Ahh.. although I had turned Online Armour off before running ComboFix, I didn't stop it from running at startup. I only had AVG 7.5 installed, which I uninstalled earlier today to install 8 (the malware had affected AVG's functions so I was going to have to do this anyway), but yeah, something halted the installation due to failure in creating a registry key. I'll stop it this time.
Step 1
File mqac.sys received on 10.29.2008 12:52:07 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/36 (0%)
Antivirus Version Last Update Result
AhnLab-V3 2008.10.28.3 2008.10.29 -
AntiVir 7.9.0.10 2008.10.29 -
Authentium 5.1.0.4 2008.10.28 -
Avast 4.8.1248.0 2008.10.28 -
AVG 8.0.0.161 2008.10.29 -
BitDefender 7.2 2008.10.29 -
CAT-QuickHeal 9.50 2008.10.29 -
ClamAV 0.93.1 2008.10.29 -
DrWeb 4.44.0.09170 2008.10.29 -
eSafe 7.0.17.0 2008.10.28 -
eTrust-Vet 31.6.6179 2008.10.29 -
Ewido 4.0 2008.10.28 -
F-Prot 4.4.4.56 2008.10.28 -
F-Secure 8.0.14332.0 2008.10.29 -
Fortinet 3.117.0.0 2008.10.28 -
GData 19 2008.10.29 -
Ikarus T3.1.1.44.0 2008.10.29 -
K7AntiVirus 7.10.511 2008.10.29 -
Kaspersky 7.0.0.125 2008.10.29 -
McAfee 5417 2008.10.28 -
Microsoft 1.4005 2008.10.29 -
NOD32 3565 2008.10.29 -
Norman 5.80.02 2008.10.28 -
Panda 9.0.0.4 2008.10.29 -
PCTools 4.4.2.0 2008.10.29 -
Prevx1 V2 2008.10.29 -
Rising 21.01.22.00 2008.10.29 -
SecureWeb-Gateway 6.7.6 2008.10.29 -
Sophos 4.35.0 2008.10.29 -
Sunbelt 3.1.1762.1 2008.10.28 -
Symantec 10 2008.10.29 -
TheHacker 6.3.1.1.133 2008.10.28 -
TrendMicro 8.700.0.1004 2008.10.29 -
VBA32 3.12.8.8 2008.10.28 -
ViRobot 2008.10.29.1443 2008.10.29 -
VirusBuster 4.5.11.0 2008.10.28 -
Additional information
File size: 77712 bytes
MD5...: f1f1caddbf2eb8c333ed3f18e46b7f2f
SHA1..: 574173cc48cf05bbc63193eaae807c05503e2ca2
SHA256: fbb338f2f6f419c1fb3186d8f2a21b57d56675daaf20cb9fd1f82039739e9472
SHA512: b2750b6bf2fb0663d674c935714d6e6c4755cf43e8d8c3759335fa860e0ddb05
a8a3833a75dee6c8b14dc423efd59120cfc0f132ff8100136b94f794812b6066
PEiD..: -
TrID..: File type identification
Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x16980
timedatestamp.....: 0x48a0a7fd (Mon Aug 11 20:58:37 2008)
machinetype.......: 0x14c (I386)
( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x2c0 0x1065e 0x10660 6.42 8e9475beb43783675bee7caa4dac8f2f
.rdata 0x10920 0x73c 0x740 6.73 910881774981e992c1a147cddae12fff
.data 0x11060 0x8d0 0x8e0 1.43 daa839b02575454daa485ba6f8282c0b
INIT 0x11940 0x5a4 0x5c0 5.31 1104c68576da0d592b9c8d20b1b4264f
.rsrc 0x11f00 0x488 0x4a0 3.31 9a17323135be5ef275b9ae05c7fa0abc
.reloc 0x123a0 0xac8 0xae0 6.58 17eaf76634e81567f371866ae9ee27e3
( 1 imports )
> ntoskrnl.exe: ExFreePool, ExAllocatePoolWithTagPriority, ExAllocatePoolWithTag, IoReleaseCancelSpinLock, InterlockedExchange, KeLeaveCriticalRegion, ExReleaseFastMutexUnsafe, IofCompleteRequest, ExAcquireFastMutexUnsafe, KeEnterCriticalRegion, InterlockedDecrement, IoAcquireCancelSpinLock, ObfDereferenceObject, MmMapViewInSystemSpace, ObReferenceObjectByHandle, MmUnmapViewInSystemSpace, RtlCompareMemory, IoCheckShareAccess, IoGetRequestorProcess, _purecall, IoSetShareAccess, _except_handler3, wcslen, _snwprintf, InterlockedIncrement, ZwWriteFile, KeAttachProcess, KeDetachProcess, IoGetCurrentProcess, ZwReadFile, ZwDeleteFile, MmUnmapViewOfSection, MmMapViewOfSection, ZwClose, MmCreateSection, ZwCreateFile, RtlInitUnicodeString, swprintf, ZwSetInformationFile, IoCreateSymbolicLink, KeInitializeEvent, IoDeleteDevice, IoCreateDevice, KeInitializeDpc, KeInitializeTimer, IoDeleteSymbolicLink, ZwQuerySystemInformation, KeQuerySystemTime, ExRaiseAccessViolation, MmUserProbeAddress, wcscpy, KeDelayExecutionThread, ExQueueWorkItem, IoRemoveShareAccess, KeSetTimer, KeCancelTimer
( 0 exports )
---------------------------------------------------
File mqmig.exe received on 10.29.2008 12:55:17 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/36 (0%)
Antivirus Version Last Update Result
AhnLab-V3 2008.10.28.3 2008.10.29 -
AntiVir 7.9.0.10 2008.10.29 -
Authentium 5.1.0.4 2008.10.28 -
Avast 4.8.1248.0 2008.10.28 -
AVG 8.0.0.161 2008.10.29 -
BitDefender 7.2 2008.10.29 -
CAT-QuickHeal 9.50 2008.10.29 -
ClamAV 0.93.1 2008.10.29 -
DrWeb 4.44.0.09170 2008.10.29 -
eSafe 7.0.17.0 2008.10.28 -
eTrust-Vet 31.6.6179 2008.10.29 -
Ewido 4.0 2008.10.28 -
F-Prot 4.4.4.56 2008.10.28 -
F-Secure 8.0.14332.0 2008.10.29 -
Fortinet 3.117.0.0 2008.10.28 -
GData 19 2008.10.29 -
Ikarus T3.1.1.44.0 2008.10.29 -
K7AntiVirus 7.10.511 2008.10.29 -
Kaspersky 7.0.0.125 2008.10.29 -
McAfee 5417 2008.10.28 -
Microsoft 1.4005 2008.10.29 -
NOD32 3565 2008.10.29 -
Norman 5.80.02 2008.10.28 -
Panda 9.0.0.4 2008.10.29 -
PCTools 4.4.2.0 2008.10.29 -
Prevx1 V2 2008.10.29 -
Rising 21.01.22.00 2008.10.29 -
SecureWeb-Gateway 6.7.6 2008.10.29 -
Sophos 4.35.0 2008.10.29 -
Sunbelt 3.1.1762.1 2008.10.28 -
Symantec 10 2008.10.29 -
TheHacker 6.3.1.1.133 2008.10.28 -
TrendMicro 8.700.0.1004 2008.10.29 -
VBA32 3.12.8.8 2008.10.28 -
ViRobot 2008.10.29.1443 2008.10.29 -
VirusBuster 4.5.11.0 2008.10.28 -
Additional information
File size: 98064 bytes
MD5...: 7275b4836ed6a6cdcdeabb330d1ab306
SHA1..: ec08029a3fff1efc4a32147cc9989bd7f2def629
SHA256: 5ad6a9832233250ffc1b6c059a32fa1b20bf930f9936b82ec08c0fc9d56e69cd
SHA512: 74f2f35316c1b8b88ab640ce6e58f9927b64e5b89f45250aefc3d02e94ddc421
2eee060d5f7496a15b4845f320efa5d3fc7a211a12f29707bf6fe8ff10e09645
PEiD..: InstallShield 2000
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x406070
timedatestamp.....: 0x48a0a75d (Mon Aug 11 20:55:57 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x5c51 0x5e00 6.11 59edf4d941f0fb36e6455136e3cc23fd
.rdata 0x7000 0x2c2e 0x2e00 4.77 a559945416dc4c9c1525dd8b8f2c0e90
.data 0xa000 0x6e0 0x400 4.16 cd7a94503483392d289a732f4e4182fe
.rsrc 0xb000 0xe920 0xea00 3.76 9dd1ada7783e3b973a882713f34ff5b3
( 9 imports )
> SHLWAPI.dll: PathRemoveFileSpecA, PathFileExistsA, PathIsDirectoryA
> WLDAP32.dll: -, -
> VERSION.dll: GetFileVersionInfoSizeA, VerQueryValueA, GetFileVersionInfoA
> MFC42.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> MSVCRT.dll: _controlfp, _except_handler3, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, _onexit, __dllonexit, _setmbcp, _strcmpi, memset, wcslen, strrchr, __CxxFrameHandler, _EH_prolog, strcpy, strlen, sprintf, printf, memcpy
> KERNEL32.dll: lstrlenA, lstrcpyA, CreateDirectoryA, GetDriveTypeA, GetFileAttributesA, GetLastError, MultiByteToWideChar, GetSystemDirectoryA, WaitForSingleObject, LoadLibraryA, GetModuleFileNameA, GetComputerNameA, CreateProcessA, GetComputerNameW, GetComputerNameExW, SetLastError, FreeLibrary, GetModuleHandleA, MapViewOfFile, CreateFileMappingA, UnmapViewOfFile, ExitProcess, GetStartupInfoA, WideCharToMultiByte, GetTickCount, GetProcAddress, InterlockedIncrement, GetWindowsDirectoryA, Sleep, CreateThread, CloseHandle, DeleteFileA, SetEvent, CreateEventA
> USER32.dll: LoadBitmapA, ShowWindow, SetWindowLongA, SetForegroundWindow, DispatchMessageA, MsgWaitForMultipleObjects, PeekMessageA, SetDlgItemTextA, CreateDialogParamA, DefWindowProcA, FindWindowA, CharLowerA, GetSystemMenu, InsertMenuA, DrawMenuBar, LoadIconA, SendMessageA, KillTimer, SetTimer, GetDlgItem, IsWindowEnabled, CharNextA, PostMessageA, GetParent, EnableWindow, MessageBoxA, LoadStringA, BringWindowToTop
> GDI32.dll: CreateFontIndirectA
> ADVAPI32.dll: ControlService, RegCreateKeyExA, RegSetValueExA, RegFlushKey, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, CreateServiceA, ChangeServiceConfig2A, QueryServiceConfigA, OpenSCManagerA, OpenServiceA, ChangeServiceConfigA, StartServiceA, CloseServiceHandle, RegDeleteKeyA, QueryServiceStatus
( 0 exports )
---------------------------------------------------
File mqbkup.exe received on 10.29.2008 12:58:27 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/36 (0%)
Antivirus Version Last Update Result
AhnLab-V3 2008.10.28.3 2008.10.29 -
AntiVir 7.9.0.10 2008.10.29 -
Authentium 5.1.0.4 2008.10.28 -
Avast 4.8.1248.0 2008.10.28 -
AVG 8.0.0.161 2008.10.29 -
BitDefender 7.2 2008.10.29 -
CAT-QuickHeal 9.50 2008.10.29 -
ClamAV 0.93.1 2008.10.29 -
DrWeb 4.44.0.09170 2008.10.29 -
eSafe 7.0.17.0 2008.10.28 -
eTrust-Vet 31.6.6179 2008.10.29 -
Ewido 4.0 2008.10.28 -
F-Prot 4.4.4.56 2008.10.28 -
F-Secure 8.0.14332.0 2008.10.29 -
Fortinet 3.117.0.0 2008.10.28 -
GData 19 2008.10.29 -
Ikarus T3.1.1.44.0 2008.10.29 -
K7AntiVirus 7.10.511 2008.10.29 -
Kaspersky 7.0.0.125 2008.10.29 -
McAfee 5417 2008.10.28 -
Microsoft 1.4005 2008.10.29 -
NOD32 3565 2008.10.29 -
Norman 5.80.02 2008.10.28 -
Panda 9.0.0.4 2008.10.29 -
PCTools 4.4.2.0 2008.10.29 -
Prevx1 V2 2008.10.29 -
Rising 21.01.22.00 2008.10.29 -
SecureWeb-Gateway 6.7.6 2008.10.29 -
Sophos 4.35.0 2008.10.29 -
Sunbelt 3.1.1762.1 2008.10.28 -
Symantec 10 2008.10.29 -
TheHacker 6.3.1.1.133 2008.10.28 -
TrendMicro 8.700.0.1004 2008.10.29 -
VBA32 3.12.8.8 2008.10.28 -
ViRobot 2008.10.29.1443 2008.10.29 -
VirusBuster 4.5.11.0 2008.10.28 -
Additional information
File size: 25360 bytes
MD5...: 7ddeb08974f2d2ee0999b6065ba2b516
SHA1..: db4e5803a3ae9062397dd31a08fd3c9be731b5c5
SHA256: 3d00697624c649a3939ac290d1e11c3a54dc1c0f9f9cdebccc6d1f9aca0d3c0a
SHA512: 4b843f3423544c66191393a8baf24714b1318dc9b3afb5bfbd34cb71f3555ccb
2922264e19a80fbaa6b8b2c00bee251cb17c8d4ae97b93f26daeee6117afb61a
PEiD..: InstallShield 2000
TrID..: File type identification
Win64 Executable Generic (80.9%)
Win32 Executable Generic (8.0%)
Win32 Dynamic Link Library (generic) (7.1%)
Generic Win/DOS Executable (1.8%)
DOS Executable Generic (1.8%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x404010
timedatestamp.....: 0x48a0a7a5 (Mon Aug 11 20:57:09 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3306 0x3400 5.79 e0cc9169de180ce55b4419ff7b7a2a73
.rdata 0x5000 0xc04 0xe00 4.49 a75be8644d88ddacacdb0524de5f4430
.data 0x6000 0x264 0x400 3.19 dbda59489f78076108461569a5fe0f12
.rsrc 0x7000 0x1680 0x1800 3.35 b1ab4600813464079e4bbd13e422ed47
( 5 imports )
> KERNEL32.dll: GetSystemDirectoryA, GetFileAttributesA, CreateDirectoryA, CopyFileA, GetSystemTimeAsFileTime, GetDiskFreeSpaceExA, DeviceIoControl, Sleep, FreeLibrary, WriteFile, CompareStringA, FindFirstFileA, DeleteFileA, FindNextFileA, GetModuleHandleA, FindClose, GetCurrentProcess, GetLastError, CloseHandle, FormatMessageA, LocalFree, LoadLibraryA, GetProcAddress, GetVersionExA, GetFullPathNameA, CreateFileA
> USER32.dll: CharNextA, LoadStringA
> ADVAPI32.dll: AddAce, AllocateAndInitializeSid, GetLengthSid, InitializeSecurityDescriptor, InitializeAcl, AddAccessAllowedAce, SetSecurityDescriptorDacl, SetFileSecurityA, FreeSid, RegSetValueExA, RegRestoreKeyA, RegSaveKeyA, RegCreateKeyExA, StartServiceA, OpenSCManagerA, OpenServiceA, ControlService, CloseServiceHandle, QueryServiceStatus, RegQueryValueExA, RegOpenKeyExA, RegCloseKey, LookupPrivilegeValueA, AdjustTokenPrivileges, OpenProcessToken
> CLUSAPI.dll: OfflineClusterResource, OnlineClusterResource, GetClusterResourceState, CloseClusterResource, OpenCluster, OpenClusterResource, CloseCluster, ClusterResourceControl
> MSVCRT.dll: wcslen, __dllonexit, _controlfp, printf, strcat, strlen, strcpy, exit, scanf, _mbsrchr, __3@YAXPAX@Z, memcpy, __2@YAPAXI@Z, _mbschr, sprintf, __CxxFrameHandler, _EH_prolog, mbstowcs, _onexit, _mbsnbcat, memset, _mbctolower, _exit, _XcptFilter, __p___initenv, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3
( 0 exports )
---------------------------------------------------
File mqsvc.exe received on 10.29.2008 13:01:13 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/36 (0%)
Antivirus Version Last Update Result
AhnLab-V3 2008.10.28.3 2008.10.29 -
AntiVir 7.9.0.10 2008.10.29 -
Authentium 5.1.0.4 2008.10.28 -
Avast 4.8.1248.0 2008.10.28 -
AVG 8.0.0.161 2008.10.29 -
BitDefender 7.2 2008.10.29 -
CAT-QuickHeal 9.50 2008.10.29 -
ClamAV 0.93.1 2008.10.29 -
DrWeb 4.44.0.09170 2008.10.29 -
eSafe 7.0.17.0 2008.10.28 -
eTrust-Vet 31.6.6179 2008.10.29 -
Ewido 4.0 2008.10.29 -
F-Prot 4.4.4.56 2008.10.28 -
F-Secure 8.0.14332.0 2008.10.29 -
Fortinet 3.117.0.0 2008.10.28 -
GData 19 2008.10.29 -
Ikarus T3.1.1.44.0 2008.10.29 -
K7AntiVirus 7.10.511 2008.10.29 -
Kaspersky 7.0.0.125 2008.10.29 -
McAfee 5417 2008.10.28 -
Microsoft 1.4005 2008.10.29 -
NOD32 3565 2008.10.29 -
Norman 5.80.02 2008.10.28 -
Panda 9.0.0.4 2008.10.29 -
PCTools 4.4.2.0 2008.10.29 -
Prevx1 V2 2008.10.29 -
Rising 21.01.22.00 2008.10.29 -
SecureWeb-Gateway 6.7.6 2008.10.29 -
Sophos 4.35.0 2008.10.29 -
Sunbelt 3.1.1762.1 2008.10.28 -
Symantec 10 2008.10.29 -
TheHacker 6.3.1.1.133 2008.10.28 -
TrendMicro 8.700.0.1004 2008.10.29 -
VBA32 3.12.8.8 2008.10.28 -
ViRobot 2008.10.29.1443 2008.10.29 -
VirusBuster 4.5.11.0 2008.10.28 -
Additional information
File size: 14096 bytes
MD5...: fb78e358b230c757a6e656291935b867
SHA1..: a959619fa29ec22c9159bbfe47f49b45de909b1e
SHA256: 9857e88f612526670a6933138e030ea5ddb4399946b1f3933caa0f7fadb232bf
SHA512: aa8f5c83a687ee83f1157497fc5f383bf9302b4d1e20b003ec1e2789aea88353
b922154a822502afa2482e2b5b2c708bd62406514844b879f5eba7c96b3a6b93
PEiD..: InstallShield 2000
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x402a80
timedatestamp.....: 0x48a0a6e1 (Mon Aug 11 20:53:53 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1d84 0x1e00 5.98 d339e2d1402331d5de19c300710779d4
.rdata 0x3000 0x844 0xa00 4.31 fbdc510820b838b748ccb4b040cefd1a
.data 0x4000 0x3a4 0x400 3.96 6510f29792634f03c8fa5400c821bae8
.rsrc 0x5000 0x458 0x600 2.62 e55dd55beb51c64dd97a12544b93471c
( 4 imports )
> MQQM.dll: QMInit, QMRun, _QMFinish@0
> KERNEL32.dll: WaitForSingleObject, Sleep, Beep, LeaveCriticalSection, EnterCriticalSection, SetEvent, CreateSemaphoreA, CreateThread, LocalFree, GetCurrentProcess, LocalAlloc, ReleaseSemaphore, MultiByteToWideChar, ExitProcess, CloseHandle, DeleteCriticalSection, CreateEventA, InitializeCriticalSection, GetLastError
> ADVAPI32.dll: GetTokenInformation, OpenProcessToken, AllocateAndInitializeSid, FreeSid, EqualSid, SetServiceStatus, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA
> MSVCRT.dll: __3@YAXPAX@Z, exit, malloc, __2@YAPAXI@Z, __CxxFrameHandler, free, realloc, isalpha, gets, printf, __dllonexit, _onexit, _exit, _XcptFilter, __p___initenv, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp, _stricmp, _strnicmp
( 0 exports )
---------------------------------------------------
File mq1sync.exe received on 10.29.2008 13:05:45 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/36 (0%)
Antivirus Version Last Update Result
AhnLab-V3 2008.10.28.3 2008.10.29 -
AntiVir 7.9.0.10 2008.10.29 -
Authentium 5.1.0.4 2008.10.28 -
Avast 4.8.1248.0 2008.10.28 -
AVG 8.0.0.161 2008.10.29 -
BitDefender 7.2 2008.10.29 -
CAT-QuickHeal 9.50 2008.10.29 -
ClamAV 0.93.1 2008.10.29 -
DrWeb 4.44.0.09170 2008.10.29 -
eSafe 7.0.17.0 2008.10.28 -
eTrust-Vet 31.6.6179 2008.10.29 -
Ewido 4.0 2008.10.29 -
F-Prot 4.4.4.56 2008.10.28 -
F-Secure 8.0.14332.0 2008.10.29 -
Fortinet 3.117.0.0 2008.10.28 -
GData 19 2008.10.29 -
Ikarus T3.1.1.44.0 2008.10.29 -
K7AntiVirus 7.10.511 2008.10.29 -
Kaspersky 7.0.0.125 2008.10.29 -
McAfee 5417 2008.10.28 -
Microsoft 1.4005 2008.10.29 -
NOD32 3565 2008.10.29 -
Norman 5.80.02 2008.10.28 -
Panda 9.0.0.4 2008.10.29 -
PCTools 4.4.2.0 2008.10.29 -
Prevx1 V2 2008.10.29 -
Rising 21.01.22.00 2008.10.29 -
SecureWeb-Gateway 6.7.6 2008.10.29 -
Sophos 4.35.0 2008.10.29 -
Sunbelt 3.1.1762.1 2008.10.28 -
Symantec 10 2008.10.29 -
TheHacker 6.3.1.1.133 2008.10.28 -
TrendMicro 8.700.0.1004 2008.10.29 -
VBA32 3.12.8.8 2008.10.28 -
ViRobot 2008.10.29.1443 2008.10.29 -
VirusBuster 4.5.11.0 2008.10.28 -
Additional information
File size: 14096 bytes
MD5...: 8fa7ff2d1001599b2a173445da40790b
SHA1..: 3c1a02e0177b7f986d2a8de51a1f7cb8a144f479
SHA256: b79bb33f30391a8fd1dca46603f2e8702dfca157c4ca88d9232713a28e63a3bb
SHA512: 7548d56b03432b82fed3714162bfd671710f7fb6d81976053c479da3d4b5450e
b12179126ccf8d2357459b05b5b7d065efa0fef8bf5c1f58399576981628cfea
PEiD..: InstallShield 2000
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x402a40
timedatestamp.....: 0x48a0a792 (Mon Aug 11 20:56:50 2008)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1d44 0x1e00 5.95 829146326e99dfdca71f4d359ef91e2e
.rdata 0x3000 0x818 0xa00 4.24 3e932d53632f6c317d8eaf294c8a3cee
.data 0x4000 0x408 0x400 4.26 6536562e47e5ade0b53eae40ac586682
.rsrc 0x5000 0x478 0x600 2.68 6f97e907ef7cbfd5326bc14086ab1d78
( 3 imports )
> KERNEL32.dll: EnterCriticalSection, SetEvent, CreateSemaphoreA, GetLastError, LocalFree, GetCurrentProcess, LeaveCriticalSection, ReleaseSemaphore, GetProcAddress, LoadLibraryA, FreeLibrary, ExitProcess, Beep, Sleep, WaitForSingleObject, CreateThread, CloseHandle, DeleteCriticalSection, CreateEventA, InitializeCriticalSection, LocalAlloc
> ADVAPI32.dll: OpenProcessToken, GetTokenInformation, AllocateAndInitializeSid, FreeSid, EqualSid, SetServiceStatus, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA
> MSVCRT.dll: __3@YAXPAX@Z, exit, malloc, __2@YAPAXI@Z, __CxxFrameHandler, free, realloc, isalpha, gets, printf, __dllonexit, _onexit, _exit, _XcptFilter, __p___initenv, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp, _stricmp, _strnicmp
( 0 exports )
There apparently was still problems when it comes to the registry.
Maybe it wasn't stopped after all ? Perhaps I should try uninstalling Online Armour next.
Step 2
ComboFix 08-10-25.01 - nine 10/29/2008 20:23:06.2 - FAT32x86
Microsoft Windows 2000 Professional 5.0.2195.4.932.81.1033.18.770 [GMT 8:00]
Running from: C:\Documents and Settings\nine\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\nine\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PVOPSTRR
-------\Service_pvopstrr
-------\Service_VFILT
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-29 )))))))))))))))))))))))))))))))
.
2008-10-29 19:09 . 08-10-29 19:09 464,530 ---h----- C:\WINNT\ShellIconCache
2008-10-26 07:12 . 08-10-26 07:12 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-26 07:12 . 08-10-26 07:12 <DIR> d-------- C:\Documents and Settings\nine\Application Data\Malwarebytes
2008-10-26 07:12 . 08-10-26 07:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-26 07:12 . 08-10-22 16:10 38,496 --a------ C:\WINNT\system32\drivers\mbamswissarmy.sys
2008-10-26 07:12 . 08-10-22 16:10 15,504 --a------ C:\WINNT\system32\drivers\mbam.sys
2008-10-25 13:41 . 08-10-25 13:41 76,042 --a------ C:\prog_error.jpg
2008-10-25 02:59 . 08-10-25 02:59 <DIR> d-------- C:\rsit
2008-10-24 19:26 . 08-10-25 09:01 244,869,120 --a------ C:\[SS-Eclipse] Kyouran Kazoku Nikki - 02 (XviD) [8AFBFCBE].avi
2008-10-24 03:25 . 08-10-24 16:41 243,435,520 --a------ C:\[SS-Eclipse] Kyouran Kazoku Nikki - 01 (XviD) [3AFFBD34].avi
2008-10-22 22:11 . 08-10-22 22:11 <DIR> d-------- C:\[Nipponsei] Toradora! OP Single - Pre-Parade [Various]
2008-10-21 04:02 . 08-10-21 04:02 <DIR> d-------- C:\Program Files\Tall Emu
2008-10-21 04:02 . 08-10-07 00:09 178,376 --a------ C:\WINNT\system32\drivers\OADriver.sys
2008-10-21 04:02 . 08-10-07 00:09 30,920 --a------ C:\WINNT\system32\drivers\OAmon.sys
2008-10-21 04:02 . 08-10-07 00:09 28,872 --a------ C:\WINNT\system32\drivers\OAnet.sys
2008-10-21 04:01 . 08-10-21 04:01 <DIR> d-------- C:\OnlineArmor
2008-10-20 05:34 . 08-10-20 05:34 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-19 23:33 . 08-10-19 23:33 <DIR> d-------- C:\WINNT\system32\rpcproxy
2008-10-19 23:33 . 08-10-19 23:33 <DIR> d-------- C:\WINNT\system32\rocket
2008-10-18 20:19 . 08-10-18 20:19 0 -rahs---- C:\WINNT\system32\drivers\rkreveal150.sys
2008-10-18 20:17 . 08-10-18 20:17 <DIR> d-------- C:\WINNT\system32\34566
2008-10-18 04:05 . 08-10-18 04:05 <DIR> d-------- C:\[Nipponsei] Yozakura Quartet OP Single - JUST TUNE [savage genius]
2008-10-16 11:44 . 08-10-16 11:44 <DIR> d-------- C:\WINNT\system32\Windows Media
2008-10-16 11:43 . 08-10-16 11:43 <DIR> d-------- C:\WINNT\msiinst.tmp
2008-10-16 11:39 . 08-10-16 11:39 <DIR> d-------- C:\WINNT\mui
2008-10-16 11:39 . 05-06-28 10:21 22,752 --a------ C:\WINNT\system32\spupdsvc.exe
2008-10-16 11:39 . 08-10-16 11:39 957 --a------ C:\WINNT\setup.inf
2008-10-16 11:39 . 08-10-16 11:39 283 --a------ C:\WINNT\setup.rpt
2008-10-16 11:37 . 02-12-11 17:34 208,896 --a------ C:\WINNT\system32\wmpns.dll
2008-10-15 17:22 . 02-08-29 07:14 44,032 --------- C:\WINNT\system32\dllcache\msxml3r.dll
2008-10-15 14:28 . 08-10-15 14:28 <DIR> d-------- C:\WINNT\system32\BITS
2008-10-15 13:36 . 08-10-15 13:36 <DIR> d-------- C:\WINNT\system\catroot
2008-10-15 13:36 . 08-10-15 13:36 <DIR> d-------- C:\Program Files\ZTE
2008-10-15 00:18 . 08-10-15 00:17 193,770 --a------ C:\1217920173864.jpg
2008-10-05 16:19 . 08-10-05 16:20 262 --a------ C:\WINNT\YAN2.INI
2008-10-04 14:15 . 08-10-29 20:26 335 --a------ C:\WINNT\system32\Pen_Tablet.dat
2008-10-03 13:00 . 08-10-03 12:46 3,701,530 --a------ C:\yozakura_quartet_OP.flv
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-17 17:41 310,032 ----a-w C:\WINNT\system32\dllcache\NETAPI32.DLL
2008-09-15 05:13 1,644,432 ----a-w C:\WINNT\system32\WIN32K.SYS
2008-09-15 05:13 1,644,432 ------w C:\WINNT\system32\dllcache\win32k.sys
2008-09-12 02:19 --------- d-----w C:\Program Files\Anathema
2008-09-05 22:05 --------- d-----w C:\Program Files\7-Zip
2008-08-28 04:44 239,344 ----a-w C:\WINNT\system32\drivers\SRV.SYS
2008-08-28 04:44 239,344 ----a-w C:\WINNT\system32\dllcache\srv.sys
2008-08-20 04:24 132,096 ----a-w C:\WINNT\system32\dllcache\MSRATING.DLL
2008-08-20 04:23 402,944 ----a-w C:\WINNT\system32\dllcache\SHLWAPI.DLL
2008-08-20 04:23 143,360 ----a-w C:\WINNT\system32\dllcache\CDFVIEW.DLL
2008-08-20 04:23 1,340,416 ----a-w C:\WINNT\system32\dllcache\SHDOCVW.DLL
2008-08-20 04:23 1,018,368 ----a-w C:\WINNT\system32\dllcache\BROWSEUI.DLL
2008-08-20 02:51 69,632 ----a-w C:\WINNT\system32\dllcache\INSENG.DLL
2008-08-20 02:51 575,488 ----a-w C:\WINNT\system32\WININET.DLL
2008-08-20 02:51 575,488 ----a-w C:\WINNT\system32\dllcache\WININET.DLL
2008-08-20 02:51 498,176 ----a-w C:\WINNT\system32\dllcache\MSTIME.DLL
2008-08-20 02:51 462,336 ----a-w C:\WINNT\system32\dllcache\URLMON.DLL
2008-08-20 02:51 351,744 ----a-w C:\WINNT\system32\dllcache\DXTMSFT.DLL
2008-08-20 02:51 34,816 ----a-w C:\WINNT\system32\dllcache\PNGFILT.DLL
2008-08-20 02:51 236,032 ----a-w C:\WINNT\system32\dllcache\IEPEERS.DLL
2008-08-20 02:51 2,706,432 ----a-w C:\WINNT\system32\dllcache\MSHTML.DLL
2008-08-20 02:51 192,512 ----a-w C:\WINNT\system32\dllcache\DXTRANS.DLL
2008-08-20 02:51 12,288 ----a-w C:\WINNT\system32\dllcache\JSPROXY.DLL
2008-08-12 07:47 98,064 ----a-w C:\WINNT\system32\dllcache\mqmig.exe
2008-08-12 07:47 77,712 ----a-w C:\WINNT\system32\dllcache\mqac.sys
2008-08-12 07:47 25,360 ----a-w C:\WINNT\system32\dllcache\mqbkup.exe
2008-08-12 07:47 14,096 ----a-w C:\WINNT\system32\dllcache\mqsvc.exe
2008-08-12 07:47 14,096 ----a-w C:\WINNT\system32\dllcache\mq1sync.exe
2007-11-25 09:48 271 ---h--w C:\Program Files\desktop.ini
2007-11-25 09:48 21,952 ---h--w C:\Program Files\folder.htt
2003-08-27 03:49 3,424 ----a-w C:\WINNT\inf\OTHER\cmiainfo.sys
2003-07-04 04:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\WINNT\system32\34566 ----
08-10-27 12:25 429801 --a------ C:\WINNT\system32\34566\sp03.exe
08-10-27 12:25 2278 --a------ C:\WINNT\system32\34566\f01.ini
08-10-27 11:30 18 --a------ C:\WINNT\system32\34566\d00.ini
08-10-27 11:14 16 --a------ C:\WINNT\system32\34566\d02.ini
08-10-27 10:20 60 --a------ C:\WINNT\system32\34566\ev0.info
08-10-19 18:17 2855 --a------ C:\WINNT\system32\34566\svchost.PIF
08-10-18 20:33 1118208 --a------ C:\WINNT\system32\34566\libeay32.dll
08-10-18 20:32 262144 --a------ C:\WINNT\system32\34566\ssleay32.dll
((((((((((((((((((((((((((((( snapshot@Mon 2008-10-27_13.20.36.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-12-01 14:56:00 96,256 ----a-w C:\WINNT\system32\ATL80.dll
+ 2006-12-01 16:08:00 40,960 ----a-w C:\WINNT\system32\mfc80CHS.dll
+ 2006-12-01 16:08:00 45,056 ----a-w C:\WINNT\system32\mfc80CHT.dll
+ 2006-12-01 16:08:00 65,536 ----a-w C:\WINNT\system32\mfc80DEU.dll
+ 2006-12-01 16:08:00 57,344 ----a-w C:\WINNT\system32\mfc80ENU.dll
+ 2006-12-01 16:08:00 61,440 ----a-w C:\WINNT\system32\mfc80ESP.dll
+ 2006-12-01 16:08:00 61,440 ----a-w C:\WINNT\system32\mfc80FRA.dll
+ 2006-12-01 16:08:00 61,440 ----a-w C:\WINNT\system32\mfc80ITA.dll
+ 2006-12-01 16:08:00 49,152 ----a-w C:\WINNT\system32\mfc80JPN.dll
+ 2006-12-01 16:08:00 49,152 ----a-w C:\WINNT\system32\mfc80KOR.dll
+ 2006-12-01 14:56:00 96,256 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2006-12-01 16:08:00 40,960 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-01 16:08:00 45,056 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-01 16:08:00 65,536 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-01 16:08:00 57,344 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-01 16:08:00 61,440 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-01 16:08:00 61,440 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-01 16:08:00 61,440 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-01 16:08:00 49,152 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-01 16:08:00 49,152 ----a-w C:\WINNT\winsxs\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [06-11-16 19:04 139264]
"internat.exe"="internat.exe" [03-07-04 12:00 20752 C:\WINNT\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [06-01-12 15:40 155648]
"NvCplDaemon"="C:\WINNT\system32\NvCpl.dll" [07-11-07 07:00 8523776]
"SoundMan"="SOUNDMAN.EXE" [05-06-20 21:42 77824 C:\WINNT\soundman.exe]
"Synchronization Manager"="mobsync.exe" [03-07-04 12:00 111376 C:\WINNT\system32\mobsync.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"vidc.xvid"= xvid.dll
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"@OnlineArmor GUI"="C:\Program Files\Tall Emu\Online Armor\oaui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
R1 OADevice;OADriver;C:\WINNT\system32\drivers\OADriver.sys [08-10-07 00:09 178376]
R1 OAmon;OAmon;C:\WINNT\system32\drivers\OAmon.sys [08-10-07 00:09 30920]
R1 OAnet;OAnet;C:\WINNT\system32\drivers\OAnet.sys [08-10-07 00:09 28872]
R2 OAcat;Online Armor Helper Service;C:\Program Files\Tall Emu\Online Armor\oacat.exe [08-10-07 00:09 1402568]
R2 TabletServicePen;TabletServicePen;C:\WINNT\system32\Pen_Tablet.exe [07-09-08 02:16 1373480]
R3 lne100v5;Linksys LNE100TX(v5) Fast Ethernet Adapter;C:\WINNT\system32\DRIVERS\lne100v5.sys [01-04-02 11:01 36013]
R3 openhci;Microsoft USB Open Host Controller Driver;C:\WINNT\system32\DRIVERS\openhci.sys [03-07-04 12:00 24784]
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 12:05 49776]
R3 ZTPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINNT\system32\DRIVERS\ztpppoe.sys [04-01-04 18:37 18238]
S3 ADM9X;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINNT\system32\DRIVERS\ADM9X.sys [01-10-25 14:43 35968]
S3 viafilter;VIA USB Filter;C:\WINNT\system32\Drivers\viausb.sys [05-03-23 16:56 9038]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-29 20:27:04
Windows 5.0.2195 Service Pack 4 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Avg7Core]
"ImagePath"="nul"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Avg7RsNT]
"ImagePath"="nul"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Avg7UpdSvc]
"ImagePath"="nul"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AvgClean]
"ImagePath"="nul"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AASW2_Service]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AbtrusionDriver]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AbtrusionSecurityService]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\acshield]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AeServ]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AMBRAPP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AMBRIM]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AntiVirFirewallService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ANTIVIRSERVICE]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\APFTrans]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\avas_service]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\avfwot]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AVG Anti-Rootkit]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Avg7Core]
"ImagePath"="nul"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Avg7RsNT]
"ImagePath"="nul"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Avg7UpdSvc]
"ImagePath"="nul"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\avg8wd]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AvgArCln]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AvgClean]
"ImagePath"="nul"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AvgCore]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AvgCoreSvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AvgFsh]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\avgfws8]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AVGFwSrv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AvgMfx86]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AvgRkx86]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AvgServ]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\avipbb]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AVKWCtl]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AVP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AVZRK]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AVZSG]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\baserand]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bc_filter]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bc_ip_f]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdftdif]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BlackICE]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\blinksvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BOCore]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BufferZoneSvc]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BZDcomLaunch]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BZRpcSs]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CAISafe]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cavasm]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CmdAgent]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cmdGuard]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Comodo Anti-Virus and Anti-Spyware Service]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ctdrvw2k]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ctiserv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ctsvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cyberhawk]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DarkSpy]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DCSPGSRV]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DeepFrz]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DEEPMON]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\defensewall_serv]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DRIVESENTRYCOMMSDRIVER]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drivesentryfilterdriver2lite]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DRIVESENTRYKEEPERDRIVER]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DriveSentryRegHookDriver]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DrvFltIp]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Ds2kDrv]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dwall]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ECONCEAL]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EconService]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ekrn]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EQService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EQSpyWatch]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eScan Monitor Service]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ESCANMX]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\esiasdrv]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\F-Secure Gatekeeper Handler Starter]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\F-Secure HIPS]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fgccow]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fgccsrt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fgcrepl]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FileHook]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FILEMON701]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FireSvc]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FortiPFW]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fortknox]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fortknox_drv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FSDFWD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fsfltdrv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FSFW]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FSRT]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fwdrv]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GDFwSvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ghostsec]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ghstwall]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Gmer]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GuardX]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HipService]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\iamServ]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\icsak]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IMMDRV]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\InoRT]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ipcSvc]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ipfrwl]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IsDrv118]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ISFWEnt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IsPubDrv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ISRService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\IswSvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\itmrtsvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\jetico personal firewall server]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KAVMonitorService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kavsvc]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KerioServerFirewall]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\khips]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KLIF]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KLPF]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Klpid]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KPF4]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KPfwSvc]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\KWatchSvc]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lnsfw1]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\LocalCpa]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\McODS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\McRedirector]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\McShield]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MksFwall]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mksfwallf]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MKSFWALLT]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MPFP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MPFSERVICE]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MPSVCService]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MSFWHLPR]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVAPEL]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\navapsvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\naveng]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAVEX15]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NCDSSvc]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\neoava_drv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\neosvc]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NETFLTDI]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nk4Seem]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nod32drv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NOD32krn]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norman ZANDA]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NORTON ANTIVIRUS SERVER]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OneCareMP]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OnlineNT]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OutpostFirewall]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pavfires]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Pavkre]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PavProt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pavsrv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PcCtlCom]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PcScnSrv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCTAVSvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCToolsFirewallPlus]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PersFw]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PFNet]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Pldriver]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PortsLock]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PPCtlPriv]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PREVXAgent]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PrismaNDIS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PrismaNDISFilter]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PROCEXP100]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PROCEXP90]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PROCMON10]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PROCMON11]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ProSecur]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ProtectedStorage]
"ImagePath"="%SystemRoot%\system32\services.exe"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSEXESVC]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSHost]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\psh_svc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSIMSVC]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSMAntiSpy]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pwipf2]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PWIPF6]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\QuickHealFirewall]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RapApp]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RegHook]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\REGMON701]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteAccess]
"ImagePath"="C:\WINNT\system32\34566\svchost.exe"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RFW]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RfwService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RGSvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RKD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rkhdrv10]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rkhdrv31]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rkhdrv40]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RVSDISK]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\safemon]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SafenSec]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAFESYSTEM]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SanaSafeConnectAgent]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\savant]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\savantnetagent]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\savrtpel]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SBAPIFS]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SBCSSvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SBHR]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sdAuxService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sdCoreService]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sfcorevt]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SfCtlCom]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Shadow]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ShadowSystemService]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SmcService]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SnoopFree]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SnoopFreeSvc]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sophos Client Firewall]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SPF4]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\spider]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SPIDERCTL]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\spidernt]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srescan]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Superkill]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SvcOnlineArmor]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Symantec AntiVirus]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SymantecAntiBotAgent]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SymEvent]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SysProtService]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tahi]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TAVM_Service]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDI_RD]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Teefer]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ThreatFire]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TMBMServer]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tmntsrv]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TmPfw]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tppfdmn]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TPSrv]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UmxCfg]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\UmxPol]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Vba32Ldr]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VCFSVC]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\VETMONNT]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vrfwsvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsmon]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WehnServ]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinDefend]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Windows SteadyState]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinRollBackSvc]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinRoute]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WRDRV]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\XCOMM]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\XPacket]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ZeroVProtect]
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ZVRegMon]
.
Completion time: 2008-10-29 20:28:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-29 12:28:00
ComboFix2.txt 2008-10-27 05:21:18
Pre-Run: 1,957,117,952 bytes free
Post-Run: 1,981,300,736 bytes free
528 --- E O F --- 2008-10-24 06:05:59