ComboFix 11-05-16.03 - B-m_q.Q 17/05/2011 14:45:14.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.2047.1411 [GMT 2:00]
Running from: c:\documents and settings\B-m_q.Q\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\B-m_q.Q\Application Data\FFSJ
c:\documents and settings\B-m_q.Q\Application Data\FFSJ\FFSJ.cfg
c:\documents and settings\B-m_q.Q\WINDOWS
c:\windows\system32\drivers\RKHit.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_RKHIT
.
.
((((((((((((((((((((((((( Files Created from 2011-04-17 to 2011-05-17 )))))))))))))))))))))))))))))))
.
.
2011-05-16 19:24 . 2011-05-16 19:24 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-16 11:20 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-16 11:20 . 2011-05-16 11:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-16 11:20 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-01 19:33 . 2011-05-01 19:38 -------- d-----w- c:\program files\Perfect Uninstaller
2011-04-30 01:33 . 2011-04-30 01:33 -------- d-----w- c:\documents and settings\B-m_q.Q\Application Data\Reviversoft
2011-04-30 01:32 . 2011-04-30 01:33 -------- d-----w- c:\program files\Registry Reviver
2011-04-30 01:32 . 2011-01-22 13:33 16704 ----a-w- c:\windows\system32\roboot.exe
2011-04-30 01:18 . 2011-04-30 01:18 -------- d-----w- c:\windows\B9DB4C7601A446D58910F7AA6376DBAF.TMP
2011-04-30 01:18 . 2011-04-30 01:21 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2011-04-30 01:18 . 2011-04-30 01:22 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA
2011-04-27 01:17 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-04-27 01:17 . 2009-08-06 17:24 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2011-04-27 01:17 . 2009-08-06 17:24 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2011-04-27 01:17 . 2009-08-06 17:24 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2011-04-27 01:17 . 2009-08-06 17:24 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2011-04-27 01:14 . 2011-04-27 01:15 102400 ----a-w- c:\windows\RegBootClean.exe
2011-04-26 23:45 . 2010-09-06 09:26 189520 ----a-w- c:\windows\system32\drivers\tmcomm.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2011-04-27 01:23 . 2009-10-14 14:49 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-04-27 01:15 . 2006-12-18 19:33 77824 ----a-w- c:\windows\system32\browser.dll.tmp
2011-04-08 05:14 . 2011-03-09 00:38 4111232 ----a-w- c:\windows\system32\nv4_disp.dll
2011-04-08 05:14 . 2011-03-09 00:38 12501600 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-04-07 20:16 . 2011-04-07 20:16 81920 ----a-w- c:\windows\system32\nvwddi.dll
2011-04-07 20:16 . 2011-04-07 20:16 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-04-07 20:16 . 2011-04-07 20:16 282624 ----a-w- c:\windows\system32\nvrsel.dll
2011-04-07 20:16 . 2011-04-07 20:16 253952 ----a-w- c:\windows\system32\nvrsth.dll
2011-04-07 20:16 . 2011-04-07 20:16 249856 ----a-w- c:\windows\system32\nvrseng.dll
2011-04-07 20:16 . 2011-04-07 20:16 126976 ----a-w- c:\windows\system32\nvrszht.dll
2011-04-07 20:16 . 2011-04-07 20:16 331776 ----a-w- c:\windows\system32\nvrshe.dll
2011-04-07 20:16 . 2011-04-07 20:16 286720 ----a-w- c:\windows\system32\nvrsfr.dll
2011-04-07 20:16 . 2011-04-07 20:16 274432 ----a-w- c:\windows\system32\nvrsnl.dll
2011-04-07 20:16 . 2011-04-07 20:16 274432 ----a-w- c:\windows\system32\nvrsesm.dll
2011-04-07 20:16 . 2011-04-07 20:16 270336 ----a-w- c:\windows\system32\nvrsru.dll
2011-04-07 20:16 . 2011-04-07 20:16 262144 ----a-w- c:\windows\system32\nvrshu.dll
2011-04-07 20:16 . 2011-04-07 20:16 258048 ----a-w- c:\windows\system32\nvrstr.dll
2011-04-07 20:16 . 2011-04-07 20:16 258048 ----a-w- c:\windows\system32\nvrssl.dll
2011-04-07 20:16 . 2011-04-07 20:16 253952 ----a-w- c:\windows\system32\nvrsda.dll
2011-04-07 20:16 . 2011-04-07 20:16 249856 ----a-w- c:\windows\system32\nvrsfi.dll
2011-04-07 20:16 . 2011-04-07 20:16 229376 ----a-w- c:\windows\system32\nvrszhc.dll
2011-04-07 20:16 . 2011-04-07 20:16 335872 ----a-w- c:\windows\system32\nvrsar.dll
2011-04-07 20:16 . 2011-04-07 20:16 282624 ----a-w- c:\windows\system32\nvrsit.dll
2011-04-07 20:16 . 2011-04-07 20:16 282624 ----a-w- c:\windows\system32\nvrses.dll
2011-04-07 20:16 . 2011-04-07 20:16 278528 ----a-w- c:\windows\system32\nvrsde.dll
2011-04-07 20:16 . 2011-04-07 20:16 277608 ----a-w- c:\windows\system32\nvmccs.dll
2011-04-07 20:16 . 2011-04-07 20:16 274432 ----a-w- c:\windows\system32\nvrspt.dll
2011-04-07 20:16 . 2011-04-07 20:16 270336 ----a-w- c:\windows\system32\nvrsptb.dll
2011-04-07 20:16 . 2011-04-07 20:16 270336 ----a-w- c:\windows\system32\nvrsja.dll
2011-04-07 20:16 . 2011-04-07 20:16 266240 ----a-w- c:\windows\system32\nvrsko.dll
2011-04-07 20:16 . 2011-04-07 20:16 258048 ----a-w- c:\windows\system32\nvrssk.dll
2011-04-07 20:16 . 2011-04-07 20:16 258048 ----a-w- c:\windows\system32\nvrspl.dll
2011-04-07 20:16 . 2011-04-07 20:16 253952 ----a-w- c:\windows\system32\nvrssv.dll
2011-04-07 20:16 . 2011-04-07 20:16 253952 ----a-w- c:\windows\system32\nvrsno.dll
2011-04-07 20:16 . 2011-04-07 20:16 249856 ----a-w- c:\windows\system32\nvrscs.dll
2011-04-07 20:16 . 2011-04-07 20:16 13891176 ----a-w- c:\windows\system32\nvcpl.dll
2011-04-07 20:16 . 2011-04-07 20:16 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-04-07 20:16 . 2011-04-07 20:16 155752 ----a-w- c:\windows\system32\nvsvc32.exe
2011-04-07 20:16 . 2011-04-07 20:16 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-03-24 14:03 . 2010-08-29 00:10 56936 ----a-w- c:\windows\system32\RtkCoInstXP.dll
.
.
------- Sigcheck -------
.
[-] 2009-11-10 . E7DFCFFA380749B8626AD71E8F367DCB . 360576 . . [5.1.2600.2892] . . c:\windows\system32\drivers\TCPIP.SYS
[-] 2009-11-10 . E7DFCFFA380749B8626AD71E8F367DCB . 360576 . . [5.1.2600.2892] . . c:\windows\system32\dllcache\TCPIP.SYS
[7] 2006-12-18 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\ERDNT\cache\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"CTxfiHlp"="c:\windows\system32\CTXFIHLP.EXE" [2006-08-11 18944]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.E XE" [2006-12-18 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScI nst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT \TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TIN TSETP.EXE" [2004-08-03 455168]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-06-09 49208]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-06 281768]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 110592]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-17 421160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"CTHelper"="CTHELPER.EXE" [2010-03-18 19456]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2011-04-07 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-07 13891176]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-25 813584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 10:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\xchat\\xchat.exe"=
"d:\\xchat\\xchat.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Program Files\\Wippien\\Wippien.exe"=
"c:\\Program Files\\Leaf Networks\\Leaf\\bin\\Leaf.exe"=
"d:\\Loki\\Loki.exe"=
"d:\\Loki\\Autorun\\AutoRun.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\VoipCheapCom\\VoipCheapCom.exe"=
"d:\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\FlashGet\\FlashGet.exe"=
"c:\\Program Files\\FreeCall\\FreeCall.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\VoipDiscount\\VoipDiscount.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ABC\\abc.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\aol\\1273098257\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\aol\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\alien swarm\\srcds.exe"=
"c:\\Program Files\\Steam\\steamapps\\glenn_or_2nd@hotmail.com\ \counter-strike source\\hl2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SmartVoip\\SmartVoip.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\steamapps\\pederastafas@pandora.be\\ counter-strike\\hl.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\Steam\\steamapps\\glenn_or_2nd@hotmail.com\ \half-life\\hl.exe"=
"c:\\Program Files\\Steam\\steamapps\\glenn_or_2nd@hotmail.com\ \counter-strike\\hl.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"20018:TCP"= 20018:TCP:BitComet 20018 TCP
"20018:UDP"= 20018:UDP:BitComet 20018 UDP
"6102:TCP"= 6102:TCP:RDM
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26/08/2007 1:35 685816]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHD RV85.sys [7/09/2007 18:48 78848]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [14/10/2009 16:49 135336]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepK E.sys [25/01/2009 21:04 10384]
R2 Mobiola Wave Service;Mobiola Wave Service;c:\program files\Common Files\SHAPE Services\Mobiola Wave Service\MobiolaWaveService.exe [3/03/2011 17:06 125088]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPN T.SYS [20/01/2011 16:32 14976]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sy s [11/08/2007 10:12 38656]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\driv ers\COMMONFX.sys [18/03/2010 21:39 99416]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\driver s\CTAUDFX.sys [18/03/2010 21:39 555096]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\driver s\CTSBLFX.sys [18/03/2010 21:39 566360]
R3 MOBIOLA_Wave;Mobiola Wave Audio Device (WDM);c:\windows\system32\drivers\mobiolawave.sys [12/01/2011 2:13 24128]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfil t.sys --> c:\windows\system32\drivers\Ambfilt.sys [?]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMM ONFX.sys [18/03/2010 21:39 99416]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [21/06/2010 16:58 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDF X.sys [18/03/2010 21:39 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\driv ers\CTERFXFX.sys [18/03/2010 21:39 100952]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTER FXFX.sys [18/03/2010 21:39 100952]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLF X.sys [18/03/2010 21:39 566360]
S3 leafnets;Leaf Networks Adapter;c:\windows\system32\drivers\leafnets.sys [3/05/2007 1:48 55296]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys --> c:\windows\system32\DRIVERS\ManyCam.sys [?]
S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOO K.SYS [26/12/2007 17:44 44928]
S3 vaxscsi;vaxscsi;c:\windows\system32\Drivers\vaxscs i.sys --> c:\windows\system32\Drivers\vaxscsi.sys [?]
S3 wip0204;Wippien Network Adapter 2.4;c:\windows\system32\drivers\wip0204.sys [9/07/2008 3:04 23480]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30 319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504]
S3 WPRO_40_1123;WinPcap Packet Driver (WPRO_40_1123);c:\windows\system32\drivers\WPRO_40 _1123.sys --> c:\windows\system32\drivers\WPRO_40_1123.sys [?]
S3 WPRO_40_901;WinPcap Packet Driver (WPRO_40_901);c:\windows\system32\drivers\WPRO_40_ 901.sys --> c:\windows\system32\drivers\WPRO_40_901.sys [?]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - uphcleanhlp
.
Contents of the 'Scheduled Tasks' folder
.
2010-11-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.be/
mStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
uInternet Settings,ProxyOverride = *.local
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xporteren naar Microsoft Excel
TCP: {322D76FA-3D04-4A6D-B780-7A9063004C10} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\B-m_q.Q\Application Data\Mozilla\Firefox\Profiles\jb3kz01s.default\
FF - prefs.js: browser.search.selectedEngine - WarezBB - Anime
FF - prefs.js: browser.startup.homepage - hxxp://www.igoogle.be/
FF - user.js: general.useragent.extra.zencast - );user_pref(general.useragent.extra.zencast, );user_pref(general.useragent.extra.zencast,
.
.
------- File Associations -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-RTHDCPL - RTHDCPL.EXE
.
.
.
************************************************** ************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2011-05-17 14:50
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
************************************************** ************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\{ 95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\PowerDVD\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1343024091-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved\{1ADD03C3-DB10-FB4D-BF94-D9C4DECF4B5A}*]
"jackjklijklaapnbnmad"=hex:62,61,6f,64,00,00
"jackjklijklaapnbnmed"=hex:62,61,6e,64,00,00
"iacpfbchoahgkoekae"=hex:6b,61,70,64,6f,62,61,6c,6 6,6f,6f,61,6d,68,69,67,66,62,
64,67,61,6f,00,00
.
[HKEY_USERS\S-1-5-21-1343024091-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved\{7A5DF020-7933-27F9-57EB-4EDBED79F998}*]
"bbloddeidllcbbihpbipcdokbghhnhppajkc"=hex:61,61,0 0,00
"abloddeidllcbbihpbjpaahhfdienagfap"=hex:61,61,00, 00
.
[HKEY_USERS\S-1-5-21-1343024091-602609370-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:20,01,d7,41,6c,e7,99,17,c0,5c,e8,ed,2c,9c ,82,2a,20,8d,70,c6,03,dc,a3,
0f,43,15,5f,d0,a4,c2,1a,83,89,56,24,2c,78,bb,e2,8c ,f7,62,18,ed,37,ae,74,dc,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33 ,8f,50
.
[HKEY_USERS\S-1-5-21-1343024091-602609370-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:8e,e1,de,4d,74,10,39,47,80,18,b8,43 ,26,ee,39,72,ba,f4,86,e0,5b,
50,a6,34,52,5b,35,b8,08,a2,94,da,43,5e,ae,f8,76,72 ,a6,33,e4,be,1e,96,c4,bd,\
"rkeysecu"=hex:4e,03,11,15,73,47,71,b2,a1,ed,34,8c ,ea,cd,a0,5f
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(820)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(1916)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
************************************************** ************************
.
Completion time: 2011-05-17 14:54:02 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-17 12:54
.
Pre-Run: 6.794.305.536 bytes free
Post-Run: 8.116.617.216 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /noexecute=optin /fastdetect
.
Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - FD3DE9C84BE9A171DB5C67DB99A43892