someguy
ComboFix 11-12-04.02 - John 12/04/2011 7:17.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1379 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
H:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-11-04 to 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-12-04 12:09 . 2011-12-04 12:09 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\MpKsld69ad287.sys
2011-12-04 12:09 . 2011-12-04 12:09 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\offreg.dll
2011-12-04 12:09 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\mpengine.dll
2011-12-02 05:41 . 2011-12-02 05:41 ——– d—–w- c:\program files\CamStudio 2.6b
2011-12-02 05:41 . 2010-10-24 05:56 49664 —-a-w- c:\windows\system32\CamCodec.dll
2011-11-26 22:59 . 2011-11-26 23:01 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-26 03:05 . 2011-11-26 03:05 54016 —-a-w- c:\windows\system32\drivers\vtkcjvk.sys
2011-11-25 23:53 . 2011-11-25 23:53 54016 —-a-w- c:\windows\system32\drivers\evocs.sys
2011-11-25 18:35 . 2011-11-25 18:35 ——– d—–w- c:\windows\system32\LogFiles
2011-11-25 18:35 . 2011-11-25 19:36 ——– d—–w- c:\documents and settings\John\Application Data\384F4
2011-11-25 04:39 . 2011-11-25 04:39 ——– d—–w- C:\Ready to run with view Thesis
2011-11-25 04:29 . 2011-11-25 04:29 ——– d—–w- C:\Copy (2) of Thesis
2011-11-25 02:24 . 2011-11-25 02:24 ——– d—–w- C:\Base Results of Thesis
2011-11-25 02:05 . 2011-11-25 02:05 ——– d—–w- C:\Copy of Thesis
2011-11-25 00:31 . 2011-11-26 04:52 ——– d—–w- C:\Thesis
2011-11-24 04:40 . 2011-11-30 00:00 ——– d—–w- c:\documents and settings\John\Application Data\Autodesk
2011-11-24 04:40 . 2011-11-24 04:45 ——– d—–w- c:\program files\AutoCAD 2008
2011-11-24 04:39 . 2011-11-24 04:39 180224 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\iGdiCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 32768 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\objpscnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 262144 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IScrCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 409600 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\ISRT.dll
2011-11-24 04:39 . 2011-11-24 04:39 172032 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IUserCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 761856 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe
2011-11-24 04:39 . 2011-11-24 04:39 540772 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\_ISRES1033.dll
2011-11-24 04:39 . 2011-11-24 04:40 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Autodesk
2011-11-24 04:11 . 2011-11-24 04:11 ——– d—–w- c:\documents and settings\John\Application Data\SUPERAntiSpyware.com
2011-11-24 04:09 . 2011-11-24 04:11 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-11-24 04:09 . 2011-11-24 04:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-11-23 04:45 . 2011-11-23 21:24 ——– d—–w- C:\Office
2011-11-22 00:46 . 2011-11-22 00:46 54016 —-a-w- c:\windows\system32\drivers\cechtwji.sys
2011-11-22 00:29 . 2011-11-22 00:29 ——– d—–w- c:\documents and settings\John\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-22 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-25 23:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-22 00:28 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-21 23:13 . 1997-04-09 01:08 299520 —-a-w- c:\windows\uninst.exe
2011-11-21 00:07 . 2011-11-21 00:07 ——– d—–w- C:\Sierra
2011-11-20 22:00 . 2011-11-21 00:07 ——– d—–w- c:\program files\Sierra On-Line
2011-11-17 10:55 . 2011-11-17 10:55 ——– d—–w- c:\program files\Free Convert MPEG WMV to MP4 FLV AVI Converter
2011-11-17 10:55 . 2007-09-04 16:56 164352 —-a-w- c:\windows\system32\unrar.dll
2011-11-17 10:54 . 2008-07-04 06:34 860160 —-a-w- c:\windows\system32\lameACM.acm
2011-11-17 10:54 . 2007-09-21 00:52 118784 —-a-w- c:\windows\system32\ac3acm.acm
2011-11-17 10:54 . 2004-01-25 16:18 217088 —-a-w- c:\windows\system32\yv12vfw.dll
2011-11-17 10:54 . 2008-05-22 22:22 3596288 —-a-w- c:\windows\system32\qt-dx331.dll
2011-11-17 10:54 . 2008-05-22 22:19 81920 —-a-w- c:\windows\system32\dpl100.dll
2011-11-17 10:54 . 2008-01-10 12:16 159839 —-a-w- c:\windows\system32\xvidvfw.dll
2011-11-17 10:54 . 2008-01-10 12:15 755027 —-a-w- c:\windows\system32\xvidcore.dll
2011-11-17 10:54 . 2008-06-12 18:36 7680 —-a-w- c:\windows\system32\ff_vfw.dll
2011-11-17 10:54 . 2008-05-30 23:22 683520 —-a-w- c:\windows\system32\divx.dll
2011-11-17 10:54 . 2011-11-17 10:54 ——– d—–w- c:\program files\K-Lite Codec Pack
2011-11-13 20:27 . 2011-11-22 04:48 ——– d—–w- c:\windows\system32\NtmsData
2011-11-12 23:13 . 2011-11-13 06:38 ——– d—–w- c:\documents and settings\John\Application Data\Grasshopper
2011-11-12 20:20 . 2008-04-14 12:00 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-11-11 21:37 . 2011-11-11 21:37 ——– d—–w- c:\program files\LucasArts
2011-11-11 21:36 . 2005-04-04 04:02 69714 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2011-11-11 21:36 . 2005-04-04 04:01 274432 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2011-11-11 21:36 . 2005-04-04 04:00 184320 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2011-11-11 21:36 . 2005-04-04 03:59 5632 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2011-11-11 21:36 . 2005-04-04 04:02 753664 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2011-11-11 21:36 . 2011-11-11 21:36 331908 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2011-11-11 21:36 . 2011-11-11 21:36 200836 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2011-11-10 03:22 . 2009-09-10 17:48 27072 —-a-w- c:\windows\system32\drivers\AFGSp50.sys
2011-11-10 03:21 . 2011-11-10 03:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Affinegy
2011-11-10 03:21 . 2011-11-10 03:21 ——– d—–w- c:\program files\Belkin
2011-11-09 20:40 . 2011-11-10 01:05 ——– d—–w- C:\Shading
2011-11-04 20:52 . 2011-12-04 11:59 ——– d—–w- c:\documents and settings\All Users\Application Data\BOINC
2011-11-04 20:52 . 2011-11-04 22:16 ——– d—–w- c:\program files\BOINC
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-09-11 06:10 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-10 14:22 . 2008-04-25 21:27 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2008-04-25 16:16 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 02:41 . 2008-07-30 07:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 02:41 . 2008-04-25 16:16 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 02:41 . 2008-04-25 16:16 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-08 01:06 . 2011-09-08 01:06 1227295 —-a-w- c:\program files\unins000.exe
2011-09-06 13:25 . 2008-04-25 16:16 1867904 —-a-w- c:\windows\system32\win32k.sys
2011-09-05 13:56 . 2008-04-25 16:16 667136 —-a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2008-04-25 16:16 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:56 . 2008-04-25 16:16 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-09-05 12:35 . 2008-04-25 16:16 369664 —-a-w- c:\windows\system32\html.iec
2011-07-23 02:45 . 2011-09-08 01:06 309248 —-a-w- c:\program files\mpcresources.ua.dll
2011-07-23 02:45 . 2011-09-08 01:06 305152 —-a-w- c:\program files\mpcresources.tr.dll
2011-07-23 02:45 . 2011-09-08 01:06 304128 —-a-w- c:\program files\mpcresources.sv.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.es.dll
2011-07-23 02:45 . 2011-09-08 01:06 311296 —-a-w- c:\program files\mpcresources.sk.dll
2011-07-23 02:45 . 2011-09-08 01:06 310784 —-a-w- c:\program files\mpcresources.ru.dll
2011-07-23 02:45 . 2011-09-08 01:06 315904 —-a-w- c:\program files\mpcresources.pl.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.br.dll
2011-07-23 02:45 . 2011-09-08 01:06 273920 —-a-w- c:\program files\mpcresources.kr.dll
2011-07-23 02:45 . 2011-09-08 01:06 278016 —-a-w- c:\program files\mpcresources.ja.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.it.dll
2011-07-23 02:45 . 2011-09-08 01:06 313344 —-a-w- c:\program files\mpcresources.hu.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.de.dll
2011-07-23 02:45 . 2011-09-08 01:06 295936 —-a-w- c:\program files\mpcresources.he.dll
2011-07-23 02:45 . 2011-09-08 01:06 316416 —-a-w- c:\program files\mpcresources.fr.dll
2011-07-23 02:45 . 2011-09-08 01:06 306688 —-a-w- c:\program files\mpcresources.nl.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.cz.dll
2011-07-23 02:45 . 2011-09-08 01:06 267776 —-a-w- c:\program files\mpcresources.tc.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.ca.dll
2011-07-23 02:45 . 2011-09-08 01:06 267264 —-a-w- c:\program files\mpcresources.sc.dll
2011-07-23 02:45 . 2011-09-08 01:06 307200 —-a-w- c:\program files\mpcresources.by.dll
2011-07-23 02:45 . 2011-09-08 01:06 305664 —-a-w- c:\program files\mpcresources.hy.dll
2011-07-23 02:45 . 2011-09-08 01:06 2845184 —-a-w- c:\program files\mpciconlib.dll
2011-07-23 02:45 . 2011-09-08 01:06 9981952 —-a-w- c:\program files\mpc-hc.exe
2011-09-03 06:01 . 2011-09-09 20:32 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-09-09 20:38 . 2011-09-09 20:38 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-30_10.54.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-04 11:57 . 2011-12-04 11:57 16384 c:\windows\Temp\Perflib_Perfdata_630.dat
+ 2011-09-08 00:40 . 2011-12-04 02:39 27744 c:\windows\system32\nvModes.dat
- 2011-09-08 00:40 . 2011-11-29 09:25 27744 c:\windows\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-07 4617600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-02-17 278528]
"DellCleanup"="c:\dell\WINCLEAN.EXE" [2011-09-02 212992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-22 13508608]
"nwiz"="nwiz.exe" [2008-02-22 1626112]
"NVHotkey"="nvHotkey.dll" [2008-02-22 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-22 86016]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2011-09-09 30192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-06-22 1407248]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-22 1210640]
"boincmgr"="c:\program files\BOINC\boincmgr.exe" [2011-07-28 4514992]
"boinctray"="c:\program files\BOINC\boinctray.exe" [2011-07-28 70832]
"InstaLAN"="c:\program files\Belkin\Router Setup and Monitor\BelkinSetup.exe" [2009-09-11 6788944]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\John\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\John\Application Data\Dropbox\bin\Dropbox.exe [2011-9-1 24183152]
PdaNet Desktop.lnk - c:\program files\PdaNet for Android\PdaNetPC.exe [2011-9-20 447952]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-9-30 113664]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\John\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"5353:TCP"= 5353:TCP:Adobe CSI CS4
.
R1 MpKsld69ad287;MpKsld69ad287;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\MpKsld69ad287.sys [12/4/2011 7:09 AM 29904]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 5:56 AM 133968]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [10/7/2011 12:20 AM 6609920]
R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [9/7/2011 2:14 PM 9472]
S1 MpKsl77c167a1;MpKsl77c167a1; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [9/9/2011 3:38 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NvtSp50.sys –> c:\windows\system32\Drivers\NvtSp50.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 11:16 AM 14336]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLD69AD287
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005Core.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005UA.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-12-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2011-12-04 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-09-08 02:18]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\nnirvzdv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 52202
FF - prefs.js: network.proxy.type - 1
.
.
——- File Associations ——-
.
.scr=ft000002
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 07:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1064)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\netprovcredman.dll
.
Completion time: 2011-12-04 07:31:07
ComboFix-quarantined-files.txt 2011-12-04 12:31
ComboFix2.txt 2011-11-30 10:58
.
Pre-Run: 27,081,134,080 bytes free
Post-Run: 37,447,417,856 bytes free
.
- - End Of File - - 1DDA729C4A4BD8D07BA00ACF93DC5FC9
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1379 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
H:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-11-04 to 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-12-04 12:09 . 2011-12-04 12:09 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\MpKsld69ad287.sys
2011-12-04 12:09 . 2011-12-04 12:09 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\offreg.dll
2011-12-04 12:09 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\mpengine.dll
2011-12-02 05:41 . 2011-12-02 05:41 ——– d—–w- c:\program files\CamStudio 2.6b
2011-12-02 05:41 . 2010-10-24 05:56 49664 —-a-w- c:\windows\system32\CamCodec.dll
2011-11-26 22:59 . 2011-11-26 23:01 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-26 03:05 . 2011-11-26 03:05 54016 —-a-w- c:\windows\system32\drivers\vtkcjvk.sys
2011-11-25 23:53 . 2011-11-25 23:53 54016 —-a-w- c:\windows\system32\drivers\evocs.sys
2011-11-25 18:35 . 2011-11-25 18:35 ——– d—–w- c:\windows\system32\LogFiles
2011-11-25 18:35 . 2011-11-25 19:36 ——– d—–w- c:\documents and settings\John\Application Data\384F4
2011-11-25 04:39 . 2011-11-25 04:39 ——– d—–w- C:\Ready to run with view Thesis
2011-11-25 04:29 . 2011-11-25 04:29 ——– d—–w- C:\Copy (2) of Thesis
2011-11-25 02:24 . 2011-11-25 02:24 ——– d—–w- C:\Base Results of Thesis
2011-11-25 02:05 . 2011-11-25 02:05 ——– d—–w- C:\Copy of Thesis
2011-11-25 00:31 . 2011-11-26 04:52 ——– d—–w- C:\Thesis
2011-11-24 04:40 . 2011-11-30 00:00 ——– d—–w- c:\documents and settings\John\Application Data\Autodesk
2011-11-24 04:40 . 2011-11-24 04:45 ——– d—–w- c:\program files\AutoCAD 2008
2011-11-24 04:39 . 2011-11-24 04:39 180224 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\iGdiCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 32768 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\objpscnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 262144 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IScrCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 409600 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\ISRT.dll
2011-11-24 04:39 . 2011-11-24 04:39 172032 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IUserCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 761856 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe
2011-11-24 04:39 . 2011-11-24 04:39 540772 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\_ISRES1033.dll
2011-11-24 04:39 . 2011-11-24 04:40 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Autodesk
2011-11-24 04:11 . 2011-11-24 04:11 ——– d—–w- c:\documents and settings\John\Application Data\SUPERAntiSpyware.com
2011-11-24 04:09 . 2011-11-24 04:11 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-11-24 04:09 . 2011-11-24 04:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-11-23 04:45 . 2011-11-23 21:24 ——– d—–w- C:\Office
2011-11-22 00:46 . 2011-11-22 00:46 54016 —-a-w- c:\windows\system32\drivers\cechtwji.sys
2011-11-22 00:29 . 2011-11-22 00:29 ——– d—–w- c:\documents and settings\John\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-22 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-25 23:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-22 00:28 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-21 23:13 . 1997-04-09 01:08 299520 —-a-w- c:\windows\uninst.exe
2011-11-21 00:07 . 2011-11-21 00:07 ——– d—–w- C:\Sierra
2011-11-20 22:00 . 2011-11-21 00:07 ——– d—–w- c:\program files\Sierra On-Line
2011-11-17 10:55 . 2011-11-17 10:55 ——– d—–w- c:\program files\Free Convert MPEG WMV to MP4 FLV AVI Converter
2011-11-17 10:55 . 2007-09-04 16:56 164352 —-a-w- c:\windows\system32\unrar.dll
2011-11-17 10:54 . 2008-07-04 06:34 860160 —-a-w- c:\windows\system32\lameACM.acm
2011-11-17 10:54 . 2007-09-21 00:52 118784 —-a-w- c:\windows\system32\ac3acm.acm
2011-11-17 10:54 . 2004-01-25 16:18 217088 —-a-w- c:\windows\system32\yv12vfw.dll
2011-11-17 10:54 . 2008-05-22 22:22 3596288 —-a-w- c:\windows\system32\qt-dx331.dll
2011-11-17 10:54 . 2008-05-22 22:19 81920 —-a-w- c:\windows\system32\dpl100.dll
2011-11-17 10:54 . 2008-01-10 12:16 159839 —-a-w- c:\windows\system32\xvidvfw.dll
2011-11-17 10:54 . 2008-01-10 12:15 755027 —-a-w- c:\windows\system32\xvidcore.dll
2011-11-17 10:54 . 2008-06-12 18:36 7680 —-a-w- c:\windows\system32\ff_vfw.dll
2011-11-17 10:54 . 2008-05-30 23:22 683520 —-a-w- c:\windows\system32\divx.dll
2011-11-17 10:54 . 2011-11-17 10:54 ——– d—–w- c:\program files\K-Lite Codec Pack
2011-11-13 20:27 . 2011-11-22 04:48 ——– d—–w- c:\windows\system32\NtmsData
2011-11-12 23:13 . 2011-11-13 06:38 ——– d—–w- c:\documents and settings\John\Application Data\Grasshopper
2011-11-12 20:20 . 2008-04-14 12:00 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-11-11 21:37 . 2011-11-11 21:37 ——– d—–w- c:\program files\LucasArts
2011-11-11 21:36 . 2005-04-04 04:02 69714 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2011-11-11 21:36 . 2005-04-04 04:01 274432 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2011-11-11 21:36 . 2005-04-04 04:00 184320 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2011-11-11 21:36 . 2005-04-04 03:59 5632 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2011-11-11 21:36 . 2005-04-04 04:02 753664 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2011-11-11 21:36 . 2011-11-11 21:36 331908 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2011-11-11 21:36 . 2011-11-11 21:36 200836 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2011-11-10 03:22 . 2009-09-10 17:48 27072 —-a-w- c:\windows\system32\drivers\AFGSp50.sys
2011-11-10 03:21 . 2011-11-10 03:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Affinegy
2011-11-10 03:21 . 2011-11-10 03:21 ——– d—–w- c:\program files\Belkin
2011-11-09 20:40 . 2011-11-10 01:05 ——– d—–w- C:\Shading
2011-11-04 20:52 . 2011-12-04 11:59 ——– d—–w- c:\documents and settings\All Users\Application Data\BOINC
2011-11-04 20:52 . 2011-11-04 22:16 ——– d—–w- c:\program files\BOINC
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-09-11 06:10 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-10 14:22 . 2008-04-25 21:27 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2008-04-25 16:16 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 02:41 . 2008-07-30 07:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 02:41 . 2008-04-25 16:16 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 02:41 . 2008-04-25 16:16 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-08 01:06 . 2011-09-08 01:06 1227295 —-a-w- c:\program files\unins000.exe
2011-09-06 13:25 . 2008-04-25 16:16 1867904 —-a-w- c:\windows\system32\win32k.sys
2011-09-05 13:56 . 2008-04-25 16:16 667136 —-a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2008-04-25 16:16 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:56 . 2008-04-25 16:16 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-09-05 12:35 . 2008-04-25 16:16 369664 —-a-w- c:\windows\system32\html.iec
2011-07-23 02:45 . 2011-09-08 01:06 309248 —-a-w- c:\program files\mpcresources.ua.dll
2011-07-23 02:45 . 2011-09-08 01:06 305152 —-a-w- c:\program files\mpcresources.tr.dll
2011-07-23 02:45 . 2011-09-08 01:06 304128 —-a-w- c:\program files\mpcresources.sv.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.es.dll
2011-07-23 02:45 . 2011-09-08 01:06 311296 —-a-w- c:\program files\mpcresources.sk.dll
2011-07-23 02:45 . 2011-09-08 01:06 310784 —-a-w- c:\program files\mpcresources.ru.dll
2011-07-23 02:45 . 2011-09-08 01:06 315904 —-a-w- c:\program files\mpcresources.pl.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.br.dll
2011-07-23 02:45 . 2011-09-08 01:06 273920 —-a-w- c:\program files\mpcresources.kr.dll
2011-07-23 02:45 . 2011-09-08 01:06 278016 —-a-w- c:\program files\mpcresources.ja.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.it.dll
2011-07-23 02:45 . 2011-09-08 01:06 313344 —-a-w- c:\program files\mpcresources.hu.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.de.dll
2011-07-23 02:45 . 2011-09-08 01:06 295936 —-a-w- c:\program files\mpcresources.he.dll
2011-07-23 02:45 . 2011-09-08 01:06 316416 —-a-w- c:\program files\mpcresources.fr.dll
2011-07-23 02:45 . 2011-09-08 01:06 306688 —-a-w- c:\program files\mpcresources.nl.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.cz.dll
2011-07-23 02:45 . 2011-09-08 01:06 267776 —-a-w- c:\program files\mpcresources.tc.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.ca.dll
2011-07-23 02:45 . 2011-09-08 01:06 267264 —-a-w- c:\program files\mpcresources.sc.dll
2011-07-23 02:45 . 2011-09-08 01:06 307200 —-a-w- c:\program files\mpcresources.by.dll
2011-07-23 02:45 . 2011-09-08 01:06 305664 —-a-w- c:\program files\mpcresources.hy.dll
2011-07-23 02:45 . 2011-09-08 01:06 2845184 —-a-w- c:\program files\mpciconlib.dll
2011-07-23 02:45 . 2011-09-08 01:06 9981952 —-a-w- c:\program files\mpc-hc.exe
2011-09-03 06:01 . 2011-09-09 20:32 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-09-09 20:38 . 2011-09-09 20:38 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-30_10.54.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-04 11:57 . 2011-12-04 11:57 16384 c:\windows\Temp\Perflib_Perfdata_630.dat
+ 2011-09-08 00:40 . 2011-12-04 02:39 27744 c:\windows\system32\nvModes.dat
- 2011-09-08 00:40 . 2011-11-29 09:25 27744 c:\windows\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-07 4617600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-02-17 278528]
"DellCleanup"="c:\dell\WINCLEAN.EXE" [2011-09-02 212992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-22 13508608]
"nwiz"="nwiz.exe" [2008-02-22 1626112]
"NVHotkey"="nvHotkey.dll" [2008-02-22 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-22 86016]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2011-09-09 30192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-06-22 1407248]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-22 1210640]
"boincmgr"="c:\program files\BOINC\boincmgr.exe" [2011-07-28 4514992]
"boinctray"="c:\program files\BOINC\boinctray.exe" [2011-07-28 70832]
"InstaLAN"="c:\program files\Belkin\Router Setup and Monitor\BelkinSetup.exe" [2009-09-11 6788944]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\John\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\John\Application Data\Dropbox\bin\Dropbox.exe [2011-9-1 24183152]
PdaNet Desktop.lnk - c:\program files\PdaNet for Android\PdaNetPC.exe [2011-9-20 447952]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-9-30 113664]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\John\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"5353:TCP"= 5353:TCP:Adobe CSI CS4
.
R1 MpKsld69ad287;MpKsld69ad287;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\MpKsld69ad287.sys [12/4/2011 7:09 AM 29904]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 5:56 AM 133968]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [10/7/2011 12:20 AM 6609920]
R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [9/7/2011 2:14 PM 9472]
S1 MpKsl77c167a1;MpKsl77c167a1; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [9/9/2011 3:38 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NvtSp50.sys –> c:\windows\system32\Drivers\NvtSp50.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 11:16 AM 14336]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLD69AD287
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005Core.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005UA.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-12-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2011-12-04 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-09-08 02:18]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\nnirvzdv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 52202
FF - prefs.js: network.proxy.type - 1
.
.
——- File Associations ——-
.
.scr=ft000002
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 07:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1064)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\netprovcredman.dll
.
Completion time: 2011-12-04 07:31:07
ComboFix-quarantined-files.txt 2011-12-04 12:31
ComboFix2.txt 2011-11-30 10:58
.
Pre-Run: 27,081,134,080 bytes free
Post-Run: 37,447,417,856 bytes free
.
- - End Of File - - 1DDA729C4A4BD8D07BA00ACF93DC5FC9