ComboFix 10-05-04.06 - philip 05/05/2010 13:38:07.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.894.591 [GMT 1:00]
Running from: c:\documents and settings\philip\My Documents\Downloads\Programs\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\philip\Local Settings\Temporary Internet Files\0li5g.jpg
c:\documents and settings\philip\Local Settings\Temporary Internet Files\aD6qeEV.jpg
c:\documents and settings\philip\Local Settings\Temporary Internet Files\b0JVTR2mB.jpg
c:\documents and settings\philip\Local Settings\Temporary Internet Files\iNDSq6S5g.jpg
c:\documents and settings\philip\Local Settings\Temporary Internet Files\Oj70IU5Sv.jpg
c:\documents and settings\philip\Local Settings\Temporary Internet Files\p14L6p.jpg
c:\documents and settings\philip\Local Settings\Temporary Internet Files\R46xAmV21.jpg
c:\documents and settings\philip\Local Settings\Temporary Internet Files\xD4nB.jpg
c:\program files\WindowsUpdate
C:\restore
Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((( Files Created from 2010-04-05 to 2010-05-05 )))))))))))))))))))))))))))))))
.
2010-05-04 07:38 . 2010-04-12 16:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-29 20:06 . 2010-04-29 20:06 -------- d-----w- C:\found.002
2010-04-16 18:15 . 2010-04-16 18:15 57344 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-04-16 18:15 . 2010-04-16 18:13 754984 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Setup\Resource.dll
2010-04-16 18:15 . 2010-04-16 18:11 1180952 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Setup\DivXSetup.exe
2010-04-16 18:15 . 2010-04-16 18:15 56766 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-04-16 18:15 . 2010-04-16 18:15 56978 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-04-16 18:15 . 2010-04-16 18:15 57409 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-04-16 18:15 . 2010-04-16 18:15 53600 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Update\Uninstaller.exe
2010-04-16 18:15 . 2010-04-16 18:15 52963 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-04-16 18:14 . 2010-04-16 18:14 54073 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-04-16 18:13 . 2010-04-16 18:13 144696 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-04-16 18:11 . 2010-04-16 18:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\DivX
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-05 12:34 . 2010-01-29 18:18 -------- d-----w- c:\documents and settings\philip\Application Data\DMCache
2010-05-05 12:21 . 2008-04-27 14:38 -------- d-----w- c:\program files\LimeWire
2010-05-04 12:11 . 2008-11-09 19:30 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-04 07:38 . 2007-11-13 18:08 -------- d-----w- c:\program files\Java
2010-05-03 13:58 . 2009-06-29 16:43 -------- d-----w- c:\documents and settings\philip\Application Data\Spotify
2010-05-02 16:01 . 2009-03-05 18:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-02 16:00 . 2009-03-29 09:18 6153352 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-05-01 15:49 . 2010-01-29 18:18 -------- d-----w- c:\documents and settings\philip\Application Data\IDM
2010-04-29 20:52 . 2006-10-15 22:07 -------- d-----w- c:\program files\DivX
2010-04-29 14:39 . 2009-03-05 18:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2009-03-05 18:03 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-17 17:59 . 2008-11-10 23:24 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Temp
2010-04-17 17:59 . 2009-01-24 15:57 -------- d-----w- c:\program files\SpywareBlaster
2010-04-16 18:14 . 2009-06-23 15:55 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-04-14 21:58 . 2009-01-14 20:16 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2010-03-30 19:31 . 2007-11-13 18:07 -------- d-----w- c:\program files\Common Files\Java
2010-03-30 19:30 . 2010-03-30 19:30 503808 ----a-w- c:\documents and settings\philip\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-40152f3e-n\msvcp71.dll
2010-03-30 19:30 . 2010-03-30 19:30 499712 ----a-w- c:\documents and settings\philip\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-40152f3e-n\jmc.dll
2010-03-30 19:30 . 2010-03-30 19:30 348160 ----a-w- c:\documents and settings\philip\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-40152f3e-n\msvcr71.dll
2010-03-30 19:30 . 2010-03-30 19:30 61440 ----a-w- c:\documents and settings\philip\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3d5210e3-n\decora-sse.dll
2010-03-30 19:30 . 2010-03-30 19:30 12800 ----a-w- c:\documents and settings\philip\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3d5210e3-n\decora-d3d.dll
2010-03-12 00:26 . 2010-03-12 00:26 118784 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-12 00:26 . 2010-03-12 00:26 118784 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-12 00:26 . 2010-03-12 00:26 118784 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-12 00:26 . 2010-03-12 00:26 118784 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-12 00:26 . 2010-03-12 00:26 118784 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-12 00:26 . 2010-03-12 00:26 300616 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-12 00:26 . 2010-03-12 00:26 329312 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-12 00:26 . 2010-03-12 00:26 118784 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-12 00:26 . 2009-06-17 20:48 -------- d-----w- c:\program files\Common Files\Real
2010-03-12 00:26 . 2009-09-18 09:26 -------- d-----w- c:\program files\real
2010-03-12 00:26 . 2010-03-12 00:26 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-12 00:25 . 2003-03-18 20:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-11 12:38 . 2004-08-04 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2009-12-08 10:46 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2004-08-04 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2004-08-04 12:00 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-02 17:13 . 2009-10-31 22:10 426356 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aepack.dll
2010-03-02 17:12 . 2009-10-31 22:10 188790 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aecore.dll
2010-02-26 17:12 . 2010-03-19 19:28 254323 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aesbx.dll
2010-02-26 17:12 . 2009-10-31 22:10 1032570 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aescript.dll
2010-02-26 17:11 . 2009-10-31 22:10 127347 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aescn.dll
2010-02-26 17:11 . 2009-10-31 22:10 237942 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aehelp.dll
2010-02-26 17:11 . 2009-10-31 22:10 373107 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aegen.dll
2010-02-24 13:11 . 2004-08-04 12:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-20 16:49 . 2009-10-31 22:10 196987 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aeoffice.dll
2010-02-20 16:49 . 2009-10-31 22:10 2326902 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aeheur.dll
2010-02-17 19:00 . 2010-02-17 19:00 86016 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS\Adobe_Downloads\arh.exe
2010-02-17 08:10 . 2004-08-04 12:00 2189952 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2066816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-14 00:15 . 2008-11-08 23:48 69624 ----a-w- c:\documents and settings\philip\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-13 16:41 . 2009-10-31 22:10 479602 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira\AntiVir Desktop\FAILSAVE\aerdl.dll
2010-02-12 10:03 . 2010-03-18 09:39 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2004-08-04 12:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 12:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-12-23 2642168]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-27 2815408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 577536]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2007-11-16 91432]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-12 202256]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912]
c:\documents and settings\philip\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP

xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP

xpsp2res.dll,-22016
"500:UDP"= 500:UDP

xpsp2res.dll,-22017
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [31/10/2009 22:18 108289]
.
Contents of the 'Scheduled Tasks' folder
2010-04-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-05-05 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-854245398-436374069-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 22:09]
2010-05-05 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-854245398-436374069-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 22:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - ProfilePath - c:\documents and settings\philip\Application Data\Mozilla\Firefox\Profiles\sv7phyv6.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\All Users.WINDOWS\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\philip\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
BHO-{79a7b6cc-15f4-4598-9442-343ab84d19ce} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
SharedTaskScheduler-{0074BAD5-04AC-49A8-9314-1D8B356B62FF} - c:\windows\system32\exphylla.dll
Notify-!SASWinLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-05 13:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):c7,0a,a1,69,34,49,e8,51,b6,63,12,fa,b7,8f,28,ed,2e,4a,30,f5,b4,
08,4a,81,8a,36,f9,a1,96,9c,ee,34,89,41,0b,91,15,3b,52,e6,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f0d1f918-c822-40a2-b45a-e6a35fda78d4}]
@Denied: (Full) (Everyone)
"Model"=dword:0000005c
"Therad"=dword:00000009
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
Completion time: 2010-05-05 13:57:50
ComboFix-quarantined-files.txt 2010-05-05 12:57
Pre-Run: 9,518,493,696 bytes free
Post-Run: 11,299,454,976 bytes free
- - End Of File - - C7F4AF28FB1D8ECB87C7BC1E03718149
when combofix needed to reboot the computer, i clicked ok and did its things, then after the welcome sign, combofix came up, then soon after avira anti virus appeared and 'is the TR/Patched.Gen Trojan' was detected. i moved it to quarantine. but havent deleted or scanned the computer with avira yet.