Thank you..
ComboFix 09-05-31.02 - Dane 05/31/2009 20:50.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.595 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dane\x.exe
c:\windows\system32\drivers\kungsfbgryifog.sys
c:\windows\system32\kungsfalscwrwa.dll
c:\windows\system32\kungsfeemdgqih.dat
c:\windows\system32\kungsfjweoqqhs.dat
c:\windows\system32\kungsflog.dat
c:\windows\system32\kungsfmgwnjwqp.dll
c:\windows\system32\sysloc
c:\windows\system32\test.ttt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_kungsfodocnbsc
((((((((((((((((((((((((( Files Created from 2009-05-01 to 2009-06-01 )))))))))))))))))))))))))))))))
.
2009-05-31 22:23 . 2009-05-31 22:23 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-05-27 09:36 . 2009-05-27 09:36 2 —h–w- c:\windows\sonce122730.dat
2009-05-26 22:04 . 2009-05-31 22:23 ——– d—–w- c:\program files\a-squared Free
2009-05-26 21:49 . 2009-06-01 00:37 ——– d—–w- C:\ComboFix
2009-05-26 21:42 . 2009-03-24 20:08 55640 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-05-26 12:04 . 2009-04-06 19:32 15504 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-26 12:04 . 2009-04-06 19:32 38496 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 12:04 . 2009-05-26 12:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-25 21:30 . 2009-05-25 21:30 ——– d—–w- c:\program files\Windows Defender
2009-05-25 20:45 . 2009-05-25 20:45 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-05-25 20:03 . 2009-05-25 20:03 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\SupportSoft
2009-05-25 16:31 . 2009-05-26 11:44 20480 —-a-w- c:\windows\system32\pm.exe
2009-05-18 22:52 . 2009-05-18 22:52 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-18 22:51 . 2009-05-18 22:51 152576 —-a-w- c:\documents and settings\Dane\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-18 22:37 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-05-18 22:37 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 00:47 . 2005-10-29 15:38 11985 –sha-w- c:\windows\system32\mmf.sys
2009-06-01 00:46 . 2005-10-05 17:43 384 —-a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
2009-06-01 00:46 . 2005-10-05 17:43 384 —-a-w- c:\windows\system32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
2009-05-31 22:33 . 2007-11-10 14:52 169936 —-a-w- c:\documents and settings\Dane\Application Data\Mozilla\Firefox\Profiles\t2v7442w.default\FlashGot.exe
2009-05-31 22:25 . 2008-12-03 00:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-05-31 22:25 . 2008-12-03 00:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-31 11:34 . 2008-06-01 15:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-05-27 04:13 . 2007-04-25 22:10 ——– d—–w- c:\documents and settings\Dane\Application Data\.gaim
2009-05-26 21:32 . 2008-12-02 01:19 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-05-26 00:17 . 2009-03-18 21:44 ——– d—–w- c:\documents and settings\Dane\Application Data\Skype
2009-05-25 21:11 . 2009-03-27 21:50 ——– d—–w- c:\program files\EPSON
2009-05-24 21:00 . 2008-12-16 03:10 ——– d—–w- c:\program files\Common Files\Research In Motion
2009-05-24 20:54 . 2008-12-16 03:29 256 —-a-w- c:\windows\system32\pool.bin
2009-05-18 22:52 . 2005-10-05 17:37 ——– d—–w- c:\program files\Java
2009-05-14 00:57 . 2005-10-08 20:58 79504 —-a-w- c:\documents and settings\Dane\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-21 00:13 . 2005-10-10 15:19 56 –sh–r- c:\windows\system32\A8C539A9E2.sys
2009-04-21 00:13 . 2005-10-10 15:19 2516 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-04-20 22:26 . 2009-04-20 22:26 89998 —-a-r- c:\documents and settings\Dane\Application Data\Microsoft\Installer\{603C09ED-65ED-4B15-8CFF-15974D28E68F}\SM_shortcut_exe_elic_6DD3041B5E3C4C9CAC6DBBB68D39AB5F.exe
2009-04-20 22:26 . 2009-04-20 22:26 89998 —-a-r- c:\documents and settings\Dane\Application Data\Microsoft\Installer\{603C09ED-65ED-4B15-8CFF-15974D28E68F}\SM_exe_elic_6DD3041B5E3C4C9CAC6DBBB68D39AB5F1.exe
2009-04-20 22:26 . 2009-04-20 22:26 89998 —-a-r- c:\documents and settings\Dane\Application Data\Microsoft\Installer\{603C09ED-65ED-4B15-8CFF-15974D28E68F}\DTShort_exe_elicense_6DD3041B5E3C4C9CAC6DBBB68D39AB5F.exe
2009-04-20 22:26 . 2009-04-20 22:26 7662 —-a-r- c:\documents and settings\Dane\Application Data\Microsoft\Installer\{603C09ED-65ED-4B15-8CFF-15974D28E68F}\ARPPRODUCTICON.exe
2009-04-20 22:22 . 2006-06-23 13:57 ——– d—–w- c:\program files\Sports Interactive
2009-04-13 11:41 . 2009-04-13 11:40 ——– d—–w- c:\documents and settings\Dane\Application Data\Docx2Rtf
2009-04-13 11:41 . 2009-04-13 11:41 ——– d—–w- c:\documents and settings\Dane\Application Data\NwDocx
2009-03-06 14:22 . 2004-08-19 20:49 284160 —-a-w- c:\windows\system32\pdh.dll
2006-01-08 17:59 . 2005-10-29 15:38 2537 –sha-w- c:\windows\system32\mmf(2).sys
2006-01-12 02:17 . 2005-10-29 15:38 2537 –sha-w- c:\windows\system32\mmf(3).sys
2006-02-09 21:53 . 2005-10-29 15:38 3193 –sha-w- c:\windows\system32\mmf(4)(2).sys
2007-11-15 22:04 . 2005-10-29 15:38 11977 –sha-w- c:\windows\system32\mmf(5)(2).sys
2007-11-15 21:53 . 2005-10-29 15:38 11977 –sha-w- c:\windows\system32\mmf(6)(2).sys
2007-11-15 21:38 . 2005-10-29 15:38 11977 –sha-w- c:\windows\system32\mmf(7)(2).sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"Google Update"="c:\documents and settings\Dane\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-09 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-01 344064]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2007-08-30 205480]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"MPFEXE"="c:\program files\McAfee.com\Personal Firewall\MPFTray.exe" [2005-11-11 1005096]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-18 148888]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-03-26 615696]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2004-03-11 28672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SYSDLL"="SYSDLL" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 20:28 352256 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MpfService"=2 (0x2)
"McSysmon"=3 (0x3)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV 3 Basic\\PVSLibraryAppService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV 3 Basic\\BTVWebServer.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV 3 Basic\\BTVRecordingEngine.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV 3 Basic\\BTVGuideDataLoader.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV 3 Basic\\PVSConfigService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV 3 Basic\\BTVD3DShell.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Defcon\\defcon.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [11/17/2008 4:11 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/17/2008 4:11 PM 55024]
R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [10/29/2005 11:38 AM 2560]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [12/1/2008 9:19 PM 210216]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S2 gupdate1c99e0252929a74;Google Update Service (gupdate1c99e0252929a74);c:\program files\Google\Update\GoogleUpdate.exe [3/5/2009 10:21 PM 133104]
S3 MultiDec DVB-TV-Treiber;MultiDec DVB-TV-Treiber;WINDRVR.SYS –> WINDRVR.SYS [?]
S3 SageTV;SageTV;c:\program files\Frey Technologies\SageTV\SageTVService.exe [4/4/2005 10:46 AM 622592]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/17/2008 4:11 PM 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder
2009-05-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]
2009-06-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-01 01:01]
2009-06-01 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-06 02:21]
2009-05-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3463915915-369664898-1379251412-1005.job
- c:\documents and settings\Dane\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-09 21:50]
2009-05-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-12-02 14:53]
2009-05-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-12-02 14:53]
2009-03-18 c:\windows\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job
- c:\program files\Microsoft LifeCam\LifeExp.exe [2007-05-17 21:45]
2009-06-01 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
SafeBoot-procexp90.Sys
.
——- Supplementary Scan ——-
.
uStart Page =
https://www.google.com/accounts/ServiceLogi…mp;ltmplcache=2
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
FF - ProfilePath - c:\documents and settings\Dane\Application Data\Mozilla\Firefox\Profiles\t2v7442w.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.http - localhost
FF - prefs.js: network.proxy.http_port - 7171
FF - prefs.js: network.proxy.type - 1
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Dane\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\documents and settings\Dane\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-31 20:56
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MPFEXE = "c:\program files\McAfee.com\Personal Firewall\MPFTray.exe"????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847]
"1"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,86,2b,9b,9b,f3,96,a9,
e9
"2"=hex:05,83,26,a9,dc,b6,17,45,de,2e,f0,41,a5,95,91,56,fe,07,ca,23,63,6c,c8,
df,a0,cb,29,a7,07,62,23,54
"3"=hex:1a,c6,90,39,73,14,70,4f,c7,99,3b,d6,b3,40,09,16,39,39,6a,6e,1d,99,29,
0e,9a,9e,61,33,16,37,68,38,ee,25,f6,f1,91,9f,21,a9,58,ec,19,f6,96,30,78,09
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \169D180DB7FE8847\963F846157C74A39E2C899654953DA1B]
"1"=hex:0e,99,cd,9c,6f,50,13,a2,82,70,40,54,38,93,8f,c5,05,f3,da,4d,e8,82,d5,
04,c7,c6,1f,bf,24,f4,89,65
"8"=hex:63,5a,d7,1b,b1,d4,18,46,9d,8a,b3,da,f7,a8,9d,ab,02,f0,96,ce,68,90,9c,
19,fa,fa,2b,4b,6b,8c,15,01,e3,1a,d1,28,a5,f7,a8,07
"18"=hex:d0,71,12,cb,08,b7,a7,d6
"3"=hex:35,33,a8,dd,5d,c4,70,6d,6a,b9,fe,7c,6c,42,03,5c,4e,65,49,0b,03,f4,8c,
00,c9,f1,de,5f,d1,68,42,36,de,5f,ce,9e,d4,e3,5b,1a,83,30,32,11,10,32,97,44,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \7B89AC59B91B61F6]
"1"=hex:e2,7f,28,b3,f4,78,a8,90,a3,fe,4e,87,45,83,70,cb,36,b1,2e,f7,56,49,5f,
1a
"2"=hex:75,4f,d5,56,e6,9d,1a,13,c8,71,03,1e,73,6c,6e,62,58,a8,9a,49,4f,b9,cd,
0f,5b,63,25,a5,82,25,ac,36
"3"=hex:e2,7f,28,b3,f4,78,a8,90,a3,fe,4e,87,45,83,70,cb,f0,b4,6d,ee,bc,c7,ac,
0b,c8,17,e0,ea,3a,b9,a9,b3,2b,85,23,84,db,a5,db,15,57,06,da,7a,f2,b6,f8,62,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \7B89AC59B91B61F6\F441D6F238B9ABA2D3FCA772F626AD2B]
"1"=hex:7e,63,ed,e4,ff,c6,da,b0,42,9d,58,ab,db,aa,ef,ee,87,d7,ab,27,3e,71,cd,
57
"8"=hex:63,5a,d7,1b,b1,d4,18,46,1a,71,d0,d8,f4,aa,c9,dc,12,96,5a,35,4b,e0,a7,
97,8a,49,13,86,27,5b,8c,1d,85,69,8e,f8,26,af,a9,53
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"3"=hex:3e,7f,4f,b4,c8,47,17,dc,d3,a9,41,d8,eb,43,f2,02,54,ba,03,b9,cd,83,ea,
61,b5,24,c4,33,d4,6e,fb,be,a3,63,51,02,f4,2b,e9,ce,1e,de,17,ce,00,95,2b,a7,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \EC1A69D1C0948222]
"1"=hex:b0,cd,e0,26,42,20,9e,7c,08,f1,c1,23,e7,41,66,ec,04,7d,73,7b,41,5e,94,
fd
"2"=hex:f1,df,16,de,80,08,0e,2a,78,a4,28,cb,d2,56,ff,58,ba,e9,e0,76,1f,5b,ab,
75
"3"=hex:b0,cd,e0,26,42,20,9e,7c,08,f1,c1,23,e7,41,66,ec,2b,92,4b,0d,22,14,9d,
cb,e3,f8,73,90,7d,a4,36,0d,f2,c9,99,66,1f,10,89,7d,ec,36,ce,6f,e7,65,ad,a4
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \EC1A69D1C0948222\F347AA9A592B216D597E028785020CD4]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,60,42,a5,db,24,eb,e2,
b0,0d,ef,4b,fc,af,c2,2e,ad
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,73,7e,45,c6,9f,9e,10,
63,a0,2f,06,c2,a3,e9,62,70,90,4c,ec,d6,92,e1,28,ba,e5,5d,0d,25,ef,fb,b7,21,\
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"3"=hex:0b,a9,30,39,73,80,69,54,1a,bb,b1,a8,42,f7,e2,21,1d,b1,7f,7b,c0,5f,7b,
9a,c8,12,d7,a6,3e,fc,b5,5b,65,5c,38,93,11,ef,4d,47,16,52,01,44,df,b6,64,ec,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F93383AA3238BCCB]
"1"=hex:47,af,e3,b9,38,4b,f6,e6,cb,8b,59,0c,3a,af,c5,a2,d6,9f,52,ce,23,dc,1a,
c2
"2"=hex:d1,c8,c3,5e,08,10,b9,8f,1e,fd,a6,7c,f5,6d,b0,f3,a6,71,8f,f8,ab,bd,bd,
76,64,10,04,f0,92,77,f9,20
"3"=hex:47,af,e3,b9,38,4b,f6,e6,cb,8b,59,0c,3a,af,c5,a2,ac,98,11,9b,be,95,83,
07,ae,ba,7e,d8,e6,d6,56,50,c4,dc,bb,7b,18,78,a4,de,04,5c,25,4e,9f,d7,39,6d
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F93383AA3238BCCB\B405A2EBBFCE91A4C13BDEA4B89DC260]
"1"=hex:47,e4,6c,02,68,b4,3b,2b,30,11,db,3c,35,63,21,d4,11,b1,7e,c5,ed,aa,8e,
1a,40,6d,c3,6d,0e,a9,b1,96
"8"=hex:63,5a,d7,1b,b1,d4,18,46,0a,a7,b3,1c,99,c8,a4,fc,08,21,24,20,f1,96,6a,
7a,cd,13,31,a6,7d,dc,f4,81,0d,1c,44,d3,0b,59,cb,af
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"3"=hex:48,b8,d3,9c,57,d8,4c,2a,f5,56,84,df,39,86,ae,5c,da,ac,10,e7,79,20,c8,
b3,de,ff,cf,6d,e8,d6,38,9c,58,b2,fc,08,5a,b8,85,11,8d,9f,27,7b,28,9b,a8,de,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F93383AA3238BCCB\DBF31101A5C3B93315CBBEA90ED13257]
"1"=hex:05,63,4e,ca,af,1d,39,e0,e8,3b,06,bc,35,26,5b,04,02,70,fd,49,72,ea,3f,
0d,c1,ed,7b,62,a7,87,bb,89
"8"=hex:63,5a,d7,1b,b1,d4,18,46,0a,a7,b3,1c,99,c8,a4,fc,86,f4,fe,cb,ec,d3,4e,
4c,1b,ae,32,7d,1e,63,9b,e8,91,4b,74,fd,63,b1,f5,71
"18"=hex:4b,72,8f,bc,6c,3f,e4,15
"3"=hex:ad,71,72,da,8e,4b,69,9b,73,ab,d9,f5,f0,b1,1e,23,50,c1,29,9a,9f,d8,4a,
ac,ac,77,64,7f,e7,0d,01,75,92,86,2f,fd,5a,8f,ae,c4,14,9e,11,1f,71,fe,11,0c,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(768)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-06-01 20:59
ComboFix-quarantined-files.txt 2009-06-01 00:59
ComboFix2.txt 2008-12-19 00:57
Pre-Run: 41,483,804,672 bytes free
Post-Run: 41,682,644,992 bytes free
Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
317 — E O F — 2009-05-29 05:35