ComboFix 12-06-04.02 - Sonny13 05/24/2012 16:33:16.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.189 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\michael corleone\WINDOWS
c:\documents and settings\Owner\WINDOWS
c:\documents and settings\shera\WINDOWS
c:\documents and settings\Sonny13\WINDOWS
C:\Install.exe
c:\program files\SoftwareOnline
c:\windows\_detmp.2
c:\windows\desktop
c:\windows\desktop\Compaq Knowledge Center.lnk
c:\windows\didduid.ini
c:\windows\Downloaded Program Files\Install.inf
c:\windows\Downloaded Program Files\UWFX5LP_0001_0802NetInstaller.exe
c:\windows\patch.exe
c:\windows\SET4DB.tmp
c:\windows\system32\_005646_.tmp.dll
c:\windows\system32\_005647_.tmp.dll
c:\windows\system32\_005648_.tmp.dll
c:\windows\system32\_005649_.tmp.dll
c:\windows\system32\_005656_.tmp.dll
c:\windows\system32\_005657_.tmp.dll
c:\windows\system32\_005658_.tmp.dll
c:\windows\system32\_005659_.tmp.dll
c:\windows\system32\_005661_.tmp.dll
c:\windows\system32\_005662_.tmp.dll
c:\windows\system32\_005663_.tmp.dll
c:\windows\system32\_005665_.tmp.dll
c:\windows\system32\_005666_.tmp.dll
c:\windows\system32\_005668_.tmp.dll
c:\windows\system32\_005669_.tmp.dll
c:\windows\system32\_005670_.tmp.dll
c:\windows\system32\_005671_.tmp.dll
c:\windows\system32\_005672_.tmp.dll
c:\windows\system32\_005675_.tmp.dll
c:\windows\system32\_005676_.tmp.dll
c:\windows\system32\_005680_.tmp.dll
c:\windows\system32\_005681_.tmp.dll
c:\windows\system32\_005683_.tmp.dll
c:\windows\system32\_005685_.tmp.dll
c:\windows\system32\_005686_.tmp.dll
c:\windows\system32\_005688_.tmp.dll
c:\windows\system32\_005689_.tmp.dll
c:\windows\system32\_005690_.tmp.dll
c:\windows\system32\_005691_.tmp.dll
c:\windows\system32\_005692_.tmp.dll
c:\windows\system32\_005695_.tmp.dll
c:\windows\system32\_005696_.tmp.dll
c:\windows\system32\_005697_.tmp.dll
c:\windows\system32\_005698_.tmp.dll
c:\windows\system32\_005699_.tmp.dll
c:\windows\system32\_005704_.tmp.dll
c:\windows\system32\_005706_.tmp.dll
c:\windows\system32\_005707_.tmp.dll
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\dllcache\wmpvis.dll
c:\windows\system32\drivers\etc\hosts.bho
c:\windows\system32\SET179.tmp
c:\windows\system32\SET17A.tmp
c:\windows\system32\SET17C.tmp
c:\windows\system32\SET17E.tmp
c:\windows\system32\SET17F.tmp
c:\windows\system32\SET180.tmp
c:\windows\system32\SET187.tmp
c:\windows\system32\SET188.tmp
c:\windows\system32\SET18B.tmp
c:\windows\system32\SET19A.tmp
c:\windows\system32\SET1A0.tmp
c:\windows\system32\SET1A1.tmp
c:\windows\system32\SET1A4.tmp
c:\windows\system32\SET1A5.tmp
c:\windows\system32\SET1A6.tmp
c:\windows\system32\SET1A8.tmp
c:\windows\system32\SET1A9.tmp
c:\windows\system32\SET1AC.tmp
c:\windows\system32\SET1AD.tmp
c:\windows\system32\SET1AE.tmp
c:\windows\system32\SET1AF.tmp
c:\windows\system32\SET1B5.tmp
c:\windows\system32\SET1BC.tmp
c:\windows\system32\SET1BD.tmp
c:\windows\system32\SET1BE.tmp
c:\windows\system32\SET1BF.tmp
c:\windows\system32\SET1C2.tmp
c:\windows\system32\SET1C4.tmp
c:\windows\system32\SET1C5.tmp
c:\windows\system32\SET1CC.tmp
c:\windows\system32\SET1CE.tmp
c:\windows\system32\SET1CF.tmp
c:\windows\system32\SET1D0.tmp
c:\windows\system32\SET1D2.tmp
c:\windows\system32\SET1D3.tmp
c:\windows\system32\SET1D4.tmp
c:\windows\system32\SET1D9.tmp
c:\windows\system32\SET1DA.tmp
c:\windows\system32\SET1DB.tmp
c:\windows\system32\SET1DC.tmp
c:\windows\system32\SET1DF.tmp
c:\windows\system32\SET1E5.tmp
c:\windows\system32\SET1EB.tmp
c:\windows\system32\SET1EC.tmp
c:\windows\system32\SET1EF.tmp
c:\windows\system32\SET1F0.tmp
c:\windows\system32\SET1F2.tmp
c:\windows\system32\SET1F3.tmp
c:\windows\system32\SET1F5.tmp
c:\windows\system32\SET1FA.tmp
c:\windows\system32\SET1FB.tmp
c:\windows\system32\SET1FD.tmp
c:\windows\system32\SET20A.tmp
c:\windows\system32\SET20B.tmp
c:\windows\system32\SET20E.tmp
c:\windows\system32\SET210.tmp
c:\windows\system32\SET211.tmp
c:\windows\system32\SET212.tmp
c:\windows\system32\SET213.tmp
c:\windows\system32\SET214.tmp
c:\windows\system32\SET215.tmp
c:\windows\system32\SET219.tmp
c:\windows\system32\SET225.tmp
c:\windows\system32\SET22A.tmp
c:\windows\system32\SET22C.tmp
c:\windows\system32\SET22E.tmp
c:\windows\system32\SET22F.tmp
c:\windows\system32\SET230.tmp
c:\windows\system32\SET233.tmp
c:\windows\system32\SET234.tmp
c:\windows\system32\SET239.tmp
c:\windows\system32\SET23C.tmp
c:\windows\system32\SET23D.tmp
c:\windows\system32\SET23E.tmp
c:\windows\system32\SET244.tmp
c:\windows\system32\SET245.tmp
c:\windows\system32\SET246.tmp
c:\windows\system32\SET24E.tmp
c:\windows\system32\SET254.tmp
c:\windows\system32\SET255.tmp
c:\windows\system32\SET256.tmp
c:\windows\system32\SET258.tmp
c:\windows\system32\SET25A.tmp
c:\windows\system32\SET260.tmp
c:\windows\system32\SET26C.tmp
c:\windows\system32\SET26E.tmp
c:\windows\system32\SET270.tmp
c:\windows\system32\SET271.tmp
c:\windows\system32\SET272.tmp
c:\windows\system32\SET27F.tmp
c:\windows\system32\SET281.tmp
c:\windows\system32\SET282.tmp
c:\windows\system32\SET285.tmp
c:\windows\system32\SET287.tmp
c:\windows\system32\SET28B.tmp
c:\windows\system32\SET29F.tmp
c:\windows\system32\SET2A0.tmp
c:\windows\system32\SET2A7.tmp
c:\windows\system32\SET2A8.tmp
c:\windows\system32\SET2AB.tmp
c:\windows\system32\SET2AC.tmp
c:\windows\system32\SET2AD.tmp
c:\windows\system32\SET2AE.tmp
c:\windows\system32\SET2AF.tmp
c:\windows\system32\SET2B1.tmp
c:\windows\system32\SET2B2.tmp
c:\windows\system32\SET2B3.tmp
c:\windows\system32\SET2B5.tmp
c:\windows\system32\SET2B6.tmp
c:\windows\system32\SET2B7.tmp
c:\windows\system32\SET2BA.tmp
c:\windows\system32\SET2BD.tmp
c:\windows\system32\SET2C2.tmp
c:\windows\system32\SET2C3.tmp
c:\windows\system32\SET2C4.tmp
c:\windows\system32\SET2C8.tmp
c:\windows\system32\SET2C9.tmp
c:\windows\system32\SET2CA.tmp
c:\windows\system32\SET2CC.tmp
c:\windows\system32\SET2CF.tmp
c:\windows\system32\SET2D1.tmp
c:\windows\system32\SET2D2.tmp
c:\windows\system32\SET2D5.tmp
c:\windows\system32\SET2D6.tmp
c:\windows\system32\SET2D9.tmp
c:\windows\system32\SET2DC.tmp
c:\windows\system32\SET2DD.tmp
c:\windows\system32\SET2E4.tmp
c:\windows\system32\SET2EA.tmp
c:\windows\system32\SET2F0.tmp
c:\windows\system32\SET2F2.tmp
c:\windows\system32\SET2F3.tmp
c:\windows\system32\SET2F7.tmp
c:\windows\system32\SET304.tmp
c:\windows\system32\SET307.tmp
c:\windows\system32\SET309.tmp
c:\windows\system32\SET30A.tmp
c:\windows\system32\SET316.tmp
c:\windows\system32\SET318.tmp
c:\windows\system32\SET319.tmp
c:\windows\system32\SET31A.tmp
c:\windows\system32\SET31B.tmp
c:\windows\system32\SET31D.tmp
c:\windows\system32\SET31F.tmp
c:\windows\system32\SET323.tmp
c:\windows\system32\SET327.tmp
c:\windows\system32\SET333.tmp
c:\windows\system32\SET336.tmp
c:\windows\system32\SET337.tmp
c:\windows\system32\SET339.tmp
c:\windows\system32\SET33A.tmp
c:\windows\system32\SET33F.tmp
c:\windows\system32\SET341.tmp
c:\windows\system32\SET342.tmp
c:\windows\system32\SET349.tmp
c:\windows\system32\SET358.tmp
c:\windows\system32\SET359.tmp
c:\windows\system32\SET35A.tmp
c:\windows\system32\SET35B.tmp
c:\windows\system32\SET35E.tmp
c:\windows\system32\SET366.tmp
c:\windows\system32\SET368.tmp
c:\windows\system32\SET36E.tmp
c:\windows\system32\SET370.tmp
c:\windows\system32\SET377.tmp
c:\windows\system32\SET379.tmp
c:\windows\system32\SET393.tmp
c:\windows\system32\SET397.tmp
c:\windows\system32\SET399.tmp
c:\windows\system32\SET39B.tmp
c:\windows\system32\SET3A2.tmp
c:\windows\system32\SET3A7.tmp
c:\windows\system32\SET3BD.tmp
c:\windows\system32\SET3C0.tmp
c:\windows\system32\SET3C6.tmp
c:\windows\system32\SET3C8.tmp
c:\windows\system32\SET3C9.tmp
c:\windows\system32\SET3CA.tmp
c:\windows\system32\SET3D0.tmp
c:\windows\system32\SET3D4.tmp
c:\windows\system32\SET3DD.tmp
c:\windows\system32\SET3E3.tmp
c:\windows\system32\SET3E5.tmp
c:\windows\system32\SET3E6.tmp
c:\windows\system32\SET3E7.tmp
c:\windows\system32\SET3F1.tmp
c:\windows\system32\SET3F5.tmp
c:\windows\system32\SET400.tmp
c:\windows\system32\SET413.tmp
c:\windows\system32\SET414.tmp
c:\windows\system32\SET43E.tmp
c:\windows\system32\SET441.tmp
c:\windows\system32\SET449.tmp
c:\windows\system32\SET44A.tmp
c:\windows\system32\SET44C.tmp
c:\windows\system32\SET44D.tmp
c:\windows\system32\SET44E.tmp
c:\windows\system32\SET451.tmp
c:\windows\system32\SET453.tmp
c:\windows\system32\SET454.tmp
c:\windows\system32\SET456.tmp
c:\windows\system32\SET459.tmp
c:\windows\system32\SET45B.tmp
c:\windows\system32\SET460.tmp
c:\windows\system32\SET461.tmp
c:\windows\system32\SET469.tmp
c:\windows\system32\SET470.tmp
c:\windows\system32\SET477.tmp
c:\windows\system32\SET47B.tmp
c:\windows\system32\SET47E.tmp
c:\windows\system32\SET480.tmp
c:\windows\system32\SET484.tmp
c:\windows\system32\SET487.tmp
c:\windows\system32\SET488.tmp
c:\windows\system32\SET489.tmp
c:\windows\system32\SET48D.tmp
c:\windows\system32\SET48E.tmp
c:\windows\system32\SET48F.tmp
c:\windows\system32\SET492.tmp
c:\windows\system32\SET493.tmp
c:\windows\system32\SET49C.tmp
c:\windows\system32\SET49F.tmp
c:\windows\system32\SET4A1.tmp
c:\windows\system32\SET4A4.tmp
c:\windows\system32\SET4A7.tmp
c:\windows\system32\SET4A9.tmp
c:\windows\system32\SETF5D.tmp
c:\windows\system32\SETF61.tmp
c:\windows\system32\SETF64.tmp
c:\windows\system32\SETF69.tmp
c:\windows\system32\SETF9A.tmp
c:\windows\system32\SETFC3.tmp
c:\windows\system32\stlbdist.XML
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_SVCPROC
——-\Service_SvcProc
.
.
((((((((((((((((((((((((( Files Created from 2012-04-24 to 2012-05-24 )))))))))))))))))))))))))))))))
.
.
2012-05-24 22:07 . 2012-05-24 22:07 ——– d—–w- c:\documents and settings\Sonny13\Local Settings\Application Data\Thunderbird
2012-05-24 22:07 . 2012-05-24 22:07 ——– d—–w- c:\documents and settings\Sonny13\Application Data\Thunderbird
2012-05-24 02:37 . 2012-05-24 02:37 ——– d—–w- c:\program files\OpenOffice.org 3
2012-05-24 02:17 . 2012-05-24 02:17 ——– d—–w- c:\program files\Mozilla Thunderbird
2012-05-23 22:45 . 2012-05-23 22:45 1010720 –s—r- c:\windows\system32\MSCHRT20.OCX
2012-05-23 22:45 . 2012-05-23 22:45 ——– d—–w- c:\program files\Technitium
2012-05-23 22:38 . 2012-05-23 22:38 ——– d—–w- c:\program files\CCleaner
2012-05-23 03:00 . 2012-05-23 03:06 ——– d—–w- c:\windows\system32\scripting
2012-05-23 03:00 . 2012-05-23 03:06 ——– d—–w- c:\windows\l2schemas
2012-05-23 03:00 . 2012-05-23 03:06 ——– d—–w- c:\windows\system32\en
2012-05-23 02:41 . 2004-08-04 07:56 2897920 ——w- c:\windows\system32\xpsp2res.dll
2012-05-23 02:40 . 2001-08-18 12:00 5120 —-a-w- c:\windows\system32\dllcache\dcomcnfg.exe
2012-05-23 02:39 . 2010-02-05 18:40 1291264 —-a-w- c:\windows\system32\dllcache\quartz.dll
2012-05-23 02:38 . 2009-12-31 16:14 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2012-05-22 21:41 . 2008-04-14 00:12 178176 —-a-w- c:\windows\system32\wbem\SET52C.tmp
2012-05-22 21:41 . 2008-04-14 00:12 65536 —-a-w- c:\program files\Common Files\System\Ole DB\SET4F0.tmp
2012-05-22 21:41 . 2008-04-14 00:12 487424 —-a-w- c:\program files\Common Files\System\Ole DB\SET4F1.tmp
2012-05-22 21:41 . 2008-04-14 00:12 47104 —-a-w- c:\windows\system32\wbem\SET52F.tmp
2012-05-22 21:39 . 2008-04-14 00:11 185344 —-a-w- c:\windows\system32\wbem\SET533.tmp
2012-05-22 21:39 . 2006-12-28 19:01 19569 —-a-w- c:\windows\005250_.tmp
2012-05-22 21:39 . 2008-04-14 00:11 472064 —-a-w- c:\windows\system32\wbem\SET534.tmp
2012-05-22 21:39 . 2008-04-14 00:11 247808 —-a-w- c:\windows\system32\wbem\SET536.tmp
2012-05-22 20:55 . 2012-05-22 20:55 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-22 20:55 . 2012-05-22 20:55 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-22 20:50 . 2012-05-23 21:15 ——– d—–w- c:\windows\system32\CatRoot_bak
2012-05-22 20:39 . 2009-06-21 22:04 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2012-05-22 20:39 . 2009-10-23 14:27 3555328 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2012-05-22 20:37 . 2009-06-05 07:42 655872 -c—-w- c:\windows\system32\dllcache\mstscax.dll
2012-05-22 20:36 . 2009-07-31 04:57 1172480 -c—-w- c:\windows\system32\dllcache\msxml3.dll
2012-05-22 20:28 . 2008-05-01 14:30 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll
2012-05-22 20:13 . 2012-05-23 21:17 ——– d–h–w- c:\windows\$hf_mig$
2012-05-22 08:14 . 2012-05-23 03:18 ——– d—–w- c:\windows\system32\wbem\AutoRecover
2012-05-22 07:54 . 2012-05-23 03:08 ——– d—–w- c:\windows\peernet
2012-05-22 07:54 . 2012-05-22 07:54 ——– d—–w- c:\windows\provisioning
2012-05-22 07:49 . 2012-05-22 22:46 ——– d—–w- c:\windows\ServicePackFiles
2012-05-22 07:40 . 2007-08-11 03:46 26488 —-a-w- c:\windows\system32\spupdsvc.exe
2012-05-22 07:33 . 2012-05-23 02:37 ——– d—–w- c:\windows\EHome
2012-05-22 02:56 . 2012-05-22 02:56 ——– d—–w- c:\documents and settings\Sonny13\Local Settings\Application Data\Adobe
2012-05-22 00:04 . 2012-05-22 00:05 ——– d—–w- c:\documents and settings\Sonny13\Application Data\MSN6
2012-05-21 22:08 . 2012-03-06 23:03 337880 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-05-21 22:08 . 2012-03-06 23:02 35672 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-05-21 22:08 . 2012-03-06 23:01 53848 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-05-21 22:08 . 2012-03-06 23:01 95704 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2012-05-21 22:08 . 2012-03-06 23:01 89048 —-a-w- c:\windows\system32\drivers\aswmon.sys
2012-05-21 22:08 . 2012-03-06 22:58 24920 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2012-05-21 22:06 . 2012-03-06 23:15 41184 —-a-w- c:\windows\avastSS.scr
2012-05-21 22:06 . 2012-03-06 23:15 201352 —-a-w- c:\windows\system32\aswBoot.exe
2012-05-21 22:05 . 2012-05-21 22:05 ——– d—–w- c:\program files\AVAST Software
2012-05-21 22:05 . 2012-05-21 22:05 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-21 01:19 . 1980-05-22 01:03 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2000-07-13 311350]
"srmclean"="c:\cpqs\Scom\srmclean.exe" [2001-07-24 36864]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2002-09-11 368706]
"IPInSightLAN 02"="c:\program files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" [2003-06-11 380928]
"IPInSightMonitor 02"="c:\program files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe" [2003-06-11 122880]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-13 98304]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"CPQEASYACC"="c:\compaq\eakdrv\STARTDRV.exe" [2001-07-11 40960]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-7-13 24633]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2006-4-22 819200]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter2.0]
2004-07-20 16:34 851968 —-a-w- c:\program files\Brother\ControlCenter2\brctrcen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2001-11-17 15:55 26112 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Brother XP spl Service"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [5/21/2012 3:08 PM 337880]
S3 Gcr432;Gcr432;c:\windows\system32\drivers\Gcr432.sys [9/6/2001 11:05 AM 89371]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/21/1980 6:03 PM 129976]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
*Deregistered* - IPVNMon
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://yahoo.sbc.com/dsl
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Sonny13\Application Data\Mozilla\Firefox\Profiles\rihcn18h.default\
FF - prefs.js: network.proxy.ftp - 107.10.85.131
FF - prefs.js: network.proxy.http - 107.10.85.131
FF - prefs.js: network.proxy.socks - [removed]
FF - prefs.js: network.proxy.ssl - [removed]
FF - prefs.js: network.proxy.type - 1
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Microsoft Works Update Detection - c:\program files\Microsoft Works\WkDetect.exe
HKLM-Run-WorksFUD - (no file)
HKLM-Run-zXDHX9 - c:\documents and settings\michael corleone\local settings\temp\zXDHX9.exe
HKLM-Run-PKBdhT.exe - c:\windows\system32\PKBdhT.exe
HKLM-Run-zXDHX9.exe - c:\documents and settings\michael corleone\local settings\temp\zXDHX9.exe
HKLM-Run-Dinst - c:\windows\dinst.exe
HKLM-Run-ftimels - c:\windows\system32\cwybbic.exe
Notify-dimsntfy - (no file)
MSConfigStartUp-Rundll32_8 - c:\windows\System32\inetp60.dll
AddRemove-BroadJump Client Foundation - c:\program files\BroadJump\Client Foundation\Uninst.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-05-24 16:55
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\System32\SCardSvr.exe
c:\windows\System32\nvsvc32.exe
c:\windows\system32\pctspk.exe
c:\compaq\eakdrv\EAKDRV.exe
c:\compaq\eakdrv\EAUSBKBD.EXE
.
**************************************************************************
.
Completion time: 2012-05-24 17:01:48 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-25 00:01
.
Pre-Run: 20,858,564,608 bytes free
Post-Run: 20,839,682,048 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 69D12CECF12330622523AC32C30DDB54