ComboFix 10-09-11.03 - Ian 12/09/2010 15:55:51.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3070.2678 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\HyperCam Toolbar\tbHElper.dll
.
((((((((((((((((((((((((( Files Created from 2010-08-12 to 2010-09-12 )))))))))))))))))))))))))))))))
.
2010-09-11 09:53 . 2010-09-11 09:53 ——– d—–w- c:\documents and settings\Ian\Application Data\Malwarebytes
2010-09-11 09:53 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-11 09:53 . 2010-09-11 09:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-11 09:53 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-11 09:53 . 2010-09-11 09:53 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-07 18:58 . 2010-09-07 14:47 17744 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-07 18:58 . 2010-09-07 14:52 165584 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-07 18:58 . 2010-09-07 14:47 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-07 18:58 . 2010-09-07 14:52 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-07 18:58 . 2010-09-07 14:47 100176 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-07 18:58 . 2010-09-07 14:47 94544 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-07 18:58 . 2010-09-07 14:46 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-07 18:57 . 2010-09-07 15:12 38848 —-a-w- c:\windows\avastSS.scr
2010-09-07 18:57 . 2010-09-07 15:11 167592 —-a-w- c:\windows\system32\aswBoot.exe
2010-09-07 18:57 . 2010-09-07 18:57 ——– d—–w- c:\program files\Alwil Software
2010-09-07 18:57 . 2010-09-07 18:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-09-07 18:39 . 2010-09-12 15:09 ——– d—–w- c:\program files\Steam
2010-09-05 13:22 . 2010-09-05 13:22 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-09-02 09:43 . 2009-11-03 13:07 1970176 —-a-w- c:\windows\system32\d3dx9.dll
2010-09-02 09:43 . 2010-09-11 20:33 ——– d—–w- c:\program files\Cheat Engine
2010-09-02 09:43 . 2009-11-03 13:07 679936 —-a-w- c:\windows\system32\D3DX81ab.dll
2010-08-31 15:19 . 2010-08-31 15:19 ——– d—–w- c:\documents and settings\Ian\Application Data\Toolbar4
2010-08-31 15:19 . 2010-09-12 15:03 ——– d—–w- c:\program files\HyperCam Toolbar
2010-08-31 15:18 . 2010-08-31 15:18 ——– d—–w- c:\program files\HyCam2
2010-08-30 19:58 . 2010-08-30 20:06 ——– d—–w- c:\program files\Fiesta Online(EU_English)
2010-08-30 18:36 . 2010-08-30 18:36 ——– d—–w- c:\program files\Common Files\DirectX
2010-08-30 18:26 . 2010-01-13 16:48 118176 —-a-w- c:\windows\patchw.dll
2010-08-30 18:18 . 2010-08-30 18:48 ——– d—–w- c:\program files\Outspark
2010-08-30 15:45 . 2010-08-30 15:45 ——– d—–w- C:\fb9724e9ee31c0e7443ee6a3
2010-08-29 10:10 . 2010-08-29 10:10 ——– d—–w- C:\a990d76d4996e0a254d3
2010-08-29 10:08 . 2007-05-17 11:28 549376 —-a-w- c:\windows\system32\oleaut32.dll
2010-08-29 09:57 . 2006-02-28 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-08-28 12:35 . 2010-09-11 10:14 ——– d—–w- c:\windows\Sun
2010-08-28 08:50 . 2010-08-28 08:50 ——– d—–w- c:\program files\Common Files\Java
2010-08-28 08:50 . 2010-07-17 04:00 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-27 16:34 . 2010-09-12 11:37 ——– d—–w- c:\documents and settings\Ian\Application Data\LimeWire
2010-08-27 16:33 . 2010-08-28 08:50 ——– d—–w- c:\program files\Java
2010-08-27 16:33 . 2010-08-27 16:34 ——– d—–w- c:\program files\LimeWire
2010-08-27 14:57 . 2010-08-27 14:57 ——– d-sh–w- c:\documents and settings\Ian\IECompatCache
2010-08-27 14:39 . 2010-08-27 14:43 ——– d—–w- c:\windows\ie8updates
2010-08-27 12:22 . 2010-08-30 23:01 ——– d—–w- c:\documents and settings\Ian\Local Settings\Application Data\PMB Files
2010-08-27 12:22 . 2010-08-30 18:51 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2010-08-27 12:21 . 2010-08-27 12:21 ——– d—–w- c:\program files\Pando Networks
2010-08-27 11:59 . 2010-05-06 10:41 599040 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-08-27 11:59 . 2010-05-06 10:41 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-08-27 11:59 . 2010-05-06 10:41 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-08-27 11:59 . 2010-05-06 10:41 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-08-27 11:59 . 2010-05-06 10:41 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-08-27 11:59 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-27 11:59 . 2010-05-06 10:41 11076096 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-08-27 11:47 . 2010-08-27 11:47 ——– d-sh–w- c:\documents and settings\Ian\PrivacIE
2010-08-27 11:47 . 2010-08-27 11:54 ——– d—–w- c:\windows\system32\CatRoot_bak
2010-08-27 11:19 . 2010-08-27 11:21 ——– d—–w- c:\windows\system32\wbem\Repository
2010-08-27 11:18 . 2010-08-27 11:32 ——– d—–w- c:\windows\system32\en
2010-08-27 11:18 . 2010-08-27 11:32 ——– d—–w- c:\windows\system32\bits
2010-08-27 11:14 . 2010-08-27 11:14 ——– d—–w- c:\windows\EHome
2010-08-27 10:16 . 2010-08-27 11:32 ——– d—–w- c:\windows\system32\scripting
2010-08-27 10:16 . 2010-08-27 11:31 ——– d—–w- c:\windows\l2schemas
2010-08-27 10:07 . 2009-12-24 07:05 177664 —-a-w- c:\windows\system32\dllcache\wintrust.dll
2010-08-27 10:00 . 2010-08-27 10:00 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-08-27 09:58 . 2010-08-27 09:58 ——– d-sh–w- c:\documents and settings\Ian\IETldCache
2010-08-26 17:12 . 2010-08-26 17:12 ——– d—–w- C:\9031e5d399997adc63
2010-08-26 15:47 . 2010-08-26 15:48 ——– dc-h–w- c:\windows\ie8
2010-08-26 15:13 . 2010-08-26 15:13 ——– d—–w- C:\c66445dd4b6cdd2c70fb4df583a4bb
2010-08-26 15:13 . 2010-08-26 15:13 ——– d—–w- C:\6b4feaf3eaa8d23d3b620a15
2010-08-26 15:01 . 2010-08-26 15:01 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-08-26 15:00 . 2010-08-26 15:00 ——– d—–w- c:\program files\MSXML 6.0
2010-08-26 14:48 . 2010-08-27 11:38 ——– d—–w- c:\windows\ServicePackFiles
2010-08-26 12:51 . 2010-02-12 10:03 293376 ——w- c:\windows\system32\browserchoice.exe
2010-08-26 11:49 . 2009-08-06 18:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-08-26 11:49 . 2009-08-06 18:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-08-22 16:10 . 2010-09-08 19:29 ——– d—–w- c:\program files\SweetIM
2010-08-18 09:50 . 2003-04-17 08:21 98176 —-a-r- c:\windows\system32\drivers\vnet558x.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-08 19:29 . 2007-07-03 12:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-09-08 19:05 . 2007-07-03 12:24 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-09-07 18:59 . 2010-01-04 20:33 ——– d—–w- c:\program files\Google
2010-09-05 13:26 . 2006-01-10 16:35 ——– d—–w- c:\program files\Common Files\Adobe
2010-09-05 13:22 . 2010-09-05 13:22 53632 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-08-30 18:48 . 2006-01-06 15:13 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-28 09:52 . 2006-01-07 14:53 80640 —-a-w- c:\documents and settings\Ian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-27 20:46 . 2010-08-27 20:46 503808 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-53101f1d-n\msvcp71.dll
2010-08-27 20:46 . 2010-08-27 20:46 499712 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-53101f1d-n\jmc.dll
2010-08-27 20:46 . 2010-08-27 20:46 348160 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-53101f1d-n\msvcr71.dll
2010-08-27 20:46 . 2010-08-27 20:46 61440 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-632ae020-n\decora-sse.dll
2010-08-27 20:46 . 2010-08-27 20:46 12800 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-632ae020-n\decora-d3d.dll
2010-08-27 16:34 . 2010-08-27 16:34 8192 —-a-w- c:\documents and settings\Ian\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
2010-08-27 16:31 . 2010-04-14 13:12 ——– d—–w- c:\documents and settings\Ian\Application Data\uTorrent
2010-08-27 11:29 . 2006-01-06 15:06 76487 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-08-26 14:52 . 2007-01-14 09:26 ——– d—–w- c:\program files\Microsoft Works
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2009-09-14 1217808]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 81920]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-07-21 2752512]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"ShowWnd"="ShowWnd.exe" [2003-09-19 36864]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-02 17530368]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"nwiz"="nwiz.exe" [2009-02-09 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 50688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-08-26 1796368]
"CHotkey"="zHotkey.exe" [2004-05-17 543232]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
c:\documents and settings\Ian\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-8-19 503808]
PdaNet Desktop.lnk - c:\program files\PdaNet for iPhone\PdaNetPC.exe [2009-12-8 173520]
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2006-8-30 2240080]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CoreCenter.lnk]
backup=c:\windows\pss\CoreCenter.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Status Monitor 3 Environment Check 2.lnk]
backup=c:\windows\pss\EPSON Status Monitor 3 Environment Check 2.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Ian^Start Menu^Programs^Startup^Registration .LNK]
backup=c:\windows\pss\Registration .LNKStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Midway Games\\Rise and Fall\\RiseAndFall.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEARMP.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEARXP\\FEARXP.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"f:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"f:\\Program Files\\EA GAMES\\The Battle for Middle-earth ™\\game.dat"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enGB-downloader.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires\\Empires.exe"=
"f:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2300:TCP"= 2300:TCP:age
"2300:UDP"= 2300:UDP:age1
"58097:TCP"= 58097:TCP:Pando Media Booster
"58097:UDP"= 58097:UDP:Pando Media Booster
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [05/07/2006 13:46 63352]
R0 sonyhcb;Sony Digital Imaging Base;c:\windows\system32\drivers\sonyhcb.sys [08/07/2007 09:06 6097]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [07/09/2010 19:58 165584]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [14/06/2009 21:46 132168]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [14/06/2009 21:46 25160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07/09/2010 19:58 17744]
R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [12/08/2009 09:51 9472]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04/01/2010 21:33 135664]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [11/12/2008 22:48 1684736]
S3 OEMFVNETusb(505 2958)®;OEM FVNETusb(505 2958)® Service for 802.11b Pen Size Wireless USB Adapter;c:\windows\system32\drivers\vnet558x.sys [18/08/2010 10:50 98176]
S3 pnicml;pnicml;\??\c:\docume~1\Ian\LOCALS~1\Temp\pnicml.sys –> c:\docume~1\Ian\LOCALS~1\Temp\pnicml.sys [?]
S3 sonyhcs;Sony Digital Imaging Video;c:\windows\system32\drivers\sonyhcs.sys [08/07/2007 09:06 299923]
S3 XDva344;XDva344;\??\c:\windows\system32\XDva344.sys –> c:\windows\system32\XDva344.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-04 20:33]
2010-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-04 20:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - f:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {791BA8B0-9824-437D-B593-03913AA02AAF} = 192.168.1.2
FF - ProfilePath - c:\documents and settings\Ian\Application Data\Mozilla\Firefox\Profiles\b5362naz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q;=
FF - prefs.js: browser.search.selectedEngine - Yahoo.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/?ref=home
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q;=
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff36\gears.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Musicnotes\npmusicn.dll
FF - plugin: c:\program files\Musicnotes\NPSibelius.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: f:\ian\My Documents\Sparkplay Media\Sparkplayer (Beta)\npSparkPlayerNS.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Notify-dimsntfy - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-12 16:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync02.sys >>UNKNOWN [0x8B7CD6E0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0fcfc3
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\atapi -> sfsync02.sys @ 0xba0c98b4
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
user & kernel MBR OK
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1644491937-1364589140-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:79,6d,7e,18,87,3a,d5,58,3e,92,0a,6a,54,5e,bf,d8,91,f9,85,a9,d2,69,14,
fd,e4,04,cb,7e,15,d4,ef,87,b6,9d,e0,9c,81,96,b6,0d,4e,ea,61,64,24,23,03,13,\
"??"=hex:5b,ea,67,63,47,83,c4,14,1d,89,60,78,85,d0,4c,af
[HKEY_USERS\S-1-5-21-1644491937-1364589140-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:57,f0,86,a4,c7,a7,0d,84,66,a5,7e,e3,2b,02,4a,b9,d3,27,f8,f5,69,
55,ee,61,3c,b5,95,82,c9,bc,ab,8f,f6,be,8e,33,21,35,0e,e2,3c,8e,d1,69,ac,53,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2444)
c:\windows\system32\WININET.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\imapi.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\zHotkey.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Completion time: 2010-09-12 16:14:15 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-12 15:14
Pre-Run: 94,865,428,480 bytes free
Post-Run: 95,124,279,296 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 59F57C9CC52E912C52EA187188114648