Thanks once again for all your clear and complete help.
GooredFix Log
—————————————————————————–
GooredFix by jpshortstuff (12.07.09)
Log created at 06:11 on 09/09/2009 (aactech)
Firefox version 3.0.13 (en-US)
========== GooredScan ==========
Deleting HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{33686B31-A2C3-4448-B2E6-2E06FB417FD8} -> Success!
Deleting C:\Documents and Settings\Saira\Local Settings\Application Data\{33686B31-A2C3-4448-B2E6-2E06FB417FD8} -> Success!
C:\Program Files\Mozilla Firefox\extensions\
[removed] [08:01 22/08/2009]
{972ce4c6-7e08-4474-a285-3208198ce6fd} [03:08 17/03/2008]
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} [17:14 22/06/2008]
[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [10:07 22/08/2009]
-=E.O.F=-
—————————————————————————————————————————————————————————
—————————————————————————————————————————————————————————
—————————————————————————————————————————————————————————
ComboFix Log
—————————————————————————–
ComboFix 09-09-08.07 - aactech 09/09/2009 6:29.5.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.233 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\rixisex.reg
c:\documents and settings\All Users\Application Data\wonojog.vbs
c:\documents and settings\All Users\Documents\recasibi.bat
c:\documents and settings\Saira\Local Settings\Application Data\pikonepesu.inf
c:\documents and settings\Saira\Local Settings\Application Data\ymonygibe.bat
c:\program files\Protection System
c:\windows\run.log
c:\windows\system32\doxajyl.vbs
c:\windows\system32\drivers\1028_DELL_XPS_MM061 .MRK
c:\windows\system32\drivers\DELL_XPS_MM061 .MRK
c:\windows\system32\drivers\hjgruixppyvbyq.sys
c:\windows\system32\drivers\UAChxiqlxrloy.sys
c:\windows\system32\gavulowe.dll.tmp
c:\windows\system32\hjgruifpwvrosl.dat
c:\windows\system32\hjgruihgltokto.dll
c:\windows\system32\hjgruimqllgpfq.dat
c:\windows\system32\hjgruinsrapgax.dll
c:\windows\system32\hjgruiovdlnnsr.dll
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\ltfil13n.dll
c:\windows\system32\pedabara.dll.tmp
c:\windows\system32\UACfxxvmyvjdk.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACmnrersytqr.dll
c:\windows\system32\UACnunhnfemxf.dll
c:\windows\system32\UACqjwqomurrw.dll
c:\windows\system32\UACrnvdpbmesw.dll
c:\windows\system32\wscsvc32.exe
c:\windows\Temp\1019167004.exe
c:\windows\Temp\2498985320.exe
c:\windows\Temp\292873626.exe
c:\windows\ynykanyf.bat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_hjgruilpxdkpia
——-\Legacy_hjgruilpxdkpia
——-\Service_UACd.sys
——-\Legacy_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-08-09 to 2009-09-09 )))))))))))))))))))))))))))))))
.
2009-09-09 13:37 . 2009-09-09 13:37 ——– d—–w- c:\documents and settings\aactech\Application Data\agi
2009-09-08 14:22 . 2009-09-08 14:22 0 —-a-w- c:\documents and settings\aactech\settings.dat
2009-09-07 22:21 . 2009-09-07 23:12 320 —-a-w- c:\windows\system32\drivers\sfi.dat
2009-09-07 20:10 . 2009-09-07 22:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2009-09-07 20:09 . 2009-09-07 20:09 87104 —-a-w- c:\windows\system32\drivers\inspect.sys
2009-09-07 20:09 . 2009-09-07 20:09 25160 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-09-07 20:09 . 2009-09-07 20:09 179792 —-a-w- c:\windows\system32\guard32.dll
2009-09-07 20:09 . 2009-09-07 20:09 132168 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2009-09-07 20:09 . 2009-09-07 20:09 ——– d—–w- c:\program files\COMODO
2009-09-07 19:46 . 2009-07-28 23:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-26 15:20 . 2009-09-07 18:48 ——– d—–w- c:\documents and settings\aactech\Application Data\skypePM
2009-08-26 15:19 . 2009-09-07 20:48 ——– d—–w- c:\documents and settings\aactech\Application Data\Skype
2009-08-26 07:26 . 2009-08-26 07:26 ——– d—–w- c:\documents and settings\aactech\Local Settings\Application Data\Mozilla
2009-08-26 07:25 . 2009-08-26 07:25 ——– d—–w- c:\documents and settings\aactech\Application Data\Apple Computer
2009-08-26 07:12 . 2009-09-02 18:31 ——– d—–w- c:\documents and settings\aactech\Local Settings\Application Data\Adobe
2009-08-26 07:11 . 2009-08-26 07:11 ——– d—–w- c:\documents and settings\aactech\Application Data\Malwarebytes
2009-08-22 08:01 . 2009-08-22 08:01 ——– d—–w- c:\program files\Common Files\Skype
2009-08-22 01:31 . 2009-08-22 01:31 ——– d—–w- C:\_OTM
2009-08-13 10:01 . 2009-08-13 10:01 ——– d—–w- c:\windows\ServicePackFiles
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-09 06:32 . 2008-03-13 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-07 18:33 . 2008-10-21 04:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-07 14:41 . 2008-06-08 21:58 ——– d—–w- c:\documents and settings\Saira\Application Data\Skype
2009-09-07 07:03 . 2008-06-08 21:59 ——– d—–w- c:\documents and settings\Saira\Application Data\skypePM
2009-09-07 06:09 . 2008-02-09 06:37 ——– d—–w- c:\documents and settings\Saira\Application Data\OpenOffice.org2
2009-08-29 17:00 . 2008-02-04 00:26 72360 —-a-w- c:\documents and settings\Saira\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 07:25 . 2008-04-04 18:12 72360 —-a-w- c:\documents and settings\aactech\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-22 08:01 . 2008-06-08 21:57 ——– d—–r- c:\program files\Skype
2009-08-22 08:01 . 2008-06-08 21:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-08-05 09:11 . 2004-08-04 12:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 20:36 . 2008-10-21 04:14 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 20:36 . 2008-10-21 04:14 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-19 01:54 . 2008-02-07 05:39 ——– d—–w- c:\documents and settings\Saira\Application Data\NetSarang
2009-07-19 01:48 . 2008-12-01 17:20 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-19 01:40 . 2008-02-04 00:10 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-19 01:39 . 2009-07-18 21:03 ——– d—–w- c:\program files\Astonsoft
2009-07-18 22:05 . 2008-06-28 01:05 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-07-18 01:57 . 2009-07-18 01:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-07-18 01:57 . 2008-06-20 06:35 ——– d—–w- c:\program files\Norton Security Scan
2009-07-18 01:02 . 2009-07-18 01:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-18 01:02 . 2009-07-18 01:02 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-07-17 18:55 . 2004-08-04 12:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 09:18 . 2004-08-04 12:00 233472 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-13 04:09 . 2008-04-04 22:11 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-26 16:18 . 2004-08-04 12:00 659456 —-a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-06-25 18:36 . 2004-08-04 12:00 95744 —-a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2004-08-04 12:00 661504 —-a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2004-08-04 12:00 517120 —-a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2004-08-04 12:00 48640 —-a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2004-08-04 12:00 471552 —-a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2004-08-04 12:00 47104 —-a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2004-08-04 12:00 225280 —-a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2004-08-04 12:00 186880 —-a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2004-08-04 12:00 177152 —-a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2004-08-04 12:00 16896 —-a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2004-08-04 12:00 138240 —-a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2004-08-04 12:00 123392 —-a-w- c:\windows\system32\mqrtdep.dll
2009-06-25 08:17 . 2004-08-04 12:00 729600 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:17 . 2004-08-04 12:00 59392 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:17 . 2004-08-04 12:00 56320 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:17 . 2004-08-04 12:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:17 . 2004-08-04 12:00 168448 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:17 . 2004-08-04 12:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-22 11:49 . 2004-08-04 12:00 19968 —-a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2004-08-04 12:00 117248 —-a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2004-08-04 12:00 4608 —-a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2004-08-04 12:00 91776 —-a-w- c:\windows\system32\drivers\mqac.sys
2009-06-22 11:35 . 2004-08-04 12:00 92544 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:55 . 2004-08-04 12:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-04 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 2004-08-04 12:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 2004-08-04 12:00 76288 —-a-w- c:\windows\system32\telnet.exe
2008-10-21 03:57 . 2008-10-21 03:57 16321 —-a-w- c:\program files\Common Files\lygone.dll
2008-10-21 03:57 . 2008-10-21 03:57 13362 —-a-w- c:\program files\Common Files\gawiro._dl
2007-11-13 19:47 . 2007-11-13 19:47 217 —-a-w- c:\program files\setup.ini
2002-03-11 09:06 . 2002-03-11 09:06 1822520 —-a-w- c:\program files\instmsiw.exe
2002-03-11 08:45 . 2002-03-11 08:45 1708856 —-a-w- c:\program files\instmsia.exe
2008-09-06 03:33 . 2008-09-06 03:33 63211 –sha-w- c:\windows\system32\fepuhegu.dll.tmp
2008-09-02 04:39 . 2008-09-02 04:39 64052 –sha-w- c:\windows\system32\fosepoyo.dll.tmp
2008-12-02 23:31 . 2008-12-02 23:31 4096 –sha-w- c:\windows\system32\jefiyuna.exe
2008-09-04 15:32 . 2008-09-04 15:32 66101 –sha-w- c:\windows\system32\regogera.dll.tmp
2008-09-06 03:33 . 2008-09-06 03:33 63211 –sha-w- c:\windows\system32\tiseluwi.dll.tmp
2008-09-02 04:39 . 2008-09-02 04:39 64052 –sha-w- c:\windows\system32\wepejapu.dll.tmp
2008-09-04 15:32 . 2008-09-04 15:32 66101 –sha-w- c:\windows\system32\wojigovu.dll.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-04 1032192]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-11 39792]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-31 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-31 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-31 138008]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-20 185896]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-09-07 1796368]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-25 282624]
c:\documents and settings\Saira\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-11-14 157000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2009-3-31 25214]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\C:\0autocheck autochk *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\apps\\Java\\jdk1.6.0_01\\bin\\java.exe"=
"c:\\apps\\Java\\jdk1.6.0_01\\jre\\bin\\java.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\java.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\WLTRYSVC.EXE"=
"c:\\Program Files\\OpenOffice.org 2.3\\program\\soffice.bin"=
"c:\\Program Files\\AGI\\common\\win32\\pythonservice.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\Program Files\\OpenOffice.org 2.3\\program\\soffice.exe"=
"c:\\WINDOWS\\system32\\BCMWLTRY.EXE"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\Program Files\\Java\\jre1.6.0_06\\bin\\jusched.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.EXE"=
"c:\\Program Files\\WIDCOMM\\Bluetooth Software\\bin\\btwdins.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiadap.exe"=
"c:\\WINDOWS\\system32\\verclsid.exe"=
"c:\\Program Files\\AGI\\Python25\\pythonw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [9/7/2009 1:09 PM 132168]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9/7/2009 1:09 PM 25160]
R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [11/14/2008 7:31 PM 10240]
S2 dzqe;dzqe;c:\windows\system32\drivers\iimwob.sys –> c:\windows\system32\drivers\iimwob.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe –> c:\program files\Spyware Doctor\pctsAuxs.exe [?]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://personalfirewall.comodo.com/download_firewall.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\aactech\Application Data\Mozilla\Firefox\Profiles\l8e0znt5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\Shim.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
AddRemove-ef275db8-4dba-fbe7-3e42-8217943b3fcb - c:\windows\system32\ef275db8-4dba-fbe7-3e42-8217943b3fcb.exe
AddRemove-Microsoft SQL Server 2000 Analysis Services - c:\windows\ISUNINST.EXE -fc:\program files\Microsoft Analysis Services\uninst.isu
AddRemove-qowtnhqtfmmvuf - c:\windows\system32\qowtnhqtfmmvuf.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-09 06:37
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\docume~1\aactech\LOCALS~1\Temp\Perflib_Perfdata_664.dat 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
Completion time: 2009-09-09 6:38
ComboFix-quarantined-files.txt 2009-09-09 13:38
ComboFix2.txt 2009-07-14 02:13
Pre-Run: 2,331,435,008 bytes free
Post-Run: 2,626,985,984 bytes free
282 — E O F — 2009-09-09 06:33
—————————————————————————————————————————————————————————
—————————————————————————————————————————————————————————
—————————————————————————————————————————————————————————
RootRepeal Log
—————————————————————————–
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/09 06:49
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
——————-
Name: catchme.sys
Image Path: C:\DOCUME~1\aactech\LOCALS~1\Temp\catchme.sys
Address: 0xF8864000 Size: 31744 File Visible: No Signed: -
Status: -
Name: Combo-Fix.sys
Image Path: Combo-Fix.sys
Address: 0xF8524000 Size: 60416 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAA082000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8A68000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xF89EC000 Size: 6464 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA958C000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
——————-
Path: C:\WINDOWS\Temp\ib1C3.tmp
Status: Locked to the Windows API!
Path: C:\WINDOWS\Temp\ib1C4.tmp
Status: Locked to the Windows API!
Path: C:\WINDOWS\Temp\ib1C5.tmp
Status: Locked to the Windows API!
Path: C:\WINDOWS\Temp\ib1C6.tmp
Status: Locked to the Windows API!
Path: C:\WINDOWS\Temp\ib1C7.tmp
Status: Locked to the Windows API!
Path: C:\Program Files\COMODO\COMODO Internet Security\Quarantine
Status: Locked to the Windows API!
Path: C:\WINDOWS\system32\drivers\sfi.dat
Status: Locked to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_620.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\TMP87.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\TMP88.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\TMP89.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\TMP8A.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\UAC000
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\UAC4c56.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\url.txt
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\UserInfoSetup(20090517194657C34).log
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\VBE
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\walmartyourzone.bmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WebshotsTemp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER1046.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER1317.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Quality factors.doc
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\QuickTimePlayer (2009-07-14 0.37.11).dmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\rem4D.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\seneka000
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\setup.exe
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\SetupExe(2009051718430827C).log
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\SetupExe(20090517194655C34).log
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\winamp.exe
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WMC0000.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\wzszx000
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\xas1D7.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\y8o1D5.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\ywiseext.dll
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\z4g33F.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\__SkypeIEToolbar_Cache
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\{90A64B70-3ED6-45EF-B5B8-E0A518E416AC}
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF18C6.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF193E.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF1A10.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF1D43.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF2D24.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF2D65.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF2E97.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF2F8A.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF2F95.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF3E87.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\OIS
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-65
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-66
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-67
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-68
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-69
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-7
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-70
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-71
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-72
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-73
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-74
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-75
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-76
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-77
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-78
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-79
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-8
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-80
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-81
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF8996.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF8AC9.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF9842.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF9855.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF9B29.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFA731.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFB0DB.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFB109.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFB164.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFB8EE.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFC981.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFCC91.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFCEC4.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFD14F.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFD30C.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFDD61.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFDD6C.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFE18C.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFE3B1.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFE635.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFF0B0.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFF131.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFF2EB.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DFFB07.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Shreve%2C Anita - Olympia OK.rar
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\SKYNET000
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\SkypeSetup.exe
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\SoftArchDocTemplate-1.doc
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\SoftArchDocTemplate.doc
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\spoolsv.exe
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Stephanie Laurens-Bastion Club books.rar
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\svkl1.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\system.exe
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\tbh_ff.txt
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\tdss000
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Temporary Directory 1 for spring-framework-2.5.2-with-dependencies.zip
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Temporary Internet Files
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\TFR1C1.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\OneNoteRuntimeCache
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\outlook logging
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata__755.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\phn contacts.csv
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Picture 250.jpg
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-10
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-11
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-12
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-13
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-14
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-15
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-16
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-17
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-18
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-19
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-2
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-20
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-21
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-22
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-23
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-24
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-25
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-26
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-27
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-47
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-48
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-49
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-5
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-50
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-51
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-52
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-53
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-54
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-55
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-56
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-57
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-58
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-59
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-6
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-60
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-61
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-62
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-63
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_6a4.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_78c.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_7d4.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_830.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_848.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_868.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_888.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_918.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_948.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_9a0.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_9d8.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_a4c.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_a5c.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_a90.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_ae4.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_af8.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_b0c.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_b90.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_bb8.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_c00.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_c0c.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_c58.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Police Dispatch System F09-1.doc
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Police Dispatch System F09-2.doc
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Police Dispatch System F09-3.doc
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Police Dispatch System F09.doc
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\ppt2A9.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\purinaproplan.bmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\pvu332.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\quadra000
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Quality Exercise.doc
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER1650.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER1f16.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER63fd.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER71d4.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER7438.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER77b1.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER7b84.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WER9b1c.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WERa64b.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\WERbb77.dir00
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-29
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-3
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-30
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-31
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-32
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-33
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-34
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-35
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-36
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-37
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-38
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-39
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-4
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-40
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-41
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-42
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-43
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-44
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\plugtmp-45
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF4580.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF4599.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF460D.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF4738.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF4B6E.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF5592.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF58A6.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF599A.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF59A5.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF5E4.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF66BD.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF6864.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF69E.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF6EAA.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF6FFE.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF706E.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF7C16.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF834F.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF8363.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF84AF.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\~DF84BA.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\nsg1CF1.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\NSSRT.exe
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\o8q1A9.tmp
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_108.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_194.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_3bc.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_410.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_53c.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_5e4.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_c88.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_cc8.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_ce8.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_d0.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_d08.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_d40.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_d54.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_d6c.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_dc0.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_e54.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_e94.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_ec0.dat
Status: Invisible to the Windows API!
Path: C:\Documents and Settings\Saira\Local Settings\temp\Perflib_Perfdata_ed4.dat
Status: Invisible to tSSDT
——————-
#: 011 Function Name: NtAdjustPrivilegesToken
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31ef4a
#: 031 Function Name: NtConnectPort
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31e454
#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31eaee
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31f4c6
#: 046 Function Name: NtCreatePort
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31e132
#: 050 Function Name: NtCreateSection
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa3201d6
#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa3204ae
#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31dcf8
#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31f130
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31f2e0
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31da5a
#: 097 Function Name: NtLoadDriver
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31fe58
#: 105 Function Name: NtMakeTemporaryObject
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31e6d8
#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31ed32
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31d78a
#: 125 Function Name: NtOpenSection
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31e968
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31d902
#: 192 Function Name: NtRenameKey
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31f88c
#: 200 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31e250
#: 210 Function Name: NtSecureConnectPort
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31fbf4
#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa320006
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31f68c
#: 249 Function Name: NtShutdownSystem
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31e672
#: 255 Function Name: NtSystemDebugControl
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31e85c
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31dffc
#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa31deca
Shadow SSDT
——————-
#: 013 Function Name: NtGdiBitBlt
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa32228a
#: 122 Function Name: NtGdiDeleteObjectApp
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa3229ae
#: 227 Function Name: NtGdiMaskBlt
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa3223be
#: 233 Function Name: NtGdiOpenDCW
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa32286e
#: 237 Function Name: NtGdiPlgBlt
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa3224fe
#: 292 Function Name: NtGdiStretchBlt
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa322632
#: 310 Function Name: NtUserBlockInput
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa32210a
#: 319 Function Name: NtUserCallHwndParamLock
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa32135c
#: 383 Function Name: NtUserGetAsyncKeyState
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa321dda
#: 389 Function Name: NtUserGetClipboardData
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa32276c
#: 414 Function Name: NtUserGetKeyboardState
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa321b48
#: 416 Function Name: NtUserGetKeyState
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa321c8a
#: 460 Function Name: NtUserMessageCall
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa32182c
#: 465 Function Name: NtUserMoveWindow
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa321094
#: 475 Function Name: NtUserPostMessage
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa3214de
#: 476 Function Name: NtUserPostThreadMessage
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa32168a
#: 491 Function Name: NtUserRegisterRawInputDevices
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa321f2a
#: 502 Function Name: NtUserSendInput
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa3219ee
#: 509 Function Name: NtUserSetClipboardViewer
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa322020
#: 529 Function Name: NtUserSetParent
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa321204
#: 549 Function Name: NtUserSetWindowsHookEx
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa322a14
#: 552 Function Name: NtUserSetWinEventHook
Status: Hooked by "C:\WINDOWS\System32\DRIVERS\cmdguard.sys" at address 0xaa322c48
==EOF==