ComboFix 09-03-28.06 - James 2009-03-29 15:31:57.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2039.1285 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\James\Desktop\CFScript.txt.txt
* Created a new restore point
FILE ::
c:\windows\system32\ropfnqz.exe
.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-29 )))))))))))))))))))))))))))))))
.
2009-03-27 19:24 . 2009-03-27 19:24 264,870,366 –a—— c:\windows\MEMORY.DMP
2009-03-23 20:16 . 2009-03-23 20:16 d——– c:\users\James\AppData\Roaming\vlc
2009-03-11 15:59 . 2007-12-12 14:12 233,472 –a—— c:\windows\System32\BtwRSupport.dll
2009-03-11 15:59 . 2007-12-12 14:12 80,936 –a—— c:\windows\System32\drivers\btwavdt.sys
2009-03-11 15:59 . 2007-12-12 14:12 80,424 –a—— c:\windows\System32\drivers\btwaudio.sys
2009-03-11 15:59 . 2007-12-12 14:12 16,168 –a—— c:\windows\System32\drivers\btwrchid.sys
2009-03-11 15:58 . 2009-03-11 15:58 d——– c:\windows\System32\es-MX
2009-03-11 15:58 . 2009-03-11 15:58 d——– c:\windows\System32\es-AR
2009-03-11 15:38 . 2008-02-29 17:07 54,824 ——— c:\windows\System32\agrsmdel.exe
2009-03-11 15:37 . 2009-03-11 15:37 d——– c:\windows\Options
2009-03-11 15:34 . 2009-03-11 15:34 d——– c:\windows\System32\no-NO
2009-03-11 15:26 . 2009-03-11 15:26 d——– C:\Intel
2009-03-11 15:04 . 2006-01-12 15:52 1,904 ——— c:\windows\System32\SetupBD.din
2009-03-11 15:03 . 2007-09-27 18:28 12,800 –a—— c:\windows\HPNICVersion.dll
2009-03-11 12:48 . 2008-12-16 04:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-11 12:48 . 2009-02-09 04:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-11 12:48 . 2008-11-27 05:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-11 12:48 . 2008-12-16 06:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-11 12:48 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-11 12:48 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\dxmasf.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 14:34 ——— d—–w c:\programdata\Kontiki
2009-03-29 08:41 ——— d—–w c:\programdata\Google Updater
2009-03-28 19:23 ——— d—–w c:\users\James\AppData\Roaming\uTorrent
2009-03-25 17:25 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-25 17:25 ——— d—–w c:\program files\Hewlett-Packard
2009-03-18 07:59 ——— d—–w c:\users\James\AppData\Roaming\Vso
2009-03-15 13:11 ——— d—–w c:\programdata\Roxio
2009-03-11 15:05 ——— d—–w c:\program files\Windows Mail
2009-03-11 15:02 ——— d—–w c:\users\James\AppData\Roaming\Hewlett-Packard
2009-03-11 14:37 ——— d—–w c:\users\James\AppData\Roaming\Hewlett Packard
2009-03-11 14:20 ——— d—–w c:\program files\Analog Devices
2009-03-11 14:06 ——— d—–w c:\programdata\Hewlett-Packard
2009-03-10 19:41 ——— d—–w c:\program files\Sports Interactive
2009-03-05 11:29 16,648 —-a-w c:\windows\Help\OEM\scripts\HC_ProtectSmartPatch.exe
2009-02-28 17:38 ——— d—–w c:\users\James\AppData\Roaming\BraCa_Soft
2009-02-28 17:27 ——— d—–w c:\program files\Free Download Manager
2009-02-28 17:25 ——— d—a-w c:\programdata\TEMP
2009-02-28 15:55 ——— d—–w c:\users\James\AppData\Roaming\LimeWire
2009-02-10 20:19 ——— d—–w c:\program files\Kontiki
2009-02-10 20:19 ——— d—–w c:\program files\Channel4
2009-02-10 20:18 ——— d—–w c:\programdata\Channel4
2009-01-30 17:24 14,600 —-a-w c:\windows\Help\OEM\scripts\HC_InstallHPHC.exe
2009-01-29 19:23 ——— d—–w c:\program files\Activision
2009-01-15 06:11 827,392 —-a-w c:\windows\System32\wininet.dll
2008-10-04 10:26 174 –sha-w c:\program files\desktop.ini
2008-06-23 16:07 47,360 —-a-w c:\users\James\AppData\Roaming\pcouffin.sys
2008-06-14 00:07 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2008-06-14 00:07 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008061420080615\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-29_10.24.49.33 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-29 08:40:44 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 09:24:25 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 09:24:25 262,144 —ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-29 08:40:39 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 09:24:20 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2009-03-29 09:19:36 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-29 14:22:46 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-29 09:19:36 65,536 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-29 14:22:46 65,536 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-29 09:19:36 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-29 14:22:46 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-19 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-20 266497]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-03-14 54832]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-07 833072]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-02-21 1183744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-04 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-04 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-04 133656]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ST Recovery Launcher"="c:\windows\SMINST\launcher.exe" [2007-06-06 44168]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-12-04 727592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
–a—— 2007-02-21 15:14 1183744 c:\program files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-03-14 12:43 83608 c:\program files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-06-19 19:49 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
–a—— 2007-05-23 11:00 192512 c:\program files\InterVideo\DVD Check\DVDCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1408827420-3023802417-3614498867-1006]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DE3F1BC4-50BB-4C6F-93EB-A5783DF3426F}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{1288F1AD-2AF2-41E8-8581-85E5C9AA7898}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{B3EA6666-D1E3-4BE6-A96E-CAC412AE3F11}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{81FBD5EA-20D7-4A7B-84DB-199C0A6F486C}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{BD1A509A-4378-4663-87D3-E0CAD361D777}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"{A03D27F0-9EFD-4E49-979E-33AD9A6B8756}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{B1DC532B-4BE3-49D3-AD3B-6B33469D9149}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{879E0625-7B87-4706-8A3D-752B578DE69E}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{3C7855D2-404E-4AA4-876E-21374994D369}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{26A402A8-E076-4B5F-A0FD-4432F8BC98C4}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{812A05BB-039E-40B1-B892-36C478E1D61E}"= c:\program files\Cyberlink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{F3B3668D-344E-4041-856E-1DE18F04132F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{11D95C54-86F2-4C3B-8256-779549A2C5C5}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{C7CACFA6-3D1C-4CB8-B6CB-B4126AFC14AB}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{904EAE78-54AB-43CD-B8CA-AD4BCF568F01}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{94619F90-0098-4FA4-8034-901563BF7C92}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{8DE963EC-F76F-4C8E-8983-F1367EB17938}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"{D3E845FC-8226-4CE9-B2A3-2D8BEDCF144E}"= UDP:c:\program files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"{3FDD37D8-8BBE-4EC1-86E2-27B42251C428}"= TCP:c:\program files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"TCP Query User{CA1BE92A-DF6B-40A1-A07A-5987E1257488}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{F9E6C729-0CCB-40B7-BBFA-C751035347D2}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"TCP Query User{70D7C39C-EC2E-4F2E-A867-69F41714A14F}c:\\program files\\uusee\\uuseeplayer.exe"= UDP:c:\program files\uusee\uuseeplayer.exe:UUPlayer
"UDP Query User{4128B5A2-BE18-45C4-A9FC-1CE4643636B4}c:\\program files\\uusee\\uuseeplayer.exe"= TCP:c:\program files\uusee\uuseeplayer.exe:UUPlayer
"{01030978-2F5B-4FD4-B1E7-F605F054C36A}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{0B15CCD5-4E6D-4E33-A9C0-BA8E1BBB2308}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{22C3B6E7-2F72-4525-A26F-F9CF0697B6B6}"= UDP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{674AAFDB-BFA2-474B-BD71-506CAC65F59D}"= TCP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{56D61AB5-1C3A-47F7-86DC-339584B40329}"= UDP:3724:Blizzard Downloader: 3724
"TCP Query User{B3CA796F-1889-48AC-8B09-3B16E359D8B1}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8E14172A-23E1-4CDD-9607-924663ACD682}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{B2280B7F-CD33-4D79-A138-7403DF85C8ED}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C9FB674F-19C6-4E01-B5C6-67BD2119FCF7}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{EA5CA11A-D30B-4BB8-9B85-7AF311514B55}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{EB2E103F-66A1-48CF-AA9F-0EF749CA15B4}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{FA322D19-1A2F-4ED3-997D-2EEF8980953F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{5CDCE150-87EF-4307-BF17-E00FB6CBE0D1}"= UDP:c:\program files\Curse\CurseClient.exe:Curse Client
"{8A1767AF-8468-4366-9C0D-CE026FF376CF}"= TCP:c:\program files\Curse\CurseClient.exe:Curse Client
"{22610662-2A78-4A0C-A079-6E610C64029A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{222BFFF0-542C-4D0F-B531-B1D8A09DA3A0}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{3FD2E66A-B65B-4A3C-BB67-2B6BC7FC0290}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009 Demo\fm.exe:Football Manager 2009 Demo
"{EE2B182E-23DA-4F69-8474-C71BA7207C1C}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009 Demo\fm.exe:Football Manager 2009 Demo
"{6891F999-401A-495B-B088-9947CA8747D6}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{5A83D648-5D55-4552-B09B-EA20B6B96F5B}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"TCP Query User{8232B7EE-6D77-4E88-AA7C-3841F68221E8}c:\\users\\james\\desktop\\iexplore.exe"= UDP:c:\users\james\desktop\iexplore.exe:iexplore.exe
"UDP Query User{C00B7F16-F19B-4ABA-99B2-CDEE8F98B55B}c:\\users\\james\\desktop\\iexplore.exe"= TCP:c:\users\james\desktop\iexplore.exe:iexplore.exe
"{1B250390-287D-494F-9AD1-C4F93F463E29}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{F7C82CE3-1F57-4504-839C-ECD60CE261CC}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{7771161D-4066-4266-BC73-E66076B5AB7E}c:\\program files\\kontiki\\khost.exe"= UDP:c:\program files\kontiki\khost.exe:Delivery Manager
"UDP Query User{627E00CA-46A3-4414-9524-B53C04383024}c:\\program files\\kontiki\\khost.exe"= TCP:c:\program files\kontiki\khost.exe:Delivery Manager
"{6BF78CB7-EFC6-4D5C-A0D9-1533429EFBBB}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{9BC99080-189F-4D50-A001-19265CF71C19}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{E4026D65-2359-4C0E-86CE-EEFD0F3C57F0}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009 Beta\fm.exe:Football Manager 2009 Demo
"{2FDE9B55-66EC-43D2-B3FF-A3B1CE0E6C69}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009 Beta\fm.exe:Football Manager 2009 Demo
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\uusee\\UUSeePlayer.exe"= c:\program files\uusee\UUSeePlayer.exe:*:Enabled:UUPlayer
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\
000.fcl [2007-09-19 21:37:48 41456]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2007-12-11 540448]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-06-17 810320]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2006-11-02 167936]
S3 DAMDrv;DAMDrv;c:\windows\System32\drivers\DAMDrv.sys [2007-12-11 30008]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\System32\flcdlock.exe [2007-06-08 172131]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-03-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 19:02]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = about:blank
IE: Download all with Free Download Manager
IE: Download selected with Free Download Manager
IE: Download video with Free Download Manager
IE: Download with Free Download Manager
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-29 15:34:57
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(1104)
c:\windows\system32\btmmhook.dll
.
Completion time: 2009-03-29 15:37:31
ComboFix-quarantined-files.txt 2009-03-29 14:37:25
ComboFix2.txt 2009-03-29 09:26:50
Pre-Run: 41,559,138,304 bytes free
Post-Run: 41,540,943,872 bytes free
233 — E O F — 2009-03-26 19:00:13
GMER 1.0.15.14966 -
http://www.gmer.net
Rootkit scan 2009-03-29 15:48:38
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.15 —-
SSDT A72D911C ZwCreateThread
SSDT A72D9108 ZwOpenProcess
SSDT A72D910D ZwOpenThread
SSDT A72D9117 ZwTerminateProcess
SSDT A72D9112 ZwWriteVirtualMemory
INT 0x51 ? 86442BF8
INT 0x51 ? 86442BF8
INT 0x62 ? 86442BF8
INT 0x72 ? 86442BF8
INT 0x82 ? 86442BF8
INT 0x92 ? 849C3BF8
INT 0xA2 ? 849C3BF8
INT 0xB2 ? 849C7BF8
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 849C91F8
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Driver\volmgr \Device\VolMgrControl 849C51F8
Device \Driver\usbuhci \Device\USBPDO-0 8625B1F8
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016411f4ab6
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37624c68
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@0018135f0d55 0x62 0x74 0xA3 0xB9 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001d25f92e33 0xEE 0x8A 0x5D 0x80 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001fccf7732e 0x21 0x9A 0x18 0x99 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDA 0xC9 0x0F 0xB0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x45 0xBE 0xC9 0x24 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x4E 0x41 0x58 0x29 …
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\0016411f4ab6
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37624c68
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@0018135f0d55 0x62 0x74 0xA3 0xB9 …
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001d25f92e33 0xEE 0x8A 0x5D 0x80 …
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001fccf7732e 0x21 0x9A 0x18 0x99 …
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxvfwxgtbhtjmxppsxsrbojveopjmemixf.sys
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxvfwxgtbhtjmxppsxsrbojveopjmemixf.sys
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxxiimmltxxqxbvxfcrypquspkbnonispe.dll
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDA 0xC9 0x0F 0xB0 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x45 0xBE 0xC9 0x24 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x4E 0x41 0x58 0x29 …
—- Disk sectors - GMER 1.0.15 —-
Disk \Device\Harddisk0\DR0 sector 01: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR
—- EOF - GMER 1.0.15 —-
Dont know if it worked or not to be honest.
Comp is running ok but is slightly slow.