It seems if you leave the computer untouched for awhile it will freeze up.
This website would create a lot of popups before: But right now there doesn't seem to be any so far.
http://sagipsul.com/go/?cmp=vm_mg_juan&…p;cl=profiling4
ComboFix 09-01-02.01 - Jonathan 2009-01-03 14:23:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.248 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jonathan\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: AVG 7.5.552 *On-access scanning enabled* (Updated)
FW: ZoneAlarm Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Jonathan\Application Data\gadcom
c:\documents and settings\Jonathan\Application Data\gadcom\gadcom.exe
c:\documents and settings\Jonathan\Application Data\inst.exe
c:\documents and settings\Jonathan\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\system32\dslcunrp.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\giwqmjoq.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\iifDutSI.dll
c:\windows\system32\ishjtyxk.ini
c:\windows\system32\jraawjds.dll
c:\windows\system32\jwhyji.dll
c:\windows\system32\luienv.dll
c:\windows\system32\NUCIknpo.ini
c:\windows\system32\NUCIknpo.ini2
c:\windows\system32\opnkhgEu.dll
c:\windows\system32\opnkICUN.dll
c:\windows\system32\Process.exe
c:\windows\system32\prunnet.exe
c:\windows\system32\sbkjdqub.dll
c:\windows\system32\sdjwaarj.ini
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\voypwmpp.dll
c:\windows\system32\vtcbjupk.ini
c:\windows\system32\wcoezt.dll
c:\windows\system32\WS2Fix.exe
c:\windows\system32\xhptno.dll
—– BITS: Possible infected sites —–
hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2008-12-03 to 2009-01-03 )))))))))))))))))))))))))))))))
.
2008-12-25 21:38 . 2008-12-25 21:50 d——– C:\RENDITION
2008-12-23 15:47 . 2008-12-23 15:47 d——– C:\VundoFix Backups
2008-12-22 15:04 . 2008-12-22 15:04 d——– c:\program files\Trend Micro
2008-12-18 21:32 . 2008-12-18 21:33 d——– c:\program files\DVDFab 5
2008-12-18 21:32 . 2008-12-18 21:33 d——– c:\documents and settings\Jonathan\Application Data\Vso
2008-12-18 21:32 . 2008-12-18 21:32 47,360 –a—— c:\windows\system32\drivers\pcouffin.sys
2008-12-18 21:32 . 2008-12-18 21:32 47,360 –a—— c:\documents and settings\Jonathan\Application Data\pcouffin.sys
2008-12-17 16:40 . 2008-12-17 16:40 d——– c:\program files\Activision
2008-12-17 03:00 . 2008-12-17 03:00 d——– c:\program files\MSXML 6.0
2008-12-15 12:10 . 2008-12-15 12:10 d——– c:\documents and settings\All Users\Application Data\Fallout3
2008-12-15 12:09 . 2008-12-15 12:09 d——– c:\windows\Logs
2008-12-15 12:09 . 2007-10-12 15:14 3,734,536 –a—— c:\windows\system32\d3dx9_36.dll
2008-12-15 12:09 . 2007-07-19 18:14 3,727,720 –a—— c:\windows\system32\d3dx9_35.dll
2008-12-15 12:09 . 2007-10-12 15:14 1,374,232 –a—— c:\windows\system32\D3DCompiler_36.dll
2008-12-15 12:09 . 2007-07-19 18:14 1,358,192 –a—— c:\windows\system32\D3DCompiler_35.dll
2008-12-15 12:09 . 2007-10-02 09:56 444,776 –a—— c:\windows\system32\d3dx10_36.dll
2008-12-15 12:09 . 2007-07-19 18:14 444,776 –a—— c:\windows\system32\d3dx10_35.dll
2008-12-15 12:09 . 2007-07-20 00:57 267,112 –a—— c:\windows\system32\xactengine2_9.dll
2008-12-15 12:08 . 2008-12-15 12:08 d——– c:\program files\MSBuild
2008-12-15 12:05 . 2008-12-15 12:05 d——– c:\windows\system32\XPSViewer
2008-12-15 12:05 . 2008-12-15 12:05 d——– c:\program files\Reference Assemblies
2008-12-15 12:04 . 2006-06-29 13:07 14,048 –a—— c:\windows\system32\spmsg2.dll
2008-12-15 12:01 . 2008-12-15 12:01 d——– c:\windows\system32\xlive
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-03 19:20 ——— d—–w c:\documents and settings\Jonathan\Application Data\LimeWire
2008-12-26 02:37 ——— d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-21 04:49 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-21 04:36 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2008-12-20 19:54 ——— d—–w c:\documents and settings\Jonathan\Application Data\AVG7
2008-12-19 02:30 ——— d—–w c:\documents and settings\Jonathan\Application Data\uTorrent
2008-12-17 21:49 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-15 17:10 ——— d—–w c:\program files\Bethesda Softworks
2008-12-15 13:00 ——— d—–w c:\documents and settings\Other People\Application Data\AVG7
2008-12-14 18:15 ——— d—–w c:\program files\SystemRequirementsLab
2008-12-14 18:14 ——— d—–w c:\documents and settings\Jonathan\Application Data\SystemRequirementsLab
2008-12-04 00:52 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-04 00:52 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2008-11-13 02:27 ——— d—–w c:\program files\LimeWire
2008-11-04 03:06 ——— d—–w c:\program files\MSECache
2008-12-19 03:04 67,688 —-a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 03:04 54,368 —-a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 03:04 34,944 —-a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 03:04 46,712 —-a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 03:04 172,136 —-a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-08-15 18:59 41,924,640 –sha-w c:\windows\system32\drivers\fidbox.dat
.
——- Sigcheck ——-
2008-04-13 19:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2007-12-23 13:29 502272 6225f14b8ce08ccba8b25ad27843c674 c:\windows\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2007-12-19 486856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-06-23 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-06-23 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-06-23 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-10-17 590848]
"VX3000"="c:\windows\vVX3000.exe" [2006-12-05 707360]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-12 275800]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-06 200704]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 86016]
"SMSERIAL"="sm56hlpr.exe" [2005-06-06 c:\windows\sm56hlpr.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2008-05-02 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2007-12-23 219136]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=luienv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0lsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEARMP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mass Effect\\Binaries\\MassEffect.exe"=
"c:\\Program Files\\Mass Effect\\MassEffectLauncher.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Westwood\\RA2\\game.exe"=
"c:\\Westwood\\RA2\\Ra2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R3 EloBus;Elobus Filter Driver;c:\windows\system32\drivers\EloBus.sys [2007-12-26 14336]
R3 EloSer;Elo Serial Driver;c:\windows\system32\drivers\EloSer.Sys [2007-12-26 108672]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7bde015-6a89-11dd-9004-001921191c94}]
\Shell\AutoRun\command - l:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2007-12-25 c:\windows\Tasks\Microsoft_Hardware_Launch_setup_exe.job
- H:\setup.exe [2000-09-20 18:15]
2009-01-03 c:\windows\Tasks\xxrlvfjg.job
- c:\windows\system32\rundll32.exe [2004-08-04 07:00]
.
- - - - ORPHANS REMOVED - - - -
BHO-{408249a2-914c-4c09-b843-bdef011b9713} - c:\windows\system32\luienv.dll
BHO-{FB371D57-038A-46B2-B560-30C298D8D34D} - c:\windows\system32\opnkICUN.dll
HKCU-Run-prunnet - c:\windows\system32\prunnet.exe
HKLM-Run-prunnet - c:\windows\system32\prunnet.exe
Notify-byXNeFww - byXNeFww.dll
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\qz3q53pm.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-veoh&p=
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-veoh&p=
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-03 14:31:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-2000478354-261478967-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*NULL*]
"??"=hex:1b,af,4c,f5,d7,6a,c7,47,b8,fd,8f,9b,23,59,58,e3,d2,99,f7,d1,6e,98,89,\
ba,42,bb,66,57,f2,d6,dd,63,cd,a2,d1,df,24,af,c6,d7,d3,cb,e8,ad,7c,fa,44,90,\
44,e2,12,26,7c,4c,dc,b3,8c,b9,8e,e8,ab,5c,85,2f,3b,aa,dc,e4,27,80,76,1e,6e,\
05,b3,dd,84,79,26,2c,b5,ff,43,49,bd,4a,45,c1,06,35,ae,19,c0,52,47,17,e0,03,\
59,11,74,d2,d5,e8,b0,33,14,2e,fc,66,f7,e7,3a,fb,c8,f5,df,bd,d2,38,c1,af,13,\
33,cb,6d,8d,b8,9f,2c,60,b5,33,c3,58,9d,59,e5,23,b5,4b,46,a9,8b,13,e4,34,17,\
a3,53,2d,42,f5,9d,ea,a8,33,5b,ba,f7,8b,79,ae,16,67,27,7c,f3,18,cf,b6,b7,cf,\
af,52,69,8c,0c,67,ef,b5,a8,53,d4,b4,ae,2d,de,2b,8a,62,2c,ef,9a,07,87,92,f5,\
7e,c8,fb,46,4c,60,bf,da,ed,6e,af,49,02,06,8f,96,4d,91,8b,63,9b,eb,a0,ff,38,\
a4,1e,d5,2b,6b,6b,7a,a2,4e,96,e0,de,c6,bb,a7,5f,ee,9b,83,f3,d1,a4,6a,65,49,\
26,41,d5,cc,00,80,46,52,9a,d7,81,97,7a,3a,d4,df,b6,9c,00,44,8b,da,a7,a5,e7,\
a9,a0,81,87,9b,f6,99,a7,4c,3d,e1,3e,ed,36,f9,e4,50,57,b3,07,23,4e,2c,6e,bf,\
e2,a6,3d,d8,b4,ef,2e,64,a7,55,13,e3,45,38,1c,2b,70,42,5a,9d,42,81,d2,f5,d1,\
35,d7,8b,14,ad,9e,dd,35,55,8e,fa,05,32,74,33,d7,13,8c,a1,ee,cc,97,67,7f,91,\
04,19,01,f4,07,38,12,75,1f,23,40,3b,fa,2b,f9,b7,a9,fd,33,dd,45,e6,0e,38,dc,\
09,6d,ad,5d,58,f0,a2,da,64,d1,21,e6,a8,05,5a,a0,51,8e,e2,82,1f,b8,41,8b,e7,\
1e,f0,94,19,80,9b,9a,f1,69,9b,aa,f3,21,7e,e1,b1,53,dc,34,2f,4b,1a,24,03,43,\
4c,bc,88,34,77,27,51,1d,92,be,87,43,6a,a7,44,3d,bb,55,cf,ff,02,d2,cd,9a,23,\
f0,65,92,57,b2,3f,7d,0e,16,05,60,dd,19,0b,1e,98,9b,bd,a5,0e,7b,54,20,3e,16,\
0b,7a,54,f2,c8,45,9b,91,f4,14,dc,1a,9f,28,ee,84,fe,12,d4,75,15,10,0b,92,05,\
30,24,41,4a,a7,72,b0,f0,cb,02,8b,e1,23,80,41,5b,4c,20,99,b2,14,60,6c,77,a0,\
45,49,b5,f6,c6,0f,a2,69,d7,af,ec,f4,28,06,53,bd,0b,c0,48,8c,d3,cd,82,91,57,\
38,a6,ad,5f,b7,0e,55,cb,45,ec,46,ed,dd,9f,f3,0b,28,9b,61,14,86,dc,17,35,d8,\
a4,9f,5d,4f,68,64,17,1e,37,e4,a1,12,5d,61,39,f2,5b,88,02,ef,93,94,91,7f,11,\
d4,48,92,31,67,1c,c9,2d,96,5c,84,dc,53,22,ab,71,23,41,ac,b1,5f,b7,39,d2,6c,\
49,73,dc,f5,0f,1c,8d,8c,25,58,7d,e1,00,f6,64,c8,a0,00,14,2e,d0,9b,d1,99,a5,\
ac,54,ae,d8,88,a8,34,f1,8a,6c,3f,0e,e2,2c,c0,4d,7c,d1,81,21,9f,47,c1,9c,94,\
eb,72,96,ec,30,6f,d5,0e,a9,54,01,65,3e,34,a8,da,26,25,64,ad,84,f3,c7,7e,99,\
07,29,1c,3b,fb,2c,2a,ec,75,88,bd,db,8e,d4,31,c9,a1,28,ea,4c,50,f4,34,f5,89,\
56,ea,67,ea,f1,ab,14,52,d0,a3,8e,3d,d5,a2,e6,ee,2f,9d,b2,45,63,cf,a2,8d,c2,\
e9,75,de,b4,63,86,b2,2f,8f,43,96,f9,cc,97,5e,3d,f6,05,49,bf,c9,b4,ed,d9,85,\
06,c3,03,e8,93,62,32,16,95,a6,41,fb,d2,1a,d3,d3,7e,10,22,08,9e,f1,41,4b,e1,\
f6,85,e3,04,ed,4c,f4,f6,70,0a,6d,8c,ed,0d,1a,89,7b,6a,d0,aa,11,57,60,2d,be,\
82,66,e5,90,8e,06,d6,98,f4,ef,ef,80,91,ad,84,a8,a0,ef,13,56,bb,ba,b6,7c,51,\
e8,07,6e,17,4b,73,8b,fa,58,a8,71,de,6f,41,af,4f,31,5a,96,79,c4,22,15,b6,fe,\
58,29,42,1e,d0,d1,ef,69,34,0d,f5,22,b4,d3,fc,e2,ea,68,a0,b2,fb,cc,e1,b3,aa,\
ef,6a,1c,65,bc,46,8d,43,26,69,01,c4,db,af,78,30,20,69,ae,24,2e,8f,9a,5e,5a,\
28,44,9a,7c,7b,97,1c,d4,15,b4,5a,41,b4,63,10,9a,82,d1,5f,3d,44,71,fe,21,23,\
00,a4,1e,9d,63,0a,0f,c3,dd,a5,3d,05,d2,8b,c5,64,84,79,eb,56,03,35,d1,64,c2,\
50,a3,3a,06,c2,4b,8c,fc,c4,b7,37,bd,ea,18,99,2d,10,8a,3c,79,c8,2e,21,3d,47,\
c1,40,75,2c,38,fb,1f,f3,2d,a7,43,6b,ef,68,a9,70,25,c1,ec,36,38,83,2a,62,9c,\
44,13,06,47,01,34,33,c3,d4,b5,68,69,2c,05,64,34,2e,77,3c,b1,f7,8f,2b,5f,45,\
6d,3d,bb,80,35,dd,9e,71,03,c0,29,e2,ba,97,7d,36,70,a8,6a,62,52,7d,72,ff,e8,\
bf,e6,fd,e6,52,61,5d,2b,42,e1,f6,eb,50,5c,61,07,ec,69,63,f3,01,76,86,ef,8b,\
ab,c7,66,b0,b0,b2,7c,3b,1a,85,6b,7e,f6,74,91,da,c5,ea,72,d3,c3,f4,e3,3c,94,\
ba,ef,77,54,48,89,04,ff,b8,14,2c,22,77,19,41,f4,89,7a,e2,2c,fa,4a,e1,9c,df,\
8d,a4,19,85,d5,9f,e4,7a,ea,81,4f,6f,e0,77,25,1a,2b,37,f3,0b,b5,d0,b6,60,c6,\
31,80,93,40,1a,b8,51,99,b6,4e,d6,e0,16,b3,2b,93,e7,0e,e8,05,40,d5,82,0f,66,\
f2,e5,17,ad,71,99,0d,bd,2d,e2,0f,ef,68,60,22,2b,67,3b,85,34,e0,53,46,0b,32,\
45,d4,79,2a,8e,a1,ca,23,a3,71,ea,cd,d7,5c,12,42,4e,be,b6,0c,02,e0,9d,c9,a1,\
86,e9,c5,6b,5c,c4,4b,33,a8,92,08,da,d8,c6,09,7c,51,aa,56,d7,54,ad,f6,2e,57,\
c5,6a,e0,aa,9d,c6,8f,c7,58,51,05,9f,99,81,ec,59,5e,8f,12,94,93,94,64,e9,98,\
a6,94,e9
"??"=hex:44,03,2a,46,4a,7a,27,f1,11,37,33,ec,fe,cd,00,ac
[HKEY_USERS\S-1-5-21-2000478354-261478967-725345543-1003\Software\SecuROM\License information*NULL*]
"datasecu"=hex:75,7a,67,c1,c6,75,0d,3f,90,1c,d2,69,91,56,75,f7,31,2b,49,09,e3,\
74,47,62,02,b1,d6,75,0c,21,4b,1a,75,01,0e,5c,6c,0f,10,bd,ce,71,c9,85,01,a7,\
62,67,71,f8,b6,8e,3c,f8,dd,58,1e,ea,c5,18,ad,e7,2f,7f,13,56,02,84,ae,ed,65,\
aa,f8,70,cd,cc,95,20,bb,0e,1b,22,bd,55,ef,e2,ae,d2,ba,f2,73,06,27,03,77,db,\
d3,c7,b1,7d,8e,ce,ea,20,88,0d,83,53,2e,98,c5,63,db,ff,80,80,eb,78,a1,36,46,\
f6,f7,25,b3,fa,eb,f1,18,b2,f7,18,20,4c,94,12,12,f9,db,4c,62,51,d9,fa,08,e5,\
6a,05,fc,44,05,d2,bc,5d,54,06,b5,2a,1a,86,4a,aa,35,24,61,7c,e9,3b,ef,eb,37,\
16,37,00,4c,c8,d5,99,3d,f1,a8,99,14,40,e1,2c,c4,28,26,b1,82,52,2e,31,71,30,\
87,e6,fd,9a,ff,ea,be,7b,fa,d3,c8,f0,d0,aa,65,50,f6,a7,34,35,51,cc,02,57,5f,\
03,63,5f,85,4c,2f,cb,4d,a9,39,9d,20,b7,78,53,b3,c1,31,d5,cb,cd,17,6e,c6,ca,\
a8,72,f6,33,a4,12,2b,23,21,9d,05,9e,02,c2,70,c6,0f,5b,a7,4f,79,90,54,2a,a7,\
0a,2e,36,7c,e3,7c,54,c6,94,46,f0,f9,78,6c,23,b0,5d,b9,6a,00,4b,e2,62,07,cb,\
49,c6,3b,3e,d2,48,e3,5c,ff,d6,dc,4d,d0,e0,51,b7,11,ed,82,80,10,9e,a1,cf,5a,\
9e,30,cc,05,0c,c8,c5,8f,dc,3d,f0,5e,09,4c,7f,31,11,4c,40,2a,d5,d1,e0,45,6f,\
a2,14,ba,d6,97,6e,af,14,30,41,e7,34,72,98,d2,ec,70,46,ed,76,32,c5,34,58,81,\
a7,48,02,4b,79,0c,58,e9,bc,5f,16,a6,eb,44,74,5b,23,3d,55,9b,9f,37,62,87,16,\
00,0d,7e,b6,7c,ca,b3,69,67,83,e2,46,81,59,e4,ec,4d,18,12,36,83,6c,73,b8,82,\
40,19,4b,87,32,dd,a7,c9,e0,d3,be,88,e9,87,6d,e7,7a,a1,9b,73,3a,b7,03,31,b0,\
d5,9b,af,b9,33,f0,82,be,df,5c,ee,1e,c8,50,8a,ae,97,5f,95,25,6e,9f,1c,7e,b1,\
39,52,bf,5b,99,b9,33,9c,f7,fd,d6,cd,f9,6b,c6,a8,3c,bc,d3,8d,d5,ce,70,3d,5f,\
96,a6,11,9e,b7,bf,a6,28,4e,b1,ef,eb,ad,7e,da,da,3b,6c,58,fe,3f,76,87,16,45,\
01,07,39,ad,8e,6e,b7,7a,98,6d,25,36,b9,8f,aa,e4,3c,c1,0a,41,29,f4,a1,97,a8,\
fd,c1,a1,5c,68,2c,f0,df,22,64,2a,c2,45,ff,0e,20,d5,79,30,f5,dd,05,63,17,a8,\
f8,bf,a6,31,0f,d3,02,54,49,5a,64,7b,53,ec,92,59,81,3f,f8,db,e9,bb,ca,52,6f,\
dc,56,82,19,23,8c,ae,36,15,1c,5f,d9,33,8e,4a,48,ca,16,05,d4,05,7e,20,9d,31,\
d6,ec,bd,0b,10,42,dd,60,13,c1,83,e8,c7,53,25,30,d1,98,ff,2c,67,5e,9a,1c,b0,\
db,e4,b0,84,9d,28,e3,de,f8,3e,55,86,b8,ef,58,7e,e7,c9,f6,97,99,b7,55,23,67,\
8e,6a,cf,92,6e,9f,ab,84,41,41,27,50,fa,bb,0f,d2,61,9b,b6,e9,e9,18,be,83,7a,\
05,71,1e,f4,e6,85,df,49,c0,0d,9c,c2,5c,4c,68,7d,4f,95,bc,fc,68,ce,09,13,48,\
b6,eb,0d,14,78,45,86,d0,44,fe,a8,1c,c1,22,93,c5,ad,31,02,27,cf,7e,de,ee,b5,\
bc,49,88,47,f9,7e,1e,19,50,3b,82,63,f3,a2,34,2b,5b,be,b0,cc,c9,eb,42,ed,46,\
1a,7c,b7,cc,2b,55,2a,7f,de,03,35,8f,34,d2,10,57,2d,e6,88,26,bc,cd,27,a3,6c,\
4c,5d,a0,d1,62,6f,fe,6c,b5,5f,dd,4d,47,06,ac,08,fd,f6,5f,32,86,9a,27,f7,08,\
1c,b7,24,0e,a4,11,eb,a3,ca,d2,6e,68,77,ec,71,52,b7,41,af,10,01,77,b6,e3,de,\
59,89,73,66,7d,c8,42,b0,6b,ce,45,fa,05,9a,dd,50,dd,7c,17,c6,e9,9e,eb,c2,84,\
dc,29,d4,ca,00,48,6c,b0,54,f6,9c,a6,8a,11,a6,06,87,ec,9a,3c,a0,27,1d,d8,50,\
93,7f,93,e3,82,7b,ee,48,b3,d3,78,f9,fa,3b,10,06,49,6e,3c,72,b0,9f,b0,f3,3e,\
95,1e,35,f1,15,c2,42,84,79,e2,ad,6e,5d,44,0d,8d,82,a7,3c,b5,7c,21,b7,d3,48,\
ad,f9,ec,c7,0b,e4,06,0a,7a,e1,30,b1,d1,15,f5,39,b5,37,37,7a,7a,10,e6,be,30,\
bb,6b,8b,58,58,4c,11,42,ba,21,8d,d0,28,04,e8,c6,40,ca,84,19,a3,13,8e,f8,b4,\
9d,db,2c,18,71,13,f3,02,8b,f0,0e,01,96,bd,fe,83,74,ad,ac,48,f4,5e,a2,7c,dc,\
a9,f9,98,4c,35,d8,9b,9f,3a,30,c8,24,de,c3,f8,62,61,ed,74,97,f6,99,d3,27,c9,\
2d,35,41,06,74,53,ca,df,33,91,52,09,c9,85,9f,40,56,23,e3,e5,a6,f6,56,66,56,\
59,b2,23,10,18,56,d2,40,ff,63,fb,0d,61,19,6e,fd,be,c7,19,7a,27,d0,f3,23,de,\
0d,79,cb,06,95,48,de,e4,a7,29,a4,3e,f4,b1,e4,0d,6a,7e,52,aa,6f,16,07,69,13,\
75,54,5e,b5,cf,78,90,cd,3a,e5,4f,2d,b8,58,be,2d,c7,a6,46,10,03,6a,1f,af,a7,\
20,6c,2c,e7,b1,f1,07,78,69,78,1c,c3,4a,fa,b1,a2,43,1f,74,14,25,49,d3,b2,fa,\
78,65,25,9a,eb,1d,bb,3d,ca,9b,79,70,39,f8,bf,8c,13,86,27,ab,2f,49,e8,8e,41,\
15,72,e1,ba,32,76,a8,61,08,6b,35,1a,79,cd,fa,2f,52,9d,22,78,88,66,f0,11,50,\
ac,bd,0e,f0,45,da,a8,55,e0,7d,1a,64,5f,54,9d,79,68,92,21,12,68,51,bd,6d,f4,\
e9,5a,96,10,60,30,c2,1b,fb,62,a9,53,ec,45,c7,fb,e4,0e,eb,15,0a,5d,25,a8,ea,\
61,da,d1,52,10,96,25,72,d6,28,f6,67,f7,03,a4,54,16,bd,d8,af,42,1b,a5,2c,a3,\
59,56,14,5e,59
"rkeysecu"=hex:de,b6,88,f1,4a,ef,9e,a7,7b,a7,e0,ef,c4,ac,6c,b4
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\Grisoft\AVG7\avgamsvr.exe
c:\progra~1\Grisoft\AVG7\avgupsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\EloSrvce.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\EloDkMon.exe
c:\windows\system32\EloTTray.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-01-03 14:34:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-03 19:34:05
Pre-Run: 144,578,301,952 bytes free
Post-Run: 144,963,313,664 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
349 — E O F — 2008-12-19 08:00:48