ComboFix txt:
ComboFix 09-02-15.01 - Nick 2009-02-16 10:26:24.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.658 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nick\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\docume~1\Nick\Desktop\torrential\Winzip 11 pro\keygen.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Nick\Desktop\torrential\Winzip 11 pro\keygen.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-16 to 2009-02-16 )))))))))))))))))))))))))))))))
.
2009-02-15 21:11 . 2009-02-15 21:13 d——– C:\Rooter$
2009-02-15 19:45 . 2009-02-15 19:57 d——– C:\Worknow
2009-02-15 04:06 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-15 04:06 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-15 02:51 . 2009-02-15 02:51 664 –a—— c:\windows\system32\d3d9caps.dat
2009-02-14 17:08 . 2009-02-14 17:26 d——– c:\documents and settings\All Users\Application Data\Electronic Arts
2009-02-14 17:03 . 2009-02-15 19:52 d——– c:\windows\system32\inf
2009-02-10 16:35 . 2009-02-10 16:35 0 –a—— c:\windows\nsreg.dat
2009-02-04 20:24 . 2009-02-04 20:24 d——– c:\documents and settings\Nick\Application Data\Maple
2009-02-04 20:16 . 2009-02-04 20:16 d——– C:\watcom-1.3
2009-02-04 20:16 . 2009-02-04 20:16 212,992 –a—— c:\windows\system32\WMIMPLEX.dll
2009-02-04 20:16 . 2009-02-04 20:16 40,960 –a—— c:\windows\system32\maplec.dll
2009-02-04 20:16 . 2009-02-04 20:16 20,480 –a—— c:\windows\system32\maplecompat.dll
2009-02-04 20:14 . 2009-02-04 20:14 d–h—– c:\program files\Zero G Registry
2009-02-04 20:14 . 2009-02-04 20:17 d——– c:\program files\Maple 12
2009-02-04 20:13 . 2009-02-04 20:13 d–h—– c:\documents and settings\Nick\InstallAnywhere
2009-01-31 12:16 . 2009-01-31 12:16 10,520 –a—— c:\windows\system32\avgrsstx.dll
2009-01-23 15:52 . 2008-10-16 14:06 268,648 –a—— c:\windows\system32\mucltui.dll
2009-01-23 15:52 . 2008-10-16 14:06 208,744 –a—— c:\windows\system32\muweb.dll
2009-01-23 15:52 . 2008-10-16 14:06 27,496 –a—— c:\windows\system32\mucltui.dll.mui
2009-01-23 02:19 . 2009-01-23 02:19 d——– c:\program files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-16 02:19 3,609 –sha-w c:\windows\system32\mmf.sys
2009-02-15 17:14 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-15 16:16 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-15 06:52 ——— d—–w c:\program files\BitTorrent
2009-02-14 22:32 ——— d—–w c:\program files\Electronic Arts
2009-02-14 19:51 ——— d—–w c:\documents and settings\Nick\Application Data\uTorrent
2009-02-03 03:58 ——— d—–w c:\program files\Wolverine Studios
2009-01-31 17:16 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-24 08:13 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-24 08:01 ——— d—–w c:\program files\Microsoft Works
2009-01-17 02:35 3,594,752 ——w c:\windows\system32\dllcache\mshtml.dll
2009-01-15 23:03 ——— d—–w c:\program files\Java
2009-01-14 17:22 ——— d—–w c:\documents and settings\Nick\Application Data\SPORE
2009-01-14 17:20 107,888 —-a-w c:\windows\system32\CmdLineExt.dll
2009-01-14 17:20 ——— d–h–r c:\documents and settings\Nick\Application Data\SecuROM
2009-01-13 01:39 2,802,580 —-a-w c:\program files\PFCSetup1.0.223.exe
2009-01-13 01:20 ——— d—–w c:\documents and settings\Nick\Application Data\BitTorrent
2009-01-09 17:26 ——— d—–w c:\program files\uTorrent
2009-01-08 14:52 ——— d—–w c:\documents and settings\Nick\Application Data\SPORE Creature Creator
2009-01-08 14:47 ——— d—–w c:\program files\DominateGame
2008-12-25 09:48 ——— d—–w c:\program files\WinPcap
2008-12-23 19:43 ——— d—–w c:\program files\music
2008-12-19 09:10 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ——w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 10:57 333,952 ——w c:\windows\system32\dllcache\srv.sys
2008-11-07 22:09 536,811 —-a-w c:\program files\ie-spyad.exe
2008-11-07 22:08 2,062,665 —-a-w c:\program files\spywareguardsetup.exe
2008-11-07 22:07 2,869,536 —-a-w c:\program files\spywareblastersetup41.exe
2008-10-23 16:17 18,829,383 —-a-w c:\program files\tibia831.exe
2008-08-14 01:59 232,904,074 —-a-w c:\program files\ootp9setup.exe
2008-07-07 13:34 24,234,968 —-a-w c:\program files\setupeng.exe
2008-07-04 19:01 15,336,856 —-a-w c:\program files\jre-6u10-beta-windows-i586-p.exe
2008-07-04 18:50 50,688 —-a-w c:\program files\ATF-Cleaner.exe
2008-06-26 21:45 9,722,720 —-a-w c:\program files\spybotsd152.exe
2008-06-23 02:32 49,384,056 —-a-w c:\program files\avg_free_stf_all_8_100a1323.exe
2008-06-21 00:07 5,632 –sha-w c:\program files\Thumbs.db
2008-05-18 07:37 18,289,392 —-a-w c:\program files\DivXInstaller.exe
2007-11-21 22:55 6,637,432 —-a-w c:\program files\dMC-R12.3-Ref-Registered.exe
2007-11-13 16:01 13,871,095 —-a-w c:\program files\schedulemaker.zip
2007-06-15 05:35 9,690,219 —-a-w c:\program files\mws094f.exe
2007-06-14 16:29 380,208,128 —-a-w c:\program files\mtgodl2.exe
2007-03-18 23:57 26,583,420 —-a-w c:\program files\Geneforge4Demo.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-02-15_19.55.28.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2009-02-15 20:24:37 59,652 —-a-w c:\windows\system32\perfc009.dat
+ 2009-02-16 02:24:22 59,652 —-a-w c:\windows\system32\perfc009.dat
- 2009-02-15 20:24:37 395,580 —-a-w c:\windows\system32\perfh009.dat
+ 2009-02-16 02:24:22 395,580 —-a-w c:\windows\system32\perfh009.dat
+ 2009-02-16 02:19:53 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_2bc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-09 851968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-06 81920]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-05-09 1392640]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"NVHotkey"="nvHotkey.dll" [2007-06-06 c:\windows\system32\nvhotkey.dll]
c:\documents and settings\Nick\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-01 50688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 12:16 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\a.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\matrix31290.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpa.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpb.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpc.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
–a—— 2006-08-17 10:00 1116920 c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
–a—— 2006-11-05 12:22 221184 c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\mtg\\Magic\\Manalink.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Maple 12\\jre\\bin\\maple.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-11-02 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-31 298264]
R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2007-12-09 2560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-12-08 24652]
S2 MSMQSVC;Message Queuing Service;c:\windows\system32\mqsv32.exe –> c:\windows\system32\mqsv32.exe [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
S3 xbreader;MaxDrive XBox Driver (xbreader.sys);c:\windows\system32\drivers\xbreader.sys [2001-01-02 19677]
.
Contents of the 'Scheduled Tasks' folder
2009-02-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://yahoo.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: Crawler Search
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Nick\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-yahtzee/zylomplayer.cab
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\5ei8gwd3.default\
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-16 10:29:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-267048546-3394276723-1217438979-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{487E2DE6-47C1-82BA-77C5-BBCA30098FFF}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abiloomoglgjpidfgnnkhadhplebcckbfe"=hex:61,61,00,00
"bbiloomoglgjpidfgnmkkafcdennaabjgdal"=hex:61,61,00,00
[HKEY_USERS\S-1-5-21-267048546-3394276723-1217438979-1006\Software\SecuROM\License information*]
"datasecu"=hex:8c,f8,da,f0,d7,f1,ea,e5,2b,9c,4e,6b,89,01,7d,1b,6d,01,b3,64,9d,
2e,81,17,6b,c0,b5,fe,f4,97,db,ca,7a,8b,7f,c2,22,c1,ef,85,83,1b,0a,69,93,14,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847]
"1"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,86,2b,9b,9b,f3,96,a9,
e9
"2"=hex:05,83,26,a9,dc,b6,17,45,de,2e,f0,41,a5,95,91,56,fe,07,ca,23,63,6c,c8,
df,a0,cb,29,a7,07,62,23,54
"3"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,39,39,6a,6e,1d,99,29,
0e,9a,9e,61,33,16,37,68,38,ee,25,f6,f1,91,9f,21,a9,58,ec,19,f6,96,30,78,09
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\13D3AF07D4AFC792B9BD996AC108D6B5]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,15,18,bd,aa,84,24,4a,2c
"2"=hex:ed,a7,cb,4f,94,68,06,bf
"3"=hex:cf,54,22,5c,b2,32,a3,f4,13,e2,99,75,72,f5,de,7b,7f,a5,9e,59,7e,5c,50,
44,b2,68,4e,b6,6c,25,93,09,5a,dc,75,c8,13,9f,30,27,3a,76,73,04,ed,44,fc,f6,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,0a,4e,8a,24,18,b0,7f,
17,12,df,d0,2e,5e,18,49,90,2f,a8,42,c9,bd,28,bd,03,a4,ed,67,8d,07,a7,03,f5,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,91,e8,a9,4b,f4,c5,51,
df,c7,9b,39,cf,09,f9,b0,9b,ad,64,39,7b,c1,66,34,b7,bd,5f,73,03,3f,65,09,a8,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:65,4e,c5,8b,92,5b,93,b4,84,b4,53,c9,0f,64,69,91,d5,cf,39,d2,75,99,08,
27,e6,19,a2,b5,8e,b8,6c,07,ee,9f,43,2e,79,b7,48,19,56,03,46,c5,47,47,5e,70,\
"13"=hex:f8,b3,e2,65,7c,0d,e7,15,ac,0e,57,02,77,42,98,d3,b2,2e,ba,2f,10,0d,5f,
a0
"14"=hex:0d,7e,11,86,a7,43,bb,80,cb,84,d6,9b,52,2b,0b,b6
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:fc,1b,0f,70,de,f5,b6,81,51,f6,6c,be,8c,f4,09,4f
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:ea,3d,b9,9a,7b,92,6d,f6,6d,47,d0,e6,0f,f6,f3,8d,61,dc,12,97,34,e6,62,
83,72,96,f8,4a,e7,dc,ff,05,8e,96,13,15,e6,04,c8,3e,b1,5b,d5,2e,13,82,02,68,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\CC7B909C85BC507A2CDBC39B09A1A69B]
"1"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,3c,a9,5c,7c,76,d5,a4,ad
"2"=hex:4c,00,a2,b4,d4,72,2e,96
"3"=hex:8f,79,e9,fb,03,cd,2a,03,2d,0f,cb,cd,74,1e,fc,f9,c7,60,c5,d9,0d,89,2d,
e1,ac,91,a2,29,00,7d,b8,b0,5b,db,a3,bb,64,f6,e7,69,15,09,37,66,19,58,5e,67,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:6a,02,e3,17,35,aa,4f,41,58,69,23,a3,81,f4,a8,0e,57,fe,fa,3f,01,c1,2c,
1c,5e,e5,91,0b,2f,7e,4c,e7,32,04,0f,a6,73,b5,06,c7,40,57,27,33,7c,b4,61,2d,\
"7"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,5c,6c,8a,b0,95,8d,88,
02,5c,f2,b7,9f,8e,b8,9a,b3,47,aa,06,9a,55,51,85,6f,7c,bd,b8,83,41,dc,29,77,\
"8"=hex:63,5a,d7,1b,b1,d4,18,46,9d,8a,b3,da,f7,a8,9d,ab,87,a3,2a,ca,13,f6,e4,
c5,41,b1,c1,29,7c,b2,b7,13,8f,1c,0d,5f,4b,3c,0f,fb
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:28,d5,32,14,d2,aa,ea,92,15,12,99,8b,12,63,43,80,74,95,f1,5d,0b,3d,c7,
a4,18,ad,c2,8f,ac,bb,a4,80,d2,74,e3,27,c9,ce,dd,39,92,fa,e1,a3,17,5c,47,2e,\
"13"=hex:0b,d1,9c,3a,64,a8,b5,e9,8c,33,4e,cd,6a,da,75,60,fc,13,0a,57,f6,08,bb,
c3
"14"=hex:0d,f5,4e,44,fe,9e,11,67,d4,ec,25,e7,d8,da,e7,24
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:f7,77,5c,72,03,28,57,bd,09,30,5c,5d,2b,ad,12,bd
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:ec,c6,8f,95,1e,e3,3a,a1,ca,92,d1,4c,08,18,ed,8e,3d,fe,1c,4e,f7,7d,db,
77,ee,48,d8,f6,7f,4c,f8,3e,88,68,c2,6c,63,e6,3e,8a,a3,6d,7d,b9,5b,6f,f1,9a,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,44,f7,88,8f,b5,4c,1b,f9,3e,da,c2,d2,eb,69,77,32,91,02,8c,84,09,5e,d2,d3
"2"=hex:f1,df,16,de,80,08,0e,2a,d1,38,b5,6f,94,ca,dc,d2,b3,e8,d2,40,6c,6f,61,
5e,d2,5e,7f,21,14,b5,b2,29
"3"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,f2,55,76,c8,bc,53,92,25,3f,d1,b6,bc,00,35,73,43,96,90,79,f6,5b,97,35,47,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F\3323E31CCF524E1933A08EFC0405BBBB]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,ce,d6,da,a0,ab,80,e1,24
"2"=hex:cf,77,c8,3e,ea,da,16,30
"3"=hex:a8,94,fb,1d,a8,04,93,f6,27,ba,9f,0c,1e,f4,d0,fa,15,d2,13,e7,60,58,bf,
34,53,b1,e8,5a,1a,a8,42,b7,2d,fd,1c,80,83,b7,98,df,e2,e7,5e,a6,54,59,11,31,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,9f,82,d5,6a,b3,ab,12,e7,1d,59,ee,f8,65,a3,77,fa,21,98,53,17,b3,88,55,98,\
"7"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,e5,98,6b,ad,2b,ca,86,50
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,6b,8d,dd,0b,84,72,f6,
f2,3d,a6,3c,a0,07,7d,db,f3,88,a8,6c,3f,5c,60,94,94,89,77,0c,65,96,1c,ff,8e,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"10"=hex:1c,bd,ea,59,8e,8d,e1,5f
"11"=hex:7d,ba,74,77,fe,09,92,36
"12"=hex:a0,df,59,f4,e0,d8,0a,fb,cc,26,53,e2,71,64,8d,71,ba,4e,45,28,8c,cb,ad,
f4,ad,a6,4b,f6,0b,36,45,63,80,07,b3,29,1a,d2,24,19,0d,d9,f2,62,b0,4d,44,2b,\
"13"=hex:dc,57,f7,3b,8a,43,9d,48,6e,d4,56,e7,f9,b4,6f,02,ef,9f,db,da,f9,28,c9,
17
"14"=hex:4e,63,05,ff,92,a2,5b,c8
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:55,3b,68,6f,03,fb,52,52,1d,27,1b,a1,9b,47,55,0a
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:e8,cc,f6,66,72,7c,fe,c6,e4,b5,3c,4a,a8,61,22,91,aa,4c,e9,68,ac,5f,e5,
82,00,ba,60,5d,62,f0,d8,db,11,10,68,38,36,5d,7f,2d,b3,37,f5,6d,42,af,fb,27,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(928)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-02-16 10:31:58
ComboFix-quarantined-files.txt 2009-02-16 15:31:33
ComboFix2.txt 2009-02-16 00:57:07
Pre-Run: 58,105,802,752 bytes free
Post-Run: 58,145,996,800 bytes free
Current=4 Default=4 Failed=1 LastKnownGood=2 Sets=1,2,3,4
315 — E O F — 2009-02-12 17:11:48
HiJackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:21 AM, on 2/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Nick\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5071202
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [dscactivate] "%ProgramFiles%\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Nick\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://152.1.164.197/activex/AxisCamControl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} (FamilyFeud Control) - http://www.worldwinner.com/games/v47/famil…/familyfeud.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Message Queuing Service (MSMQSVC) - Unknown owner - C:\WINDOWS\system32\mqsv32.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
–
End of file - 7811 bytes