ComboFix 09-01-08.05 - Nick 2009-01-10 8:59:09.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.412 [GMT -5:00]
Running from: c:\documents and settings\Nick\My Documents\downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Nick\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\Tasks\µTorrent.job
c:\windows\Tasks\gkevxuwo.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Nick\Application Data\uTorrent
c:\documents and settings\Nick\Application Data\uTorrent\??@wu.ha.free.fr@Private Gold 81 Porn Wars.torrent
c:\documents and settings\Nick\Application Data\uTorrent\[Movie Pack] Whorecraft - Episodes 1-6.torrent
c:\documents and settings\Nick\Application Data\uTorrent\2cstjaclyncasegiannalynn_large.mpg.torrent
c:\documents and settings\Nick\Application Data\uTorrent\789-PBUSA-0708.rar.torrent
c:\documents and settings\Nick\Application Data\uTorrent\AA282FullInstaller_BitTorrent.exe.torrent
c:\documents and settings\Nick\Application Data\uTorrent\addkellykline_large.mpg.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Airbourne.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Angels and Airwaves - We Don t Need to Whisper.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Assassins.Creed.REPACK-RELOADED.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Baby Got Boobs - JACLYN CASE.zip.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Baby Got Boobs - Slackin on the Job - Kylee Strutt.torrent
c:\documents and settings\Nick\Application Data\uTorrent\bbw4595500k.wmv.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Call.Of.Duty.World.At.War-RELOADED.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Chevelle.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Code.Monkeys.S02E06.DSR.XViD-SYS.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Code.Monkeys.S02E07.DSR.XviD-TuBES.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Counter-Strike Source FULL [October 15 2007] DiGiTALZonE.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Crissy.Moran.Ultra.Pack.1.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Crissy.Moran.Ultra.Pack.2.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Crissy.Moran.Ultra.Pack.torrent
c:\documents and settings\Nick\Application Data\uTorrent\CSI Las Vegas [9x03] (XviD asd) EnglishV+NapisyPL -
www.tvshows.yoyo.pl.torrent
c:\documents and settings\Nick\Application Data\uTorrent\dht.dat
c:\documents and settings\Nick\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Nick\Application Data\uTorrent\Doctor Adventures - Deja Vu... - Kylee Strutt.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Eureka.S01.DVDRip.XviD-TOPAZ.1.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Eureka.S01.DVDRip.XviD-TOPAZ.2.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Eureka.S01.DVDRip.XviD-TOPAZ.3.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Eureka.S01.DVDRip.XviD-TOPAZ.4.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Eureka.S01.DVDRip.XviD-TOPAZ.5.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Eureka.S01.DVDRip.XviD-TOPAZ.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Eve.Lawrence.XeDiOuS.RIp.torrent
c:\documents and settings\Nick\Application Data\uTorrent\eve.mpg.torrent
c:\documents and settings\Nick\Application Data\uTorrent\ftnaadriannaangelina_2k.wmv.torrent
c:\documents and settings\Nick\Application Data\uTorrent\ftnacourtneysimpson_512k.wmv.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Greg The Bunny.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Hanna Hilton - Fucking the Instructor.wmv.1.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Hanna Hilton - Fucking the Instructor.wmv.2.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Hanna Hilton - Fucking the Instructor.wmv.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Heroes.S03E01.720p.HDTV.X264-DIMENSION [
www.btarena.org].torrent
c:\documents and settings\Nick\Application Data\uTorrent\HIMYM.torrent
c:\documents and settings\Nick\Application Data\uTorrent\How I Met Your Mother (Complete).torrent
c:\documents and settings\Nick\Application Data\uTorrent\Human.Body.Pushing.the.Limits.E01.Strength.HDTV.XviD-FQM.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Human.Body.Pushing.the.Limits.E02.Sight.HDTV.XviD-FQM.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Jana Cova in Blue[2CDs][Dvd-Rip][
www.zonatorrent.com].1.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Jana Cova in Blue[2CDs][Dvd-Rip][
www.zonatorrent.com].torrent
c:\documents and settings\Nick\Application Data\uTorrent\Juno Soundtrack.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Kiki - Amateur Allure by Mr.Mxl.avi.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Kiki Vidis Minipack.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Kiki Vidis_AshlynnAndFriends06.wmv.torrent
c:\documents and settings\Nick\Application Data\uTorrent\languages.1.torrent
c:\documents and settings\Nick\Application Data\uTorrent\languages.2.torrent
c:\documents and settings\Nick\Application Data\uTorrent\languages.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Marvel Trading Card Game [MULTI5][EUR][PSP][
www.topetorrent.com].torrent
c:\documents and settings\Nick\Application Data\uTorrent\Marvel Ultimate Alliance [PCDVD][Multi4][
www.newpct.com].torrent
c:\documents and settings\Nick\Application Data\uTorrent\My Sister's Hot Friend - Courtney James.wmv.torrent
c:\documents and settings\Nick\Application Data\uTorrent\N64.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Naked News Eps. #114.divx.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Naked.News.TV.Ep.100.PPV.DSRip.XviD-aAF.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Natural Sleeping Aid Collection.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Nero Ultra 6.6.1.15a + Keygen + Audio Plugins.rar.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Papa_Roach-The_Paramour_Sessions-2006-RNS.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Penny.Arcade.Adventures.On.the.Rain-Slick.Precipice.of.Darkness.Episode.1.v1.0.BUGFIX.REPACK-TE.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Pirates (XXX) (2005).avi.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Playboy - February 2008.pdf.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Playboy Magazine March 2008 25 Sexiest Celebrities Starring The Girls Next Door.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Playboy.2008.January.HD.rar.1.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Playboy.2008.January.HD.rar.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Puddle Of Mudd - 2007 - Famous.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Queens of the Stone Age.torrent
c:\documents and settings\Nick\Application Data\uTorrent\RavenRiley.Fresh.Out.Of.The.Shower.Time.To.Get.Dirty.XXX.DivX-Pr0nDoNORS.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Reaper.torrent
c:\documents and settings\Nick\Application Data\uTorrent\resume.dat
c:\documents and settings\Nick\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Nick\Application Data\uTorrent\Rosetta Stone 27 Languages [h33t PC MAC].torrent
c:\documents and settings\Nick\Application Data\uTorrent\Rosetta Stone Ultimate Language Disk v2.iso.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Rosetta Stone V3 - German.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Rosetta Stone V3 - Spanish (Latin America).torrent
c:\documents and settings\Nick\Application Data\uTorrent\RS.3.0.57.UPDATE.exe.torrent
c:\documents and settings\Nick\Application Data\uTorrent\rss.dat
c:\documents and settings\Nick\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Nick\Application Data\uTorrent\Salesgirl Raped - T.Patrick.mpeg.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Seether-Finding_Beauty_In_Negative_Spaces-2007-MTD.torrent
c:\documents and settings\Nick\Application Data\uTorrent\settings.dat
c:\documents and settings\Nick\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Nick\Application Data\uTorrent\Shay Laren - Love at First Squeeze.wmv.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Shay Laren Shower.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Shogun Total War Gold Edition-Evocation8.torrent
c:\documents and settings\Nick\Application Data\uTorrent\South Park Complete Seasons 1-10.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Team iDemise Alliance Leveling Guide.rar.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Teradise.Island[Tera.Patrick]XXX.DVDRiP.XviD.torrent
c:\documents and settings\Nick\Application Data\uTorrent\The Rosetta Stone German 1 & 2.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Tia Tanaka - Young Asian Cuties 4.avi.torrent
c:\documents and settings\Nick\Application Data\uTorrent\top_setup_1.36.20071016.exe.torrent
c:\documents and settings\Nick\Application Data\uTorrent\utorrent.lng
c:\documents and settings\Nick\Application Data\uTorrent\Wolverine and the X-Men - 11 - Past Directions [A-T].avi.torrent
c:\documents and settings\Nick\Application Data\uTorrent\Wolverine_and_the_X-Men_-_12_-_eXcessive_Force_[A-T].avi.torrent
c:\documents and settings\Nick\Application Data\uTorrent\X-men Evolution.torrent
c:\program files\uTorrent
c:\program files\uTorrent\uTorrent.exe
c:\windows\Tasks\µTorrent.job
c:\windows\Tasks\gkevxuwo.job
.
((((((((((((((((((((((((( Files Created from 2008-12-10 to 2009-01-10 )))))))))))))))))))))))))))))))
.
2009-01-09 05:11 . 2009-01-09 05:11 <DIR> d-------- C:\rsit
2008-12-27 00:05 . 2008-12-30 00:14 <DIR> d-------- c:\program files\PokerStars
2008-12-19 08:21 . 2008-12-19 08:21 319 --a------ c:\windows\game.ini
2008-12-16 12:08 . 2008-12-16 12:08 <DIR> d--h----- c:\windows\PIF
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-22 05:55 --------- d-----w c:\program files\Symantec AntiVirus
2008-12-20 17:56 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-20 14:27 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-19 13:21 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-19 13:10 --------- d-----w c:\program files\Activision
2008-12-19 06:04 --------- d-----w c:\program files\CDisplay
2008-12-10 08:07 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-10 03:22 --------- d-----w c:\documents and settings\All Users\Application Data\Rosetta Stone
2008-12-01 04:27 --------- d-----w c:\program files\World of Warcraft
2008-11-15 02:35 --------- d-----w c:\program files\Warner Bros. Interactive Entertainment
2008-10-27 15:04 70,992 ----a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 15:04 514,384 ----a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 15:04 235,856 ----a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 15:04 23,376 ----a-w c:\windows\system32\X3DAudio1_5.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-10 09:52 452,440 ----a-w c:\windows\system32\d3dx10_40.dll
2008-10-10 09:52 4,379,984 ----a-w c:\windows\system32\D3DX9_40.dll
2008-10-10 09:52 2,036,576 ----a-w c:\windows\system32\D3DCompiler_40.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-22_11.13.41.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-17 07:08:40 3,593,216 -c----w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
- 2008-10-17 07:08:40 3,593,216 -c--a-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 -c--a-w c:\windows\system32\dllcache\mshtml.dll
- 2007-04-10 18:00:46 236,928 -c----w c:\windows\system32\dllcache\WgaLogon.dll
+ 2008-09-06 04:30:42 241,704 -c----w c:\windows\system32\dllcache\wgaLogon.dll
- 2007-04-10 18:01:18 336,768 -c----w c:\windows\system32\dllcache\WgaTray.exe
+ 2008-09-06 04:29:58 917,032 -c----w c:\windows\system32\dllcache\WgaTray.exe
- 2007-04-24 15:32:06 1,485,696 ----a-w c:\windows\system32\LegitCheckControl.dll
+ 2008-09-06 04:30:06 1,480,232 ----a-w c:\windows\system32\LegitCheckControl.dll
- 2008-10-17 07:08:40 3,593,216 ----a-w c:\windows\system32\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll
- 2007-04-10 18:00:46 236,928 ----a-w c:\windows\system32\WgaLogon.dll
+ 2008-09-06 04:30:42 241,704 ----a-w c:\windows\system32\WgaLogon.dll
- 2007-04-10 18:01:18 336,768 ----a-w c:\windows\system32\WgaTray.exe
+ 2008-09-06 04:29:58 917,032 ----a-w c:\windows\system32\WgaTray.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-22 167368]
"Uniblue SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe" [2007-12-07 9479448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-06-28 8466432]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-03-14 125632]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
c:\documents and settings\Nick\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-06-28 23:43 81920 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-06-28 23:43 1626112 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\MidTen Media\\Comic Collector Live\\CCL.exe"=
R0 Copystar;Copystar;c:\windows\system32\drivers\copystar.sys [2002-06-01 82400]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-05 99376]
R4 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\
000.fcl [2008-02-01 16:24:04 41456]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-03-14 116416]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1ff6e4fd-731f-11dd-be0a-00095be1bf34}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-01-10 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2008-12-26 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-12-07 08:42]
2008-07-29 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-12-07 08:42]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = about:blank
Trusted Zone: *.antimalwareguard.com
Trusted Zone: *.antispyexpert.com
Trusted Zone: *.avsystemcare.com
Trusted Zone: *.gomyhit.com
Trusted Zone: *.imagesrvr.com
Trusted Zone: *.onerateld.com
Trusted Zone: *.safetydownload.com
Trusted Zone: *.spyguardpro.com
Trusted Zone: *.storageguardsoft.com
Trusted Zone: *.trustedantivirus.com
Trusted Zone: *.virusremover2008.com
Trusted Zone: *.virusschlacht.com
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\szs0xjxw.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1541204&SearchSource=3&q=
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=1k96igf4806cy<mpl=default<mplcache=2
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-10 09:00:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\
000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1957994488-1993962763-839522115-1003\Software\SecuROM\License information*NULL*]
"datasecu"=hex:32,99,c4,f1,c0,bb,26,9d,7b,68,b5,bf,45,ff,5f,d9,f6,e6,c4,2f,2e,
79,1b,91,a6,24,f2,de,7d,83,2d,09,db,71,d9,7f,0c,8e,b7,0a,b9,e5,35,d5,9a,7c,\
"rkeysecu"=hex:5b,c1,5b,1b,5c,87,ed,fb,40,8e,02,80,a3,d1,37,27
[HKEY_LOCAL_MACHINE\System\MountedDevices]
@Denied: (Read) (Administrators)
"\\??\\Volume{218f0dc7-4bef-11dc-8d20-806d6172696f}"=hex:00,00,00,48,00,7e,00,
00,00,00,00,00
"\\DosDevices\\C:"=hex:00,00,00,48,00,7e,00,00,00,00,00,00
"\\??\\Volume{c81205c2-4bf4-11dc-bd7f-806d6172696f}"=hex:5c,00,3f,00,3f,00,5c,
00,49,00,44,00,45,00,23,00,43,00,64,00,52,00,6f,00,6d,00,50,00,42,00,44,00,\
"\\DosDevices\\D:"=hex:5c,00,3f,00,3f,00,5c,00,49,00,44,00,45,00,23,00,43,00,
64,00,52,00,6f,00,6d,00,50,00,42,00,44,00,53,00,5f,00,43,00,44,00,52,00,57,\
"\\??\\Volume{2b82b2cc-4dae-11dc-bd83-aab7c12f5868}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\DosDevices\\E:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,43,00,6f,00,70,\
"\\??\\Volume{81f2b798-4ed7-11dc-bd8b-001bfc8182ed}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{f4f9b548-5a69-11dc-bd8f-001bfc8182ed}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\F:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,43,00,53,00,49,00,23,00,
43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,00,58,00,58,00,39,\
"\\??\\Volume{e8c3653a-648a-11dc-bd9a-fb1404b6bce3}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{16786086-6862-11dc-bda4-00095be1bf34}"=hex:44,b9,e6,31,00,0c,f1,
02,00,00,00,00
"\\??\\Volume{16786087-6862-11dc-bda4-00095be1bf34}"=hex:44,b9,e6,31,00,08,9c,
52,09,00,00,00
"\\DosDevices\\G:"=hex:5c,00,3f,00,3f,00,5c,00,55,00,53,00,42,00,53,00,54,00,
4f,00,52,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e,00,5f,\
"\\??\\Volume{167860a8-6862-11dc-bda4-00095be1bf34}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\??\\Volume{30e1b00f-cded-11dc-bdbe-00095be1bf34}"=hex:5d,e2,5d,e2,00,7e,00,
00,00,00,00,00
"\\??\\Volume{caf08f1f-eb2b-11dc-bdc7-00095be1bf34}"=hex:54,72,75,65,43,72,79,
70,74,4d
"\\??\\Volume{1ff6e4fd-731f-11dd-be0a-00095be1bf34}"=hex:5c,00,3f,00,3f,00,5c,
00,55,00,53,00,42,00,53,00,54,00,4f,00,52,00,23,00,43,00,64,00,52,00,6f,00,\
"\\??\\Volume{1ff6e4fe-731f-11dd-be0a-00095be1bf34}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,54,00,4f,00,52,00,41,00,47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,\
"\\DosDevices\\H:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
"\\??\\Volume{a66adb7d-8076-11dd-be0f-00095be1bf34}"=hex:5c,00,3f,00,3f,00,5c,
00,53,00,43,00,53,00,49,00,23,00,43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,\
"\\DosDevices\\I:"=hex:5c,00,3f,00,3f,00,5c,00,53,00,54,00,4f,00,52,00,41,00,
47,00,45,00,23,00,52,00,65,00,6d,00,6f,00,76,00,61,00,62,00,6c,00,65,00,4d,\
.
Completion time: 2009-01-10 9:01:59
ComboFix-quarantined-files.txt 2009-01-10 14:01:57
ComboFix2.txt 2009-01-10 03:51:08
ComboFix3.txt 2008-12-22 16:14:21
Pre-Run: 70,554,570,752 bytes free
Post-Run: 70,550,286,336 bytes free
321 --- E O F --- 2008-12-23 14:13:12
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:22:40 AM, on 1/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.antispyexpert.com
O15 - Trusted Zone: *.avsystemcare.com
O15 - Trusted Zone: *.gomyhit.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.onerateld.com
O15 - Trusted Zone: *.safetydownload.com
O15 - Trusted Zone: *.spyguardpro.com
O15 - Trusted Zone: *.storageguardsoft.com
O15 - Trusted Zone: *.trustedantivirus.com
O15 - Trusted Zone: *.virusremover2008.com
O15 - Trusted Zone: *.virusschlacht.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1187458611078
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -
http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 7595 bytes