orderinthecourt
2009-07-26, 23:51
combofix log:
ComboFix 09-07-25.08 - Alex 07/26/2009 13:36.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1070 [GMT -7:00]
Running from: c:\documents and settings\Alex\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Alex\Favorites\translator.url
c:\documents and settings\Alex\x.exe
c:\recycler\NPROTECT
c:\windows\Installer\103cd.msi
c:\windows\Installer\103df.msi
c:\windows\Installer\103e6.msi
c:\windows\Installer\10a32e.msi
c:\windows\Installer\177405d.msi
c:\windows\Installer\18fda508.msi
c:\windows\Installer\1c520acd.msi
c:\windows\Installer\214aade0.msi
c:\windows\Installer\2827990f.msi
c:\windows\Installer\293f2.msi
c:\windows\Installer\2a6822.msi
c:\windows\Installer\2b17d246.msi
c:\windows\Installer\2b567af4.msi
c:\windows\Installer\2b567afb.msi
c:\windows\Installer\2e88a.msi
c:\windows\Installer\48223e5.msi
c:\windows\Installer\7b26d0.msi
c:\windows\Installer\7f8bace.msi
c:\windows\Installer\a3846.msi
c:\windows\Installer\b49aaeb.msi
c:\windows\Installer\c5e9de.msi
c:\windows\Installer\cd791c.msi
c:\windows\Installer\dfbac75.msi
c:\windows\system32\Data
c:\windows\system32\disk.dll
c:\windows\system32\drivers\SKYNETbaekvbln.sys
c:\windows\system32\NX.exe
c:\windows\system32\SKYNETmbjsflgh.dll
c:\windows\system32\SKYNETviqyfdfw.dat
c:\windows\system32\SKYNETxdgquslq.dll
c:\windows\system32\SKYNETywuowndb.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETuaitsquo
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-26 18:58 . 2009-07-26 18:58 -------- d-----w- c:\documents and settings\Alex\Application Data\Malwarebytes
2009-07-26 18:58 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-26 18:58 . 2009-07-26 18:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-26 18:58 . 2009-07-26 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-26 18:58 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-23 23:07 . 2009-07-23 23:38 -------- d-----w- C:\Lop SD
2009-07-23 22:59 . 2009-07-23 22:59 -------- d-----w- C:\songs 2 SS
2009-07-23 22:58 . 2009-07-23 22:59 -------- d-----w- C:\songs 1 L
2009-07-23 02:46 . 2009-07-23 02:46 -------- d-----w- C:\rsit
2009-07-23 02:46 . 2009-07-23 02:46 -------- d-----w- c:\program files\trend micro
2009-07-15 04:50 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-07-15 04:06 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-15 04:04 . 2009-07-08 17:28 2920112 -c--a-w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-07-15 04:03 . 2009-07-15 04:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-15 03:36 . 2009-07-15 03:36 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-07-15 03:34 . 2009-07-15 03:34 -------- d-sh--w- c:\documents and settings\Alex\PrivacIE
2009-07-15 03:32 . 2009-07-15 03:32 -------- d-sh--w- c:\documents and settings\Alex\IETldCache
2009-07-15 03:31 . 2009-07-15 03:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-15 03:16 . 2009-07-15 03:16 -------- d-----w- c:\windows\system32\XPSViewer
2009-07-15 03:16 . 2009-07-15 03:16 -------- d-----w- c:\program files\MSBuild
2009-07-15 03:16 . 2009-07-15 03:16 -------- d-----w- c:\program files\Reference Assemblies
2009-07-15 03:15 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-07-15 03:15 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-07-15 03:15 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-07-15 03:15 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-07-15 03:15 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-07-15 03:15 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-07-15 03:15 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-07-15 03:09 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-07-15 03:09 . 2009-07-15 03:09 -------- d-----w- c:\windows\ie8updates
2009-07-15 03:09 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-07-15 03:09 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-15 03:07 . 2009-07-15 03:08 -------- dc-h--w- c:\windows\ie8
2009-07-15 02:13 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-07-15 02:13 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-07-15 02:13 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-07-15 02:13 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-07-15 02:13 . 2009-02-09 12:10 729088 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-07-15 02:13 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-07-15 02:13 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-07-15 02:13 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-07-15 02:13 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-07-15 02:13 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-07-15 02:13 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-07-14 08:03 . 2009-07-15 04:04 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-14 02:57 . 2009-07-14 05:09 -------- d-----w- c:\windows\BDOSCAN8
2009-07-14 02:53 . 2008-06-20 00:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-07-14 02:52 . 2009-07-14 02:52 -------- d-----w- c:\program files\Panda Security
2009-07-14 02:49 . 2009-07-14 02:51 -------- d-----w- c:\documents and settings\Alex\.housecall6.6
2009-06-30 04:40 . 2009-07-13 04:47 -------- d-----w- c:\documents and settings\Alex\Local Settings\Application Data\MediaMonkey
2009-06-30 04:40 . 2009-06-30 04:40 -------- d-----w- c:\program files\MediaMonkey
2009-06-28 20:59 . 2009-06-28 20:59 -------- d-----w- c:\program files\iTunes
2009-06-28 20:59 . 2009-06-28 20:59 -------- d-----w- C:\Floola-win
2009-06-28 20:22 . 2009-06-28 20:22 -------- d-----w- c:\program files\Bonjour
2009-06-28 20:21 . 2009-06-28 20:21 -------- d-----w- c:\program files\Apple Software Update
2009-06-28 20:20 . 2009-06-28 20:20 -------- d-----w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 20:35 . 2004-07-18 03:03 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-26 19:49 . 2006-11-23 03:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-24 03:40 . 2006-08-28 00:00 20912 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-07-23 23:06 . 2004-08-08 02:43 -------- d-----w- c:\program files\Soulseek
2009-07-23 23:06 . 2005-05-06 21:43 -------- d-----w- c:\program files\LimeWire
2009-07-18 07:28 . 2006-07-09 15:55 -------- d-----w- c:\program files\CinemaForge
2009-07-17 00:44 . 2008-08-06 06:51 -------- d-----w- c:\program files\PeerGuardian2
2009-07-15 04:07 . 2004-07-18 02:48 -------- d-----w- c:\program files\SpywareBlaster
2009-07-15 04:03 . 2004-07-18 02:46 -------- d-----w- c:\program files\Lavasoft
2009-07-15 03:23 . 2004-10-01 22:47 145408 ----a-w- c:\windows\system32\drivers\VMM.sys
2009-07-14 13:17 . 2004-07-18 02:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-14 08:08 . 2004-08-26 22:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-01 04:25 . 2004-07-18 02:52 -------- d-----w- c:\program files\Winamp
2009-06-28 20:23 . 2004-07-21 07:07 -------- d-----w- c:\program files\iPod
2009-06-28 20:22 . 2006-04-15 09:13 -------- d-----w- c:\program files\QuickTime
2009-06-28 20:21 . 2004-07-21 07:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-20 05:53 . 2004-07-17 00:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-16 14:36 . 2001-08-23 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2001-08-23 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-08 07:51 . 2009-06-08 07:50 -------- d-----w- c:\documents and settings\Alex\Application Data\Winamp
2009-06-06 05:17 . 2007-08-26 18:32 -------- d-----w- c:\documents and settings\Alex\Application Data\Orbit
2009-06-03 19:09 . 2005-08-30 16:14 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-30 02:52 . 2009-05-30 02:52 -------- d-----w- c:\program files\7-Zip
2009-05-13 05:15 . 2005-06-18 06:49 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2001-08-23 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:55 . 2009-04-29 04:55 78336 ------w- c:\windows\system32\ieencode.dll
2001-10-05 19:53 . 2004-10-03 02:09 21866 ----a-w- c:\program files\Common Files\tppupd2k.dll
2009-07-22 02:04 . 2009-03-19 23:21 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-03 102400]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mmtask"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2004-01-26 53248]
"TPP Auto Loader"="c:\windows\TPPALDR.EXE" [2001-10-05 118784]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-11 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-16 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-23 81920]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 84640]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2006-09-05 26248]
"StxTrayMenu"="c:\program files\Seagate\SystemTray\StxMenuMgr.exe" [2007-01-18 190008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-04-10 37888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-02-23 278528]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\Alcxmntr.exe [2004-09-07 57344]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-10-04 90112]
"P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2005-05-04 64512]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-7-18 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Alex^Start Menu^Programs^Startup^PalNetaware.lnk]
backup=c:\windows\pss\PalNetaware.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\RavenShield\\system\\RavenShield.exe"=
"c:\\Program Files\\K-Lite Codec Pack\\Media Player Classic\\mplayerc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"d:\\Condition Zero\\czero.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"d:\\UnrealTournament\\System\\UnrealTournament.exe"=
"d:\\Quake 3\\quake3.exe"=
"c:\\Program Files\\SmartFTP\\SmartFTP.exe"=
"c:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"d:\\Duke Nukem 3D\\spill\\duke3d\\eduke32.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\UT2004\\System\\UT2004.exe"=
"d:\\Valve\\Steam\\SteamApps\\psychomantis2144@yahoo.com\\team fortress 2\\hl2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16567:UDP"= 16567:UDP:bf21
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/14/2009 9:06 PM 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [7/13/2009 7:53 PM 28544]
R2 Seagate Sync Service;Seagate Sync Service;c:\program files\Seagate\Sync\SeaSyncServices.exe [1/18/2007 2:20 PM 24120]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/1/2009 11:22 AM 101936]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 7:49 AM 1029456]
S3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [3/20/2006 7:34 PM 1452032]
S3 pnicml;pnicml;\??\c:\docume~1\Alex\LOCALS~1\Temp\pnicml.sys --> c:\docume~1\Alex\LOCALS~1\Temp\pnicml.sys [?]
S3 TPP200;USB Storage Adapter V2 (TPP);c:\windows\system32\drivers\tpp200.sys [10/2/2004 7:09 PM 35541]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
2008-07-19 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Alex.job
- c:\progra~1\NORTON~1\Navw32.exe [2006-09-07 00:38]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{F3DF2532-A2CC-48D8-8643-A033AE4FC313} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKLM-Run-SaitekInstall - f:\winnt\InstallWizard.exe
HKLM-Run-CmPCIaudio - CMICNFG3.CPL
HKLM-Run-CTXFIREG - CTxfiReg.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: aol.com\free
FF - ProfilePath - c:\documents and settings\Alex\Application Data\Mozilla\Firefox\Profiles\default.y19\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJPI150_01.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPOJI610.dll
FF - plugin: d:\gametap\bin\Release\npgametaptool.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-26 13:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-796845957-2111687655-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"????????????????????????"=hex:bd,50,9f,4d,61,ff,02,14,7e,90,d7,39,62,28,83,1d,
63,63,70,63,56,56,05,f7,63,63,56,be,05,f4,c2,c2,00,00,00,00,00,00,00,00,00,\
"???n"=hex:d5,05,9b,37,3b,d5,c7,01,66,ed,b8,96,2c,41,bc,83,ef,9f,ec,61,8a,a4,
59,6c,c7,81,bd,e4,99,4c,54,d0,7f,83,16,cd,84,49,03,f6,91,5e,0e,15,2d,65,f5,\
"?????"=hex:00,be,22,14,12,08,03,6a,63,5e,6b,3d,09,4c,3a,3a
"???n"=hex:8c,68,39,e9,6d,02,64,7f,10,77,37,16,17,26,10,7c,04,3e,d1,de,29,16,
2c,8f,1c,c4,64,82,96,e2,ba,c7,51,37,8c,96,dc,96,af,3a,81,dc,8b,38,a2,0b,09,\
"???n"=hex:e4,81,0b,f0,54,71,93,c9,94,c2,8e,9c,77,e2,d2,2d,1a,62,42,17,cf,a9,
d2,8d,ec,c1,70,32,47,bd,1a,4b,70,b3,da,f1,04,ea,dd,6a,bd,fb,9b,86,95,a8,10,\
"???n"=hex:de,d9,df,d6,79,04,96,56,e7,c4,91,73,6d,0b,a2,5b,b2,85,07,d1,a9,f9,
33,73,b7,ba,d3,ee,9f,52,86,dc,6a,6f,50,78,39,20,25,c5,ed,f7,7b,c4,5e,49,fc,\
"???n"=hex:d0,02,e8,15,d3,75,fd,51,0c,09,15,63,8a,b9,48,28,f8,a2,1f,be,cd,4a,
d7,7f,90,61,4f,49,16,94,e8,b3,c3,21,29,72,98,9f,13,71,9d,59,ea,58,8a,d1,c9,\
"???n"=hex:e7,6c,4f,f5,b5,16,c1,4d,d0,75,c1,1b,83,05,e5,eb,c7,a0,8d,bf,f5,d5,
25,0f,e4,58,97,f6,bf,f5,9d,01,ee,f7,46,a9,a2,e4,d0,1a,3e,85,bd,07,aa,59,ab,\
"???n"=hex:e5,6f,86,ed,96,2f,d4,12,e3,a2,c8,81,70,b2,81,b9,61,1b,b0,82,a4,28,
a6,f9,b6,3e,49,5d,68,1f,59,56,a6,32,8d,c4,c8,0e,16,d9,e8,0f,26,a8,9f,f2,ac,\
"???n"=hex:a1,78,a7,19,3e,a0,bc,11,d1,2f,37,6c,2d,5a,87,b6,53,09,09,9e,94,73,
b4,4a,34,b5,6f,8a,22,07,e9,cc,f6,20,9a,30,c1,74,fd,d6,6b,c3,2c,b2,27,dc,b4,\
"???n"=hex:6e,08,a2,0f,93,f4,57,fe,b5,34,06,73,97,34,2f,85,56,0a,4b,e6,d8,db,
07,b8,fd,e3,7b,19,0a,d7,42,12,73,ca,21,28,40,d3,7a,b6,8b,a9,fd,e9,a5,48,eb,\
"??"=hex:41,4c,c9,d4,ec,9f,6b,cc,aa,5f,78,e4,55,6e,48,46,3f,ab,54,91,3c,30,18,
72,4c,af,f5,1f,9d,0a,17,94,99,51,6f,25,72,63,18,3f,e8,b3,79,a1,a7,38,20,66,\
"??"=hex:98,57,df,2a,12,b1,c4,e8,d1,ce,9f,04,bc,8c,27,63
[HKEY_LOCAL_MACHINE\software\Classes\.application\bootstrap]
@DACL=(02 0000)
@="bootstrap.application.1"
[HKEY_LOCAL_MACHINE\software\Classes\giffile\shell\Open\ddeexec]
@DACL=(02 0000)
@="\"file:%1\",,-1,,,,,"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG06.00.00.01WORKSTATION"="60E51B6F03099E7254874EDCBE0E1E9E4DAC8C755B59E2BEE9F8F5BCADCD1A57879B16BF7959D8FE503731371AE6CFCB0FD75DA60CDC52FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C9DB7CE019D40AA5CA6171C11EC38DE3DC038D530D6EB3452FEBC9E127BECC74C3AD2A98E0D1DC67D4DA71AD9B4F0CCF5AA00D213CB18E93B78D5B9263B5295C99B730B0434042D01984C59B765B26B2C0CA688562F5C8052A41770BAEE92285C3FC2F793DD6FDF0D81FBD53D75CF1DBF912ACF70ED6AA3FD5303133CC6AD5EE9C0111DD464EED0EA4A0DAFB036EA9437C685D672731CE8A4775A83A7E651CD539E042C52C7A5371899A7874921BE494D1D07D2E2535EA6DD6D3125EF1B3FCEAAB914DA8BA9CA0DC6FB4C06B3D195F6F1E751FA3A41B1FAF2EFEE62FA50CE7F3BDA8E62F2D12B8FDBDF4AD30F86509BC5605B0A6396ADC5E4A2CFA5A318E9C001AA13816F2BA3427099C8A1EE26E3FAA0A27040C150F8A9678962E0B6A80FB72B371878DBC329E952E041A05D36D79B8B2FAEE1A90E520FE18D0C8976DBD0CD1FF4E40E09CF429183CE8087D4E348C9466A8836639589A46FFD831798AF542F75B8170B38A40A8739E4AA92457E6513449DC6082D4F86D6DF0B530548C5554E7B3D1F3F21BF31DCDC86B27D92F9744C2AF202A8B7C9BFDCB64A5E57A264A05F30A0C0F8ED3D79E78CF9648D96EDCC8CD27D2AEA27B345ADAA35D68FBA75195C48E59710BEE1BA4419EBDC881B185B2DCCAE812516E336842929C3371586B4012DF28DDDA69260CE08E98DB961D5204EDB621F351051C7E2CF6781DCAC4AFE50FA9264BF2BDCE92B1469BCEE9DABAED47452ECF9171BC40D7315408DEE95158D82F2B19749EC6A3C294184F9F6433064C31FAAD6207F8A0A9A3D04E1BE6229C34827DD4B6F980830692BD1330B66E0EB25CEEAB213660826014B23EE7150823F832424C37F547F722BC866F4678691172EC894FA4ED6C47397114B54511FFA11A245186ED13C1FB5761D581D91B5255CA359E29DA2FD59C30045FAB09C36808EC5491C3E300F4B700A8E128F812E947080B0E38F54ACF1AF12FE0629059E15CFBF51E9A8DB2FF95D56695031244AECCE73E379C71DD75294DA3E94E6B0864FB31BE50DA5852438F9025CA6EDD789CCB8DEEADB4229194D1198E22296B83F5A5A946E6935D418A38866FAF8B37191E9AD58A2957E9A2C4D8ABEB17F682DBF73291ABC30D665DAEF8E113E807639290CF82C4A850006F250A875D5CE118E216DC9D2016D12C5DE6557C1FE4D2C6ABC8EA1D7885E4FF371665797DB8849D322ADA816D17BEF79BADDF0707D40CEB55BE27A8D63A576E252B5C73535F84E66A33077712A0B7DF6AAC8ACC6DE8EDD3EB98E9435C7B7864260F56C1137"
.
Completion time: 2009-07-26 13:45
ComboFix-quarantined-files.txt 2009-07-26 20:45
Pre-Run: 1,096,638,464 bytes free
Post-Run: 1,002,106,880 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
320 --- E O F --- 2008-11-12 11:01