ComboFix 09-11-04.02 - Paul 11/04/2009 20:06.3.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.255.30 [GMT -6:00]
Running from: c:\documents and settings\Paul\My Documents\Downloads\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\badekofi.dll
c:\windows\system32\benopezu.dll
c:\windows\system32\binezitu.dll.tmp
c:\windows\system32\bunuyuza.dll
c:\windows\system32\busofama.dll
c:\windows\system32\feduloke.dll
c:\windows\system32\fohuveka.dll
c:\windows\system32\gohivoju.dll
c:\windows\system32\hilupana.dll
c:\windows\system32\hufubebe.dll
c:\windows\system32\lekepegu.dll
c:\windows\system32\likayube.dll
c:\windows\system32\luyizebo.dll.tmp
c:\windows\system32\mabafaye.dll
c:\windows\system32\mulimaka.dll.tmp
c:\windows\system32\pedigeyi.dll.tmp
c:\windows\system32\pegeweya.dll
c:\windows\system32\petobuke.dll
c:\windows\system32\popajodo.dll
c:\windows\system32\popapabe.dll
c:\windows\system32\potawoyi.dll
c:\windows\system32\pugediro.dll
c:\windows\system32\punonoho.dll
c:\windows\system32\rahobeto.dll
c:\windows\system32\rajuguke.dll
c:\windows\system32\rohawoyu.dll
c:\windows\system32\rozevowe.dll
c:\windows\system32\sefavezo.dll
c:\windows\system32\sisifeme.dll
c:\windows\system32\suvibala.dll
c:\windows\system32\tagiboja.dll
c:\windows\system32\tamotumu.dll
c:\windows\system32\tunopovo.dll.tmp
c:\windows\system32\tusafaja.dll
c:\windows\system32\varareto.dll
c:\windows\system32\wamepesi.dll
c:\windows\system32\wemudisi.dll
c:\windows\system32\wiwediwi.dll
c:\windows\system32\woferezi.dll
c:\windows\system32\wokidaro.dll
c:\windows\system32\wowifoga.dll
c:\windows\system32\yaroteze.dll
c:\windows\system32\zaroyisu.dll.tmp
c:\windows\system32\zogugusa.dll
c:\windows\system32\zubazolo.dll
.
((((((((((((((((((((((((( Files Created from 2009-10-05 to 2009-11-05 )))))))))))))))))))))))))))))))
.
2009-11-05 02:28 . 2009-11-05 02:28 -------- d-----w- c:\windows\LastGood
2009-10-30 14:48 . 2009-11-02 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\07905324
2009-10-30 14:48 . 2009-10-30 14:48 274 ----a-w- c:\documents and settings\All Users\Application Data\07905324\07905324.bat
2009-10-30 02:48 . 2009-11-02 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\88727638
2009-10-30 02:48 . 2009-10-30 02:48 274 ----a-w- c:\documents and settings\All Users\Application Data\88727638\88727638.bat
2009-10-29 14:48 . 2009-10-29 14:48 274 ----a-w- c:\documents and settings\All Users\Application Data\34489432\34489432.bat
2009-10-29 14:48 . 2009-11-02 04:03 -------- d-----w- c:\documents and settings\All Users\Application Data\34489432
2009-10-28 14:48 . 2009-11-02 04:03 -------- d-----w- c:\documents and settings\All Users\Application Data\36214723
2009-10-28 14:48 . 2009-10-28 14:48 274 ----a-w- c:\documents and settings\All Users\Application Data\36214723\36214723.bat
2009-10-28 05:35 . 2009-10-28 05:35 0 ----a-w- c:\documents and settings\Paul\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2009-10-28 05:27 . 2009-10-31 19:07 -------- d-----w- c:\documents and settings\Paul\Application Data\FrostWire
2009-10-26 02:45 . 2009-10-27 05:08 -------- d-----w- c:\documents and settings\All Users\Application Data\87967239
2009-10-25 14:45 . 2009-10-25 14:45 274 ----a-w- c:\documents and settings\All Users\Application Data\82153322\82153322.bat
2009-10-25 14:45 . 2009-10-27 05:04 -------- d-----w- c:\documents and settings\All Users\Application Data\82153322
2009-10-25 02:45 . 2009-10-27 05:04 -------- d-----w- c:\documents and settings\All Users\Application Data\17535021
2009-10-25 02:45 . 2009-10-25 02:45 274 ----a-w- c:\documents and settings\All Users\Application Data\17535021\17535021.bat
2009-10-25 01:27 . 2009-10-25 01:27 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-10-24 14:44 . 2009-10-24 14:44 274 ----a-w- c:\documents and settings\All Users\Application Data\94004320\94004320.bat
2009-10-24 14:44 . 2009-10-27 05:04 -------- d-----w- c:\documents and settings\All Users\Application Data\94004320
2009-10-24 04:21 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-24 04:21 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-24 04:21 . 2009-10-24 04:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-24 02:44 . 2009-10-24 02:44 274 ----a-w- c:\documents and settings\All Users\Application Data\38045020\38045020.bat
2009-10-24 02:44 . 2009-10-27 05:04 -------- d-----w- c:\documents and settings\All Users\Application Data\38045020
2009-10-23 14:44 . 2009-10-23 14:44 274 ----a-w- c:\documents and settings\All Users\Application Data\29178532\29178532.bat
2009-10-23 14:44 . 2009-10-27 05:04 -------- d-----w- c:\documents and settings\All Users\Application Data\29178532
2009-10-23 02:44 . 2009-10-27 05:04 -------- d-----w- c:\documents and settings\All Users\Application Data\74456026
2009-10-23 02:44 . 2009-10-23 02:44 274 ----a-w- c:\documents and settings\All Users\Application Data\74456026\74456026.bat
2009-10-22 14:43 . 2009-10-22 14:43 274 ----a-w- c:\documents and settings\All Users\Application Data\60582425\60582425.bat
2009-10-22 14:43 . 2009-10-27 05:04 -------- d-----w- c:\documents and settings\All Users\Application Data\60582425
2009-10-22 02:43 . 2009-10-22 02:43 274 ----a-w- c:\documents and settings\All Users\Application Data\67978643\67978643.bat
2009-10-22 02:43 . 2009-10-22 05:44 -------- d-----w- c:\documents and settings\All Users\Application Data\67978643
2009-10-21 14:43 . 2009-10-22 05:44 -------- d-----w- c:\documents and settings\All Users\Application Data\36329730
2009-10-21 14:43 . 2009-10-21 14:43 274 ----a-w- c:\documents and settings\All Users\Application Data\36329730\36329730.bat
2009-10-21 02:43 . 2009-10-21 02:43 274 ----a-w- c:\documents and settings\All Users\Application Data\10111610\10111610.bat
2009-10-21 02:43 . 2009-10-22 05:44 -------- d-----w- c:\documents and settings\All Users\Application Data\10111610
2009-10-20 14:42 . 2009-10-22 05:44 -------- d-----w- c:\documents and settings\All Users\Application Data\43850323
2009-10-20 14:42 . 2009-10-20 14:42 274 ----a-w- c:\documents and settings\All Users\Application Data\43850323\43850323.bat
2009-10-20 02:42 . 2009-10-22 05:44 -------- d-----w- c:\documents and settings\All Users\Application Data\02480418
2009-10-20 02:42 . 2009-10-20 02:42 274 ----a-w- c:\documents and settings\All Users\Application Data\02480418\02480418.bat
2009-10-19 02:09 . 2009-10-19 02:09 274 ----a-w- c:\documents and settings\All Users\Application Data\83099938\83099938.bat
2009-10-19 02:09 . 2009-10-22 05:44 -------- d-----w- c:\documents and settings\All Users\Application Data\83099938
2009-10-17 05:36 . 2009-11-02 03:46 -------- d-----w- c:\program files\Ultimate MMA Simulator 2 B3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-02 03:45 . 2009-03-27 04:10 -------- d-----w- c:\program files\UltimateMMASimulator 1.6.11
2009-11-02 03:45 . 2009-09-18 04:19 -------- d-----w- c:\program files\PokerStars
2009-10-31 18:45 . 2007-11-06 23:38 -------- d-----w- c:\documents and settings\Paul\Application Data\DivX
2009-10-28 20:56 . 2007-11-03 05:56 -------- d-----w- c:\program files\DivX
2009-10-28 20:53 . 2009-08-25 06:28 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-10-27 05:08 . 2009-07-21 04:09 117760 ----a-w- c:\documents and settings\Paul\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-10-27 05:08 . 2009-07-21 04:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-25 01:27 . 2008-06-28 04:10 -------- d-----w- c:\program files\TVUPlayer
2009-10-20 04:29 . 2009-07-21 03:06 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-08 23:22 . 2008-08-11 16:31 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-25 16:41 . 2009-09-25 16:41 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-09-25 16:41 . 2009-09-25 16:41 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-09-25 16:41 . 2009-09-25 16:41 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-09-25 16:41 . 2009-09-25 16:41 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-09-25 16:41 . 2009-09-25 16:41 696320 ----a-w- c:\windows\system32\DivX.dll
2009-08-30 02:14 . 2009-08-30 02:13 5519752 ----a-w- c:\documents and settings\Paul\Application Data\TVU Networks\TVU AutoUpgrade\TVUPlayer2.4.7.2.exe
2009-08-30 02:13 . 2007-09-18 19:49 27512 -c--a-w- c:\documents and settings\Paul\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-29_01.23.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 07:19 . 2007-11-07 07:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 11:07 . 2008-07-29 11:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 11:07 . 2008-07-29 11:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2009-11-05 02:24 . 2009-11-05 02:24 16384 c:\windows\temp\Perflib_Perfdata_6a4.dat
+ 2004-08-04 12:00 . 2009-11-05 02:29 40912 c:\windows\system32\perfc009.dat
- 2004-08-04 12:00 . 2009-05-17 19:53 40912 c:\windows\system32\perfc009.dat
+ 2009-02-26 19:49 . 2009-08-02 15:47 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2009-02-26 19:49 . 2009-06-03 15:38 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-29 01:28 . 2008-10-16 20:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2008-07-29 13:05 . 2008-07-29 13:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2009-07-12 06:12 . 2009-07-12 06:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 06:09 . 2009-07-12 06:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 06:08 . 2009-07-12 06:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2004-08-04 12:00 . 2009-11-05 02:29 313048 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2009-05-17 19:53 313048 c:\windows\system32\perfh009.dat
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-29 05:02 . 2009-07-29 05:01 148888 c:\windows\system32\javaws.exe
+ 2009-07-29 05:02 . 2009-07-29 05:01 144792 c:\windows\system32\javaw.exe
+ 2009-07-29 05:02 . 2009-07-29 05:01 144792 c:\windows\system32\java.exe
+ 2005-12-31 22:44 . 2009-10-08 23:22 138056 c:\windows\system32\FNTCACHE.DAT
- 2005-12-31 22:44 . 2009-06-10 08:14 138056 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-29 05:02 . 2009-07-29 05:01 410984 c:\windows\system32\deploytk.dll
+ 2006-01-01 05:09 . 2006-01-01 05:09 233472 c:\windows\system32\config\systemprofile\ntuser.dat
+ 2009-10-28 20:53 . 2009-10-28 20:53 169472 c:\windows\Installer\8893014.msi
+ 2009-07-29 05:01 . 2009-07-29 05:01 536576 c:\windows\Installer\86b64.msi
+ 2009-10-20 04:13 . 2009-10-20 04:13 228352 c:\windows\Installer\39b06d38.msi
+ 2008-07-29 13:05 . 2008-07-29 13:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-09-15 21:00 . 2009-09-15 21:00 15709696 c:\windows\Installer\8052e37a.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-10-27 2000112]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-29 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-10-27 05:08 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^microsoft office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^wireless-g notebook adapter.lnk]
backup=c:\windows\pss\Wireless-G Notebook Adapter.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccapp
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\Paul\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Avira\\AntiVir Desktop\\avcenter.exe"=
"c:\\Program Files\\Avira\\AntiVir Desktop\\update.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18722:TCP"= 18722:TCP:BitComet 18722 TCP
"18722:UDP"= 18722:UDP:BitComet 18722 UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 10:01 AM 9968]
R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 10:01 AM 74480]
R2 antivirschedulerservice;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7/20/2009 9:06 PM 108289]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/4/2008 10:49 PM 24652]
R3 Ptserli;PCTEL Serial Device Driver for INTEL;c:\windows\system32\drivers\ptserli.sys [1/2/2006 2:24 AM 128286]
R3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 10:01 AM 7408]
S2 SerialNW;NW Serial port driver;c:\windows\system32\DRIVERS\serialnw.sys --> c:\windows\system32\DRIVERS\serialnw.sys [?]
S3 TDWXP;WavePlus 802.11b Wireless PCI/PCMCIA Card Driver;c:\windows\system32\drivers\wpndis51.sys [8/3/2004 4:24 PM 151552]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 18:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ask.com?o=14196&l=dis
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
TCP: {0D4CE743-A9FD-4C88-86F7-DC289838F413} = 10.106.128.1
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\5gj188sf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\5gj188sf.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\5gj188sf.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
BHO-{a2a2a7e5-9791-46d6-96e1-5214bf32de17} - janubafo.dll
HKLM-Run-83099938 - c:\documents and settings\All Users\Application Data\83099938\83099938.exe
HKLM-Run-02480418 - c:\documents and settings\All Users\Application Data\02480418\02480418.exe
HKLM-Run-43850323 - c:\documents and settings\All Users\Application Data\43850323\43850323.exe
HKLM-Run-10111610 - c:\documents and settings\All Users\Application Data\10111610\10111610.exe
HKLM-Run-36329730 - c:\documents and settings\All Users\Application Data\36329730\36329730.exe
HKLM-Run-67978643 - c:\documents and settings\All Users\Application Data\67978643\67978643.exe
HKLM-Run-87967239 - c:\docume~1\ALLUSE~1\APPLIC~1\87967239\87967239.exe
HKLM-Run-36214723 - c:\documents and settings\All Users\Application Data\36214723\36214723.exe
HKLM-Run-88727638 - c:\documents and settings\All Users\Application Data\88727638\88727638.exe
HKLM-Run-07905324 - c:\documents and settings\All Users\Application Data\07905324\07905324.exe
SharedTaskScheduler-{ad0f88bb-061f-4692-a9db-7cb3ed0cbe65} - c:\windows\system32\hufubebe.dll
SSODL-bimakodud-{ad0f88bb-061f-4692-a9db-7cb3ed0cbe65} - c:\windows\system32\hufubebe.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-04 20:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-583907252-839522115-1343024091-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-583907252-839522115-1343024091-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B371C4C1-4F55-2EAA-427C-673701621939}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(580)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\documents and settings\Paul\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
- - - - - - - > 'explorer.exe'(3756)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
c:\windows\system32\pctspk.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-11-05 20:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-05 02:46
ComboFix2.txt 2009-07-29 04:40
ComboFix3.txt 2009-07-29 01:32
Pre-Run: 20,500,508,672 bytes free
Post-Run: 21,196,935,168 bytes free