ComboFix 10-03-26.01 - 12linnz 27/03/2010 13:13:40.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.1977.1539 [GMT 11:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
c:\recycler\S-1-5-21-1644491937-2147142785-839522115-500
c:\windows\system32\CNCFLeNL.DLL
—– BITS: Possible infected sites —–
hxxp://cgsremote6
.
((((((((((((((((((((((((( Files Created from 2010-02-27 to 2010-03-27 )))))))))))))))))))))))))))))))
.
2010-03-26 10:54 . 2010-03-26 10:51 754984 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-03-26 10:54 . 2010-03-26 10:51 986904 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-03-26 10:54 . 2010-03-26 10:54 56978 —-a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-03-26 10:54 . 2010-03-26 10:54 56766 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-03-26 10:54 . 2010-03-26 10:54 57677 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-03-26 10:54 . 2010-03-26 10:54 53600 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-03-26 10:51 . 2010-03-26 10:55 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-03-25 12:08 . 2010-03-25 12:08 ——– d—–w- c:\program files\Common Files\Java
2010-03-25 12:08 . 2010-03-25 12:08 503808 —-a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46d5ece0-n\msvcp71.dll
2010-03-25 12:08 . 2010-03-25 12:08 499712 —-a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46d5ece0-n\jmc.dll
2010-03-25 12:08 . 2010-03-25 12:08 348160 —-a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46d5ece0-n\msvcr71.dll
2010-03-25 12:08 . 2010-03-25 12:08 61440 —-a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-127ec96c-n\decora-sse.dll
2010-03-25 12:08 . 2010-03-25 12:08 12800 —-a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-127ec96c-n\decora-d3d.dll
2010-03-25 12:04 . 2010-03-25 12:04 152576 —-a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-03-25 12:03 . 2010-03-25 12:04 79488 —-a-w- c:\documents and settings\12linnz\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-25 09:16 . 2010-03-25 09:16 ——– d—–w- c:\documents and settings\12linnz\Application Data\Malwarebytes
2010-03-25 09:16 . 2010-01-07 05:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-25 09:16 . 2010-03-25 09:16 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-25 09:16 . 2010-03-25 09:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-25 09:16 . 2010-01-07 05:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-23 23:43 . 2010-03-23 23:44 ——– d—–w- C:\Hotspot Shield
2010-03-23 23:43 . 2010-03-23 23:44 ——– d—–w- c:\program files\Hotspot Shield
2010-03-23 23:36 . 2010-03-23 23:36 ——– d—–w- C:\TEMP
2010-03-23 23:34 . 2010-03-23 23:34 ——– d—–w- c:\documents and settings\12linnz\Application Data\GPass
2010-03-23 14:51 . 2010-03-23 14:51 ——– d—–w- C:\Nexon
2010-03-23 14:51 . 2010-03-23 14:51 98304 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2010-03-23 14:51 . 2010-03-23 14:51 765952 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2010-03-23 14:51 . 2010-03-23 14:51 401408 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2010-03-23 14:51 . 2010-03-23 14:51 258352 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2010-03-23 14:51 . 2010-03-23 14:51 126976 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2010-03-23 14:51 . 2010-03-23 14:51 172032 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2010-03-23 14:51 . 2010-03-23 14:51 ——– d—–w- c:\documents and settings\All Users\Application Data\NexonUS
2010-03-23 14:48 . 2010-03-26 04:16 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\PMB Files
2010-03-23 14:48 . 2010-03-23 14:48 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2010-03-23 14:47 . 2010-03-23 14:47 ——– d—–w- c:\program files\Pando Networks
2010-03-23 11:12 . 2010-03-23 11:12 ——– d—–w- c:\program files\Common Files\CANON
2010-03-23 11:10 . 2008-04-13 13:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-03-23 11:10 . 2008-04-13 13:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-03-23 11:10 . 2001-08-17 02:53 6784 -c–a-w- c:\windows\system32\dllcache\serscan.sys
2010-03-23 11:10 . 2001-08-17 02:53 6784 —-a-w- c:\windows\system32\drivers\serscan.sys
2010-03-23 11:10 . 2010-03-23 11:10 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2010-03-23 11:10 . 2007-05-21 20:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP95.DLL
2010-03-23 11:10 . 2007-05-21 20:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD95.DLL
2010-03-23 11:10 . 2007-05-21 20:00 215040 —-a-w- c:\windows\system32\CNMLM95.DLL
2010-03-23 11:10 . 2010-03-23 11:10 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2010-03-23 11:08 . 2007-05-14 06:49 142336 —-a-w- c:\windows\system32\CNMNPUI.DLL
2010-03-23 11:08 . 2007-05-14 06:49 362496 —-a-w- c:\windows\system32\CNMNPPM.DLL
2010-03-23 11:07 . 2008-04-13 13:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2010-03-23 11:07 . 2008-04-13 13:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2010-03-23 11:07 . 2010-03-23 11:11 ——– d—–w- c:\program files\Canon
2010-03-23 07:30 . 2010-03-23 07:30 ——– d—–w- c:\documents and settings\12linnz\Bluetooth Software
2010-03-23 01:55 . 2010-03-23 01:55 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-03-22 00:20 . 2010-01-05 10:00 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-03-22 00:20 . 2010-01-05 10:00 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-03-22 00:20 . 2010-01-05 10:00 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-03-22 00:20 . 2010-01-05 10:00 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2010-03-22 00:20 . 2010-01-05 10:00 380928 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2010-03-22 00:20 . 2009-12-31 15:33 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2010-03-22 00:20 . 2009-06-29 08:33 2452872 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2010-03-22 00:20 . 2010-01-05 10:00 6067200 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-03-20 00:53 . 2010-03-20 00:53 1924976 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2010-03-20 00:53 . 2010-03-22 00:16 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-19 09:08 . 2010-03-19 09:08 ——– d—–w- C:\a996d97d2b523c76418c
2010-03-19 09:05 . 2008-10-09 17:52 452440 —-a-w- c:\windows\system32\d3dx10_40.dll
2010-03-19 09:05 . 2008-10-09 17:52 2036576 —-a-w- c:\windows\system32\D3DCompiler_40.dll
2010-03-19 09:05 . 2008-10-09 17:52 4379984 —-a-w- c:\windows\system32\D3DX9_40.dll
2010-03-19 09:05 . 2007-04-04 07:53 81768 —-a-w- c:\windows\system32\xinput1_3.dll
2010-03-19 09:05 . 2010-03-19 09:05 ——– d—–w- c:\windows\Logs
2010-03-19 09:04 . 2010-03-26 14:07 ——– d—–w- c:\program files\Heroes of Newerth
2010-03-19 08:32 . 2010-03-26 10:53 ——– d—–w- c:\documents and settings\12linnz\Application Data\DivX
2010-03-19 07:28 . 2010-03-19 07:28 ——– d—–w- c:\program files\CCleaner
2010-03-19 07:27 . 2010-03-19 07:27 ——– d—–w- c:\program files\uTorrent
2010-03-19 07:27 . 2010-03-23 04:17 ——– d—–w- c:\documents and settings\12linnz\Application Data\uTorrent
2010-03-19 07:18 . 2008-04-13 13:15 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2010-03-19 07:18 . 2008-04-13 13:15 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2010-03-19 03:44 . 2010-03-19 03:42 130104 —-a-w- c:\windows\system32\sdccoinstaller.dll
2010-03-19 03:44 . 2010-03-19 03:44 ——– d—–w- c:\program files\Common Files\Cisco Systems
2010-03-19 03:44 . 2010-03-19 03:42 23552 —-a-w- c:\windows\system32\sophosboottasks.exe
2010-03-19 03:43 . 2010-03-19 03:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Sophos
2010-03-19 03:42 . 2010-03-19 03:42 14976 —-a-w- c:\windows\system32\drivers\SophosBootDriver.sys
2010-03-19 03:42 . 2010-03-19 03:42 38528 —-a-w- c:\windows\system32\drivers\savonaccessfilter.sys
2010-03-19 03:42 . 2010-03-19 03:42 110848 —-a-w- c:\windows\system32\drivers\savonaccesscontrol.sys
2010-03-19 03:40 . 2010-03-19 03:44 ——– d—–w- c:\program files\Sophos
2010-03-19 03:33 . 2010-03-23 09:41 ——– d—–w- c:\documents and settings\12linnz\Tracing
2010-03-19 03:33 . 2010-03-19 03:33 ——– d—–w- c:\program files\Microsoft Silverlight
2010-03-19 03:32 . 2010-03-19 03:33 ——– d—–w- c:\program files\Microsoft
2010-03-19 03:32 . 2010-03-19 03:32 ——– d—–w- c:\program files\Windows Live SkyDrive
2010-03-19 03:32 . 2010-03-19 03:33 ——– d—–w- c:\program files\Windows Live
2010-03-19 03:24 . 2010-03-19 03:24 ——– d—–w- c:\program files\Common Files\Windows Live
2010-03-19 03:19 . 2010-03-19 12:55 105544 —-a-w- c:\documents and settings\12linnz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-19 03:17 . 2010-03-19 03:22 ——– d—–w- c:\documents and settings\12linnz\Application Data\Apple Computer
2010-03-19 03:16 . 2009-05-18 03:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-03-19 03:16 . 2008-04-17 02:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-03-19 03:16 . 2010-03-19 03:16 ——– d—–w- c:\program files\iPod
2010-03-19 03:16 . 2010-03-19 03:16 ——– d—–w- c:\program files\iTunes
2010-03-19 03:16 . 2010-03-19 03:16 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-03-19 03:15 . 2010-03-19 03:15 ——– d—–w- c:\program files\Bonjour
2010-03-19 03:15 . 2010-03-19 03:15 ——– d—–w- c:\program files\QuickTime
2010-03-19 03:15 . 2010-03-19 03:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-03-19 03:14 . 2010-03-19 03:14 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Apple
2010-03-19 03:14 . 2010-03-19 03:14 ——– d—–w- c:\program files\Apple Software Update
2010-03-19 03:14 . 2010-03-19 03:16 ——– d—–w- c:\program files\Common Files\Apple
2010-03-19 03:14 . 2010-03-19 03:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-03-19 03:13 . 2010-03-19 12:51 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Apple Computer
2010-03-19 03:13 . 2009-10-21 05:38 75776 -c—-w- c:\windows\system32\dllcache\strmfilt.dll
2010-03-19 03:13 . 2009-10-21 05:38 25088 -c—-w- c:\windows\system32\dllcache\httpapi.dll
2010-03-19 03:13 . 2009-10-20 16:20 265728 -c—-w- c:\windows\system32\dllcache\http.sys
2010-03-19 02:51 . 2010-03-19 02:51 ——– d—–w- c:\windows\system32\winrm
2010-03-19 02:51 . 2010-03-19 02:51 ——– d—–w- c:\windows\system32\GroupPolicy
2010-03-19 02:51 . 2010-03-19 02:51 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2010-03-19 02:50 . 2010-03-19 02:50 ——– d—–w- c:\documents and settings\12linnz\Local Settings\Application Data\Microsoft Help
2010-03-19 02:49 . 2010-03-23 11:09 ——– d—–w- c:\documents and settings\saaa
2010-03-19 02:41 . 2009-06-12 12:31 80896 -c—-w- c:\windows\system32\dllcache\tlntsess.exe
2010-03-19 02:41 . 2009-06-12 12:31 76288 -c—-w- c:\windows\system32\dllcache\telnet.exe
2010-03-19 02:41 . 2009-12-14 07:08 33280 -c—-w- c:\windows\system32\dllcache\csrsrv.dll
2010-03-19 02:41 . 2009-06-10 06:14 132096 -c—-w- c:\windows\system32\dllcache\wkssvc.dll
2010-03-19 02:41 . 2009-03-21 14:06 989696 -c—-w- c:\windows\system32\dllcache\kernel32.dll
2010-03-19 02:41 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-03-19 02:41 . 2009-10-12 13:38 149504 -c—-w- c:\windows\system32\dllcache\rastls.dll
2010-03-19 02:41 . 2009-10-12 13:38 79872 -c—-w- c:\windows\system32\dllcache\raschap.dll
2010-03-19 02:41 . 2009-10-15 16:28 81920 -c—-w- c:\windows\system32\dllcache\fontsub.dll
2010-03-19 02:41 . 2009-10-15 16:28 119808 -c—-w- c:\windows\system32\dllcache\t2embed.dll
2010-03-19 02:39 . 2009-11-27 17:11 17920 -c—-w- c:\windows\system32\dllcache\msyuv.dll
2010-03-19 02:39 . 2009-07-17 19:01 58880 -c—-w- c:\windows\system32\dllcache\atl.dll
2010-03-19 02:39 . 2010-03-19 02:39 0 —-a-w- c:\windows\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-27 02:23 . 2010-03-27 02:23 0 —-a-w- c:\documents and settings\12linnz\.user-client.12linnz.12linnz.lock.tmp
2010-03-26 16:42 . 2008-10-22 03:44 ——– d—–w- c:\program files\Launch Manager
2010-03-25 12:07 . 2008-11-05 00:35 ——– d—–w- c:\program files\Java
2010-03-23 11:09 . 2010-03-23 11:09 ——– d–h–w- c:\program files\CanonBJ
2010-03-19 03:11 . 2008-10-24 01:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-19 02:56 . 2008-10-24 01:32 ——– d—–w- c:\program files\Microsoft Works
2010-02-19 19:27 . 2010-02-19 19:27 720384 —-a-w- c:\windows\system32\DivX.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 —-a-w- c:\windows\system32\divx_xx0c.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 —-a-w- c:\windows\system32\divx_xx07.dll
2010-02-19 19:27 . 2010-02-19 19:27 847872 —-a-w- c:\windows\system32\divx_xx0a.dll
2010-02-19 19:27 . 2010-02-19 19:27 843776 —-a-w- c:\windows\system32\divx_xx16.dll
2010-02-19 19:27 . 2010-02-19 19:27 839680 —-a-w- c:\windows\system32\divx_xx11.dll
2010-02-15 07:41 . 2010-02-15 07:41 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-08 23:42 . 2010-01-08 23:42 37376 —-a-w- c:\windows\system32\drivers\HssDrv.sys
2010-01-08 23:42 . 2010-01-08 23:42 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2010-01-05 10:00 . 2006-02-28 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2006-02-28 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2006-02-28 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2006-02-28 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2010-03-23 23:43 220208 —-a-w- c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-03-23 2937528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 16862208]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2008-10-22 3680768]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1028096]
"IFXSPMGT"="c:\windows\system32\ifxspmgt.exe" [2007-07-23 677144]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-04 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-04 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-04 141848]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-05-02 870920]
"PaperCut NG Client"="c:\program files\PaperCut NG Client\pc-client.exe" [2006-11-02 184320]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"IJNetworkScanUtility"="c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE" [2007-05-20 124512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2009-7-2 245760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-10-22 03:39 3076096 —-a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0pgdfgsvc C 1\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\PopTag\\CA.exe"=
"c:\\Nexon\\PopTag\\NMCOSrv.exe"=
"c:\\Program Files\\Heroes of Newerth\\hon.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56440:TCP"= 56440:TCP:Pando Media Booster
"56440:UDP"= 56440:UDP:Pando Media Booster
R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\drivers\AlfaFF.sys [22/10/2008 2:39 PM 43184]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [24/07/2007 8:59 AM 38816]
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [19/03/2010 2:42 PM 110848]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [19/03/2010 2:42 PM 38528]
R2 FPSensor;LTT-Corp Fingerprint Reader Driver (FPSensor.sys);c:\windows\system32\drivers\FPSensor.sys [22/10/2008 2:39 PM 20352]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [9/01/2010 10:42 AM 285744]
R2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [22/10/2008 2:39 PM 3481600]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [19/03/2010 2:41 PM 80936]
R2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [19/03/2010 2:42 PM 98304]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [24/07/2007 8:59 AM 41216]
R3 ITEIRDA;ITE Infrared Device Driver;c:\windows\system32\drivers\ITEirda.sys [22/10/2008 2:59 PM 24576]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15/08/2008 5:46 AM 284016]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [28/02/2006 11:00 PM 14336]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [19/03/2010 2:42 PM 14976]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
2010-03-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
.
.
——- Supplementary Scan ——-
.
uStart Page =
https://intranet.cgs.vic.edu.au
uInternet Settings,ProxyOverride = local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\12linnz\Application Data\Mozilla\Firefox\Profiles\myryunuq.default\
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-27 13:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Sophos Message Router]
"ImagePath"="\"c:\program files\Sophos\Remote Management System\RouterNT.exe\" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1188)
c:\program files\Acer\Acer Bio Protection\CompPtc.dll
c:\program files\Acer\Acer Bio Protection\CustomRes.dll
c:\windows\system32\NBMatS1SDK.DLL
c:\program files\Acer\Acer Bio Protection\WinNotify.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'lsass.exe'(1244)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(2168)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\windows\system32\IFXTCS.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\IfxPsdSv.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Sophos\Remote Management System\ManagementAgentNT.exe
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\Sophos\Remote Management System\RouterNT.exe
c:\windows\RTHDCPL.EXE
c:\program files\Hotspot Shield\bin\openvpntray.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Infineon\Security Platform Software\PSDrt.exe
c:\program files\Infineon\Security Platform Software\SpTna.exe
c:\windows\system32\igfxext.exe
c:\docume~1\12linnz\LOCALS~1\Temp\RtkBtMnt.exe
c:\windows\TEMP\sophos_autoupdate1.dir\alupdate.exe
.
**************************************************************************
.
Completion time: 2010-03-27 13:26:42 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-27 02:26
Pre-Run: 104,339,636,224 bytes free
Post-Run: 104,288,755,712 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 2463FD8A79CE3A28267D95F1AC93B1C9