Well all of those torrents were months old, I haven't dled much recently because of my bandwidth limit being eaten up by 4 other ppl. I haven't been to a torrent site in well over 2 months now, excluding direct anime subbers who post torrent on there own site. Either way, meh.
——————–\\ Lop S&D; 4.2.5-0 XP/Vista
Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Core™2 CPU 6600 @ 2.40GHz )
BIOS : BIOS Date: 01/12/07 16:56:17 Ver: 08.00.12
USER : Drew ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090121-0] 4.8.1296 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:232 Go (Free:93 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [3] ( Thu 01/22/2009| 1:44 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX
Deleted! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\close poke frag ooze
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
——————–\\ Listing folders in APPLIC~1
[10/23/2007|03:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[01/14/2009|02:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[04/02/2008|08:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[04/02/2008|08:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[11/04/2008|11:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Armagetron
[10/24/2007|09:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Azureus
[10/19/2008|09:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CanonBJ
[03/24/2008|09:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DassaultSystemes
[10/29/2007|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Hewlett-Packard
[10/19/2008|09:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[12/20/2007|04:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ IJJIGame
[08/25/2008|11:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[10/24/2007|10:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ LogiShrd
[10/24/2007|10:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Logitech
[10/24/2007|11:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Macrovision
[08/31/2008|06:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[10/26/2007|04:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[07/17/2008|04:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NexonUS
[01/03/2009|02:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Raxco
[12/11/2008|05:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ ScanSoft
[10/24/2007|08:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[08/31/2008|07:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SUPERAntiSpyware.com
[07/22/2008|07:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TrackMania
[07/25/2008|08:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Ubisoft
[10/29/2007|11:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WEBREG
[10/23/2007|04:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[10/23/2007|03:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[01/14/2009|02:29] C:\DOCUME~1\Drew\APPLIC~1\ Adobe
[04/28/2008|02:10] C:\DOCUME~1\Drew\APPLIC~1\ Apple Computer
[11/04/2008|11:42] C:\DOCUME~1\Drew\APPLIC~1\ Armagetron
[07/08/2008|06:46] C:\DOCUME~1\Drew\APPLIC~1\ Atari
[01/01/2009|03:59] C:\DOCUME~1\Drew\APPLIC~1\ Azureus
[10/26/2008|02:48] C:\DOCUME~1\Drew\APPLIC~1\ Canon
[03/24/2008|09:35] C:\DOCUME~1\Drew\APPLIC~1\ DassaultSystemes
[05/07/2008|02:12] C:\DOCUME~1\Drew\APPLIC~1\ DivX
[10/26/2008|10:01] C:\DOCUME~1\Drew\APPLIC~1\ dyyno-vlc
[08/14/2008|08:09] C:\DOCUME~1\Drew\APPLIC~1\ GarageGames
[11/23/2008|02:09] C:\DOCUME~1\Drew\APPLIC~1\ Hamachi
[10/29/2007|11:57] C:\DOCUME~1\Drew\APPLIC~1\ HP
[10/23/2007|03:25] C:\DOCUME~1\Drew\APPLIC~1\ Identities
[12/20/2007|04:11] C:\DOCUME~1\Drew\APPLIC~1\ ijjigame
[04/03/2008|09:19] C:\DOCUME~1\Drew\APPLIC~1\ Image Zone Express
[08/25/2008|11:41] C:\DOCUME~1\Drew\APPLIC~1\ InstallShield
[07/08/2008|05:03] C:\DOCUME~1\Drew\APPLIC~1\ Leadertech
[10/24/2007|10:22] C:\DOCUME~1\Drew\APPLIC~1\ Logitech
[11/29/2007|09:53] C:\DOCUME~1\Drew\APPLIC~1\ Macromedia
[08/31/2008|06:33] C:\DOCUME~1\Drew\APPLIC~1\ Malwarebytes
[10/24/2007|11:25] C:\DOCUME~1\Drew\APPLIC~1\ Media Player Classic
[01/19/2009|06:56] C:\DOCUME~1\Drew\APPLIC~1\ Microsoft
[08/30/2008|01:58] C:\DOCUME~1\Drew\APPLIC~1\ Mozilla
[12/20/2007|02:42] C:\DOCUME~1\Drew\APPLIC~1\ NHN Corporation
[11/11/2007|03:33] C:\DOCUME~1\Drew\APPLIC~1\ Printer Info Cache
[10/25/2007|08:28] C:\DOCUME~1\Drew\APPLIC~1\ SecuROM
[11/03/2007|12:50] C:\DOCUME~1\Drew\APPLIC~1\ Sun
[08/31/2008|07:54] C:\DOCUME~1\Drew\APPLIC~1\ SUPERAntiSpyware.com
[05/09/2008|09:22] C:\DOCUME~1\Drew\APPLIC~1\ SystemRequirementsLab
[10/24/2007|10:05] C:\DOCUME~1\Drew\APPLIC~1\ teamspeak2
[08/31/2008|12:28] C:\DOCUME~1\Drew\APPLIC~1\ U3
[11/18/2008|01:16] C:\DOCUME~1\Drew\APPLIC~1\ Ventrilo
[01/22/2009|12:29] C:\DOCUME~1\Drew\APPLIC~1\ Xfire
[10/23/2007|03:20] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[11/14/2008|12:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Xfire
[10/23/2007|03:20] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft
[10/26/2008|09:54] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Xfire
——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[01/21/2009 10:06 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[02/28/2006 07:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini
——————–\\ Listing Folders in C:\Program Files
[10/24/2007|10:44] C:\Program Files\ 7-Zip
[11/18/2007|10:26] C:\Program Files\ Abexo
[11/06/2008|09:45] C:\Program Files\ Activision
[05/23/2008|10:05] C:\Program Files\ Adobe
[10/24/2007|07:12] C:\Program Files\ Alwil Software
[10/23/2007|03:49] C:\Program Files\ Analog Devices
[04/02/2008|08:28] C:\Program Files\ Apple Software Update
[11/17/2008|01:47] C:\Program Files\ Armagetron Advanced
[07/08/2008|05:00] C:\Program Files\ Atari
[12/24/2008|03:31] C:\Program Files\ Azureus
[10/19/2008|09:58] C:\Program Files\ Canon
[10/19/2008|09:56] C:\Program Files\ CanonBJ
[05/07/2008|02:04] C:\Program Files\ Combined Community Codec Pack
[01/21/2009|05:13] C:\Program Files\ Common Files
[10/23/2007|03:18] C:\Program Files\ ComPlus Applications
[01/02/2008|01:20] C:\Program Files\ dayam NFO Viewer
[03/24/2008|09:39] C:\Program Files\ Dassault Systemes
[10/26/2008|07:37] C:\Program Files\ DivX
[10/26/2008|10:01] C:\Program Files\ Dyyno
[01/06/2008|10:35] C:\Program Files\ EA GAMES
[09/13/2008|12:49] C:\Program Files\ Electronic Arts
[05/17/2008|09:18] C:\Program Files\ G-Collections
[11/23/2008|12:26] C:\Program Files\ Hamachi
[10/19/2008|09:44] C:\Program Files\ HP
[12/28/2008|02:51] C:\Program Files\ InstallShield Installation Information
[10/23/2007|03:39] C:\Program Files\ Intel
[12/26/2007|10:45] C:\Program Files\ InterActual
[12/13/2008|03:02] C:\Program Files\ Internet Explorer
[01/20/2009|09:19] C:\Program Files\ Java
[10/24/2007|10:21] C:\Program Files\ Logitech
[10/24/2007|09:29] C:\Program Files\ Macromedia
[01/21/2009|07:12] C:\Program Files\ Malwarebytes' Anti-Malware
[10/23/2007|03:57] C:\Program Files\ Marvell
[08/27/2008|07:57] C:\Program Files\ Messenger
[10/24/2007|12:56] C:\Program Files\ Microsoft ActiveSync
[10/21/2008|12:42] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[10/23/2007|03:21] C:\Program Files\ microsoft frontpage
[03/28/2008|01:05] C:\Program Files\ Microsoft Office
[08/27/2008|07:52] C:\Program Files\ Movie Maker
[01/22/2009|12:23] C:\Program Files\ Mozilla Firefox
[03/28/2008|01:04] C:\Program Files\ MSECache
[10/23/2007|03:17] C:\Program Files\ MSN
[10/23/2007|03:18] C:\Program Files\ MSN Gaming Zone
[08/27/2008|09:08] C:\Program Files\ MSN Messenger
[10/31/2007|02:00] C:\Program Files\ MSXML 4.0
[10/23/2007|04:06] C:\Program Files\ My Company Name
[08/27/2008|07:51] C:\Program Files\ NetMeeting
[10/23/2007|03:18] C:\Program Files\ Online Services
[08/27/2008|07:51] C:\Program Files\ Outlook Express
[01/19/2008|03:27] C:\Program Files\ PowerISO
[04/02/2008|08:28] C:\Program Files\ QuickTime
[01/03/2009|02:38] C:\Program Files\ Raxco
[11/18/2007|10:30] C:\Program Files\ RivaTuner v2.06
[10/19/2008|10:00] C:\Program Files\ ScanSoft
[12/07/2008|12:53] C:\Program Files\ SpeedFan
[12/10/2008|11:53] C:\Program Files\ Spybot - Search & Destroy
[11/10/2008|03:18] C:\Program Files\ SubaGames
[12/11/2008|01:40] C:\Program Files\ SUPERAntiSpyware
[05/09/2008|09:22] C:\Program Files\ SystemRequirementsLab
[10/24/2007|10:04] C:\Program Files\ Teamspeak2_RC2
[02/24/2008|07:19] C:\Program Files\ THQ
[05/31/2008|11:18] C:\Program Files\ TmNationsForever
[08/31/2008|01:47] C:\Program Files\ Trend Micro
[11/18/2008|06:33] C:\Program Files\ Ubisoft
[10/23/2007|03:25] C:\Program Files\ Uninstall Information
[11/18/2008|01:16] C:\Program Files\ Ventrilo
[11/18/2008|07:10] C:\Program Files\ Veoh Networks
[04/02/2008|08:39] C:\Program Files\ Vernier Software
[08/27/2008|07:53] C:\Program Files\ Windows Media Player
[08/27/2008|07:51] C:\Program Files\ Windows NT
[10/23/2007|03:20] C:\Program Files\ WindowsUpdate
[10/23/2007|03:21] C:\Program Files\ xerox
[01/22/2009|12:22] C:\Program Files\ Xfire
——————–\\ Listing Folders in C:\Program Files\Common Files
[05/23/2008|10:06] C:\Program Files\Common Files\ Adobe
[10/24/2007|11:10] C:\Program Files\Common Files\ Adobe Systems Shared
[10/19/2008|09:58] C:\Program Files\Common Files\ CANON
[03/24/2008|09:39] C:\Program Files\Common Files\ Designer
[12/20/2007|02:42] C:\Program Files\Common Files\ DirectX
[10/29/2007|11:54] C:\Program Files\Common Files\ Hewlett-Packard
[07/08/2008|06:57] C:\Program Files\Common Files\ INCA Shared
[08/25/2008|11:41] C:\Program Files\Common Files\ InstallShield
[10/24/2007|09:00] C:\Program Files\Common Files\ Java
[07/02/2008|08:08] C:\Program Files\Common Files\ Logishrd
[07/02/2008|08:08] C:\Program Files\Common Files\ Logitech
[10/24/2007|09:29] C:\Program Files\Common Files\ Macromedia
[03/28/2008|01:05] C:\Program Files\Common Files\ Microsoft Shared
[10/23/2007|03:19] C:\Program Files\Common Files\ MSSoap
[10/23/2007|11:09] C:\Program Files\Common Files\ ODBC
[07/08/2008|05:03] C:\Program Files\Common Files\ PocketSoft
[10/23/2007|03:19] C:\Program Files\Common Files\ Services
[10/23/2007|11:09] C:\Program Files\Common Files\ SpeechEngines
[08/27/2008|07:51] C:\Program Files\Common Files\ System
[04/02/2008|08:37] C:\Program Files\Common Files\ TI Shared
[04/02/2008|08:39] C:\Program Files\Common Files\ Vernier Software
[11/18/2008|01:16] C:\Program Files\Common Files\ Wise Installation Wizard
——————–\\ Process
( 44 Processes )
… OK !
——————–\\ Searching with S_Lop
No Lop folder found !
——————–\\ Searching for Lop Files - Folders
No Lop folder found !
——————–\\ Searching within the Registry
….. OK !
——————–\\ Checking the Hosts file
Hosts file CLEAN
——————–\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-22 01:45:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 83
——————–\\ Searching for other infections
——————–\\ Cracks & Keygens ..
C:\DOCUME~1\Drew\Application Data\Azureus\torrents\MASS.EFFECT.PROPER.CRACKFiX.READ.NFO-iND.4225545.TPB.torrent
C:\DOCUME~1\Drew\Application Data\Azureus\torrents\Mass_Effect_gmfix_working_crack_really_this_time.4220207.TPB.torrent
C:\DOCUME~1\Drew\Application Data\Azureus\torrents\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR] [mininova].torrent
C:\DOCUME~1\Drew\Application Data\Azureus\torrents\Spore.Crackfix-RELOADED.4379413.TPB.torrent
C:\DOCUME~1\Drew\My Documents\Azureus Downloads\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR]
C:\DOCUME~1\Drew\My Documents\Azureus Downloads\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR]\tracked_by_h33t_com.txt
C:\DOCUME~1\Drew\My Documents\My Games\Soldat\Sfx\bonecrack.wav
C:\DOCUME~1\Drew\My Documents\My Games\Soldat\Sfx\firecrack.wav
C:\DOCUME~1\Drew\My Documents\My Received Files\Programs\Adobe Photoshop CS 8.0\crack
C:\DOCUME~1\Drew\My Documents\My Received Files\Programs\Adobe Photoshop CS 8.0\crack\AdobeLM.dll
C:\DOCUME~1\Drew\My Documents\My Received Files\Programs\Adobe Photoshop CS 8.0\crack\Tw10122.dat
C:\DOCUME~1\Drew\My Documents\My Received Files\Torrents\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR] [mininova].torrent
[F:22][D:5]-> C:\DOCUME~1\Drew\LOCALS~1\Temp
[F:11][D:0]-> C:\DOCUME~1\Drew\Cookies
[F:203][D:4]-> C:\DOCUME~1\Drew\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Thu 01/22/2009| 0:31 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - Thu 01/22/2009| 1:46 - Option : [3]
——————–\\ Scan completed at 1:46:05
ComboFix 09-01-21.02 - Drew 2009-01-22 1:53:24.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1550 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Drew\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090121-0] *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\docume~1\Drew\Application Data\Azureus\torrents\MASS.EFFECT.PROPER.CRACKFiX.READ.NFO-iND.4225545.TPB.torrent
c:\docume~1\Drew\Application Data\Azureus\torrents\Mass_Effect_gmfix_working_crack_really_this_time.4220207.TPB.torrent
c:\docume~1\Drew\Application Data\Azureus\torrents\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR] [mininova].torrent
c:\docume~1\Drew\Application Data\Azureus\torrents\Spore.Crackfix-RELOADED.4379413.TPB.torrent
c:\docume~1\Drew\My Documents\Azureus Downloads\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR]
c:\docume~1\Drew\My Documents\Azureus Downloads\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR]\tracked_by_h33t_com.txt
c:\docume~1\Drew\My Documents\My Received Files\Programs\Adobe Photoshop CS 8.0\crack
c:\docume~1\Drew\My Documents\My Received Files\Programs\Adobe Photoshop CS 8.0\crack\AdobeLM.dll
c:\docume~1\Drew\My Documents\My Received Files\Programs\Adobe Photoshop CS 8.0\crack\Tw10122.dat
c:\docume~1\Drew\My Documents\My Received Files\Torrents\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR] [mininova].torrent
c:\docume~1\Drew\My Documents\My Received Files\Torrents\Spore.Crackfix-RELOADED.4379413.TPB.torrent
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Drew\Application Data\Azureus\torrents\MASS.EFFECT.PROPER.CRACKFiX.READ.NFO-iND.4225545.TPB.torrent
c:\docume~1\Drew\Application Data\Azureus\torrents\Mass_Effect_gmfix_working_crack_really_this_time.4220207.TPB.torrent
c:\docume~1\Drew\Application Data\Azureus\torrents\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR] [mininova].torrent
c:\docume~1\Drew\Application Data\Azureus\torrents\Spore.Crackfix-RELOADED.4379413.TPB.torrent
c:\docume~1\Drew\My Documents\Azureus Downloads\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR]\tracked_by_h33t_com.txt
c:\docume~1\Drew\My Documents\My Received Files\Programs\Adobe Photoshop CS 8.0\crack\AdobeLM.dll
c:\docume~1\Drew\My Documents\My Received Files\Programs\Adobe Photoshop CS 8.0\crack\Tw10122.dat
c:\docume~1\Drew\My Documents\My Received Files\Torrents\Nero 8.1.1.0 Ultra Edition + Keygen [h33t] [CaZoR] [mininova].torrent
.
((((((((((((((((((((((((( Files Created from 2008-12-22 to 2009-01-22 )))))))))))))))))))))))))))))))
.
2009-01-22 00:29 . 2009-01-22 01:46 d——– C:\Lop SD
2009-01-20 21:19 . 2009-01-20 21:19 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-20 18:35 . 2009-01-20 21:19 d——– c:\documents and settings\Drew\.SunDownloadManager
2009-01-15 03:37 . 2009-01-15 03:37 42,320 –a—— c:\windows\system32\xfcodec.dll
2009-01-03 02:38 . 2009-01-03 02:38 d——– c:\documents and settings\All Users\Application Data\Raxco
2009-01-03 02:38 . 2009-01-05 14:16 71,184 -ra—— c:\windows\system32\drivers\DefragFS.sys
2009-01-03 02:37 . 2009-01-03 02:38 d——– c:\program files\Raxco
2008-12-31 13:12 . 2008-12-31 13:12 230,664 –a—— c:\windows\system32\PDBoot.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-22 05:29 ——— d—–w c:\documents and settings\Drew\Application Data\Xfire
2009-01-22 05:22 ——— d—–w c:\program files\Xfire
2009-01-22 03:55 137,688 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-01-22 03:54 202,040 —-a-w c:\windows\system32\PnkBstrB.exe
2009-01-22 03:22 196,608 —-a-w c:\windows\system32\drivers\nStandard.bin
2009-01-22 00:12 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-01-21 03:17 261,376 —-a-w c:\documents and settings\Drew\Application Data\GDIPFONTCACHEV1.DAT
2009-01-21 02:19 ——— d—–w c:\program files\Java
2009-01-14 21:11 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 21:11 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-01-01 20:59 ——— d—–w c:\documents and settings\Drew\Application Data\Azureus
2008-12-28 07:51 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-24 08:31 ——— d—–w c:\program files\Azureus
2008-12-11 22:09 ——— d—–w c:\documents and settings\All Users\Application Data\ScanSoft
2008-12-11 18:40 ——— d—–w c:\program files\SUPERAntiSpyware
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-10 16:53 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-07 05:53 ——— d—–w c:\program files\SpeedFan
2008-11-23 07:09 ——— d—–w c:\documents and settings\Drew\Application Data\Hamachi
2008-11-23 05:26 17,480 —-a-w c:\windows\system32\drivers\hamachi.sys
2008-11-23 05:26 ——— d—–w c:\program files\Hamachi
2008-11-07 21:38 84,496 —-a-w c:\windows\system32\KemXML.dll
2008-11-07 21:38 170,512 —-a-w c:\windows\system32\kemutb.dll
2008-11-07 21:38 145,936 —-a-w c:\windows\system32\KemUtil.dll
2008-11-07 21:38 117,264 —-a-w c:\windows\system32\KemWnd.dll
2008-11-07 21:37 301,656 —-a-w c:\windows\system32\BtCoreIf.dll
2008-11-07 01:43 682,280 —-a-w c:\windows\system32\pbsvc.exe
2008-11-07 01:43 66,872 —-a-w c:\windows\system32\PnkBstrA.exe
2008-11-07 01:43 22,328 —-a-w c:\documents and settings\Drew\Application Data\PnkBstrK.sys
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2006-06-23 06:48 32,768 —-a-r c:\windows\inf\UpdateUSB.exe
2008-08-28 00:57 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082720080828\index.dat
2008-09-01 00:18 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008083120080901\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-21_17.24.55.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-22 03:06:43 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_1e8.dat
+ 2009-01-22 03:06:34 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_564.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-10-05 868352]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-24 13524992]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-20 136600]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-24 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-10-24 113664]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-01-19 809488]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-11 13:39 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 16:41 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\
0autocheck autochk *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
–a—— 2008-08-28 09:18 3660848 c:\program files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Launcher.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\THQ\\Company of Heroes\\RelicCOH.exe"=
"c:\\Program Files\\Dassault Systemes\\B16\\intel_a\\code\\bin\\orbixd.exe"=
"c:\\Program Files\\Dassault Systemes\\B16\\intel_a\\code\\bin\\CNEXT.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Common Files\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Documents and Settings\\Drew\\Application Data\\GarageGames\\IAPlayer\\products\\www_instantaction_com\\7000\\install\\Zap.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Documents and Settings\\Drew\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\Armagetron Advanced\\armagetronad.exe"=
"c:\program files\SubaGames\ACEonline\Launcher.atm"= c:\program files\SubaGames\ACEonline\Launcher.atm:Enabled:GameExe2
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\SubaGames\\ACEonline\\Res-Voip\\SCVoIP.exe"=
"c:\\WINDOWS\\ATKKBService.exe"=
"c:\\Program Files\\Alwil Software\\Avast4\\ashWebSv.exe"=
"c:\\ComboFix\\fdsv.cfexe"=
"c:\\WINDOWS\\system32\\cscript.exe"=
"c:\\Program Files\\Alwil Software\\Avast4\\ashMaiSv.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-03 111184]
R1 LUMDriver;LUMDriver;c:\windows\system32\drivers\LUMDriver.sys [2003-07-11 14912]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-08-19 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-08-19 55024]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-03 20560]
R4 BBDemon;Backbone Service;c:\program files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe [2005-09-06 35840]
R4 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [2008-12-31 693512]
S0 kmxewvbq;kmxewvbq;c:\windows\system32\drivers\uknrjgvz.sys –> c:\windows\system32\drivers\uknrjgvz.sys [?]
S3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [2008-12-31 910600]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-08-19 7408]
S4 Pe10wxy;Pe10wxy; [x]
— Other Services/Drivers In Memory —
*NewlyCreated* - PNKBSTRB
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2583fd26-7782-11dd-b77b-001a92615591}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Drew\Application Data\Mozilla\Firefox\Profiles\luujybm8.default\
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Drew\Application Data\Mozilla\Firefox\Profiles\luujybm8.default\extensions\[removed]\plugins\npiaplayer.dll
FF - plugin: c:\program files\Dyyno\Dyyno Player\npvlc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPHoldemFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-22 01:55:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-2000478354-2052111302-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:71,e3,05,71,8f,08,27,f5,92,0f,d2,cb,ff,ae,a2,0f,ca,e1,ff,88,05,05,5c,
48,ba,f9,08,b8,8e,08,c3,41,8b,12,42,56,61,e1,b3,8d,38,a2,cc,22,8f,5c,f2,c9,\
"??"=hex:6d,c2,fa,9e,fc,72,0e,31,11,0b,fd,78,46,8c,59,05
[HKEY_USERS\S-1-5-21-2000478354-2052111302-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:0a,b1,81,4e,fc,95,98,fb,f3,2f,8d,dd,af,39,7c,65,1c,9d,6d,41,86,
c6,8c,91,88,3c,3e,0d,ef,3f,68,0c,4e,13,a0,46,81,4b,d3,b0,29,e6,9c,31,69,f1,\
"rkeysecu"=hex:27,0d,7c,78,9c,19,59,1f,2a,26,4b,3d,34,1c,6b,17
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(704)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-01-22 1:57:25
ComboFix-quarantined-files.txt 2009-01-22 06:57:23
ComboFix2.txt 2009-01-21 22:25:36
ComboFix3.txt 2008-12-13 03:28:34
Pre-Run: 99,843,870,720 bytes free
Post-Run: 99,837,210,624 bytes free
228 — E O F — 2009-01-21 22:18:16