ComboFix 09-11-25.05 - 12LinNZ 27/11/2009 11:05.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.1977.1487 [GMT 11:00]
Running from: c:\documents and settings\12linnz\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\12linnz\Desktop\CFScript.txt
AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\12linnz\Application Data\addons.dat
c:\program files\HaRepacker
c:\program files\HaRepacker\HaRepacker.exe
c:\program files\HaRepacker\logg.dat
.
((((((((((((((((((((((((( Files Created from 2009-10-27 to 2009-11-27 )))))))))))))))))))))))))))))))
.
2009-11-26 07:49 . 2009-11-26 07:49 -------- dc----w- c:\documents and settings\12linnz\Application Data\Malwarebytes
2009-11-26 07:49 . 2009-09-10 03:54 38224 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-26 07:49 . 2009-11-26 07:49 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-26 07:49 . 2009-11-26 07:49 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-26 07:49 . 2009-09-10 03:53 19160 -c--a-w- c:\windows\system32\drivers\mbam.sys
2009-11-20 00:06 . 2009-11-20 00:06 -------- dc----w- c:\program files\Activision
2009-11-19 05:56 . 2009-11-19 05:56 -------- dc----w- c:\program files\ERUNT
2009-11-17 12:25 . 2009-11-17 12:25 -------- dc----w- c:\documents and settings\12linnz\Local Settings\Application Data\Rockstar Games
2009-11-17 08:56 . 2009-11-17 08:56 107888 -c--a-w- c:\windows\system32\CmdLineExt.dll
2009-11-17 05:37 . 2009-11-17 05:37 -------- dc----w- c:\documents and settings\All Users\Application Data\BioWare
2009-11-17 00:50 . 2009-11-17 00:50 -------- dc----w- c:\windows\system32\winrm
2009-11-17 00:50 . 2009-11-17 00:50 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2009-11-16 06:57 . 2009-11-16 07:17 -------- dc----w- c:\program files\Dragon Age
2009-11-16 06:57 . 2009-11-16 07:30 -------- dc----w- c:\program files\Common Files\BioWare
2009-11-16 06:15 . 2009-11-26 08:28 -------- dc----w- c:\program files\Rockstar Games
2009-11-15 20:50 . 2009-11-15 20:50 152576 -c--a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-15 20:50 . 2009-11-15 20:50 79488 -c--a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-12 13:21 . 2009-11-21 12:16 -------- dc----w- C:\Log
2009-11-11 05:16 . 2009-11-11 05:17 -------- dc----w- c:\program files\Machinarium
2009-11-10 07:25 . 2009-11-10 07:25 -------- dc----w- c:\program files\DIFX
2009-11-10 06:44 . 2009-11-10 06:44 -------- dc----w- c:\program files\2K Games
2009-11-10 06:44 . 2009-11-10 07:24 -------- dc----w- C:\BDS
2009-11-08 12:22 . 2009-11-12 09:40 -------- dc----w- c:\windows\system32\Adobe
2009-11-05 10:37 . 2009-11-26 23:57 -------- dc----w- c:\documents and settings\12linnz\Application Data\runic games
2009-11-05 10:15 . 2009-11-26 23:57 -------- dc----w- c:\program files\Runic Games
2009-11-03 11:54 . 2009-11-03 11:54 -------- dc----w- c:\documents and settings\12linnz\Application Data\vlc
2009-11-03 10:36 . 2009-11-03 10:36 -------- dc----w- c:\documents and settings\12linnz\Local Settings\Application Data\Graboid_Inc
2009-11-03 10:36 . 2009-11-03 10:38 -------- dc----w- c:\documents and settings\12linnz\Application Data\MozillaControl
2009-11-03 10:36 . 2009-11-03 10:40 -------- dc----w- c:\documents and settings\12linnz\Local Settings\Application Data\Graboid
2009-11-03 10:35 . 2009-11-03 10:35 -------- dc----w- c:\program files\Mozilla ActiveX Control v1.7.12
2009-11-03 10:34 . 2009-11-03 10:34 -------- dc----w- c:\program files\VideoLAN
2009-11-03 10:30 . 2009-11-26 23:58 -------- dc----w- c:\program files\Graboid
2009-11-02 12:07 . 2009-11-02 12:07 -------- dc----w- c:\program files\iPod
2009-11-02 12:00 . 2009-11-02 12:00 79144 -c--a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-26 22:24 . 2009-08-03 08:27 -------- dc----w- c:\documents and settings\12linnz\Application Data\uTorrent
2009-11-19 17:30 . 2009-09-19 23:44 -------- dc----w- c:\documents and settings\12linnz\Application Data\Gearbox Software
2009-11-19 17:30 . 2009-09-19 23:30 -------- dc----w- c:\program files\Ubisoft
2009-11-17 00:56 . 2008-10-24 01:29 -------- dc----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-16 07:30 . 2009-09-11 21:55 -------- dc----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-15 20:51 . 2008-11-05 00:35 -------- dc----w- c:\program files\Java
2009-11-12 13:11 . 2009-10-06 03:58 -------- dc----w- c:\program files\EA Sports
2009-11-10 10:19 . 2009-08-03 08:29 -------- dc----w- c:\program files\Messenger Plus! Live
2009-11-10 07:24 . 2009-08-26 04:27 -------- dc----w- c:\documents and settings\All Users\Application Data\Sports Interactive
2009-11-10 07:21 . 2009-08-26 00:42 -------- dc----w- c:\documents and settings\12linnz\Application Data\Sports Interactive
2009-11-10 07:01 . 2009-08-26 00:43 -------- dc----w- c:\program files\Sports Interactive
2009-11-10 06:44 . 2008-10-22 03:27 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-11-04 05:34 . 2009-09-19 02:12 139456 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-04 05:34 . 2009-09-19 02:12 190160 -c--a-w- c:\windows\system32\PnkBstrB.exe
2009-11-03 01:45 . 2009-09-22 02:44 -------- dc----w- c:\documents and settings\12linnz\Application Data\LimeWire
2009-11-02 12:08 . 2009-09-11 07:44 -------- dc----w- c:\program files\iTunes
2009-11-02 12:07 . 2009-08-03 08:19 -------- dc----w- c:\program files\Common Files\Apple
2009-10-28 08:50 . 2009-09-23 08:09 664 -c--a-w- c:\windows\system32\d3d9caps.dat
2009-10-26 23:20 . 2009-10-26 23:20 -------- dc----w- c:\program files\Google
2009-10-23 08:28 . 2009-09-19 02:12 138056 -c--a-w- c:\documents and settings\12linnz\Application Data\PnkBstrK.sys
2009-10-23 08:28 . 2009-09-19 02:12 138056 -c--a-w- c:\documents and settings\12linnz\Application Data\PnkBstrK.sys
2009-10-23 08:28 . 2009-09-19 02:12 75064 -c--a-w- c:\windows\system32\PnkBstrA.exe
2009-10-23 08:28 . 2009-10-23 08:28 2395944 -c--a-w- c:\windows\system32\pbsvc_heroes.exe
2009-10-22 22:39 . 2008-10-24 01:40 -------- dc----w- c:\program files\Common Files\Adobe
2009-10-19 05:39 . 2009-09-11 07:52 77028 -c-ha-w- c:\windows\system32\mlfcache.dat
2009-10-14 07:25 . 2009-10-14 07:23 -------- dc----w- c:\documents and settings\12linnz\Application Data\PPStream
2009-10-10 17:17 . 2008-11-05 00:35 411368 -c--a-w- c:\windows\system32\deploytk.dll
2009-10-09 05:23 . 2009-10-09 05:23 1107456 -c----w- c:\windows\system32\WsmSvc.dll
2009-10-09 05:23 . 2009-10-09 05:23 178176 -c----w- c:\windows\system32\wevtfwd.dll
2009-10-09 05:22 . 2009-10-09 05:22 368640 -c----w- c:\windows\system32\WsmRes.dll
2009-10-09 05:22 . 2009-10-09 05:22 69632 -c----w- c:\windows\system32\winrs.exe
2009-10-09 05:22 . 2009-10-09 05:22 42496 -c----w- c:\windows\system32\pwrshplugin.dll
2009-10-09 03:56 . 2009-10-09 03:56 209408 -c----w- c:\windows\system32\WsmWmiPl.dll
2009-10-09 03:56 . 2009-10-09 03:56 14848 -c----w- c:\windows\system32\wsmprovhost.exe
2009-10-09 03:56 . 2009-10-09 03:56 22528 -c----w- c:\windows\system32\winrshost.exe
2009-10-09 03:56 . 2009-10-09 03:56 25088 -c----w- c:\windows\system32\winrmprov.dll
2009-10-09 03:56 . 2009-10-09 03:56 12288 -c----w- c:\windows\system32\wsmplpxy.dll
2009-10-09 03:56 . 2009-10-09 03:56 2048 -c----w- c:\windows\system32\winrsmgr.dll
2009-10-09 03:56 . 2009-10-09 03:56 233984 -c----w- c:\windows\system32\winrscmd.dll
2009-10-09 03:56 . 2009-10-09 03:56 225280 -c----w- c:\windows\system32\wsmanhttpconfig.exe
2009-10-09 03:56 . 2009-10-09 03:56 12288 -c----w- c:\windows\system32\winrssrv.dll
2009-10-09 03:56 . 2009-10-09 03:56 139776 -c----w- c:\windows\system32\WsmAuto.dll
2009-10-08 03:57 . 2007-10-09 02:03 611328 -c--a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 03:57 . 2006-02-28 12:00 220160 -c--a-w- c:\windows\system32\oleacc.dll
2009-10-08 03:56 . 2006-02-28 12:00 20480 -c--a-w- c:\windows\system32\oleaccrc.dll
2009-10-06 05:20 . 2009-10-06 05:20 -------- dc----w- c:\documents and settings\12linnz\Application Data\Leadertech
2009-10-05 09:18 . 2009-10-05 07:41 -------- dc----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-10-05 09:18 . 2009-10-05 07:41 -------- dc----w- c:\documents and settings\12linnz\Application Data\Uniblue
2009-10-05 07:38 . 2009-10-05 07:38 -------- dc----w- c:\program files\IObit
2009-09-30 22:48 . 2009-09-30 22:48 -------- dc----w- c:\program files\Electronic Arts
2009-09-29 04:53 . 2009-09-29 04:47 -------- dc----w- c:\program files\Microsoft
2009-09-29 04:53 . 2009-09-29 04:53 -------- dc----w- c:\program files\Microsoft Office Outlook Connector
2009-09-28 05:41 . 2009-09-27 07:02 -------- dc----w- c:\program files\Vuze
2009-09-22 21:59 . 2009-08-03 08:08 105488 -c--a-w- c:\documents and settings\12linnz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-19 02:12 . 2009-09-19 02:12 794408 -c--a-w- c:\windows\system32\pbsvc.exe
2009-09-18 06:39 . 2009-09-18 06:39 444952 -c--a-w- c:\windows\system32\wrap_oal.dll
2009-09-18 06:39 . 2009-09-18 06:39 109080 -c--a-w- c:\windows\system32\OpenAL32.dll
2009-09-14 07:58 . 2009-09-30 22:47 1291640 -c--a-w- c:\documents and settings\12linnz\Application Data\Mozilla\Firefox\Profiles\ehr3xlul.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\BFHUpdater.exe
2009-09-14 07:58 . 2009-09-30 22:47 729088 -c--a-w- c:\documents and settings\12linnz\Application Data\Mozilla\Firefox\Profiles\ehr3xlul.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
2009-09-11 21:54 . 2009-09-11 21:54 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-04 07:44 . 2009-09-11 21:56 515416 -c--a-w- c:\windows\system32\XAudio2_5.dll
2009-09-04 07:44 . 2009-09-11 21:56 238936 -c--a-w- c:\windows\system32\xactengine3_5.dll
2009-09-04 07:44 . 2009-09-11 21:56 69464 -c--a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 07:29 . 2009-09-11 21:56 235344 -c--a-w- c:\windows\system32\d3dx11_42.dll
2009-09-04 07:29 . 2009-09-11 21:56 453456 -c--a-w- c:\windows\system32\d3dx10_42.dll
2009-09-04 07:29 . 2009-09-11 21:56 1974616 -c--a-w- c:\windows\system32\D3DCompiler_42.dll
2009-09-04 07:29 . 2009-09-11 21:56 5501792 -c--a-w- c:\windows\system32\d3dcsx_42.dll
2009-09-04 07:29 . 2009-09-11 21:56 1892184 -c--a-w- c:\windows\system32\D3DX9_42.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-26_09.59.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-11-26 09:59 . 2008-07-04 00:35 73728 c:\windows\Temp\sophos_autoupdate1.dir\xmltok.dll
+ 2009-11-27 00:18 . 2008-07-04 00:35 73728 c:\windows\Temp\sophos_autoupdate1.dir\xmltok.dll
- 2009-11-26 09:59 . 2008-07-04 00:35 57344 c:\windows\Temp\sophos_autoupdate1.dir\xmlparse.dll
+ 2009-11-27 00:18 . 2008-07-04 00:35 57344 c:\windows\Temp\sophos_autoupdate1.dir\xmlparse.dll
+ 2009-11-27 00:18 . 2008-07-04 00:35 14336 c:\windows\Temp\sophos_autoupdate1.dir\xmlcpp.dll
- 2009-11-26 09:59 . 2008-07-04 00:35 14336 c:\windows\Temp\sophos_autoupdate1.dir\xmlcpp.dll
- 2009-11-26 09:59 . 2008-07-04 00:35 18432 c:\windows\Temp\sophos_autoupdate1.dir\SharedRes.dll
+ 2009-11-27 00:18 . 2008-07-04 00:35 18432 c:\windows\Temp\sophos_autoupdate1.dir\SharedRes.dll
- 2009-11-26 09:59 . 2008-07-04 00:35 20480 c:\windows\Temp\sophos_autoupdate1.dir\crypto.dll
+ 2009-11-27 00:18 . 2008-07-04 00:35 20480 c:\windows\Temp\sophos_autoupdate1.dir\crypto.dll
+ 2009-11-27 00:18 . 2008-07-04 00:35 45056 c:\windows\Temp\sophos_autoupdate1.dir\boost_date_time-vc71-mt-1_32.dll
- 2009-11-26 09:59 . 2008-07-04 00:35 45056 c:\windows\Temp\sophos_autoupdate1.dir\boost_date_time-vc71-mt-1_32.dll
+ 2009-11-27 00:19 . 2009-11-27 00:19 16384 c:\windows\Temp\Perflib_Perfdata_374.dat
+ 2009-11-27 00:18 . 2009-11-27 00:18 16384 c:\windows\Temp\Perflib_Perfdata_130.dat
+ 2009-11-27 00:18 . 2009-07-22 14:50 2970 c:\windows\Temp\sophos_autoupdate1.dir\scf.dat
- 2009-11-26 09:59 . 2009-07-22 14:50 2970 c:\windows\Temp\sophos_autoupdate1.dir\scf.dat
- 2009-11-26 09:59 . 2009-01-28 13:06 208896 c:\windows\Temp\sophos_autoupdate1.dir\retailer.dll
+ 2009-11-27 00:18 . 2009-01-28 13:06 208896 c:\windows\Temp\sophos_autoupdate1.dir\retailer.dll
+ 2009-11-27 00:18 . 2008-07-04 00:33 348160 c:\windows\Temp\sophos_autoupdate1.dir\MSVCR71.DLL
- 2009-11-26 09:59 . 2008-07-04 00:33 348160 c:\windows\Temp\sophos_autoupdate1.dir\MSVCR71.DLL
+ 2009-11-27 00:18 . 2008-07-04 00:34 499712 c:\windows\Temp\sophos_autoupdate1.dir\MSVCP71.DLL
- 2009-11-26 09:59 . 2008-07-04 00:34 499712 c:\windows\Temp\sophos_autoupdate1.dir\MSVCP71.DLL
+ 2009-11-27 00:18 . 2008-07-04 00:35 745472 c:\windows\Temp\sophos_autoupdate1.dir\libeay32.dll
- 2009-11-26 09:59 . 2008-07-04 00:35 745472 c:\windows\Temp\sophos_autoupdate1.dir\libeay32.dll
+ 2009-11-27 00:18 . 2009-01-28 13:07 159744 c:\windows\Temp\sophos_autoupdate1.dir\libcurl.dll
- 2009-11-26 09:59 . 2009-01-28 13:07 159744 c:\windows\Temp\sophos_autoupdate1.dir\libcurl.dll
+ 2009-11-27 00:18 . 2009-07-22 14:50 176128 c:\windows\Temp\sophos_autoupdate1.dir\CidSync.dll
- 2009-11-26 09:59 . 2009-07-22 14:50 176128 c:\windows\Temp\sophos_autoupdate1.dir\CidSync.dll
- 2009-11-26 09:59 . 2009-07-01 13:42 172032 c:\windows\Temp\sophos_autoupdate1.dir\ChannelUpdater.dll
+ 2009-11-27 00:18 . 2009-07-01 13:42 172032 c:\windows\Temp\sophos_autoupdate1.dir\ChannelUpdater.dll
+ 2009-11-27 00:18 . 2009-07-22 14:50 663552 c:\windows\Temp\sophos_autoupdate1.dir\ALUpdate.exe
- 2009-11-26 09:59 . 2009-07-22 14:50 663552 c:\windows\Temp\sophos_autoupdate1.dir\ALUpdate.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2008-10-22 3680768]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1028096]
"IFXSPMGT"="c:\windows\system32\ifxspmgt.exe" [2007-07-23 677144]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-04 170520]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-05-02 870920]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-07 16862208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2009-7-2 245760]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-11 576104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-10-22 03:39 3076096 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2010\\fm.exe"=
"c:\\Program Files\\2K Games\\Gearbox Software\\Borderlands\\Binaries\\Borderlands.exe"=
"c:\\Program Files\\EA Sports\\FIFA Online 2\\FF2Client.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Documents and Settings\\12linnz\\My Documents\\Downloads\\Call Of Duty 4\\iw3mp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8484:TCP"= 8484:TCP:Localhost
"8888:TCP"= 8888:TCP:ms
"3306:TCP"= 3306:TCP:MySQL Server
R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\drivers\AlfaFF.sys [22/10/2008 2:39 PM 43184]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/09/2009 8:54 AM 721904]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [24/07/2007 8:59 AM 38816]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [3/08/2009 6:08 PM 110848]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [3/08/2009 6:09 PM 38528]
R2 FPSensor;LTT-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\drivers\FPSensor.sys [22/10/2008 2:39 PM 20352]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [29/10/2009 1:34 PM 80936]
R2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [3/08/2009 6:08 PM 98304]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [24/07/2007 8:59 AM 41216]
R3 ITEIRDA;ITE Infrared Device Driver;c:\windows\system32\drivers\ITEirda.sys [22/10/2008 2:59 PM 24576]
S2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [22/10/2008 2:39 PM 3481600]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15/08/2008 5:46 AM 284016]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [16/11/2009 6:17 PM 25832]
S3 GarenaPEngine;GarenaPEngine; [x]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [28/02/2006 11:00 PM 14336]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [3/08/2009 6:09 PM 14976]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
2009-11-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://intranet.cgs.vic.edu.au
uInternet Settings,ProxyOverride = local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\12linnz\Application Data\Mozilla\Firefox\Profiles\ehr3xlul.default\
FF - plugin: c:\documents and settings\12linnz\Application Data\Mozilla\Firefox\Profiles\ehr3xlul.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-27 11:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sophos Message Router]
"ImagePath"="\"c:\program files\Sophos\Remote Management System\RouterNT.exe\" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1024)
c:\program files\Acer\Acer Bio Protection\CompPtc.dll
c:\program files\Acer\Acer Bio Protection\CustomRes.dll
c:\windows\system32\NBMatS1SDK.DLL
c:\program files\Acer\Acer Bio Protection\WinNotify.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'lsass.exe'(1080)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(4044)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\IfxPsdSv.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Sophos\Remote Management System\ManagementAgentNT.exe
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\Sophos\Remote Management System\RouterNT.exe
c:\program files\Infineon\Security Platform Software\PSDrt.exe
c:\program files\Infineon\Security Platform Software\SpTna.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\docume~1\12linnz\LOCALS~1\Temp\RtkBtMnt.exe
.
**************************************************************************
.
Completion time: 2009-11-27 11:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-27 00:30
ComboFix2.txt 2009-11-26 10:08
Pre-Run: 17,998,426,112 bytes free
Post-Run: 17,951,010,816 bytes free
- - End Of File - - 3DFC0ABCEF49D4702E7E660285A5B477