Trojan and virus - Virtual Dr Forums-Computer Tech Support
USA
Posts: 377
More—
ComboFix 09-07-20.01 - Charles F. Mitchell 07/20/2009 18:07.1.1 - NTFSx86
Microsoft Windows XP Home Edition in different 5.1.2600.3.1252.1.1033.18.1023.667 [GMT -4:00]
Running from: c:\documents and settings\Charles F. Mitchell\My Documents\My Received Files\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
C:\rawrite.exe
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Installer\1208e7b.msp
c:\windows\Installer\162ef3f.msi
c:\windows\Installer\17796f3.msi
c:\windows\Installer\20fdb1a.msp
c:\windows\Installer\21f35cb.msp
c:\windows\Installer\21f35cc.msp
c:\windows\Installer\21f35cd.msp
c:\windows\Installer\21f35ce.msp
c:\windows\Installer\21f35cf.msp
c:\windows\Installer\21f35d0.msp
c:\windows\Installer\21f35d1.msp
c:\windows\Installer\21f35d2.msp
c:\windows\Installer\21f35d3.msp
c:\windows\Installer\2cbc5.msi
c:\windows\Installer\95a4bf.msp
c:\windows\Installer\WMEncoder.msi
c:\windows\MailSwitch.ocx
c:\windows\system32\open.ico
.
((((((((((((((((((((((((((((((((((((((( in different detracting Other Deletions in different detracting )))))))))))))))))))))))))))))))))))))))))))))))))
.
((((((((((((((((((((((((((((((((((((((( in different detracting Drivers/Services in different detracting )))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-18 00:38 in different.
——-\Legacy_FILEMON
——-\Legacy_NPF
((((((((((((((((((((((((( in different detracting Files Created from 2009-06-20 to 2009-07-20 in different )))))))))))))))))))))))))))))))
. 2009-07-18 00:38 ——– d—–w- c:\documents and settings\Charles F.
(((((((((((((((((((((((((((((((((((((((( in different detracting Find3M Report in different detracting ))))))))))))))))))))))))))))))))))))))))))))))))))))
. Mitchell\Local Settings\Application Data\Temp
.
2009-07-20 21:50 in different.
Mitchell\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-20 17:04 in different. 2009-05-04 12:40 117760 —-a-w- c:\documents and settings\Charles F. 2008-09-20 03:08 ——– d—–w- c:\program files\Malwarebytes’ Anti-Malware
2009-07-20 17:04 in different. 2007-02-09 00:31 ——– d—–w- c:\documents and settings\Charles F.
2008-10-20 12:49 3775175 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes’ Anti-Malware\mbam-setup.exe
2009-07-20 16:22 in different. Mitchell\Application Data\Simple Sudoku
2009-07-19 12:40 in different. 2008-04-22 23:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-14 22:46 in different. 2003-05-18 23:54 ——– d—–w- c:\program files\America Online 8.0
2009-07-14 22:47 in different. 2008-06-22 15:24 ——– d—–w- c:\program files\SpywareBlaster
2009-07-13 17:36 in different.
2008-09-20 03:08 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-16 14:36 in different. 2008-09-20 03:08 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 17:36 in different. 2003-03-31 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 in different. 2009-06-11 15:36 ——– d—–w- c:\program files\Garmin GPS Plugin
2009-06-10 21:37 in different. 2003-03-31 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-11 15:36 in different.
2009-06-10 21:37 ——– d—–w- c:\program files\Skyhook Wireless
2009-06-10 21:28 in different. 2009-06-10 21:28 ——– d—–w- c:\program files\Garmin
2009-06-03 19:09 in different. 2009-06-10 21:28 ——– d—–w- c:\program files\DIFX
2009-06-10 21:28 in different. 2003-12-16 22:27 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-02 22:06 in different.
2008-12-16 17:17 ——– d—–w- c:\documents and settings\Charles F. 2009-06-02 22:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Zylom
2009-05-25 15:24 in different. Mitchell\Application Data\DVD Flick
2009-05-08 16:05 in different. Mitchell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-07 15:32 in different. 2003-07-13 20:07 140808 —-a-w- c:\documents and settings\Charles F.
2003-03-31 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 in different. 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2005-03-18 00:43 in different. 2004-02-06 22:05 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 in different. 2003-11-15 02:53 21 ——w- c:\program files\AVPersonalAVWIN.INI
2009-06-16 15:00 in different. 2006-03-08 17:06 28672 —-a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
. 2008-12-08 02:25 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2006-03-08 17:06 in different.
((((((((((((((((((((((((((((((((((((( in different detracting Reg Loading Points in different detracting ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.