ComboFix 09-01-10.03 - Owner 2009-01-11 10:58:02.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.504.218 [GMT -8:00]
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix\Combo-Fix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\system32\pmnoPjGA.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\BitTorrent
c:\program files\BitTorrent\addrmap.dat
c:\program files\BitTorrent\credits-l10n.txt
c:\program files\BitTorrent\etc\gtk-2.0\gdk-pixbuf.loaders
c:\program files\BitTorrent\etc\gtk-2.0\gtkrc
c:\program files\BitTorrent\etc\pango\pango.aliases
c:\program files\BitTorrent\etc\pango\pango.modules
c:\program files\BitTorrent\plugin.inf
c:\program files\BitTorrent\share\locale\af\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\af\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\bg\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\bg\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\bg\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\ca\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\ca\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\ca\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\cs\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\cs\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\cs\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\da\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\da\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\da\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\de\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\de\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\de\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\el\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\el\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\el\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\es\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\es\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\es\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\fr\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\fr\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\fr\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\he\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\he\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\he\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\hu\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\hu\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\hu\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\is\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\is\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\is\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\it\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\it\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\it\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\ja\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\ja\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\ja\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\ko\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\ko\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\ko\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\nl\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\nl\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\nl\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\pl\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\pl\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\pl\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\pt\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\pt\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\pt\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\pt_BR\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\pt_BR\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\pt_BR\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\ro\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\ro\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\ro\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\ru\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\ru\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\ru\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\sk\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\sk\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\sk\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\sl\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\sl\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\sl\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\sv\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\sv\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\sv\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\tr\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\tr\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\tr\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\vi\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\vi\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\vi\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\zh_CN\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\zh_CN\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\zh_CN\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\locale\zh_TW\LC_MESSAGES\glib20.mo
c:\program files\BitTorrent\share\locale\zh_TW\LC_MESSAGES\gtk20-properties.mo
c:\program files\BitTorrent\share\locale\zh_TW\LC_MESSAGES\gtk20.mo
c:\program files\BitTorrent\share\themes\MS-Windows\gtk-2.0\gtkrc
c:\program files\Soulseek
c:\program files\Soulseek\attributes.cfg
c:\program files\Soulseek\attrstrings.cfg
c:\program files\Soulseek\autoaway.cfg
c:\program files\Soulseek\chatrooms.cfg
c:\program files\Soulseek\chatui.cfg
c:\program files\Soulseek\dlbans.cfg
c:\program files\Soulseek\extensions.cfg
c:\program files\Soulseek\hotlist.cfg
c:\program files\Soulseek\ignores.cfg
c:\program files\Soulseek\login.cfg
c:\program files\Soulseek\pchat.cfg
c:\program files\Soulseek\port.cfg
c:\program files\Soulseek\queue.cfg
c:\program files\Soulseek\queue2.cfg
c:\program files\Soulseek\rcmnd.cfg
c:\program files\Soulseek\save.cfg
c:\program files\Soulseek\search.cfg
c:\program files\Soulseek\shared.cfg
c:\program files\Soulseek\ticker.cfg
c:\program files\Soulseek\transfersview.cfg
c:\program files\Soulseek\ui.cfg
c:\program files\Soulseek\userinfo.cfg
c:\program files\Soulseek\usernotes.cfg
c:\program files\Soulseek\wishlist.cfg
c:\windows\system32\pmnoPjGA.dll
.
((((((((((((((((((((((((( Files Created from 2008-12-11 to 2009-01-11 )))))))))))))))))))))))))))))))
.
2009-01-10 10:55 . 2009-01-10 10:55 <DIR> d-------- c:\windows\Sun
2009-01-10 10:55 . 2009-01-10 10:54 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-10 10:55 . 2009-01-10 10:54 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-01-10 10:54 . 2009-01-10 10:54 <DIR> d-------- c:\program files\Java
2008-12-27 10:22 . 2008-12-27 10:22 <DIR> d-------- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 02:54 --------- d-----w c:\program files\Google
2009-01-02 19:40 --------- d-----w c:\documents and settings\Owner\Application Data\Roxio
2008-12-26 04:41 --------- d-----w c:\documents and settings\Owner\Application Data\ZoomBrowser EX
2008-12-26 01:04 --------- d-----w c:\documents and settings\Owner\Application Data\CameraWindowDC
2008-12-21 08:32 --------- d-----w c:\program files\Steinberg
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 22:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 22:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 22:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-13 14:06 7,670,000 ----a-w c:\documents and settings\Owner\QuickCareSetup2.exe
2006-03-20 00:36 6,715,392 -c----w c:\program files\WindowsDefender.msi
2008-12-19 04:35 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 04:35 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 04:35 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 04:35 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 04:35 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-07_19.54.47.78 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-10 18:54:59 144,792 ----a-w c:\windows\system32\java.exe
+ 2009-01-10 18:54:59 144,792 ----a-w c:\windows\system32\javaw.exe
+ 2009-01-10 18:54:59 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2009-01-11 18:06:57 16,384 ----atw c:\windows\temp\Perflib_Perfdata_764.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-29 68856]
"NVIEW"="nview.dll" [2003-05-02 c:\windows\system32\nview.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-10 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 02:50 40960 c:\program files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealOne Player\\realplay.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Softex\\OmniPass\\OPXPApp.exe"=
R4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-09-26 33752]
S4 mrtRate;mrtRate; [x]
.
Contents of the 'Scheduled Tasks' folder
2009-01-11 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2009-01-11 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.wikipedia.org/
uDefault_Search_URL = hxxp://srch-qus9.hpwis.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://qwest.live.com
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*
http://www.yahoo.com/search/ie.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/verizon/*
http://www.yahoo.com
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ggyf129n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ggyf129n.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\components\FoxyTunes.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-11 11:01:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,12,46,a7,aa,eb,
35,f7,2b,2e,e8,e1,00,eb,16,2b,de,48,bf,3c,2e,10,67,53,2f,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,33,b9,f4,32,ed,
2c,9a,fe,46,47,15,b0,92,4b,c7,ef,08,f8,e5,88,f6,42,ca,f2,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,25,9b,cf,88,9a,
81,9f,45,7a,45,05,fd,91,e8,6f,31,20,ce,91,d8,47,99,80,55,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,6f,42,ff,99,e5,
2b,2d,f6,6b,65,49,6a,7e,99,74,f7,32,56,af,a7,33,5c,ba,86,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,07,ec,41,f3,80,
14,62,0f,e9,02,6c,fa,fb,1d,47,57,c2,84,ec,d2,a2,bb,4e,e5,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,b2,a6,d1,20,83,
fc,4e,d3,50,93,e5,ab,ec,6a,4e,ab,49,d0,5f,c4,87,42,2c,66,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,f6,35,ab,9c,59,
4a,7f,02,97,20,4e,9a,c7,f1,35,ee,fb,62,56,df,f4,c3,87,8e,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,78,25,00,b2,44,
2c,00,ec,aa,52,c6,00,84,3c,26,64,d9,86,8f,fb,d5,57,56,13,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,52,a3,9e,81,7e,
0a,db,ec,b2,46,9a,e2,1b,fe,1b,94,2b,32,7e,df,29,cb,19,01,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,2b,71,95,7a,1d,
b8,43,93,37,a4,aa,c3,a6,15,56,0a,17,bf,a5,96,88,5c,df,76,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,e0,93,c9,0b,e6,
2c,f8,c1,f8,31,0f,a9,5f,a0,ec,fb,15,29,47,8f,57,6e,0e,71,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,81,b9,06,2f,11,
86,34,4e,05,73,21,dd,54,d8,4a,c5,49,7b,76,ce,1a,66,0e,fb,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(536)
c:\program files\Softex\OmniPass\opxpgina.dll
.
Completion time: 2009-01-11 11:04:39
ComboFix-quarantined-files.txt 2009-01-11 19:03:22
ComboFix2.txt 2009-01-11 18:47:50
ComboFix3.txt 2009-01-11 18:12:34
ComboFix4.txt 2009-01-08 03:57:09
Pre-Run: 12,903,497,728 bytes free
Post-Run: 12,889,538,560 bytes free
314 --- E O F --- 2009-01-10 18:15:49
----------------------------------------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 11:07:21 AM, on 1/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijack This\hijackthis\smothered.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-qus9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.wikipedia.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://qwest.live.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/verizon/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O9 - Extra button: Qwest Live - {67F01570-7AFE-471B-99B3-C2485A5FD637} -
http://qwest.live.com (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} -
https://www.windowsonecare.com/install/cli/1.0.0971.18/WinSSWebAgent.CAB
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) -
https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://scan.safety.live.com/resource/download/scanner/wlscbase5059.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138915993484
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138915962109
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) -
http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: SupportSoft RemoteAssist - Unknown owner - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe (file missing)