Wicked Kitt_E
Hi Jeff,
I want to let you know that I wont have access to the infected computer until Thursday evening. I hope you could keep this thread open while I'm gone. Thx
Here is the combofix file that you requested:
ComboFix 11-12-12.02 - Deano-Casino 12/13/2011 9:40.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.330 [GMT -7:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\windows\system32\G4E7R0u.com_"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Deano-Casino\Application Data\Toolbar4
.
.
((((((((((((((((((((((((( Files Created from 2011-11-13 to 2011-12-13 )))))))))))))))))))))))))))))))
.
.
2011-12-12 05:42 . 2011-12-12 05:44 ——– d—–w- c:\documents and settings\Administrator\.minecraft
2011-12-09 22:28 . 2011-12-09 22:30 79872 —-a-w- c:\windows\system32\G4E7R0u.com_
2011-12-07 06:12 . 2011-12-07 06:12 ——– d—–w- C:\76eb605531d17f49d13974016cf124
2011-12-07 05:59 . 2011-12-07 06:18 ——– d—–w- c:\windows\SxsCaPendDel
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\AVG Secure Search
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\The Crew\Application Data\AVG2012
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG2012
2011-12-01 20:45 . 2011-12-01 20:45 ——– d—–w- C:\tdsskiller
2011-11-23 17:57 . 2011-11-23 17:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-22 12:19 . 2011-11-22 12:19 ——– d—–w- C:\found.000
2011-11-19 23:45 . 2011-11-19 23:45 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15 . 2011-11-19 22:15 ——– d—–w- c:\program files\Emerge Desktop
2011-11-18 07:47 . 2011-11-18 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\3B35B
2011-11-18 06:52 . 2011-11-18 06:52 ——– d—–w- C:\LB Photo Realism x256 6.9.2
2011-11-16 15:39 . 2011-11-16 15:39 ——– d—–w- c:\documents and settings\All Users\Application Data\F3A9
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-13 00:00 . 2011-12-13 00:00 1557928 —-a-w- C:\tdsskiller1.zip
2011-12-01 12:48 . 2008-04-14 12:00 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-01 04:44 . 2011-12-01 20:45 1547774 —-a-w- C:\tdsskiller.zip
2011-10-25 08:07 . 2011-10-08 02:26 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-10-10 14:22 . 2009-10-07 00:45 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 13:23 . 2010-12-08 11:12 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 13:21 . 2010-08-03 22:23 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06 . 2008-04-14 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2008-07-30 02:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2008-04-14 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2008-04-14 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-23 22:02 . 2011-05-19 20:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 17:05 . 2011-03-29 21:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\All Users\Application Data\3B35B —-
.
2011-11-18 07:48 . 2010-12-14 15:02 3957 —-a-w- c:\documents and settings\All Users\Application Data\3B35B\{B031773F-6F0E-4BB2-8C0E-D1D8DEB3851B}.swf
.
—- Directory of c:\documents and settings\All Users\Application Data\F3A9 —-
.
2011-11-16 15:39 . 2010-12-14 15:02 3957 —-a-w- c:\documents and settings\All Users\Application Data\F3A9\{F62FF99B-E3A0-4F9D-A0C8-604391F13C25}.swf
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-12_18.09.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-13 16:20 . 2011-12-13 16:20 16384 c:\windows\Temp\Perflib_Perfdata_444.dat
+ 2011-01-07 22:39 . 2011-01-07 22:39 51024 c:\windows\system32\vcomp100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 51024 c:\windows\system32\vcomp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80720 c:\windows\system32\mfcm100u.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80720 c:\windows\system32\mfcm100u.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80208 c:\windows\system32\mfcm100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80208 c:\windows\system32\mfcm100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 60752 c:\windows\system32\mfc100rus.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 60752 c:\windows\system32\mfc100rus.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43344 c:\windows\system32\mfc100kor.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43344 c:\windows\system32\mfc100kor.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43856 c:\windows\system32\mfc100jpn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 62288 c:\windows\system32\mfc100ita.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 62288 c:\windows\system32\mfc100ita.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100fra.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100fra.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 63824 c:\windows\system32\mfc100esn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 63824 c:\windows\system32\mfc100esn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 55120 c:\windows\system32\mfc100enu.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 55120 c:\windows\system32\mfc100enu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100deu.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100deu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100cht.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100cht.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100chs.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100chs.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 768848 c:\windows\system32\msvcr100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 421200 c:\windows\system32\msvcp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 421200 c:\windows\system32\msvcp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 137544 c:\windows\system32\atl100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4342600 c:\windows\system32\mfc100.dll
+ 2011-12-13 16:30 . 2011-12-13 16:30 2186240 c:\windows\Installer\aa899.msi
+ 2011-01-08 03:10 . 2011-01-08 03:10 3991040 c:\windows\Installer\33ccf61.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-12-07 04:15 1451336 —-a-w- c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2011-03-23 15:12 931696 —-a-w- c:\program files\kikin\ie_kikin.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll" [2011-12-07 1451336]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2011-12-07 218464]
.
c:\documents and settings\The Crew\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Styler.lnk - c:\documents and settings\The Crew\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2011-6-16 15086]
.
c:\documents and settings\Deano-Casino\Start Menu\Programs\Startup\AutorunsDisabled
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fliptoast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Fliptoast.lnk
backup=c:\windows\pss\Fliptoast.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Philips GoGear VIBE Device Manager.lnk]
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2011-04-12 07:14 4613624 —-a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Update]
2011-04-12 07:14 608760 —-a-w- c:\program files\4shared Desktop\checkUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
2008-04-13 12:39 49152 —-a-w- c:\program files\Vista Drive Icon\DrvIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2008-04-14 12:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iMesh]
2011-06-01 19:19 21880240 —-a-w- c:\program files\iMesh Applications\iMesh\iMesh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2011-10-08 21:31 366024 —-a-w- c:\program files\IncrediMail\Bin\IncMail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-07-30 17:41 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 09:57 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM]
2011-09-13 04:59 106496 —-a-w- c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-02-17 17:14 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyPC]
2011-05-24 00:27 67960 —-a-w- c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2010-04-29 16:38 1652736 —-a-r- c:\program files\AWS\WeatherBug\Weather.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"SearchAnonymizer"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 Beta 5\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 RC 1\\firefox.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Lighthouse Interactive\\T34vsTiger\\TvsT.exe"=
"c:\\Program Files\\Ubisoft\\IL-2 Sturmovik Forgotten Battles\\il2.exe"=
"c:\\Program Files\\Lead Pursuit\\Battlefield Operations\\FalconAF.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\brink\\brink.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\ava\\REACTOR.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life\\hl.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\iBryte\\playbryte\\ibrytedesktop.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Documents and Settings\\The Crew.DEAM\\Local Settings\\Temp\\incredimail_install.exe"=
"c:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Steam\\steamapps\\azcrew\\garrysmod\\hl2.exe"=
"c:\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/20/2009 9:23 AM 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/12/2009 9:05 AM 206256]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 230608]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [4/27/2011 10:33 PM 2218600]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [12/6/2011 9:15 PM 246624]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 16720]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [12/11/2009 9:37 AM 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [10/7/2009 9:39 AM 457312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/8/2009 3:29 PM 47360]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [5/1/2007 4:11 PM 132232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2/3/2009 7:41 AM 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2/3/2009 7:41 AM 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2009 12:39 PM 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/12/2009 9:05 AM 348824]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizerHelper.exe [9/12/2011 9:59 PM 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 17:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\At10.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At12.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-10 c:\windows\Tasks\At14.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-10 c:\windows\Tasks\At16.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At18.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At2.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At20.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At22.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At24.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At26.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At28.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At30.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At32.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At34.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At36.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At38.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At4.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At40.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At42.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At44.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At46.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At48.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At6.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At8.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-02 00:24]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-09-26 c:\windows\Tasks\Norton Security Scan for Deano-Casino.job
- c:\progra~1\NORTON~2\Engine\351~1.6\Nss.exe [2011-07-16 11:19]
.
2011-12-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-18 00:27]
.
2011-12-13 c:\windows\Tasks\User_Feed_Synchronization-{D81FAA29-1225-43D0-9C2B-A4B5A9C8A97D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bigseekpro.com/pivotstickfigure/{5D7E9955-3C04-4B2E-BE43-C161637CC061}
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bd8b798bc-6ae6-4a18-90fc-15f2bf54a416%7D&mid=27ee163b2f4cb34ac3e1da2365327ceb-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=8.0.0.40&lang=en&pr=fr&d=2011-12-06%2021%3A15%3A09&sap=ku&q=
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-13 09:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1060284298-1659004503-1177238915-1003\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:31,e4,75,d6,9b,a1,3f,18,f1,28,20,5c,9e,f8,f2,f7,43,3a,5e,af,c0,
98,ad,90,f4,d9,c1,fd,4d,93,dc,2d,41,a7,a0,33,b3,7d,0e,42,26,9e,e5,12,e7,4a,\
"rkeysecu"=hex:b2,95,bd,3c,85,4b,48,d5,56,4b,32,96,d0,df,b0,b6
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1080)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-13 10:04:38
ComboFix-quarantined-files.txt 2011-12-13 17:04
ComboFix2.txt 2011-12-12 18:15
ComboFix3.txt 2011-12-07 03:34
ComboFix4.txt 2011-12-05 02:19
ComboFix5.txt 2011-12-13 16:33
.
Pre-Run: 34,073,661,440 bytes free
Post-Run: 34,060,410,880 bytes free
.
- - End Of File - - 93B8F0F9C53E6852CC6FE3AFF7D6CAC3
I want to let you know that I wont have access to the infected computer until Thursday evening. I hope you could keep this thread open while I'm gone. Thx
Here is the combofix file that you requested:
ComboFix 11-12-12.02 - Deano-Casino 12/13/2011 9:40.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.330 [GMT -7:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\windows\system32\G4E7R0u.com_"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Deano-Casino\Application Data\Toolbar4
.
.
((((((((((((((((((((((((( Files Created from 2011-11-13 to 2011-12-13 )))))))))))))))))))))))))))))))
.
.
2011-12-12 05:42 . 2011-12-12 05:44 ——– d—–w- c:\documents and settings\Administrator\.minecraft
2011-12-09 22:28 . 2011-12-09 22:30 79872 —-a-w- c:\windows\system32\G4E7R0u.com_
2011-12-07 06:12 . 2011-12-07 06:12 ——– d—–w- C:\76eb605531d17f49d13974016cf124
2011-12-07 05:59 . 2011-12-07 06:18 ——– d—–w- c:\windows\SxsCaPendDel
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\AVG Secure Search
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\The Crew\Application Data\AVG2012
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG2012
2011-12-01 20:45 . 2011-12-01 20:45 ——– d—–w- C:\tdsskiller
2011-11-23 17:57 . 2011-11-23 17:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-22 12:19 . 2011-11-22 12:19 ——– d—–w- C:\found.000
2011-11-19 23:45 . 2011-11-19 23:45 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15 . 2011-11-19 22:15 ——– d—–w- c:\program files\Emerge Desktop
2011-11-18 07:47 . 2011-11-18 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\3B35B
2011-11-18 06:52 . 2011-11-18 06:52 ——– d—–w- C:\LB Photo Realism x256 6.9.2
2011-11-16 15:39 . 2011-11-16 15:39 ——– d—–w- c:\documents and settings\All Users\Application Data\F3A9
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-13 00:00 . 2011-12-13 00:00 1557928 —-a-w- C:\tdsskiller1.zip
2011-12-01 12:48 . 2008-04-14 12:00 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-01 04:44 . 2011-12-01 20:45 1547774 —-a-w- C:\tdsskiller.zip
2011-10-25 08:07 . 2011-10-08 02:26 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-10-10 14:22 . 2009-10-07 00:45 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 13:23 . 2010-12-08 11:12 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 13:21 . 2010-08-03 22:23 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06 . 2008-04-14 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2008-07-30 02:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2008-04-14 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2008-04-14 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-23 22:02 . 2011-05-19 20:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 17:05 . 2011-03-29 21:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\All Users\Application Data\3B35B —-
.
2011-11-18 07:48 . 2010-12-14 15:02 3957 —-a-w- c:\documents and settings\All Users\Application Data\3B35B\{B031773F-6F0E-4BB2-8C0E-D1D8DEB3851B}.swf
.
—- Directory of c:\documents and settings\All Users\Application Data\F3A9 —-
.
2011-11-16 15:39 . 2010-12-14 15:02 3957 —-a-w- c:\documents and settings\All Users\Application Data\F3A9\{F62FF99B-E3A0-4F9D-A0C8-604391F13C25}.swf
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-12_18.09.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-13 16:20 . 2011-12-13 16:20 16384 c:\windows\Temp\Perflib_Perfdata_444.dat
+ 2011-01-07 22:39 . 2011-01-07 22:39 51024 c:\windows\system32\vcomp100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 51024 c:\windows\system32\vcomp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80720 c:\windows\system32\mfcm100u.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80720 c:\windows\system32\mfcm100u.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80208 c:\windows\system32\mfcm100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80208 c:\windows\system32\mfcm100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 60752 c:\windows\system32\mfc100rus.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 60752 c:\windows\system32\mfc100rus.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43344 c:\windows\system32\mfc100kor.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43344 c:\windows\system32\mfc100kor.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43856 c:\windows\system32\mfc100jpn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 62288 c:\windows\system32\mfc100ita.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 62288 c:\windows\system32\mfc100ita.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100fra.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100fra.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 63824 c:\windows\system32\mfc100esn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 63824 c:\windows\system32\mfc100esn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 55120 c:\windows\system32\mfc100enu.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 55120 c:\windows\system32\mfc100enu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100deu.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100deu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100cht.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100cht.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100chs.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100chs.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 768848 c:\windows\system32\msvcr100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 421200 c:\windows\system32\msvcp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 421200 c:\windows\system32\msvcp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 137544 c:\windows\system32\atl100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4342600 c:\windows\system32\mfc100.dll
+ 2011-12-13 16:30 . 2011-12-13 16:30 2186240 c:\windows\Installer\aa899.msi
+ 2011-01-08 03:10 . 2011-01-08 03:10 3991040 c:\windows\Installer\33ccf61.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-12-07 04:15 1451336 —-a-w- c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2011-03-23 15:12 931696 —-a-w- c:\program files\kikin\ie_kikin.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll" [2011-12-07 1451336]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2011-12-07 218464]
.
c:\documents and settings\The Crew\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Styler.lnk - c:\documents and settings\The Crew\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2011-6-16 15086]
.
c:\documents and settings\Deano-Casino\Start Menu\Programs\Startup\AutorunsDisabled
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fliptoast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Fliptoast.lnk
backup=c:\windows\pss\Fliptoast.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Philips GoGear VIBE Device Manager.lnk]
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2011-04-12 07:14 4613624 —-a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Update]
2011-04-12 07:14 608760 —-a-w- c:\program files\4shared Desktop\checkUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
2008-04-13 12:39 49152 —-a-w- c:\program files\Vista Drive Icon\DrvIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2008-04-14 12:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iMesh]
2011-06-01 19:19 21880240 —-a-w- c:\program files\iMesh Applications\iMesh\iMesh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2011-10-08 21:31 366024 —-a-w- c:\program files\IncrediMail\Bin\IncMail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-07-30 17:41 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 09:57 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM]
2011-09-13 04:59 106496 —-a-w- c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-02-17 17:14 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyPC]
2011-05-24 00:27 67960 —-a-w- c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2010-04-29 16:38 1652736 —-a-r- c:\program files\AWS\WeatherBug\Weather.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"SearchAnonymizer"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 Beta 5\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 RC 1\\firefox.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Lighthouse Interactive\\T34vsTiger\\TvsT.exe"=
"c:\\Program Files\\Ubisoft\\IL-2 Sturmovik Forgotten Battles\\il2.exe"=
"c:\\Program Files\\Lead Pursuit\\Battlefield Operations\\FalconAF.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\brink\\brink.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\ava\\REACTOR.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life\\hl.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\iBryte\\playbryte\\ibrytedesktop.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Documents and Settings\\The Crew.DEAM\\Local Settings\\Temp\\incredimail_install.exe"=
"c:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Steam\\steamapps\\azcrew\\garrysmod\\hl2.exe"=
"c:\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/20/2009 9:23 AM 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/12/2009 9:05 AM 206256]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 230608]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [4/27/2011 10:33 PM 2218600]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [12/6/2011 9:15 PM 246624]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 16720]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [12/11/2009 9:37 AM 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [10/7/2009 9:39 AM 457312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/8/2009 3:29 PM 47360]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [5/1/2007 4:11 PM 132232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2/3/2009 7:41 AM 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2/3/2009 7:41 AM 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2009 12:39 PM 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/12/2009 9:05 AM 348824]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizerHelper.exe [9/12/2011 9:59 PM 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 17:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\At10.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At12.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-10 c:\windows\Tasks\At14.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-10 c:\windows\Tasks\At16.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At18.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At2.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At20.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At22.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At24.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At26.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At28.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At30.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At32.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At34.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At36.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At38.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At4.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At40.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At42.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At44.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At46.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At48.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At6.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At8.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-02 00:24]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-09-26 c:\windows\Tasks\Norton Security Scan for Deano-Casino.job
- c:\progra~1\NORTON~2\Engine\351~1.6\Nss.exe [2011-07-16 11:19]
.
2011-12-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-18 00:27]
.
2011-12-13 c:\windows\Tasks\User_Feed_Synchronization-{D81FAA29-1225-43D0-9C2B-A4B5A9C8A97D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bigseekpro.com/pivotstickfigure/{5D7E9955-3C04-4B2E-BE43-C161637CC061}
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bd8b798bc-6ae6-4a18-90fc-15f2bf54a416%7D&mid=27ee163b2f4cb34ac3e1da2365327ceb-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=8.0.0.40&lang=en&pr=fr&d=2011-12-06%2021%3A15%3A09&sap=ku&q=
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-13 09:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1060284298-1659004503-1177238915-1003\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:31,e4,75,d6,9b,a1,3f,18,f1,28,20,5c,9e,f8,f2,f7,43,3a,5e,af,c0,
98,ad,90,f4,d9,c1,fd,4d,93,dc,2d,41,a7,a0,33,b3,7d,0e,42,26,9e,e5,12,e7,4a,\
"rkeysecu"=hex:b2,95,bd,3c,85,4b,48,d5,56,4b,32,96,d0,df,b0,b6
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1080)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-13 10:04:38
ComboFix-quarantined-files.txt 2011-12-13 17:04
ComboFix2.txt 2011-12-12 18:15
ComboFix3.txt 2011-12-07 03:34
ComboFix4.txt 2011-12-05 02:19
ComboFix5.txt 2011-12-13 16:33
.
Pre-Run: 34,073,661,440 bytes free
Post-Run: 34,060,410,880 bytes free
.
- - End Of File - - 93B8F0F9C53E6852CC6FE3AFF7D6CAC3