Big scary wall of text inc…
Thanks again.
ComboFix 09-09-06.06 - Compaq_Administrator 09/07/2009 9:14.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1982.1560 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: a-squared Anti-Malware *On-access scanning disabled* (Outdated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\-1878584615
c:\docume~1\COMPAQ~1.001\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\All Users\Application Data\99494996.ini
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Temp\IadHide5.dll
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\windows\Install.txt
c:\windows\Installer\10ae67.msi
c:\windows\Installer\13849554.msi
c:\windows\Installer\1384956b.msp
c:\windows\Installer\14715ac8.msi
c:\windows\Installer\1831d44.msi
c:\windows\Installer\1831d48.msi
c:\windows\Installer\1bbdf93e.msi
c:\windows\Installer\1bbdf942.msi
c:\windows\Installer\1d31b926.msi
c:\windows\Installer\2944d7.msi
c:\windows\Installer\34482.msi
c:\windows\Installer\346d5.msp
c:\windows\Installer\3cdc55.msi
c:\windows\Installer\3e471e.msi
c:\windows\Installer\3e4728.msi
c:\windows\Installer\62e1d.msi
c:\windows\Installer\9975cb.msp
c:\windows\Installer\bb6f4c.msi
c:\windows\Installer\d3c5e71.msi
c:\windows\kb913800.exe
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000013_.tmp.dll
.
((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.
2009-09-06 18:23 . 2009-09-06 18:23 ——– d—–w- c:\windows\system32\Service
2009-09-06 16:05 . 2009-09-06 16:05 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\Malwarebytes
2009-09-06 16:05 . 2009-08-03 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-06 16:05 . 2009-09-06 16:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-06 16:05 . 2009-08-03 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-06 16:04 . 2009-09-06 17:54 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-04 21:00 . 2009-09-04 21:01 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\WeatherBug
2009-09-04 21:00 . 2009-09-06 15:35 ——– d—–w- c:\program files\AWS
2009-09-03 08:54 . 2009-09-05 12:31 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\BitTorrent
2009-09-01 07:56 . 2009-09-02 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-31 01:46 . 2009-08-31 01:46 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\WinBatch
2009-08-30 17:41 . 2009-03-21 04:17 48640 —-a-w- c:\windows\system32\dataguard.sys
2009-08-30 17:41 . 2009-08-30 17:41 ——– d—–w- c:\program files\DataGuard
2009-08-30 14:09 . 2009-08-30 14:09 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\Identities
2009-08-28 07:37 . 2009-08-28 07:38 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\Temp
2009-08-25 08:06 . 2009-08-25 08:06 ——– d—–w- c:\program files\IObit
2009-08-24 22:16 . 2009-08-24 22:16 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\AdobeUM
2009-08-24 22:15 . 2009-08-24 22:16 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\Adobe
2009-08-23 22:47 . 2009-08-23 22:47 ——– d—–w- c:\windows\system32\scripting
2009-08-23 22:47 . 2009-08-23 22:47 ——– d—–w- c:\windows\system32\en
2009-08-23 22:47 . 2009-08-23 22:47 ——– d—–w- c:\windows\system32\bits
2009-08-23 09:21 . 2009-08-23 09:21 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\Desktopicon
2009-08-23 09:21 . 2009-08-23 09:21 ——– d—–w- c:\program files\Unlocker
2009-08-22 20:13 . 2009-09-05 12:35 ——– d—–w- c:\program files\a-squared Anti-Malware
2009-08-22 19:56 . 2009-09-06 17:53 ——– d—–w- c:\program files\Anti-keylogger
2009-08-21 08:55 . 2009-04-02 23:08 50192 —-a-w- c:\windows\system32\drivers\tmactmon.sys
2009-08-21 08:55 . 2009-04-02 23:08 50192 —-a-w- c:\windows\system32\drivers\tmevtmgr.sys
2009-08-21 08:55 . 2009-04-02 23:08 153104 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-08-21 08:55 . 2009-08-21 08:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Trend Micro
2009-08-21 08:54 . 2009-08-21 08:55 ——– d—–w- c:\program files\Trend Micro
2009-08-21 08:35 . 2009-08-21 08:35 80400 —-a-w- c:\windows\system32\drivers\tmtdi.sys
2009-08-21 08:35 . 2009-08-21 08:35 335376 —-a-w- c:\windows\system32\drivers\TM_CFW.sys
2009-08-21 08:35 . 2009-05-22 08:02 225296 —-a-w- c:\windows\system32\drivers\tmxpflt.sys
2009-08-21 08:35 . 2009-05-22 08:00 36368 —-a-w- c:\windows\system32\drivers\tmpreflt.sys
2009-08-21 08:35 . 2009-05-22 07:45 1220120 —-a-w- c:\windows\system32\drivers\vsapint.sys
2009-08-21 08:22 . 2009-08-21 08:22 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\HPQ
2009-08-20 08:14 . 2008-04-14 00:11 32768 ——w- c:\windows\system32\ativtmxx.dll
2009-08-20 08:13 . 2008-04-13 18:31 36352 ——w- c:\windows\system32\drivers\intelppm.sys
2009-08-20 08:13 . 2008-04-13 18:43 9728 ——w- c:\windows\system32\comsdupd.exe
2009-08-20 08:13 . 2008-04-14 00:12 10752 ——w- c:\windows\system32\smtpapi.dll
2009-08-20 08:13 . 2008-04-14 00:12 9728 ——w- c:\windows\system32\rwnh.dll
2009-08-20 08:13 . 2008-04-14 00:09 6144 ——w- c:\windows\system32\kbdbhc.dll
2009-08-20 08:13 . 2008-04-14 00:09 6144 ——w- c:\windows\system32\kbdiultn.dll
2009-08-20 08:13 . 2008-04-14 00:09 6144 ——w- c:\windows\system32\kbdpash.dll
2009-08-20 08:13 . 2008-04-14 00:09 6144 ——w- c:\windows\system32\kbdnepr.dll
2009-08-20 08:13 . 2008-04-14 00:11 61440 ——w- c:\windows\system32\kmsvc.dll
2009-08-20 08:13 . 2008-04-14 00:11 37376 ——w- c:\windows\system32\l2gpstore.dll
2009-08-20 08:12 . 2008-04-14 00:11 397312 ——w- c:\windows\system32\mmcex.dll
2009-08-20 08:12 . 2008-04-14 00:11 184320 ——w- c:\windows\system32\microsoft.managementconsole.dll
2009-08-20 08:12 . 2008-04-14 00:11 106496 ——w- c:\windows\system32\mmcfxcommon.dll
2009-08-20 08:12 . 2008-04-14 00:12 33792 ——w- c:\windows\system32\mmcperf.exe
2009-08-20 08:12 . 2008-04-14 00:12 155136 ——w- c:\windows\system32\mssha.dll
2009-08-20 08:12 . 2008-04-13 18:14 76800 ——w- c:\windows\system32\msshavmsg.dll
2009-08-20 08:10 . 2008-04-13 18:40 10240 ——w- c:\windows\system32\drivers\sffp_mmc.sys
2009-08-20 07:45 . 2009-08-20 07:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-18 09:16 . 2009-08-18 09:16 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-08-18 08:53 . 2009-08-18 08:53 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\DivX
2009-08-18 08:53 . 2009-08-18 08:53 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\Media Player Classic
2009-08-18 08:52 . 2009-07-14 00:17 129784 ——w- c:\windows\system32\pxafs.dll
2009-08-18 08:52 . 2009-08-18 08:52 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-08-17 08:11 . 2009-08-17 08:11 ——– d—–w- c:\windows\system32\LogFiles
2009-08-17 00:38 . 2009-06-26 16:50 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-08-17 00:25 . 2009-06-25 08:25 730112 ——w- c:\windows\system32\lsasrv.dll
2009-08-17 00:25 . 2009-06-24 11:18 92928 ——w- c:\windows\system32\drivers\ksecdd.sys
2009-08-16 13:46 . 2009-06-03 19:09 1291264 ——w- c:\windows\system32\dllcache\quartz.dll
2009-08-16 13:45 . 2008-10-24 11:21 455296 ——w- c:\windows\system32\dllcache\mrxsmb.sys
2009-08-16 13:45 . 2008-12-11 10:57 333952 ——w- c:\windows\system32\dllcache\srv.sys
2009-08-16 13:45 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-16 13:45 . 2008-04-11 19:04 691712 ——w- c:\windows\system32\dllcache\inetcomm.dll
2009-08-16 13:44 . 2008-10-15 16:34 337408 ——w- c:\windows\system32\dllcache\netapi32.dll
2009-08-16 13:44 . 2008-10-23 12:36 286720 ——w- c:\windows\system32\dllcache\gdi32.dll
2009-08-16 13:44 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-08-16 13:44 . 2008-04-21 12:08 215552 ——w- c:\windows\system32\dllcache\wordpad.exe
2009-08-16 01:37 . 2009-08-16 01:37 ——– d—–w- c:\program files\Ascaron Entertainment
2009-08-15 23:19 . 2008-05-08 14:02 203136 ——w- c:\windows\system32\dllcache\rmcast.sys
2009-08-15 23:17 . 2009-03-06 14:22 284160 ——w- c:\windows\system32\dllcache\pdh.dll
2009-08-15 23:17 . 2009-06-25 08:25 730112 ——w- c:\windows\system32\dllcache\lsasrv.dll
2009-08-15 23:17 . 2009-02-09 12:10 714752 ——w- c:\windows\system32\dllcache\ntdll.dll
2009-08-15 23:17 . 2009-02-09 12:10 617472 ——w- c:\windows\system32\dllcache\advapi32.dll
2009-08-15 23:17 . 2009-02-09 12:10 473600 ——w- c:\windows\system32\dllcache\fastprox.dll
2009-08-15 23:17 . 2009-02-09 12:10 453120 ——w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-08-15 23:17 . 2009-02-09 12:10 401408 ——w- c:\windows\system32\dllcache\rpcss.dll
2009-08-15 23:17 . 2009-02-06 11:11 110592 ——w- c:\windows\system32\dllcache\services.exe
2009-08-15 23:17 . 2009-02-06 10:10 227840 ——w- c:\windows\system32\dllcache\wmiprvse.exe
2009-08-15 23:17 . 2009-02-06 11:06 2145280 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-08-15 23:17 . 2009-02-06 11:08 2189056 ——w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-08-15 23:17 . 2009-02-06 10:32 2023936 ——w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-08-15 23:02 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2009-08-15 23:02 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\dllcache\bthport.sys
2009-08-14 16:10 . 2009-02-24 23:42 116736 —-a-w- c:\windows\system32\drivers\mcdbus.sys
2009-08-14 15:11 . 2009-08-14 15:11 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2009-08-14 15:06 . 2009-08-14 15:06 722416 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-08-14 15:06 . 2009-08-14 15:19 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\DAEMON Tools Pro
2009-08-14 07:59 . 2009-08-21 21:27 ——– d—–w- c:\program files\MagicISO
2009-08-12 16:16 . 2009-08-18 08:56 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\Google
2009-08-12 16:13 . 2009-08-12 16:13 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\Sonic
2009-08-12 16:13 . 2009-08-12 16:13 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\Leadertech
2009-08-12 09:28 . 2009-08-12 09:28 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\Netscape
2009-08-12 09:28 . 2009-08-12 09:28 ——– d-s—w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\UserData
2009-08-12 07:58 . 2009-08-12 07:58 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Application Data\Ventrilo
2009-08-12 07:46 . 2009-08-12 07:46 ——– d—–w- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Local Settings\Application Data\Blizzard Entertainment
2009-08-11 18:59 . 2006-08-01 21:09 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2009-08-11 18:19 . 2009-09-02 13:34 ——– d-sh–r- c:\windows\system32\dllcache
2009-08-11 08:00 . 2009-08-11 08:05 ——– d—–w- c:\program files\support
2009-08-11 08:00 . 2009-08-11 08:00 ——– d—–w- c:\program files\movies
2009-08-11 08:00 . 2009-08-11 08:00 ——– d—–w- c:\program files\directx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-05 12:34 . 2008-12-29 03:06 ——– d—–w- c:\program files\World of Warcraft
2009-08-29 17:39 . 2006-08-01 21:04 44456 -c–a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-21 08:52 . 2006-08-01 21:32 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-21 08:52 . 2006-08-01 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-21 08:51 . 2006-08-01 21:32 ——– d—–w- c:\program files\Symantec
2009-08-18 08:55 . 2009-01-11 17:20 ——– d—–w- c:\program files\Google
2009-08-18 08:52 . 2009-01-10 09:01 ——– d—–w- c:\program files\DivX
2009-08-18 08:51 . 2009-04-24 19:19 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-08-14 16:33 . 2004-08-10 04:00 4224 —-a-w- c:\windows\system32\drivers\beep.sys
2009-08-14 16:10 . 2009-04-08 16:06 ——– d—–w- c:\program files\MagicDisc
2009-08-11 19:03 . 2009-08-11 19:03 1699 –sha-r- c:\windows\system32\drivers\103C_HP_CPC_RE473AA-ABA SR2020NX NA680_YC_0Pres_QCNH634_E64NAemREA3_48_INAOS_SASUSTek Computer INC._V1.05_B3.00_T060630_WXP2_L409_M1983_J160_7AMD_8Athlon 64_92.2_#061020_N_Z14F12F20_G10DE0241.MRK
2009-08-11 16:13 . 2008-12-29 04:31 ——– d—–w- c:\program files\DNA
2009-08-05 09:01 . 2004-08-10 04:00 204800 ——w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:37 . 2004-08-10 04:00 81920 ——w- c:\windows\system32\fontsub.dll
2009-07-29 04:37 . 2004-08-10 04:00 119808 ——w- c:\windows\system32\t2embed.dll
2009-07-17 18:55 . 2004-08-10 04:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 00:17 . 2006-08-01 21:05 120056 ——w- c:\windows\system32\pxcpyi64.exe
2009-07-14 00:17 . 2006-08-01 21:05 118520 ——w- c:\windows\system32\pxinsi64.exe
2009-07-14 00:17 . 2005-08-19 17:00 43528 ——w- c:\windows\system32\drivers\pxhelp20.sys
2009-07-14 00:15 . 2009-07-14 00:15 90112 —-a-w- c:\windows\system32\dpl100.dll
2009-07-14 00:15 . 2009-07-14 00:15 823296 —-a-w- c:\windows\system32\divx_xx0c.dll
2009-07-14 00:15 . 2009-07-14 00:15 823296 —-a-w- c:\windows\system32\divx_xx07.dll
2009-07-14 00:15 . 2009-07-14 00:15 815104 —-a-w- c:\windows\system32\divx_xx0a.dll
2009-07-14 00:15 . 2009-07-14 00:15 811008 —-a-w- c:\windows\system32\divx_xx16.dll
2009-07-14 00:15 . 2009-07-14 00:15 802816 —-a-w- c:\windows\system32\divx_xx11.dll
2009-07-14 00:15 . 2009-07-14 00:15 685056 —-a-w- c:\windows\system32\DivX.dll
2009-07-13 15:08 . 2004-08-10 04:00 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-26 16:50 . 2004-08-10 04:00 666624 —-a-w- c:\windows\system32\wininet.dll
2009-06-25 18:36 . 2004-08-10 04:00 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2004-08-10 04:00 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2004-08-10 04:00 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2004-08-10 04:00 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2004-08-10 04:00 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2004-08-10 04:00 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2004-08-10 04:00 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2004-08-10 04:00 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2004-08-10 04:00 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2004-08-10 04:00 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2004-08-10 04:00 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2004-08-10 04:00 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-25 08:25 . 2004-08-10 04:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-10 04:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-10 04:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-10 04:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-10 04:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-22 11:49 . 2004-08-10 04:00 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2004-08-10 04:00 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2004-08-10 04:00 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2004-08-10 04:00 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-13 04:57 . 2009-06-13 04:57 19 -c–a-w- c:\windows\popcinfo.dat
2009-06-12 12:31 . 2004-08-10 04:00 80896 ——w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-10 11:00 76288 ——w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2004-08-10 04:00 2066432 ——w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-10 04:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2004-08-10 04:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-08-21 492808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-01 180269]
"a-squared"="c:\program files\a-squared Anti-Malware\a2guard.exe" [2009-08-23 3213456]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"DataGuard"="c:\program files\DataGuard\Dataguard.exe" [2009-03-21 2313728]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"Easy Dock"="c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\My Documents\RCA easyRip\EZDock.exe" [2009-04-03 573440]
"ftutil2"="ftutil2.dll" - c:\windows\system32\ftutil2.dll [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-06-14 16239616]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" - c:\windows\arpwrmsg.exe [2005-08-03 77312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-05-09 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-08-21 492808]
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-4-8 576000]
c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-4-8 576000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - c:\program files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-8-1 36903]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 akl_svc;Anti-keylogger Service;c:\program files\Anti-keylogger\akl_svc.exe [4/21/2009 7:56 PM 59904]
R2 DataGuardService;Data Guard Service;c:\windows\system32\dataguard.sys [8/30/2009 12:41 PM 48640]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [8/21/2009 3:35 AM 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [8/21/2009 3:35 AM 335376]
S2 gupdate1ca1fe12bf9cf98;Google Update Service (gupdate1ca1fe12bf9cf98);c:\program files\Google\Update\GoogleUpdate.exe [8/18/2009 3:51 AM 133104]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [8/21/2009 3:55 AM 50192]
S2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [8/21/2009 3:56 AM 497008]
S2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [8/21/2009 3:56 AM 677128]
S3 krnl_akl;Anti-keylogger Kernel Service;c:\windows\system32\drivers\krnl_akl.sys [4/21/2009 7:49 PM 360960]
— Other Services/Drivers In Memory —
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2009-09-07 c:\windows\Tasks\03 - Real Solution 9.job
- c:\documents and settings\Compaq_Administrator.YOUR-4DACD0EA75.001\My Documents\Downloads\03 - Real Solution 9 .mp3 [2009-08-12 02:32]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DAEMON Tools Pro Agent - c:\program files\DAEMON Tools Pro\DTProAgent.exe
HKLM-Run-PCDrProfiler - (no file)
ShellExecuteHooks-{58101905-D80F-4788-96F6-986A8186178A} - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ask.com?o=14986&l=dis
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-07 09:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-09-07 9:19
ComboFix-quarantined-files.txt 2009-09-07 14:19
Pre-Run: 81,673,760,768 bytes free
Post-Run: 81,646,194,688 bytes free
319 — E O F — 2009-09-02 13:34