ComboFix 09-10-17.01 - Administrator 10/19/2009 7:48.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.343 [GMT 11:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((( Files Created from 2009-09-18 to 2009-10-18 )))))))))))))))))))))))))))))))
.
2009-10-18 17:46 . 2009-10-18 17:46 -------- d-----w- c:\windows\LastGood
2009-10-18 17:46 . 2009-07-28 05:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-18 17:46 . 2009-03-29 23:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-18 17:46 . 2009-02-13 01:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-18 17:46 . 2009-02-13 01:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-18 17:46 . 2009-10-18 17:46 -------- d-----w- c:\program files\Avira
2009-10-18 17:46 . 2009-10-18 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-10-18 16:34 . 2009-10-18 16:35 -------- d-----w- c:\program files\ERUNT
2009-10-16 18:56 . 2009-10-16 19:15 -------- d-----w- c:\program files\Trend Micro
2009-10-16 16:31 . 2009-10-16 16:31 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-16 16:31 . 2009-10-16 16:31 -------- d-----w- c:\program files\Spyware Doctor
2009-10-14 21:51 . 2009-10-14 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-10-14 18:03 . 2009-10-14 18:03 0 ----a-w- c:\windows\system32\atiicdxx.dat
2009-10-14 18:02 . 2009-10-14 18:02 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-06 17:04 . 2009-10-06 17:04 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\NCSoft
2009-10-06 16:58 . 2009-10-06 16:58 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ATI
2009-10-06 16:58 . 2009-10-06 16:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\ATI
2009-10-06 16:58 . 2009-10-06 16:58 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-10-06 16:58 . 2009-10-16 20:30 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
2009-10-06 16:52 . 2006-05-03 00:57 520192 ------w- c:\windows\system32\ati2sgag.exe
2009-10-06 16:51 . 2009-10-06 16:53 -------- d-----w- c:\program files\ATI Technologies
2009-10-06 16:50 . 2009-10-06 16:50 -------- d-----w- C:\ATI
2009-10-06 08:02 . 2009-10-07 05:33 -------- d-----w- c:\program files\City of Heroes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-18 20:42 . 2008-05-11 11:05 -------- d-----w- c:\program files\WPE PRO - modified
2009-10-16 18:45 . 2009-03-13 06:31 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-14 21:55 . 2009-04-16 14:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\LimeWire
2009-10-06 16:51 . 2008-11-19 12:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-06 08:43 . 2008-06-11 11:03 -------- d-----w- c:\program files\Google
2009-10-06 08:02 . 2008-11-26 05:21 -------- d-----w- c:\program files\Starcraft
2009-10-06 08:02 . 2008-08-11 12:24 -------- d-----w- c:\program files\Cheat Engine
2009-09-17 04:45 . 2009-02-28 21:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-10 04:54 . 2009-03-02 12:04 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 04:53 . 2009-03-02 12:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-02 02:11 . 2008-06-10 06:56 -------- d-----w- c:\program files\Messenger Plus! Live
2009-09-01 20:09 . 2009-08-28 16:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Name beep copy real
2009-09-01 02:47 . 2009-09-01 02:47 -------- d-----w- c:\program files\Windows Journal Viewer
2009-08-30 21:31 . 2008-04-20 08:27 12912 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-30 21:20 . 2008-04-22 13:12 -------- d-----w- c:\program files\Windows Live Toolbar
2009-08-30 21:13 . 2009-08-30 21:13 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-08-30 21:13 . 2008-06-10 06:56 -------- d-----w- c:\program files\Windows Live
2009-08-30 21:00 . 2009-08-30 20:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-08-28 16:45 . 2009-08-28 16:45 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-08-28 16:42 . 2009-08-28 16:42 -------- d-----w- c:\program files\Microsoft
2009-08-25 22:43 . 2009-08-25 21:36 -------- d-----w- c:\program files\Screaming Bee
2009-08-25 21:37 . 2009-08-25 21:37 -------- d-----w- c:\documents and settings\Administrator\Application Data\Screaming Bee
2009-08-25 17:05 . 2009-08-25 16:59 -------- d-----w- c:\program files\Yahoo!
2009-08-25 16:37 . 2009-08-25 16:27 6120 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2009-08-25 16:37 . 2009-08-25 16:37 64567 ----a-w- c:\windows\BricoPackUninst.cmd
2009-08-25 14:23 . 2009-07-26 02:41 -------- d-----w- c:\program files\Risk
2009-07-29 19:32 . 2008-06-21 11:09 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-26 06:44 . 2009-07-26 06:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-21 17:50 . 2009-07-21 17:50 14776 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-04-22 13:09 . 2008-04-22 13:09 18895728 ----a-w- c:\program files\Install_Messenger.exe
2008-04-22 11:55 . 2008-04-22 11:55 53786 ----a-w- c:\program files\Install_WLMessenger.msi
2008-04-22 07:24 . 2008-04-22 07:24 1164456 ----a-w- c:\program files\adobeflashplayer90.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-01_20.01.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-06 15:19 . 2007-11-06 15:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-28 19:07 . 2008-07-28 19:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-28 19:07 . 2008-07-28 19:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2009-03-02 01:11 . 2009-10-14 18:02 38520 c:\windows\system32\Restore\rstrlog.dat
+ 2004-08-04 12:00 . 2009-10-03 16:32 81064 c:\windows\system32\perfc009.dat
- 2004-08-04 12:00 . 2009-08-22 22:40 81064 c:\windows\system32\perfc009.dat
+ 2006-05-03 16:45 . 2006-05-03 16:45 77824 c:\windows\system32\Oemdspif.dll
+ 2009-10-18 17:46 . 2009-05-10 23:12 28520 c:\windows\system32\drivers\ssmdrv.sys
+ 2006-05-03 16:10 . 2006-05-03 16:10 40960 c:\windows\system32\drivers\ati2erec.dll
+ 2001-11-09 15:01 . 2001-11-09 15:01 24064 c:\windows\system32\ativcoxx.dll
+ 2006-05-03 16:15 . 2006-05-03 16:15 17408 c:\windows\system32\atitvo32.dll
+ 2006-05-03 16:43 . 2006-05-03 16:43 53248 c:\windows\system32\ATIDDC.DLL
+ 2006-05-03 16:45 . 2006-05-03 16:45 26112 c:\windows\system32\Ati2mdxx.exe
+ 2006-05-03 16:44 . 2006-05-03 16:44 61440 c:\windows\system32\ati2evxx.dll
+ 2006-05-03 16:45 . 2006-05-03 16:45 41984 c:\windows\system32\ati2edxx.dll
+ 2009-10-06 16:56 . 2009-10-06 16:56 9158 c:\windows\Installer\{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}\NewShortcut5_6E06A57A67284CFBAA9A5149F9C9ADB3.exe
+ 2009-10-06 16:56 . 2009-10-06 16:56 9158 c:\windows\Installer\{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}\NewShortcut3_6E06A57A67284CFBAA9A5149F9C9ADB3.exe
+ 2009-10-06 16:56 . 2009-10-06 16:56 9158 c:\windows\Installer\{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}\NewShortcut22_6E06A57A67284CFBAA9A5149F9C9ADB3.exe
+ 2009-10-06 16:56 . 2009-10-06 16:56 9158 c:\windows\Installer\{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}\NewShortcut21_6E06A57A67284CFBAA9A5149F9C9ADB3.exe
+ 2009-10-06 16:56 . 2009-10-06 16:56 9158 c:\windows\Installer\{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}\NewShortcut2_6E06A57A67284CFBAA9A5149F9C9ADB3.exe
+ 2009-10-06 16:56 . 2009-10-06 16:56 9158 c:\windows\Installer\{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}\NewShortcut1_6E06A57A67284CFBAA9A5149F9C9ADB3.exe
+ 2009-10-06 16:56 . 2009-10-06 16:56 9158 c:\windows\Installer\{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}\ARPPRODUCTICON.exe
+ 2008-07-28 21:05 . 2008-07-28 21:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-28 16:54 . 2008-07-28 16:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2009-10-06 16:51 . 2004-08-04 00:56 516768 c:\windows\system32\ReinstallBackups\0001\DriverFiles\ativvaxx.dll
+ 2009-10-06 16:51 . 2004-08-04 00:56 870784 c:\windows\system32\ReinstallBackups\0001\DriverFiles\ati3d1ag.dll
+ 2009-10-06 16:51 . 2004-08-03 22:29 701440 c:\windows\system32\ReinstallBackups\0001\DriverFiles\ati2mtag.sys
+ 2009-10-06 16:51 . 2004-08-04 00:56 201728 c:\windows\system32\ReinstallBackups\0001\DriverFiles\ati2dvag.dll
+ 2009-10-06 16:51 . 2004-08-04 00:56 229376 c:\windows\system32\ReinstallBackups\0001\DriverFiles\ati2cqag.dll
+ 2009-10-06 16:52 . 2004-08-04 00:56 516768 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ativvaxx.dll
+ 2009-10-06 16:52 . 2004-08-04 00:56 870784 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati3d1ag.dll
+ 2009-10-06 16:52 . 2004-08-04 00:56 201728 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2dvag.dll
+ 2009-10-06 16:52 . 2004-08-04 00:56 229376 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2cqag.dll
- 2004-08-04 12:00 . 2009-08-22 22:40 482064 c:\windows\system32\perfh009.dat
+ 2004-08-04 12:00 . 2009-10-03 16:32 482064 c:\windows\system32\perfh009.dat
+ 2006-05-03 16:45 . 2006-05-03 16:45 114688 c:\windows\system32\atipdlxx.dll
+ 2006-05-03 16:15 . 2006-05-03 16:15 151552 c:\windows\system32\atikvmag.dll
+ 2006-05-03 16:54 . 2006-05-03 16:54 307200 c:\windows\system32\atiiiexx.dll
+ 2006-05-03 16:12 . 2006-05-03 16:12 286720 c:\windows\system32\ATIDEMGR.dll
+ 2006-05-03 16:43 . 2006-05-03 16:43 413696 c:\windows\system32\ati2evxx.exe
+ 2008-04-20 17:36 . 2006-05-03 16:51 258048 c:\windows\system32\ati2dvag.dll
+ 2008-04-20 17:36 . 2006-05-03 16:09 282624 c:\windows\system32\ati2cqag.dll
+ 2009-10-16 16:32 . 2009-10-16 16:32 228352 c:\windows\Installer\5c51ed.msi
+ 2009-10-18 16:35 . 2009-10-18 16:35 200704 c:\windows\ERDNT\10-19-2009\Users\00000002\UsrClass.dat
+ 2009-10-18 16:35 . 2005-10-20 01:02 163328 c:\windows\ERDNT\10-19-2009\ERDNT.EXE
+ 2008-07-28 21:05 . 2008-07-28 21:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-28 21:05 . 2008-07-28 21:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2009-10-06 16:51 . 2004-08-04 00:56 1888992 c:\windows\system32\ReinstallBackups\0001\DriverFiles\ati3duag.dll
+ 2009-10-06 16:52 . 2004-08-04 00:56 1888992 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati3duag.dll
+ 2009-10-06 16:52 . 2006-05-03 16:50 1540608 c:\windows\system32\ReinstallBackups\0000\DriverFiles\ati2mtag.sys
+ 2008-04-20 17:36 . 2006-05-03 16:50 1540608 c:\windows\system32\drivers\ati2mtag.sys
+ 2008-04-20 17:36 . 2006-05-03 16:50 1540608 c:\windows\system32\dllcache\ati2mtag.sys
+ 2008-04-20 17:36 . 2006-05-03 16:29 1408000 c:\windows\system32\ativvaxx.dll
+ 2006-05-03 16:18 . 2006-05-03 16:18 5033984 c:\windows\system32\atioglxx.dll
+ 2006-05-03 16:21 . 2006-05-03 16:21 6684672 c:\windows\system32\atioglx1.dll
+ 2008-04-20 17:36 . 2006-05-03 16:35 2693280 c:\windows\system32\ati3duag.dll
+ 2009-10-18 16:35 . 2009-10-18 16:35 8335360 c:\windows\ERDNT\10-19-2009\Users\00000001\ntuser.dat
+ 2009-10-06 16:56 . 2009-10-06 16:56 13135872 c:\windows\Installer\2bbb9ca.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^RocketDock.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\RocketDock.lnk
backup=c:\windows\pss\RocketDock.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=2 (0x2)
"gupdate1c99b7d993d971c"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\World of Warcraft\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\World of Warcraft\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\World of Warcraft\\Launcher.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\World of Warcraft\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\World of Warcraft\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"58614:TCP"= 58614:TCP:Pando Media Booster
"58614:UDP"= 58614:UDP:Pando Media Booster
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [10/19/2009 4:46 AM 108289]
R3 tenCapture;tenCapture;c:\windows\system32\drivers\tenCapture.sys [4/22/2007 1:15 AM 9344]
S3 CEDRIVER53;CEDRIVER53;\??\c:\program files\Cheat Engine\dbk32.sys --> c:\program files\Cheat Engine\dbk32.sys [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [4/6/2009 2:19 PM 23064]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ANTIVIRSCHEDULERSERVICE
*NewlyCreated* - ANTIVIRSERVICE
*NewlyCreated* - AVGIO
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB
*NewlyCreated* - SSMDRV
.
Contents of the 'Scheduled Tasks' folder
2009-10-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-16 15:21]
2009-10-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-963894560-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-11 09:09]
2009-10-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-963894560-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-11 09:09]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspx
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\pulocm9w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-19 07:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-746137067-963894560-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(376)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(776)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-10-18 7:58
ComboFix-quarantined-files.txt 2009-10-18 20:57
ComboFix2.txt 2009-03-02 17:48
Pre-Run: 4,054,192,128 bytes free
Post-Run: 4,101,468,160 bytes free
247