Deleted Member
Topic Starter
I keep getting pop-ups on my system. I have ran antivirus, spybot, adaware. Rebooted to safemode and did the same thing. Ran combofix, but alas!! My efforts are in vain.
Also, I made a post earlier, but forgot to post the combofix log file as well and made that as a seperate post…then finally read that I shouldn't reply to my own post hah (sorry!)
So anyone who wants to help, I appreciate all your efforts.
Here is my log file for Hijackthis and Combofix. If anyone has any insight in this, please let me know.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:35:47 AM, on 2009-01-02
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Kaos Inc\System Utilities\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\astsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SURADOCRMOFFLINE\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\java.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\Kaos Inc\QK\RocketDock\RocketDock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {a58ef46e-0289-4eca-b0c0-6767866c58dd} - C:\WINDOWS\system32\tadibiha.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [\\TIMBROWN\EPSON Stylus Photo R220 Series shared] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P48 "\\TIMBROWN\EPSON Stylus Photo R220 Series shared" /O20 "\\timbrown\timbepson" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [\\PENNY\EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P38 "\\PENNY\EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [\\GORDONSLIVER\EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P45 "\\GORDONSLIVER\EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [\\RICH\EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P37 "\\RICH\EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [\\MAKAILA\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P40 "\\MAKAILA\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [masiyajufi] Rundll32.exe "C:\WINDOWS\system32\lenidure.dll",s
O4 - HKLM\..\Run: [CPMc7a45b90] Rundll32.exe "c:\windows\system32\jiwofehu.dll",a
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\Kaos Inc\QK\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - http://tank/connectcomputer/nshelp.dll
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Gemvision.local
O17 - HKLM\Software\..\Telephony: DomainName = Gemvision.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Gemvision.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Gemvision.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = Gemvision.local
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\mitapuwi.dll c:\windows\system32\ c:\windows\system32\yegehija.dll c:\windows\system32\jiwofehu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jiwofehu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jiwofehu.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Kaos Inc\System Utilities\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\WINDOWS\SYSTEM32\astsrv.exe
O23 - Service: ASTSRV - Nalpeiron Ltd. - c:\Windows\System32\AstSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.30\bin\mysqld.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/djohnson/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg
–
End of file - 14243 bytes
————-Combo Fix Log
ComboFix 08-12-30.02 - DJohnson 2008-12-31 19:38:50.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1534.805 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Kaos Inc\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\oraburos.ini
.
((((((((((((((((((((((((( Files Created from 2008-12-01 to 2009-01-01 )))))))))))))))))))))))))))))))
.
2008-12-31 03:22 . 2008-12-31 03:54 d——– C:\GMOD10
2008-12-31 01:16 . 2008-12-31 01:16 d——– c:\program files\RADVideo
2008-12-30 18:14 . 2008-12-31 15:12 d——– C:\HammerAutosave
2008-12-30 16:15 . 2008-12-30 16:15 d——– c:\program files\Trend Micro
2008-12-29 10:04 . 2008-12-29 10:04 d——– c:\program files\Microsoft Visual Studio 8
2008-12-27 19:59 . 2008-12-27 20:13 d——– c:\program files\Spybot - Search & Destroy
2008-12-27 12:29 . 2008-12-27 12:29 1,094,368 –a—— c:\windows\system32\rn.tmp
2008-12-27 12:20 . 2008-12-27 12:20 45,056 –a—— c:\windows\system32\efcBsPhI.dll
2008-12-26 01:41 . 2008-12-26 01:42 d——– C:\wamp
2008-12-25 15:19 . 2008-12-25 15:19 d——– c:\program files\GoldWave
2008-12-24 00:42 . 2008-12-24 00:42 d——– c:\windows\system32\Adobe
2008-12-23 15:16 . 2008-12-23 15:16 131,072 –a—— c:\windows\system32\SpoonUninstall.exe
2008-12-22 06:12 . 2008-12-22 06:12 d——– c:\program files\MySQL
2008-12-21 00:49 . 2008-12-21 00:49 d——– C:\Garmin
2008-12-21 00:07 . 2008-12-21 00:07 d——– c:\documents and settings\djohnson\Application Data\Windows Search
2008-12-19 18:00 . 2008-12-19 18:00 d—s—- c:\program files\HLSW
2008-12-19 18:00 . 2008-12-31 15:15 d——– c:\documents and settings\djohnson\Application Data\HLSW
2008-12-17 08:55 . 2008-12-17 08:55 d——– c:\windows\system32\GroupPolicy
2008-12-17 08:55 . 2008-12-23 19:11 d——– c:\program files\Windows Desktop Search
2008-12-16 13:00 . 2008-12-16 13:00 d——– c:\documents and settings\LocalService\Application Data\iolo
2008-12-16 11:02 . 2008-12-16 11:02 406 –a—— c:\windows\system32\ioloBootDefrag.cfg
2008-12-15 11:30 . 2008-12-15 11:30 268 –ah—– C:\sqmdata09.sqm
2008-12-15 11:30 . 2008-12-15 11:30 244 –ah—– C:\sqmnoopt09.sqm
2008-12-05 14:01 . 2008-12-05 14:32 d——– c:\documents and settings\djohnson\Application Data\Notepad++
2008-12-05 13:26 . 2008-12-06 00:41 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-05 13:25 . 2008-12-06 03:02 d——– C:\Fraps
2008-12-04 17:35 . 2008-12-04 17:35 d——– c:\documents and settings\All Users\Application Data\CyberLink
2008-12-01 17:36 . 2008-12-01 17:36 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-01 01:47 ——— d—–w c:\program files\Symantec AntiVirus
2009-01-01 01:35 ——— d—–w c:\program files\Steam
2009-01-01 01:18 ——— d—–w c:\documents and settings\djohnson\Application Data\.purple
2008-12-31 09:30 ——— d—–w c:\documents and settings\djohnson\Application Data\uTorrent
2008-12-31 00:10 ——— d—–w c:\program files\Matrix60
2008-12-29 16:05 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-28 21:11 ——— d—–w c:\program files\Kaos Inc
2008-12-28 21:08 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-28 21:08 ——— d—–w c:\program files\Dell
2008-12-28 21:07 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2008-12-28 21:05 ——— d—–w c:\program files\Norton Ghost
2008-12-28 21:05 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-12-28 06:28 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-27 04:48 ——— d—–w c:\documents and settings\djohnson\Application Data\U3
2008-12-24 18:33 ——— d—–w c:\program files\Common Files\Adobe
2008-12-23 21:57 ——— d—–w c:\documents and settings\All Users\Application Data\iolo
2008-12-19 05:24 ——— d—–w c:\documents and settings\djohnson\Application Data\Skype
2008-12-19 02:09 ——— d—–w c:\documents and settings\djohnson\Application Data\skypePM
2008-12-16 20:00 ——— d—–w c:\documents and settings\djohnson\Application Data\iolo
2008-12-16 19:08 ——— d—–w c:\documents and settings\Doug Johnson.D6D4W4H1\Application Data\uTorrent
2008-12-05 22:09 960 —-a-w c:\windows\system32\drivers\sthdae.log
2008-11-29 21:02 136,720 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-28 06:53 ——— d—–w c:\documents and settings\djohnson\Application Data\Palo Alto Software
2008-11-28 06:51 ——— d—–w c:\program files\Common Files\Palo Alto Software
2008-11-28 06:51 ——— d—–w c:\program files\Common Files\Intuit
2008-11-28 06:51 ——— d—–w c:\documents and settings\All Users\Application Data\Palo Alto Software
2008-11-28 06:48 ——— d—–w c:\documents and settings\All Users\Application Data\PAS
2008-11-24 17:40 ——— d—–w c:\documents and settings\djohnson\Application Data\Ventrilo
2008-11-24 17:39 ——— d—–w c:\program files\Ventrilo
2008-11-24 17:39 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-11-11 23:20 ——— d—–w c:\program files\Microsoft Silverlight
2008-11-09 23:40 ——— d—–w c:\program files\DVD Shrink
2008-11-09 23:40 ——— d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-11-06 15:53 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2008-11-03 02:10 ——— d—–w c:\documents and settings\djohnson\Application Data\gtk-2.0
2008-11-01 01:47 ——— d—–w c:\documents and settings\All Users\Application Data\Adobe Systems
2008-11-01 01:43 ——— d—–w c:\program files\Common Files\Adobe Systems Shared
2008-10-23 17:41 22,328 —-a-w c:\documents and settings\djohnson\Application Data\PnkBstrK.sys
2008-10-22 18:38 155,995 —-a-w c:\windows\java\Packages\6C35BHB9.ZIP
1601-01-01 00:12 61,118 –sha-w c:\windows\system32\mikadazo.dll
1601-01-01 00:12 61,118 –sha-w c:\windows\system32\puwasoyo.dll
1601-01-01 00:12 61,118 –sha-w c:\windows\system32\tadibiha.dll
2008-09-07 18:51 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090720080908\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-12-30_17.07.47.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-30 20:46:20 155,322 —-a-w c:\windows\system32\nvModes.dat
+ 2008-12-31 22:42:43 155,282 —-a-w c:\windows\system32\nvModes.dat
- 2008-12-23 21:58:15 81,530 —-a-w c:\windows\system32\perfc009.dat
+ 2008-12-30 23:52:26 81,530 —-a-w c:\windows\system32\perfc009.dat
- 2008-12-23 21:58:15 465,144 —-a-w c:\windows\system32\perfh009.dat
+ 2008-12-30 23:52:26 465,144 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-01 01:00:33 83,557 –sha-w c:\windows\system32\sorubaro.dll
+ 2009-01-01 01:47:04 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_4d8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a58ef46e-0289-4eca-b0c0-6767866c58dd}]
61118 –ahs—- c:\windows\system32\tadibiha.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\Kaos Inc\QK\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-06-15 124656]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-26 1024000]
"\\TIMBROWN\EPSON Stylus Photo R220 Series shared"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE" [2005-03-09 98304]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-06-02 2220032]
"\\PENNY\EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-12-05 405504]
"\\GORDONSLIVER\EPSON Stylus Photo R220 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE" [2005-03-09 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-06 8466432]
"\\RICH\EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"\\MAKAILA\EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-08 99840]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-13 169984]
"nwiz"="nwiz.exe" [2007-08-06 c:\windows\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2007-08-06 c:\windows\system32\nvmctray.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=c:\windows\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Icatch(VI) SnapDetect.lnk]
backup=c:\windows\pss\Icatch(VI) SnapDetect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Palo Alto Software Update Manager 9.0.lnk]
backup=c:\windows\pss\Palo Alto Software Update Manager 9.0.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
backup=c:\windows\pss\Service Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Surado CRM Always-In-Sync .lnk]
backup=c:\windows\pss\Surado CRM Always-In-Sync .lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^djohnson^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\djohnson\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
–a—— 2002-09-10 20:26 368706 c:\program files\BroadJump\Client Foundation\CFD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c497680c]
–ahs—- 2008-12-31 19:00 83557 c:\windows\system32\sorubaro.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 18:12 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
–a—— 2008-08-13 23:08 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
–a—— 2006-10-26 23:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2006-11-13 12:39 1289000 c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-12-13 18:10 1688872 c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 11:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
–a–c— 2007-12-03 13:21 2213160 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a–c— 2007-03-01 13:57 153136 c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
——— 2008-02-26 09:57 128296 c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecureUpgrade]
–a–c— 2007-09-14 09:53 218424 c:\program files\Wave Systems Corp\SecureUpgrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2008-09-29 16:57 21755688 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WavXMgr]
–a–c— 2007-09-10 08:55 92160 c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
–a–c— 2007-08-06 15:27 67584 c:\windows\system32\nvhotkey.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-08-06 15:28 1626112 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Kaos Inc\\Internet Utilities\\Utorrent\\uTorrent.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\NWN2\\nwn2main.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\NWN2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\NWN2\\nwupdate.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\NWN2\\nwn2server.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Kaos Inc\\Internet Utilities\\CuteFTP 8 Professional\\ftpte.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\Bionic Commando Rearmed\\bcr.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 LinksysUpdater;Linksys Updater;"c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe" -s "c:\program files\Linksys\Linksys Updater\conf\wrapper.conf" [2008-01-15 204800]
R2 MSSQL$SURADOCRMOFFLINE;MSSQL$SURADOCRMOFFLINE;c:\program files\Microsoft SQL Server\MSSQL$SURADOCRMOFFLINE\Binn\sqlservr.exe -sSURADOCRMOFFLINE []
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe /Processid:{8277F0D9-812F-470B-BFC1-A6D96FBA774A} [2004-08-11 5120]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe /Processid:{BDFEFE06-0F3F-44F4-984D-3BF2A1CA8D75} [2004-08-11 5120]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-12 99376]
S2 ASTSRV;ASTSRV;c:\windows\System32\AstSrv.exe [2008-08-27 57344]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-09-26 33752]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2006-06-15 115952]
S3 SQLAgent$SURADOCRMOFFLINE;SQLAgent$SURADOCRMOFFLINE;c:\program files\Microsoft SQL Server\MSSQL$SURADOCRMOFFLINE\Binn\sqlagent.EXE -i SURADOCRMOFFLINE []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
2009-01-01 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe []
2008-12-25 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe []
2009-01-01 c:\windows\Tasks\zdgsywya.job
- c:\windows\system32\rundll32.exe [2008-04-13 18:12]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-CPMc7a45b90 - c:\windows\system32\yodibapi.dll
MSConfigStartUp-masiyajufi - c:\windows\system32\lenidure.dll
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\djohnson\Application Data\Mozilla\Firefox\Profiles\j1ylc7cx.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\djohnson\Application Data\Mozilla\Firefox\Profiles\j1ylc7cx.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\nppdf32.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npptkver.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npptkver.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-31 19:47:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\windows\system32\oraburos.ini 1262075 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-2835384908-1013129077-2624498441-4518
@Allowed: (Read) (Everyone)
@Allowed: (Read) (Users)
@Allowed: (Read) (PowerUsers)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (S-1-5-21-2835384908-1013129077-2624498441-4518)
"*"=dword:00000004
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_USERS\S-1-5-21-2835384908-1013129077-2624498441-4518\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-2835384908-1013129077-2624498441-4518
@Allowed: (Full) (S-1-5-21-2835384908-1013129077-2624498441-4518)
@Allowed: (Full) (S-1-5-21-2835384908-1013129077-2624498441-4518)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
"*"=dword:00000004
[HKEY_USERS\S-1-5-21-2835384908-1013129077-2624498441-4518\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_USERS\S-1-5-21-2835384908-1013129077-2624498441-4518\Software\SecuROM\License information*NULL*]
@Security="Inherited"
"datasecu"=hex:1d,f0,80,1e,cc,4b,05,a0,a9,0c,c7,5c,43,ba,c3,04,1a,56,54,4e,db,\
8a,c0,6b,bc,6d,80,88,dc,eb,da,f7,90,1a,8b,f4,fa,ec,19,7a,45,60,d6,31,20,3e,\
65,6f,7a,bc,17,0b,53,b2,b8,9f,53,80,0d,8a,d8,c0,44,e1,cf,5b,30,81,eb,4a,d9,\
91,47,a3,3e,d3,d0,af,53,a3,ec,b3,e3,22,09,16,b2,5f,14,cc,96,e4,63,99,cf,8b,\
01,85,61,b4,e3,6a,9a,e4,6f,f5,1f,11,fc,76,3d,8e,e0,21,18,c6,2d,21,8f,99,e7,\
71,46,aa,d0,a0,bf,38,75,1e,ee,de,44,d3,f0,14,05,b5,43,96,08,99,b3,dc,dc,73,\
f5,36,f3,67,61,f6,2c,5c,88,df,dc,4e,71,84,ec,ce,58,7f,8e,f8,5a,61,d1,d6,82,\
78,4e,4c,2f,f8,69,7f,79,04,3b,25,fe,a5,1e,ac,1d,2b,d3,e6,8c,96,02,24,c1,20,\
dd,89,ba,42,19,94,ea,53,b8,e5,61,90,93,a6,70,48,51,60,31,0c,0b,a5,d6,62,d4,\
fa,84,f4,b6,69,1e,57,a0,63,d1,c2,8a,26,90,28,c2,e9,e0,2a,2a,d3,78,eb,68,d0,\
88,9e,e1,33,6d,27,63,da,94,85,1e,67,7f,25,32,9d,a5,39,15,d0,97,37,e1,32,fb,\
e8,d6,ad,a8,52,58,cc,9d,aa,d8,ac,79,0a,99,61,8e,9f,df,22,ec,97,0f,1f,c3,30,\
24,9a,17,6e,ad,a5,8f,77,a1,2a,8f,b9,5b,fe,ab,57,a9,04,8e,73,ba,72,19,a3,1d,\
06,44,71,21,b2,43,87,af,6c,90,76,1e,27,3f,97,db,8b,33,cf,70,43,d1,fa,b0,7a,\
9f,5d,fa,a6,68,cb,ef,1d,cd,a4,4f,b9,0a,70,9f,aa,0f,9c,08,29,98,c7,d0,6e,1a,\
53,34,ad,46,8c,94,94,48,b0,cc,42,e7,df,34,a4,77,54,98,a6,53,d3,5b,f0,87,f3,\
7d,b1,85,51,7d,68,2b,de,da,a7,cb,7b,fd,73,fa,f1,6b,76,a0,b4,22,be,6d,b2,ec,\
36,0e,22,b9,d1,6e,04,de,8a,da,10,1c,38,20,c7,3d,94,b1,fb,01,8b,6b,11,e1,61,\
49,36,4b,25,cc,55,c7,11,53,99,03,f0,bb,3a,c3,b7,77,fd,76,48,9c,63,9c,54,31,\
08,8e,3d,09,04,cb,92,bd,5b,e5,6e,1f,67,78,d9,2d,2e,a4,30,e0,8e,f5,e6,fe,13,\
92,cd,27,d3,b3,a9,12,75,05,b2,22,7d,3c,89,11,bc,be,98,38,ef,01,80,4b,72,e2,\
cc,65,e0,1f,2b,b4,e8,3a,a1,14,99,f5,94,23,e0,32,87,51,6d,fe,d7,12,5e,ff,61,\
f2,27,f2,06,cd,0a,b9,da,28,41,b7,c1,30,07,9c,f5,44,08,a4,2d,15,fa,e4,ac,16,\
a4,ad,38,0a,80,09,3f,0c,73,28,88,c0,7b,a3,44,f7,62,33,13,11,70,4c,3f,aa,87,\
1d,c2,2e,db,af,30,8e,c3,70,db,63,6c,b5,5e,71,78,1c,e3,81,43,32,b1,db,8a,5f,\
20,18,cb,69,cf,4e,22,c2,0d,99,42,77,3c,03,8c,99,31,38,fd,2f,09,d2,b8,63,e2,\
b3,fd,4d,cf,70,31,e0,d5,ce,d6,9f,6a,98,23,62,e8,6d,9b,f3,03,9a,76,fa,48,f8,\
17,28,24,98,31,3e,c9,09,da,b1,ba,23,67,0d,5f,38,11,eb,5f,99,91,34,7b,b8,b4,\
c0,8f,bf,ff,6b,66,0c,f3,a8,70,94,1e,5c,fe,db,c1,33,ca,6b,bb,8f,e5,be,72,1b,\
c6,44,e8,4b,27,b2,47,32,e4,53,0a,1b,1a,e8,33,44,a2,5a,c7,f9,84,bb,ed,ff,44,\
59,99,25,35,be,b3,f7,98,59,6d,d6,98,7a,30,75,99,4d,9b,52,59,27,79,6c,e5,17,\
09,81,2b,20,d7,7b,5c,3e,82,19,10,88,26,1a,23,e3,38,21,a9,91,28,c1,3e,6e,5d,\
98,44,f2,e7,25,5e,8b,dc,0f,86,60,14,92,8a,12,5a,88,9f,18,89,3b,74,f0,8f,35,\
06,f9,c0,e0,b8,25,38,85,5b,7d,9e,b0,7f,56,94,5b,e4,79,be,23,b8,31,54,33,ad,\
68,ab,9c,2e,cd,78,5f,b4,17,54,5f,ec,0b,09,cd,0a,18,05,8a,c0,a7,46,e5,e6,f5,\
ea,d7,d0,ab,b2,54,72,9a,e4,a0,fd,f9,b3,a4,12,e6,0f,c7,2e,d6,aa,d4,f1,33,07,\
a5,bd,03,2b,65,64,dc,8c,6b,7e,a6,3b,3a,76,41,e4,e1,a7,e1,35,42,96,98,a2,53,\
ee,cc,2c,da,fa,e0,77,bf,87,3c,ab,34,ca,77,fa,c8,39,37,03,e7,03,36,3c,1c,cf,\
0d,f9,28,c0,87,d5,24,b1,87,1f,7b,b1,ea,ae,cb,f2,16,72,c2,9f,b1,e9,b2,b5,a4,\
9c,7d,a9,e4,67,60,c1,b3,ff,26,2c,40,88,38,04,bf,84,98,2f,3c,41,3b,88,01,fa,\
5d,a6,f8,76,48,35,30,e7,24,51,9b,8b,a2,df,22,28,34,c2,f5,c7,9c,b8,bf,53,47,\
49,b3,9d,08,61,4c,83,6d,49,34,77,de,26,27,63,e1,15,fc,16,62,5d,2a,32,1c,4e,\
7b,da,ad,8d,ad,72,3e,1f,e3,fa,39,12,07,c9,dd,d7,24,31,ea,0e,00,60,eb,76,33,\
6d,43,7c,b6,dd,f9,1c,54,1f,5e,e7,39,6e,14,fb,8c,ec,c6,0f,40,b1,be,2e,2d,28,\
94,0d,f1,f5,90,e1,e1,6f,16,d8,f7,80,1f,27,78,3a,8a,76,56,58,32,51,c5,0a,ca,\
47,e3,cf,2d,f4,66,86,c9,ca,e5,13,c0,f4,6a,b1,cc,44,cb,02,58,ef,48,b3,d3,16,\
5e,d0,14,57,e5,40,cb,74,76,e8,b8,7f,e4,88,00,17,50,b9,5b,69,fa,bc,c8,28,0a,\
49,0e,17,2d,ac,12,c0,c8,5e,5a,1a,4a,9f,8c,e2,68,ca,a3,0c,c1,ea,51,91,cb,ae,\
0d,ca,82,b1,98,f1,10,e3,a0,b0,86,00,fe,f7,86,4c,16,3b,b6,1d,17,e9,b4,ce,df,\
42,72,95,62,00,3c,97,9b,dc,69,92,a4,1b,46,8f,93,b6,c6,7e,ff,26,64,ae,45,c2,\
47,63,5d,81,ba,35,99,cb,28,c3,87,92,9c,b5,49,29,46,ea,9f,f8,91,f8,61,fc,b8,\
7c,20,4f,53,a5,c4,4f,c6,d7,f4,ca,f2,3b,27,dd,95,8d,53,58,23,8c,08,31,c7,eb,\
c1,3a,29,9c,0c,9f,d1,af,1b,5d,82,e0,22,09,6a,08,53,f7,a1,f7,6c,7b,c3,c5,7a,\
2b,76,a9,d4,6d,2c,01,eb,9b,3a,f6,d7,f6,81,b6,62,2b,30,94,71,e0,2c,1e,ea,c1,\
3b,f1,4a,85,d4,27,86,40,ec,a9,ae,94,42,91,36,bc,16,cc,99,17,20,45,63,f7,39,\
e6,d6,99,81,27,28,17,0b,dc,48,bb,99,be,40,2c,19,f2,94,7e,f2,89,22,c0,66,e5,\
7f,17,0e,9f,85,8a,81,10,f1,d6,5a,c1,90,3b,d3,b5,4b,b8,33,13,19,1d,c6,93,31,\
5a,e1,b1,0d,4a,59,76,0e,91,6c,9a,4e,51,3c,88,a7,0e,ed,1d,4f,05,37,c4,c6,01,\
dd,e0,58,f3,8c,8f,58,8b,aa,3b,dd,d8,d3,c3,8b,c4,cc,ce,36,3d,1e,42,6e,ba,4e,\
a5,d6,c8,b3,7a,9e,8a,14,d5,69,a3,08,51,d3,2a,3e,c6,25,c4,b6,3d,a2,b0,86,90,\
4c,69,74,0e,ab,46,15,46,ce,79,6e,41,ab,4b,f4,47,ee,09,6c,cd,7e,4a,2d,bc,12,\
26,7f,23,00,ea,c0,31,57,fa,54,27,24,af,56,f3,dd,80,04,2f,d2,ae,41,6f,74,d9,\
40,b6,13,e4,03,32,82,8e,82,10,eb,a3,ee,62,9a,93,58,3d,7f,c0,d3,b0,46,86,3f,\
95,4e,a0,76,ee,48,2e,b4,09,11,0c,1b,d7,31,97,65,6f,0a,2c,77,a0,78,e9,a9,85,\
87,d9,04,8b,01,12,e0,50,09,af,c7,39,ba,ca,0a,f5,42,2f,4b,8b,40,a6,ad,1f,e8,\
25,8e,0b,38,4a,fa,fa,27,eb,68,39,b3,20,be,8e,45,25,a6,50,05,c7,3f,1c,3d,b0,\
8f,62,46,2a,75,8d,98,84,08,79,90,88,f2,84,45,40,b3,11,05,1e,e1,a7,41,68,52,\
cd,72,6b,f0,a9,94,ce,64,94,3d,cf,01,5b,c0,66,b5,24,db,2b,0a,fc,e5,ab,37,44,\
14,ec,8c,c6,c8,dd,3b,1c,63,ce,82,09,eb,03,0a,c2,b4,45,d4,87,89,ae,5e,a0,c3,\
c3,74,ea,52,11,b3,33,b8,1e,79,91,7b,9e,06,cf,77,a5,9e,54,d6,21,4a,0f,18,3f,\
49,64,7d,e8,54,2a,3a,f5,5d,48,2c,22,57,05,28,25,3d,12,7f,c0,dd,e0,60,fd,23,\
b7,e0,70,82,2b,85,bf,da,4f,dc,c1,2a,b6,dd,5e,88,b2,b5,9e,f9,4a,c1,e1,ac,64,\
58,70,93,a5,1f,9a,2a,e8,a0,ca,24,b3,68,1d,3e,03,95,7e,48,9d,18,d4,0f,bd,70,\
90,7f,a9,ea,00,14,67,1a,1d,44,d3,15,0a,74,d1,87,10,c7,f1,6d,b5,05,0c,0e,1f,\
6b,ad,51,8a,7c,d1,f1,1e,f1,9a,64,46,92,73,07,a3,fe,9a,b4,66,8c,9a,13,9f,db,\
74,74,41,b8,37,a3,a0,35,5e,9f,4b,b3,63,32,a1,4f,e1,f4,cb,71,30,67,4b,7d,fa,\
5c,2b,b4,16,11,72,36,79,fb,93,2b,22,ba,26,69,d5,8d,6b,73,c5,47,0d,f6,4e,f2,\
2c,7e,9e,48,c5,b3,f5,4e,5c,16,25,e5,f5,7b,b8,8e,0b,31,8e,01,3a,7e,3b,39,d4,\
a9,ed,67,eb,2f,8f,e0,aa,68,d3,cf,83,7a,ae,49,60,25,b6,56,77,ea,fd,eb,e5,b2,\
a4,c4,0a,d2,64,13,78,c5,28,33,8e,24,5a,53,0c,dd,e6,2f,3b,1c,fb,a5,81,23,90,\
9e,9c,f5,29,14,0f,49,01,a6,fd,ae,6b,74,5c,67,56,ae,88,6a,7f,18,99,c0,48,34,\
9e,22,46,24,9b,4f,68,be,1e,ea,47,c9,e8,e3,d5,c2,d9,c2,3c,64,78,fa,42,f1,42,\
1b,de,1c,25,c7,ae,be,73,53,e0,91,e2,62,b0,69,64,f5,70,ae,2d,56,51,8f,b2,b8,\
53,45,ca,f0,c1,ae,3a,7d,6b,58,23,28,d4,d8,e2,7f,dd,15,1e,3c,68,77,40,98,9b,\
3a,c3,e2,30,83,bf,8b,65,57,a1,30,5f,e2,35,53,44,db,dc,bf,02,1e,15,fe,0c,fb,\
23,d9,9d,7c,f0,ae,af,6c,43,13,83,3b,32,5e,b2,e6,78,b2,17,5b,d5,5e,b2,6d,6c,\
30,d6,9c,52,82,a7,e8,64,77,3e,10,6b,1f,e4,4b,55,eb,ca,e0,30,04,4f,7d,36,d2,\
34,9d,ae,96,f0,cf,a6,df,21,13,79,8b,14,04,e4,80,cd,15,0f,18,ef,b6,4c,79,7f,\
ce,78,bc,b6,aa,ec,96,7a,8d,ab,ae,89,40,69,cd,af,7e,80,5f,cd,ca,be,37,64,20,\
41,8d,c0,b0,ad,e5,d2,1f,fa,4e,0e,df,98,f3,a2,21,7e,7b,40,3a,7d,49,18,83,41,\
00,15,8e,70,c9,7f,b8,9e,9d,16,9c,a7,d0,33,c4,ad,49,90,ca,e8,99,42,35,94,04,\
0b,47,60,b3,14,4a,91,15,5a,9d,f5,cc,aa,c2,3e,fd,ab,e1,1f,79,d1,2b,3e,41,dc,\
c7,41,90,71,b9,83,06,92,59,50,87,65,e9,c8,02,4d,73,55,ad,8e,df,d5,1a,f8,30,\
ee,95,42,f0,6e,8e,a2,24,44,63,c7,33,06,a9,fd,97,43,0c,b4,f8,a7,e4,09,a3,7d,\
fb,ad,07,73,5e,4c,71,9b,00,4b,66,9d,26,3b,e0,1d,96,87,8d,22,33,b8,bc,eb,47,\
ee,b7,8c,66,fb,fc,d9,bd,7f,a6,dc,72,c6,5b,61,3b,3c,a5,8b,ad,c8,69,e9,29,93,\
47,b0,4c,fc,ff,58,d0,8a,12,05,67,5e,8b,2f,f2,1b,d3,50,a6,90,54,50,57,66,84,\
2e,63,31,08,43,ea,31,f9,1f,45,85,6b,65,2c,7b,67,83,ad,c5,35,2a,cf,49,1a,d1,\
63,07,ce,cf,bd,9a,32,6f,c9,a7,16,f5,85,bd,57,0b,1e,e7,0c,6d,b8,27,a1,4f,60,\
e1,4a,61,0c,78,5f,d7,8a,a7,38,fc,08,6e,26,dc,5d,79,59,17,c6,f1,63,f7,86,55,\
bc,57,93,f9,de,3f,55,71,cd,38,cc,97,19,ec,0f,9f,68,28,25,e8,b5,cd,c7,02,84,\
3f,4d,b3,83,dd,c2,25,98,9e,c7,05,ec,b9,c2,c7,d5,05,8e,2b,34,24,33,c2,de,8c,\
a3,47,9c,87,2d,88,9f,3f,0b,8a,7a,63,ba,f0,2d,a3,33,2c,77,cf,a7,86,6e,24,a8,\
c7,90,80,83,31,04,a5,c3,b1,a8,8c,c2,22,b7,f5,8d,cd,ed,ea,63,0f,c5,61,4f,1e,\
6f,9c,66,e3,28,2a,a8,4c,f1,91,51,20,e6,f5,d9,fe,2d,76,bb,f9,74,3b,ec,a1,00,\
82,fe,09,75,fe,90,82,5c,7b,c9,db,f7,3e,4c,3c,be,4f,0a,c4,dd,b4,f1,30,b5,1e,\
88,f9,9f,ec,1c,f2,2d,74,a6,f5,96,ec,18,da,ac,e9,cc,c2,15,ac,4b,7d,75,67,ea,\
13,8a,72,71,fe,a5,dd,9c,9e,ee,5a,55,a7,f7,11,b3,f4,d5,8e,1d,14,22,fb,6e,83,\
d7,c2,b7,b6,f3,a1,82,7e,07,a7,69,ff,db,86,a2,4d,63,04,7b,69,2c,6c,0b,16,c8,\
8f,2c,4e,24,35,a3,7e,72,01,dc,83,3b,e8,bd,14,66,fc,f2,56,7d,9d,44,3f,bf,23,\
b9,fd,41,c2,ea,c7,cf,83,cd,41,a2,e5,37,03,01,ac,fd,e3,8b,ca,9b,9a,12,12,29,\
2a,34,f8,94,d7,78,44,04,2a,6a,21,67,3e,e2,1a,3f,bb,cb,a0,55,2a,f5,aa,45,28,\
41,7c,5c,ad,39,68,c8,14,ca,21,d8,85,d2,df,06,bd,19,45,62,ea,a3,b6,18,e3,88,\
7c,ac,ea,44,4b,e4,54,32,b0,b5,68,7c,c7,2d,66,40,7a,cd,34,a6,95,4e,4c,d7,2d,\
1e,6c,72,7b,dd,65,fb,6c,eb,52,51,68,4c,be,65,13,44,4f,20,d8,e1,c7,1f,cb,15,\
a7,5a,d7,58,c0,4a,f2,ed,00,1d,98,25,da,2e,02,38,dc,e8,3d,c1,ea,b4,5f,a0,d8,\
38,7e,cd,30,1c,c0,97,7b,d2,f2,37,4b,ee,0b,a1,b0,f7,36,c8,63,3f,5b,d4,f2,36,\
64,2b,de,bb,1e,4a,ad,0b,ee,ac,0e,5c,c2,1c,a2,86,0f,22,b3,7f,58,0f,0b,68,bd,\
ef,86,4c,c3,16,91,38,82,a3,51,21,9b,7d,e2,c3,6c,19,d9,3d,b6,e6,42,cf,69,34,\
45,8f,db,ee,b1,ae,1a,35,29,34,3a,1a,09,04,2c,af,2a,ea,7c,cf,67,41,ed,fd,ac,\
63,ee,a1,6c,82,14,49,a8,c8,c6,0a,a9,1d,8d,d0,d2,6d,08,88,cd,dc,a6,30,c0,41,\
dc,10,cb,6b,01,9c,7f,a1,6f,19,48,be,ac,cd,c1,3f,89,31,08,19,d2,43,8e,86,2f,\
92,3f,24,f2,6e,5b,7d,93,92,e5,74,1c,ae,47,33,26,64,74,0d,55,d6,a1,55,2a,7b,\
4f,30,0b,cf,25,0b,39,26,28,f8,ad,56,a9,72,f3,23,35,a7,32,59,85,21,1b,2c,40,\
19,c5,e9,d0,39,48,d8,f0,3e,06,87,58,0f,0b,cf,11,4c,c1,bc,cf,e0,45,42,17,d1,\
fd,f6,b6,78,e9,f0,e8,83,11,fa,33,18,ca,44,36,86,23,ac,34,82,bf,b9,64,a4,3c,\
44,a4,d6,63,af,16,58,fa,1f,af,1c,45,d8,09,65,b3,48,84,30,1e,e9,04,7c,7a,68,\
e5,e5,5d,7b,c0,8b,a7,81,30,1a,4b,f3,0f,97,43,ce,1f,3f,2e,ca,d0,fc,2a,a9,b3,\
45,e6,30,8f,9a,ee,be,28,a3,60,23,eb,a8,8b,36,c5,7c,65,fe,85,c5,5b,90,d8,bc,\
05,d5,2f,df,2c,58,b2,7f,ac,ae,bb,2f,5b,08,3f,60,95,a9,17,22,ff,92,52,54,04,\
1c,24,d3,53,40,9b,ee,db,1a,cd,c4,e7,d3,3a,c9,a0,12,9f,18,6e,bd,7a,74,56,5d,\
13,2a,6a,dc,e8,16,46,11,46,ec,20,ca,2e,9c,2b,07,30,08,f1,fa,8a,9e,90,2b,9a,\
ad,62,57,e3,ad,41,55,6b,ce,0d,8e,65,4c,bf,d7,48,4c,e8,db,bd,a6,a1,c5,7d,c1,\
b3,91,f8,8e,3d,96,55,3b,c5,ae,e0,21,a2,ee,87,7f,a9,27,8b,c5,b0,59,99,ce,37,\
49,ac,70,2d,af,bb,45,9b,ef,9a,20,98,a7,fa,fc,a4,60,7f,91,30,3b,64,cb,de,c0,\
15,48,93,d6,b7,22,53,89,b2,52,26,eb,4a,36,07,37,d3,90,0d,b9,d9,41,9d,05,62,\
2b,a4,8b,3a,da,4e,fe,db,f5,93,f8,19,f9,78,7b,2b,1a,b0,98,3d,6b,c7,6a,1b,2f,\
b5,a0,1b,31,27,8c,01,11,4a,89,75,b3,13,50,be,b6,04,22,2e,86,78,87,b7,2a,1b,\
90,5d,ad,59,4e,d5,33,96,ac,54,f4,7a,a3,e5,fa,4d,a3,13,4f,7a,85,31,78,02,42,\
dc,f7,b6,a7,62,15,8d,77,4e,f9,6b,10,00,f1,12,15,50,05,8b,04,7d,61,5f,cf,85,\
a5,0f,db,3d,8f,3c,95,95,73,09,80,f3,70,5c,ea,5b,54,2c,0f,78,30,34,e4,9e,8e,\
8c,57,4f,32,f7,73,19,56,0a,23,4f,7f,4a,b7,73,a4,bd,52,6a,a5,a1,49,e2,36,04,\
5e,da,7b,35,2a,ae,99,9c,44,a4,48,27,52,18,47,76,cf,d0,1c,3f,7f,78,ad,a6,00,\
03,7e,16,da,e5,50,8f,eb,7f,61,f4,d1,04,bf,fe,a2,e4,79,0f,de,2f,75,57,e0,39,\
57,7d,21,13,ed,dc,65,e9,a4,18,32,7b,5a,21,d0,0a,e4,1f,e4,de,db,b1,d1,f3,aa,\
58,15,92,db,ce,35,d3,d9,5d,7c,12,c5,66,ae,76,3a,8c,36,53,cd,e5,f8,24,48,2f,\
38,1e,fe,7f,d7,a5,46,70,0d,a7,a3,7a,d6,ac,ea,16,d7,79,f6,35,af,7b,c2,77,ac,\
bf,ae,b1,46,a6,47,e9,e4,38,24,c6,a2,c9,c5,55,11,72,29,6b,de,b5,13,95,b5,52,\
42,1b,e6,bd,af,05,05,28,8e,d0,35,50,7b,1a,3e,b0,b7,aa,b9,61,21,2f,c8,0e,3e,\
ec,e4,1a,28,5d,6d,51,c5,b6,e7,35,4a,a8,7a,00,33,f6,bd,1f,6c,d3,de,04,7d,9a,\
44,09,b4,98,fd,16,30,d6,bc,60,67,29,68,3c,58,0e,d5,38,ce,6e,c0,79,75,e3,6a,\
6d,21,9f,6f,89,ba,c2,46,8a,7e,b1,4a,a3,9a,bb,9e,4b,9f,79,f5,f9,ac,b2,b0,b4,\
bc,33,93,f9,4e,b6,42,34,88,26,22,59,f5,a4,ff,20,c8,64,fb,3c,19,de,55,87,da,\
08,f7,c9,65,42,0f,7e,01,ea,1f,a5,b5,90,82,df,2c,33,b5,18,6d,ff,4f,da,bb,b4,\
db,fc,79,cf,07,28,14,58,21,80,05,6a,b0,8b,06,3a,94,93,32,05,e5,44,ec,75,ba,\
55,ce,a1,ab,83,f7,0a,19,50,ae,61,29,f8,6c,3b,97,0e,9b,f5,32,5d,07,05,b0,10,\
b7,72,13,84,3c,5a,b0,02,5c,26,d9,84,ea,4a,7e,b7,3d,66,3e,54,e6,92,02,ab,14,\
db,61,af,f0,6e,5a,86,05,b1,5b,0a,64,7c,42,72,f4,6a,56,5c,57,79,2f,11,32,1d,\
03,e3,da,fe,51,69,5e,9f,5c,77,bf,01,9e,f2,cc,a0,89,28,34,86,9f,9e,37,4c,8b,\
bc,b8,4d,fd,bc,ca,ec,57,a2,ca,ff,64,a1,9f,c4,91,97,bd,e3,32,78,ea,6b,c8,c5,\
64,4b,b7,d3,23,a1,7d,56,76,78,e0,17,92,4a,b2,02,c0,a2,8f,b7,5c,97,4d,02,f3,\
33,73,3d,44,ae,b9,1a,cb,5c,1b,e9,24,20,a7,37,07,d0,72,60,e2,b6,cb,dd,a9,c3,\
ae,1f,bb,50,e8,5b,cf,c3,d6,1a,f0,23,30,b1,dd,a9,66,8e,a8,a0,23,ef,5d,bc,69,\
a0,39,1e,96,6c,e5,df,a2,44,22,10,8b,44,31,72,fd,3c,a0,2f,f3,1b,2c,a6,73,40,\
87,81,ca,23,31,82,21,8c,f2,c9,4f,9d,ad,4e,ab,d2,1f,03,dc,46,0f,61,53,e9,e4,\
23,d0,6d,5b,25,49,1f,d7,3e,1b,64,df,06,0b
"rkeysecu"=hex:a8,a1,aa,9e,c4,be,3e,69,17,f2,60,08,67,b4,3b,4f
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•A~*NULL*]
@Security="Inherited"
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_LOCAL_MACHINE\software\Sigmatel\GlobalState]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=Administrators
@Denied: (Full) (Guests)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrator)
@Allowed: (B 1 2 3 4 5) (S-1-5-4)
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Kaos Inc\System Utilities\Ad-Aware\aawservice.exe
c:\windows\system32\scardsvr.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Crypserv.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
c:\program files\Microsoft SQL Server\MSSQL$SURADOCRMOFFLINE\Binn\sqlservr.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\java.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\dllhost.exe
c:\program files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\msdtc.exe
.
**************************************************************************
.
Completion time: 2008-12-31 19:53:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-01 01:53:20
ComboFix2.txt 2008-12-30 23:08:24
Pre-Run: 38,608,060,416 bytes free
Post-Run: 38,738,853,888 bytes free
544 — E O F — 2008-12-15 15:36:18
Also, I made a post earlier, but forgot to post the combofix log file as well and made that as a seperate post…then finally read that I shouldn't reply to my own post hah (sorry!)
So anyone who wants to help, I appreciate all your efforts.
Here is my log file for Hijackthis and Combofix. If anyone has any insight in this, please let me know.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:35:47 AM, on 2009-01-02
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Kaos Inc\System Utilities\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\astsrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SURADOCRMOFFLINE\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\java.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\Kaos Inc\QK\RocketDock\RocketDock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {a58ef46e-0289-4eca-b0c0-6767866c58dd} - C:\WINDOWS\system32\tadibiha.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [\\TIMBROWN\EPSON Stylus Photo R220 Series shared] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P48 "\\TIMBROWN\EPSON Stylus Photo R220 Series shared" /O20 "\\timbrown\timbepson" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [\\PENNY\EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P38 "\\PENNY\EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [\\GORDONSLIVER\EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P45 "\\GORDONSLIVER\EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [\\RICH\EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P37 "\\RICH\EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [\\MAKAILA\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P40 "\\MAKAILA\EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [masiyajufi] Rundll32.exe "C:\WINDOWS\system32\lenidure.dll",s
O4 - HKLM\..\Run: [CPMc7a45b90] Rundll32.exe "c:\windows\system32\jiwofehu.dll",a
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\Kaos Inc\QK\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.7.109.cab
O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - http://tank/connectcomputer/nshelp.dll
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Gemvision.local
O17 - HKLM\Software\..\Telephony: DomainName = Gemvision.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Gemvision.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Gemvision.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = Gemvision.local
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\mitapuwi.dll c:\windows\system32\ c:\windows\system32\yegehija.dll c:\windows\system32\jiwofehu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jiwofehu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\jiwofehu.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Kaos Inc\System Utilities\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C:\WINDOWS\SYSTEM32\astsrv.exe
O23 - Service: ASTSRV - Nalpeiron Ltd. - c:\Windows\System32\AstSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.30\bin\mysqld.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/djohnson/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg
–
End of file - 14243 bytes
————-Combo Fix Log
ComboFix 08-12-30.02 - DJohnson 2008-12-31 19:38:50.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1534.805 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Kaos Inc\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\oraburos.ini
.
((((((((((((((((((((((((( Files Created from 2008-12-01 to 2009-01-01 )))))))))))))))))))))))))))))))
.
2008-12-31 03:22 . 2008-12-31 03:54 d——– C:\GMOD10
2008-12-31 01:16 . 2008-12-31 01:16 d——– c:\program files\RADVideo
2008-12-30 18:14 . 2008-12-31 15:12 d——– C:\HammerAutosave
2008-12-30 16:15 . 2008-12-30 16:15 d——– c:\program files\Trend Micro
2008-12-29 10:04 . 2008-12-29 10:04 d——– c:\program files\Microsoft Visual Studio 8
2008-12-27 19:59 . 2008-12-27 20:13 d——– c:\program files\Spybot - Search & Destroy
2008-12-27 12:29 . 2008-12-27 12:29 1,094,368 –a—— c:\windows\system32\rn.tmp
2008-12-27 12:20 . 2008-12-27 12:20 45,056 –a—— c:\windows\system32\efcBsPhI.dll
2008-12-26 01:41 . 2008-12-26 01:42 d——– C:\wamp
2008-12-25 15:19 . 2008-12-25 15:19 d——– c:\program files\GoldWave
2008-12-24 00:42 . 2008-12-24 00:42 d——– c:\windows\system32\Adobe
2008-12-23 15:16 . 2008-12-23 15:16 131,072 –a—— c:\windows\system32\SpoonUninstall.exe
2008-12-22 06:12 . 2008-12-22 06:12 d——– c:\program files\MySQL
2008-12-21 00:49 . 2008-12-21 00:49 d——– C:\Garmin
2008-12-21 00:07 . 2008-12-21 00:07 d——– c:\documents and settings\djohnson\Application Data\Windows Search
2008-12-19 18:00 . 2008-12-19 18:00 d—s—- c:\program files\HLSW
2008-12-19 18:00 . 2008-12-31 15:15 d——– c:\documents and settings\djohnson\Application Data\HLSW
2008-12-17 08:55 . 2008-12-17 08:55 d——– c:\windows\system32\GroupPolicy
2008-12-17 08:55 . 2008-12-23 19:11 d——– c:\program files\Windows Desktop Search
2008-12-16 13:00 . 2008-12-16 13:00 d——– c:\documents and settings\LocalService\Application Data\iolo
2008-12-16 11:02 . 2008-12-16 11:02 406 –a—— c:\windows\system32\ioloBootDefrag.cfg
2008-12-15 11:30 . 2008-12-15 11:30 268 –ah—– C:\sqmdata09.sqm
2008-12-15 11:30 . 2008-12-15 11:30 244 –ah—– C:\sqmnoopt09.sqm
2008-12-05 14:01 . 2008-12-05 14:32 d——– c:\documents and settings\djohnson\Application Data\Notepad++
2008-12-05 13:26 . 2008-12-06 00:41 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-05 13:25 . 2008-12-06 03:02 d——– C:\Fraps
2008-12-04 17:35 . 2008-12-04 17:35 d——– c:\documents and settings\All Users\Application Data\CyberLink
2008-12-01 17:36 . 2008-12-01 17:36 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-01 01:47 ——— d—–w c:\program files\Symantec AntiVirus
2009-01-01 01:35 ——— d—–w c:\program files\Steam
2009-01-01 01:18 ——— d—–w c:\documents and settings\djohnson\Application Data\.purple
2008-12-31 09:30 ——— d—–w c:\documents and settings\djohnson\Application Data\uTorrent
2008-12-31 00:10 ——— d—–w c:\program files\Matrix60
2008-12-29 16:05 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-28 21:11 ——— d—–w c:\program files\Kaos Inc
2008-12-28 21:08 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-28 21:08 ——— d—–w c:\program files\Dell
2008-12-28 21:07 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2008-12-28 21:05 ——— d—–w c:\program files\Norton Ghost
2008-12-28 21:05 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-12-28 06:28 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-27 04:48 ——— d—–w c:\documents and settings\djohnson\Application Data\U3
2008-12-24 18:33 ——— d—–w c:\program files\Common Files\Adobe
2008-12-23 21:57 ——— d—–w c:\documents and settings\All Users\Application Data\iolo
2008-12-19 05:24 ——— d—–w c:\documents and settings\djohnson\Application Data\Skype
2008-12-19 02:09 ——— d—–w c:\documents and settings\djohnson\Application Data\skypePM
2008-12-16 20:00 ——— d—–w c:\documents and settings\djohnson\Application Data\iolo
2008-12-16 19:08 ——— d—–w c:\documents and settings\Doug Johnson.D6D4W4H1\Application Data\uTorrent
2008-12-05 22:09 960 —-a-w c:\windows\system32\drivers\sthdae.log
2008-11-29 21:02 136,720 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-28 06:53 ——— d—–w c:\documents and settings\djohnson\Application Data\Palo Alto Software
2008-11-28 06:51 ——— d—–w c:\program files\Common Files\Palo Alto Software
2008-11-28 06:51 ——— d—–w c:\program files\Common Files\Intuit
2008-11-28 06:51 ——— d—–w c:\documents and settings\All Users\Application Data\Palo Alto Software
2008-11-28 06:48 ——— d—–w c:\documents and settings\All Users\Application Data\PAS
2008-11-24 17:40 ——— d—–w c:\documents and settings\djohnson\Application Data\Ventrilo
2008-11-24 17:39 ——— d—–w c:\program files\Ventrilo
2008-11-24 17:39 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-11-11 23:20 ——— d—–w c:\program files\Microsoft Silverlight
2008-11-09 23:40 ——— d—–w c:\program files\DVD Shrink
2008-11-09 23:40 ——— d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-11-06 15:53 ——— d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2008-11-03 02:10 ——— d—–w c:\documents and settings\djohnson\Application Data\gtk-2.0
2008-11-01 01:47 ——— d—–w c:\documents and settings\All Users\Application Data\Adobe Systems
2008-11-01 01:43 ——— d—–w c:\program files\Common Files\Adobe Systems Shared
2008-10-23 17:41 22,328 —-a-w c:\documents and settings\djohnson\Application Data\PnkBstrK.sys
2008-10-22 18:38 155,995 —-a-w c:\windows\java\Packages\6C35BHB9.ZIP
1601-01-01 00:12 61,118 –sha-w c:\windows\system32\mikadazo.dll
1601-01-01 00:12 61,118 –sha-w c:\windows\system32\puwasoyo.dll
1601-01-01 00:12 61,118 –sha-w c:\windows\system32\tadibiha.dll
2008-09-07 18:51 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090720080908\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-12-30_17.07.47.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-30 20:46:20 155,322 —-a-w c:\windows\system32\nvModes.dat
+ 2008-12-31 22:42:43 155,282 —-a-w c:\windows\system32\nvModes.dat
- 2008-12-23 21:58:15 81,530 —-a-w c:\windows\system32\perfc009.dat
+ 2008-12-30 23:52:26 81,530 —-a-w c:\windows\system32\perfc009.dat
- 2008-12-23 21:58:15 465,144 —-a-w c:\windows\system32\perfh009.dat
+ 2008-12-30 23:52:26 465,144 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-01 01:00:33 83,557 –sha-w c:\windows\system32\sorubaro.dll
+ 2009-01-01 01:47:04 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_4d8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a58ef46e-0289-4eca-b0c0-6767866c58dd}]
61118 –ahs—- c:\windows\system32\tadibiha.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\Kaos Inc\QK\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-06-15 124656]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-26 1024000]
"\\TIMBROWN\EPSON Stylus Photo R220 Series shared"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE" [2005-03-09 98304]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-06-02 2220032]
"\\PENNY\EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-12-05 405504]
"\\GORDONSLIVER\EPSON Stylus Photo R220 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE" [2005-03-09 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-06 8466432]
"\\RICH\EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"\\MAKAILA\EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-08 99840]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-13 169984]
"nwiz"="nwiz.exe" [2007-08-06 c:\windows\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2007-08-06 c:\windows\system32\nvmctray.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=c:\windows\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Icatch(VI) SnapDetect.lnk]
backup=c:\windows\pss\Icatch(VI) SnapDetect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Palo Alto Software Update Manager 9.0.lnk]
backup=c:\windows\pss\Palo Alto Software Update Manager 9.0.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
backup=c:\windows\pss\Service Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Surado CRM Always-In-Sync .lnk]
backup=c:\windows\pss\Surado CRM Always-In-Sync .lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^djohnson^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\djohnson\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
–a—— 2002-09-10 20:26 368706 c:\program files\BroadJump\Client Foundation\CFD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c497680c]
–ahs—- 2008-12-31 19:00 83557 c:\windows\system32\sorubaro.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 18:12 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
–a—— 2008-08-13 23:08 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
–a—— 2006-10-26 23:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2006-11-13 12:39 1289000 c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a—— 2007-12-13 18:10 1688872 c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 11:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
–a–c— 2007-12-03 13:21 2213160 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a–c— 2007-03-01 13:57 153136 c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
——— 2008-02-26 09:57 128296 c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SecureUpgrade]
–a–c— 2007-09-14 09:53 218424 c:\program files\Wave Systems Corp\SecureUpgrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2008-09-29 16:57 21755688 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WavXMgr]
–a–c— 2007-09-10 08:55 92160 c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
–a–c— 2007-08-06 15:27 67584 c:\windows\system32\nvhotkey.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-08-06 15:28 1626112 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Kaos Inc\\Internet Utilities\\Utorrent\\uTorrent.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\NWN2\\nwn2main.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\NWN2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\NWN2\\nwupdate.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\NWN2\\nwn2server.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Kaos Inc\\Internet Utilities\\CuteFTP 8 Professional\\ftpte.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\Bionic Commando Rearmed\\bcr.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Program Files\\Kaos Inc\\Games\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 LinksysUpdater;Linksys Updater;"c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe" -s "c:\program files\Linksys\Linksys Updater\conf\wrapper.conf" [2008-01-15 204800]
R2 MSSQL$SURADOCRMOFFLINE;MSSQL$SURADOCRMOFFLINE;c:\program files\Microsoft SQL Server\MSSQL$SURADOCRMOFFLINE\Binn\sqlservr.exe -sSURADOCRMOFFLINE []
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe /Processid:{8277F0D9-812F-470B-BFC1-A6D96FBA774A} [2004-08-11 5120]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe /Processid:{BDFEFE06-0F3F-44F4-984D-3BF2A1CA8D75} [2004-08-11 5120]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-12 99376]
S2 ASTSRV;ASTSRV;c:\windows\System32\AstSrv.exe [2008-08-27 57344]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-09-26 33752]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2006-06-15 115952]
S3 SQLAgent$SURADOCRMOFFLINE;SQLAgent$SURADOCRMOFFLINE;c:\program files\Microsoft SQL Server\MSSQL$SURADOCRMOFFLINE\Binn\sqlagent.EXE -i SURADOCRMOFFLINE []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
2009-01-01 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe []
2008-12-25 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe []
2009-01-01 c:\windows\Tasks\zdgsywya.job
- c:\windows\system32\rundll32.exe [2008-04-13 18:12]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-CPMc7a45b90 - c:\windows\system32\yodibapi.dll
MSConfigStartUp-masiyajufi - c:\windows\system32\lenidure.dll
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Kaos Inc\Multimedia Utilities\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\djohnson\Application Data\Mozilla\Firefox\Profiles\j1ylc7cx.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\djohnson\Application Data\Mozilla\Firefox\Profiles\j1ylc7cx.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\nppdf32.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npptkver.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
FF - plugin: c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npptkver.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-31 19:47:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\windows\system32\oraburos.ini 1262075 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-2835384908-1013129077-2624498441-4518
@Allowed: (Read) (Everyone)
@Allowed: (Read) (Users)
@Allowed: (Read) (PowerUsers)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (S-1-5-21-2835384908-1013129077-2624498441-4518)
"*"=dword:00000004
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_USERS\S-1-5-21-2835384908-1013129077-2624498441-4518\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-2835384908-1013129077-2624498441-4518
@Allowed: (Full) (S-1-5-21-2835384908-1013129077-2624498441-4518)
@Allowed: (Full) (S-1-5-21-2835384908-1013129077-2624498441-4518)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
"*"=dword:00000004
[HKEY_USERS\S-1-5-21-2835384908-1013129077-2624498441-4518\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_USERS\S-1-5-21-2835384908-1013129077-2624498441-4518\Software\SecuROM\License information*NULL*]
@Security="Inherited"
"datasecu"=hex:1d,f0,80,1e,cc,4b,05,a0,a9,0c,c7,5c,43,ba,c3,04,1a,56,54,4e,db,\
8a,c0,6b,bc,6d,80,88,dc,eb,da,f7,90,1a,8b,f4,fa,ec,19,7a,45,60,d6,31,20,3e,\
65,6f,7a,bc,17,0b,53,b2,b8,9f,53,80,0d,8a,d8,c0,44,e1,cf,5b,30,81,eb,4a,d9,\
91,47,a3,3e,d3,d0,af,53,a3,ec,b3,e3,22,09,16,b2,5f,14,cc,96,e4,63,99,cf,8b,\
01,85,61,b4,e3,6a,9a,e4,6f,f5,1f,11,fc,76,3d,8e,e0,21,18,c6,2d,21,8f,99,e7,\
71,46,aa,d0,a0,bf,38,75,1e,ee,de,44,d3,f0,14,05,b5,43,96,08,99,b3,dc,dc,73,\
f5,36,f3,67,61,f6,2c,5c,88,df,dc,4e,71,84,ec,ce,58,7f,8e,f8,5a,61,d1,d6,82,\
78,4e,4c,2f,f8,69,7f,79,04,3b,25,fe,a5,1e,ac,1d,2b,d3,e6,8c,96,02,24,c1,20,\
dd,89,ba,42,19,94,ea,53,b8,e5,61,90,93,a6,70,48,51,60,31,0c,0b,a5,d6,62,d4,\
fa,84,f4,b6,69,1e,57,a0,63,d1,c2,8a,26,90,28,c2,e9,e0,2a,2a,d3,78,eb,68,d0,\
88,9e,e1,33,6d,27,63,da,94,85,1e,67,7f,25,32,9d,a5,39,15,d0,97,37,e1,32,fb,\
e8,d6,ad,a8,52,58,cc,9d,aa,d8,ac,79,0a,99,61,8e,9f,df,22,ec,97,0f,1f,c3,30,\
24,9a,17,6e,ad,a5,8f,77,a1,2a,8f,b9,5b,fe,ab,57,a9,04,8e,73,ba,72,19,a3,1d,\
06,44,71,21,b2,43,87,af,6c,90,76,1e,27,3f,97,db,8b,33,cf,70,43,d1,fa,b0,7a,\
9f,5d,fa,a6,68,cb,ef,1d,cd,a4,4f,b9,0a,70,9f,aa,0f,9c,08,29,98,c7,d0,6e,1a,\
53,34,ad,46,8c,94,94,48,b0,cc,42,e7,df,34,a4,77,54,98,a6,53,d3,5b,f0,87,f3,\
7d,b1,85,51,7d,68,2b,de,da,a7,cb,7b,fd,73,fa,f1,6b,76,a0,b4,22,be,6d,b2,ec,\
36,0e,22,b9,d1,6e,04,de,8a,da,10,1c,38,20,c7,3d,94,b1,fb,01,8b,6b,11,e1,61,\
49,36,4b,25,cc,55,c7,11,53,99,03,f0,bb,3a,c3,b7,77,fd,76,48,9c,63,9c,54,31,\
08,8e,3d,09,04,cb,92,bd,5b,e5,6e,1f,67,78,d9,2d,2e,a4,30,e0,8e,f5,e6,fe,13,\
92,cd,27,d3,b3,a9,12,75,05,b2,22,7d,3c,89,11,bc,be,98,38,ef,01,80,4b,72,e2,\
cc,65,e0,1f,2b,b4,e8,3a,a1,14,99,f5,94,23,e0,32,87,51,6d,fe,d7,12,5e,ff,61,\
f2,27,f2,06,cd,0a,b9,da,28,41,b7,c1,30,07,9c,f5,44,08,a4,2d,15,fa,e4,ac,16,\
a4,ad,38,0a,80,09,3f,0c,73,28,88,c0,7b,a3,44,f7,62,33,13,11,70,4c,3f,aa,87,\
1d,c2,2e,db,af,30,8e,c3,70,db,63,6c,b5,5e,71,78,1c,e3,81,43,32,b1,db,8a,5f,\
20,18,cb,69,cf,4e,22,c2,0d,99,42,77,3c,03,8c,99,31,38,fd,2f,09,d2,b8,63,e2,\
b3,fd,4d,cf,70,31,e0,d5,ce,d6,9f,6a,98,23,62,e8,6d,9b,f3,03,9a,76,fa,48,f8,\
17,28,24,98,31,3e,c9,09,da,b1,ba,23,67,0d,5f,38,11,eb,5f,99,91,34,7b,b8,b4,\
c0,8f,bf,ff,6b,66,0c,f3,a8,70,94,1e,5c,fe,db,c1,33,ca,6b,bb,8f,e5,be,72,1b,\
c6,44,e8,4b,27,b2,47,32,e4,53,0a,1b,1a,e8,33,44,a2,5a,c7,f9,84,bb,ed,ff,44,\
59,99,25,35,be,b3,f7,98,59,6d,d6,98,7a,30,75,99,4d,9b,52,59,27,79,6c,e5,17,\
09,81,2b,20,d7,7b,5c,3e,82,19,10,88,26,1a,23,e3,38,21,a9,91,28,c1,3e,6e,5d,\
98,44,f2,e7,25,5e,8b,dc,0f,86,60,14,92,8a,12,5a,88,9f,18,89,3b,74,f0,8f,35,\
06,f9,c0,e0,b8,25,38,85,5b,7d,9e,b0,7f,56,94,5b,e4,79,be,23,b8,31,54,33,ad,\
68,ab,9c,2e,cd,78,5f,b4,17,54,5f,ec,0b,09,cd,0a,18,05,8a,c0,a7,46,e5,e6,f5,\
ea,d7,d0,ab,b2,54,72,9a,e4,a0,fd,f9,b3,a4,12,e6,0f,c7,2e,d6,aa,d4,f1,33,07,\
a5,bd,03,2b,65,64,dc,8c,6b,7e,a6,3b,3a,76,41,e4,e1,a7,e1,35,42,96,98,a2,53,\
ee,cc,2c,da,fa,e0,77,bf,87,3c,ab,34,ca,77,fa,c8,39,37,03,e7,03,36,3c,1c,cf,\
0d,f9,28,c0,87,d5,24,b1,87,1f,7b,b1,ea,ae,cb,f2,16,72,c2,9f,b1,e9,b2,b5,a4,\
9c,7d,a9,e4,67,60,c1,b3,ff,26,2c,40,88,38,04,bf,84,98,2f,3c,41,3b,88,01,fa,\
5d,a6,f8,76,48,35,30,e7,24,51,9b,8b,a2,df,22,28,34,c2,f5,c7,9c,b8,bf,53,47,\
49,b3,9d,08,61,4c,83,6d,49,34,77,de,26,27,63,e1,15,fc,16,62,5d,2a,32,1c,4e,\
7b,da,ad,8d,ad,72,3e,1f,e3,fa,39,12,07,c9,dd,d7,24,31,ea,0e,00,60,eb,76,33,\
6d,43,7c,b6,dd,f9,1c,54,1f,5e,e7,39,6e,14,fb,8c,ec,c6,0f,40,b1,be,2e,2d,28,\
94,0d,f1,f5,90,e1,e1,6f,16,d8,f7,80,1f,27,78,3a,8a,76,56,58,32,51,c5,0a,ca,\
47,e3,cf,2d,f4,66,86,c9,ca,e5,13,c0,f4,6a,b1,cc,44,cb,02,58,ef,48,b3,d3,16,\
5e,d0,14,57,e5,40,cb,74,76,e8,b8,7f,e4,88,00,17,50,b9,5b,69,fa,bc,c8,28,0a,\
49,0e,17,2d,ac,12,c0,c8,5e,5a,1a,4a,9f,8c,e2,68,ca,a3,0c,c1,ea,51,91,cb,ae,\
0d,ca,82,b1,98,f1,10,e3,a0,b0,86,00,fe,f7,86,4c,16,3b,b6,1d,17,e9,b4,ce,df,\
42,72,95,62,00,3c,97,9b,dc,69,92,a4,1b,46,8f,93,b6,c6,7e,ff,26,64,ae,45,c2,\
47,63,5d,81,ba,35,99,cb,28,c3,87,92,9c,b5,49,29,46,ea,9f,f8,91,f8,61,fc,b8,\
7c,20,4f,53,a5,c4,4f,c6,d7,f4,ca,f2,3b,27,dd,95,8d,53,58,23,8c,08,31,c7,eb,\
c1,3a,29,9c,0c,9f,d1,af,1b,5d,82,e0,22,09,6a,08,53,f7,a1,f7,6c,7b,c3,c5,7a,\
2b,76,a9,d4,6d,2c,01,eb,9b,3a,f6,d7,f6,81,b6,62,2b,30,94,71,e0,2c,1e,ea,c1,\
3b,f1,4a,85,d4,27,86,40,ec,a9,ae,94,42,91,36,bc,16,cc,99,17,20,45,63,f7,39,\
e6,d6,99,81,27,28,17,0b,dc,48,bb,99,be,40,2c,19,f2,94,7e,f2,89,22,c0,66,e5,\
7f,17,0e,9f,85,8a,81,10,f1,d6,5a,c1,90,3b,d3,b5,4b,b8,33,13,19,1d,c6,93,31,\
5a,e1,b1,0d,4a,59,76,0e,91,6c,9a,4e,51,3c,88,a7,0e,ed,1d,4f,05,37,c4,c6,01,\
dd,e0,58,f3,8c,8f,58,8b,aa,3b,dd,d8,d3,c3,8b,c4,cc,ce,36,3d,1e,42,6e,ba,4e,\
a5,d6,c8,b3,7a,9e,8a,14,d5,69,a3,08,51,d3,2a,3e,c6,25,c4,b6,3d,a2,b0,86,90,\
4c,69,74,0e,ab,46,15,46,ce,79,6e,41,ab,4b,f4,47,ee,09,6c,cd,7e,4a,2d,bc,12,\
26,7f,23,00,ea,c0,31,57,fa,54,27,24,af,56,f3,dd,80,04,2f,d2,ae,41,6f,74,d9,\
40,b6,13,e4,03,32,82,8e,82,10,eb,a3,ee,62,9a,93,58,3d,7f,c0,d3,b0,46,86,3f,\
95,4e,a0,76,ee,48,2e,b4,09,11,0c,1b,d7,31,97,65,6f,0a,2c,77,a0,78,e9,a9,85,\
87,d9,04,8b,01,12,e0,50,09,af,c7,39,ba,ca,0a,f5,42,2f,4b,8b,40,a6,ad,1f,e8,\
25,8e,0b,38,4a,fa,fa,27,eb,68,39,b3,20,be,8e,45,25,a6,50,05,c7,3f,1c,3d,b0,\
8f,62,46,2a,75,8d,98,84,08,79,90,88,f2,84,45,40,b3,11,05,1e,e1,a7,41,68,52,\
cd,72,6b,f0,a9,94,ce,64,94,3d,cf,01,5b,c0,66,b5,24,db,2b,0a,fc,e5,ab,37,44,\
14,ec,8c,c6,c8,dd,3b,1c,63,ce,82,09,eb,03,0a,c2,b4,45,d4,87,89,ae,5e,a0,c3,\
c3,74,ea,52,11,b3,33,b8,1e,79,91,7b,9e,06,cf,77,a5,9e,54,d6,21,4a,0f,18,3f,\
49,64,7d,e8,54,2a,3a,f5,5d,48,2c,22,57,05,28,25,3d,12,7f,c0,dd,e0,60,fd,23,\
b7,e0,70,82,2b,85,bf,da,4f,dc,c1,2a,b6,dd,5e,88,b2,b5,9e,f9,4a,c1,e1,ac,64,\
58,70,93,a5,1f,9a,2a,e8,a0,ca,24,b3,68,1d,3e,03,95,7e,48,9d,18,d4,0f,bd,70,\
90,7f,a9,ea,00,14,67,1a,1d,44,d3,15,0a,74,d1,87,10,c7,f1,6d,b5,05,0c,0e,1f,\
6b,ad,51,8a,7c,d1,f1,1e,f1,9a,64,46,92,73,07,a3,fe,9a,b4,66,8c,9a,13,9f,db,\
74,74,41,b8,37,a3,a0,35,5e,9f,4b,b3,63,32,a1,4f,e1,f4,cb,71,30,67,4b,7d,fa,\
5c,2b,b4,16,11,72,36,79,fb,93,2b,22,ba,26,69,d5,8d,6b,73,c5,47,0d,f6,4e,f2,\
2c,7e,9e,48,c5,b3,f5,4e,5c,16,25,e5,f5,7b,b8,8e,0b,31,8e,01,3a,7e,3b,39,d4,\
a9,ed,67,eb,2f,8f,e0,aa,68,d3,cf,83,7a,ae,49,60,25,b6,56,77,ea,fd,eb,e5,b2,\
a4,c4,0a,d2,64,13,78,c5,28,33,8e,24,5a,53,0c,dd,e6,2f,3b,1c,fb,a5,81,23,90,\
9e,9c,f5,29,14,0f,49,01,a6,fd,ae,6b,74,5c,67,56,ae,88,6a,7f,18,99,c0,48,34,\
9e,22,46,24,9b,4f,68,be,1e,ea,47,c9,e8,e3,d5,c2,d9,c2,3c,64,78,fa,42,f1,42,\
1b,de,1c,25,c7,ae,be,73,53,e0,91,e2,62,b0,69,64,f5,70,ae,2d,56,51,8f,b2,b8,\
53,45,ca,f0,c1,ae,3a,7d,6b,58,23,28,d4,d8,e2,7f,dd,15,1e,3c,68,77,40,98,9b,\
3a,c3,e2,30,83,bf,8b,65,57,a1,30,5f,e2,35,53,44,db,dc,bf,02,1e,15,fe,0c,fb,\
23,d9,9d,7c,f0,ae,af,6c,43,13,83,3b,32,5e,b2,e6,78,b2,17,5b,d5,5e,b2,6d,6c,\
30,d6,9c,52,82,a7,e8,64,77,3e,10,6b,1f,e4,4b,55,eb,ca,e0,30,04,4f,7d,36,d2,\
34,9d,ae,96,f0,cf,a6,df,21,13,79,8b,14,04,e4,80,cd,15,0f,18,ef,b6,4c,79,7f,\
ce,78,bc,b6,aa,ec,96,7a,8d,ab,ae,89,40,69,cd,af,7e,80,5f,cd,ca,be,37,64,20,\
41,8d,c0,b0,ad,e5,d2,1f,fa,4e,0e,df,98,f3,a2,21,7e,7b,40,3a,7d,49,18,83,41,\
00,15,8e,70,c9,7f,b8,9e,9d,16,9c,a7,d0,33,c4,ad,49,90,ca,e8,99,42,35,94,04,\
0b,47,60,b3,14,4a,91,15,5a,9d,f5,cc,aa,c2,3e,fd,ab,e1,1f,79,d1,2b,3e,41,dc,\
c7,41,90,71,b9,83,06,92,59,50,87,65,e9,c8,02,4d,73,55,ad,8e,df,d5,1a,f8,30,\
ee,95,42,f0,6e,8e,a2,24,44,63,c7,33,06,a9,fd,97,43,0c,b4,f8,a7,e4,09,a3,7d,\
fb,ad,07,73,5e,4c,71,9b,00,4b,66,9d,26,3b,e0,1d,96,87,8d,22,33,b8,bc,eb,47,\
ee,b7,8c,66,fb,fc,d9,bd,7f,a6,dc,72,c6,5b,61,3b,3c,a5,8b,ad,c8,69,e9,29,93,\
47,b0,4c,fc,ff,58,d0,8a,12,05,67,5e,8b,2f,f2,1b,d3,50,a6,90,54,50,57,66,84,\
2e,63,31,08,43,ea,31,f9,1f,45,85,6b,65,2c,7b,67,83,ad,c5,35,2a,cf,49,1a,d1,\
63,07,ce,cf,bd,9a,32,6f,c9,a7,16,f5,85,bd,57,0b,1e,e7,0c,6d,b8,27,a1,4f,60,\
e1,4a,61,0c,78,5f,d7,8a,a7,38,fc,08,6e,26,dc,5d,79,59,17,c6,f1,63,f7,86,55,\
bc,57,93,f9,de,3f,55,71,cd,38,cc,97,19,ec,0f,9f,68,28,25,e8,b5,cd,c7,02,84,\
3f,4d,b3,83,dd,c2,25,98,9e,c7,05,ec,b9,c2,c7,d5,05,8e,2b,34,24,33,c2,de,8c,\
a3,47,9c,87,2d,88,9f,3f,0b,8a,7a,63,ba,f0,2d,a3,33,2c,77,cf,a7,86,6e,24,a8,\
c7,90,80,83,31,04,a5,c3,b1,a8,8c,c2,22,b7,f5,8d,cd,ed,ea,63,0f,c5,61,4f,1e,\
6f,9c,66,e3,28,2a,a8,4c,f1,91,51,20,e6,f5,d9,fe,2d,76,bb,f9,74,3b,ec,a1,00,\
82,fe,09,75,fe,90,82,5c,7b,c9,db,f7,3e,4c,3c,be,4f,0a,c4,dd,b4,f1,30,b5,1e,\
88,f9,9f,ec,1c,f2,2d,74,a6,f5,96,ec,18,da,ac,e9,cc,c2,15,ac,4b,7d,75,67,ea,\
13,8a,72,71,fe,a5,dd,9c,9e,ee,5a,55,a7,f7,11,b3,f4,d5,8e,1d,14,22,fb,6e,83,\
d7,c2,b7,b6,f3,a1,82,7e,07,a7,69,ff,db,86,a2,4d,63,04,7b,69,2c,6c,0b,16,c8,\
8f,2c,4e,24,35,a3,7e,72,01,dc,83,3b,e8,bd,14,66,fc,f2,56,7d,9d,44,3f,bf,23,\
b9,fd,41,c2,ea,c7,cf,83,cd,41,a2,e5,37,03,01,ac,fd,e3,8b,ca,9b,9a,12,12,29,\
2a,34,f8,94,d7,78,44,04,2a,6a,21,67,3e,e2,1a,3f,bb,cb,a0,55,2a,f5,aa,45,28,\
41,7c,5c,ad,39,68,c8,14,ca,21,d8,85,d2,df,06,bd,19,45,62,ea,a3,b6,18,e3,88,\
7c,ac,ea,44,4b,e4,54,32,b0,b5,68,7c,c7,2d,66,40,7a,cd,34,a6,95,4e,4c,d7,2d,\
1e,6c,72,7b,dd,65,fb,6c,eb,52,51,68,4c,be,65,13,44,4f,20,d8,e1,c7,1f,cb,15,\
a7,5a,d7,58,c0,4a,f2,ed,00,1d,98,25,da,2e,02,38,dc,e8,3d,c1,ea,b4,5f,a0,d8,\
38,7e,cd,30,1c,c0,97,7b,d2,f2,37,4b,ee,0b,a1,b0,f7,36,c8,63,3f,5b,d4,f2,36,\
64,2b,de,bb,1e,4a,ad,0b,ee,ac,0e,5c,c2,1c,a2,86,0f,22,b3,7f,58,0f,0b,68,bd,\
ef,86,4c,c3,16,91,38,82,a3,51,21,9b,7d,e2,c3,6c,19,d9,3d,b6,e6,42,cf,69,34,\
45,8f,db,ee,b1,ae,1a,35,29,34,3a,1a,09,04,2c,af,2a,ea,7c,cf,67,41,ed,fd,ac,\
63,ee,a1,6c,82,14,49,a8,c8,c6,0a,a9,1d,8d,d0,d2,6d,08,88,cd,dc,a6,30,c0,41,\
dc,10,cb,6b,01,9c,7f,a1,6f,19,48,be,ac,cd,c1,3f,89,31,08,19,d2,43,8e,86,2f,\
92,3f,24,f2,6e,5b,7d,93,92,e5,74,1c,ae,47,33,26,64,74,0d,55,d6,a1,55,2a,7b,\
4f,30,0b,cf,25,0b,39,26,28,f8,ad,56,a9,72,f3,23,35,a7,32,59,85,21,1b,2c,40,\
19,c5,e9,d0,39,48,d8,f0,3e,06,87,58,0f,0b,cf,11,4c,c1,bc,cf,e0,45,42,17,d1,\
fd,f6,b6,78,e9,f0,e8,83,11,fa,33,18,ca,44,36,86,23,ac,34,82,bf,b9,64,a4,3c,\
44,a4,d6,63,af,16,58,fa,1f,af,1c,45,d8,09,65,b3,48,84,30,1e,e9,04,7c,7a,68,\
e5,e5,5d,7b,c0,8b,a7,81,30,1a,4b,f3,0f,97,43,ce,1f,3f,2e,ca,d0,fc,2a,a9,b3,\
45,e6,30,8f,9a,ee,be,28,a3,60,23,eb,a8,8b,36,c5,7c,65,fe,85,c5,5b,90,d8,bc,\
05,d5,2f,df,2c,58,b2,7f,ac,ae,bb,2f,5b,08,3f,60,95,a9,17,22,ff,92,52,54,04,\
1c,24,d3,53,40,9b,ee,db,1a,cd,c4,e7,d3,3a,c9,a0,12,9f,18,6e,bd,7a,74,56,5d,\
13,2a,6a,dc,e8,16,46,11,46,ec,20,ca,2e,9c,2b,07,30,08,f1,fa,8a,9e,90,2b,9a,\
ad,62,57,e3,ad,41,55,6b,ce,0d,8e,65,4c,bf,d7,48,4c,e8,db,bd,a6,a1,c5,7d,c1,\
b3,91,f8,8e,3d,96,55,3b,c5,ae,e0,21,a2,ee,87,7f,a9,27,8b,c5,b0,59,99,ce,37,\
49,ac,70,2d,af,bb,45,9b,ef,9a,20,98,a7,fa,fc,a4,60,7f,91,30,3b,64,cb,de,c0,\
15,48,93,d6,b7,22,53,89,b2,52,26,eb,4a,36,07,37,d3,90,0d,b9,d9,41,9d,05,62,\
2b,a4,8b,3a,da,4e,fe,db,f5,93,f8,19,f9,78,7b,2b,1a,b0,98,3d,6b,c7,6a,1b,2f,\
b5,a0,1b,31,27,8c,01,11,4a,89,75,b3,13,50,be,b6,04,22,2e,86,78,87,b7,2a,1b,\
90,5d,ad,59,4e,d5,33,96,ac,54,f4,7a,a3,e5,fa,4d,a3,13,4f,7a,85,31,78,02,42,\
dc,f7,b6,a7,62,15,8d,77,4e,f9,6b,10,00,f1,12,15,50,05,8b,04,7d,61,5f,cf,85,\
a5,0f,db,3d,8f,3c,95,95,73,09,80,f3,70,5c,ea,5b,54,2c,0f,78,30,34,e4,9e,8e,\
8c,57,4f,32,f7,73,19,56,0a,23,4f,7f,4a,b7,73,a4,bd,52,6a,a5,a1,49,e2,36,04,\
5e,da,7b,35,2a,ae,99,9c,44,a4,48,27,52,18,47,76,cf,d0,1c,3f,7f,78,ad,a6,00,\
03,7e,16,da,e5,50,8f,eb,7f,61,f4,d1,04,bf,fe,a2,e4,79,0f,de,2f,75,57,e0,39,\
57,7d,21,13,ed,dc,65,e9,a4,18,32,7b,5a,21,d0,0a,e4,1f,e4,de,db,b1,d1,f3,aa,\
58,15,92,db,ce,35,d3,d9,5d,7c,12,c5,66,ae,76,3a,8c,36,53,cd,e5,f8,24,48,2f,\
38,1e,fe,7f,d7,a5,46,70,0d,a7,a3,7a,d6,ac,ea,16,d7,79,f6,35,af,7b,c2,77,ac,\
bf,ae,b1,46,a6,47,e9,e4,38,24,c6,a2,c9,c5,55,11,72,29,6b,de,b5,13,95,b5,52,\
42,1b,e6,bd,af,05,05,28,8e,d0,35,50,7b,1a,3e,b0,b7,aa,b9,61,21,2f,c8,0e,3e,\
ec,e4,1a,28,5d,6d,51,c5,b6,e7,35,4a,a8,7a,00,33,f6,bd,1f,6c,d3,de,04,7d,9a,\
44,09,b4,98,fd,16,30,d6,bc,60,67,29,68,3c,58,0e,d5,38,ce,6e,c0,79,75,e3,6a,\
6d,21,9f,6f,89,ba,c2,46,8a,7e,b1,4a,a3,9a,bb,9e,4b,9f,79,f5,f9,ac,b2,b0,b4,\
bc,33,93,f9,4e,b6,42,34,88,26,22,59,f5,a4,ff,20,c8,64,fb,3c,19,de,55,87,da,\
08,f7,c9,65,42,0f,7e,01,ea,1f,a5,b5,90,82,df,2c,33,b5,18,6d,ff,4f,da,bb,b4,\
db,fc,79,cf,07,28,14,58,21,80,05,6a,b0,8b,06,3a,94,93,32,05,e5,44,ec,75,ba,\
55,ce,a1,ab,83,f7,0a,19,50,ae,61,29,f8,6c,3b,97,0e,9b,f5,32,5d,07,05,b0,10,\
b7,72,13,84,3c,5a,b0,02,5c,26,d9,84,ea,4a,7e,b7,3d,66,3e,54,e6,92,02,ab,14,\
db,61,af,f0,6e,5a,86,05,b1,5b,0a,64,7c,42,72,f4,6a,56,5c,57,79,2f,11,32,1d,\
03,e3,da,fe,51,69,5e,9f,5c,77,bf,01,9e,f2,cc,a0,89,28,34,86,9f,9e,37,4c,8b,\
bc,b8,4d,fd,bc,ca,ec,57,a2,ca,ff,64,a1,9f,c4,91,97,bd,e3,32,78,ea,6b,c8,c5,\
64,4b,b7,d3,23,a1,7d,56,76,78,e0,17,92,4a,b2,02,c0,a2,8f,b7,5c,97,4d,02,f3,\
33,73,3d,44,ae,b9,1a,cb,5c,1b,e9,24,20,a7,37,07,d0,72,60,e2,b6,cb,dd,a9,c3,\
ae,1f,bb,50,e8,5b,cf,c3,d6,1a,f0,23,30,b1,dd,a9,66,8e,a8,a0,23,ef,5d,bc,69,\
a0,39,1e,96,6c,e5,df,a2,44,22,10,8b,44,31,72,fd,3c,a0,2f,f3,1b,2c,a6,73,40,\
87,81,ca,23,31,82,21,8c,f2,c9,4f,9d,ad,4e,ab,d2,1f,03,dc,46,0f,61,53,e9,e4,\
23,d0,6d,5b,25,49,1f,d7,3e,1b,64,df,06,0b
"rkeysecu"=hex:a8,a1,aa,9e,c4,be,3e,69,17,f2,60,08,67,b4,3b,4f
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•A~*NULL*]
@Security="Inherited"
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NUL
L*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_LOCAL_MACHINE\software\Sigmatel\GlobalState]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=Administrators
@Denied: (Full) (Guests)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrator)
@Allowed: (B 1 2 3 4 5) (S-1-5-4)
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Kaos Inc\System Utilities\Ad-Aware\aawservice.exe
c:\windows\system32\scardsvr.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Crypserv.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
c:\program files\Microsoft SQL Server\MSSQL$SURADOCRMOFFLINE\Binn\sqlservr.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\java.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\dllhost.exe
c:\program files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\msdtc.exe
.
**************************************************************************
.
Completion time: 2008-12-31 19:53:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-01 01:53:20
ComboFix2.txt 2008-12-30 23:08:24
Pre-Run: 38,608,060,416 bytes free
Post-Run: 38,738,853,888 bytes free
544 — E O F — 2008-12-15 15:36:18