Combo Fix
ComboFix 09-03-06.02 - user 2009-03-08 11:40:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.704 [GMT -5:00]
Running from: c:\documents and settings\user\Desktop\Greg2B.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated)
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\4_exception.nls
c:\windows\system32\config\systemprofile\Application Data\Macromedia\Common
c:\windows\system32\drivers\UAClaswrubl.sys
c:\windows\system32\L8C50.tmp.exe
c:\windows\system32\UACewqwhxbx.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACpultnsbr.log
c:\windows\system32\UACqsoqpphw.log
c:\windows\system32\UACripoymwu.dll
c:\windows\system32\UACvkbmpuqt.dll
c:\windows\system32\UACwllqjkll.dat
c:\windows\system32\UACwoliqpta.log
c:\windows\system32\UACxodpemyc.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-02-08 to 2009-03-08 )))))))))))))))))))))))))))))))
.
2009-03-08 10:15 . 2009-03-08 10:15 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-08 10:15 . 2009-03-08 10:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-08 10:15 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-08 10:15 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-07 21:33 . 2009-03-07 21:33 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-07 21:25 . 2009-03-07 21:25 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-03-07 21:24 . 2009-03-07 21:59 <DIR> d-------- c:\windows\SxsCaPendDel
2009-03-07 19:15 . 2009-03-07 19:15 <DIR> d-------- c:\program files\Trend Micro
2009-03-04 15:49 . 2009-03-04 16:30 <DIR> d-------- c:\program files\SpywareBlaster
2009-03-04 15:49 . 2009-03-04 16:31 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-03-04 15:24 . 2009-03-04 15:24 <DIR> dr-h----- c:\documents and settings\Administrator.USER-4OMUS4XFAI\Application Data\yahoo!
2009-03-02 12:00 . 2009-03-07 21:54 <DIR> d-------- c:\documents and settings\user\Application Data\U3
2009-03-02 10:01 . 2008-12-20 18:15 6,066,688 -----c--- c:\windows\system32\dllcache\ieframe.dll
2009-03-02 10:01 . 2008-12-20 18:15 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2009-03-02 10:01 . 2008-12-20 18:15 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-03-02 10:01 . 2008-12-20 18:15 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2009-03-02 10:01 . 2008-12-20 18:15 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-03-02 10:01 . 2008-12-20 18:15 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-02 10:01 . 2008-12-19 04:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-03-01 18:58 . 2009-03-01 21:35 <DIR> d-------- c:\documents and settings\Administrator.USER-4OMUS4XFAI\Application Data\U3
2009-03-01 17:12 . 2009-03-04 15:23 <DIR> d-------- c:\documents and settings\Administrator.USER-4OMUS4XFAI
2009-03-01 14:46 . 2009-03-01 14:46 <DIR> d-------- c:\program files\Lavasoft
2009-03-01 14:46 . 2009-03-01 14:46 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-03-01 14:46 . 2009-03-01 14:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-01 13:06 . 2009-03-04 15:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-01 12:54 . 2009-03-01 12:54 <DIR> d-------- c:\program files\CCleaner
2009-02-26 22:25 . 2009-02-26 22:25 8,297,026 --a------ c:\windows\system32\SBSP.dat
2009-02-26 22:25 . 2009-02-26 22:25 153 --a------ c:\windows\system32\SBFC.dat
2009-02-26 22:25 . 2009-02-26 23:30 0 --a------ c:\windows\system32\SBRC.dat
2009-02-08 11:45 . 2009-02-08 11:45 <DIR> d-------- c:\documents and settings\user\IECompatCache
2009-02-08 11:44 . 2009-02-08 11:44 <DIR> d-------- c:\documents and settings\user\PrivacIE
2009-02-08 11:44 . 2009-02-08 11:44 <DIR> d-------- c:\documents and settings\user\IETldCache
2009-02-08 11:40 . 2009-02-08 11:40 <DIR> d-------- c:\windows\ie8updates
2009-02-08 11:36 . 2009-02-10 19:53 <DIR> d----c--- c:\windows\ie8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-08 02:33 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 02:33 --------- d-----w c:\program files\Java
2009-03-08 02:24 --------- d-----w c:\program files\Common Files\Adobe
2009-03-08 00:17 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-04 20:24 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-02 16:26 --------- d-----w c:\program files\ESET
2009-03-02 04:45 --------- d-----w c:\program files\Yahoo!
2009-03-01 20:29 --------- d-----w c:\program files\Windows Live Toolbar
2009-01-21 23:10 --------- d-----w c:\documents and settings\user\Application Data\Yahoo!
2009-01-20 22:28 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-16 01:09 --------- d-----w c:\documents and settings\TEMP\Application Data\MSN6
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 344064]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-07-07 949376]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-07-20 286720]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-14 185896]
"Dell AIO Printer A960"="c:\program files\Dell AIO Printer A960\dlbfbmgr.exe" [2003-09-21 270336]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-07 148888]
c:\documents and settings\user\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-05-09 344064]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-06-21 282624]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-02-05 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\c:\
0autocheck autochk *\
0lsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-13 19:12 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBCSTray]
--a------ 2007-12-21 16:30 698864 c:\program files\Sunbelt Software\CounterSpy\SBCSTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2004-10-14 14:42 1404928 c:\program files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
--a------ 2005-05-03 19:38 64512 c:\windows\system32\P17.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 SBHR;SBHR;c:\windows\system32\drivers\sbhr.sys [2008-02-07 15544]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2007-07-07 15424]
R3 SBAPIFS;SBAPIFS;\??\c:\windows\system32\drivers\sbapifs.sys --> c:\windows\system32\drivers\sbapifs.sys [?]
S3 P1130VID;Creative WebCam NX Pro;c:\windows\system32\drivers\P1130Vid.sys [2008-07-27 90357]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - SBAPIFS
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 13:42]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy2\TeaTimer.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\csy1qlpc.default\
FF - plugin: c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-08 11:45:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\docume~1\user\LOCALS~1\Temp\.Sony_PMBrowser2000_BrowserDiskCache 6574080 bytes
c:\docume~1\user\LOCALS~1\Temp\W7351XOV.htm 1735 bytes
c:\docume~1\user\LOCALS~1\Temp\WEA07UTO.htm 1450 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.addbtn.btn upgrade status 109 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.msn.mymsn.btn feed 0 4831 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.msn.mymsn.btn update 365 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.msn.mymsn.btn upgrade status 109 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.addbtn.btn feed 0 2275 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.addbtn.btn feed 1 2717 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.addbtn.btn feed 2 382 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.addbtn.btn feed 3 2696 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 0 21231 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 1 19981 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 2 18185 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 3 23898 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 4 21340 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 5 31985 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 6 23069 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 7 28510 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 8 382 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn feed 9 382 bytes
c:\docume~1\user\LOCALS~1\Temp\WLTB Custom Button Feeds\microsoft.windowslive.news.btn upgrade status 109 bytes
c:\docume~1\user\LOCALS~1\Temp\.Sony_PMBrowser2000_BrowserDiskCache.idx 2199920 bytes
c:\docume~1\user\LOCALS~1\Temp\{1501B916-81BC-4242-B4B8-626168B9B74C}
c:\docume~1\user\LOCALS~1\Temp\{1501B916-81BC-4242-B4B8-626168B9B74C}\{D5068583-D569-468B-9755-5FBF5848F46F}
c:\docume~1\user\LOCALS~1\Temp\{1501B916-81BC-4242-B4B8-626168B9B74C}\{D5068583-D569-468B-9755-5FBF5848F46F}\ENG
c:\docume~1\user\LOCALS~1\Temp\{1501B916-81BC-4242-B4B8-626168B9B74C}\{D5068583-D569-468B-9755-5FBF5848F46F}\ENG\LocaleSetting.xml 19305 bytes
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\Audio
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\CardScan.dll 81920 bytes executable
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\Common.dll 98304 bytes executable
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\CTCabEx.DLL 286720 bytes executable
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\Error.ini 1196 bytes
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\Pfmodbs.vxd 7062 bytes
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\RegEdit.dll 53248 bytes executable
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\Setup.bmp 9160 bytes
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\SUPPORT.CAB 84983 bytes
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\WebDrv.ini 790 bytes
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\_ISUSER.DLL 126976 bytes executable
c:\docume~1\user\LOCALS~1\Temp\{1948D49E-D2AD-4CD7-A683-AF1CA07031FF}\{CD4C8BAB-29E8-4F95-B685-B9F53AB89F15}\_setup.dll 368640 bytes executable
c:\docume~1\user\LOCALS~1\Temp\{22EB2FA7-1BA0-4FFB-972F-353EC6ABA9D5}.log 803 bytes
c:\docume~1\user\LOCALS~1\Temp\{2580475D-701E-43CB-B5E5-DF9A7727E1CE}
c:\docume~1\user\LOCALS~1\Temp\{2580475D-701E-43CB-B5E5-DF9A7727E1CE}\{f0a37341-d692-11d4-a984-009027ec0a9c}
c:\docume~1\user\LOCALS~1\Temp\{2580475D-701E-43CB-B5E5-DF9A7727E1CE}\{f0a37341-d692-11d4-a984-009027ec0a9c}\Platform.ini 5988 bytes
c:\docume~1\user\LOCALS~1\Temp\{28B97CAB-828F-49D8-A30A-675476F9BA92}.log 850 bytes
c:\docume~1\user\LOCALS~1\Temp\{390FF986-468D-4CA9-8830-2C4B313F447F}
c:\docume~1\user\LOCALS~1\Temp\{4E7DC12A-3597-4A94-9429-F6C6987361B1}.log 852 bytes
c:\docume~1\user\LOCALS~1\Temp\{6813C983-427E-4511-8456-E98FCAA1A125}.log 852 bytes
c:\docume~1\user\LOCALS~1\Temp\wmplog00.sqm 1680 bytes
c:\docume~1\user\LOCALS~1\Temp\wmplog01.sqm 1416 bytes
c:\docume~1\user\LOCALS~1\Temp\wmplog02.sqm 1416 bytes
c:\docume~1\user\LOCALS~1\Temp\wmplog03.sqm 1416 bytes
c:\docume~1\user\LOCALS~1\Temp\wmplog04.sqm 1620 bytes
c:\docume~1\user\LOCALS~1\Temp\wmsetup.log 13159 bytes
c:\docume~1\user\LOCALS~1\Temp\WPDNSE
c:\docume~1\user\LOCALS~1\Temp\WQVR2BPM.htm 32768 bytes
c:\docume~1\user\LOCALS~1\Temp\wr-1-0000077.exe 5574 bytes executable
c:\docume~1\user\LOCALS~1\Temp\X04UGI05.emf 284 bytes
c:\docume~1\user\LOCALS~1\Temp\XBJNL0JO.emf 138968 bytes
c:\docume~1\user\LOCALS~1\Temp\XLTJ411I.emf 78488 bytes
c:\docume~1\user\LOCALS~1\Temp\Y0SKFEQZ.htm 1735 bytes
c:\docume~1\user\LOCALS~1\Temp\Y0XVZ16G.htm 1735 bytes
c:\docume~1\user\LOCALS~1\Temp\YDFXSettings.dat 72 bytes
c:\docume~1\user\LOCALS~1\Temp\YGBCHDKS.htm 624 bytes
c:\docume~1\user\LOCALS~1\Temp\ymemsi.log 6092 bytes
c:\docume~1\user\LOCALS~1\Temp\ymp2EB.exe 12932840 bytes executable
c:\docume~1\user\LOCALS~1\Temp\ymp6812.exe 12955880 bytes executable
c:\docume~1\user\LOCALS~1\Temp\YSZH7ULF.htm 14145 bytes
c:\docume~1\user\LOCALS~1\Temp\YV9I7ZKF.emf 41024 bytes
c:\docume~1\user\LOCALS~1\Temp\dgm000 0 bytes
c:\docume~1\user\LOCALS~1\Temp\gaopdx000 0 bytes
c:\docume~1\user\LOCALS~1\Temp\hsperfdata_user
c:\docume~1\user\LOCALS~1\Temp\IH4B.tmp 11387 bytes
c:\docume~1\user\LOCALS~1\Temp\IHFA.tmp 8316 bytes
c:\docume~1\user\LOCALS~1\Temp\java_install.log 26955 bytes
c:\docume~1\user\LOCALS~1\Temp\java_install_reg.log 5651 bytes
c:\docume~1\user\LOCALS~1\Temp\java_install_sp.log 2840 bytes
c:\docume~1\user\LOCALS~1\Temp\jinstall.cfg 9669 bytes
c:\docume~1\user\LOCALS~1\Temp\jusched.log 6772 bytes
c:\docume~1\user\LOCALS~1\Temp\MSI3de3d.LOG 392 bytes
c:\docume~1\user\LOCALS~1\Temp\MSI5291d.LOG 392 bytes
c:\docume~1\user\LOCALS~1\Temp\MSI5e17f.LOG 392 bytes
c:\docume~1\user\LOCALS~1\Temp\MSI66db3.LOG 392 bytes
c:\docume~1\user\LOCALS~1\Temp\MSI8b051.LOG 434 bytes
c:\docume~1\user\LOCALS~1\Temp\MSIcc4e8.LOG 392 bytes
c:\docume~1\user\LOCALS~1\Temp\msqpdx000 0 bytes
c:\docume~1\user\LOCALS~1\Temp\Perflib_Perfdata__755.dat 60416 bytes executable
c:\docume~1\user\LOCALS~1\Temp\quadra000 0 bytes
c:\docume~1\user\LOCALS~1\Temp\RarSFX0
c:\docume~1\user\LOCALS~1\Temp\seneka000 0 bytes
c:\docume~1\user\LOCALS~1\Temp\VerChk.txt 88 bytes
c:\docume~1\user\LOCALS~1\Temp\WMC0000.tmp
c:\docume~1\user\LOCALS~1\Temp\WMC0000.tmp\WMPAU.exe 1669120 bytes executable
c:\docume~1\user\LOCALS~1\Temp\{0bedbd4e-2d34-47b5-9973-57e62b29307c}
c:\docume~1\user\LOCALS~1\Temp\{0bedbd4e-2d34-47b5-9973-57e62b29307c}\CP_XP.reg 2593 bytes
c:\docume~1\user\LOCALS~1\Temp\{0bedbd4e-2d34-47b5-9973-57e62b29307c}\FGL_32.reg 7881 bytes
c:\docume~1\user\LOCALS~1\Temp\{FCDD3F6E-EFE9-4DD5-BF02-9341C49F10DC}
c:\docume~1\user\LOCALS~1\Temp\{FCDD3F6E-EFE9-4DD5-BF02-9341C49F10DC}\{f0a37341-d692-11d4-a984-009027ec0a9c}
c:\docume~1\user\LOCALS~1\Temp\{FCDD3F6E-EFE9-4DD5-BF02-9341C49F10DC}\{f0a37341-d692-11d4-a984-009027ec0a9c}\Platform.ini 5988 bytes
c:\docume~1\user\LOCALS~1\Temp\2132-1-2009-3-2-17-16-25-609
c:\docume~1\user\LOCALS~1\Temp\2132-1-2009-3-2-17-16-25-609\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\2656-1-2009-3-1-19-40-6-546
c:\docume~1\user\LOCALS~1\Temp\2656-1-2009-3-1-19-40-6-546\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\2684-1-2009-3-1-20-58-57-578
c:\docume~1\user\LOCALS~1\Temp\2684-1-2009-3-1-20-58-57-578\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\348-1-2009-3-8-3-10-24-953
c:\docume~1\user\LOCALS~1\Temp\348-1-2009-3-8-3-10-24-953\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\3780-1-2009-3-2-2-52-55-640
c:\docume~1\user\LOCALS~1\Temp\3780-1-2009-3-2-2-52-55-640\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\3900-1-2009-3-1-19-29-26-859
c:\docume~1\user\LOCALS~1\Temp\3900-1-2009-3-1-19-29-26-859\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\460-1-2009-3-2-6-12-28-343
c:\docume~1\user\LOCALS~1\Temp\460-1-2009-3-2-6-12-28-343\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\568-1-2009-3-2-6-21-7-703
c:\docume~1\user\LOCALS~1\Temp\568-1-2009-3-2-6-21-7-703\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\7fecc7.mst 1358848 bytes
c:\docume~1\user\LOCALS~1\Temp\816658.mst 1412608 bytes
c:\docume~1\user\LOCALS~1\Temp\964-1-2009-3-8-0-18-4-421
c:\docume~1\user\LOCALS~1\Temp\964-1-2009-3-8-0-18-4-421\KESetup.cfg 0 bytes
c:\docume~1\user\LOCALS~1\Temp\9e842.mst 1412608 bytes
c:\docume~1\user\LOCALS~1\Temp\AVSETUP_49b30cc0
c:\docume~1\user\LOCALS~1\Temp\AVSETUP_49b30cc0\setup.log 25496 bytes
c:\docume~1\user\LOCALS~1\Temp\BABHZP1B.htm 1735 bytes
c:\docume~1\user\LOCALS~1\Temp\calog.txt 50 bytes
c:\docume~1\user\LOCALS~1\Temp\catchme.dll 53248 bytes executable
c:\docume~1\user\LOCALS~1\Temp\cc2log.txt 38 bytes
c:\docume~1\user\LOCALS~1\Temp\CTZapTest.txt 8404 bytes
c:\docume~1\user\LOCALS~1\Temp\{7136FE70-D1A9-42A5-9BBD-87C440701D9F}
c:\docume~1\user\LOCALS~1\Temp\{7136FE70-D1A9-42A5-9BBD-87C440701D9F}\SBHRInst.exe 88560 bytes executable
c:\docume~1\user\LOCALS~1\Temp\{7DADB304-AF20-48C3-A780-4B4133A08817}.log 852 bytes
c:\docume~1\user\LOCALS~1\Temp\{9C423CF6-2DAA-4A37-94B8-59D7ECC7DB13}.log 852 bytes
c:\docume~1\user\LOCALS~1\Temp\{AC76BA86-7AD7-1033-7B44-A81000000003}.ini 724 bytes
c:\docume~1\user\LOCALS~1\Temp\{AC76BA86-7AD7-1033-7B44-A81200000003}.ini 1403 bytes
c:\docume~1\user\LOCALS~1\Temp\{ACE66099-E18E-4037-83C8-9D182E5B9FA8}.log 1345 bytes
c:\docume~1\user\LOCALS~1\Temp\{D5068583-D569-468B-9755-5FBF5848F46F}.log 5952 bytes
c:\docume~1\user\LOCALS~1\Temp\{FA6CC4B4-7741-4F8D-8E81-15C4BAB9869B}.log 852 bytes
c:\docume~1\user\LOCALS~1\Temp\~DF31DD.tmp 98304 bytes
c:\docume~1\user\LOCALS~1\Temp\~DF3DA9.tmp 32768 bytes
c:\docume~1\user\LOCALS~1\Temp\~DF5B0F.tmp 32768 bytes
c:\docume~1\user\LOCALS~1\Temp\~DF62ED.tmp 212992 bytes
c:\docume~1\user\LOCALS~1\Temp\~DF6F93.tmp 32768 bytes
c:\docume~1\user\LOCALS~1\Temp\~DF82F2.tmp 98304 bytes
c:\docume~1\user\LOCALS~1\Temp\~DF83BF.tmp 32768 bytes
c:\docume~1\user\LOCALS~1\Temp\~DF889B.tmp 16384 bytes
c:\docume~1\user\LOCALS~1\Temp\~DFC7E.tmp 98304 bytes
c:\docume~1\user\LOCALS~1\Temp\~DFF58A.tmp 16384 bytes
c:\docume~1\user\LOCALS~1\Temp\~nsu.tmp
c:\docume~1\user\LOCALS~1\Temp\1128-1-2009-3-8-15-18-42-62
c:\docume~1\user\LOCALS~1\Temp\1128-1-2009-3-8-15-18-42-62\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\1196-1-2009-3-4-21-12-4-687
c:\docume~1\user\LOCALS~1\Temp\1196-1-2009-3-4-21-12-4-687\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\1332-1-2009-3-1-19-17-37-0
c:\docume~1\user\LOCALS~1\Temp\1332-1-2009-3-1-19-17-37-0\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\1384-1-2009-3-2-15-39-49-125
c:\docume~1\user\LOCALS~1\Temp\1384-1-2009-3-2-15-39-49-125\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\1556-1-2009-3-1-23-14-34-765
c:\docume~1\user\LOCALS~1\Temp\1556-1-2009-3-1-23-14-34-765\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\1880-1-2008-4-15-23-1-50-203
c:\docume~1\user\LOCALS~1\Temp\1880-1-2008-4-15-23-1-50-203\KESetup.cfg 1487 bytes
c:\docume~1\user\LOCALS~1\Temp\SunbeltCSCInstaller.log 436604 bytes
c:\docume~1\user\LOCALS~1\Temp\tdss000 0 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\search[1].htm 35115 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\search[2] 454 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\search[3] 512 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\search[4] 550 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\search_02[1].gif 7444 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\search_03[1].gif 395 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\sendToPhone[1].js 7402 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\send_email[1].gif 677 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\cumshot4[1].jpg 16245 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\dank-haus[1].htm 28709 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\4TYZOL2V\dataCache[1].swf 401 bytes
****************
I took out Temporary Internet Files --- way to many
****************
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5MVWHEN\top_06[1].jpg 1175 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5MVWHEN\top_07[1].jpg 1082 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5MVWHEN\top_08[1].jpg 17130 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5MVWHEN\toy[1].jpg 7397 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5MVWHEN\to[1].htm 802 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5MVWHEN\to[2].htm 804 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5MVWHEN\trace[1].gif 43 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5MVWHEN\trailer[1].jpg 42917 bytes
c:\docume~1\user\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O5MVWHEN\transpacatchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(728)
c:\windows\system32\imon.dll
.
Completion time: 2009-03-08 11:48:52
ComboFix-quarantined-files.txt 2009-03-08 16:47:33
Pre-Run: 139,809,132,544 bytes free
Post-Run: 139,832,578,048 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
2879 --- E O F --- 2009-03-08 02:58:21