Combifix log
Here you go Peku006
ComboFix 09-11-27.05 - Mark 28/11/2009 10:13.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.767.410 [GMT 0:00]
Running from: c:\documents and settings\Mark\My Documents\Downloads\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mark\Application Data\wiaserva.log
c:\windows\cookies.ini
c:\windows\patch.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\InprocServer32.dll
c:\windows\system32\install.exe
c:\windows\system32\mcrh.tmp
c:\windows\system32\twain_32.dll
c:\windows\winhelp.ini
.
((((((((((((((((((((((((( Files Created from 2009-10-28 to 2009-11-28 )))))))))))))))))))))))))))))))
.
2009-11-06 07:38 . 2009-11-06 07:38 -------- d-----w- c:\program files\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-28 08:27 . 2004-11-29 08:46 -------- d-----w- c:\program files\Trend Micro
2009-11-28 08:02 . 2006-02-19 12:04 -------- d-----w- c:\documents and settings\Mark\Application Data\uTorrent
2009-11-27 09:25 . 2009-04-06 16:29 -------- d-----w- c:\documents and settings\Mark\Application Data\HPAppData
2009-11-08 12:27 . 2004-07-07 10:20 -------- d-----w- c:\program files\Azureus
2009-11-06 07:49 . 2004-07-07 10:33 -------- d-----w- c:\documents and settings\Mark\Application Data\Azureus
2009-10-25 18:23 . 2008-07-30 07:01 -------- d-----w- c:\documents and settings\Mark\Application Data\U3
2009-10-19 16:34 . 2002-09-16 22:48 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-14 17:08 . 2004-06-19 10:14 24 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000007-00001102-00000002-80221102}.dat
2009-10-14 17:08 . 2004-06-19 10:14 24 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000007-00001102-00000002-80221102}.dat
2009-10-09 07:25 . 2003-12-16 17:57 24064 ----a-w- c:\windows\system32\ctfmon.exe
2009-09-11 14:18 . 2001-08-18 06:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2001-08-18 06:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-02 11:16 . 2009-09-02 11:16 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\msxml6Exec.exe
2009-09-02 11:16 . 2009-09-02 11:16 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\Sleep.exe
2009-09-02 11:16 . 2009-09-02 11:16 3181612 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\Installer\CommonCustomActions\vcredistExec.exe
2009-09-02 11:15 . 2009-09-02 11:16 24501456 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{F983B4FE-547B-4C44-BAF7-4F4DBA93D548}\NokiaSoftwareUpdaterSetup_en.exe
2007-04-06 09:19 . 2005-02-11 08:10 129 -c--a-w- c:\program files\AutoUpdate.dat
2006-01-09 18:52 . 1602-07-12 21:55 1031 -csh--w- c:\windows\SYSTEM\ws32ntfg.dat
2002-04-16 10:27 . 2002-04-16 10:27 5 --sha-w- c:\windows\SYSTEM32\CdI5T.drv
.
------- Sigcheck -------
[-] 2009-10-09 07:25 . C3A2915C71AE6F225EB906C25CCD29B5 . 24064 . . [1.0.0.5] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2009-10-09 07:25 . C3A2915C71AE6F225EB906C25CCD29B5 . 24064 . . [1.0.0.5] . . c:\windows\SYSTEM32\ctfmon.exe
[7] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Google Update"="c:\documents and settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-13 133104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-08 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe " [X]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-04-09 2029640]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk.disabled [2009-7-16 1788]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=c:\windows\pss\SpySubtract.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Mark^Start Menu^Programs^Startup^BitTorrent.lnk]
path=c:\documents and settings\Mark\Start Menu\Programs\Startup\BitTorrent.lnk
backup=c:\windows\pss\BitTorrent.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"winvnc"=2 (0x2)
"TUWinStylerThemeSvc"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Fax"=2 (0x2)
"tmproxy"=2 (0x2)
"Tmntsrv"=2 (0x2)
"PcCtlCom"=2 (0x2)
"XWPCHostService"=3 (0x3)
"XWPCApplicationLoaderService"=3 (0x3)
"UPS"=3 (0x3)
"vsmon"=3 (0x3)
"WUSB54GSVC"=2 (0x2)
"iPod Service"=3 (0x3)
"HauppaugeTVServer"=3 (0x3)
"ose"=3 (0x3)
"LexBceS"=2 (0x2)
"gusvc"=3 (0x3)
"WMPNetworkSvc"=2 (0x2)
"WinDefend"=2 (0x2)
"usnjsvc"=3 (0x3)
"idsvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"WZCSVC"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AIM"=c:\progra~1\AIM\aim.exe -cnetwait.odl
"PlaxoUpdate"=c:\windows\Plaxo\2.13.1.6\PlaxoHelper.exe -a
"BIBLauncher"=c:\program files\Business-in-a-Box\BIBLauncher.exe
"TomTomHOME.exe"="i:\tomtom home 2\TomTomHOMERunner.exe"
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WINDVDPatch"=CTHELPER.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\ypager.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\SYSTEM32\\mmc.exe"=
"c:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_04\\bin\\javaw.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Asp Studio Professional\\AspStudio.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1:TCP"= 1:TCP:192.168.1.2/255.255.255.255,192.168.1.3/255.255.255.255,192.168.1.4/255.255.255.255:Enabled:Intranet
R1 ehdrv;ehdrv;c:\windows\SYSTEM32\DRIVERS\ehdrv.sys [06/02/2009 14:23 107256]
R1 epfwtdir;epfwtdir;c:\windows\SYSTEM32\DRIVERS\epfwtdir.sys [06/02/2009 14:24 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [09/04/2009 14:19 731840]
R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [01/03/2006 13:55 28672]
R2 TomTomHOMEService;TomTomHOMEService;i:\tomtom home 2\TomTomHOMEService.exe [03/06/2009 12:46 92008]
R3 Msikbd2k;DellTouch;c:\windows\SYSTEM32\DRIVERS\Msikbd2k.sys [01/03/2006 13:55 6942]
S2 gupdate1c9d22c28f3a07e;Google Update Service (gupdate1c9d22c28f3a07e);c:\program files\Google\Update\GoogleUpdate.exe [11/05/2009 11:32 133104]
S3 ADM8511;ADM8511 USB To Fast Ethernet Adapter;c:\windows\SYSTEM32\DRIVERS\ADM8511.SYS [15/10/2001 16:39 20160]
S3 ADM851X;ADM851X USB To Fast Ethernet Adapter;c:\windows\SYSTEM32\DRIVERS\ADM851X.SYS [27/10/2004 16:05 22144]
S3 cpuz132;cpuz132;c:\windows\SYSTEM32\DRIVERS\cpuz132_x32.sys [11/05/2009 07:46 12672]
S3 Hauppauge WinTV-HVR;Hauppauge WinTV-HVR 713X PCI Card;c:\windows\SYSTEM32\DRIVERS\HCW713x.sys [15/03/2007 19:40 968192]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\SYSTEM32\DRIVERS\nmwcdnsu.sys [02/09/2009 11:28 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\SYSTEM32\DRIVERS\nmwcdnsuc.sys [02/09/2009 11:28 8320]
S4 WUSB54GSVC;WUSB54GSVC;c:\program files\WUSB54G Wireless-G Adapter\WLService.exe [27/06/2005 08:15 41027]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
2009-11-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-11 11:32]
2009-11-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-11 11:32]
2009-11-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3918705649-2214429306-939620716-1006Core.job
- c:\documents and settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-13 15:00]
2009-11-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3918705649-2214429306-939620716-1006UA.job
- c:\documents and settings\Mark\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-13 15:00]
2009-11-28 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2003-03-16 15:31]
2009-11-28 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-06-30 15:31]
2009-11-28 c:\windows\Tasks\uTorrent.job
- c:\program files\uTorrent\uTorrent.exe [2009-11-06 07:39]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://news.google.co.uk/nwshp?hl=en&tab=wn
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*
http://www.yahoo.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {76FACBCF-8EF8-11D4-8A2C-005004425934} - hxxp://www.aol.co.uk/try/web_reg/aolcdt171.cab
DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} - hxxps://www.linkedin.com/cab/wabctrl.cab
FF - ProfilePath - c:\documents and settings\Mark\Application Data\Mozilla\Firefox\Profiles\mknm40dm.default\
FF - prefs.js: browser.startup.homepage - hxxp://news.google.co.uk/nwshp?hl=en&tab=wn
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJPI142_04.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPOJI610.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{2C7236A1-BC25-4E42-931E-7520E2330298} - (no file)
BHO-{548D1086-746E-47E7-8970-B8F114EC9A44} - (no file)
BHO-{79C1215A-0096-4868-98AF-18520E1A62FF} - (no file)
BHO-{7FF066E6-647B-44A1-8C8D-284BBF806ED0} - (no file)
BHO-{A100240C-7C83-4919-9308-40966A265893} - (no file)
BHO-{a370688d-679f-4292-9a5c-cbb03ab42137} - (no file)
BHO-{A8E55AF7-7108-46D2-BA08-D9785F49C074} - (no file)
BHO-{c75c7091-650b-4a25-8757-5c9a618e3f59} - (no file)
BHO-{CF612076-FAC1-43CB-A841-4154CE0C6DB9} - (no file)
BHO-{E9B8BEB2-9603-49BB-A258-6956BFBCE185} - (no file)
BHO-{F205651E-87AF-41D9-AF20-EC4056982A44} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SSODL-pntqkflv-{288374DD-E5C3-4D10-B471-13A9521FF94B} - (no file)
SSODL-qegbdmwf-{F7733EF1-8AD4-4F45-AA0F-B5100B2C6E58} - (no file)
SSODL-KbdSun-{c3dc4bec-921a-4d9f-aed9-f60335cfd314} - (no file)
Notify-tuvstqPJ - tuvstqPJ.dll
Notify-wlballoon - (no file)
AddRemove-NVIDIA Display Driver - c:\windows\System32\nvudisp.exe Uninstall
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-28 10:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x82CEF1E8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf758cf28
\Driver\ACPI -> ACPI.sys @ 0xf74d7cb8
\Driver\atapi -> atapi.sys @ 0xf748f852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7358bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7365a21
SendHandler -> NDIS.sys @ 0xf734387b
user & kernel MBR OK
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3918705649-2214429306-939620716-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(316)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\program files\SmartFTP Client 2.0\smarthook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\ESET\ESET NOD32 Antivirus\shellExt.dll
c:\progra~1\WINZIP\WZSHLSTB.DLL
c:\program files\WinRAR\rarext.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\progra~1\SPYBOT~1\SDHelper.dll
c:\program files\Haali\MatroskaSplitter\mmfinfo.dll
c:\program files\Haali\MatroskaSplitter\mkunicode.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\devldr32.exe
c:\windows\System32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\documents and settings\Mark\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\System32\tcpsvcs.exe
c:\windows\System32\MsPMSPSv.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\documents and settings\Mark\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\Mark\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\Mark\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
**************************************************************************
.
Completion time: 2009-11-28 10:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-28 10:45
Pre-Run: 9,521,795,072 bytes free
Post-Run: 9,389,367,296 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 60D2AF340BF54D54CFAC98BD0F6C3993