ComboFix 09-05-26.05 - Owner 05/27/2009 20:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.560 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common Files\System\Uninstall
c:\windows\Install.txt
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\drivers\core.cache(2).dsk
c:\windows\system32\drivers\core.cache(3).dsk
c:\windows\system32\drivers\RKHit.sys
c:\windows\system32\drivers\UACfmaanbubiusjbff.sys
c:\windows\system32\Install.txt
c:\windows\system32\mywfhit.ini
c:\windows\system32\mywfhit.ini.tmp
c:\windows\system32\UACbedvnwayrjdtrmw.dll
c:\windows\system32\UACchgwmkdrmrcmnia.log
c:\windows\system32\UACfadlvutcbgmnoag.log
c:\windows\system32\UACfsnddnraurqjxdt.log
c:\windows\system32\UACktdxrpvhudethyo.dat
c:\windows\system32\UACojcaiutasqikuso.dll
c:\windows\system32\UACqordqcungqnyimw.dll
c:\windows\system32\UACwalpiyrpividgaf.dll
c:\windows\system32\UACwqfrgffivtrunna.dll
H:\Autorun.inf
H:\Desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_AFINDING
-------\Legacy_MACIDWE
-------\Legacy_NOBICYT
-------\Legacy_PANDRV
-------\Legacy_PERFS
-------\Legacy_ROUTING
-------\Legacy_SEICTRL
-------\Legacy_SOBICYT
-------\Legacy_TDXDOWKC
-------\Legacy_WSERVING
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-28 )))))))))))))))))))))))))))))))
.
2009-05-27 21:27 . 2009-05-27 21:28 -------- d-----w c:\program files\Spybot
2009-05-27 21:27 . 2009-05-27 21:28 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-27 20:49 . 2009-05-27 21:15 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-27 20:21 . 2009-05-27 23:57 -------- d-----w c:\program files\awsome
2009-05-27 18:20 . 2009-02-20 18:09 78336 ----a-w c:\windows\system32\ieencode.dll
2009-05-27 18:20 . 2009-02-20 18:09 78336 ----a-w c:\windows\system32\dllcache\ieencode.dll
2009-05-26 20:22 . 2009-05-26 20:22 -------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-26 01:59 . 2009-05-27 23:53 -------- d-----w c:\program files\dd
2009-05-26 01:55 . 2009-05-26 01:58 -------- d-----w c:\program files\d
2009-05-26 01:35 . 2009-05-25 20:45 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-05-25 20:46 . 2009-05-25 20:45 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-05-25 20:40 . 2009-05-25 20:40 -------- dc-h--w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-25 20:40 . 2009-03-12 08:17 2902048 -c--a-w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-05-25 20:39 . 2009-05-25 20:39 -------- d-----w c:\program files\Lavasoft
2009-05-25 20:39 . 2009-05-25 20:39 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-25 19:37 . 2009-05-25 19:37 -------- d-----w c:\documents and settings\All Users\Application Data\SITEguard
2009-05-25 19:36 . 2009-05-25 19:36 -------- d-----w c:\program files\Common Files\iS3
2009-05-20 20:14 . 2009-05-20 20:28 -------- d-----w C:\Quake
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-28 00:16 . 2009-02-02 22:17 81984 ----a-w c:\windows\system32\bdod.bin
2009-05-27 23:53 . 2008-08-22 20:30 3371383 ----a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-26 20:47 . 2006-06-19 04:25 36656 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-26 20:46 . 2007-02-25 05:41 -------- d-----w c:\program files\Viewpoint
2009-05-26 20:41 . 2006-08-19 07:51 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-26 20:39 . 2008-12-27 19:32 -------- d-----w c:\documents and settings\All Users\Application Data\Roxio
2009-05-26 20:39 . 2006-08-19 08:02 -------- d-----w c:\program files\Common Files\Roxio Shared
2009-05-26 20:22 . 2007-03-09 20:04 -------- d-----w c:\documents and settings\Owner\Application Data\Viewpoint
2009-05-26 17:20 . 2008-08-22 20:30 40160 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 17:19 . 2008-08-22 20:30 19096 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-26 02:03 . 2008-08-22 20:30 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-25 21:06 . 2008-08-20 22:34 -------- d-----w c:\program files\Google
2009-05-25 21:05 . 2006-09-30 00:58 -------- d-----w c:\program files\LimeWire
2009-05-21 21:59 . 2007-03-30 01:39 -------- d-----w c:\documents and settings\Owner\Application Data\OpenOffice.org2
2009-05-18 03:20 . 2008-03-16 16:58 -------- d-----w c:\documents and settings\Owner\Application Data\mIRC
2009-05-16 17:59 . 2008-01-02 16:46 41924 ---ha-w c:\windows\system32\mlfcache.dat
2009-05-14 00:49 . 2008-08-21 21:09 -------- d-----w c:\documents and settings\Owner\Application Data\dvdcss
2009-05-10 19:02 . 2008-11-10 21:32 -------- d-----w c:\program files\PokerStars
2009-04-29 17:29 . 2008-12-27 19:44 -------- d-----w c:\documents and settings\Owner\Application Data\Roxio
2009-04-26 04:57 . 2008-12-27 19:40 256 ----a-w c:\windows\system32\pool.bin
2009-04-26 04:52 . 2009-02-26 21:17 256 ----a-w c:\documents and settings\Owner\pool.bin
2009-04-14 00:27 . 2008-08-13 20:25 334912 ----a-w c:\documents and settings\Owner\Application Data\id Software\quakelive\home\baseq3\cgamex86.dll
2009-04-14 00:27 . 2008-08-13 20:24 171072 ----a-w c:\documents and settings\Owner\Application Data\id Software\quakelive\home\baseq3\uix86.dll
2009-04-13 23:35 . 2009-02-14 02:31 138944 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-13 23:34 . 2009-02-14 02:31 189784 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-13 23:34 . 2008-08-13 20:24 57344 ----a-w c:\documents and settings\Owner\Application Data\id Software\quakelive\home\pb\pbag.dll
2009-04-13 23:34 . 2008-08-13 20:24 479232 ----a-w c:\documents and settings\Owner\Application Data\id Software\quakelive\home\pb\pbsv.dll
2009-04-13 23:34 . 2008-08-13 20:24 874660 ----a-w c:\documents and settings\Owner\Application Data\id Software\quakelive\home\pb\pbcl.dll
2009-04-13 23:34 . 2008-08-13 20:24 2669632 ----a-w c:\documents and settings\Owner\Application Data\id Software\quakelive\home\baseq3\quakelive.dll
2009-04-01 22:37 . 2006-08-19 07:56 -------- d-----w c:\program files\Java
2009-04-01 22:36 . 2009-04-01 22:36 152576 ----a-w c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-01 22:27 . 2008-10-23 20:45 -------- d-----w c:\program files\MAXBrowse
2009-04-01 22:19 . 2009-04-01 22:19 -------- d-----w c:\program files\CCleaner
2009-04-01 01:49 . 2008-10-02 23:35 -------- d-----w c:\program files\Common
2009-03-26 21:04 . 2009-02-14 02:31 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-03-26 20:53 . 2008-08-13 20:22 22328 ----a-w c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2009-03-26 20:53 . 2008-08-13 20:22 22328 ----a-w c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2009-03-26 20:53 . 2009-02-14 02:31 2246144 ----a-w c:\windows\system32\pbsvc.exe
2009-03-25 18:44 . 2006-08-08 17:56 3650 ----a-w c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-03-15 21:19 . 2008-08-13 20:24 441408 ----a-w c:\documents and settings\Owner\Application Data\id Software\quakelive\home\baseq3\qagamex86.dll
2009-03-09 09:19 . 2009-02-22 15:57 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-09 09:03 . 2006-08-19 08:06 121984 ----a-w c:\windows\system32\drivers\Rtnicxp.sys
2009-03-08 18:22 . 2009-03-08 18:22 1241088 ----a-w c:\windows\system32\SETF2.tmp
2009-03-08 18:22 . 2009-03-08 18:22 1241088 ----a-w c:\windows\system32\SET129.tmp
2009-03-08 18:21 . 2009-03-08 18:21 2771706 ----a-w c:\windows\inf\SETEE.tmp
2009-03-08 18:21 . 2009-03-08 18:21 2771706 ----a-w c:\windows\inf\SETC1.tmp
2009-03-08 18:21 . 2009-03-08 18:21 13460 ----a-w c:\windows\inf\IEM\
0409\SETEF.tmp
2009-03-08 18:21 . 2009-03-08 18:21 13460 ------w c:\windows\inf\IEM\
0409\SETC2.tmp
2009-03-08 18:21 . 2009-03-08 18:21 10240 ----a-w c:\windows\system32\SET118.tmp
2009-03-08 18:21 . 2009-03-08 18:21 10240 ------w c:\windows\system32\SETE1.tmp
2009-03-08 18:09 . 2009-03-08 18:09 391536 ----a-w c:\windows\system32\SETEF.tmp
2009-03-08 18:09 . 2009-03-08 18:09 391536 ----a-w c:\windows\system32\SET126.tmp
2009-03-08 08:41 . 2009-03-08 08:41 5937152 ----a-w c:\windows\system32\SET13B.tmp
2009-03-08 08:41 . 2009-03-08 08:41 5937152 ----a-w c:\windows\system32\SET105.tmp
2009-03-08 08:39 . 2009-03-08 08:39 11063808 ----a-w c:\windows\system32\SETF1.tmp
2009-03-08 08:39 . 2009-03-08 08:39 11063808 ----a-w c:\windows\system32\SET128.tmp
2009-03-08 08:35 . 2009-03-08 08:35 385024 ----a-w c:\windows\system32\SETE5.tmp
2009-03-08 08:35 . 2009-03-08 08:35 385024 ----a-w c:\windows\system32\SET11C.tmp
2009-03-08 08:33 . 2009-03-08 08:33 18944 ----a-w c:\windows\system32\SETE2.tmp
2009-03-08 08:33 . 2009-03-08 08:33 18944 ----a-w c:\windows\system32\SET119.tmp
2009-03-08 08:33 . 2009-03-08 08:33 25600 ----a-w c:\windows\system32\SETFE.tmp
2009-03-08 08:33 . 2009-03-08 08:33 25600 ----a-w c:\windows\system32\SET134.tmp
2009-03-08 08:33 . 2009-03-08 08:33 726528 ----a-w c:\windows\system32\SETFD.tmp
2009-03-08 08:33 . 2009-03-08 08:33 726528 ----a-w c:\windows\system32\SET133.tmp
2009-03-08 08:33 . 2009-03-08 08:33 229376 ----a-w c:\windows\system32\SETEB.tmp
2009-03-08 08:33 . 2009-03-08 08:33 229376 ----a-w c:\windows\system32\SET122.tmp
2009-03-08 08:33 . 2009-03-08 08:33 420352 ----a-w c:\windows\system32\SET148.tmp
2009-03-08 08:33 . 2009-03-08 08:33 420352 ----a-w c:\windows\system32\SET112.tmp
2009-03-08 08:33 . 2009-03-08 08:33 125952 ----a-w c:\windows\system32\SETEA.tmp
2009-03-08 08:33 . 2009-03-08 08:33 125952 ----a-w c:\windows\system32\SET121.tmp
2009-03-08 08:31 . 2009-03-08 08:31 183808 ----a-w c:\windows\system32\SETF3.tmp
2009-03-08 08:30 . 2009-03-08 08:30 66560 ----a-w c:\windows\system32\SET145.tmp
2009-03-08 08:30 . 2009-03-08 08:30 66560 ----a-w c:\windows\system32\SET10F.tmp
2009-03-08 08:22 . 2009-03-08 08:22 164352 ----a-w c:\windows\system32\SET12E.tmp
2009-03-08 08:22 . 2009-03-08 08:22 164352 ------w c:\windows\system32\SETF7.tmp
2009-03-08 08:22 . 2009-03-08 08:22 156160 ----a-w c:\windows\system32\SET13F.tmp
2009-03-08 08:22 . 2009-03-08 08:22 156160 ----a-w c:\windows\system32\SET109.tmp
2009-03-08 08:15 . 2009-03-08 08:15 57667 ----a-w c:\windows\system32\SETF8.tmp
2009-03-08 08:15 . 2009-03-08 08:15 57667 ----a-w c:\windows\system32\SET12F.tmp
2009-03-08 08:11 . 2009-03-08 08:11 445952 ----a-w c:\windows\system32\SETEE.tmp
2009-03-08 08:11 . 2009-03-08 08:11 445952 ----a-w c:\windows\system32\SET125.tmp
2009-03-06 14:22 . 2006-06-17 09:23 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 16:18 . 2009-01-16 18:45 73728 ----a-w c:\windows\system32\RtNicProp32.dll
2009-03-03 00:18 . 2006-06-17 09:23 826368 ----a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-03-22 1191936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2008-09-05 159744]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-04-28 778240]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-04-02 69632]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-25 516440]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-07-23 16804864]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-18 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0sprecovr \SystemRoot\sprecovr.txt\
0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
backup=c:\windows\pss\BigFix.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cleanup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msci
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1155974661\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1155974661\\EE\\aolsoftware.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\QUAKE\\ezquake-gl.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\steam\\steamapps\\common\\quake 3 arena\\quake3.exe"=
"c:\\q3\\quake3.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/25/2009 4:46 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 953168]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [9/18/2008 12:09 PM 111112]
R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [12/27/2008 2:14 PM 22784]
S2 gupdate1c9743e80ffcf14;Google Update Service (gupdate1c9743e80ffcf14);c:\program files\Google\Update\GoogleUpdate.exe [1/11/2009 6:46 PM 133104]
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" --> c:\program files\Viewpoint\Common\ViewpointService.exe [?]
S3 Aldebaran;Aldebaran - Storage Filter Drivers;\??\c:\windows\system32\Drivers\Aldebaran.sys --> c:\windows\system32\Drivers\Aldebaran.sys [?]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [7/17/2008 1:06 PM 118784]
S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [12/25/2008 4:12 PM 12032]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder
2009-05-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 20:45]
2009-05-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-11 19:28]
2006-09-29 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-06-17 00:12]
2006-09-29 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-06-17 00:12]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Search
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-27 20:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(4056)
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\aolshare\aolshcpy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
c:\program files\BitDefender\BitDefender 2009\vsserv.exe
c:\program files\Common Files\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\searchindexer.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\dllhost.exe
c:\program files\Razer\DeathAdder\razertra.exe
c:\program files\Razer\DeathAdder\razerofa.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\windows\TEMP\GoogleUpdate.exe68ba8Update.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-05-28 20:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-28 00:24
Pre-Run: 167,095,894,016 bytes free
Post-Run: 167,047,634,944 bytes free
304 --- E O F --- 2009-05-13 07:02