ComboFix 09-07-09.08 - Homie 07/11/2009 18:13.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1470.927 [GMT -4:00]
Running from: c:\documents and settings\Homie\Desktop\Combo-Fix.exe.exe
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\3ed56251-224a-4256-a485-b694a866e00c.ocx
c:\windows\Downloaded Program Files\PurpleBean.exe
c:\windows\Installer\17be3d.msp
c:\windows\Installer\17be3e.msp
c:\windows\Installer\17be3f.msp
c:\windows\Installer\17be40.msp
c:\windows\Installer\17be41.msp
c:\windows\Installer\17be42.msp
c:\windows\Installer\17be43.msp
c:\windows\Installer\17be44.msp
c:\windows\Installer\17be45.msp
c:\windows\Installer\1ab99c.msp
c:\windows\Installer\1ab99d.msp
c:\windows\Installer\1ab99e.msp
c:\windows\Installer\1ab99f.msp
c:\windows\Installer\1ab9a0.msp
c:\windows\Installer\1ab9a1.msp
c:\windows\Installer\1ab9a2.msp
c:\windows\Installer\1ab9a3.msp
c:\windows\Installer\1ab9a4.msp
c:\windows\Installer\1ab9a5.msp
c:\windows\Installer\1b9607.msp
c:\windows\Installer\1b9611.msp
c:\windows\Installer\1b961c.msp
c:\windows\system32\32985ae5-e1a2-444b-a036-f62f31304442.dll
c:\windows\system32\hjgruiqlivcqea.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_hjgruitltfhoym
-------\Service_MSIVXserv.sys
((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.
2009-07-11 22:19 . 2009-04-10 13:58 6327408 ---ha-w- c:\documents and settings\Homie\Application Data\mjusbsp\in00000\setup.exe
2009-07-11 22:19 . 2009-04-10 13:55 725296 ---ha-w- c:\documents and settings\Homie\Application Data\mjusbsp\ar00000\install.exe
2009-07-07 19:06 . 2009-07-07 19:08 -------- d-----w- c:\documents and settings\Homie\Application Data\ManyCam
2009-07-07 19:06 . 2009-07-07 19:08 -------- d-----w- c:\program files\ManyCam 2.4
2009-07-06 03:03 . 2009-07-06 03:03 -------- d-----w- c:\documents and settings\Homie\Application Data\MPEG Streamclip
2009-07-04 15:43 . 2009-07-04 16:00 -------- d-----w- c:\program files\PartyGaming
2009-07-03 16:42 . 2009-07-03 16:42 -------- d-----w- c:\program files\VSTplugins
2009-07-01 05:17 . 2009-07-02 04:17 -------- d-----w- c:\documents and settings\Homie\Local Settings\Application Data\Temp
2009-06-30 23:35 . 2009-07-01 02:36 -------- d-----w- C:\mbam&sas
2009-06-30 19:44 . 2009-06-30 23:41 117760 ----a-w- c:\documents and settings\Administrator.DANSLAPTOP\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-30 19:43 . 2009-06-30 19:43 -------- d-----w- c:\documents and settings\Administrator.DANSLAPTOP\Application Data\SUPERAntiSpyware.com
2009-06-30 19:02 . 2009-06-30 19:02 -------- d-----w- c:\documents and settings\Administrator.DANSLAPTOP\Application Data\Malwarebytes
2009-06-30 18:33 . 2009-06-30 18:33 117760 ----a-w- c:\documents and settings\Homie\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-30 18:21 . 2009-06-30 18:21 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-30 18:21 . 2009-06-30 18:21 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-30 18:21 . 2009-06-30 18:21 -------- d-----w- c:\documents and settings\Homie\Application Data\SUPERAntiSpyware.com
2009-06-29 20:11 . 2009-06-29 20:11 -------- d-----w- c:\program files\Eyeball Networks
2009-06-29 19:11 . 2009-06-29 19:11 138520 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-29 19:11 . 2009-06-29 19:11 189640 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-06-29 19:11 . 2009-06-29 19:11 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-06-29 19:09 . 2009-06-25 20:36 1291640 ----a-w- c:\documents and settings\Homie\Application Data\Mozilla\Firefox\Profiles\l83aqo37.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\BFHUpdater.exe
2009-06-29 19:09 . 2009-06-25 20:36 729088 ----a-w- c:\documents and settings\Homie\Application Data\Mozilla\Firefox\Profiles\l83aqo37.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
2009-06-29 18:00 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-29 18:00 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-29 18:00 . 2009-06-29 18:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-28 16:21 . 2009-06-28 16:21 -------- d-----w- c:\documents and settings\Homie\Application Data\Malwarebytes
2009-06-28 16:21 . 2009-06-28 16:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-27 16:25 . 2009-04-01 04:47 2929528 ----a-w- c:\documents and settings\Homie\Application Data\Simply Super Software\Trojan Remover\elw1.exe
2009-06-26 20:31 . 2009-06-26 20:31 15884 ----a-w- c:\documents and settings\Homie\Application Data\Azureus\plugins\azitunes\libProcessAccess.dll
2009-06-26 20:31 . 2009-06-26 20:31 102400 ----a-w- c:\documents and settings\Homie\Application Data\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll
2009-06-26 20:31 . 2009-06-26 20:31 4141117 ----a-w- c:\documents and settings\Homie\Application Data\Azureus\plugins\vuzexcode\mediainfo.exe
2009-06-26 20:31 . 2009-06-26 20:31 6516755 ----a-w- c:\documents and settings\Homie\Application Data\Azureus\plugins\vuzexcode\ffmpeg.exe
2009-06-26 20:12 . 2009-06-26 20:14 -------- d-----w- c:\program files\Trojan Remover
2009-06-26 20:10 . 2009-06-26 20:13 -------- d-----w- c:\documents and settings\Homie\Application Data\Simply Super Software
2009-06-26 19:27 . 2006-06-19 17:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2009-06-26 19:27 . 2006-05-25 19:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2009-06-26 19:27 . 2005-08-26 05:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2009-06-26 19:26 . 2009-06-26 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-06-26 19:09 . 2009-07-03 17:11 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-26 19:05 . 2003-02-02 23:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2009-06-26 19:05 . 2002-03-06 04:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2009-06-23 23:51 . 2009-06-23 23:51 -------- d-----w- c:\documents and settings\Homie\Application Data\Publish Providers
2009-06-23 23:48 . 2009-06-27 04:07 -------- d-----w- c:\documents and settings\Homie\Local Settings\Application Data\Sony
2009-06-23 23:48 . 2009-06-23 23:51 -------- d-----w- c:\documents and settings\Homie\Application Data\Sony
2009-06-23 23:23 . 2009-06-23 23:25 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-06-23 19:54 . 2009-06-23 19:54 -------- d-----w- c:\documents and settings\Homie\Local Settings\Application Data\PunkBuster
2009-06-23 19:13 . 2009-06-23 19:13 139152 ----a-w- c:\documents and settings\Homie\Application Data\PnkBstrK.sys
2009-06-23 19:13 . 2009-06-23 23:23 -------- d-----w- c:\windows\system32\LogFiles
2009-06-23 17:07 . 2008-12-04 05:25 120832 ----a-w- c:\documents and settings\Homie\Application Data\Mozilla\Firefox\Profiles\l83aqo37.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
2009-06-23 16:50 . 2009-06-23 16:50 -------- d-----w- c:\program files\EA Games
2009-06-22 19:23 . 2009-06-22 19:23 239088 ----a-w- c:\documents and settings\Homie\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-06-22 01:19 . 2009-06-22 01:19 -------- d-----w- c:\program files\DVD Shrink
2009-06-22 01:15 . 2009-06-22 03:24 -------- d-----w- c:\documents and settings\Homie\Application Data\dvdcss
2009-06-21 17:24 . 2009-06-21 17:27 -------- d-----w- c:\documents and settings\Homie\Application Data\VTExtra
2009-06-21 17:22 . 2009-06-21 17:24 -------- d-----w- c:\documents and settings\Homie\Local Settings\Application Data\VTShared
2009-06-21 17:22 . 2009-06-24 02:22 -------- d-----w- c:\documents and settings\Homie\Local Settings\Application Data\SilverDollarCasino
2009-06-21 05:58 . 2009-06-21 05:58 -------- d-----w- c:\program files\ImgBurn
2009-06-20 02:02 . 2009-06-20 02:02 -------- d-----w- c:\documents and settings\Homie\Local Settings\Application Data\TechSmith
2009-06-19 01:08 . 2009-06-19 01:08 -------- d-----w- c:\documents and settings\Administrator.DANSLAPTOP\Application Data\Subversion
2009-06-19 01:07 . 2009-06-30 23:39 -------- d-----w- c:\documents and settings\Administrator.DANSLAPTOP\Local Settings\Application Data\TSVNCache
2009-06-13 20:59 . 2009-06-13 20:59 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-06-12 03:19 . 2009-06-12 03:19 -------- d-----w- c:\documents and settings\All Users\Application Data\StormPredator
2009-06-12 03:19 . 2009-06-12 03:20 -------- d-----w- c:\program files\StormPredator
2009-06-12 03:19 . 2009-06-12 03:19 -------- d-----w- c:\windows\StormPredator
2009-06-12 03:17 . 2009-06-29 18:18 -------- d-----w- c:\program files\Common Files\MF
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-11 22:20 . 2009-05-15 13:28 -------- d-----w- c:\documents and settings\Homie\Application Data\mjusbsp
2009-07-04 13:06 . 2009-05-22 22:52 34 ----a-w- c:\documents and settings\Homie\jagex_runescape_preferences.dat
2009-07-04 12:42 . 2009-05-15 19:10 -------- d-----w- c:\documents and settings\Homie\Application Data\Skype
2009-07-04 12:27 . 2009-05-15 19:12 -------- d-----w- c:\documents and settings\Homie\Application Data\skypePM
2009-07-04 11:45 . 2009-06-05 17:36 -------- d-----w- c:\documents and settings\Homie\Application Data\tor
2009-07-04 11:45 . 2009-05-16 21:27 -------- d-----w- c:\documents and settings\Homie\Application Data\Vidalia
2009-07-03 16:19 . 2009-05-30 21:42 -------- d-----w- c:\documents and settings\Homie\Application Data\Azureus
2009-07-03 03:23 . 2009-06-10 03:35 337197168 ----a-w- c:\documents and settings\Homie\Application Data\ijjigame\U_SFInstaller.exe
2009-06-30 18:20 . 2009-05-21 01:06 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-28 16:16 . 2009-06-09 04:05 -------- d-----w- c:\documents and settings\Homie\Application Data\EyeballChatUserData
2009-06-24 16:06 . 2009-06-09 04:08 -------- d-----w- c:\documents and settings\Homie\Application Data\EyeballChatAvatars
2009-06-22 02:02 . 2009-05-15 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-06-20 02:10 . 2009-05-21 01:12 -------- d-----w- c:\program files\TechSmith
2009-06-20 02:03 . 2009-05-16 06:46 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-06-20 01:15 . 2009-06-09 05:07 -------- d-----w- c:\program files\ClubWPT
2009-06-16 19:33 . 2009-06-10 16:05 -------- d-----w- c:\documents and settings\Homie\Application Data\TeamViewer
2009-06-12 02:54 . 2009-05-15 04:47 12912 ----a-w- c:\documents and settings\Homie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-10 22:21 . 2009-06-10 22:21 -------- d-----w- c:\program files\Drug Lord 2
2009-06-10 16:09 . 2009-06-10 16:09 -------- d-----w- c:\program files\TeamViewer
2009-06-10 05:10 . 2009-06-10 05:10 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-06-10 04:00 . 2009-06-10 03:35 -------- d--h--w- c:\documents and settings\Homie\Application Data\ijjigame
2009-06-10 03:52 . 2009-06-10 03:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-10 03:35 . 2009-06-10 03:34 558552 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PLauncher.exe
2009-06-10 03:34 . 2009-06-10 03:34 -------- d-----w- c:\documents and settings\All Users\Application Data\ijjigame
2009-06-10 03:33 . 2009-06-10 03:33 -------- d-----w- c:\program files\NHN USA
2009-06-08 02:47 . 2009-06-07 23:38 -------- d-----w- c:\program files\Pando Networks
2009-06-08 01:55 . 2009-06-08 01:38 -------- d-----w- c:\documents and settings\All Users\Application Data\NexonUS
2009-06-08 01:38 . 2009-06-08 01:38 98304 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2009-06-08 01:38 . 2009-06-08 01:38 81920 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2009-06-08 01:38 . 2009-06-08 01:38 520192 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2009-06-08 01:38 . 2009-06-08 01:38 335872 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2009-06-08 01:38 . 2009-06-08 01:38 258352 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2009-06-08 01:38 . 2009-06-08 01:38 167936 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2009-06-05 17:34 . 2009-06-05 17:26 -------- d-----w- c:\program files\Vidalia Bundle
2009-06-03 21:48 . 2009-06-10 03:34 779720 ----a-w- c:\documents and settings\All Users\Application Data\ijjigame\PurpleBean.exe
2009-06-02 21:20 . 2009-05-15 05:03 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-30 22:24 . 2009-05-30 22:24 10684866 ----a-w- c:\documents and settings\Homie\Application Data\Azureus\plugins\azump\mplayer.exe
2009-05-30 21:42 . 2009-05-30 21:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-05-30 21:41 . 2009-05-30 21:41 -------- d-----w- c:\program files\Vuze
2009-05-30 04:53 . 2009-05-30 04:53 -------- d-----w- c:\program files\Sun
2009-05-30 04:53 . 2009-05-20 21:10 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-30 04:50 . 2009-05-20 21:10 -------- d-----w- c:\program files\Java
2009-05-30 04:26 . 2009-05-15 08:09 90112 ----a-w- c:\windows\DUMP4853.tmp
2009-05-30 04:22 . 2009-05-30 04:22 -------- d-----w- c:\documents and settings\Homie\Application Data\TortoiseSVN
2009-05-30 03:36 . 2009-05-30 03:36 -------- d-----w- c:\documents and settings\Homie\Application Data\Subversion
2009-05-30 03:33 . 2009-05-30 03:33 -------- d-----w- c:\program files\TortoiseSVN
2009-05-30 03:33 . 2009-05-30 03:33 -------- d-----w- c:\program files\Common Files\TortoiseOverlays
2009-05-30 02:35 . 2009-05-30 02:34 -------- d-----w- c:\program files\QuickTime
2009-05-30 02:34 . 2009-05-30 02:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-30 02:34 . 2009-05-30 02:34 -------- d-----w- c:\program files\Apple Software Update
2009-05-30 02:34 . 2009-05-30 02:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-05-26 21:31 . 2009-06-10 03:33 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe
2009-05-25 15:24 . 2009-05-25 15:24 -------- d-----w- c:\documents and settings\Homie\Application Data\CamfrogWEB
2009-05-25 15:24 . 2009-05-25 15:24 -------- d-----w- c:\program files\CFWebAdvancedU
2009-05-22 18:42 . 2009-05-15 08:09 90112 ----a-w- c:\windows\DUMP513c.tmp
2009-05-20 21:09 . 2009-05-20 21:09 152576 ----a-w- c:\documents and settings\Homie\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-19 17:25 . 2009-05-15 08:09 90112 ----a-w- c:\windows\DUMP60cd.tmp
2009-05-18 16:24 . 2009-05-18 16:22 -------- d-----w- c:\program files\One Club Casino
2009-05-17 19:00 . 2009-05-16 07:09 -------- d-----w- c:\program files\Camfrog
2009-05-17 18:58 . 2009-05-17 18:58 -------- d-----w- c:\program files\Common Files\Skype
2009-05-17 18:58 . 2009-05-17 18:58 -------- d-----r- c:\program files\Skype
2009-05-17 18:58 . 2009-05-15 19:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-05-17 18:43 . 2009-05-17 18:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-17 18:42 . 2009-05-17 18:42 -------- d-----w- c:\program files\Yahoo!
2009-05-17 17:51 . 2009-05-15 18:35 -------- d-----w- c:\program files\Common Files\LogiShrd
2009-05-17 17:34 . 2009-05-17 17:34 10134 ----a-r- c:\documents and settings\Homie\Application Data\Microsoft\Installer\{5FE1E412-D114-46E8-A891-5BE087B256A5}\ARPPRODUCTICON.exe
2009-05-17 17:22 . 2009-05-17 17:22 -------- d-----w- c:\program files\Microsoft
2009-05-17 17:22 . 2009-05-17 17:21 -------- d-----w- c:\program files\Windows Live
2009-05-17 17:09 . 2009-05-17 17:09 -------- d-----w- c:\program files\Readon Technology
2009-05-17 17:00 . 2009-05-17 17:00 -------- d-----w- c:\program files\microsoft frontpage
2009-05-17 16:56 . 2009-05-17 16:56 -------- d-----w- c:\program files\nintendo
2009-05-17 16:48 . 2009-05-15 05:32 -------- d-----w- c:\program files\Unlocker
2009-05-17 16:47 . 2009-05-17 16:47 -------- d-----w- c:\program files\EasyCleaner
2009-05-17 16:43 . 2009-05-17 16:43 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-05-17 16:35 . 2009-05-17 16:35 -------- d-----w- c:\documents and settings\Homie\Application Data\ESET
2009-05-17 09:30 . 2009-05-15 04:32 -------- d-----w- c:\program files\DirectX9.0c
2009-05-17 09:30 . 2009-05-15 05:11 -------- d-----w- c:\program files\Adobe Media Player
2009-05-17 09:28 . 2009-05-15 18:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd
2009-05-17 09:27 . 2009-05-16 07:04 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-05-17 08:54 . 2009-05-15 04:21 -------- d-----w- c:\program files\MultiRes
2009-05-16 15:17 . 2009-05-16 07:10 -------- d-----w- c:\documents and settings\Homie\Application Data\Camfrog
2009-05-16 07:36 . 2009-05-16 07:36 -------- d-----w- c:\program files\MSBuild
2009-05-16 07:36 . 2009-05-16 07:36 -------- d-----w- c:\program files\Reference Assemblies
2009-05-15 19:12 . 2009-05-15 19:12 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-05-15 18:52 . 2009-05-15 18:52 -------- d-----w- c:\documents and settings\Homie\Application Data\Leadertech
2009-05-15 18:30 . 2009-05-15 18:30 -------- d-----w- c:\documents and settings\Homie\Application Data\vlc
2009-05-15 18:19 . 2009-05-15 18:19 -------- d-----w- c:\documents and settings\Homie\Application Data\ImgBurn
2009-05-15 17:30 . 2009-05-15 17:30 -------- d-----w- c:\program files\VideoLAN
2009-05-15 13:32 . 2009-05-15 13:32 -------- d-----w- c:\program files\Common Files\Windows Live
2009-05-15 08:23 . 2009-05-15 01:48 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-15 05:09 . 2009-05-15 05:09 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-15 05:05 . 2009-05-15 05:05 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-05-15 04:55 . 2009-05-15 04:55 0 ----a-w- c:\windows\nsreg.dat
2009-05-15 04:39 . 2009-05-15 04:39 -------- d-----w- c:\program files\ESET
2009-05-15 04:39 . 2009-05-15 04:39 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-05-15 04:20 . 2009-05-15 04:20 472576 ----a-w- c:\windows\Radeon Omega Drivers v4.8.442 Uninstall.exe
2009-05-15 04:20 . 2009-05-15 04:20 -------- d-----w- c:\program files\Radeon Omega Drivers
2009-05-15 02:59 . 2009-05-15 02:59 -------- d-----w- c:\program files\Innovative Solutions
2009-05-15 01:44 . 2009-05-15 01:44 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-05-13 19:32 . 2009-05-17 18:42 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Homie\Application Data\mjusbsp\cdloader2.exe" [2009-04-10 50520]
"Google Update"="c:\documents and settings\Homie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-05 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-13 2046120]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-30 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-06-01 1059720]
"AtiPTA"="atiptaxx.exe" - c:\windows\system32\atiptaxx.exe [2006-02-22 344064]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-11-10 15473664]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Eyeball Chat"="c:\program files\Eyeball Networks\Eyeball Chat\EyeballChat.exe" [2009-06-29 2666496]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2007-10-12 439568]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Privoxy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Privoxy.lnk
backup=c:\windows\pss\Privoxy.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Homie\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Homie\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Homie\\Application Data\\mjusbsp\\magicJack.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2/13/2009 1:07 PM 106208]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2/13/2009 1:07 PM 727720]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [1/14/2008 6:06 AM 21632]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-07-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-115176313-1644491937-1003Core.job
- c:\documents and settings\Homie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-05 23:20]
2009-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-115176313-1644491937-1003UA.job
- c:\documents and settings\Homie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-05 23:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DriverMax - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - hxxp://activex.camfrogweb.com/advanced/2.0.2.3/cfweb_activex.camfrogweb.com-advanced-2.0.2.3_instmodule.exe
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.17.0.cab
FF - ProfilePath - c:\documents and settings\Homie\Application Data\Mozilla\Firefox\Profiles\l83aqo37.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=13&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Homie\Application Data\Mozilla\Firefox\Profiles\l83aqo37.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\documents and settings\Homie\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Homie\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-11 18:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(940)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3548)
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\documents and settings\Homie\Application Data\mjusbsp\st00000\mjsetup.exe
c:\documents and settings\Homie\Application Data\mjusbsp\magicJack.exe
.
**************************************************************************
.
Completion time: 2009-07-11 18:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-11 22:24
Pre-Run: 62,210,297,856 bytes free
Post-Run: 62,136,934,400 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
376 --- E O F --- 2009-06-11 03:13