ComboFix 10-07-13.05 - Robbie 07/14/2010 2:41.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2591 [GMT -5:00] Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\install.exe c:\windows.0\system32\kabaker.dll c:\windows.0\system32\msconfig.exe c:\windows.0\system32\srcr.dat . ((((((((((((((((((((((((( Files Created from 2010-06-14 to 2010-07-14 ))))))))))))))))))))))))))))))) . 2010-07-12 08:33 . 2010-07-12 08:33 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Mozilla 2010-07-12 08:17 . 2010-07-12 08:17 2568656 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe 2010-07-12 08:17 . 2010-07-14 04:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2010-07-12 01:59 . 2010-07-12 01:59 -------- d-----w- c:\program files\Java 2010-07-12 01:53 . 2010-07-12 01:53 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2010-07-12 01:38 . 2010-07-12 01:38 -------- d-----w- c:\program files\Common Files\Java 2010-07-11 22:01 . 2010-07-14 05:00 -------- d-----w- c:\program files\Steam 2010-07-11 08:02 . 2010-07-11 08:02 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe 2010-07-11 08:02 . 2010-07-11 08:02 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe 2010-07-11 08:02 . 2010-07-11 08:02 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe 2010-07-11 08:02 . 2010-07-11 08:02 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe 2010-07-11 08:02 . 2010-07-11 08:02 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe 2010-07-11 08:02 . 2010-07-11 08:02 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe 2010-07-11 08:02 . 2010-07-11 08:02 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe 2010-07-11 08:02 . 2010-07-11 08:02 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe 2010-07-11 08:02 . 2010-07-11 08:02 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe 2010-07-11 07:46 . 2010-07-11 07:46 503808 ----a-w- c:\documents and settings\Robbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-43ddd47d-n\msvcp71.dll 2010-07-11 07:46 . 2010-07-11 07:46 499712 ----a-w- c:\documents and settings\Robbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-43ddd47d-n\jmc.dll 2010-07-11 07:46 . 2010-07-11 07:46 348160 ----a-w- c:\documents and settings\Robbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-43ddd47d-n\msvcr71.dll 2010-07-11 07:46 . 2010-07-11 07:46 61440 ----a-w- c:\documents and settings\Robbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4970dcf3-n\decora-sse.dll 2010-07-11 07:46 . 2010-07-11 07:46 12800 ----a-w- c:\documents and settings\Robbie\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4970dcf3-n\decora-d3d.dll 2010-07-11 07:46 . 2010-07-12 01:59 411368 ----a-w- c:\windows.0\system32\deployJava1.dll 2010-07-11 07:31 . 2010-07-11 07:31 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure 2010-07-11 06:51 . 2010-07-11 06:51 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe 2010-07-11 06:49 . 2010-07-11 06:49 -------- d-----w- c:\documents and settings\Robbie\Application Data\Malwarebytes 2010-07-11 06:49 . 2010-04-29 20:39 38224 ----a-w- c:\windows.0\system32\drivers\mbamswissarmy.sys 2010-07-11 06:49 . 2010-07-11 06:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-07-11 06:49 . 2010-07-11 06:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-07-11 06:49 . 2010-04-29 20:39 20952 ----a-w- c:\windows.0\system32\drivers\mbam.sys 2010-07-10 17:42 . 2010-07-10 17:42 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE 2010-07-10 17:42 . 2010-07-10 17:42 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2010-07-10 17:42 . 2010-02-17 16:19 71960 ----a-w- c:\documents and settings\Robbie\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-npoctoshape.dll 2010-07-10 17:42 . 2010-02-17 16:19 420352 ----a-w- c:\documents and settings\Robbie\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-libOctoshapeClient.dll 2010-07-10 17:42 . 2010-02-17 16:19 124184 ----a-w- c:\documents and settings\Robbie\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-apoctoshape.dll 2010-07-10 17:41 . 2010-07-10 17:41 -------- d-sh--w- c:\documents and settings\Robbie\IETldCache 2010-07-10 17:36 . 2010-07-10 17:38 -------- dc-h--w- c:\windows.0\ie8 2010-07-08 05:46 . 2010-07-08 08:35 -------- d-----w- c:\program files\StarCraft II Beta enUS 13891 Installer . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-14 07:38 . 2010-03-15 04:57 -------- d-----w- c:\program files\Common Files\Akamai 2010-07-14 07:35 . 2008-12-19 03:04 -------- d-----w- c:\documents and settings\Robbie\Application Data\DNA 2010-07-14 05:00 . 2010-06-09 20:53 -------- d-----w- c:\documents and settings\Robbie\Application Data\Skype 2010-07-14 05:00 . 2008-12-19 03:04 -------- d-----w- c:\program files\DNA 2010-07-14 04:15 . 2008-09-20 09:58 102400 ----a-w- c:\windows.0\DUMPb94d.tmp 2010-07-14 04:08 . 2010-06-09 20:56 -------- d-----w- c:\documents and settings\Robbie\Application Data\skypePM 2010-07-14 02:23 . 2010-01-22 06:28 0 ----a-w- c:\documents and settings\Robbie\Local Settings\Application Data\prvlcl.dat 2010-07-13 18:29 . 2008-09-21 02:08 -------- d-----w- c:\program files\World of Warcraft 2010-07-11 08:10 . 2010-04-11 07:10 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll 2010-07-11 08:10 . 2010-04-11 07:09 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX 2010-07-11 08:02 . 2008-09-21 16:52 -------- d-----w- c:\program files\DivX 2010-07-11 08:01 . 2010-04-11 07:10 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe 2010-07-11 08:01 . 2010-04-11 07:10 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll 2010-07-11 06:35 . 2008-09-20 02:27 12528 ----a-w- c:\documents and settings\Robbie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-07-10 19:03 . 2010-04-12 19:36 262457 ----a-w- c:\documents and settings\Robbie\Application Data\Sony Online Entertainment\npsoeact.dll 2010-07-10 19:03 . 2010-04-12 19:36 -------- d-----w- c:\documents and settings\Robbie\Application Data\Sony Online Entertainment 2010-07-10 19:01 . 2008-09-20 02:18 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-07-08 17:57 . 2010-04-26 02:18 -------- d-----w- c:\program files\StarCraft II Beta 2010-07-08 17:10 . 2008-09-20 02:36 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment 2010-06-22 17:53 . 2009-08-20 01:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment 2010-06-09 20:56 . 2010-06-09 20:56 56 ---ha-w- c:\windows.0\system32\ezsidmv.dat 2010-06-09 20:53 . 2010-06-09 20:53 -------- d-----r- c:\program files\Skype 2010-06-09 20:53 . 2010-06-09 20:53 -------- d-----w- c:\program files\Common Files\Skype 2010-06-09 20:53 . 2010-06-09 20:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2010-06-02 19:00 . 2009-12-29 19:51 242896 ----a-w- c:\windows.0\system32\drivers\avgtdix.sys 2010-06-02 19:00 . 2009-12-29 19:51 29584 ----a-w- c:\windows.0\system32\drivers\avgmfx86.sys 2010-05-28 17:50 . 2010-05-24 17:57 -------- d-----w- c:\documents and settings\Robbie\Application Data\runic games 2010-05-28 17:48 . 2010-05-24 17:46 -------- d-----w- c:\program files\Runic Games 2010-05-28 17:45 . 2008-09-21 06:16 -------- d-----w- c:\documents and settings\Robbie\Application Data\Azureus 2010-05-28 17:34 . 2010-05-28 17:34 8463808 ----a-w- c:\documents and settings\Robbie\Application Data\Azureus\tmp\AZU46359.tmp\Vuze_4.4.0.4_win32.exe 2010-05-28 10:32 . 2010-05-28 10:32 503808 ----a-w- c:\documents and settings\Robbie\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5861bdb8-n\msvcp71.dll 2010-05-28 10:32 . 2010-05-28 10:32 499712 ----a-w- c:\documents and settings\Robbie\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5861bdb8-n\jmc.dll 2010-05-28 10:32 . 2010-05-28 10:32 348160 ----a-w- c:\documents and settings\Robbie\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5861bdb8-n\msvcr71.dll 2010-05-16 17:46 . 2010-05-16 17:46 -------- d-----w- c:\program files\CAPCOM 2010-05-16 17:46 . 2010-05-16 17:46 -------- d-----w- c:\program files\MSBuild 2010-05-16 17:45 . 2010-05-16 17:45 65624 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2010-05-16 17:44 . 2010-05-16 17:44 -------- d-----w- c:\program files\Reference Assemblies 2010-05-16 17:43 . 2010-05-16 17:43 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE 2010-04-21 16:16 . 2009-06-06 20:51 71960 ----a-w- c:\documents and settings\Robbie\Application Data\Mozilla\Plugins\npoctoshape.dll 2008-12-19 19:51 . 2008-12-19 16:59 1095193104 ----a-w- c:\program files\MSSetupv63.exe . ------- Sigcheck ------- [-] 2008-04-28 . 68F06FE0021B01E670AF37B8C5964FDF . 361344 . . [5.1.2600.5512] . . c:\windows.0\system32\drivers\tcpip.sys c:\windows.0\System32\drivers\beep.sys ... is missing !! c:\windows.0\System32\wscntfy.exe ... is missing !! c:\windows.0\System32\regsvc.dll ... is missing !! . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392] "CreativeTaskScheduler"="c:\program files\Creative\Shared Files\CTSched.exe" [2006-11-17 53341] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032] "Octoshape Streaming Services"="c:\documents and settings\Robbie\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168] "Steam"="c:\program files\Steam\Steam.exe" [2010-07-11 1238352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 55824] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696] "RTHDCPL"="RTHDCPL.EXE" [2008-11-07 17421824] "MsmqIntCert"="mqrt.dll" [2008-04-14 177152] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "VolPanel"="c:\program files\Creative\USB Headsets\Volume Panel\VolPanlu.exe" [2008-05-05 221300] "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-02 2065248] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_3"="advpack.dll" [2009-03-08 128512] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-19 784912] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoResolveTrack"= 1 (0x1) "NoSMConfigurePrograms"= 1 (0x1) [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoSMHelp"= 1 (0x1) "NoResolveTrack"= 1 (0x1) "NoSMConfigurePrograms"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2010-03-13 13:20 12464 ----a-w- c:\windows.0\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn] 2007-11-15 14:10 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Ventrilo\\Ventrilo.exe"= "c:\\Program Files\\DNA\\btdna.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"= "c:\\WINDOWS.0\\system32\\mqsvc.exe"= "c:\\Program Files\\AVG\\AVG9\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "56793:TCP"= 56793:TCP:Pando Media Booster "56793:UDP"= 56793:UDP:Pando Media Booster R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows.0\system32\drivers\avgldx86.sys [12/29/2009 2:51 PM 216200] R1 AvgTdiX;AVG Free Network Redirector;c:\windows.0\system32\drivers\avgtdix.sys [12/29/2009 2:51 PM 242896] R1 BIOS;BIOS;c:\windows.0\system32\drivers\BIOS.sys [9/19/2008 9:14 PM 13696] R2 Akamai;Akamai NetSession Interface;c:\windows.0\System32\svchost.exe -k Akamai [4/13/2008 10:42 PM 14336] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [3/13/2010 8:20 AM 916760] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/13/2010 8:20 AM 308064] R3 skfilt;skfilt;c:\windows.0\system32\drivers\skfilt.SYS [4/18/2009 3:33 PM 1670016] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [4/18/2009 3:32 PM 79360] S3 XDva220;XDva220;\??\c:\windows.0\system32\XDva220.sys --> c:\windows.0\system32\XDva220.sys [?] S3 XDva337;XDva337;\??\c:\windows.0\system32\XDva337.sys --> c:\windows.0\system32\XDva337.sys [?] S4 sptd;sptd;c:\windows.0\system32\drivers\sptd.sys [6/20/2009 11:47 PM 721904] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = FF - ProfilePath - c:\documents and settings\Robbie\Application Data\Mozilla\Firefox\Profiles\n4cw6yw1.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.youtube.com/ FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll FF - plugin: c:\documents and settings\Robbie\Application Data\Mozilla\plugins\npoctoshape.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPHoldemFireLauncher.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMFireLauncher.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPPGWrap.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . - - - - ORPHANS REMOVED - - - - HKLM-Run-Turbine Download Manager Tray Icon - c:\program files\Turbine\Turbine Download Manager\TurbineDownloadManagerIcon.exe AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-07-14 02:45 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8c,19,00,ce,3e,19,03,49,99,f7,d3,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8c,19,00,ce,3e,19,03,49,99,f7,d3,\ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(720) c:\windows.0\system32\Ati2evxx.dll c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll c:\program files\common files\logishrd\bluetooth\LBTServ.dll . Completion time: 2010-07-14 02:46:25 ComboFix-quarantined-files.txt 2010-07-14 07:46 Pre-Run: 223,901,249,536 bytes free Post-Run: 227,227,693,056 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0 [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0="Microsoft Windows XP Professional" /noexecute=optin /fastdetect multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - FBF8D58004D642CECC68C4322908B2FA