GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-10-30 17:23:13
Windows 6.1.7601 Service Pack 1
Running: xp32bzdk.exe
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79X2UZ5G\49493478-5a4e-4a35-baa7-83df349fd0ef[1].swf 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79X2UZ5G\SkyscraperScreens[1].swf 77646 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79X2UZ5G\glamadapt_srv[1].htm 6383 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79X2UZ5G\your-family-prepared-weather-emergency[1].htm 124231 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8YK09QNE\mytwtv;dcopt=ist;topic=transworld;pos=frame1;kw=;id=;sz=88x31;tile=2;remnant=yes;device=;ord=1031579073[1].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8YK09QNE\service[3].htm 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXI1YB4Q\PublisherEventServlet[1].txt 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXI1YB4Q\PublisherEventServlet[2].txt 5 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXI1YB4Q\cb_blogtitleimage_4262_4e1e3ab8c930f[1].gif 1378 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXI1YB4Q\jukPlayer[1].swf 101812 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXI1YB4Q\lookup-theword_com[1].htm 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXI1YB4Q\pc[1] 43 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FXI1YB4Q\a64016b0-fdd8-4a7a-8cc6-71eef1908839[1].swf 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\liftgeo[1].js 59 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\PublisherEventServlet[1].txt 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\skateboarding;dcopt=ist;topic=transworld;pos=x96;kw=landing;id=15;sz=1565x700;tile=4;remnant=yes;device=;ord=1700158678[1].js 38 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\features;dcopt=ist;topic=transworld;pos=top;kw=landing,photos;id=;sz=728x90;tile=1;remnant=yes;device=;ord=1221831577[1].js 1022 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\surly[5].js 2096 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\logCA5Y423P.gif 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\Track[5].txt 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\Track[6].txt 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\Track[7].txt 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\medications[1].htm 51520 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\res[1].js 16271 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\display_ads[1].htm 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\okinsider-321203-10-19-2012[1].mp4 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\optn=64[2].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\optn=64[3].js 681 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\849586b6a3d53c09bbb1b313c3dbb8f3_d709f38ef758b5066ef31b18039b8ce5x38db3aed920cf82ab059bfccbd02be6a[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\ros;pos=right3;tile=3;sz=300x250;ord=4591361065783927[1].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\iframe_containing[2].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\httpErrorPagesScripts[2] 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\Twonescreen;pos=right2;sz=300x250;ord=3925624919428757[1].js 610 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LF3DMK57\maskmask[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSAG9NK1\atids[2].htm 469 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSAG9NK1\logCALZISKJ.gif 43 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSAG9NK1\TidalTV_VPAID_V1_0_04[2].swf 7027 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSAG9NK1\CookieSetter[2].swf 868 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSAG9NK1\2307822[5].htm 31424 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSAG9NK1\the-hangover-movie-picture-51[1].jpg 2732 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSAG9NK1\ros;pos=right3;tile=3;sz=300x250;ord=3114562822760659[1].js 385 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PSAG9NK1\css_Di_0Kjd1VZeAYRjaw8zN4Bhrtk3Hq5FhE-PBxbbKRg4[1].css 4432 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\generic_3_fa_fv[1].xml 5451 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\image2[1].png 25739 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\r-box[1].png 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\showad[3].js 23613 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\Chickpea_curry_fa_thumb_medium[1].jpg 10279 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\logCALV13N8.gif 43 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\meta[1].htm 1715 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\timthumb[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\timthumb[2].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\adsCAGSQ29U.js 9418 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\137260_f520_fa_thumb_medium[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\smartad[1].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\the-hangover-movie-picture-50[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\ros;tile=1;dcopt=ist;poz=top;!c=f;sz=728x90;ord=425927272[1].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXMEVIB4\crossdomainCADC07PA.xml 269 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\cbcpc[1].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\adsCA0TB0YP.js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\js_S9lXwaNg1LjJKL0IZOH6PAFMy_JFiNySty8jkvvsbzw[1].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\inthisissue_ad[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\logCAULFI38.gif 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\xml;length=;campaign=;ord=570146094[1].xml 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\xrefid[2].gif 43 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\r7ywkg[1].gif 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\front[1].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\image1[1].png 18490 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\Track[8].txt 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\Track[9].txt 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\clear[1].gif 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\BirthdayCake_A[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\being-happy-and-putting-yourself-first[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\the-hangover-movie-picture-49[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\timthumb_fa_thumb_medium[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\Twonescreen;pos=right3;sz=300x250;ord=4591361065783927[1].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\1202678_DA_OTU4OTY0MDc=[2].jpg 5296 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\1202678_DA_OTU4OTY1NDY=[2].jpg 3356 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\1202678_DA_OTU4OTYyMzQ=[2].jpg 4015 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\1202678_DA_OTU4OTYyOTE=[1].jpg 3440 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\kid-health-tips[1].htm 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\drx-breastcancer-th-070312[1].jpg 10363 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\skateboarding;pos=right2;sz=300x250;ord=3890948679942845[1].js 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\Greek_Potato_Stew_Progress_Web_fa_thumb_medium[1].jpg 10512 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\green-salad-tomatoes-bread[1].jpg 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UXYRMXSO\crossdomainCAEIT33N.xml 0 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\BIJ9V13H.txt 882 bytes
File C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\S7L8WQQR.txt