ComboFix 09-12-02.05 - Owner 12/06/2009 15:45.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.494 [GMT -6:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFscript.txt
file zipped: c:\windows\system32\mmf.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\mmf.sys
.
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.
2009-12-06 21:20 . 2009-12-06 21:20 ——– d—–w- c:\program files\ATI
2009-12-06 21:14 . 2009-12-06 21:14 ——– d—–w- C:\ATI
2009-12-06 20:50 . 2009-12-06 20:50 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\UAB
2009-12-06 20:50 . 2009-12-06 20:50 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\PC_Drivers_Headquarters
2009-12-06 20:49 . 2009-12-06 20:49 ——– d—–w- c:\program files\PC Drivers HeadQuarters
2009-11-30 00:03 . 2009-11-30 20:59 ——– d—–w- c:\documents and settings\Owner\Application Data\ElementalsTheMagicKey
2009-11-21 17:40 . 2009-11-21 17:40 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2009-11-21 17:31 . 2009-11-21 17:31 ——– d—–w- c:\program files\2K Games
2009-11-15 13:39 . 2009-11-15 13:39 ——– d—–w- c:\documents and settings\Owner\Application Data\Flood Light Games
2009-11-15 13:39 . 2009-11-15 13:39 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Flood Light Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-06 18:28 . 2007-05-17 04:51 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-05 23:49 . 2007-05-17 04:53 1100 —-a-w- c:\windows\system32\d3d8caps.dat
2009-12-05 16:32 . 2007-05-17 23:50 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-12-01 19:35 . 2009-07-01 01:52 ——– d—–w- c:\program files\Opera
2009-11-30 21:26 . 2009-10-14 22:02 ——– d—–w- c:\documents and settings\Owner\Application Data\Merscom
2009-11-30 21:26 . 2009-07-03 01:22 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Merscom
2009-11-25 01:05 . 2009-10-26 20:10 1 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-21 17:31 . 2006-01-07 04:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-11-19 02:48 . 2009-10-30 15:37 ——– d—–w- c:\program files\Finjan Secure Browsing
2009-11-19 02:26 . 2008-06-20 20:51 ——– d—–w- c:\documents and settings\Owner\Application Data\Playrix Entertainment
2009-11-14 20:23 . 2007-05-18 00:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\JollyBear
2009-11-12 23:32 . 2007-06-19 00:59 ——– d—–w- c:\documents and settings\Owner\Application Data\PlayFirst
2009-11-12 23:32 . 2007-06-19 00:59 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\PlayFirst
2009-11-11 09:02 . 2007-05-17 00:15 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-11-07 01:11 . 2009-04-07 20:07 ——– d—–w- c:\documents and settings\Owner\Application Data\Meridian93
2009-11-06 22:36 . 2007-09-28 23:07 ——– d—–w- c:\documents and settings\Owner\Application Data\gtk-2.0
2009-11-05 21:50 . 2009-11-05 21:49 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Becky Brogan
2009-10-30 17:11 . 2009-03-07 16:17 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-10-30 17:11 . 2009-09-01 19:55 38208 —-a-w- c:\documents and settings\Default User.WINDOWS\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-30 17:11 . 2009-03-07 16:18 38208 —-a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-30 15:34 . 2009-10-30 15:09 ——– d—–w- c:\documents and settings\Owner\Application Data\WinFF
2009-10-30 15:09 . 2009-10-30 15:09 ——– d—–w- c:\program files\WinFF
2009-10-29 17:36 . 2009-10-29 17:26 ——– d—–w- c:\program files\AutoGK
2009-10-29 17:30 . 2009-10-29 17:30 ——– d—–w- c:\program files\XviD
2009-10-29 17:29 . 2009-10-29 17:29 ——– d—–w- c:\program files\Gabest
2009-10-29 16:53 . 2009-10-29 16:07 ——– d—–w- c:\documents and settings\Owner\Application Data\Vso
2009-10-29 16:53 . 2009-10-29 16:07 87608 —-a-w- c:\documents and settings\Owner\Application Data\inst.exe
2009-10-29 16:53 . 2009-10-29 16:07 87608 —-a-w- c:\documents and settings\Owner\Application Data\inst.exe
2009-10-29 16:53 . 2009-10-29 16:07 47360 —-a-w- c:\documents and settings\Owner\Application Data\pcouffin.sys
2009-10-29 16:53 . 2009-10-29 16:07 47360 —-a-w- c:\documents and settings\Owner\Application Data\pcouffin.sys
2009-10-29 16:07 . 2009-10-29 16:07 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-10-27 23:04 . 2007-05-16 03:13 29600 -c–a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-26 20:09 . 2009-10-26 20:09 ——– d—–w- c:\documents and settings\Owner\Application Data\OpenOffice.org
2009-10-26 20:07 . 2009-10-26 20:07 ——– d—–w- c:\program files\JRE
2009-10-26 20:07 . 2009-10-26 20:07 ——– d—–w- c:\program files\OpenOffice.org 3
2009-10-26 20:06 . 2009-06-22 17:49 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-10-26 20:06 . 2007-06-18 00:30 ——– d—–w- c:\program files\Java
2009-10-25 17:56 . 2009-10-25 17:56 ——– d—–w- c:\documents and settings\Owner\Application Data\Magic Academy 2
2009-10-25 16:49 . 2009-10-25 16:49 ——– d—–w- c:\documents and settings\Owner\Application Data\gamehouse
2009-10-25 16:49 . 2008-06-13 20:57 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\GameHouse
2009-10-23 20:57 . 2007-07-04 13:19 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Sandlot Games
2009-10-19 21:08 . 2009-09-21 21:10 3695616 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\AutoLaunch.exe
2009-10-19 21:08 . 2009-06-22 21:08 2353992 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-10-17 21:55 . 2009-10-17 21:55 ——– d—–w- c:\documents and settings\Owner\Application Data\FlyWheelGames
2009-10-17 19:13 . 2009-10-17 19:13 ——– d—–w- c:\documents and settings\Owner\Application Data\Freezetag
2009-10-17 13:48 . 2009-10-17 13:48 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Wrinkle-free Games
2009-10-11 19:18 . 2008-09-10 17:16 ——– d—a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-10-11 15:07 . 2009-10-11 15:07 ——– d—–w- c:\program files\Enigma Software Group
2009-10-10 23:34 . 2009-10-10 23:34 18308 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\serifiqylu.dll
2009-10-10 23:34 . 2009-10-10 23:34 18308 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\serifiqylu.dll
2009-10-10 23:34 . 2009-10-10 23:34 16399 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\ybizifeky.dat
2009-10-10 23:34 . 2009-10-10 23:34 14554 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\ricesotaj.exe
2009-10-10 23:23 . 2009-10-10 23:23 ——– d—–w- c:\program files\VS Revo Group
2009-10-10 23:15 . 2008-09-10 17:18 ——– d—–w- c:\program files\SpywareBlaster
2009-10-10 23:12 . 2009-10-10 22:47 ——– d—–w- c:\documents and settings\Owner\Application Data\Uniblue
2009-10-10 23:12 . 2009-10-10 22:47 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\DriverScanner
2009-10-10 22:00 . 2009-04-02 03:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-10-10 22:00 . 2009-04-07 01:38 4045528 -c–a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-10-10 20:00 . 2009-10-10 20:00 19329 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\ivuxuw.scr
2009-10-10 20:00 . 2009-10-10 20:00 19329 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\ivuxuw.scr
2009-10-10 20:00 . 2009-10-10 20:00 18387 —-a-w- c:\documents and settings\Owner\Application Data\ykerocivax.bin
2009-10-10 20:00 . 2009-10-10 20:00 17842 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\lysuryciw.bat
2009-10-10 20:00 . 2009-10-10 20:00 17094 —-a-w- c:\documents and settings\Owner\Application Data\aqar.bin
2009-10-10 20:00 . 2009-10-10 20:00 15334 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\ivoh.reg
2009-10-10 19:56 . 2009-10-10 19:56 341504 —-a-w- c:\documents and settings\Owner\Application Data\seres.exe
2009-10-10 19:56 . 2009-10-10 19:56 341504 —-a-w- c:\documents and settings\Owner\Application Data\seres.exe
2009-09-21 21:12 . 2009-06-22 21:08 314712 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\threatwork.exe
2009-09-21 21:12 . 2009-06-22 21:08 25440 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-09-21 21:12 . 2009-06-22 21:08 168800 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\lavamessage.dll
2009-09-21 21:12 . 2009-05-26 21:08 15688 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-09-21 21:12 . 2009-04-02 03:00 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-09-21 21:12 . 2009-06-22 21:08 349008 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\lavalicense.dll
2009-09-21 21:12 . 2009-09-21 21:12 17632 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\WSCUpdate.dll
2009-09-21 21:12 . 2009-06-22 21:08 298336 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\UpdateManager.dll
2009-09-21 21:12 . 2009-05-26 21:08 84320 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\ShellExt.dll
2009-09-21 21:12 . 2009-06-22 21:08 1630560 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-09-21 21:11 . 2009-05-26 21:08 246640 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\RPAPI.dll
2009-09-21 21:11 . 2009-09-21 21:11 68640 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\Drivers\64\lbd.sys
2009-09-21 21:11 . 2009-05-26 21:08 40288 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\PrivacyClean.dll
2009-09-21 21:11 . 2009-09-21 21:11 303976 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\Drivers\64\AAWDriverTool.exe
2009-09-21 21:11 . 2009-06-22 21:08 664936 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\CEAPI.dll
2009-09-21 21:10 . 2009-06-22 21:08 562552 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareCommand.exe
2009-09-21 21:09 . 2009-06-22 21:08 566632 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareAdmin.exe
2009-09-21 21:09 . 2009-06-22 21:08 640760 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\AAWWSC.exe
2009-09-21 21:08 . 2009-06-22 21:08 520024 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\AAWTray.exe
2009-09-21 21:08 . 2009-06-22 21:08 1028432 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft\Ad-Aware\update\AAWService.exe
2009-09-17 02:18 . 2009-09-17 02:18 413696 —-a-w- c:\documents and settings\Owner\Application Data\yoclient\native\OpenAL32.dll
2009-09-17 02:18 . 2009-09-17 02:18 153600 —-a-w- c:\documents and settings\Owner\Application Data\yoclient\native\lwjgl.dll
2009-09-11 14:18 . 2006-02-28 12:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-10 19:54 . 2009-04-02 03:25 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2009-04-02 03:25 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2007-05-12 23:38 . 2007-05-12 23:38 774144 —-a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-12-03_00.54.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-06 21:59 . 2009-12-06 21:59 16384 c:\windows\temp\Perflib_Perfdata_730.dat
- 2007-01-29 08:58 . 2009-07-14 11:03 46080 c:\windows\System32\tzchange.exe
+ 2007-01-29 08:58 . 2009-10-28 15:07 46080 c:\windows\System32\tzchange.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 54584 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\UNINST_Uninstall_D_4299976C1167441FA07CEF9926E410B1.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 46392 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\ProductName.chm.de_E8BE655ADEA641369B5E012FC4DD61C6.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 75064 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\NewShortcut7_093EA01C878D4FB8BBB75CF2AF29E7A1.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 75064 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\DriversHQ.DriverDe_84B8F33B3EBF407BAC7CF7FF8090594C.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 75064 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\DriversHQ.DriverDe_73EA94828B1A467994E24B03923D8FFE.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 75064 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\DriverDetective.pt_6CF114D33913468CBA2AA6967939B819.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 75064 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\DriverDetective.it_251B66F1CA924E82A1EE29E85D5EC5A1.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 75064 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\DriverDetective.fr_E1678746353A46E3A9150D3E8B3832B1.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 75064 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\DriverDetective.es_654C8EA5162D4D4084239A5EDD67F462.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 75064 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\DriverDetective.ch_571875AB094D409B841CA52363CEAF75.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 75064 c:\windows\Installer\{4640FDE1-B83A-4376-84ED-86F86BEE2D41}\ARPPRODUCTICON.exe
+ 2009-12-06 20:49 . 2009-12-06 20:49 15872 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\1ded203bd27031c3a5e3441f94b528c0\Microsoft.VisualC.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 58368 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\056d7c7d3c3b16eee1c3af4a120eb03b\DriversHQ.DriverDetective.ExceptionLogging.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\4b8fdce9960f5bd4884eaeee1442a355\XPBurnComponent.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\af21e3011fb4e107b13ea5c40c351ec4\System.Runtime.Remoting.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 309248 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\d4b78c1f7910f81abe6576f95a438186\Microsoft.Practices.EnterpriseLibrary.Common.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 148992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\d359b1ece5f5561e997a539fed49412f\Microsoft.Practices.EnterpriseLibrary.Security.Cryptography.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 303616 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\568201a26541439437df40aa3a5b27b1\Microsoft.Practices.ObjectBuilder.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 230400 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\de76bbb430b59ef7a16d498d70d9801e\Microsoft.ApplicationBlocks.Updater.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 307200 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\a23c5cd7b0a1d8be68ba99452e43afb1\DriversHQ.DriverDetective.Common.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 296960 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\036073efd78dcabb14850e0899aadd4b\DriversHQ.DriverDetective.Client.Communication.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 402432 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.Common\d994906214c2beb90c64ea53f977bc43\DriversHQ.Common.ni.dll
+ 2008-08-17 04:58 . 2009-07-31 16:05 1372672 c:\windows\System32\msxml6.dll
+ 2006-02-28 12:00 . 2009-07-31 04:35 1172480 c:\windows\System32\msxml3.dll
+ 2008-08-17 04:58 . 2009-07-31 16:05 1372672 c:\windows\System32\dllcache\msxml6.dll
+ 2006-02-28 12:00 . 2009-07-31 04:35 1172480 c:\windows\System32\dllcache\msxml3.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 1928192 c:\windows\Installer\f34c3ec.msi
+ 2009-12-06 20:49 . 2009-12-06 20:49 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\ffa1018e8022964eb51025c2c6d8727a\System.Data.OracleClient.ni.dll
+ 2009-12-06 20:49 . 2009-12-06 20:49 3817984 c:\windows\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\3b461c3596b2e41fc5107762d709bec1\DriversHQ.DriverDetective.Client.ni.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-07-27 286720]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-09-21 520024]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-26 149280]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-06-01 16208384]
c:\users\Zoie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Acer Product Registration.lnk - c:\program files\Acer Registration\ACE1.exe [2006-12-13 3166208]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\Handspring\HOTSYNC.EXE [2009-2-25 299008]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Games\\Sony\\EverQuest II\\EverQuest2.exe"=
"c:\\Program Files\\Real\\RealArcade\\RNArcade.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\GIMP-2.0\\lib\\gimp\\2.0\\plug-ins\\script-fu.exe"=
"c:\\Program Files\\KingsIsle Entertainment\\Wizard101\\Wizard101.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Disney\\Disney Online\\PiratesOnline\\Launcher1.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization IV Colonization\\Colonization.exe"=
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [3/31/2009 3:08 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 1:06 PM 1028432]
S2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [7/19/2008 3:49 PM 2560]
.
Contents of the 'Scheduled Tasks' folder
2009-12-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 21:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.thebreastcancersite.com/clickToGive/home.faces?siteId=2&ThirdPartyClicks=EPB_072709_t
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &Search
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://kingsisle.hs.llnwd.net/e1/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\v00uuacb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=3&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.thebreastcancersite.com/clickToGive/home.faces?siteId=2
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=59099&ei=utf-8&yahoo_domain=search.yahoo.com&p=
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-06 16:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \04F7528984592EA0]
"1"=hex:d5,3e,50,00,82,25,c9,f6,dd,f6,18,c9,99,5b,70,06,b4,b6,07,c1,1b,95,01,
2f
"2"=hex:e4,d7,da,38,b0,b5,3c,88,a2,01,5f,80,71,fc,07,41,22,5f,c1,26,5d,01,8c,
86
"3"=hex:d5,3e,50,00,82,25,c9,f6,dd,f6,18,c9,99,5b,70,06,53,86,fb,a3,af,c0,18,
8b,f9,e5,ef,ce,f2,5f,47,59,1f,2b,25,f6,12,48,81,74
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \04F7528984592EA0\FD1E79A92259B5BC6F3673C7C70B3F80]
"1"=hex:a0,05,e5,14,70,56,59,19,19,f2,d5,d0,45,ea,42,c8,7b,0e,8f,12,8d,fe,0d,
89,e7,25,77,a8,98,63,f3,0c
"2"=hex:14,ce,87,8d,79,74,ee,b2
"3"=hex:5c,5e,d4,bc,bb,6a,f4,ac,19,1a,5a,10,f3,da,86,dd,20,48,17,d2,c9,0f,3f,
4c,25,a1,a0,5e,b8,c6,af,ba,2f,23,f8,b0,db,62,49,7f,42,05,94,2e,4d,c1,86,57,\
"4"=hex:f4,42,f4,0c,e7,da,ef,8e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:c9,3a,93,65,d5,aa,5c,a5,af,ff,f0,6c,ea,dc,3b,16,d5,46,14,1e,de,21,e3,
92,cf,d2,a7,a7,d7,a8,3c,60,6f,1e,ad,24,4c,e4,b3,35,f5,88,93,81,10,50,6e,57,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,c7,5d,79,50,5b,51,9a,
93,75,a1,9e,ff,20,fc,d2,00,0b,20,84,9e,88,7b,1b,1b,04,21,ff,cd,b0,78,2c,05,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:70,56,26,33,e3,20,f8,ab
"10"=hex:c7,b0,18,85,7b,39,96,ed
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2196)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Common Files\Microsoft Shared\OFFICE12\MSOXEV.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\ATI Technologies\ATI.ACE\cli.exe
c:\program files\ATI Technologies\ATI.ACE\cli.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-12-06 16:42 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-06 22:42
ComboFix2.txt 2009-12-03 23:45
ComboFix3.txt 2009-12-03 01:01
Pre-Run: 45,306,470,400 bytes free
Post-Run: 45,295,243,264 bytes free
- - End Of File - - 2AE300591F6D708F96A54707114E66B1
http://www.virscan.org/report/1c84416d82bb…ed7f53b0c5.html
Malwarebytes' Anti-Malware 1.42
Database version: 3307
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
12/6/2009 7:27:36 PM
mbam-log-2009-12-06 (19-27-36).txt
Scan type: Quick Scan
Objects scanned: 115511
Time elapsed: 4 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\Owner\Application Data\seres.exe (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.