ComboFix 10-04-17.01 - Administrator 17/04/2010 20:59:46.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1263.803 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Desktop\pie.com
Command switches used :: c:\docume~1\ADMINI~1\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
The following files were disabled during the run:
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Infected copy of c:\windows\system32\drivers\acpiec.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((( Files Created from 2010-03-17 to 2010-04-17 )))))))))))))))))))))))))))))))
.
2010-04-17 19:08 . 2010-04-17 19:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Novatel Wireless
2010-04-16 14:40 . 2010-04-16 14:41 -------- d-----w- c:\program files\trend micro
2010-04-16 14:40 . 2010-04-16 14:41 -------- d-----w- C:\rsit
2010-04-15 11:20 . 2010-04-15 11:20 0 ----a-w- c:\windows\system32\userinit.vir
2010-04-15 10:53 . 2010-04-15 11:32 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-04-15 10:52 . 2010-04-15 11:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-04-15 10:52 . 2010-04-15 10:52 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-04-15 10:38 . 2010-04-15 10:38 -------- d-----w- c:\program files\Enigma Software Group
2010-04-15 10:38 . 2010-04-15 10:46 -------- d-----w- c:\windows\61D3AAE1D5214CD7939B37813DE8F955.TMP
2010-04-15 10:37 . 2010-04-15 10:37 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-04-15 09:50 . 2010-04-15 09:50 -------- d-----w- C:\!KillBox
2010-04-14 16:51 . 2010-04-14 16:51 -------- d-----w- c:\program files\af0.net
2010-04-09 15:49 . 2010-04-09 15:49 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2010-04-09 15:49 . 2010-04-09 15:49 80400 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\fssync.dll
2010-04-09 15:43 . 2010-04-09 15:43 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2010-04-09 15:43 . 2010-04-09 15:43 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2010-04-09 15:39 . 2010-04-09 15:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2010-04-09 14:32 . 2010-04-09 14:32 -------- d-sh--w- c:\documents and settings\NetworkService\IECompatCache
2010-04-08 18:19 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-07 13:37 . 2010-04-07 13:37 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-06 17:05 . 2010-04-15 07:23 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-04-06 17:05 . 2010-04-14 12:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-05 10:12 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-04-05 10:11 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-04-04 19:45 . 2009-12-14 11:44 39352 ----a-w- c:\windows\system32\drivers\CSVirtualDiskDrv.sys
2010-04-04 19:45 . 2009-12-14 11:44 88632 ----a-w- c:\windows\system32\drivers\CSCrySec.sys
2010-04-04 19:44 . 2010-04-17 19:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-04-04 13:52 . 2010-04-04 13:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia Ovi Suite
2010-04-04 13:47 . 2010-04-04 13:47 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\NokiaAccount
2010-04-04 13:41 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-04-04 13:40 . 2010-04-04 13:40 -------- d-----w- c:\program files\PC Connectivity Solution
2010-04-04 13:39 . 2010-04-04 13:39 12212040 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
2010-04-04 13:39 . 2010-04-04 13:39 13930312 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
2010-04-04 13:39 . 2010-04-04 13:39 77824 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\Run_XML6_SP1.exe
2010-04-04 13:39 . 2010-04-04 13:39 61440 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMF11Runx86.exe
2010-04-04 13:39 . 2010-04-04 13:39 58880 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\WMF11Runx64.exe
2010-04-04 13:39 . 2010-04-04 13:39 50000 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Installer\CommonCustomActions\pcswpc.exe
2010-04-04 13:38 . 2010-04-04 13:38 -------- d-----w- c:\documents and settings\All Users\Application Data\OviInstallerCache
2010-04-04 13:38 . 2010-04-04 13:38 98366952 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Nokia_Ovi_Suite_PCS_Update.exe
2010-04-04 13:27 . 2010-04-04 13:27 -------- d-----w- c:\program files\Common Files\PCSuite
2010-04-04 13:25 . 2010-04-04 13:23 34442296 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_eng_us.exe
2010-04-04 13:24 . 2010-04-04 13:24 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-04-04 13:24 . 2010-04-04 13:24 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-04 13:24 . 2010-04-04 13:24 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-04 13:24 . 2010-04-04 13:24 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-03 14:46 . 2010-04-04 19:19 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-02 22:01 . 2010-04-02 22:01 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2010-04-02 22:01 . 2010-04-02 22:01 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Yahoo!
2010-04-02 16:41 . 2010-04-02 16:41 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-04-02 15:59 . 2010-04-06 09:45 120 ----a-w- c:\windows\Wsipa.dat
2010-04-02 15:59 . 2010-04-06 07:30 0 ----a-w- c:\windows\Vdurusehihe.bin
2010-03-31 07:01 . 2010-03-31 07:01 20895216 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\rp\RealPlayerSPGold.exe
2010-03-25 08:20 . 2010-03-25 08:20 -------- d-----w- c:\program files\Common Files\Skype
2010-03-22 15:04 . 2010-03-22 15:04 255472 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-03-21 15:30 . 2010-03-21 19:44 -------- d-----w- c:\program files\Password Solutions
2010-03-21 15:30 . 2010-03-21 15:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Password Solutions
2010-03-21 14:49 . 2010-03-21 14:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Passware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-17 19:58 . 2010-02-16 14:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
2010-04-17 19:58 . 2009-08-28 06:16 -------- d-----w- c:\documents and settings\Administrator\Application Data\skypePM
2010-04-16 21:56 . 2009-08-27 10:47 -------- d-----w- c:\program files\Google
2010-04-16 20:55 . 2009-11-18 04:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2010-04-15 14:39 . 2004-08-04 12:00 11648 ----a-w- c:\windows\system32\drivers\acpiec.sys
2010-04-15 10:40 . 2009-08-26 10:51 71320 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-15 09:50 . 2009-08-28 04:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-15 08:43 . 2004-08-04 12:00 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-04-14 14:29 . 2010-04-08 18:28 112 ----a-w- c:\documents and settings\All Users\Application Data\UvQAd7e1K.dat
2010-04-09 15:42 . 2009-08-26 11:13 -------- d-----w- c:\program files\Kaspersky Lab
2010-04-07 12:44 . 2009-09-11 07:31 -------- d-----w- c:\program files\Nokia
2010-04-07 12:43 . 2009-11-10 10:30 -------- d-----w- c:\program files\Common Files\Nokia
2010-04-04 13:51 . 2009-09-11 07:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia
2010-04-04 13:23 . 2009-08-27 11:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-04-03 14:31 . 2009-08-27 11:29 -------- d-----w- c:\program files\Common Files\Real
2010-04-02 22:21 . 2009-12-24 10:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-02 22:19 . 2009-12-31 04:42 5918776 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-04-02 16:34 . 2004-08-04 12:00 539136 ----a-w- c:\windows\system32\logonui.exe
2010-04-02 16:24 . 2009-08-26 09:59 221184 ----a-w- c:\windows\system32\wbem\wmiadap.exe
2010-04-02 16:23 . 2004-08-04 12:00 413696 ----a-w- c:\windows\system32\cmd.exe
2010-04-02 16:23 . 2004-08-04 12:00 36864 ----a-w- c:\windows\system32\attrib.exe
2010-04-02 16:23 . 2006-03-17 00:38 53248 ----a-w- c:\windows\system32\verclsid.exe
2010-04-02 16:23 . 2004-08-04 12:00 44544 ----a-w- c:\windows\system32\cacls.exe
2010-04-02 16:20 . 2004-08-04 12:00 58368 ----a-w- c:\windows\system32\rundll32.exe
2010-04-02 16:20 . 2004-08-04 12:00 93696 ----a-w- c:\windows\system32\notepad.exe
2010-04-02 16:20 . 2004-08-04 12:00 70144 ----a-w- c:\windows\system32\drwtsn32.exe.tmp
2010-03-29 23:46 . 2009-12-24 10:27 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 23:45 . 2009-12-24 10:27 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-29 07:07 . 2010-03-07 13:56 439816 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\setup.exe
2010-03-26 13:28 . 2009-12-23 04:08 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-17 17:43 . 2010-03-10 13:09 -------- d-----w- c:\program files\Raxco
2010-03-17 12:27 . 2010-03-17 12:27 0 ----a-w- c:\windows\nsreg.dat
2010-03-15 12:09 . 2010-03-15 12:09 8405312 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2010-03-15 12:09 . 2010-03-15 12:09 149000 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\chr_helper\LaunchHelper.exe
2010-03-15 12:08 . 2010-03-15 12:08 10309448 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-03-15 12:07 . 2010-03-15 12:07 79368 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\RUP\vista.exe
2010-03-15 12:07 . 2010-03-15 12:07 64000 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-15 12:07 . 2010-03-15 12:07 52288 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-15 12:07 . 2010-03-15 12:07 50688 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-15 12:07 . 2010-03-15 12:07 49152 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-15 12:07 . 2010-03-15 12:07 118784 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-11 14:52 . 2009-08-27 11:23 -------- d-----w- c:\program files\CCleaner
2010-03-10 06:15 . 2004-08-04 12:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 18:53 . 2010-03-09 18:39 -------- d-----w- c:\program files\Viewpoint
2010-03-09 18:52 . 2010-03-09 18:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NokiaMusic
2010-03-09 18:52 . 2009-08-27 11:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
2010-03-09 18:51 . 2009-11-13 12:02 -------- d-----w- c:\program files\BatteryBar
2010-03-09 18:51 . 2010-02-20 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-03-09 18:25 . 2010-01-16 09:23 -------- d-----w- c:\program files\Zapak Games
2010-03-09 18:24 . 2009-08-26 10:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-09 18:23 . 2010-01-09 07:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-03-08 15:39 . 2010-03-08 15:39 2360 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-03-06 11:41 . 2010-03-06 11:41 -------- d-----w- c:\program files\Veoh Networks
2010-02-27 17:32 . 2009-11-22 07:46 -------- d-----w- c:\program files\GameTop.com
2010-02-27 14:43 . 2009-09-11 07:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Suite
2010-02-27 14:42 . 2010-02-27 14:42 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-02-27 14:42 . 2010-02-27 14:42 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-02-27 14:39 . 2010-02-27 14:39 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2010-02-25 06:24 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-20 10:51 . 2010-02-20 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-02-20 10:51 . 2010-02-20 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-02-19 23:47 . 2010-02-19 23:47 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2010-02-17 08:10 . 2004-08-04 12:00 2189952 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2066816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-16 13:01 . 2004-08-04 12:00 218624 ----a-w- c:\windows\system32\uxtheme.dll
2010-02-12 04:33 . 2004-08-04 12:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 12:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
CODE
<pre>
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp .exe
c:\program files\Nokia\Nokia Music\nokiamusic .exe
c:\program files\O2CM-CE\O2 Connection Manager\tscui .exe
c:\program files\Skype\Phone\skype .exe
</pre>
((((((((((((((((((((((((((((( SnapShot@2010-04-17_09.41.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-27 09:39 . 2009-03-27 09:39 33664 c:\windows\system32\drivers\TsWlan.sys
- 2009-03-27 10:39 . 2009-03-27 10:39 33664 c:\windows\system32\drivers\TsWlan.sys
+ 2010-04-17 19:08 . 2010-04-17 19:08 10134 c:\windows\Installer\{4AA211BA-DB14-4895-AC77-EF4009144AFC}\ARPPRODUCTICON.exe
- 2010-03-09 17:59 . 2010-03-09 17:59 10134 c:\windows\Installer\{4AA211BA-DB14-4895-AC77-EF4009144AFC}\ARPPRODUCTICON.exe
+ 2010-04-17 19:08 . 2010-04-17 19:08 1482240 c:\windows\Installer\feca81.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-03-09 26100520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-10-20 340456]
"O2Start"="c:\program files\O2CM-CE\O2 Connection Manager\tscui.exe" [2009-06-05 2973696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BrowserChoice"="c:\windows\system32\browserchoice.exe" [2010-02-12 293376]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-823518204-1425521274-1801674531-500\Scripts\Logon\0\0]
"Script"=autorun.bat
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^WordWeb.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\WordWeb.lnk
backup=c:\windows\pss\WordWeb.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Yahoo! Widgets.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\Yahoo! Widgets.lnk
backup=c:\windows\pss\Yahoo! Widgets.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^YoWindow.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\YoWindow.lnk
backup=c:\windows\pss\YoWindow.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless Networking Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Belkin Wireless Networking Utility.lnk
backup=c:\windows\pss\Belkin Wireless Networking Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Radix MC-AS.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Radix MC-AS.lnk
backup=c:\windows\pss\Radix MC-AS.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-18 03:28 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-07-22 05:38 88361 ----a-r- c:\windows\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-01-04 04:15 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager]
2007-06-14 10:18 1282048 ----a-w- c:\windows\system32\wltray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-04-02 22:36 136176 ----atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 21:22 3739648 ----a-w- c:\program files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2003-10-02 06:19 118784 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2003-10-02 06:37 155648 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2009-09-17 09:50 32768 ----a-w- c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2004-10-01 08:46 262144 ----a-w- c:\progra~1\LAUNCH~1\LManager.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraAssistant]
2006-01-05 06:58 489472 ----a-w- c:\program files\Logitech\Video\CameraAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCameraService(E)]
2004-11-01 16:22 262144 ----a-w- c:\windows\system32\ElkCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
2006-01-05 07:15 73728 ----a-w- c:\program files\Logitech\Video\InstallHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2005-12-09 14:32 225280 ----a-w- c:\windows\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-03-29 23:46 1086856 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-05-26 15:36 4351216 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 --sh--w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 09:27 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NiwradSoft Welcome]
c:\windows\NiwradSoft Shell Pack\Tools\NS Welcome.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
c:\program files\Nokia\Nokia Music\NokiaMusic.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\O2Start]
2009-06-05 14:20 2973696 ----a-w- c:\program files\O2CM-CE\O2 Connection Manager\tscui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 09:57 1451520 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Qdage]
c:\windows\ahumuqujuzesec.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-03-09 09:02 26100520 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmileboxTray]
c:\documents and settings\Administrator\Application Data\Smilebox\SmileboxTray.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-07-27 09:01 68096 ----a-w- c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
c:\program files\Spybot - Search & Destroy\TeaTimer.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-30 08:42 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2004-08-12 07:12 684032 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2004-08-12 07:13 102400 ----a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
c:\program files\Common Files\Real\Update_OB\realsched.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Venturi Configurator]
c:\program files\Netbooster Client\Configurator\ventcfg.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipBuster]
c:\program files\VoipBuster.com\VoipBuster\VoipBuster.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"YahooAUService"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"wltrysvc"=2 (0x2)
"ServiceLayer"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NMIndexingService"=3 (0x3)
"MDM"=2 (0x2)
"McTaskManager"=2 (0x2)
"McShield"=2 (0x2)
"McAfeeFramework"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"gusvc"=2 (0x2)
"gupdate"=2 (0x2)
"Boonty Games"=3 (0x3)
"BlueSoleil Hid Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"d:\\Shared Folder\\Softwares\\Portable TeamViewer + Cracked Version [h33t] [Ahmed]\\TeamViewer.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [14/10/2009 20:18 36880]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 13:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/10/2009 18:39 19472]
S0 fhajeat;fhajeat; [x]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys --> c:\windows\system32\drivers\massfilter.sys [?]
S3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial;c:\windows\system32\drivers\hmemdm.sys [22/09/2009 09:10 88960]
S3 NdisWDM;Belkin Wireless G Plus USB Network Adapter Service;c:\windows\system32\drivers\NdisWDM.sys [15/09/2009 18:57 198144]
S3 TSWLAN;TsWlan Packet Driver;c:\windows\system32\drivers\TsWlan.sys [27/03/2009 10:39 33664]
S3 zteusbser;ZTE USB Device for Legacy Serial Communication;c:\windows\system32\drivers\zteusbser.sys [29/08/2009 15:08 100480]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [19/11/2009 06:26 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{67KLN5J0-4OPM-33WE-AAX5-34KC2A3453431}]
c:\setup\DATA\June.exe [N/A]
.
Contents of the 'Scheduled Tasks' folder
2010-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-19 05:26]
2010-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-19 05:26]
2010-04-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1425521274-1801674531-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-02 22:36]
2010-04-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-1425521274-1801674531-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-02 22:36]
2010-04-17 c:\windows\Tasks\User_Feed_Synchronization-{5F5B496E-2C48-4AAF-B147-48E0FDA2E7BA}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 16:23]
2010-04-17 c:\windows\Tasks\User_Feed_Synchronization-{E387758D-C605-41AC-8C93-4CDB3694854C}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 16:23]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.in/ig?hl=en&source=iglk/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = about:blank
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {E3961B02-FF7D-42DB-9B69-115E21E83B8B} = 82.132.136.103 82.132.136.102
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.co.in/s/v/58.09/uploader2.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\bujngir2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.in/ig?hl=en&source=iglk
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\documents and settings\Administrator\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-17 21:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-823518204-1425521274-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"659BD8E725A05FDCC64118EA787EAA2B534A94FABE"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e1,67,82,8d,3f,f6,c4,4f,aa,6c,17,\
"3A77B377802A4B6183DDE08FDE4AD9AF647A702826"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e1,67,82,8d,3f,f6,c4,4f,aa,6c,17,\
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ef,54,e1,71,e7,c7,c6,48,9b,1e,f1,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ef,54,e1,71,e7,c7,c6,48,9b,1e,f1,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
@Denied: (Full) (LocalSystem)
"OOBETimer"=hex:ff,d5,71,d6,8b,6a,8d,6f,d5,33,93,fd
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3528)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\BatteryBar\BatteryBar.dll
c:\program files\BatteryBar\BatteryBar.Utilities.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-04-17 21:12:39
ComboFix-quarantined-files.txt 2010-04-17 20:12
ComboFix2.txt 2010-04-17 17:25
ComboFix3.txt 2010-04-17 09:49
Pre-Run: 10,040,762,368 bytes free
Post-Run: 9,995,894,784 bytes free
- - End Of File - - BF33C9687F37EEDD070B0F3383F32A5A