ComboFix 11-08-10.01 - Administrator 08/10/2011 7:09.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2961 [GMT -4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
.
FILE ::
"c:\documents and settings\David Beyer\Application Data\Sun\Java\Deployment\cache\6.0\12\3cc664c-33707768 c:\documents and settings\David Beyer\Application Data\Sun\Java\Deployment\cache\6.0\31\4be9825f-519f23dd c:\documents and settings\David Beyer\Application Data\Sun\Java\Deployment\cache\6.0\33\3cd2021-69b6831c c:\documents and settings\David Beyer\Application Data\Sun\Java\Deployment\cache\6.0\9\29b57749-57b75566 c:\documents and settings\David Beyer\My Documents\pmsetup63_e5[1].zip"
"c:\documents and settings\David Beyer\My Documents\My Pictures\560Z_D\cdrive\Program Files\Internet Explorer\PLUGINS\nponflow.dll"
"c:\laptop\Local Settings\Application Data\Mozilla\Firefox\Profiles\a429o8fa.default\Cache(2)\94A33945d01"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\David Beyer\My Documents\My Pictures\560Z_D\cdrive\Program Files\Internet Explorer\PLUGINS\nponflow.dll
c:\laptop\Local Settings\Application Data\Mozilla\Firefox\Profiles\a429o8fa.default\Cache(2)\94A33945d01
.
.
((((((((((((((((((((((((( Files Created from 2011-07-10 to 2011-08-10 )))))))))))))))))))))))))))))))
.
.
2011-08-10 11:05 . 2011-07-06 23:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-10 11:05 . 2011-08-10 11:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-08-10 11:05 . 2011-08-10 11:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-10 11:05 . 2011-07-06 23:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-09 19:44 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-09 19:43 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-08 11:22 . 2011-08-08 11:22 -------- d-----w- c:\program files\ESET
2011-07-27 06:28 . 2011-07-20 13:44 6881616 ------w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Updates\mpengine.dll
2011-07-26 17:22 . 2011-07-26 17:22 -------- d-----r- c:\documents and settings\David Beyer\My Videos
2011-07-26 16:53 . 2011-07-26 16:53 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-07-26 16:53 . 2011-07-26 16:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2011-07-26 16:53 . 2011-07-26 16:53 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-07-26 16:50 . 2011-07-26 16:50 -------- d--h--w- c:\windows\PIF
2011-07-26 16:38 . 2011-07-26 23:24 133208 ----a-w- c:\windows\system32\drivers\81008598.sys
2011-07-26 15:10 . 2011-07-26 21:25 133208 ----a-w- c:\windows\system32\drivers\20698820.sys
2011-07-22 06:28 . 2011-07-13 03:39 6881616 ------w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{E9877E92-D0FE-44DE-969F-9C2BBE9F3859}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-10 11:00 . 2011-05-24 20:32 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-03 13:09 . 2009-02-11 02:19 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-08-03 12:04 . 2003-03-31 12:00 75264 ----a-w- c:\windows\system32\drivers\ipsec.sys
2011-07-26 17:05 . 2009-02-10 19:55 44032 ----a-w- c:\windows\system32\CTSVCCDA.EXE
2011-07-15 13:29 . 2003-03-31 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2003-03-31 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2009-02-10 07:21 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2003-03-31 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2003-03-31 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2003-03-31 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2004-08-04 05:59 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2003-03-31 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-07 15:55 . 2011-04-27 13:19 7074640 ------w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-06-02 14:02 . 2003-03-31 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-24 23:14 . 2011-04-27 13:19 222080 ------w- c:\windows\system32\MpSigStub.exe
1998-12-09 02:53 . 1998-12-09 02:53 99840 ----a-w- c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 . 1998-12-09 02:53 70144 ----a-w- c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 . 1998-12-09 02:53 48640 ----a-w- c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 . 1998-12-09 02:53 31744 ----a-w- c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 . 1998-12-09 02:53 186368 ----a-w- c:\program files\Common Files\IRAREG.DLL
1998-12-09 02:53 . 1998-12-09 02:53 17920 ----a-w- c:\program files\Common Files\IRASRIAL.DLL
2011-07-04 02:42 . 2011-05-17 12:25 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-05_13.48.48 )))))))))))))))))))))))))))))))))))))))))
.
- 2003-03-31 12:00 . 2011-04-25 16:11 66560 c:\windows\system32\mshtmled.dll
+ 2003-03-31 12:00 . 2011-06-23 18:36 66560 c:\windows\system32\mshtmled.dll
- 2007-08-13 23:54 . 2011-04-25 16:11 55296 c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 23:54 . 2011-06-23 18:36 55296 c:\windows\system32\msfeedsbs.dll
+ 2003-03-31 12:00 . 2011-06-23 18:36 25600 c:\windows\system32\jsproxy.dll
- 2003-03-31 12:00 . 2011-04-25 16:11 25600 c:\windows\system32\jsproxy.dll
+ 2009-07-09 16:38 . 2011-06-23 18:36 12800 c:\windows\system32\dllcache\xpshims.dll
- 2009-07-09 16:38 . 2011-04-25 16:11 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2007-08-13 23:54 . 2011-06-23 18:36 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2007-08-13 23:54 . 2011-04-25 16:11 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2009-02-10 22:03 . 2011-04-25 16:11 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-02-10 22:03 . 2011-06-23 18:36 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-08-13 23:44 . 2011-04-25 16:11 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2007-08-13 23:44 . 2011-06-23 18:36 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2007-08-13 23:54 . 2011-04-25 16:11 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2007-08-13 23:54 . 2011-06-23 18:36 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 12800 c:\windows\ie8updates\KB2559049-IE8\xpshims.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 66560 c:\windows\ie8updates\KB2559049-IE8\mshtmled.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 55296 c:\windows\ie8updates\KB2559049-IE8\msfeedsbs.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 43520 c:\windows\ie8updates\KB2559049-IE8\licmgr10.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 25600 c:\windows\ie8updates\KB2559049-IE8\jsproxy.dll
- 2003-03-31 12:00 . 2009-03-08 08:34 105984 c:\windows\system32\url.dll
+ 2003-03-31 12:00 . 2011-06-23 18:36 105984 c:\windows\system32\url.dll
- 2003-03-31 12:00 . 2011-04-25 16:11 206848 c:\windows\system32\occache.dll
+ 2003-03-31 12:00 . 2011-06-23 18:36 206848 c:\windows\system32\occache.dll
+ 2003-03-31 12:00 . 2011-06-23 18:36 611840 c:\windows\system32\mstime.dll
- 2003-03-31 12:00 . 2011-04-25 16:11 611840 c:\windows\system32\mstime.dll
- 2007-08-13 23:54 . 2011-04-25 16:11 602112 c:\windows\system32\msfeeds.dll
+ 2007-08-13 23:54 . 2011-06-23 18:36 602112 c:\windows\system32\msfeeds.dll
+ 2011-08-10 11:00 . 2011-08-10 11:00 243360 c:\windows\system32\Macromed\Flash\FlashUtil10v_Plugin.exe
- 2003-03-31 12:00 . 2011-04-25 16:11 184320 c:\windows\system32\iepeers.dll
+ 2003-03-31 12:00 . 2011-06-23 18:36 184320 c:\windows\system32\iepeers.dll
- 2003-03-31 12:00 . 2011-04-25 16:11 387584 c:\windows\system32\iedkcs32.dll
+ 2003-03-31 12:00 . 2011-06-23 18:36 387584 c:\windows\system32\iedkcs32.dll
+ 2003-03-31 12:00 . 2011-06-23 12:05 173568 c:\windows\system32\ie4uinit.exe
- 2003-03-31 12:00 . 2011-04-25 12:01 173568 c:\windows\system32\ie4uinit.exe
- 2010-06-18 17:45 . 2011-04-26 11:07 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2010-06-18 17:45 . 2011-06-20 17:44 293376 c:\windows\system32\dllcache\winsrv.dll
- 2007-08-13 23:54 . 2011-04-25 16:11 916480 c:\windows\system32\dllcache\wininet.dll
+ 2007-08-13 23:54 . 2011-06-23 18:36 916480 c:\windows\system32\dllcache\wininet.dll
+ 2007-08-13 23:44 . 2011-06-23 18:36 105984 c:\windows\system32\dllcache\url.dll
- 2007-08-13 23:44 . 2009-03-08 08:34 105984 c:\windows\system32\dllcache\url.dll
+ 2007-08-13 23:44 . 2011-06-23 18:36 206848 c:\windows\system32\dllcache\occache.dll
- 2007-08-13 23:44 . 2011-04-25 16:11 206848 c:\windows\system32\dllcache\occache.dll
- 2007-08-13 23:54 . 2011-04-25 16:11 611840 c:\windows\system32\dllcache\mstime.dll
+ 2007-08-13 23:54 . 2011-06-23 18:36 611840 c:\windows\system32\dllcache\mstime.dll
- 2009-02-10 22:03 . 2011-04-25 16:11 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2009-02-10 22:03 . 2011-06-23 18:36 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2009-02-10 21:58 . 2011-04-29 16:19 456320 c:\windows\system32\dllcache\mrxsmb.sys
+ 2009-02-10 21:58 . 2011-07-15 13:29 456320 c:\windows\system32\dllcache\mrxsmb.sys
- 2009-07-09 16:38 . 2011-04-25 16:11 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2009-07-09 16:38 . 2011-06-23 18:36 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2007-08-13 23:54 . 2011-06-23 18:36 184320 c:\windows\system32\dllcache\iepeers.dll
- 2007-08-13 23:54 . 2011-04-25 16:11 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2010-06-09 05:16 . 2011-06-23 18:36 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2010-06-09 05:16 . 2011-04-25 16:11 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2007-08-13 23:39 . 2011-06-23 18:36 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-08-13 23:39 . 2011-04-25 16:11 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-08-13 23:39 . 2011-06-23 12:05 173568 c:\windows\system32\dllcache\ie4uinit.exe
- 2007-08-13 23:39 . 2011-04-25 12:01 173568 c:\windows\system32\dllcache\ie4uinit.exe
+ 2011-08-10 10:55 . 2011-08-10 10:55 295606 c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A83000000003}\SC_Reader.exe
+ 2011-08-10 07:00 . 2011-04-25 16:11 916480 c:\windows\ie8updates\KB2559049-IE8\wininet.dll
+ 2011-08-10 07:00 . 2009-03-08 08:34 105984 c:\windows\ie8updates\KB2559049-IE8\url.dll
+ 2011-08-10 07:00 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2559049-IE8\spuninst\updspapi.dll
+ 2011-08-10 07:00 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2559049-IE8\spuninst\spuninst.exe
+ 2011-08-10 07:00 . 2011-04-25 16:11 206848 c:\windows\ie8updates\KB2559049-IE8\occache.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 611840 c:\windows\ie8updates\KB2559049-IE8\mstime.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 602112 c:\windows\ie8updates\KB2559049-IE8\msfeeds.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 247808 c:\windows\ie8updates\KB2559049-IE8\ieproxy.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 184320 c:\windows\ie8updates\KB2559049-IE8\iepeers.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 743424 c:\windows\ie8updates\KB2559049-IE8\iedvtool.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 387584 c:\windows\ie8updates\KB2559049-IE8\iedkcs32.dll
+ 2011-08-10 07:00 . 2011-04-25 12:01 173568 c:\windows\ie8updates\KB2559049-IE8\ie4uinit.exe
- 2009-02-10 21:58 . 2011-04-29 16:19 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2009-02-10 21:58 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2003-03-31 12:00 . 2011-06-23 18:36 1212416 c:\windows\system32\urlmon.dll
+ 2003-03-31 12:00 . 2011-07-25 15:17 5969920 c:\windows\system32\mshtml.dll
+ 2010-01-27 01:07 . 2011-08-10 11:00 6277280 c:\windows\system32\Macromed\Flash\NPSWF32.dll
- 2007-08-13 23:34 . 2011-04-25 16:11 1991680 c:\windows\system32\iertutil.dll
+ 2007-08-13 23:34 . 2011-06-23 18:36 1991680 c:\windows\system32\iertutil.dll
+ 2007-08-13 23:54 . 2011-06-23 18:36 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2007-08-13 23:54 . 2011-07-25 15:17 5969920 c:\windows\system32\dllcache\mshtml.dll
- 2009-02-10 22:03 . 2011-04-25 16:11 1991680 c:\windows\system32\dllcache\iertutil.dll
+ 2009-02-10 22:03 . 2011-06-23 18:36 1991680 c:\windows\system32\dllcache\iertutil.dll
+ 2011-08-10 10:55 . 2011-08-10 10:55 4272128 c:\windows\Installer\c75a1e.msi
+ 2011-08-10 07:00 . 2011-04-25 16:11 1211904 c:\windows\ie8updates\KB2559049-IE8\urlmon.dll
+ 2011-08-10 07:00 . 2011-05-30 22:19 5964800 c:\windows\ie8updates\KB2559049-IE8\mshtml.dll
+ 2011-08-10 07:00 . 2011-04-25 16:11 1991680 c:\windows\ie8updates\KB2559049-IE8\iertutil.dll
+ 2007-08-13 23:54 . 2011-06-23 18:36 11081728 c:\windows\system32\ieframe.dll
- 2007-08-13 23:54 . 2011-04-26 14:11 11081728 c:\windows\system32\ieframe.dll
- 2009-02-10 22:03 . 2011-04-26 14:11 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2009-02-10 22:03 . 2011-06-23 18:36 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-08-10 07:00 . 2011-04-26 14:11 11081728 c:\windows\ie8updates\KB2559049-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-06-30 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2008-07-26 1657376]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-26 13570048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-05-27 40368]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
_uninst_71187880.lnk - c:\documents and settings\Administrator\Local Settings\Temp\_uninst_71187880.bat [N/A]
_uninst_81008598.lnk - c:\documents and settings\Administrator\Local Settings\Temp\_uninst_81008598.bat [N/A]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Fujitsu Scanner Control Center.lnk - c:\windows\twain_32\Fjscan32\FJLaunch.exe [2009-2-10 114688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"LogonType"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^desktop.ini]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\desktop.ini
backup=c:\windows\pss\desktop.iniStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Application Director 11.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Desktop Application Director 11.lnk
backup=c:\windows\pss\Desktop Application Director 11.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^desktop.ini]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\desktop.ini
backup=c:\windows\pss\desktop.iniCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" -hide
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\SUPDSvc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Mozilla Firefox\\plugin-container.exe"=
"c:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Windows Live\\Toolbar\\wltuser.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\JetAudio\\JetAudio.exe"=
"c:\\Documents and Settings\\David Beyer\\Downloads\\aswMBR.exe"=
.
R0 20698820;20698820;c:\windows\system32\drivers\20698820.sys [7/26/2011 11:10 AM 133208]
R0 81008598;81008598;c:\windows\system32\drivers\81008598.sys [7/26/2011 12:38 PM 133208]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/12/2011 5:55 PM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 5:55 PM 67664]
R3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [2/10/2009 3:52 PM 11520]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2/18/2009 8:17 AM 874240]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/4/2010 8:14 AM 136176]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 ctgame;Game Port;c:\windows\system32\drivers\ctgame.sys [2/11/2009 1:24 PM 10368]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/4/2010 8:14 AM 136176]
S3 Samsung UPD Service;Samsung UPD Service;c:\windows\system32\SUPDSvc.exe [9/8/2010 8:26 AM 132464]
S3 TD4408F10;TD4408F10;c:\windows\system32\drivers\TD4408F10AV.sys [9/14/2010 4:03 PM 13227]
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 19:42]
.
2011-08-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc0433d9ad2cb0.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-04 12:14]
.
2011-08-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cc0433d9f4b33c.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-04 12:14]
.
2011-08-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
TCP: DhcpNameServer = 68.87.64.150 68.87.75.198
DPF: {FFFFFFFF-19EB-49E8-BB30-8DE03499D2F0} - hxxp://192.168.10.4/NetVideo.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\xw0mq01i.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-10 07:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-220523388-842925246-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,8b,d7,be,32,6d,0e,4d,ab,97,48,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,38,8b,d7,be,32,6d,0e,4d,ab,97,48,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(672)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-08-10 07:14:17
ComboFix-quarantined-files.txt 2011-08-10 11:14
ComboFix2.txt 2011-08-07 19:53
ComboFix3.txt 2011-08-05 13:51
.
Pre-Run: 898,459,275,264 bytes free
Post-Run: 898,536,947,712 bytes free
.
- - End Of File - - 85C2995A9630D7803A9A696CB9A3C5CA