Logs follow but when installing the Recovery Console I got a System Error, minidump attached.
ComboFix 11-05-03.02 - Administrator 05/03/2011 17:10:31.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1271.593 [GMT -4:00]
Running from: C:\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\carolyn\Local Settings\Application Data\{2F5246C7-83CB-4AFC-86BE-AF4DCA8CB75B}
c:\documents and settings\carolyn\Local Settings\Application Data\{2F5246C7-83CB-4AFC-86BE-AF4DCA8CB75B}\chrome.manifest
c:\documents and settings\carolyn\Local Settings\Application Data\{2F5246C7-83CB-4AFC-86BE-AF4DCA8CB75B}\chrome\content\_cfg.js
c:\documents and settings\carolyn\Local Settings\Application Data\{2F5246C7-83CB-4AFC-86BE-AF4DCA8CB75B}\chrome\content\overlay.xul
c:\documents and settings\carolyn\Local Settings\Application Data\{2F5246C7-83CB-4AFC-86BE-AF4DCA8CB75B}\install.rdf
c:\documents and settings\carolyn\Local Settings\Temporary Internet Files\tmp_3909.exe
c:\documents and settings\carolyn\Local Settings\Temporary Internet Files\tmp_9040.exe
c:\documents and settings\rey\Application Data\Microsoft\services530.exe
c:\documents and settings\rey\Desktop\Internet Explorer.lnk
c:\documents and settings\rey\Local Settings\Application Data\{7390C0F1-74E2-4485-8841-D7C0189CF2B2}
c:\documents and settings\rey\Local Settings\Application Data\{7390C0F1-74E2-4485-8841-D7C0189CF2B2}\chrome.manifest
c:\documents and settings\rey\Local Settings\Application Data\{7390C0F1-74E2-4485-8841-D7C0189CF2B2}\chrome\content\_cfg.js
c:\documents and settings\rey\Local Settings\Application Data\{7390C0F1-74E2-4485-8841-D7C0189CF2B2}\chrome\content\overlay.xul
c:\documents and settings\rey\Local Settings\Application Data\{7390C0F1-74E2-4485-8841-D7C0189CF2B2}\install.rdf
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_10078.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_134.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_1607.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_1859.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_2349.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_2620.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_2695.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_414.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_4568.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_5217.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_5712.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_6208.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_6618.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_6725.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_7256.exe
c:\documents and settings\rey\Local Settings\Temporary Internet Files\tmp_9447.exe
c:\documents and settings\rey\mmaasflkgansfl.exe
c:\windows\Fonts\usps4cb.TTF
c:\windows\iqilusas.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-04-03 to 2011-05-03 )))))))))))))))))))))))))))))))
.
.
2011-04-27 21:33 . 2011-04-27 21:33 -------- d-----w- c:\documents and settings\carolyn
2011-04-25 18:01 . 2011-05-02 13:46 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-04-25 18:01 . 2011-05-02 13:46 711672 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2011-04-25 15:39 . 2011-04-25 17:49 -------- dc-h--w- c:\windows\ie8
2011-04-20 19:44 . 2011-04-20 19:44 16409960 ----a-w- C:\spybotsd162.exe
2011-04-19 16:18 . 2011-04-19 16:18 190032 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-04-19 16:17 . 2011-04-19 16:17 388096 ----a-r- c:\documents and settings\rey\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-19 15:02 . 2011-04-19 15:03 60800 ----a-w- c:\windows\system32\S32EVNT1.DLL
2011-04-19 15:02 . 2011-04-19 15:03 123952 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-04-18 19:55 . 2011-04-18 19:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-04-18 19:03 . 2011-04-18 19:03 -------- d-----w- c:\documents and settings\Administrator.CAE\Application Data\Malwarebytes
2011-04-14 13:17 . 2011-05-03 13:20 0 ----a-w- c:\windows\Jwalukoneji.bin
2011-04-14 07:39 . 2011-04-14 07:39 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-04-14 07:39 . 2011-04-14 07:39 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2011-04-13 19:08 . 2011-04-13 19:08 33461 ----a-w- c:\windows\ezezonusohomatum.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-07 05:33 . 2004-06-07 18:19 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2002-02-26 19:58 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2001-08-18 14:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2004-02-06 22:05 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2002-09-13 22:38 43520 ------w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2002-09-13 22:36 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-04 05:59 385024 ------w- c:\windows\system32\html.iec
2011-02-17 13:18 . 2001-08-18 14:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2001-08-18 14:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2009-04-15 06:42 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2001-08-18 14:00 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2002-11-26 20:15 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-09 13:53 . 2002-11-26 20:15 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-08 13:33 . 2001-08-18 14:00 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2001-08-18 14:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-05-02 13:46 . 2011-04-25 18:01 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"Smapp"="c:\program files\Analog Devices\SoundMAX\Smtray.exe" [2002-01-31 81920]
"ChkAdmin"="c:\progra~1\Compaq\COMPAQ~1\CHKADMIN.EXE" [2002-01-25 81920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-08-03 53096]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2009-09-01 125368]
.
c:\documents and settings\rey\Start Menu\Programs\Startup\
LaunchU3.exe.lnk - c:\documents and settings\rey\Application Data\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe [2008-8-1 22486]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1113\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1117\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1127\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1147\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1152\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1153\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1156\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1158\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1174\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1175\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1179\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1187\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1189\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1193\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1196\Scripts\Logon\0\0]
"Script"=kaseya.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1196\Scripts\Logon\1\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1200\Scripts\Logon\0\0]
"Script"=kaseya.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1200\Scripts\Logon\1\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1215\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1217\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1226\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1230\Scripts\Logon\0\0]
"Script"=kaseya.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1230\Scripts\Logon\1\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1232\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1617\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1621\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1633\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1634\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1638\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1664\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1665\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1676\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1698\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1699\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1710\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1712\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1713\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-1737\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-2110\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-746137067-1801674531-2118\Scripts\Logon\0\0]
"Script"=login.bat
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-27 14:36 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R1 ClntMgmt;Compaq Client Management Driver;c:\windows\system32\drivers\Clntmgmt.sys [8/22/2002 5:27 AM 54222]
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [6/22/2005 11:17 AM 58464]
R2 CpqDfwWebAgent;Compaq Remote Diagnostics Enabling Agent;c:\windows\Cpqdiag\CPQDFWAG.EXE [8/22/2002 5:28 AM 212992]
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/1/2009 1:15 PM 116664]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [4/19/2011 11:20 AM 102448]
S0 tkrogw;tkrogw;c:\windows\system32\drivers\guehb.sys --> c:\windows\system32\drivers\guehb.sys [?]
S2 cpqWebDmi;Compaq DMI Web Agent;c:\progra~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe [8/22/2002 5:27 AM 24576]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/5/2010 10:56 AM 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/5/2010 10:56 AM 135664]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [7/21/2009 4:07 PM 38224]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - GUPDATEM
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2010-10-28 c:\windows\Tasks\At1.job
- c:\windows\system32\wscript.exe [2001-08-18 11:24]
.
2011-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 14:56]
.
2011-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 14:56]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.caenyc.org
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
Trusted Zone: microsoft.com\windowsupdate
TCP: {5F242527-E1F0-4094-B52F-109C62E33852} = 10.0.225.240
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator.CAE\Application Data\Mozilla\Firefox\Profiles\8p6vnqyu.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Adobe Reader Speed Launcher - c:\documents and settings\rey\Application Data\Microsoft\services530.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\documents and settings\rey\Application Data\Microsoft\services530.exe
HKLM-Run-Cradiqurejada - c:\windows\iqilusas.dll
AddRemove-WinZip - c:\program files\WinZip\WINZIP32.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-03 17:19
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-823518204-746137067-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e9,a4,d0,a2,af,c5,8b,4a,a1,9f,c2,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e9,a4,d0,a2,af,c5,8b,4a,a1,9f,c2,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(532)
c:\program files\Bonjour\mdnsNSP.dll
.
Completion time: 2011-05-03 17:22:40
ComboFix-quarantined-files.txt 2011-05-03 21:22
.
Pre-Run: 18,850,975,744 bytes free
Post-Run: 19,197,292,544 bytes free
.
- - End Of File - - F7F6C9B2D2F16549CA1195EE854A38BC
Mini050311-01.zip (23.27K)
Number of downloads: 0