ComboFix 09-09-13.04 - Dark Sword 3/2009 Sun 18:30.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.932.81.1033.18.1535.987 [GMT -5:00]
Running from: c:\documents and settings\Dark Sword\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Dark Sword\Desktop\CFscript.txt
AV: avast! antivirus 4.8.1351 [VPS 090913-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\cleanup.exe
C:\HijackThis.exe
c:\windows\Installer\122efbf.msi
c:\windows\Installer\123cea8.msi
c:\windows\Installer\1c045b3.msi
c:\windows\Installer\1c045bc.msi
c:\windows\Installer\1c045c5.msi
c:\windows\Installer\1cc4e78.msi
c:\windows\Installer\225166e.msi
c:\windows\Installer\2251675.msi
c:\windows\Installer\2ae9e55.msi
c:\windows\Installer\3bc7d8a.msi
c:\windows\run.log
c:\windows\system32\.txt
c:\windows\system32\rotscxlxrjlxbg.dll
c:\windows\system32\rotscxtituwghq.dat
c:\windows\system32\rotscxwbgkcmeu.dat
c:\windows\system32\rotscxxvkyabct.dll
c:\windows\system32\rotscxymixgipj.dll
.
--------------- FCopy ---------------
c:\windows\ServicePackFiles\i386\eventlog.dll --> c:\windows\system32\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_rotscxiqvdbakb
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_rotscxiqvdbakb
((((((((((((((((((((((((( Files Created from 2009-08-13 to 2009-09-13 )))))))))))))))))))))))))))))))
.
2009-09-13 23:04 . 2004-08-04 07:56 55808 -c--a-w- c:\windows\system32\dllcache\eventlog.dll
2009-09-13 23:04 . 2004-08-04 07:56 55808 ----a-w- c:\windows\system32\eventlog.dll
2009-09-13 19:05 . 2009-09-13 19:05 574 ----a-w- C:\cleanup.bat
2009-09-13 19:05 . 2009-09-13 19:05 135168 ----a-w- C:\zip.exe
2009-09-13 14:17 . 2009-09-13 14:17 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
2009-09-13 14:16 . 2009-09-13 14:16 30496 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-13 03:23 . 2009-09-13 03:23 -------- d-----w- C:\Docum
2009-09-12 23:09 . 2009-09-12 23:09 -------- d-----w- c:\documents and settings\Dark Sword\Application Data\Malwarebytes
2009-09-12 23:09 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-12 23:09 . 2009-09-13 20:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-12 23:09 . 2009-09-12 23:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-12 23:09 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-12 23:06 . 2009-09-12 23:06 -------- d-----w- c:\program files\Trend Micro
2009-09-12 23:03 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-09-12 23:03 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-09-12 23:03 . 2009-08-17 16:03 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-09-12 23:03 . 2009-08-17 16:06 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-09-12 23:03 . 2009-08-17 16:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-09-12 23:03 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-09-12 23:03 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-09-12 23:03 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-09-12 23:03 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-12 21:35 . 2009-09-12 21:35 2855 ----a-w- C:\HijackThis.PIF
2009-09-12 21:20 . 2009-09-12 21:20 -------- d-sh--we c:\windows\system32\GroupPolicy\User\Scripts\Logoff\Logoff
2009-09-10 00:44 . 2009-09-10 00:44 -------- d-----w- c:\program files\iPod
2009-09-10 00:44 . 2009-09-10 00:45 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-09 23:27 . 2009-06-21 22:04 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-02 22:42 . 2009-09-02 22:42 -------- d-----w- c:\documents and settings\Dark Sword\del.icio.us
2009-08-26 12:07 . 2009-08-26 12:07 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-08-26 11:47 . 2009-08-26 11:47 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-08-26 11:44 . 2009-08-26 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-23 22:40 . 2009-08-23 22:40 -------- d-----w- c:\program files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-13 18:49 . 2007-01-14 08:41 1984 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-13 03:50 . 2005-03-04 21:40 -------- d-----w- c:\program files\Trillian
2009-09-10 00:57 . 2003-10-19 00:50 -------- d-----w- c:\documents and settings\Dark Sword\Application Data\Apple Computer
2009-09-10 00:45 . 2007-10-03 02:19 -------- d-----w- c:\program files\iTunes
2009-09-10 00:44 . 2007-10-03 02:18 -------- d-----w- c:\program files\Common Files\Apple
2009-09-10 00:41 . 2008-04-05 05:10 -------- d-----w- c:\program files\QuickTime
2009-09-02 00:46 . 2008-07-20 04:01 -------- d-----w- c:\program files\Opera
2009-08-29 22:16 . 2004-06-17 17:13 -------- d-----w- c:\documents and settings\Dark Sword\Application Data\Azureus
2009-08-29 00:42 . 2008-09-09 23:34 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-29 00:42 . 2007-10-03 02:18 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-26 11:48 . 2006-08-13 20:57 -------- d-----w- c:\program files\Google
2009-08-21 01:35 . 2004-06-17 17:13 -------- d-----w- c:\program files\Azureus
2009-08-12 00:23 . 2004-07-23 02:55 -------- d-----w- c:\program files\MatroskaProp
2009-08-10 21:28 . 2009-08-10 21:27 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-08-10 21:26 . 2005-01-23 23:46 -------- d-----w- c:\program files\Matroska
2009-08-10 21:25 . 2004-07-23 02:55 -------- d-----w- c:\program files\Matroska Pack
2009-08-05 09:11 . 2003-07-18 03:09 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55 . 2001-08-23 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2004-09-23 02:46 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-26 16:18 . 2004-01-08 22:23 659456 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-04 07:56 81920 ------w- c:\windows\system32\ieencode.dll
2009-06-25 18:36 . 2001-08-23 12:00 95744 ----a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2001-08-23 12:00 661504 ----a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2001-08-23 12:00 517120 ----a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2001-08-23 12:00 48640 ----a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2001-08-23 12:00 471552 ----a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2001-08-23 12:00 47104 ----a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2001-08-23 12:00 225280 ----a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2001-08-23 12:00 186880 ----a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2001-08-23 12:00 177152 ----a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2001-08-23 12:00 16896 ----a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2001-08-23 12:00 138240 ----a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2001-08-23 12:00 123392 ----a-w- c:\windows\system32\mqrtdep.dll
2009-06-22 11:49 . 2001-08-23 12:00 19968 ----a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2001-08-23 12:00 117248 ----a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2001-08-23 12:00 4608 ----a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2001-08-23 12:00 91776 ----a-w- c:\windows\system32\drivers\mqac.sys
2009-06-16 14:55 . 2001-08-23 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2001-08-23 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-05 49152]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"RCSystem"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-05 49152]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-13 344064]
"UltraMon"="c:\program files\UltraMon\UltraMon.exe" [2006-10-13 304640]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"GIZMO2"="c:\program files\GIZMO2\GIZMO.exe" [2008-11-17 2229512]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"WINDVDPatch"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2002-07-03 24576]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2005-10-29 18944]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2002-07-03 24576]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre1.5.0_04\\bin\\javaw.exe"=
"c:\\Documents and Settings\\Dark Sword\\My Documents\\Temp\\Magic\\Manalink.exe"=
"c:\\Program Files\\DOSBox-0.61\\dosbox.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Documents and Settings\\Dark Sword\\Application Data\\Macromedia\\Flash Player\\
www.macromedia.com\\bin\\octoshape\\octoshape.exe"="c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [9/12/2009 6:03 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/12/2009 6:03 PM 20560]
R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [9/24/2006 9:22 PM 11776]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [7/14/2006 6:21 PM 450400]
R3 UltraMonMirror;UltraMonMirror;c:\windows\system32\drivers\UltraMonMirror.sys [9/24/2006 9:23 PM 3584]
S2 bzqhwe;bzqhwe;c:\windows\system32\drivers\qasymv.sys --> c:\windows\system32\drivers\qasymv.sys [?]
S2 gupdate1ca26435ef08d4;Google Update Service (gupdate1ca26435ef08d4);c:\program files\Google\Update\GoogleUpdate.exe [8/26/2009 6:47 AM 133104]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 EL98x;3Com EtherLink 10/100 PCI;c:\windows\system32\drivers\el98xn5.sys [3/19/2004 10:20 AM 70174]
S3 ldiskl;ldiskl;\??\c:\docume~1\DARKSW~1\LOCALS~1\Temp\ldiskl.sys --> c:\docume~1\DARKSW~1\LOCALS~1\Temp\ldiskl.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-07-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-09-13 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-26 11:44]
2009-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-26 11:47]
2009-09-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-26 11:47]
2009-09-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://forums.egullet.org/uDefault_Search_URL =
hxxp://www.google.com/ieuInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Dark Sword\Application Data\Mozilla\Firefox\Profiles\v2c9i8ii.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://maps.google.com/FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1691.8062\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPOJI610.dll
FF - plugin: c:\program files\Opera7\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Opera7\program\plugins\npdrmv2.dll
FF - plugin: c:\program files\Opera7\program\plugins\NPJava11.dll
FF - plugin: c:\program files\Opera7\program\plugins\NPJava12.dll
FF - plugin: c:\program files\Opera7\program\plugins\NPJava13.dll
FF - plugin: c:\program files\Opera7\program\plugins\NPJava14.dll
FF - plugin: c:\program files\Opera7\program\plugins\NPJava32.dll
FF - plugin: c:\program files\Opera7\program\plugins\NPJPI150_03.dll
FF - plugin: c:\program files\Opera7\program\plugins\NPOJI610.dll
FF - plugin: c:\program files\Opera7\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\Opera7\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Opera7\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Opera7\program\plugins\npqtplugin4.dll
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - c:\program files\Qualcomm\Eudora\EuShlExt.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-13 18:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-746137067-1770027372-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-746137067-1770027372-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\\P*]
"DisplayName"="?\13?\13"
"DeviceDesc"="?\13?\13"
"ProviderName"="y"
"MFG"="???\\"
"ReinstallString"="c:\\WINDOWS\\System32\\ReinstallBackups\\停\13\\DriverFiles\\.INF"
"DeviceInstanceIds"=multi:"07243.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(616)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\imjp81.ime
c:\windows\system32\imjp81k.dll
c:\windows\IME\IMJP8_1\Dicts\IMJPCD.DIC
- - - - - - - > 'explorer.exe'(4056)
c:\program files\UltraMon\RTSUltraMonHook.dll
c:\windows\system32\imjp81.ime
c:\windows\system32\imjp81k.dll
c:\windows\IME\IMJP8_1\Dicts\IMJPCD.DIC
c:\windows\system32\shdoclc.dll
c:\windows\IME\imjp8_1\IMJPCIC.DLL
c:\program files\UltraMon\Resources\en\RTSUltraMonHookRes.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTXFISPI.EXE
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
c:\program files\Creative\ShareDLL\CADI\NotiMan.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\program files\UltraMon\UltraMonTaskbar.exe
.
**************************************************************************
.
Completion time: 2009-09-13 19:00 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-14 00:00
Pre-Run: 36,064,641,024 bytes free
Post-Run: 36,073,017,344 bytes free
320 --- E O F --- 2009-09-10 22:40