I know torrents are risky. I-ll be more careful in the future.
ComboFix 10-02-19.03 - John 02/19/2010 18:37:52.6.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1561 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\mswintmp.dat
c:\windows\system32\Thumbs.db
c:\windows\system32\twain_32.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-20 to 2010-02-20 )))))))))))))))))))))))))))))))
.
2010-02-16 01:57 . 2010-02-16 01:58 ——– d—–w- c:\program files\trend micro
2010-02-16 01:57 . 2010-02-16 01:58 ——– d—–w- C:\rsit
2010-02-14 17:52 . 2010-02-14 17:52 22094888 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{2582FFB0-08C5-8353-3DDD-AF1F0B9EC485}-EAD4.exe
2010-02-13 20:52 . 2010-02-13 20:53 ——– d—–w- c:\documents and settings\John\Application Data\SPORE
2010-02-13 20:34 . 2010-02-13 20:34 ——– d—–w- C:\ProgramData
2010-02-13 20:34 . 2010-02-13 20:34 2496 —-a-w- c:\windows\system32\ealregsnapshot1.reg
2010-02-13 20:34 . 2010-02-13 20:34 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Downloaded Installations
2010-02-13 20:14 . 2010-02-13 20:36 ——– d—–w- c:\program files\Electronic Arts
2010-02-12 23:09 . 2010-02-12 23:09 ——– d—–w- c:\documents and settings\John\Application Data\DivX
2010-02-12 22:41 . 2010-02-12 22:41 389120 —-a-w- c:\windows\system32\CF12573.exe
2010-02-12 22:01 . 2010-02-12 22:01 123904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{6196ACAC-65EE-F747-15C2-FD1710864A60}-fmkgesng.exe
2010-02-12 02:55 . 2010-02-12 02:55 ——– d—–w- c:\program files\Common Files\Graphisoft Shared
2010-02-12 02:49 . 2010-02-12 02:49 ——– d—–w- c:\program files\Graphisoft
2010-02-08 14:50 . 2009-11-14 00:49 9464 ——w- c:\windows\system32\drivers\cdralw2k.sys
2010-02-08 14:50 . 2009-11-14 00:49 9336 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2010-02-08 14:50 . 2009-11-14 00:49 120056 ——w- c:\windows\system32\pxcpyi64.exe
2010-02-08 14:50 . 2009-11-14 00:49 118520 ——w- c:\windows\system32\pxinsi64.exe
2010-02-08 14:50 . 2009-11-14 00:49 129784 ——w- c:\windows\system32\pxafs.dll
2010-02-08 14:50 . 2010-02-08 14:50 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-02-06 02:43 . 2010-02-06 02:43 61224 —-a-w- c:\documents and settings\John\GoToAssistDownloadHelper.exe
2010-02-06 02:38 . 2010-02-06 02:38 ——– d—–w- c:\windows\system32\wbem\Repository
2010-02-05 16:39 . 2010-02-05 16:39 251376 —-a-w- c:\documents and settings\John\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-02-01 19:54 . 2010-02-07 15:20 ——– d—–w- c:\program files\Trine
2010-02-01 08:35 . 2010-02-01 08:35 13044 —-a-w- c:\windows\scunin.dat
2010-02-01 08:34 . 2010-02-06 02:37 ——– d—–w- c:\program files\Starcraft(2)
2010-01-30 07:08 . 2010-01-30 07:08 ——– d—–w- c:\program files\Veoh Networks
2010-01-30 03:43 . 2010-01-30 03:47 ——– d—–w- c:\program files\SendBlaster
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-20 00:34 . 2009-11-24 18:29 1080112 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-20 00:27 . 2009-05-06 17:12 ——– d—–w- c:\documents and settings\John\Application Data\Skype
2010-02-19 16:55 . 2009-02-16 02:48 31776 —-a-w- c:\windows\system32\nvModes.dat
2010-02-19 15:54 . 2009-04-16 14:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-02-19 09:24 . 2009-06-04 21:15 25 —-a-w- c:\windows\popcinfot.dat
2010-02-19 06:03 . 2009-05-06 17:14 ——– d—–w- c:\documents and settings\John\Application Data\skypePM
2010-02-16 15:19 . 2009-02-14 01:09 ——– d—–w- c:\program files\IrfanView
2010-02-14 17:53 . 2009-02-14 20:12 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-13 20:51 . 2009-02-16 09:15 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-02-12 22:19 . 2009-10-09 00:49 ——– d—–w- c:\program files\Pamela
2010-02-12 21:32 . 2009-07-29 03:43 ——– d—–w- c:\program files\sw3dg
2010-02-10 16:03 . 2009-07-17 15:16 ——– d—–w- c:\program files\TextAloud
2010-02-08 14:50 . 2009-08-10 04:46 ——– d—–w- c:\program files\DivX
2010-01-31 06:43 . 2009-04-10 18:02 ——– d—–w- c:\program files\Google
2010-01-31 03:48 . 2010-01-11 05:12 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-30 05:33 . 2009-03-30 22:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-30 03:41 . 2009-10-12 06:37 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 03:41 . 2009-12-23 23:39 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-21 01:18 . 2009-08-02 00:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-14 17:12 . 2009-10-19 14:56 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-12 06:34 . 2009-02-16 03:16 ——– d—–w- c:\program files\Opera
2010-01-10 00:21 . 2010-01-10 00:21 ——– d—–w- c:\documents and settings\John\Application Data\Epson
2010-01-07 22:07 . 2009-10-12 06:37 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2009-10-12 06:37 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 01:07 . 2009-02-18 03:36 102048 —-a-w- c:\documents and settings\John\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-05 10:00 . 2004-08-12 14:09 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-12 13:58 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-12 13:56 17408 —-a-w- c:\windows\system32\corpol.dll
2010-01-05 03:01 . 2010-01-05 03:01 ——– d—–w- c:\program files\Nice PDF Compressor
2009-12-30 20:23 . 2009-02-14 20:11 ——– d—–w- c:\program files\Common Files\InstallShield
2009-12-30 20:23 . 2009-12-30 20:22 ——– d—–w- c:\program files\epson
2009-12-30 20:23 . 2009-12-30 20:23 ——– d—–w- c:\program files\Epson Software
2009-12-30 20:22 . 2009-12-30 20:22 ——– d—–w- c:\documents and settings\All Users\Application Data\EPSON
2009-12-25 22:43 . 2009-12-25 22:43 ——– d—–w- c:\program files\OpenAL
2009-12-25 22:42 . 2009-12-25 22:42 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2009-12-25 22:42 . 2009-12-25 22:42 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2009-12-25 22:42 . 2009-12-25 22:42 ——– d—–w- c:\program files\Osmos
2009-12-25 04:39 . 2009-05-02 03:51 829 —-a-w- c:\windows\eReg.dat
2009-12-25 04:34 . 2009-12-25 04:34 ——– d—–w- c:\program files\EA Games
2003-12-18 16:33 . 2009-08-10 05:39 20102 —-a-w- c:\program files\Readme.txt
2003-09-03 12:46 . 2009-08-10 05:39 10960 —-a-w- c:\program files\EULA.txt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"Google Update"="c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-06 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13594624]
"nwiz"="nwiz.exe" [2009-01-30 1657376]
"NVHotkey"="nvHotkey.dll" [2009-01-30 90112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 86016]
"Dell QuickSet"="c:\program files\Dell\QuickSet\Quickset.exe" [2007-05-14 1191936]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-23 620152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
c:\documents and settings\John\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2010-1-4 295606]
Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-08-11 07:19 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^John^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\John\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^John^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\John\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 22:10 35696 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSVolFE.exe]
2005-02-23 21:57 57344 ——w- c:\program files\Creative\Mixer\CTSVolFE.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
2007-05-14 20:23 1191936 —-a-w- c:\program files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-04-06 00:12 133104 —-atw- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 21:22 3739648 —-a-w- c:\program files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2009-03-01 10:59 172792 —-a-w- c:\program files\ICQ6.5\ICQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-01-06 19:06 290088 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-01-30 15:12 13594624 —-a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
2009-01-30 15:12 90112 —-a-w- c:\windows\system32\nvhotkey.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-01-30 15:12 86016 —-a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2009-01-30 15:12 1657376 —-a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 22:18 413696 —-a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2007-05-10 16:22 405504 —-a-w- c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-04-21 19:39 24264488 —-a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-04-16 14:25 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\sulljoh1\\source sdk base 2007\\hl2.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\sulljoh1\\source sdk base\\hl2.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"=
"c:\\Documents and Settings\\John\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\John\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Codemasters\\Overlord\\Overlord.exe"=
"c:\\Program Files\\Codemasters\\Overlord II\\Overlord2.exe"=
"c:\\WINDOWS\\system32\\HPZipm12.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15043:TCP"= 15043:TCP:BitComet 15043 TCP
"15043:UDP"= 15043:UDP:BitComet 15043 UDP
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [4/14/2009 3:19 PM 222456]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2/15/2009 11:18 PM 721904]
S2 gupdate1c9be9f4c4ca05c;Google Update Service (gupdate1c9be9f4c4ca05c);c:\program files\Google\Update\GoogleUpdate.exe [4/16/2009 8:26 AM 133104]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [11/29/2009 4:59 PM 25832]
.
Contents of the 'Scheduled Tasks' folder
2010-02-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-16 14:25]
2010-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-16 14:26]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-16 14:26]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1844823847-725345543-1004Core.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-06 00:12]
2010-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1844823847-725345543-1004UA.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-06 00:12]
2010-02-20 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-07-02 22:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\j1cizrmh.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com/
FF - plugin: c:\documents and settings\John\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\John\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-19 18:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1177238915-1844823847-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:66,74,66,8b,9b,80,21,bb,74,35,68,84,73,95,b2,37,b2,ff,10,9b,94,
0c,a2,0e,7d,24,96,c1,5b,80,b7,73,b7,43,f6,fe,86,bb,e3,02,bc,0b,fd,a2,eb,ce,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(776)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
.
Completion time: 2010-02-19 18:50:21
ComboFix-quarantined-files.txt 2010-02-20 00:50
Pre-Run: 7,752,822,784 bytes free
Post-Run: 12,375,379,968 bytes free
- - End Of File - - A18E759CF6D074319D4FAAFC2B5B4C1E