undeadwolf7
2009-11-20, 10:32
Here is the requested log file please let me know if you want it a different way
ComboFix 09-11-19.05 - Kenny 11/20/2009 3:04.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.452 [GMT -5:00]
Running from: c:\documents and settings\Kenny\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Family\Local Settings\Application Data\{ADFFA9C6-7DC3-4F64-B103-E9C606A2FC36}
c:\documents and settings\Family\Local Settings\Application Data\{ADFFA9C6-7DC3-4F64-B103-E9C606A2FC36}\chrome.manifest
c:\documents and settings\Family\Local Settings\Application Data\{ADFFA9C6-7DC3-4F64-B103-E9C606A2FC36}\chrome\content\_cfg.js
c:\documents and settings\Family\Local Settings\Application Data\{ADFFA9C6-7DC3-4F64-B103-E9C606A2FC36}\chrome\content\c.js
c:\documents and settings\Family\Local Settings\Application Data\{ADFFA9C6-7DC3-4F64-B103-E9C606A2FC36}\chrome\content\overlay.xul
c:\documents and settings\Family\Local Settings\Application Data\{ADFFA9C6-7DC3-4F64-B103-E9C606A2FC36}\install.rdf
c:\documents and settings\Kenny\Local Settings\Application Data\{8651ACE7-2EFF-4A6F-A91B-0109AFDE821C}
c:\documents and settings\Kenny\Local Settings\Application Data\{8651ACE7-2EFF-4A6F-A91B-0109AFDE821C}\chrome.manifest
c:\documents and settings\Kenny\Local Settings\Application Data\{8651ACE7-2EFF-4A6F-A91B-0109AFDE821C}\chrome\content\_cfg.js
c:\documents and settings\Kenny\Local Settings\Application Data\{8651ACE7-2EFF-4A6F-A91B-0109AFDE821C}\chrome\content\c.js
c:\documents and settings\Kenny\Local Settings\Application Data\{8651ACE7-2EFF-4A6F-A91B-0109AFDE821C}\chrome\content\overlay.xul
c:\documents and settings\Kenny\Local Settings\Application Data\{8651ACE7-2EFF-4A6F-A91B-0109AFDE821C}\install.rdf
c:\documents and settings\Kenny\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\Kenny\Local Settings\Temporary Internet Files\udRemove.exe
c:\program files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
c:\windows\kb913800.exe
c:\windows\run.log
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\18324090.dll
c:\windows\system32\Cache
c:\windows\system32\Data
c:\windows\system32\xa.tmp
.
((((((((((((((((((((((((( Files Created from 2009-10-20 to 2009-11-20 )))))))))))))))))))))))))))))))
.
2009-11-20 08:04 . 2006-07-06 12:59 246784 ----a-w- c:\windows\system32\drivers\iaStor.sys
2009-11-16 12:11 . 2009-11-16 12:11 -------- d-----w- C:\found.003
2009-11-13 16:35 . 2009-11-13 16:35 -------- d-----w- c:\program files\ERUNT
2009-11-12 07:36 . 2009-11-17 18:16 -------- d-----w- c:\program files\Bethesda Softworks
2009-11-10 02:21 . 2009-11-10 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2009-11-10 01:25 . 2009-09-04 22:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-11-10 01:25 . 2009-09-04 22:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-11-10 01:25 . 2009-09-04 22:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-11-10 01:25 . 2009-09-04 22:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-11-10 01:25 . 2009-09-04 22:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-11-10 01:25 . 2009-09-04 22:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-11-10 01:25 . 2009-09-04 22:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-11-10 00:50 . 2008-05-30 19:19 507400 ----a-w- c:\windows\system32\XAudio2_1.dll
2009-11-10 00:50 . 2008-05-30 19:17 65032 ----a-w- c:\windows\system32\XAPOFX1_0.dll
2009-11-10 00:50 . 2008-05-30 19:18 238088 ----a-w- c:\windows\system32\xactengine3_1.dll
2009-11-10 00:50 . 2008-05-30 19:17 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll
2009-11-10 00:50 . 2008-05-30 19:11 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2009-11-10 00:50 . 2008-05-30 19:11 1491992 ----a-w- c:\windows\system32\D3DCompiler_38.dll
2009-11-10 00:50 . 2008-05-30 19:11 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll
2009-11-10 00:50 . 2008-03-05 21:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2009-11-10 00:50 . 2008-03-05 21:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll
2009-11-10 00:50 . 2008-03-05 21:00 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll
2009-11-10 00:45 . 2008-03-05 20:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2009-11-10 00:45 . 2008-02-06 04:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2009-11-10 00:45 . 2008-03-05 20:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2009-11-10 00:44 . 2009-11-10 00:44 -------- d-----w- c:\windows\system32\xlive
2009-11-10 00:44 . 2009-11-10 00:45 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-11-09 01:39 . 2009-11-09 01:39 -------- d-----w- C:\GamepotUSA
2009-11-08 20:11 . 2009-11-08 20:11 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-11-08 09:35 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\9c13920.dll
2009-11-08 09:35 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\17d08eb5.dll
2009-11-08 09:25 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\b533e7b.dll
2009-11-08 09:25 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\a3cb000.dll
2009-11-07 00:36 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\dd9c188.dll
2009-11-07 00:34 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\6b49aca.dll
2009-11-07 00:34 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\3920f5f4.dll
2009-11-06 13:14 . 2009-10-21 13:09 2064152 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-11-06 02:14 . 2009-11-06 02:14 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-11-04 22:31 . 2009-11-05 00:50 -------- d-----w- c:\program files\Silkroad
2009-11-04 18:38 . 2009-09-23 14:41 26176 ---ha-w- c:\windows\system32\hamachi.sys
2009-11-04 00:31 . 2009-11-04 00:31 -------- d-----w- c:\documents and settings\Kenny\Application Data\NeopleLauncherDFO
2009-10-29 02:26 . 2009-10-29 02:26 -------- d-----w- c:\program files\IObit
2009-10-22 02:34 . 2009-10-22 02:34 -------- d-----w- c:\documents and settings\Kenny\Local Settings\Application Data\Ironclad Games
2009-10-22 02:29 . 2009-10-22 02:38 -------- d-----w- c:\documents and settings\Kenny\Application Data\Stardock
2009-10-22 02:28 . 2009-10-22 02:28 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{6F7EF3E6-7F1B-4824-84CD-E8DF6F1B4168}
2009-10-22 02:28 . 2009-06-04 20:05 2606568 -c--a-w- c:\documents and settings\All Users\Application Data\{6F7EF3E6-7F1B-4824-84CD-E8DF6F1B4168}\Impulse_setup.exe
2009-10-22 02:27 . 2009-10-22 02:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Stardock
2009-10-22 02:26 . 2009-11-09 01:27 -------- dc-h--w- c:\documents and settings\Kenny\Local Settings\Application Data\~0
2009-10-22 02:22 . 2009-10-22 02:22 -------- d-----w- c:\documents and settings\Kenny\Local Settings\Application Data\PackageAware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-20 02:04 . 2007-11-24 02:33 100880 -c--a-w- c:\documents and settings\Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-20 01:36 . 2009-06-18 14:32 -------- d-----w- c:\program files\X-Change 3
2009-11-20 01:36 . 2007-04-23 12:18 -------- d-----w- c:\program files\xc2
2009-11-20 01:33 . 2007-02-04 04:31 737280 -c--a-w- c:\windows\iun6002.exe
2009-11-19 06:28 . 2008-12-10 09:34 -------- d-----w- c:\documents and settings\Kenny\Application Data\Xfire
2009-11-18 07:07 . 2008-12-10 09:34 -------- d-----w- c:\program files\Xfire
2009-11-17 22:08 . 2007-02-03 23:26 -------- d-----w- c:\program files\EA GAMES
2009-11-17 18:13 . 2007-01-16 18:15 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-16 12:19 . 2008-09-30 05:22 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-11-14 03:02 . 2008-11-01 18:46 0 ----a-w- c:\documents and settings\Family\Local Settings\Application Data\prvlcl.dat
2009-11-13 17:52 . 2007-05-25 12:51 -------- d-----w- c:\program files\Winamp
2009-11-13 05:22 . 2007-06-21 12:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-12 08:19 . 2007-08-25 23:55 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-12 05:51 . 2007-01-28 03:20 -------- d-----w- c:\program files\LucasArts
2009-11-12 03:10 . 2009-08-20 10:57 -------- d-----w- c:\program files\World of Warcraft
2009-11-10 02:15 . 2007-01-16 18:16 -------- d-----w- c:\program files\ATI Technologies
2009-11-09 22:00 . 2009-09-17 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-11-09 21:59 . 2009-09-17 20:03 -------- d-----w- c:\program files\IGN
2009-11-09 21:59 . 2007-01-26 06:30 -------- d-----w- c:\documents and settings\Kenny\Application Data\IGN_DLM
2009-11-09 21:56 . 2007-01-16 18:20 -------- d-----w- c:\program files\Roxio
2009-11-09 21:56 . 2007-01-16 18:17 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-11-09 21:53 . 2007-11-24 02:33 -------- d--h--w- c:\documents and settings\Family\Application Data\Gtek
2009-11-09 21:53 . 2007-05-03 23:35 -------- d--h--w- c:\documents and settings\MCX1\Application Data\Gtek
2009-11-09 21:53 . 2007-01-18 04:05 -------- d--h--w- c:\documents and settings\Kenny\Application Data\Gtek
2009-11-09 21:53 . 2007-01-16 18:26 -------- d--h--w- c:\documents and settings\Administrator\Application Data\GTek
2009-11-09 21:53 . 2007-07-17 07:00 -------- d-----w- c:\program files\Doushin
2009-11-09 21:50 . 2007-01-16 18:19 -------- d-----w- c:\program files\Real
2009-11-09 21:50 . 2007-01-20 03:22 -------- d-----w- c:\program files\Rhapsody
2009-11-08 23:21 . 2007-03-25 16:57 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-04 00:11 . 2009-03-28 01:22 90112 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2009-11-04 00:11 . 2009-03-28 01:22 561152 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2009-11-04 00:11 . 2009-03-28 01:22 393216 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2009-11-04 00:11 . 2009-03-28 01:22 258352 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2009-11-04 00:11 . 2009-03-28 01:22 167936 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2009-11-04 00:11 . 2009-03-28 01:22 118784 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2009-11-03 23:42 . 2009-03-28 00:10 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2009-10-22 02:27 . 2007-07-03 01:51 -------- d-----w- c:\program files\Stardock
2009-10-18 13:09 . 2009-10-18 13:09 2025752 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-10-14 07:06 . 2007-01-16 18:25 -------- d-----w- c:\program files\Microsoft Works
2009-10-12 16:36 . 2009-08-22 15:46 -------- d-----w- c:\program files\Warcraft III
2009-10-05 19:32 . 2009-10-03 00:40 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-10-03 00:58 . 2009-10-03 00:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2009-10-03 00:57 . 2009-09-17 21:41 22328 ----a-w- c:\documents and settings\Kenny\Application Data\PnkBstrK.sys
2009-10-03 00:57 . 2009-09-17 21:41 22328 ----a-w- c:\documents and settings\Kenny\Application Data\PnkBstrK.sys
2009-10-03 00:57 . 2007-07-11 02:25 22328 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-03 00:57 . 2007-07-11 02:24 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-03 00:57 . 2009-09-17 21:40 2337865 ----a-w- c:\windows\system32\pbsvc.exe
2009-10-03 00:57 . 2007-07-11 02:24 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-10-03 00:42 . 2009-10-03 00:42 -------- d-----w- c:\program files\Ubisoft
2009-10-03 00:41 . 2008-12-29 04:17 -------- d-----w- c:\documents and settings\Kenny\Application Data\DAEMON Tools Lite
2009-10-03 00:40 . 2009-10-03 00:40 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-10-03 00:32 . 2007-02-05 01:23 -------- d-----w- c:\documents and settings\Kenny\Application Data\Azureus
2009-10-02 19:44 . 2008-01-08 06:13 -------- d-----w- c:\documents and settings\Kenny\Application Data\Free Download Manager
2009-10-02 19:15 . 2007-05-25 12:51 -------- d-----w- c:\documents and settings\Kenny\Application Data\Winamp
2009-10-01 13:58 . 2008-12-29 04:17 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-24 07:03 . 2009-09-24 07:03 -------- d-----w- c:\program files\Firaxis Games
2009-09-24 04:04 . 2009-09-24 03:50 -------- d-----w- c:\documents and settings\Kenny\Application Data\Ventrilo
2009-09-24 03:47 . 2009-09-24 03:47 -------- d-----w- c:\program files\Ventrilo
2009-09-24 03:46 . 2008-03-04 19:56 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-23 15:41 . 2009-09-23 15:41 26176 ---ha-w- c:\windows\system32\drivers\hamachi.sys
2009-09-23 04:25 . 2007-03-29 00:11 -------- d-----w- c:\program files\Electronic Arts
2009-09-21 21:18 . 2009-09-21 17:39 -------- d-----w- c:\program files\Turbine
2009-09-11 14:18 . 2005-08-16 10:18 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 22:44 . 2009-11-10 00:51 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 21:03 . 2005-08-16 10:18 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-02 02:52 . 2008-04-02 05:02 98304 -c--a-w- c:\windows\system32CmdLineExt.dll
2009-08-29 07:36 . 2005-08-16 10:18 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2005-08-16 10:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2005-08-16 10:18 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2005-08-16 10:19 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 22:04 . 2009-08-25 22:04 75264 ----a-w- c:\windows\system32\uc_holybeast_launching.dll
2007-05-03 23:46 . 2007-02-05 10:13 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 16:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"SetDefaultMIDI"="MIDIDef.exe" - c:\windows\MIDIDEF.EXE [2004-12-22 24576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-03 2028312]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-01-16 98304]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-21 61440]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-07-24 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 12:46 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Extender Resource Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk
backup=c:\windows\pss\Extender Resource Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Kenny^Start Menu^Programs^Startup^GameSpot Download Manager.lnk]
path=c:\documents and settings\Kenny\Start Menu\Programs\Startup\GameSpot Download Manager.lnk
backup=c:\windows\pss\GameSpot Download Manager.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Kenny^Start Menu^Programs^Startup^ImpulseNow.lnk]
path=c:\documents and settings\Kenny\Start Menu\Programs\Startup\ImpulseNow.lnk
backup=c:\windows\pss\ImpulseNow.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Kenny^Start Menu^Programs^Startup^Xfire.lnk]
path=c:\documents and settings\Kenny\Start Menu\Programs\Startup\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"idsvc"=3 (0x3)
"TapiSrv"=3 (0x3)
"Symantec Core LC"=2 (0x2)
"PnkBstrA"=2 (0x2)
"npkcmsvc"=2 (0x2)
"npggsvc"=3 (0x3)
"NMSAccessU"=2 (0x2)
"mnmsrvc"=3 (0x3)
"MDM"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"helpsvc"=2 (0x2)
"Fax"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"ERSvc"=2 (0x2)
"DNADownloader"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"PnkBstrB"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\PortableMudMaster\\MudMaster.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"17771:UDP"= 17771:UDP:Two Worlds
"58713:TCP"= 58713:TCP:Pando Media Booster
"58713:UDP"= 58713:UDP:Pando Media Booster
"59062:TCP"= 59062:TCP:Pando Media Booster
"59062:UDP"= 59062:UDP:Pando Media Booster
"58985:TCP"= 58985:TCP:Pando Media Booster
"58985:UDP"= 58985:UDP:Pando Media Booster
"58859:TCP"= 58859:TCP:Pando Media Booster
"58859:UDP"= 58859:UDP:Pando Media Booster
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/28/2008 11:17 PM 721904]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/30/2008 12:22 AM 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/30/2008 12:22 AM 297752]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;\??\c:\program files\VMLaunch\BuddyVM.sys --> c:\program files\VMLaunch\BuddyVM.sys [?]
S3 XDva020;XDva020;\??\c:\windows\system32\XDva020.sys --> c:\windows\system32\XDva020.sys [?]
S3 XDva190;XDva190;\??\c:\windows\system32\XDva190.sys --> c:\windows\system32\XDva190.sys [?]
S3 XDva284;XDva284;\??\c:\windows\system32\XDva284.sys --> c:\windows\system32\XDva284.sys [?]
S4 DNADownloader;DNADownloader;c:\program files\GameSpot\DownloadManager_Win32.exe --> c:\program files\GameSpot\DownloadManager_Win32.exe [?]
S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CLASSPNP_2
*Deregistered* - CLASSPNP_2
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070116
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
DPF: {8C292180-8BB2-495F-B94B-89FE9F2B530A} - hxxp://rfonline-full.gscdn.com/gscdn/ccr_downloader.cab
FF - ProfilePath - c:\documents and settings\Kenny\Application Data\Mozilla\Firefox\Profiles\vgtyytk2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Kenny\Application Data\Mozilla\Firefox\Profiles\vgtyytk2.default\extensions\CSLauncher@cyberstep.com\plugins\npCsLauncher.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
SharedTaskScheduler-{d9017acf-52af-48d4-81b4-a9c261dc8a08} - c:\windows\system32\rirururu.dll
SharedTaskScheduler-{11f06a01-4b2c-4fe9-bd04-1a2190c3bdb9} - c:\windows\system32\godohavu.dll
SSODL-bibelefoh-{d9017acf-52af-48d4-81b4-a9c261dc8a08} - c:\windows\system32\rirururu.dll
SSODL-bakepahur-{11f06a01-4b2c-4fe9-bd04-1a2190c3bdb9} - c:\windows\system32\godohavu.dll
AddRemove-7-Zip - e:\program files\7-Zip\Uninstall.exe
AddRemove-All Sound Recorder XP_is1 - c:\program files\All Sound Recorder XP\unins000.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
AddRemove-GameSpotDownloadManager - c:\program files\GameSpot\uninstall.exe
AddRemove-IGN Download Manager - c:\program files\IGN\Download Manager\uninst.exe
AddRemove-Rohan_RBF - c:\rohan_global\GoUninstRBF.exe
AddRemove-StreetPlugin - c:\program files\Learn2.com\StRunner\stuninst.exe
AddRemove-{ECCA8FE7-767A-4C8A-9DAA-BAB60F877C41} - c:\documents and settings\Kenny\Local Settings\Application Data\{DF6E6A21-48E9-4FBD-B0B2-9E838A1DFED0}\setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-20 03:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spuq.sys hal.dll >>UNKNOWN [0x86F86938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf76b7f28
\Driver\ACPI -> ACPI.sys @ 0xf7431cb8
\Driver\iaStor -> iaStor.sys @ 0xf7356150
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Intel(R) 82566DC Gigabit Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf721dbb0
PacketIndicateHandler -> NDIS.sys @ 0xf722aa21
SendHandler -> NDIS.sys @ 0xf720887b
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
iaStor.sys @ 0x0 0x0 bytes
\Driver\iaStor [ IRP_MJ_CREATE ] 0x4FC2 != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_CLOSE ] 0x4FC2 != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_DEVICE_CONTROL ] 0x8CBE != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x8F80 != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_POWER ] 0xD884 != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_SYSTEM_CONTROL ] 0xD9E4 != 0xF7356150 iaStor.sys
\Driver\iaStor IRP hooks detected !
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3167047611-3067674008-2036097901-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:4f,32,ca,1e,d7,09,58,34,85,74,41,5d,06,e9,73,3f,a5,b8,50,dd,35,b6,0e,
96,8b,e7,a1,30,79,81,08,bd,94,8c,d8,e9,4c,7d,03,58,03,ee,0b,42,8e,1a,e3,4e,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
[HKEY_USERS\S-1-5-21-3167047611-3067674008-2036097901-1006\Software\SecuROM\License information*]
"datasecu"=hex:3b,08,4c,83,8c,d2,5a,87,19,b1,11,4e,85,30,77,85,34,46,3a,d6,c7,
20,3a,ad,e3,30,3a,61,bc,7a,1b,af,8d,1e,b0,c9,19,a8,d2,0e,1f,9c,e5,26,00,29,\
"rkeysecu"=hex:2d,50,a1,70,eb,32,e2,36,42,75,89,3a,8a,db,d6,0c
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{114866E9-7C82-20F7-16C3063A4CAB25A4}\{3FC78BFC-C5A7-A764-C3D11931F655D68A}\{CA848313-C322-9D26-10260A1412DD57C5}*]
"LQP5ZPUUKXNMDKQUSVXO5P66YE1"=hex:01,00,01,00,00,00,00,00,14,69,e6,a8,43,8f,2a,
a0,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1159B246-0933-86DB-AD593C3CB7051897}\{4B332D01-174C-E53B-FFAF1A8AAD861E31}\{3A54BA3C-24AD-210D-6C7EF9C90D2B01E7}*]
"L5OTYL4OSK54QTZWOGJWMONWTG1"=hex:01,00,01,00,00,00,00,00,4f,1a,34,b6,a9,51,c3,
92,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{18D6E519-4C27-E4AD-074C5D1F171B40FB}\{8D7A772B-93EE-6905-4C751BA1B544AFC9}\{7029C73E-0020-BA9C-F3FADF03D99AF0E6}*]
"G2ODBCSUISDKL2GJMZO1MJ5AUG1"=hex:01,00,01,00,00,00,00,00,9d,07,c2,9d,25,58,3c,
a7,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{29C7572E-368C-9746-3DB4E03B0C8852AE}\{D5583F53-2F82-8141-B7E22169E34927D8}\{884189AF-2B25-871B-C10F8549E6A3D936}*]
"TU4WOU1J6ARI5KX1FANSH3C1OF1"=hex:01,00,01,00,00,00,00,00,3d,cd,b7,46,4e,75,8f,
24,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3C314B03-F43E-BA89-952BA1DFD2D5EFE8}\{7539A87C-0FED-33C5-609B84E8BF01550C}\{B9902A55-37BA-35DE-AA3E0A7380F9249D}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,c9,9f,ac,
8e,92,50,2c,f7,8d,73,0e,55,c6,b9,8f,ce,6d,42,5e,de,26,16,ad,d5,92,7f,d2,0e,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47761F54-3284-4187-35228790176E1027}\{9364B136-59D9-79F3-ED3B0078FC46782B}\{67D1DB51-467A-B17B-59ADF812AC6D3A34}*]
"LQP5ZPUUKXNMDKQUSVXO5P66YE1"=hex:01,00,01,00,00,00,00,00,14,69,e6,a8,43,8f,2a,
a0,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4E801B1F-2C34-C71B-55752B4DE71FAE4A}\{6707E13D-DFA5-4083-2A160A7F601D7F5F}\{38345692-AD4C-2D4A-1F4885FC450939AB}*]
"AXBBEZDR5GG1RHH1SV4GCUI36H1"=hex:01,00,01,00,00,00,00,00,ea,70,b2,10,82,71,5d,
44,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{61F22E4F-B27F-AFC4-A522A9C3D24CB12E}\{1AB70131-6AEF-F29E-373C8656BA527ED6}\{4909E9D0-65F5-FEDD-EF93FC8CC6374EF9}*]
"G2ODBCSUISDKL2GJMZO1MJ5AUG1"=hex:01,00,01,00,00,00,00,00,9d,07,c2,9d,25,58,3c,
a7,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6283EF60-5306-646F-3E2A60A6F3147012}\{EC258BE5-E5B0-C834-EB7A48F96467BF3F}\{829C9D27-3E4A-4D61-8C18630CF0B6A85C}*]
"L5OTYL4OSK54QTZWOGJWMONWTG1"=hex:01,00,01,00,00,00,00,00,4f,1a,34,b6,a9,51,c3,
92,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{75213A09-BF18-CDCA-476AD0C74F911579}\{60ECD51F-CC80-5083-F2221FA8EEB126FE}\{82B5FD34-7E39-B473-9523AE140A4D16E3}*]
"QR1ILJL5ACMYH2P3FXOAHPVAQE1"=hex:01,00,01,00,00,00,00,00,e3,c2,76,29,f1,92,b8,
65,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8CD4472C-E90F-9EEE-8658179FAD84CDE4}\{86C14694-A4A0-6014-B9D2B6867C4357D1}\{413E2BB7-2C4D-BBD1-7F39BC4CF716110E}*]
"DIUMUTVOZPCSSGX5CJY2KLBAVE1"=hex:01,00,01,00,00,00,00,00,64,6d,b1,e3,87,75,1d,
e5,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{90C9B227-00E9-ED2B-D8335C00663422E2}\{BA143829-6513-6AB3-17B76E63BBBF825B}\{B7811D8F-B091-6828-D848878685722533}*]
"PK3IM51V2WPW5YOPIRJ365XEIG1"=hex:01,00,01,00,00,00,00,00,c3,a2,73,89,0b,39,ad,
69,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{91FA78BC-641E-4329-C41B32C9E0F96EA6}\{25E342AA-73A9-1FC4-4AC5C50BDBE96017}\{04863130-DE8E-7A09-D0B765EBFF2273E8}*]
"2EQJ2Z3RJDTDB2HBN4IWIN4ITC1"=hex:01,00,01,00,00,00,00,00,50,18,12,ae,1d,3d,93,
38,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A31F0760-3CAF-40FF-C311EB15E667F290}\{E2D01E6A-D52B-9055-85F4CB9FDFA44017}\{62A48FA1-2175-E3E4-19BA4655EA387446}*]
"AXBBEZDR5GG1RHH1SV4GCUI36H1"=hex:01,00,01,00,00,00,00,00,ea,70,b2,10,82,71,5d,
44,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}*]
"2EQJ2Z3RJDTDB2HBN4IWIN4ITC1"=hex:01,00,01,00,00,00,00,00,50,18,12,ae,1d,3d,93,
38,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C19175F0-6343-C058-D551EA9B69721CA5}\{44B8D0A6-F0B8-27D0-3AB262946B96BF2A}\{D0951FF3-5F85-5129-204F105C4943049E}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,c9,9f,ac,
8e,92,50,2c,f7,8d,73,0e,55,c6,b9,8f,ce,6d,42,5e,de,26,16,ad,d5,92,7f,d2,0e,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D19C1E37-C88F-6D4D-695F1151D26FA9B0}\{82ADB184-4273-F4A9-8B3869F4D9D9F30C}\{3C71EBCF-572C-11DA-DA6A44EB5C52EFBA}*]
"DIUMUTVOZPCSSGX5CJY2KLBAVE1"=hex:01,00,01,00,00,00,00,00,64,6d,b1,e3,87,75,1d,
e5,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E9204BC4-9B67-A3A7-9418040E7EC7E28B}\{1ACE6D24-C4A9-397B-64EF395CC2F330B1}\{685A2618-4C9F-7737-7DE531E9434892E2}*]
"TU4WOU1J6ARI5KX1FANSH3C1OF1"=hex:01,00,01,00,00,00,00,00,3d,cd,b7,46,4e,75,8f,
24,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FF3E9388-AC5C-78BA-ADD2DEDBC8CD3822}\{3A1287C7-66E7-369B-1F735B898390688C}\{D7B36791-6000-8B4A-CB886D7CE3F1E4AE}*]
"QR1ILJL5ACMYH2P3FXOAHPVAQE1"=hex:01,00,01,00,00,00,00,00,e3,c2,76,29,f1,92,b8,
65,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(208)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\windows\ehome\RMSvc.exe
c:\program files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\ehome\McrdSvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\eHome\ehmsas.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2009-11-20 03:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-20 08:25
Pre-Run: 88,956,252,160 bytes free
Post-Run: 89,076,764,672 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 34496AD8CABBC35D68B06ECEA7C895F3
undeadwolf7
2009-11-20, 23:57
Here is the Combo Fix log
ComboFix 09-11-19.05 - Kenny 11/20/2009 16:25.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.506 [GMT -5:00]
Running from: c:\documents and settings\Kenny\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kenny\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FILE ::
"c:\windows\system32\XDva020.sys"
"c:\windows\system32\XDva190.sys"
"c:\windows\system32\XDva284.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Kenny\Application Data\Azureus
c:\documents and settings\Kenny\Application Data\Azureus\.certs
c:\documents and settings\Kenny\Application Data\Azureus\.keystore
c:\documents and settings\Kenny\Application Data\Azureus\.lock
c:\documents and settings\Kenny\Application Data\Azureus\active\0A1D7859B41801E2BB52E5EF0D9B480AF14B284B.dat
c:\documents and settings\Kenny\Application Data\Azureus\active\0A1D7859B41801E2BB52E5EF0D9B480AF14B284B.dat.bak
c:\documents and settings\Kenny\Application Data\Azureus\active\B35E908CEB8EE4B0B2C21F80F40A579D0BE84C8C.dat
c:\documents and settings\Kenny\Application Data\Azureus\active\B35E908CEB8EE4B0B2C21F80F40A579D0BE84C8C.dat.bak
c:\documents and settings\Kenny\Application Data\Azureus\active\C92F053540E94E690F6D4A057916C7BFA293F65C.dat
c:\documents and settings\Kenny\Application Data\Azureus\active\C92F053540E94E690F6D4A057916C7BFA293F65C.dat.bak
c:\documents and settings\Kenny\Application Data\Azureus\active\cache.dat
c:\documents and settings\Kenny\Application Data\Azureus\azureus.config
c:\documents and settings\Kenny\Application Data\Azureus\azureus.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\azureus.statistics
c:\documents and settings\Kenny\Application Data\Azureus\azureus.statistics.bak
c:\documents and settings\Kenny\Application Data\Azureus\banips.config
c:\documents and settings\Kenny\Application Data\Azureus\banips.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\cnetworks.config
c:\documents and settings\Kenny\Application Data\Azureus\devices.config
c:\documents and settings\Kenny\Application Data\Azureus\devices.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\Kenny\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\Kenny\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\Kenny\Application Data\Azureus\dht\general.dat
c:\documents and settings\Kenny\Application Data\Azureus\dht\version.dat
c:\documents and settings\Kenny\Application Data\Azureus\downloads.config
c:\documents and settings\Kenny\Application Data\Azureus\downloads.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\filters.config
c:\documents and settings\Kenny\Application Data\Azureus\friends.config
c:\documents and settings\Kenny\Application Data\Azureus\friends.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\ipfilter.cache
c:\documents and settings\Kenny\Application Data\Azureus\logs\alerts_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\clientid_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\CNetworks_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\debug_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\debug_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\Devices_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\Friends_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\Friends_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\MetaSearch_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\NetStatus_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_alerts_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_AutoSpeedSearchHistory_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_clientid_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_CNetworks_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_debug_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_debug_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_Devices_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_Friends_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_Friends_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_MetaSearch_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_NetStatus_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_seltrace_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_seltrace_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_Subscriptions_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_thread_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_thread_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_v3.ads_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_v3.CMsgr_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_v3.Friends_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_v3.Friends_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_v3.PMsgr_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\save\1254528677632_v3.Stream_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\seltrace_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\seltrace_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\Subscriptions_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\thread_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\thread_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\v3.ads_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\v3.CMsgr_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\v3.Friends_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\v3.Friends_2.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\v3.PMsgr_1.log
c:\documents and settings\Kenny\Application Data\Azureus\logs\v3.Stream_1.log
c:\documents and settings\Kenny\Application Data\Azureus\metasearch.config
c:\documents and settings\Kenny\Application Data\Azureus\metasearch.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\net\pm_20115.dat
c:\documents and settings\Kenny\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.2.jar
c:\documents and settings\Kenny\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.2.zip
c:\documents and settings\Kenny\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.5.jar
c:\documents and settings\Kenny\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.5.zip
c:\documents and settings\Kenny\Application Data\Azureus\plugins\azupnpav\plugin.properties
c:\documents and settings\Kenny\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.2
c:\documents and settings\Kenny\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.5
c:\documents and settings\Kenny\Application Data\Azureus\sidebarauto.config
c:\documents and settings\Kenny\Application Data\Azureus\sidebarauto.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\subs\5F78AD8919FF8EA67371.vuze
c:\documents and settings\Kenny\Application Data\Azureus\subs\737553100CB057ACF094.vuze
c:\documents and settings\Kenny\Application Data\Azureus\subscriptions.config
c:\documents and settings\Kenny\Application Data\Azureus\subscriptions.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\tables.config
c:\documents and settings\Kenny\Application Data\Azureus\tables.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU3083676961748198112.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU4916250783419002826.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU6062180317684674421.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU6328486312790936435.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU662012742328735406.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU7501812493614811214.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU8195130111966532817.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU8561358674092229342.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU8662842378364569823.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU8813651221908715772.tmp
c:\documents and settings\Kenny\Application Data\Azureus\tmp\AZU9209065809145152125.tmp
c:\documents and settings\Kenny\Application Data\Azureus\torrents\((Demonoid.com))-Star_Wars_DOS_Game_Collection.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\[HentaiShare].Schoolmate.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\3D_Sexvilla_2_058_002_oxin_s_style__OxS_.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\anox_disc1.iso.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\anox_disc2.iso.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\AZU2647917505123295463.tmp
c:\documents and settings\Kenny\Application Data\Azureus\torrents\AZU3988.tmp
c:\documents and settings\Kenny\Application Data\Azureus\torrents\AZU3992.tmp
c:\documents and settings\Kenny\Application Data\Azureus\torrents\AZU8770666781420321312.tmp
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Beastiality.Vids.2[1].torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Beastiality.Vids.5[1].torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Dr. Comet's Kemono Island.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\DR_COMET_HIS_ENTIRE_WORKS.3737323.TPB.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Dr_Comet_Kemono_Islands_Cd_7.4225719.TPB.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\FxA_Pleasure_Bon_Bon_2.3522405.TPB.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Hentai-manga_Colorful_Princess_by_Youji_Sorimura_Hot_Milk_Comics[www.btmon.com].torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Hentai picture compulation [www.Fulldls.com].torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\HentaII-3D-2-v2.052.003.3973183.TPB.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Hyphen-man____s_Furry_folder_MKII.3829441.TPB.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Naruto Hentai Comix [www.Fulldls.com].torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Pretty_soldier_wars_AD_2048_[PC-CD]_[English]_.3793070.TPB.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Star_Wars_Flight-Sim_Gems(X-Wing_TIE-Fighter__XWA_.3526002.TPB.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Teenie.with.the.Big.Dog.MVCD.by.Batista.(Animalsex.Beastiality)..3455321.TPB[1].torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\Tom.Clancys.Rainbow.Six.Vegas.2-RELOADED.4125708.TPB.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\XChange_3.4715415.TPB.torrent
c:\documents and settings\Kenny\Application Data\Azureus\torrents\XXX.[beastiality].European.Woman.Gets.Dog.To.Fuck.Her.&.Lick.Pussy[1].torrent
c:\documents and settings\Kenny\Application Data\Azureus\tracker.config
c:\documents and settings\Kenny\Application Data\Azureus\tracker.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\unsentdata.config
c:\documents and settings\Kenny\Application Data\Azureus\unsentdata.config.bak
c:\documents and settings\Kenny\Application Data\Azureus\update.log
c:\documents and settings\Kenny\Application Data\Azureus\update.properties
c:\documents and settings\Kenny\Application Data\Azureus\v3.Friends.dat
c:\documents and settings\Kenny\Application Data\Azureus\v3.Friends.dat.bak
c:\documents and settings\Kenny\Application Data\Azureus\VuzeActivities.config
c:\documents and settings\Kenny\Application Data\Azureus\VuzeActivities.config.bak
c:\program files\IObit
c:\program files\IObit\Game Booster\EULA.rtf
c:\program files\IObit\Game Booster\GameBooster.exe
c:\program files\IObit\Game Booster\GameBooster.ini
c:\program files\IObit\Game Booster\gbinit.exe
c:\program files\IObit\Game Booster\gbtray.exe
c:\program files\IObit\Game Booster\Language\Arabic.lng
c:\program files\IObit\Game Booster\Language\Belarusian.lng
c:\program files\IObit\Game Booster\Language\Brasil.lng
c:\program files\IObit\Game Booster\Language\Catalan.lng
c:\program files\IObit\Game Booster\Language\ChineseSimp.lng
c:\program files\IObit\Game Booster\Language\ChineseTrad.lng
c:\program files\IObit\Game Booster\Language\Croatian.lng
c:\program files\IObit\Game Booster\Language\Czech.lng
c:\program files\IObit\Game Booster\Language\Dansk.lng
c:\program files\IObit\Game Booster\Language\Dutch.lng
c:\program files\IObit\Game Booster\Language\English.lng
c:\program files\IObit\Game Booster\Language\Estonian.lng
c:\program files\IObit\Game Booster\Language\Finnish.lng
c:\program files\IObit\Game Booster\Language\French.lng
c:\program files\IObit\Game Booster\Language\Georgian.lng
c:\program files\IObit\Game Booster\Language\German.lng
c:\program files\IObit\Game Booster\Language\Greek.lng
c:\program files\IObit\Game Booster\Language\Hebrew.lng
c:\program files\IObit\Game Booster\Language\Hungarian.lng
c:\program files\IObit\Game Booster\Language\Indonesian.lng
c:\program files\IObit\Game Booster\Language\Italiano.lng
c:\program files\IObit\Game Booster\Language\Japanese.lng
c:\program files\IObit\Game Booster\Language\Korean.lng
c:\program files\IObit\Game Booster\Language\Lithuanian.lng
c:\program files\IObit\Game Booster\Language\Norwegian.lng
c:\program files\IObit\Game Booster\Language\Persian.lng
c:\program files\IObit\Game Booster\Language\Polish.lng
c:\program files\IObit\Game Booster\Language\Portugal.lng
c:\program files\IObit\Game Booster\Language\Romanian.lng
c:\program files\IObit\Game Booster\Language\Russian.lng
c:\program files\IObit\Game Booster\Language\Slovak.lng
c:\program files\IObit\Game Booster\Language\Spanish.lng
c:\program files\IObit\Game Booster\Language\Swedish.lng
c:\program files\IObit\Game Booster\Language\Turkish.lng
c:\program files\IObit\Game Booster\Language\Ukrainian.lng
c:\program files\IObit\Game Booster\Language\Urdu.lng
c:\program files\IObit\Game Booster\Language\Vietnamese.lng
c:\program files\IObit\Game Booster\unins000.dat
c:\program files\IObit\Game Booster\unins000.exe
c:\program files\IObit\Game Booster\What's new.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_XDVA020
-------\Legacy_XDVA190
-------\Legacy_XDVA284
-------\Service_XDva020
-------\Service_XDva190
-------\Service_XDva284
((((((((((((((((((((((((( Files Created from 2009-10-20 to 2009-11-20 )))))))))))))))))))))))))))))))
.
2009-11-20 08:04 . 2006-07-06 12:59 246784 ----a-w- c:\windows\system32\drivers\iaStor.sys
2009-11-16 12:11 . 2009-11-16 12:11 -------- d-----w- C:\found.003
2009-11-13 16:35 . 2009-11-13 16:35 -------- d-----w- c:\program files\ERUNT
2009-11-12 07:36 . 2009-11-17 18:16 -------- d-----w- c:\program files\Bethesda Softworks
2009-11-10 02:21 . 2009-11-10 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2009-11-10 01:25 . 2009-09-04 22:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-11-10 01:25 . 2009-09-04 22:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-11-10 01:25 . 2009-09-04 22:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-11-10 01:25 . 2009-09-04 22:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-11-10 01:25 . 2009-09-04 22:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-11-10 01:25 . 2009-09-04 22:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-11-10 01:25 . 2009-09-04 22:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-11-10 00:50 . 2008-05-30 19:19 507400 ----a-w- c:\windows\system32\XAudio2_1.dll
2009-11-10 00:50 . 2008-05-30 19:17 65032 ----a-w- c:\windows\system32\XAPOFX1_0.dll
2009-11-10 00:50 . 2008-05-30 19:18 238088 ----a-w- c:\windows\system32\xactengine3_1.dll
2009-11-10 00:50 . 2008-05-30 19:17 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll
2009-11-10 00:50 . 2008-05-30 19:11 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2009-11-10 00:50 . 2008-05-30 19:11 1491992 ----a-w- c:\windows\system32\D3DCompiler_38.dll
2009-11-10 00:50 . 2008-05-30 19:11 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll
2009-11-10 00:50 . 2008-03-05 21:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2009-11-10 00:50 . 2008-03-05 21:03 238088 ----a-w- c:\windows\system32\xactengine3_0.dll
2009-11-10 00:50 . 2008-03-05 21:00 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll
2009-11-10 00:45 . 2008-03-05 20:56 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2009-11-10 00:45 . 2008-02-06 04:07 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2009-11-10 00:45 . 2008-03-05 20:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2009-11-10 00:44 . 2009-11-10 00:44 -------- d-----w- c:\windows\system32\xlive
2009-11-10 00:44 . 2009-11-10 00:45 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-11-09 01:39 . 2009-11-09 01:39 -------- d-----w- C:\GamepotUSA
2009-11-08 20:11 . 2009-11-08 20:11 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-11-08 09:35 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\9c13920.dll
2009-11-08 09:35 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\17d08eb5.dll
2009-11-08 09:25 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\b533e7b.dll
2009-11-08 09:25 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\a3cb000.dll
2009-11-07 00:36 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\dd9c188.dll
2009-11-07 00:34 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\6b49aca.dll
2009-11-07 00:34 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\3920f5f4.dll
2009-11-06 13:14 . 2009-10-21 13:09 2064152 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-11-06 02:14 . 2009-11-06 02:14 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-11-04 22:31 . 2009-11-05 00:50 -------- d-----w- c:\program files\Silkroad
2009-11-04 18:38 . 2009-09-23 14:41 26176 ---ha-w- c:\windows\system32\hamachi.sys
2009-11-04 00:31 . 2009-11-04 00:31 -------- d-----w- c:\documents and settings\Kenny\Application Data\NeopleLauncherDFO
2009-10-22 02:34 . 2009-10-22 02:34 -------- d-----w- c:\documents and settings\Kenny\Local Settings\Application Data\Ironclad Games
2009-10-22 02:29 . 2009-10-22 02:38 -------- d-----w- c:\documents and settings\Kenny\Application Data\Stardock
2009-10-22 02:28 . 2009-10-22 02:28 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{6F7EF3E6-7F1B-4824-84CD-E8DF6F1B4168}
2009-10-22 02:28 . 2009-06-04 20:05 2606568 -c--a-w- c:\documents and settings\All Users\Application Data\{6F7EF3E6-7F1B-4824-84CD-E8DF6F1B4168}\Impulse_setup.exe
2009-10-22 02:27 . 2009-10-22 02:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Stardock
2009-10-22 02:26 . 2009-11-09 01:27 -------- dc-h--w- c:\documents and settings\Kenny\Local Settings\Application Data\~0
2009-10-22 02:22 . 2009-10-22 02:22 -------- d-----w- c:\documents and settings\Kenny\Local Settings\Application Data\PackageAware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-20 02:04 . 2007-11-24 02:33 100880 -c--a-w- c:\documents and settings\Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-20 01:36 . 2009-06-18 14:32 -------- d-----w- c:\program files\X-Change 3
2009-11-20 01:36 . 2007-04-23 12:18 -------- d-----w- c:\program files\xc2
2009-11-20 01:33 . 2007-02-04 04:31 737280 -c--a-w- c:\windows\iun6002.exe
2009-11-19 06:28 . 2008-12-10 09:34 -------- d-----w- c:\documents and settings\Kenny\Application Data\Xfire
2009-11-18 07:07 . 2008-12-10 09:34 -------- d-----w- c:\program files\Xfire
2009-11-17 22:08 . 2007-02-03 23:26 -------- d-----w- c:\program files\EA GAMES
2009-11-17 18:13 . 2007-01-16 18:15 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-16 12:19 . 2008-09-30 05:22 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-11-14 03:02 . 2008-11-01 18:46 0 ----a-w- c:\documents and settings\Family\Local Settings\Application Data\prvlcl.dat
2009-11-13 17:52 . 2007-05-25 12:51 -------- d-----w- c:\program files\Winamp
2009-11-13 05:22 . 2007-06-21 12:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-12 08:19 . 2007-08-25 23:55 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-12 05:51 . 2007-01-28 03:20 -------- d-----w- c:\program files\LucasArts
2009-11-12 03:10 . 2009-08-20 10:57 -------- d-----w- c:\program files\World of Warcraft
2009-11-10 02:15 . 2007-01-16 18:16 -------- d-----w- c:\program files\ATI Technologies
2009-11-09 22:00 . 2009-09-17 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-11-09 21:59 . 2009-09-17 20:03 -------- d-----w- c:\program files\IGN
2009-11-09 21:59 . 2007-01-26 06:30 -------- d-----w- c:\documents and settings\Kenny\Application Data\IGN_DLM
2009-11-09 21:56 . 2007-01-16 18:20 -------- d-----w- c:\program files\Roxio
2009-11-09 21:56 . 2007-01-16 18:17 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-11-09 21:53 . 2007-11-24 02:33 -------- d--h--w- c:\documents and settings\Family\Application Data\Gtek
2009-11-09 21:53 . 2007-05-03 23:35 -------- d--h--w- c:\documents and settings\MCX1\Application Data\Gtek
2009-11-09 21:53 . 2007-01-18 04:05 -------- d--h--w- c:\documents and settings\Kenny\Application Data\Gtek
2009-11-09 21:53 . 2007-01-16 18:26 -------- d--h--w- c:\documents and settings\Administrator\Application Data\GTek
2009-11-09 21:53 . 2007-07-17 07:00 -------- d-----w- c:\program files\Doushin
2009-11-09 21:50 . 2007-01-16 18:19 -------- d-----w- c:\program files\Real
2009-11-09 21:50 . 2007-01-20 03:22 -------- d-----w- c:\program files\Rhapsody
2009-11-08 23:21 . 2007-03-25 16:57 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-04 00:11 . 2009-03-28 01:22 90112 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2009-11-04 00:11 . 2009-03-28 01:22 561152 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2009-11-04 00:11 . 2009-03-28 01:22 393216 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2009-11-04 00:11 . 2009-03-28 01:22 258352 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2009-11-04 00:11 . 2009-03-28 01:22 167936 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2009-11-04 00:11 . 2009-03-28 01:22 118784 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2009-11-03 23:42 . 2009-03-28 00:10 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2009-10-22 02:27 . 2007-07-03 01:51 -------- d-----w- c:\program files\Stardock
2009-10-18 13:09 . 2009-10-18 13:09 2025752 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-10-14 07:06 . 2007-01-16 18:25 -------- d-----w- c:\program files\Microsoft Works
2009-10-12 16:36 . 2009-08-22 15:46 -------- d-----w- c:\program files\Warcraft III
2009-10-05 19:32 . 2009-10-03 00:40 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-10-03 00:58 . 2009-10-03 00:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2009-10-03 00:57 . 2009-09-17 21:41 22328 ----a-w- c:\documents and settings\Kenny\Application Data\PnkBstrK.sys
2009-10-03 00:57 . 2009-09-17 21:41 22328 ----a-w- c:\documents and settings\Kenny\Application Data\PnkBstrK.sys
2009-10-03 00:57 . 2007-07-11 02:25 22328 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-03 00:57 . 2007-07-11 02:24 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-03 00:57 . 2009-09-17 21:40 2337865 ----a-w- c:\windows\system32\pbsvc.exe
2009-10-03 00:57 . 2007-07-11 02:24 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-10-03 00:42 . 2009-10-03 00:42 -------- d-----w- c:\program files\Ubisoft
2009-10-03 00:41 . 2008-12-29 04:17 -------- d-----w- c:\documents and settings\Kenny\Application Data\DAEMON Tools Lite
2009-10-03 00:40 . 2009-10-03 00:40 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-10-02 19:44 . 2008-01-08 06:13 -------- d-----w- c:\documents and settings\Kenny\Application Data\Free Download Manager
2009-10-02 19:15 . 2007-05-25 12:51 -------- d-----w- c:\documents and settings\Kenny\Application Data\Winamp
2009-10-01 13:58 . 2008-12-29 04:17 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-24 07:03 . 2009-09-24 07:03 -------- d-----w- c:\program files\Firaxis Games
2009-09-24 04:04 . 2009-09-24 03:50 -------- d-----w- c:\documents and settings\Kenny\Application Data\Ventrilo
2009-09-24 03:47 . 2009-09-24 03:47 -------- d-----w- c:\program files\Ventrilo
2009-09-24 03:46 . 2008-03-04 19:56 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-23 15:41 . 2009-09-23 15:41 26176 ---ha-w- c:\windows\system32\drivers\hamachi.sys
2009-09-23 04:25 . 2007-03-29 00:11 -------- d-----w- c:\program files\Electronic Arts
2009-09-11 14:18 . 2005-08-16 10:18 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 22:44 . 2009-11-10 00:51 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 21:03 . 2005-08-16 10:18 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-02 02:52 . 2008-04-02 05:02 98304 -c--a-w- c:\windows\system32CmdLineExt.dll
2009-08-29 07:36 . 2005-08-16 10:18 832512 ------w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2005-08-16 10:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2005-08-16 10:18 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2005-08-16 10:19 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-25 22:04 . 2009-08-25 22:04 75264 ----a-w- c:\windows\system32\uc_holybeast_launching.dll
2007-05-03 23:46 . 2007-02-05 10:13 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-11-20_08.15.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-20 21:38 . 2009-11-20 21:38 16384 c:\windows\Temp\Perflib_Perfdata_794.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 16:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"SetDefaultMIDI"="MIDIDef.exe" - c:\windows\MIDIDEF.EXE [2004-12-22 24576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-03 2028312]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-01-16 98304]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-21 61440]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-07-24 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 12:46 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Extender Resource Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk
backup=c:\windows\pss\Extender Resource Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Kenny^Start Menu^Programs^Startup^GameSpot Download Manager.lnk]
path=c:\documents and settings\Kenny\Start Menu\Programs\Startup\GameSpot Download Manager.lnk
backup=c:\windows\pss\GameSpot Download Manager.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Kenny^Start Menu^Programs^Startup^ImpulseNow.lnk]
path=c:\documents and settings\Kenny\Start Menu\Programs\Startup\ImpulseNow.lnk
backup=c:\windows\pss\ImpulseNow.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Kenny^Start Menu^Programs^Startup^Xfire.lnk]
path=c:\documents and settings\Kenny\Start Menu\Programs\Startup\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"idsvc"=3 (0x3)
"TapiSrv"=3 (0x3)
"Symantec Core LC"=2 (0x2)
"PnkBstrA"=2 (0x2)
"npkcmsvc"=2 (0x2)
"npggsvc"=3 (0x3)
"NMSAccessU"=2 (0x2)
"mnmsrvc"=3 (0x3)
"MDM"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"helpsvc"=2 (0x2)
"Fax"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"ERSvc"=2 (0x2)
"DNADownloader"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"PnkBstrB"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\PortableMudMaster\\MudMaster.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"17771:UDP"= 17771:UDP:Two Worlds
"58713:TCP"= 58713:TCP:Pando Media Booster
"58713:UDP"= 58713:UDP:Pando Media Booster
"59062:TCP"= 59062:TCP:Pando Media Booster
"59062:UDP"= 59062:UDP:Pando Media Booster
"58985:TCP"= 58985:TCP:Pando Media Booster
"58985:UDP"= 58985:UDP:Pando Media Booster
"58859:TCP"= 58859:TCP:Pando Media Booster
"58859:UDP"= 58859:UDP:Pando Media Booster
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/28/2008 11:17 PM 721904]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/30/2008 12:22 AM 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/30/2008 12:22 AM 297752]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;\??\c:\program files\VMLaunch\BuddyVM.sys --> c:\program files\VMLaunch\BuddyVM.sys [?]
S4 DNADownloader;DNADownloader;c:\program files\GameSpot\DownloadManager_Win32.exe --> c:\program files\GameSpot\DownloadManager_Win32.exe [?]
S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - CLASSPNP_2
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070116
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
DPF: {8C292180-8BB2-495F-B94B-89FE9F2B530A} - hxxp://rfonline-full.gscdn.com/gscdn/ccr_downloader.cab
FF - ProfilePath - c:\documents and settings\Kenny\Application Data\Mozilla\Firefox\Profiles\vgtyytk2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Kenny\Application Data\Mozilla\Firefox\Profiles\vgtyytk2.default\extensions\CSLauncher@cyberstep.com\plugins\npCsLauncher.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Game Booster_is1 - c:\program files\IObit\Game Booster\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-20 16:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spnt.sys hal.dll >>UNKNOWN [0x86F86938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf76b7f28
\Driver\ACPI -> ACPI.sys @ 0xf7431cb8
\Driver\iaStor -> iaStor.sys @ 0xf7356150
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Intel(R) 82566DC Gigabit Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf721dbb0
PacketIndicateHandler -> NDIS.sys @ 0xf720ca0d
SendHandler -> NDIS.sys @ 0xf7220b40
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
iaStor.sys @ 0x0 0x0 bytes
\Driver\iaStor [ IRP_MJ_CREATE ] 0x4FC2 != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_CLOSE ] 0x4FC2 != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_DEVICE_CONTROL ] 0x8CBE != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x8F80 != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_POWER ] 0xD884 != 0xF7356150 iaStor.sys
\Driver\iaStor [ IRP_MJ_SYSTEM_CONTROL ] 0xD9E4 != 0xF7356150 iaStor.sys
\Driver\iaStor IRP hooks detected !
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3167047611-3067674008-2036097901-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:4f,32,ca,1e,d7,09,58,34,85,74,41,5d,06,e9,73,3f,a5,b8,50,dd,35,b6,0e,
96,8b,e7,a1,30,79,81,08,bd,94,8c,d8,e9,4c,7d,03,58,03,ee,0b,42,8e,1a,e3,4e,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
[HKEY_USERS\S-1-5-21-3167047611-3067674008-2036097901-1006\Software\SecuROM\License information*]
"datasecu"=hex:3b,08,4c,83,8c,d2,5a,87,19,b1,11,4e,85,30,77,85,34,46,3a,d6,c7,
20,3a,ad,e3,30,3a,61,bc,7a,1b,af,8d,1e,b0,c9,19,a8,d2,0e,1f,9c,e5,26,00,29,\
"rkeysecu"=hex:2d,50,a1,70,eb,32,e2,36,42,75,89,3a,8a,db,d6,0c
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(4008)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\windows\ehome\RMSvc.exe
c:\windows\ehome\McrdSvc.exe
c:\program files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2009-11-20 16:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-20 21:53
ComboFix2.txt 2009-11-20 08:25
Pre-Run: 89,153,347,584 bytes free
Post-Run: 89,109,282,816 bytes free
- - End Of File - - 4093DBD6C7747FFD6117F666792FFEF1
And this is the new DDS log
DDS (Ver_09-10-26.01) - NTFSx86
Run by Kenny at 16:54:26.78 on Fri 11/20/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.536 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\WINDOWS\ehome\RMSvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Kenny\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070116
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [SetDefaultMIDI] MIDIDef.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8C292180-8BB2-495F-B94B-89FE9F2B530A} - hxxp://rfonline-full.gscdn.com/gscdn/ccr_downloader.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\kenny\applic~1\mozilla\firefox\profiles\vgtyytk2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\kenny\application data\mozilla\firefox\profiles\vgtyytk2.default\extensions\cslauncher@cyberstep.com\plugins\npCsLauncher.dll
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-9-30 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-9-30 297752]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;\??\c:\program files\vmlaunch\buddyvm.sys --> c:\program files\vmlaunch\BuddyVM.sys [?]
S4 DNADownloader;DNADownloader;c:\program files\gamespot\downloadmanager_win32.exe --> c:\program files\gamespot\DownloadManager_Win32.exe [?]
S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
=============== Created Last 30 ================
2009-11-20 08:04:43 246784 ----a-w- c:\windows\system32\drivers\iaStor.sys
2009-11-20 07:57:41 0 d-sha-r- C:\cmdcons
2009-11-20 07:46:08 98816 ----a-w- c:\windows\sed.exe
2009-11-20 07:46:08 77312 ----a-w- c:\windows\MBR.exe
2009-11-20 07:46:08 260608 ----a-w- c:\windows\PEV.exe
2009-11-20 07:46:08 161792 ----a-w- c:\windows\SWREG.exe
2009-11-16 12:11:12 0 d-----w- C:\found.003
2009-11-12 07:36:39 0 d-----w- c:\program files\Bethesda Softworks
2009-11-11 05:20:35 3252 ----a-w- c:\windows\system32\wbem\Outlook_01ca628eb28623c4.mof
2009-11-10 01:25:36 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-11-10 01:25:33 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-11-10 01:25:33 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-11-10 01:25:32 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-11-10 01:25:31 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-11-10 01:25:31 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-11-10 01:25:30 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2009-11-10 00:50:52 65032 ----a-w- c:\windows\system32\XAPOFX1_0.dll
2009-11-10 00:50:52 507400 ----a-w- c:\windows\system32\XAudio2_1.dll
2009-11-10 00:50:51 238088 ----a-w- c:\windows\system32\xactengine3_1.dll
2009-11-10 00:50:49 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll
2009-11-10 00:50:46 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2009-11-10 00:50:46 1491992 ----a-w- c:\windows\system32\D3DCompiler_38.dll
2009-11-10 00:50:43 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll
2009-11-10 00:50:41 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2009-11-10 00:50:39 238088 ----a-w- c:\windows\system32\xactengine3_0.dll
2009-11-10 00:50:38 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll
2009-11-10 00:45:23 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2009-11-10 00:45:23 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2009-11-10 00:45:21 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2009-11-10 00:44:37 0 d-----w- c:\windows\system32\xlive
2009-11-10 00:44:36 0 d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-11-09 01:39:34 0 d-----w- C:\GamepotUSA
2009-11-08 20:11:58 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-11-08 09:35:56 82432 ---h-tw- c:\windows\system32\9c13920.dll
2009-11-08 09:35:56 82432 ---h-tw- c:\windows\system32\17d08eb5.dll
2009-11-08 09:25:51 82432 ---h-tw- c:\windows\system32\b533e7b.dll
2009-11-08 09:25:51 82432 ---h-tw- c:\windows\system32\a3cb000.dll
2009-11-07 00:36:09 82432 ---h-tw- c:\windows\system32\dd9c188.dll
2009-11-07 00:34:53 82432 ---h-tw- c:\windows\system32\6b49aca.dll
2009-11-07 00:34:53 82432 ---h-tw- c:\windows\system32\3920f5f4.dll
2009-11-06 02:14:42 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-11-04 22:31:12 0 d-----w- c:\program files\Silkroad
2009-11-04 18:38:03 26176 ---ha-w- c:\windows\system32\hamachi.sys
2009-11-04 00:31:55 0 d-----w- c:\docume~1\kenny\applic~1\NeopleLauncherDFO
2009-10-22 02:29:41 0 d-----w- c:\docume~1\kenny\applic~1\Stardock
2009-10-22 02:28:08 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{6F7EF3E6-7F1B-4824-84CD-E8DF6F1B4168}
2009-10-22 02:27:30 0 d-----w- c:\docume~1\alluse~1\applic~1\Stardock
==================== Find3M ====================
2009-11-20 01:33:55 737280 -c--a-w- c:\windows\iun6002.exe
2009-10-21 04:08:54 3598336 ----a-w- c:\windows\system32\dllcache\mshtml.dll
2009-10-03 00:57:51 22328 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-03 00:57:51 22328 ----a-w- c:\docume~1\kenny\applic~1\PnkBstrK.sys
2009-10-03 00:57:41 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-03 00:57:24 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-10-03 00:57:24 2337865 ----a-w- c:\windows\system32\pbsvc.exe
2009-10-01 13:58:07 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-23 15:41:58 26176 ---ha-w- c:\windows\system32\drivers\hamachi.sys
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 14:18:39 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2009-09-04 22:44:40 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 21:03:36 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 21:03:36 58880 ------w- c:\windows\system32\dllcache\msasn1.dll
2009-09-02 02:52:57 98304 -c--a-w- c:\windows\system32CmdLineExt.dll
2009-08-28 10:28:59 70656 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe
2009-08-28 10:28:59 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-08-27 05:18:44 634648 ------w- c:\windows\system32\dllcache\iexplore.exe
2009-08-27 05:18:41 161792 ----a-w- c:\windows\system32\dllcache\ieakui.dll
2009-08-26 08:00:21 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-26 08:00:21 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-08-25 22:04:30 75264 ----a-w- c:\windows\system32\uc_holybeast_launching.dll
2007-05-03 23:46:05 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
2008-11-04 13:07:42 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008110420081105\index.dat
============= FINISH: 16:54:31.89 ===============
Do you need the attach.txt log again?