13:02 . 2009-06-01 20:43 -------- d-----w- c:\program files\Trend Micro
2009-05-20 13:01 . 2009-04-02 23:08 50192 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2009-05-20 13:01 . 2009-04-02 23:08 50192 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2009-05-20 13:01 . 2009-04-02 23:08 153104 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-05-20 13:01 . 2009-03-03 23:12 80400 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2009-05-20 13:01 . 2009-03-03 23:12 256528 ----a-w- c:\windows\system32\drivers\tmwfp.sys
2009-05-20 13:01 . 2009-03-03 23:12 145424 ----a-w- c:\windows\system32\drivers\tmlwf.sys
2009-05-20 10:52 . 2009-05-20 12:59 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-19 13:03 . 2009-05-19 13:03 1372 ----a-w- c:\windows\system32\UMIqsc8.vbs
2009-05-19 13:02 . 2009-05-19 13:02 1372 ----a-w- c:\windows\system32\TU4Zq.vbs
2009-05-16 02:02 . 2009-05-16 02:30 -------- d-----w- c:\users\dimi\AppData\Roaming\FileZilla
2009-05-16 02:02 . 2009-05-16 02:02 -------- d-----w- c:\program files\FileZilla FTP Client
2009-05-15 14:38 . 2009-05-15 14:38 -------- d-----w- c:\users\dimi\AppData\Local\Cranium
2009-05-15 13:56 . 2009-05-15 13:56 -------- d-----w- c:\users\dimi\AppData\Local\Cranium_Consulting_and_Cu
2009-05-15 13:54 . 2009-05-15 13:54 25214 ----a-r- c:\users\dimi\AppData\Roaming\Microsoft\Installer\{E33EAB77-A36A-4FBF-BB15-2BBF74C7A796}\_EF17D54428325E9F699E95.exe
2009-05-15 13:54 . 2009-05-15 13:54 10398 ----a-r- c:\users\dimi\AppData\Roaming\Microsoft\Installer\{E33EAB77-A36A-4FBF-BB15-2BBF74C7A796}\_86ADF835B1C689592C69DA.exe
2009-05-15 13:54 . 2009-05-15 13:54 -------- d-----w- c:\program files\iPhoneBrowser
2009-05-15 04:08 . 2009-05-15 04:13 -------- d-----w- c:\programdata\GlobalSCAPE
2009-05-15 03:47 . 2009-05-15 03:47 -------- d-----w- c:\users\dimi\AppData\Local\GlobalSCAPE
2009-05-15 03:47 . 2009-05-15 03:47 -------- d-----w- c:\users\dimi\AppData\Roaming\GlobalSCAPE
2009-05-15 03:47 . 2009-05-15 03:47 -------- d-----w- c:\program files\GlobalSCAPE
2009-05-14 19:09 . 2009-05-14 19:09 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-05-14 19:09 . 2009-05-14 19:09 286720 ------w- c:\windows\Setup1.exe
2009-05-09 13:03 . 2009-05-09 13:03 -------- d-----w- c:\users\dimi\AppData\Roaming\ImTOO Software Studio
2009-05-09 07:15 . 2009-05-09 07:15 -------- d-----w- c:\users\dimi\AppData\Roaming\Computer Aces
2009-05-08 04:48 . 2009-05-08 05:34 -------- d-----w- c:\users\dimi\AppData\Roaming\Apple Computer
2009-05-08 04:48 . 2009-05-08 04:48 -------- d-----w- c:\users\dimi\AppData\Local\Apple Computer
2009-05-08 04:47 . 2009-05-23 11:04 -------- dc----w- c:\windows\system32\DRVSTORE
2009-05-08 04:47 . 2009-05-08 04:47 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-08 04:47 . 2009-05-08 04:47 -------- d-----w- c:\program files\Bonjour
2009-05-08 04:46 . 2009-05-08 04:47 -------- d-----w- c:\programdata\Apple Computer
2009-05-08 04:46 . 2009-05-08 04:47 -------- d-----w- c:\program files\QuickTime
2009-05-08 04:46 . 2009-05-08 04:46 -------- d-----w- c:\users\dimi\AppData\Local\Apple
2009-05-08 04:46 . 2009-05-08 04:46 -------- d-----w- c:\program files\Apple Software Update
2009-05-08 04:45 . 2009-05-23 11:04 -------- d-----w- c:\program files\Common Files\Apple
2009-05-08 04:45 . 2009-05-08 04:45 -------- d-----w- c:\programdata\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-06 06:21 . 2009-04-02 11:31 3488915456 --sha-w- \hiberfil.sys
2009-06-06 06:21 . 2009-04-02 11:31 3802546176 --sha-w- \pagefile.sys
2009-06-05 22:12 . 2009-04-02 22:39 3894 ----a-w- c:\windows\bthservsdp.dat
2009-05-30 07:54 . 2009-05-30 07:54 5844 --sha-w- c:\windows\system32\BE10.tmp
2009-05-28 23:33 . 2009-04-02 22:38 -------- d-----w- c:\program files\Logitech
2009-05-28 23:33 . 2008-03-11 20:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-28 13:24 . 2009-04-21 08:41 -------- d-----w- c:\program files\TomTom HOME 2
2009-05-25 07:57 . 2009-04-15 13:00 848 --sha-w- c:\programdata\KGyGaAvL.sys
2009-05-25 07:57 . 2009-04-15 13:00 848 --sha-w- c:\programdata\KGyGaAvL.sys
2009-05-24 11:10 . 2009-05-24 11:10 5844 --sha-w- c:\windows\system32\566E.tmp
2009-05-24 10:46 . 2009-05-24 10:46 0 ----a-w- c:\windows\system32\2E0C.tmp
2009-05-22 06:16 . 2009-05-22 06:16 5844 --sha-w- c:\windows\system32\A2D3.tmp
2009-05-20 15:25 . 2009-05-20 13:25 139 ----a-w- c:\windows\udpcrawl.tmp
2009-05-20 13:00 . 2009-04-02 22:59 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-05-19 11:19 . 2009-04-03 02:27 -------- d-----w- c:\programdata\Corel
2009-05-17 04:52 . 2008-03-11 21:02 -------- d-----w- c:\programdata\Microsoft Help
2009-05-15 14:14 . 2009-04-02 22:55 -------- d-----w- c:\program files\Acro Software
2009-05-13 12:52 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-04-22 23:01 . 2009-04-02 22:38 -------- d-----w- c:\programdata\Logitech
2009-04-21 08:41 . 2009-04-21 08:41 -------- d-----w- c:\programdata\TomTom
2009-04-21 08:41 . 2009-04-21 08:41 -------- d-----w- c:\users\dimi\AppData\Roaming\TomTom
2009-04-21 08:41 . 2009-04-21 08:41 -------- d-----w- c:\program files\TomTom International B.V
2009-04-21 08:40 . 2009-04-21 08:40 -------- d-----w- c:\program files\TomTom DesktopSuite
2009-04-17 10:36 . 2009-04-17 10:36 -------- d-----w- c:\programdata\WindowsSearch
2009-04-17 06:46 . 2009-04-02 23:01 -------- d-----w- c:\program files\Common Files\Adobe
2009-04-17 05:26 . 2009-04-17 05:26 -------- d-----w- c:\programdata\Redfield
2009-04-17 01:40 . 2009-04-17 01:40 -------- d-----w- c:\program files\Universe Plugins
2009-04-17 01:12 . 2009-04-17 01:12 27136 ----a-w- c:\windows\~GLH0000.TMP
2009-04-17 01:12 . 2009-04-17 01:12 155136 ----a-w- c:\windows\~GLC0000.TMP
2009-04-15 12:54 . 2009-04-03 02:28 5846 ----a-w- c:\windows\system32\KGyGaAvL.sys
2009-04-15 12:53 . 2009-04-02 11:51 254216 ----a-w- c:\users\dimi\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-15 12:53 . 2009-04-03 02:28 -------- d-----w- c:\users\dimi\AppData\Roaming\Corel
2009-04-15 12:44 . 2009-04-04 03:44 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-04-15 12:44 . 2009-04-15 12:35 -------- d-----w- c:\program files\Corel
2009-04-15 12:44 . 2009-04-15 12:35 -------- d-----w- c:\program files\Common Files\Corel
2009-04-15 12:35 . 2009-04-15 12:35 -------- d-----w- c:\program files\Common Files\Protexis
2009-04-15 12:32 . 2009-04-15 12:32 -------- d-----w- c:\program files\ImageSkill
2009-04-08 11:32 . 2009-04-08 11:31 -------- d-----w- c:\program files\Windows Live
2009-04-08 11:31 . 2009-04-08 11:31 -------- d-----w- c:\program files\Microsoft
2009-04-08 11:31 . 2009-04-08 11:31 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-04-08 11:26 . 2009-04-08 11:26 -------- d-----w- c:\program files\Common Files\Windows Live
2009-04-06 12:43 . 2009-04-05 00:32 88 ------w- c:\windows\system32\86AE9AE73D.sys
2009-04-05 10:25 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-04-05 10:03 . 2006-11-02 10:32 101888 ------w- c:\windows\system32\ifxcardm.dll
2009-04-05 10:03 . 2006-11-02 10:32 82432 ------w- c:\windows\system32\axaltocm.dll
2009-04-05 01:20 . 2009-04-05 00:33 88 ------w- c:\windows\system32\959FF83584.sys
2009-04-04 07:17 . 2009-04-03 02:28 88 ------w- c:\windows\system32\B51B91AEB8.sys
2009-04-04 06:36 . 2009-04-04 06:36 0 --sha-r- \MSDOS.SYS
2009-04-04 06:36 . 2009-04-04 06:36 0 --sha-r- \IO.SYS
2009-04-04 02:20 . 2009-04-04 02:20 18816 ------w- c:\windows\system32\drivers\dvd43llh.sys
2009-04-03 13:45 . 2009-04-03 13:45 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-04-03 13:45 . 2009-04-03 13:45 315392 ----a-w- c:\windows\HideWin.exe
2009-04-03 11:53 . 2009-04-03 11:53 167376 ----a-w- c:\users\dimi\AppData\Roaming\Mozilla\Firefox\Profiles\qpc85q0w.default\FlashGot.exe
2009-04-02 18:52 . 2009-04-02 18:52 269312 ----a-w- c:\windows\system32\es.dll
2009-04-02 18:46 . 2009-04-02 18:46 1965056 ----a-w- c:\windows\system32\NlsData001a.dll
2009-04-02 18:45 . 2009-04-02 18:45 6656 ----a-w- c:\windows\system32\kbd106n.dll
2009-04-02 18:45 . 2009-04-02 18:45 988216 ----a-w- c:\windows\system32\winload.exe
2009-04-02 18:45 . 2009-04-02 18:45 927288 ----a-w- c:\windows\system32\winresume.exe
2009-04-02 18:45 . 2009-04-02 18:45 40960 ----a-w- c:\windows\system32\srclient.dll
2009-04-02 18:45 . 2009-04-02 18:45 378368 ----a-w- c:\windows\system32\srcore.dll
2009-04-02 18:45 . 2009-04-02 18:45 318464 ----a-w- c:\windows\system32\rstrui.exe
2009-04-02 18:45 . 2009-04-02 18:45 14848 ----a-w- c:\windows\system32\srdelayed.exe
2009-04-02 18:45 . 2009-04-02 18:45 46592 ----a-w- c:\windows\system32\setbcdlocale.dll
2009-04-02 18:45 . 2009-04-02 18:45 19000 ----a-w- c:\windows\system32\kd1394.dll
2009-04-02 18:45 . 2009-04-02 18:45 615992 ----a-w- c:\windows\system32\ci.dll
2009-04-02 18:34 . 2009-04-02 18:34 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-04-02 18:34 . 2009-04-02 18:34 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-04-02 18:34 . 2009-04-02 18:34 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-04-02 18:34 . 2009-04-02 18:34 83968 ----a-w- c:\windows\system32\mscories.dll
2009-04-02 18:34 . 2009-04-02 18:34 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-04-02 12:56 . 2009-04-02 12:56 0 ----a-w- c:\windows\nsreg.dat
2009-04-02 12:40 . 2009-04-02 12:40 680 ----a-w- c:\users\dimi\AppData\Local\d3d9caps.dat
2009-04-02 12:12 . 2009-04-02 12:12 61440 ----a-w- c:\windows\system32\winipsec.dll
2009-04-02 12:12 . 2009-04-02 12:12 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-04-02 12:12 . 2009-04-02 12:12 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2009-04-02 12:12 . 2009-04-02 12:12 272896 ----a-w- c:\windows\system32\polstore.dll
2009-04-02 12:12 . 2009-04-02 12:12 94720 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-04-02 12:12 . 2009-04-02 12:12 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-04-02 12:12 . 2009-04-02 12:12 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-04-02 12:11 . 2009-04-02 12:11 296960 ----a-w- c:\windows\system32\gdi32.dll
2009-04-02 12:11 . 2009-04-02 12:11 212480 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-04-02 12:11 . 2009-04-02 12:11 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-04-02 12:11 . 2009-04-02 12:11 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-04-02 12:11 . 2009-04-02 12:11 1695744 ----a-w- c:\windows\system32\gameux.dll
2009-04-02 12:10 . 2009-04-02 12:10 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-04-02 12:10 . 2009-04-02 12:10 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-04-02 12:10 . 2009-04-02 12:10 1191936 ----a-w- c:\windows\system32\msxml3.dll
2009-04-02 12:10 . 2009-04-02 12:10 2048 ----a-w- c:\windows\system32\tzres.dll
2009-04-02 12:09 . 2009-04-02 12:09 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-04-02 12:09 . 2009-04-02 12:09 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-04-02 12:09 . 2009-04-02 12:09 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-04-02 12:09 . 2009-04-02 12:09 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-04-02 12:09 . 2009-04-02 12:09 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-04-02 12:08 . 2009-04-02 12:08 2927104 ----a-w- c:\windows\explorer.exe
2009-04-02 12:08 . 2009-04-02 12:08 29184 ------w- c:\windows\system32\drivers\BTHUSB.SYS
2009-04-02 12:08 . 2009-04-02 12:08 220160 ------w- c:\windows\system32\drivers\bthport.sys
2009-04-02 12:08 . 2009-04-02 12:08 19456 ------w- c:\windows\system32\drivers\bthenum.sys
2009-04-02 12:08 . 2009-04-02 12:08 181760 ------w- c:\windows\system32\fsquirt.exe
2009-04-02 12:08 . 2009-04-02 12:08 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-04-02 12:08 . 2009-04-02 12:08 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-07-10 00:04 . 2009-04-03 06:29 22 --sha-w- c:\windows\SMINST\HPCD.SYS
2008-03-11 20:25 . 2008-03-11 20:11 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-06-02_12.24.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-11 20:39 . 2009-06-06 06:23 46338 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-06-06 06:23 74804 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:05 . 2009-06-02 12:07 74804 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-04-02 11:42 . 2009-06-02 12:24 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-04-02 11:42 . 2009-06-06 06:21 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-04-02 11:42 . 2009-06-06 06:21 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-04-02 11:42 . 2009-06-02 12:24 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-02 11:42 . 2009-06-06 06:21 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-04-02 11:42 . 2009-06-02 12:24 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-04-02 11:48 . 2009-06-06 06:23 7610 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-694825972-2939018928-1126776167-1000_UserData.bin
+ 2009-06-06 06:21 . 2009-06-06 06:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-06-06 06:21 . 2009-06-06 06:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-23 03:04 . 2009-06-05 22:12 3632 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-04-05 13:38 . 2009-06-05 22:11 329308 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-01-19 942080]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-08-03 202024]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-04-08 251240]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-05-20 497008]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-23 33648]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2008-06-02 178712]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-07 1828136]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2005-12-05 691200]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2008-01-10 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-10 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-10 88608]
"Corel File Shell Monitor"="c:\program files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2008-08-08 16712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-06-01 341312]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-07-03 6266880]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-18 76304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-05-20 497008]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-3 809488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-694825972-2939018928-1126776167-1000]
"EnableNotificationsRef"=dword:00000004
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"= c:\program files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{7974E05B-14C3-494E-9916-C6F37A639725}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{8623164F-C1EF-4140-8E9A-296A56A75D38}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{AF5375E5-B574-4B3E-9CB3-AA87E4FEB809}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{05F9EC07-641D-4346-AF2B-929979AE6F15}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{6056547B-E44D-422F-98AC-746170618AB6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7CDD1C14-9911-4E0C-BFE6-6BD2115EFE75}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4C89D741-1B90-4210-B755-BC383498C46A}"= UDP:5353:Adobe CSI CS4
"{641ABE9A-0A28-43A7-8848-CD6E0A84C9F7}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{5AEF7CD3-E728-41D4-889E-BE685DD2FAE3}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{4FE22A03-5A87-4522-A3F5-33AC5D8684AE}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.5
"{0FF220C4-78B8-464B-88AC-B46D7A782736}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.5
"{1E3EC219-89C8-4CFE-9F3B-34914212F690}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.5
"{21C48E96-9B2E-4B95-A815-F07208018FB2}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.5
"{6E010190-9DDB-4E2D-AEC2-7C98E4459502}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{494724F2-066C-4DB8-8FA5-6D48F00BBA96}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"= c:\program files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7
R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\System32\drivers\tmlwf.sys [20/05/2009 11:01 PM 145424]
R2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [20/05/2009 11:05 PM 181584]
R2 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [21/05/2009 12:07 AM 36368]
R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\System32\drivers\tmwfp.sys [20/05/2009 11:01 PM 256528]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/04/2009 8:38 PM 92008]
R3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\System32\drivers\3xHybrid.sys [12/03/2008 6:26 AM 2831232]
S2 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [20/05/2009 11:01 PM 50192]
S2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [20/05/2009 11:04 PM 497008]
S2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [20/05/2009 11:04 PM 677128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\dimi\AppData\Roaming\Mozilla\Firefox\Profiles\qpc85q0w.default\
FF - prefs.js: browser.startup.homepage - www.google.com.au
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-06 16:36
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-06 16:37
ComboFix-quarantined-files.txt 2009-06-06 06:37
ComboFix2.txt 2009-06-02 12:30
Pre-Run: 344,067,653,632 bytes free
Post-Run: 344,036,065,280 bytes free
628 --- E O F --- 2009-05-21 09:07