Ok, I will refrain myself from using HiJackThis now. I am still having the redirects. Whenever I use google or yahoo, the links that are brought up are irrelevant. Also, on the bottom left hand corner of my mozilla windows, it says "Waiting for 7.7.7.0". Do you think the computer is safe to use on the web (like logging onto bank sites, other things) or should the computer be turned on at all? Here's the Log for ComboFix. Thanks for looking and I will be waiting for your response.
ComboFix 09-01-01.02 - Administrator 2009-01-03 9:23:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1645 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: Webroot Spy Sweeper *On-access scanning disabled* (Updated)
AV: AVG 7.5.518 *On-access scanning disabled* (Updated)
FW: Webroot Internet Security Essentials *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\winlogon.exe.
((((((((((((((((((((((((( Files Created from 2008-12-03 to 2009-01-03 )))))))))))))))))))))))))))))))
.
2009-01-02 08:48 . 2008-12-12 00:57 78,336 --a------ c:\windows\system32\Agent.OMZ.Fix.exe
2009-01-01 17:36 . 2009-01-01 17:36 <DIR> d-------- C:\VundoFix Backups
2009-01-01 15:01 . 2009-01-01 15:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Webroot
2009-01-01 15:01 . 2009-01-01 15:01 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Webroot
2009-01-01 15:01 . 2008-11-13 17:11 1,553,272 --a------ c:\windows\WRSetup.dll
2008-12-30 17:07 . 2008-12-30 17:08 <DIR> d-------- c:\windows\system32\Adobe
2008-12-28 08:28 . 2009-01-01 09:38 <DIR> d-------- C:\Piano Lessons
2008-12-27 18:19 . 2008-12-27 18:19 <DIR> d-------- c:\temp\gta4
2008-12-27 14:21 . 2008-12-27 14:21 1,700,352 --a------ c:\windows\system32\gdiplus.dll
2008-12-27 13:44 . 2008-12-27 13:44 <DIR> d-------- c:\windows\system32\xlive
2008-12-27 13:44 . 2008-12-27 14:00 <DIR> d-------- c:\program files\Microsoft Games for Windows - LIVE
2008-12-27 12:22 . 2008-12-27 12:22 <DIR> d-------- c:\program files\MSBuild
2008-12-27 12:21 . 2008-12-27 14:11 <DIR> d-------- c:\windows\system32\XPSViewer
2008-12-27 12:21 . 2008-12-27 12:21 <DIR> d-------- c:\program files\Reference Assemblies
2008-12-27 12:21 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2008-12-27 12:20 . 2008-12-27 12:26 <DIR> d-------- C:\GTA IV
2008-12-06 09:14 . 2008-12-06 09:14 <DIR> d-------- c:\program files\iTunes
2008-12-06 09:14 . 2008-12-06 09:14 <DIR> d-------- c:\program files\iPod
2008-12-06 09:14 . 2008-12-06 09:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-04 22:37 . 2008-12-04 22:37 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-03 01:35 . 2008-12-03 01:35 <DIR> d-------- c:\windows\Logs
2008-12-03 01:35 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-12-03 01:35 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-12-03 01:35 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-12-03 01:35 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-12-03 01:35 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-12-03 01:35 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-12-03 01:35 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-12-03 01:24 . 2008-12-03 01:36 <DIR> d-------- C:\Call of Duty 5
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-03 14:04 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
2009-01-01 20:01 --------- d-----w c:\program files\Accessories
2009-01-01 02:39 --------- d-----w c:\documents and settings\Administrator\Application Data\AVG7
2008-12-30 19:36 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-29 18:35 --------- d-----w c:\program files\Call of Duty Game of the Year Edition
2008-12-29 18:30 138,376 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-12-27 17:26 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-22 02:03 --------- d-----w c:\documents and settings\Administrator\Application Data\LimeWire
2008-12-06 14:13 --------- d-----w c:\program files\Apple Software Update
2008-12-05 03:37 --------- d-----w c:\program files\Java
2008-12-04 00:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-04 00:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-12-03 06:04 --------- d-----w c:\documents and settings\Administrator\Application Data\Azureus
2008-12-03 02:36 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-03 02:34 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-02 07:12 --------- d-----w c:\program files\AGEIA Technologies
2008-12-02 05:31 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-02 05:23 --------- d-----w c:\program files\Microsoft Silverlight
2008-12-02 04:13 --------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-02 04:13 --------- d-----w c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-11-30 04:52 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-30 04:52 --------- d-----w c:\documents and settings\Administrator\Application Data\Malwarebytes
2008-11-26 05:59 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-16 20:52 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-16 18:46 --------- d-----w c:\program files\QuickTime
2008-11-16 18:46 --------- d-----w c:\program files\Bonjour
2008-11-16 18:45 --------- d-----w c:\program files\Common Files\Apple
2008-11-13 13:24 --------- d-----w c:\program files\Veoh
2008-11-12 21:02 29,808 ----a-w c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 21:02 23,152 ----a-w c:\windows\system32\drivers\sshrmd.sys
2008-11-12 21:02 170,608 ----a-w c:\windows\system32\drivers\ssidrv.sys
2008-11-12 19:54 6,188,320 ----a-w c:\windows\system32\drivers\nv4_mini.sys
2008-11-07 00:05 --------- d-----w c:\program files\Nick Jr. Arcade
2008-11-07 00:05 --------- d-----w c:\program files\La Casa de Dora
2008-02-01 08:39 113,664 ----a-w c:\windows\inf\hdaudio.sys
2008-03-08 04:12 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008030720080308\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 --a------ c:\program files\Accessories\SpySweeper\Backup\CtxMenu_1_0_0_10.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 01000000
"NoSMMyPictures"= 01000000
"NoSMHelp"= 01000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
"aux2"= wdmaud.sys
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0OODBS\
0lsdelete
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, credssp.dll, msnsspc.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Accessories\\AVG7\\avginet.exe"=
"c:\\Program Files\\Accessories\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Accessories\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Accessories\\Azureus\\Azureus.exe"=
"c:\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Call of Duty 4\\iw3mp.exe"=
"c:\\Program Files\\Accessories\\LimeWire\\LimeWire.exe"=
"c:\\FreeStyle Street Basketball\\FreeStyle.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Veoh\\VeohClient.exe"=
"c:\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Warcraft III\\War3.exe"=
"c:\\MVP Baseball 2005\\mvp2005.exe"=
"c:\\FIFA 2006\\FIFAWC06.exe"=
"c:\\Madden NFL 08\\Updater.exe"=
"c:\\Madden NFL 08\\mainapp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Call of Duty 5\\CoDWaWmp.exe"=
"c:\\Call of Duty 5\\CoDWaW.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\GTA IV\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\GTA IV\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\GTA IV\\Grand Theft Auto IV\\GTAIV.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2008-11-12 29808]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\Accessories\SUPERAntiSpyware\SASDIFSV.SYS [2008-08-19 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\Accessories\SUPERAntiSpyware\SASKUTIL.sys [2008-08-19 55024]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};\??\c:\program files\Accessories\PowerDVD\
000.fcl [2006-11-02 16:51:58 13560]
R2 WRConsumerService;Webroot Client Service;"c:\program files\Accessories\SpySweeper\WRConsumerService.exe" [2009-01-01 1086840]
S2 WinDefend;Windows Defender;"c:\program files\Accessories\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
S3 SASENUM;SASENUM;\??\c:\program files\Accessories\SUPERAntiSpyware\SASENUM.SYS [2008-08-19 7408]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-01-01 c:\windows\Tasks\wrSpySweeper_LD2B5B4429B4842819D3AFB788C29C0F4.job
- c:\program files\Accessories\SpySweeper\SpySweeperUI.exe [2008-11-13 17:11]
2009-01-01 c:\windows\Tasks\wrSpySweeper_LD2B5B4429B4842819D3AFB788C29C0F4.job
- c:\program files\Accessories\SpySweeper\SpySweeperUI.exe [2008-11-13 17:11]
2009-01-01 c:\windows\Tasks\wrSpySweeper_LD2B5B4429B4842819D3AFB788C29C0F4.job
- a:\","c:\","d:\","e:\","f:\","g:\" []
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://sports.yahoo.com/fantasy
Trusted Zone: *.turbotax.com
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\hu3p0pw2.default\
FF - prefs.js: browser.startup.homepage - hxxp://sports.yahoo.com/fantasy
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Veoh\Plugins\noreg\NPVeohVersion.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-03 09:28:21
Windows 5.1.2600 Service Pack 3, v.5657 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\Accessories\PowerDVD\
000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\Administrator\Software\SecuROM\License information*NULL*]
"datasecu"=hex:02,f1,e8,da,9c,58,34,53,c9,57,6b,05,3b,58,13,17,3c,6f,6d,c1,50,\
bf,2e,df,4d,83,19,6d,03,85,94,13,ef,22,08,b8,ef,a1,5a,93,11,36,ae,cd,26,51,\
0c,7c,f9,9d,69,82,85,c0,c7,e5,85,3c,24,d4,59,52,26,44,3f,80,ec,df,e5,47,5e,\
0f,22,76,b0,df,d9,75,30,f4,29,8f,4c,a5,a6,14,20,57,34,bb,9b,43,38,45,49,be,\
75,d6,85,a1,17,7b,68,35,2d,e5,cb,c6,09,3d,ff,46,47,1e,4f,ea,1b,d2,53,a2,19,\
a2,5a,59,8f,8d,e4,6e,74,73,21,40,fd,4e,be,5f,45,fd,7a,77,5a,3d,5a,ca,79,7f,\
01,75,bb,e0,d4,be,25,97,41,fd,21,0e,e5,50,98,d2,16,ec,d9,2e,39,0f,78,c9,6f,\
7e,a4,c6,d1,98,05,af,b8,65,82,60,ea,b5,26,fa,52,6a,a0,6c,50,88,45,bc,c8,c6,\
24,be,04,21,db,71,e1,2e,20,ef,f2,b2,02,b5,b9,8e,22,ec,c3,25,f1,3a,db,55,07,\
74,6f,2a,9d,a7,07,44,c9,19,91,2c,30,6b,ef,17,4b,50,5d,73,bd,51,09,c6,b3,9b,\
f8,45,77,a6,ef,8b,5f,a8,f0,23,74,e8,2a,dc,74,1b,c5,01,3e,a2,05,48,6a,39,0b,\
67,62,fb,90,b2,e0,bf,ce,c8,8d,0a,57,f4,aa,eb,b4,b7,d1,42,94,27,f8,31,c7,47,\
36,2b,a1,a4,c9,3a,bd,24,c8,8c,be,c0,99,78,51,85,4c,4c,26,cd,77,f4,39,d2,e3,\
81,2e,8d,d8,62,9d,e9,18,ec,f3,66,52,71,b2,6d,b0,9d,55,91,19,74,21,6d,87,e4,\
91,ce,27,ee,dc,62,36,3b,d9,ca,e9,4e,e6,d4,1f,11,ab,e2,e8,00,77,45,e4,3c,d1,\
27,11,1f,5e,b6,c9,1f,e6,59,b7,17,07,df,da,0c,92,a1,8c,fd,8a,6b,1a,9d,23,9f,\
25,9d,67,5c,da,c6,32,99,06,18,4f,0f,0e,8e,bd,74,ba,80,bf,ba,1d,97,72,ea,02,\
40,67,3f,9f,1c,a7,cf,df,0b,85,be,0b,d1,50,4d,60,78,d0,a8,91,a3,50,eb,02,6f,\
5a,d8,53,36,5f,7a,e9,ca,94,84,ab,da,8d,02,35,3c,8e,ec,a6,9e,b7,c5,a7,58,34,\
68,02,24,57,7d,d0,4b,69,0a,b7,24,1a,95,44,d6,f9,ee,a9,bb,d5,b8,05,cf,a5,d2,\
89,4a,22,4d,93,f4,27,34,71,8c,eb,d9,0a,0a,9d,8f,1f,f7,9c,00,cf,e4,0d,f5,6b,\
ee,9f,04,42,78,dc,3e,e1,1c,d3,50,d9,78,42,65,1f,81,5e,fa,1c,b9,a5,3a,e5,8f,\
80,0e,0f,c8,58,b0,3b,ab,c9,3a,6b,ca,2a,f3,15,99,31,0b,39,d4,20,55,cc,f2,99,\
f0,4d,e6,84,90,3f,62,cc,82,c6,50,f7,cd,0f,31,5c,c9,9d,e8,05,60,4e,24,d0,c7,\
43,22,ba,5f,c3,38,10,e2,c9,be,45,90,aa,f4,24,e6,f3,5e,06,9e,cf,22,46,5e,45,\
34,c1,7c,27,3d,44,d5,c8,2b,03,7c,c7,8d,4a,59,2c,85,8a,3d,e5,27,9b,ee,df,56,\
a1,35,21,97,51,68,9f,74,33,5c,b5,cd,f0,b5,69,65,43,34,e3,d0,fc,43,04,a0,1b,\
ad,9f,cb,f1,5c,b3,a1,9a,fd,6b,57,95,c4,8e,4e,55,c5,b4,6e,0c,46,86,47,7b,2d,\
23,3f,74,69,a2,ff,3d,ab,0b,2e,10,de,70,ea,dd,78,c2,a1,3e,be,fd,77,3c,90,aa,\
ed,68,f5,02,a6,cf,32,b5,ef,45,25,a4,a1,2b,d1,74,4d,a2,46,36,cd,ec,a8,3a,b6,\
4b,64,26,3c,f8,16,70,95,2f,e6,a1,f0,19,b9,76,ab,11,6e,52,0d,8a,62,53,7d,67,\
89,ea,cc,23,90,70,2f,f1,f2,ce,b0,3c,2b,31,a2,51,a9,52,77,2a,1e,5e,46,5d,22,\
c5,21,3a,7a,f7,7f,19,aa,48,f1,80,d4,91,e9,35,20,de,c7,47,34,57,ac,f5,62,dc,\
ae,e5,78,e7,e6,a2,93,06,65,6f,4d,e3,39,12,3e,10,72,b1,b5,1d,bd,1d,9f,40,8e,\
84,c9,a9,23,30,f1,62,47,ec,b1,3f,50,86,b5,e8,02,42,48,cd,39,0e,72,87,e4,da,\
16,f6,84,8c,46,97,9f,f1,51,2b,43,f1,c1,ee,f8,e8,8b,27,b4,e8,74,f5,8e,27,1a,\
86,23,0b,d8,11,d2,d4,f7,49,40,be,3a,e7,f7,54,3c,0e,8d,2f,6a,dc,48,30,89,f8,\
7d,24,ec,f5,d1,a7,74,c7,a5,d8,d2,e1,d9,5b,ca,44,0c,3d,75,07,d4,64,d8,01,5a,\
5a,71,59,31,fa,3c,1e,11,96,a5,e6,47,de,6f,f1,05,08,d4,94,81,07,3a,68,8d,1a,\
71,69,5d,29,40,ca,3d,e1,b0,55,b5,e0,71,66,12,6b,e1,fe,8f,60,72,0d,6d,04,62,\
a2,c6,fd,1c,f9,a1,ef,9c,86,f7,6a,b3,5c,29,52,b2,a0,74,90,9f,41,8d,81,c5,ae,\
86,b0,eb,00,ed,00,2d,7c,40,b6,70,6d,61,4d,fc,2c,7a,e8,6e,dd,95,6e,d8,67,04,\
9b,02,ca,48,d0,8f,a2,27,37,c8,5e,89,a8,eb,79,22,e0,64,d8,f0,0e,0c,1f,d1,5d,\
61,50,7e,6d,8e,0c,07,9f,36,ba,78,cc,88,de,3e,94,50,e5,a0,33,95,c0,f1,e8,f7,\
26,1e,2e,30,c0,03,25,f8,c3,a5,a9,3c,0e,45,9f,47,44,71,ff,f6,b2,d0,4a,fc,ee,\
54,a7,52,8d,68,08,71,bd,dd,f2,79,5f,26,38,ac,2b,de,31,e5,85,29,a9,17,4d,92,\
dd,85,44,bf,3b,8c,f3,b8,49,a0,a4,04,64,9d,68,ef,63,92,73,9a,65,29,d1,df,81,\
a1,0b,97,5d,a2,e7,a7,7e,e9,62,b0,35,28,98,2b,df,ea,48,0d,59,23,c9,78,49,13,\
d3,72,ea,66,d5,71,be,fd,11,14,b5,b2,75,16,21,ae,47,86,3e,b6,ea,3c,f1,e4,a9,\
3b,9a,8d,0d,55,03,d9,a0,8e,be,9f,bc,bb,81,50,21,bc,ea,d7,f6,71,c6,b5,36,91,\
86,a4,91,50,8e,0c,35,8a,69,9a,e0,a7,95,7c,42,03,79,fb,30,9d,bc,9d,68,29,f8,\
c2,39,96,bd,34,32,ef,e7,00,c3,05,55,fe,86,41,9c,c4,9c,ae,fb,39,6e,af,d8,4b,\
39,37,42,3a,db,30,37,01,a1,26,44,e3,28,e1,b9,0a,cb,c3,40,cf,04,61,48,3f,56,\
49,12,c2,db,55,aa,cd,38,18,ac,49,0d,f5,2b,4c,e3,46,c1,5d,6e,6c,07,dc,48,cb,\
43,20,82,b9,99,df,88,09,c4,76,ed,7c,b8,27,02,b7,98,89,d5,24,93,13,7b,4f,f3,\
f1,a5,6d,3e,89,7e,8b,3a,8b,0c,18,ed,33,af,a4,72,c7,dc,54,93,d5,e8,41,58,e3,\
11,e3,66,5a,a5,06,d4,91,75,21,9b,5a,2a,4c,90,12,c3,e0,99,b8,af,9d,da,e1,11,\
14,d2,f6,09,aa,95,16,a0,14,a3,f2,14,07,22,a6,25,e2,71,44,8f,83,5c,f1,10,1d,\
b6,d8,22,ae,62,75,d6,80,a5,df,dd,21,ad,2c,ee,fe,8e,9b,25,65,4f,26,7b,74,1e,\
df,3d,3d,2e,76,ce,85,a2,cf,7c,f3,61,9c,32,4a,93,da,65,47,ba,48,6c,ad,59,43,\
54,e5,80,a3,95,e0,5d,99,7e,71,fd,4d,a6,4f,1a,65,e6,6b,35,26,f1,e7,05,43,3f,\
17,37,0f,69,50,02,f7,04,0e,a1,9e,8d,3c,41,b8,f6,e4,60,93,f9,88,fe,7b,74,eb,\
c7,80,ec,e1,ba,2c,30,20,70,1d,d8,9e,e9,d9,41,93,99,45,f4,ad,bb,96,5f,38,6d,\
f1,fc,df,3e,c8,4e,44,71,81,dd,97,2f,88,5a,67,cf,f1,36,64,a9,b8,0c,49,35,9b,\
d8,64,75,ba,6e,c2,0c,66,22,1a,5f,b5,a1,9d,20,68,65,bb,49,5c,3f,1b,ee,7a,06,\
93,e2,ea,d5,4b,43,c3,84,10,14,b2,8a,15,37,a2,c5,81,13,1b,f6,91,40,00,d6,af,\
77,43,18,1b,15,76,9f,f1,01,af,be,a3,d0,b9,41,b7,d0,d0,ca,ee,77,e7,c5,49,7f,\
e2,ac,f3,53,19,ee,7e,0e,5d,e7,9e,e5,65,a6,d8,80,6e,39,0c,a0,a9,8a,b8,29,3f,\
2e,ea,bd,af,2f,2c,07,52,b4,4d,90,50,cc,2c,5f,8b,c1,e6,80,07,93,f4,e7,65,90,\
9e,2c,48,04,ed,98,d7,04,3f,9d,d6,25,e9,3d,9f,fe,a3,f2,37,eb,d7,54,88,8f,1a,\
9f,ce,16,92,32,8c,d2,b4,d1,2e,b4,2e,2a,b6,6d,2a,af,fa,1b,2f,c5,0b,e4,21,c4,\
30,d8,92,e5,12,4a,83,a6,3b,fc,8e,e8,6e,b0,ef,ed,e5,bf,f5,44,0d,61,03,d8,12,\
8c,5e,7e,d4,12,a6,a0,2b,f4,ef,26,a2,ff,11,fc,48,63,f6,93,1a,a8,7f,65,b7,03,\
ff,5b,c9,2f,9f,8c,3f,7a,0a,84,11,98,f7,ed,ff,3b,0d,bf,6d,03,12,7a,08,93,b4,\
24,95,4d,1b,ce,46,32,f9,1a,ad,42,2d,49,3d,3b,13,cb,39,04,48,6b,b7,d5,f8,87,\
79,a3,90,c8,6d,5a,19,5a,cf,1a,20,ee,03,d1,f6,9b,b8,f5,f3,c9,dc,81,64,d1,54,\
3c,83,0d,13,d2,61,cf,59,20,79,bf,9f,21,ba,3e,ab,9b,5a,5c,7c,bb,88,63,1f,1b,\
03,df,3b,d7,c2,ba,8f,e3,f7,f3,e9,b6,32,43,23,6d,a0,4b,aa,76,7b,4c,56,de,a6,\
cf,6c,fe,9d,47,74,c2,c2,ab,28,ab,c0,21,65,54,82,f2,cc,ec,ef,a9,76,1b,69,ee,\
6e,1b,59,f6,76,0b
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*NULL*]
"OODEFRAG10.00.00.01WORKSTATION"="4468EB489B4406E0B8EE6E2C162A835424228518F10B7C1F8811CE4C33973A6107B3C3BBD366D80EE36FA0E8AACBD44F4EB510D79F39E0797F2CAC8AB02F0F1725EA549043C445FB204045A2CCB10DE98F118ED3447AA74E2B41D352E719F400762F5AAFD3C8301DB3BBECC2E050F66B39E608985FEB9DD309FADEEE963ADF64C0C4A7C49EBFD1EC50DFBFF67E7D2D9D8C8F1A73260DE4C308A9006FAED9158E4315A1C0745CB465A24EF631F373204C418372758342F3DC0DC1F9A758A431CE2EAD40D658B2B988474D61FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B5555D575E7D6A3B9808FEBC9E127BECC74CD6C4A35DEA9840673F0BC53B3320848D6EC1DD270C8ED9FEC6B042265582B470FAC1A92CEE9F48E99ADAAB1456CDCF63AE8057E7C7416DB7ED4655FA765A90E4F19B9352D351741B10D892D8E3AF269E30252DEE27232277BD31833E8D1400F028326862001528EDEDBC67E2F39C2307BDE8537A93987077A443EB31F4BF7464CA168F44DFC8EE6743F87C5C22DF0B76E937A599F977F209D48813E90BE00023CD0F55B262BC742164AE08C59035415A8A3163B1CD8AE70E45BDDF52336F5CA5E8176ABAFB3789C769B621F2625052B6B6ABAC7B8391327D2E541EA6525865F7175DE241A3EF231DAE1DC70C43D56A204DAE8A0415BF59E48FF17CF955FA993B964437FBD5955A75D420DB0CDBE15CC16FF6652C003C0861AA6F8F3229AA1D236A62C37592C7EBBA3FB3A1425F011C5A80F48B27C5A10D2707DACC88413039785C024A8DDB1CB86A95FE45D402B4463A2C4D317F6CFEDAFC6C76118B9448D817F321EC75BA9AC695C4DED2B8FCF497CA5DD7EB917E5709BDE9B61B9B1DA18B6E8372B436B9C13DE0FDE23BBA8AA8718347A2358E872153DA52458FEFD9E107049C5D8F2869026987344CD47B6E315B73DCEBEC7A994896553C80F3924D9F216F95FBCBFADCBF3D549E15586E6B5FFCBDD82BD3ADCCABD74500F8B5DEFDE6D5DD0B1C20B22C554C2ABB67E25A4AF82598B70691D5B71EBBD53D742209F638460F5C4222A3738ED0FDC9A376DB59B7464C3B5B30747AE68F47556D6E96468836D62BA2D07B512D26584D5B7862E5C9763A673A1EDB3441BFEA6F9031DF003E8C9D60A88B36E866CED7105832B2C8526E5207E6AD370DDA612AF3BE6693B8B555DF257295A8E4626FAC9B16D162D6E58D9B265B16032DD72A7E920F6BB30CBF42AE6AD319F8ECBECF9C42426760EF0FD3301643700E424F7578BDC806161920A52D635322A1B30CDC01164368E9724C693E6CFE3C7F7E4D42BA2A6CDC64820E769485A9A0F0EBCFA847F12DAF93438F960981245ACE974E33FB52297B9BED37D2308CC6E88BCB"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Accessories\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\windows\system32\oodag.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\tcpsvcs.exe
c:\program files\Accessories\SpySweeper\SpySweeper.exe
.
**************************************************************************
.
Completion time: 2009-01-03 9:29:52 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2009-01-03 14:29:50
Pre-Run: 401,229,115,392 bytes free
Post-Run: 401,212,203,008 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
308 --- E O F --- 2008-12-02 05:05:30