Hi Rorschach,
ComboFix 08-04-08.4 - voomda.com 2008-04-08 19:09:20.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2158 [GMT -4:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
.
TimedOut: Windir.dat
TimedOut: progfile.dat
((((((((((((((((((((((((( Files Created from 2008-03-08 to 2008-04-08 )))))))))))))))))))))))))))))))
.
2008-04-07 12:15 . 2008-04-07 12:19 d——– C:\My Special Stuff
2008-04-06 21:22 . 2008-04-06 21:22 d——– C:\Users\All Users\Windows Genuine Advantage
2008-04-06 21:16 . 2008-04-08 19:03 1,856 –ah—– C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2008-04-06 21:16 . 2008-04-08 19:03 1,856 –ah—– C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2008-04-06 20:38 . 2008-04-06 22:16 271,657,654 –a—— C:\Windows\MEMORY.DMP
2008-04-06 20:37 . 2008-04-06 22:15 211,893 –a—— C:\Windows\System32\drivers\IsDrv122.sys
2008-04-06 15:43 . 2008-04-06 22:47 d——– C:\Program Files\Sophos
2008-04-06 05:24 . 2008-04-06 22:21 250 –a—— C:\Windows\gmer.ini
2008-04-06 03:43 . 2008-04-06 03:44 d——– C:\Program Files\Java
2008-04-06 03:42 . 2008-04-06 03:42 d——– C:\Program Files\Common Files\Java
2008-04-06 00:45 . 2008-04-07 22:54 d-a—— C:\Users\All Users\TEMP
2008-04-06 00:45 . 2008-04-07 22:54 d-a—— C:\ProgramData\TEMP
2008-04-06 00:45 . 2008-04-06 00:45 d——– C:\Fraps
2008-04-05 13:19 . 2008-04-06 15:12 d——– C:\Users\voomda.com\AppData\Roaming\SUPERAntiSpyware.com
2008-04-05 13:19 . 2008-04-05 13:19 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-04-05 13:19 . 2008-04-05 13:19 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-04-05 02:32 . 2008-04-05 16:17 d——– C:\Program Files\Trend Micro
2008-04-05 01:06 . 2008-04-05 01:06 0 –a—— C:\Windows\System32\SBRC.dat
2008-04-05 01:06 . 2008-04-05 01:06 0 –a—— C:\Windows\System32\SBFC.dat
2008-04-05 00:58 . 2008-04-05 00:58 d——– C:\Users\voomda.com\AppData\Roaming\Sunbelt Software
2008-04-05 00:55 . 2008-04-05 00:55 d——– C:\Program Files\Sunbelt Software
2008-04-04 22:45 . 2008-04-06 22:39 d——– C:\Program Files\Panda Security
2008-04-04 19:56 . 2008-04-04 19:56 d——– C:\Users\voomda.com\AppData\Roaming\DivX
2008-04-04 09:11 . 2008-04-04 09:11 d——– C:\Program Files\DivX
2008-04-04 09:11 . 2008-04-04 09:11 d——– C:\Program Files\Common Files\PX Storage Engine
2008-04-03 16:06 . 2008-04-03 16:06 d——– C:\Users\voomda.com\AppData\Roaming\Talkback
2008-04-03 16:05 . 2008-04-03 16:05 0 –a—— C:\Windows\nsreg.dat
2008-04-03 14:58 . 2008-03-03 14:25 5,702 –ah—– C:\Windows\nod32restoretemdono.reg
2008-04-03 14:58 . 2008-03-03 18:21 568 –ah—– C:\Windows\nod32fixtemdono.reg
2008-04-03 14:56 . 2008-04-03 14:56 d——– C:\Program Files\ESET
2008-04-03 11:52 . 2008-04-03 11:52 d——– C:\Users\All Users\ESET
2008-04-03 11:52 . 2008-04-03 11:52 d——– C:\ProgramData\ESET
2008-04-03 11:45 . 2008-04-03 11:45 1,905 –a—— C:\Windows\diagwrn.xml
2008-04-03 11:45 . 2008-04-03 11:45 1,905 –a—— C:\Windows\diagerr.xml
2008-04-03 09:43 . 2008-04-03 09:44 d——– C:\Users\All Users\Lavasoft
2008-04-03 09:43 . 2008-04-03 09:44 d——– C:\ProgramData\Lavasoft
2008-04-03 09:43 . 2008-04-03 09:43 d——– C:\Program Files\Lavasoft
2008-04-03 09:42 . 2008-04-06 15:11 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-04-03 08:49 . 2008-04-08 18:54 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-04-03 08:49 . 2008-04-08 18:54 d——– C:\ProgramData\Spybot - Search & Destroy
2008-04-03 08:49 . 2008-04-08 18:55 d——– C:\Program Files\Spybot - Search & Destroy
2008-04-02 21:46 . 2007-03-23 18:51 22,816 –a—— C:\Windows\System32\drivers\npusb.sys
2008-04-02 21:36 . 2008-04-02 21:46 d——– C:\Program Files\Naturalpoint
2008-04-02 21:36 . 2004-04-13 20:34 146,628 –a—— C:\Windows\System32\drivers\npusbrnm.sys
2008-04-02 21:36 . 2001-12-10 15:41 8,069 –a—— C:\Windows\System32\NPKBD.VXD
2008-04-02 21:36 . 2000-10-25 15:25 4,883 –a—— C:\Windows\System32\EYECTRL.VXD
2008-04-02 20:45 . 2007-05-11 05:07 782,336 -ra—— C:\Windows\System32\tmpE234.tmp
2008-04-02 20:45 . 2007-05-11 05:07 782,336 -ra—— C:\Windows\System32\tmpE12A.tmp
2008-04-02 20:35 . 2008-04-06 22:49 d——– C:\Program Files\Atari
2008-03-29 17:21 . 2008-03-29 17:21 d——– C:\Program Files\OpenAL
2008-03-29 17:21 . 2006-12-14 14:47 782,336 -ra—— C:\Windows\System32\tmpD13.tmp
2008-03-29 17:21 . 2008-04-02 20:45 409,600 –a—— C:\Windows\System32\wrap_oal.dll
2008-03-29 17:21 . 2008-04-02 20:45 114,688 –a—— C:\Windows\System32\OpenAL32.dll
2008-03-28 00:44 . 2007-07-26 21:07 621,056 –a—— C:\Windows\System32\drivers\dxgkrnl.sys
2008-03-28 00:44 . 2007-07-26 22:17 36,864 –a—— C:\Windows\System32\cdd.dll
2008-03-28 00:12 . 2008-03-28 00:12 d——– C:\Program Files\EA GAMES
2008-03-19 20:45 . 2008-03-19 20:45 d——– C:\Users\All Users\Media Center Programs
2008-03-19 20:45 . 2008-03-19 20:45 d——– C:\ProgramData\Media Center Programs
2008-03-12 19:35 . 2008-03-12 19:35 d——– C:\Users\voomda.com\AppData\Roaming\teamspeak2
2008-03-12 19:35 . 2008-03-12 19:35 d——– C:\Program Files\Teamspeak2_RC2
2008-03-12 19:35 . 2008-03-12 19:35 34,064 –a—— C:\Windows\System32\lhacm.acm
2008-03-12 10:43 . 2007-12-16 18:50 1,060,920 –a—— C:\Windows\System32\drivers\ntfs.sys
2008-03-12 10:43 . 2007-12-16 05:56 41,984 –a—— C:\Windows\System32\drivers\monitor.sys
2008-03-08 09:15 . 2008-04-07 14:15 d——– C:\Program Files\Lx_cats
2008-03-08 09:13 . 2008-03-08 09:18 d——– C:\Program Files\Lexmark 810 Series
2008-03-08 09:13 . 2007-01-30 11:35 274,432 –a—— C:\Windows\System32\lxbsinst.dll
2008-03-08 09:13 . 2008-03-08 09:18 9,957 –a—— C:\Windows\System32\LexFiles.ulf
2008-03-08 01:26 . 2008-03-08 01:26 d——– C:\Users\voomda.com\AppData\Roaming\CyberLink
2008-03-08 01:26 . 2008-03-08 01:26 d——– C:\Users\Public\CyberLink
2008-03-08 01:25 . 2008-03-08 01:26 d——– C:\Users\All Users\CyberLink
2008-03-08 01:25 . 2008-03-08 01:26 d——– C:\ProgramData\CyberLink
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-08 23:04 47,104 —-a-w C:\Windows\System32\rpcnet.dll
2008-04-08 23:04 17,408 —-a-w C:\Windows\System32\rpcnetp.exe
2008-04-08 23:04 ——— d—–w C:\Users\voomda.com\AppData\Roaming\Spare Backup
2008-04-08 05:24 28,314 —-a-w C:\Users\voomda.com\AppData\Roaming\nvModes.dat
2008-04-07 18:11 17,408 —-a-w C:\Windows\System32\rpcnetp.dll
2008-04-06 08:03 ——— d—–w C:\Users\voomda.com\AppData\Roaming\Azureus
2008-04-05 18:08 ——— d—–w C:\Program Files\Google
2008-04-03 01:46 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-04-01 22:49 22,328 —-a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-04-01 22:48 107,832 —-a-w C:\Windows\System32\PnkBstrB.exe
2008-03-25 19:31 ——— d—–w C:\Users\voomda.com\AppData\Roaming\gtk-2.0
2008-03-20 00:17 ——— d—–w C:\Program Files\Ubisoft
2008-03-13 22:31 ——— d—–w C:\Program Files\Windows Mail
2008-03-13 14:21 ——— d—–w C:\ProgramData\Microsoft Help
2008-03-08 23:24 ——— d—–w C:\Program Files\Azureus
2008-03-07 08:05 ——— d—–w C:\ProgramData\WildTangent
2008-03-03 15:34 ——— d—–w C:\Users\voomda.com\AppData\Roaming\Intuit
2008-03-03 15:32 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-03-03 15:31 ——— d—–w C:\ProgramData\Intuit
2008-03-03 15:31 ——— d—–w C:\Program Files\Common Files\Intuit
2008-03-03 15:30 ——— d—–w C:\Program Files\TurboTax
2008-03-01 21:27 ——— d—–w C:\Program Files\e-Sword
2008-02-27 22:32 ——— d—–w C:\Program Files\InterVideo
2008-02-27 19:59 ——— d—–w C:\ProgramData\Azureus
2008-02-27 19:07 ——— d—–w C:\Users\voomda.com\AppData\Roaming\InterVideo
2008-02-27 19:06 ——— d—–w C:\ProgramData\Apple Computer
2008-02-27 19:05 ——— d—–w C:\ProgramData\InstallShield
2008-02-27 19:05 ——— d—–w C:\Program Files\Common Files\Ulead
2008-02-27 19:03 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-02-27 18:08 ——— d—–w C:\Users\voomda.com\AppData\Roaming\Media Player Classic
2008-02-23 18:28 ——— d—–w C:\Users\voomda.com\AppData\Roaming\eBookPro6
2008-02-21 09:53 ——— d—–w C:\Users\voomda.com\AppData\Roaming\SmartDraw
2008-02-21 09:37 ——— d—–w C:\Users\voomda.com\AppData\Roaming\Palo Alto Software
2008-02-21 09:35 ——— d—–w C:\ProgramData\Palo Alto Software
2008-02-21 09:35 ——— d—–w C:\Program Files\Palo Alto Software
2008-02-21 09:35 ——— d—–w C:\Program Files\Common Files\Palo Alto Software
2008-02-21 09:32 ——— d—–w C:\ProgramData\PAS
2008-02-21 09:30 ——— d—–w C:\Program Files\Dia
2008-02-21 09:27 ——— d—–w C:\Program Files\SmartDraw 7
2008-02-21 06:13 ——— d—–w C:\Users\voomda.com\AppData\Roaming\Roxio
2008-02-21 06:13 ——— d—–w C:\ProgramData\Napster
2008-02-21 02:05 9,464 ——w C:\Windows\system32\drivers\cdralw2k.sys
2008-02-21 02:05 524,288 —-a-w C:\Windows\System32\DivXsm.exe
2008-02-21 02:05 3,596,288 —-a-w C:\Windows\System32\qt-dx331.dll
2008-02-21 02:05 200,704 —-a-w C:\Windows\System32\ssldivx.dll
2008-02-21 02:05 1,044,480 —-a-w C:\Windows\System32\libdivx.dll
2008-02-21 02:04 823,296 —-a-w C:\Windows\System32\divx_xx0c.dll
2008-02-21 02:04 823,296 —-a-w C:\Windows\System32\divx_xx07.dll
2008-02-21 02:04 81,920 —-a-w C:\Windows\System32\dpl100.dll
2008-02-21 02:04 802,816 —-a-w C:\Windows\System32\divx_xx11.dll
2008-02-21 02:04 682,496 —-a-w C:\Windows\System32\DivX.dll
2008-02-21 02:04 593,920 —-a-w C:\Windows\System32\dpuGUI11.dll
2008-02-21 02:04 57,344 —-a-w C:\Windows\System32\dpv11.dll
2008-02-21 02:04 53,248 —-a-w C:\Windows\System32\dpuGUI10.dll
2008-02-21 02:04 344,064 —-a-w C:\Windows\System32\dpus11.dll
2008-02-21 02:04 294,912 —-a-w C:\Windows\System32\dpu11.dll
2008-02-21 02:04 294,912 —-a-w C:\Windows\System32\dpu10.dll
2008-02-21 02:04 196,608 —-a-w C:\Windows\System32\dtu100.dll
2008-02-21 02:03 156,992 —-a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 —-a-w C:\Windows\System32\DivXWMPExtType.dll
2008-02-20 15:11 33,800 —-a-w C:\Windows\system32\drivers\epfwtdir.sys
2008-02-20 15:02 29,704 —-a-w C:\Windows\system32\drivers\easdrv.sys
2008-02-20 15:01 39,944 —-a-w C:\Windows\system32\drivers\eamon.sys
2008-02-19 18:20 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-19 04:54 0 —-a-w C:\Users\voomda.com\AppData\Roaming\wklnhst.dat
2008-02-19 04:49 ——— d—–w C:\Users\voomda.com\AppData\Roaming\WildTangent
2008-02-19 02:27 108,144 —-a-w C:\Windows\System32\CmdLineExt.dll
2008-02-19 02:27 ——— d–h–r C:\Users\voomda.com\AppData\Roaming\SecuROM
2008-02-19 02:16 ——— d—–w C:\Users\voomda.com\AppData\Roaming\InstallShield
2008-02-18 22:43 66,872 —-a-w C:\Windows\System32\PnkBstrA.exe
2008-02-18 16:16 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-18 16:13 ——— d—–w C:\ProgramData\Symantec
2008-02-18 06:45 ——— d—–w C:\Program Files\MSBuild
2008-02-18 06:43 ——— d—–w C:\Program Files\Microsoft Visual Studio 8
2008-02-18 06:31 ——— d—–w C:\Program Files\DAEMON Tools Lite
2008-02-18 06:28 716,272 —-a-w C:\Windows\system32\drivers\sptd.sys
2008-02-18 06:27 ——— d—–w C:\Users\voomda.com\AppData\Roaming\DAEMON Tools
2008-02-18 04:52 22,328 —-a-w C:\Users\voomda.com\AppData\Roaming\PnkBstrK.sys
2008-02-18 04:34 ——— d—–w C:\Program Files\Activision
2008-02-18 01:29 ——— d—–w C:\Users\voomda.com\AppData\Roaming\SampleView
2008-02-18 01:00 ——— d—–w C:\Program Files\Windows Sidebar
2008-02-18 00:56 943,800 —-a-w C:\Windows\System32\winload.exe
2008-02-18 00:54 45,112 —-a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-18 00:54 3,504,696 —-a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-18 00:54 3,470,392 —-a-w C:\Windows\System32\ntoskrnl.exe
2008-02-18 00:54 211,000 —-a-w C:\Windows\system32\drivers\volsnap.sys
2008-02-18 00:54 21,560 —-a-w C:\Windows\system32\drivers\atapi.sys
2008-02-18 00:54 17,464 —-a-w C:\Windows\system32\drivers\intelide.sys
2008-02-18 00:54 154,624 —-a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-18 00:54 109,624 —-a-w C:\Windows\system32\drivers\ataport.sys
2008-02-18 00:52 84,992 —-a-w C:\Windows\system32\drivers\srvnet.sys
2008-02-18 00:52 58,368 —-a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-02-18 00:52 130,048 —-a-w C:\Windows\system32\drivers\srv2.sys
2008-02-18 00:52 11,776 —-a-w C:\Windows\System32\sbunattend.exe
2008-02-18 00:52 101,888 —-a-w C:\Windows\system32\drivers\mrxsmb.sys
2008-02-18 00:49 824,832 —-a-w C:\Windows\System32\wininet.dll
2008-02-18 00:49 56,320 —-a-w C:\Windows\System32\iesetup.dll
2008-02-18 00:49 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-18 00:49 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2008-02-18 00:48 1,244,672 —-a-w C:\Windows\System32\mcmde.dll
.
((((((((((((((((((((((((((((( snapshot@2008-04-08_18.19.26.96 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-08 14:55:14 67,584 –s-a-w C:\Windows\bootstat.dat
+ 2008-04-08 23:03:46 67,584 –s-a-w C:\Windows\bootstat.dat
- 2008-04-08 14:56:51 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-04-08 23:05:14 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-04-08 14:56:45 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-04-08 23:05:19 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-04-08 15:01:58 104,868 —-a-w C:\Windows\System32\perfc009.dat
+ 2008-04-08 23:11:21 104,868 —-a-w C:\Windows\System32\perfc009.dat
- 2008-04-08 15:01:58 621,552 —-a-w C:\Windows\System32\perfh009.dat
+ 2008-04-08 23:11:21 621,552 —-a-w C:\Windows\System32\perfh009.dat
- 2008-04-08 14:57:09 9,350 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2857160768-3149739328-402376366-1000_UserData.bin
+ 2008-04-08 23:05:41 9,350 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2857160768-3149739328-402376366-1000_UserData.bin
- 2008-04-08 14:57:09 82,174 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-08 23:05:41 82,360 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-04-08 14:57:08 40,974 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-08 23:05:40 41,186 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 08:35 125440]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-02-13 19:09 486856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 16:54 5674352]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 08:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-14 06:03 1006264]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-11-14 23:03 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-11-14 23:03 8534560]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-11-14 23:03 81920]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 17:37 174872]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-15 09:50 857648]
"Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Gateway\traybar.exe" [2007-09-13 18:09 638976]
"Spare Backup"="C:\Program Files\Spare Backup\SpareBackup.exe" [2007-09-13 20:22 5252936]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2006-09-06 16:12 323216]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 08:00 33648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [ ]
"LXBSCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\LXBStime.dll" [2007-02-22 06:52 73728]
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray.exe" [2007-11-09 18:22 409600]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 11:06 1443072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B1AB1ED7-7DD6-4AAA-94C3-23E9C1064E8D}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6FCDA6AF-DDBF-44B5-AA47-3C69429EAE67}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{2CF8046A-3290-449E-8FD2-7F8850C77D6C}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{F30240B8-FFB2-4B77-B6B9-4540CB9699A1}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{3FFA0A4A-5583-4E17-A2FC-6DD51202C2C7}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{3F5436E6-3656-46A6-81C6-C5487C3AA629}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{14E20282-E05B-476E-A965-3D28D123F61C}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{5ABA13B7-0EE3-482E-8852-D7DA00D118C3}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{3D741923-FC7B-4F51-B567-3ECB98767715}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{15F4DC9F-1F96-4863-B2A9-476A3590A180}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{AA6E2695-52C2-4436-929F-ABE6A0C5353F}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E6E58080-24B7-4D93-A260-3413CFFCAFB1}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{1FFAE127-6613-47B9-A94E-F0510B0C94DD}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{EF1F73F5-C6E5-41DB-AE00-23D8F7FA6CA1}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"TCP Query User{825E8FC9-F8B4-4D9C-951E-477BCA75199E}C:\\program files\\intervideo\\dvd8\\windvd.exe"= UDP:C:\program files\intervideo\dvd8\windvd.exe:WinDVD
"UDP Query User{006C996F-5E4A-437B-88CE-DBE56F2157C5}C:\\program files\\intervideo\\dvd8\\windvd.exe"= TCP:C:\program files\intervideo\dvd8\windvd.exe:WinDVD
"TCP Query User{A7B2E443-8D1B-4B96-9219-CF66BD2A149C}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{0C5150CD-D19F-41F6-862D-37D3588EB25C}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{4E696420-1004-4DFA-8900-DDF29FAFEE03}"= Disabled:UDP:135:TCP Port 135
"{5221B3E4-0443-4CFC-937D-917839ECFB9D}"= Disabled:UDP:5000:TCP Port 5000
"{3000A89A-F6EC-4D17-A7D4-6AEE90F8D706}"= Disabled:UDP:5001:TCP Port 5001
"{BBFB86B5-F131-49E0-BBC4-F74C3074818A}"= Disabled:UDP:5002:TCP Port 5002
"{E6958E0B-717A-415F-B05C-CBA8EBAFCE72}"= Disabled:UDP:5003:TCP Port 5003
"{0DDC367A-9AB9-4DAB-A2A5-97C49AC5C3C1}"= Disabled:UDP:5004:TCP Port 5004
"{746FFAB0-43AC-4147-A621-E04E7EB4995E}"= Disabled:UDP:5005:TCP Port 5005
"{6B87D3D4-E899-4931-90C7-CF95A3D39931}"= Disabled:UDP:5006:TCP Port 5006
"{2B68B0E8-F833-413B-91CD-69F12F8657E3}"= Disabled:UDP:5007:TCP Port 5007
"{2999AB10-AC28-4517-A9C4-921361A34BEE}"= Disabled:UDP:5008:TCP Port 5008
"{0216AB8F-3EA8-4621-939B-2CCCDC8CEC63}"= Disabled:UDP:5009:TCP Port 5009
"{0E923C90-771C-4DE9-8051-797A1209BC4D}"= Disabled:UDP:5010:TCP Port 5010
"{30125468-99FD-419B-97ED-5202E062557E}"= Disabled:UDP:5011:TCP Port 5011
"{3644EBB3-6A1B-4C4E-A425-4BFCC3489442}"= Disabled:UDP:5012:TCP Port 5012
"{12AD5A0C-2439-4F04-A76F-C2C939EFDD1C}"= Disabled:UDP:5013:TCP Port 5013
"{B3B5A946-7BBF-4552-AEE4-7A58F01A11C4}"= Disabled:UDP:5014:TCP Port 5014
"{EAC42730-EFB9-44BC-BD07-8E84F2C66F48}"= Disabled:UDP:5015:TCP Port 5015
"{0F5BE12E-D3AD-4C1C-85C0-EFE901C0DE71}"= Disabled:UDP:5016:TCP Port 5016
"{E7FAD7BD-A68C-4979-B628-9509B90C6D7C}"= Disabled:UDP:5017:TCP Port 5017
"{0A3E9046-48B0-48BB-AF0C-5BC882257817}"= Disabled:UDP:5018:TCP Port 5018
"{AA4B9C4D-5E95-4D50-A2B5-AADACD5FBD50}"= Disabled:UDP:5019:TCP Port 5019
"{80176D42-C8BA-4DE0-B976-BBF7C5E48A5B}"= Disabled:UDP:5020:TCP Port 5020
"{C21AA7AE-6891-42A2-B8DE-B20E885A135A}"= UDP:C:\Windows\System32\lxbscoms.exe:810 Series Server
"{FF1E81D7-014E-456E-9AD0-64CEBB01A17D}"= TCP:C:\Windows\System32\lxbscoms.exe:810 Series Server
"{6A5DBE24-3DAA-4A75-A152-6CBD249319A9}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbspswx.exe:810 Series Printer Status
"{C92CC603-6CDA-4800-974D-2224DEC00329}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbspswx.exe:810 Series Printer Status
"{F7B38071-FA87-45F7-964B-B2E508578EBE}"= UDP:C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:TurboTax
"{93B0095C-FD07-404B-B85F-B2E1CB49126D}"= TCP:C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:TurboTax
"{0C0497EE-4D4C-4155-8B83-8036CCFEB8E0}"= UDP:C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:TurboTax Update Manager
"{6EC9D886-0F88-48A1-BDA2-2B2D5E4749FD}"= TCP:C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:TurboTax Update Manager
"TCP Query User{3783D9D0-F84D-4413-A56A-BB6454AB7F7D}C:\\program files\\ubisoft\\chessmaster grandmaster edition\\game.exe"= UDP:C:\program files\ubisoft\chessmaster grandmaster edition\game.exe:Chessmaster: Grandmaster Edition
"UDP Query User{0239FCE0-893A-4A02-BCAC-0331556C1AFE}C:\\program files\\ubisoft\\chessmaster grandmaster edition\\game.exe"= TCP:C:\program files\ubisoft\chessmaster grandmaster edition\game.exe:Chessmaster: Grandmaster Edition
"{702BBB74-366D-4350-ADA2-64D4B502E238}"= UDP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{9EAF3F40-D09A-4760-9F90-DC793DBE5EE4}"= TCP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{6F549E71-1281-4966-8C1A-E8DCAF9BE4C4}"= UDP:C:\Program Files\Atari\ArmA\arma.exe:ArmA
"{893AFC47-E734-40F0-B14F-2DD4642440CA}"= TCP:C:\Program Files\Atari\ArmA\arma.exe:ArmA
"{6424185A-5A15-4909-A4BA-C693D6E1D3A4}"= UDP:C:\Program Files\Atari\ArmA\arma_server.exe:ArmA_Server
"{4E9E993C-2677-453D-B3CD-200EABBF5B5B}"= TCP:C:\Program Files\Atari\ArmA\arma_server.exe:ArmA_Server
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 Si3531;SiI-3531 SATA Controller;C:\Windows\system32\DRIVERS\Si3531.sys [2007-06-01 14:29]
R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-02-20 11:11]
R3 RTSTOR;USB Mass Storage Device;C:\Windows\system32\drivers\RTSTOR.SYS [2008-01-03 13:35]
R3 UVCFTR;UVCFTR;C:\Windows\system32\Drivers\UVCFTR_S.SYS [2007-05-23 21:37]
S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\Windows\system32\regedt32.exe [2006-11-02 05:45]
S3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2007-03-29 15:46]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 02:20]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-02-27 02:20]
S3 DGYU;DGYU;C:\Users\voomda.com\AppData\Local\Temp\DGYU.exe []
S3 GameConsoleService;GameConsoleService;"C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe" [2008-01-29 13:09]
S3 KHQCC;KHQCC;C:\Users\voomda.com\AppData\Local\Temp\KHQCC.exe []
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 03:30]
S3 NPUSB;NPUSB;C:\Windows\system32\DRIVERS\npusb.sys [2007-03-23 18:51]
S3 SUZN;SUZN;C:\Users\voomda.com\AppData\Local\Temp\SUZN.exe []
S4 BIENUWXY;BIENUWXY;C:\Users\voomda.com\AppData\Local\Temp\BIENUWXY.exe []
S4 BZTTQN;BZTTQN;C:\Users\voomda.com\AppData\Local\Temp\BZTTQN.exe []
S4 OJERVMTKPKBR;OJERVMTKPKBR;C:\Users\voomda.com\AppData\Local\Temp\OJERVMTKPKBR.exe []
S4 SOOITY;SOOITY;C:\Users\voomda.com\AppData\Local\Temp\SOOITY.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9bf68b52-ede7-11dc-a59c-00e0b8dbe71c}]
\shell\AutoRun\command - H:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{daa01358-ddea-11dc-99ca-00e0b8dbe71c}]
\shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{db779014-aa21-11dc-bd19-806e6f6e6963}]
\shell\AutoRun\command - E:\autorun.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-08 23:04:19 C:\Windows\Tasks\SDMsgUpdate (SD).job"
- C:\PROGRA~1\SMARTD~1\Messages\SDNotify.exeQ-PSD -V750 -SSDU.ini -A -Mhttp://www.smartdraw.com/msgs/messagecheck.aspx -D0 -T
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-08 19:12:32
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBSCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-08 19:13:09
ComboFix-quarantined-files.txt 2008-04-08 23:13:06
ComboFix2.txt 2008-04-08 22:47:27
ComboFix3.txt 2008-04-08 22:19:45
Pre-Run: 158,451,200,000 bytes free
Post-Run: 158,423,810,048 bytes free
.
2008-04-06 18:54:59 — E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:13:55 PM, on 4/8/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Camera Assistant Software for Gateway\traybar.exe
C:\Program Files\Spare Backup\SpareBackup.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Camera Assistant Software for Gateway\CEC_MAIN.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gateway.com/g/startpage.html?Ch…&M;=P-6831FX
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Gateway\traybar.exe"
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: DGYU - Unknown owner - C:\Users\voomda.com\AppData\Local\Temp\DGYU.exe (file missing)
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KHQCC - Unknown owner - C:\Users\voomda.com\AppData\Local\Temp\KHQCC.exe (file missing)
O23 - Service: lxbs_device - - C:\Windows\system32\lxbscoms.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\Windows\system32\rpcnet.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: SUZN - Unknown owner - C:\Users\voomda.com\AppData\Local\Temp\SUZN.exe (file missing)
–
End of file - 7648 bytes