Part 10
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\sdfmodifier.xml
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\t2_bg.res
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\theweb.mnu
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\top7.cdf
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\Top7_theweb.mnu
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\tsd_bg.res
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\zango_btn.res
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\zango_ie_menu.res
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\avatar.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans.idx
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans1.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\buttondir.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\cursors.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_1000.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_2000.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_3000.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bar.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bbar1.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_logos.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_other.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_weather.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\default.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\editblbuttons.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\email-t1-bg.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\icons2.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_games_icon.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_video.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords1.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\layout.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\linkpathlegal.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\s_icons_buttons.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\sales_buttons.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\samplegroups2.txt
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\samplegroups2.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\sdfmodifier.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\t2_bg.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\top7.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\tsd_bg.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_btn.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_ie_menu.xip
c:\documents and settings\Nanu\nah_log.dat
c:\documents and settings\Nanu\nah_temp1.exe
c:\program files\INSTALL.LOG
c:\windows\system32\TDSSmtve.dat
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\winlogon.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-12-06 to 2009-01-06 )))))))))))))))))))))))))))))))
.
2009-01-06 13:19 . 2009-01-06 13:19 53,248 --a------ c:\temp\catchme.dll
2009-01-04 22:49 . 2009-01-04 22:49 d-------- c:\documents and settings\All Users\Application Data\McAfee
2009-01-04 19:38 . 2009-01-04 19:38 10,520 --a------ c:\windows\SYSTEM32\avgrsstx.dll
2009-01-04 19:09 . 2009-01-04 19:09 d-------- c:\documents and settings\Nanu\Application Data\Malwarebytes
2009-01-04 18:32 . 2009-01-04 19:38 d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-04 18:32 . 2009-01-04 18:32 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-04 18:32 . 2009-01-04 18:38 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-01-04 18:32 . 2009-01-04 18:38 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-01-04 00:06 . 2009-01-04 00:06 d--h----- c:\windows\PIF
2009-01-03 23:54 . 2009-01-04 17:41 d--h----- C:\$AVG8.VAULT$
2009-01-03 22:02 . 2009-01-06 07:18 d-------- c:\windows\SYSTEM32\DRIVERS\Avg
2009-01-03 22:02 . 2009-01-03 22:02 d-------- c:\program files\AVG
2009-01-03 22:02 . 2009-01-06 12:29 d-------- c:\documents and settings\All Users\Application Data\avg8
2009-01-03 22:02 . 2009-01-04 19:38 98,440 --a------ c:\windows\SYSTEM32\DRIVERS\avgldx86.sys
2009-01-03 22:02 . 2009-01-04 19:38 90,632 --a------ c:\windows\SYSTEM32\DRIVERS\avgtdix.sys
2009-01-03 22:02 . 2009-01-04 19:38 12,936 --a------ c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys
2009-01-03 21:07 . 2009-01-03 22:03 d-------- c:\documents and settings\Administrator
2009-01-03 19:56 . 2009-01-03 19:56 870,128 --a------ c:\windows\SYSTEM32\mcs.rma
2009-01-03 19:56 . 2009-01-03 19:56 4 --a------ c:\windows\SYSTEM32\0624EB
2009-01-02 13:01 . 2009-01-04 17:45 d-------- c:\program files\Windows Live Safety Center
2009-01-02 11:05 . 2009-01-02 11:05 d-------- c:\documents and settings\All Users\Application Data\suspicious_1564938143
2008-12-29 23:06 . 2008-12-29 23:06 d-------- c:\program files\Bonjour
2008-12-23 10:08 . 2008-12-23 10:09 d-------- c:\documents and settings\Nanu\Application Data\Move Networks
2008-12-21 11:09 . 2008-12-21 11:09 45,056 --a------ c:\documents and settings\Nanu\wincgf64.exe
2008-12-12 11:18 . 2008-12-12 11:18 87,336 --a------ c:\windows\SYSTEM32\dns-sd.exe
2008-12-12 11:11 . 2008-12-12 11:11 61,440 --a------ c:\windows\SYSTEM32\dnssd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 03:27 --------- d-----w c:\program files\Java
2009-01-06 03:22 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-04 02:29 --------- d-----w c:\program files\Google
2009-01-04 02:13 --------- d-----w c:\documents and settings\Nanu\Application Data\Apple Computer
2009-01-04 02:05 --------- d-----w c:\program files\NStorm
2009-01-04 02:03 --------- d-----w c:\program files\IncrediMail
2009-01-01 00:43 --------- d-----w c:\documents and settings\Nanu\Application Data\WeatherBug
2008-12-27 00:19 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2008-12-05 16:50 --------- d-----w c:\program files\Coupons
2008-11-25 15:47 --------- d-----w c:\program files\iTunes
2008-11-25 15:47 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-25 15:38 --------- d-----w c:\program files\iPod
2008-11-25 15:37 --------- d-----w c:\program files\Common Files\Apple
2008-11-25 14:27 --------- d-----w c:\program files\QuickTime
2008-04-11 04:17 32 ----a-r c:\documents and settings\All Users\hash.dat
2007-11-26 00:25 62,024 -c--a-w c:\documents and settings\Nanu\Application Data\GDIPFONTCACHEV1.DAT
2005-07-16 10:41 41,573 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
2005-07-16 10:41 48,223 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
2005-07-16 10:41 160,871 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-08-20 09:06 32,768 --sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008082020080821\index.dat
.
More to follow
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\sdfmodifier.xml
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\t2_bg.res
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\theweb.mnu
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\top7.cdf
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\Top7_theweb.mnu
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\tsd_bg.res
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\zango_btn.res
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\2\zango_ie_menu.res
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\avatar.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans.idx
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans1.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\buttondir.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\cursors.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_1000.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_2000.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_3000.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bar.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bbar1.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_logos.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_other.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_weather.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\default.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\editblbuttons.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\email-t1-bg.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\icons2.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_games_icon.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_video.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords1.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\layout.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\linkpathlegal.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\s_icons_buttons.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\sales_buttons.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\samplegroups2.txt
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\samplegroups2.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\sdfmodifier.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\t2_bg.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\top7.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\tsd_bg.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_btn.xip
c:\documents and settings\Nanu\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_ie_menu.xip
c:\documents and settings\Nanu\nah_log.dat
c:\documents and settings\Nanu\nah_temp1.exe
c:\program files\INSTALL.LOG
c:\windows\system32\TDSSmtve.dat
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\winlogon.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-12-06 to 2009-01-06 )))))))))))))))))))))))))))))))
.
2009-01-06 13:19 . 2009-01-06 13:19 53,248 --a------ c:\temp\catchme.dll
2009-01-04 22:49 . 2009-01-04 22:49
2009-01-04 19:38 . 2009-01-04 19:38 10,520 --a------ c:\windows\SYSTEM32\avgrsstx.dll
2009-01-04 19:09 . 2009-01-04 19:09
2009-01-04 18:32 . 2009-01-04 19:38
2009-01-04 18:32 . 2009-01-04 18:32
2009-01-04 18:32 . 2009-01-04 18:38 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-01-04 18:32 . 2009-01-04 18:38 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-01-04 00:06 . 2009-01-04 00:06
2009-01-03 23:54 . 2009-01-04 17:41
2009-01-03 22:02 . 2009-01-06 07:18
2009-01-03 22:02 . 2009-01-03 22:02
2009-01-03 22:02 . 2009-01-06 12:29
2009-01-03 22:02 . 2009-01-04 19:38 98,440 --a------ c:\windows\SYSTEM32\DRIVERS\avgldx86.sys
2009-01-03 22:02 . 2009-01-04 19:38 90,632 --a------ c:\windows\SYSTEM32\DRIVERS\avgtdix.sys
2009-01-03 22:02 . 2009-01-04 19:38 12,936 --a------ c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys
2009-01-03 21:07 . 2009-01-03 22:03
2009-01-03 19:56 . 2009-01-03 19:56 870,128 --a------ c:\windows\SYSTEM32\mcs.rma
2009-01-03 19:56 . 2009-01-03 19:56 4 --a------ c:\windows\SYSTEM32\0624EB
2009-01-02 13:01 . 2009-01-04 17:45
2009-01-02 11:05 . 2009-01-02 11:05
2008-12-29 23:06 . 2008-12-29 23:06
2008-12-23 10:08 . 2008-12-23 10:09
2008-12-21 11:09 . 2008-12-21 11:09 45,056 --a------ c:\documents and settings\Nanu\wincgf64.exe
2008-12-12 11:18 . 2008-12-12 11:18 87,336 --a------ c:\windows\SYSTEM32\dns-sd.exe
2008-12-12 11:11 . 2008-12-12 11:11 61,440 --a------ c:\windows\SYSTEM32\dnssd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 03:27 --------- d-----w c:\program files\Java
2009-01-06 03:22 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-04 02:29 --------- d-----w c:\program files\Google
2009-01-04 02:13 --------- d-----w c:\documents and settings\Nanu\Application Data\Apple Computer
2009-01-04 02:05 --------- d-----w c:\program files\NStorm
2009-01-04 02:03 --------- d-----w c:\program files\IncrediMail
2009-01-01 00:43 --------- d-----w c:\documents and settings\Nanu\Application Data\WeatherBug
2008-12-27 00:19 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2008-12-05 16:50 --------- d-----w c:\program files\Coupons
2008-11-25 15:47 --------- d-----w c:\program files\iTunes
2008-11-25 15:47 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-25 15:38 --------- d-----w c:\program files\iPod
2008-11-25 15:37 --------- d-----w c:\program files\Common Files\Apple
2008-11-25 14:27 --------- d-----w c:\program files\QuickTime
2008-04-11 04:17 32 ----a-r c:\documents and settings\All Users\hash.dat
2007-11-26 00:25 62,024 -c--a-w c:\documents and settings\Nanu\Application Data\GDIPFONTCACHEV1.DAT
2005-07-16 10:41 41,573 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
2005-07-16 10:41 48,223 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
2005-07-16 10:41 160,871 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-08-20 09:06 32,768 --sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008082020080821\index.dat
.
More to follow