ComboFix 09-10-28.08 - Greg Parker 10/29/2009 18:49.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.286 [GMT -4:00]
Running from: c:\documents and settings\Greg Parker\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DFR1.tmp
c:\documents and settings\Administrator\Application Data\aduxeso._dl
c:\documents and settings\Administrator\Application Data\kekogamypy.dll
c:\documents and settings\Administrator\Application Data\tabuse.com
c:\documents and settings\Administrator\Cookies\qavy.bat
c:\documents and settings\Administrator\Cookies\sohykiroqi.vbs
c:\documents and settings\Administrator\Local Settings\Application Data\kore.reg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\cuqe.reg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\fobeho.pif
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\ijawan.inf
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\loho.db
c:\documents and settings\All Users\Application Data\atic._dl
c:\documents and settings\All Users\Application Data\awefalubof._sy
c:\documents and settings\All Users\Application Data\elaqyno.dll
c:\documents and settings\All Users\Application Data\idexave.vbs
c:\documents and settings\All Users\Application Data\ijyvyv.dl
c:\documents and settings\All Users\Application Data\jahezo.inf
c:\documents and settings\All Users\Application Data\judibamo.scr
c:\documents and settings\All Users\Application Data\ojul.com
c:\documents and settings\All Users\Application Data\puzusukot.sys
c:\documents and settings\All Users\Application Data\qykamul.dll
c:\documents and settings\All Users\Application Data\ryxe.pif
c:\documents and settings\All Users\Application Data\upodityji.com
c:\documents and settings\All Users\Application Data\xaqewabo.lib
c:\documents and settings\All Users\Application Data\ydisi.exe
c:\documents and settings\All Users\Documents\agysacyxov.pif
c:\documents and settings\All Users\Documents\fijym._sy
c:\documents and settings\All Users\Documents\gohaf.pif
c:\documents and settings\All Users\Documents\ifaminam.reg
c:\documents and settings\All Users\Documents\ifux.inf
c:\documents and settings\All Users\Documents\jisakino.dl
c:\documents and settings\All Users\Documents\nuwa._dl
c:\documents and settings\All Users\Documents\sakyhuhizy._sy
c:\documents and settings\All Users\Documents\syracynek.inf
c:\documents and settings\All Users\Documents\vojema.dl
c:\documents and settings\All Users\Documents\xiji._sy
c:\documents and settings\All Users\Documents\ybebosofi._dl
c:\documents and settings\All Users\Documents\ymysuzuluz.reg
c:\documents and settings\All Users\Documents\yqepe.dl
c:\documents and settings\Greg Parker\Application Data\acapugyva.dl
c:\documents and settings\Greg Parker\Application Data\firybuhip.scr
c:\documents and settings\Greg Parker\Application Data\idex.pif
c:\documents and settings\Greg Parker\Application Data\iniasd.txt
c:\documents and settings\Greg Parker\Application Data\ivare.bat
c:\documents and settings\Greg Parker\Application Data\ligyroho.com
c:\documents and settings\Greg Parker\Application Data\nizaton._sy
c:\documents and settings\Greg Parker\Application Data\ozaxiwek.exe
c:\documents and settings\Greg Parker\Application Data\ucirag.dll
c:\documents and settings\Greg Parker\Application Data\ufomelahis.ban
c:\documents and settings\Greg Parker\Application Data\utotonera.lib
c:\documents and settings\Greg Parker\Application Data\xovepola.com
c:\documents and settings\Greg Parker\Cookies\ajelymojac.reg
c:\documents and settings\Greg Parker\Cookies\devuzol._sy
c:\documents and settings\Greg Parker\Cookies\ezymun.com
c:\documents and settings\Greg Parker\Cookies\ihisitu.bin
c:\documents and settings\Greg Parker\Cookies\iryrigyqix.pif
c:\documents and settings\Greg Parker\Cookies\pyhura.sys
c:\documents and settings\Greg Parker\Cookies\qoryn.reg
c:\documents and settings\Greg Parker\Cookies\tuzixudaf.dat
c:\documents and settings\Greg Parker\Cookies\vimusyzaza.vbs
c:\documents and settings\Greg Parker\Cookies\ypuqokunuk.bin
c:\documents and settings\Greg Parker\Cookies\yrybel.dat
c:\documents and settings\Greg Parker\Local Settings\Application Data\akepeg.inf
c:\documents and settings\Greg Parker\Local Settings\Application Data\awosawoquq.bin
c:\documents and settings\Greg Parker\Local Settings\Application Data\cuvogybuxa.scr
c:\documents and settings\Greg Parker\Local Settings\Application Data\ekif.vbs
c:\documents and settings\Greg Parker\Local Settings\Application Data\epan.dll
c:\documents and settings\Greg Parker\Local Settings\Application Data\equjidyc.dll
c:\documents and settings\Greg Parker\Local Settings\Application Data\ibofumam.ban
c:\documents and settings\Greg Parker\Local Settings\Application Data\mogy.inf
c:\documents and settings\Greg Parker\Local Settings\Application Data\ubyrogo.exe
c:\documents and settings\Greg Parker\Local Settings\Application Data\uhakyped.reg
c:\documents and settings\Greg Parker\Local Settings\Application Data\uropyzovic.dll
c:\documents and settings\Greg Parker\Local Settings\Application Data\uvixovugok.sys
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\aqafuwo.dl
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\edotocuzic.reg
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\efatic.dll
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\ikocudexow.ban
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\ixaloxe.bin
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\lefekineme.lib
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\musyg._sy
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\ocar.bat
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\ojyc._dl
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\owilo.scr
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\ugofaf.vbs
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\uqaqecerew._dl
c:\documents and settings\Greg Parker\Local Settings\Temporary Internet Files\vawujin.lib
c:\program files\Common Files\ageciqa.exe
c:\program files\Common Files\awanagyk.sys
c:\program files\Common Files\bubiky.inf
c:\program files\Common Files\esukakomif._sy
c:\program files\Common Files\jotez.sys
c:\program files\Common Files\mufa.bin
c:\program files\Common Files\nybipise.dll
c:\program files\Common Files\ogokoxejaj.reg
c:\program files\Common Files\tiwuwesen.exe
c:\program files\Common Files\xuxo.sys
c:\windows\agasosuvu.bin
c:\windows\betexab.reg
c:\windows\cevatud._dl
c:\windows\ekaqocexyn._dl
c:\windows\fani.dll
c:\windows\hyfip.scr
c:\windows\igyxarim.vbs
c:\windows\itusij.bin
c:\windows\odobeqizev.pif
c:\windows\oxakozefub.sys
c:\windows\puxu.dl
c:\windows\qezopy.exe
c:\windows\system32\~.exe
c:\windows\system32\awxcguc.dll
c:\windows\system32\bawuwiruz.vbs
c:\windows\system32\bete.sys
c:\windows\system32\drivers\noittukv.sys
c:\windows\system32\drivers\zkbumuea.sys
c:\windows\system32\fadyjy.bat
c:\windows\system32\gijy.exe
c:\windows\system32\grpqtgk.dll
c:\windows\system32\ijiho.bat
c:\windows\system32\kamugoxys.pif
c:\windows\system32\labiwux.pif
c:\windows\system32\ojukaqilaz.sys
c:\windows\system32\udyfyvyt.bat
c:\windows\system32\ukizihuc.bat
c:\windows\system32\uwyduwalos.exe
c:\windows\system32\xihoc.vbs
c:\windows\Tasks\At1.job
c:\windows\Tasks\At2.job
c:\windows\ubuku._sy
c:\windows\ufopog.pif
c:\windows\upobaz.dl
c:\windows\xaxonyrop.scr
c:\windows\xulaky.pif
c:\windows\yxamopalon.bat
c:\windows\zusup.dll
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NOITTUKV
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Service_noittukv
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-29 )))))))))))))))))))))))))))))))
.
2009-10-29 22:56 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-27 00:36 . 2009-10-27 00:36 -------- d-----w- c:\program files\Trend Micro
2009-10-26 01:13 . 2009-10-26 01:13 54 ----a-w- c:\windows\system32\rp_stats.dat
2009-10-26 01:13 . 2009-10-26 01:13 39 ----a-w- c:\windows\system32\rp_rules.dat
2009-10-26 01:12 . 2009-10-29 22:48 0 ----a-w- c:\windows\win32k.sys
2009-10-26 01:09 . 2009-10-26 01:09 -------- d-----w- c:\program files\Lavasoft
2009-10-25 21:52 . 2009-10-25 21:52 -------- d-----w- c:\program files\Common Files\iS3
2009-10-25 21:52 . 2009-10-26 01:09 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-10-25 12:25 . 2009-10-25 12:26 31232 ----a-w- C:\dsiqvib.exe
2009-10-15 07:58 . 2009-07-17 16:22 1435648 -c----w- c:\windows\system32\dllcache\query.dll
2009-10-15 07:58 . 2009-09-04 21:03 58880 -c----w- c:\windows\system32\dllcache\msasn1.dll
2009-10-13 00:20 . 2009-10-13 00:19 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-12 13:18 . 2009-10-12 13:18 19679 ----a-w- c:\windows\system32\hacohekosy.dat
2009-10-12 04:38 . 2009-09-16 14:22 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-10-12 04:38 . 2009-09-16 14:22 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-10-12 04:38 . 2009-09-16 14:22 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-10-12 04:38 . 2009-07-16 16:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-10-12 04:37 . 2009-10-12 04:38 -------- d-----w- c:\program files\Common Files\McAfee
2009-10-12 04:37 . 2009-10-12 04:37 -------- d-----w- c:\program files\McAfee.com
2009-10-12 04:36 . 2009-10-29 21:15 -------- d-----w- c:\program files\McAfee
2009-10-12 04:25 . 2009-09-16 14:22 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-10-10 01:56 . 2009-10-10 04:01 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-08 00:08 . 2009-10-08 00:08 18432 ----a-w- C:\tixqapi.exe
2009-10-08 00:07 . 2009-10-08 00:07 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-08 00:06 . 2009-10-08 00:06 72704 ----a-w- c:\windows\system32\drivers\jqvgqsbpxthqoidx.sys
2009-10-08 00:05 . 2009-10-08 00:05 72704 ----a-w- c:\windows\system32\drivers\xynevjikbccxnmei.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-27 22:26 . 2009-08-16 13:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-27 22:26 . 2009-10-26 01:09 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-10-27 00:40 . 2009-08-16 03:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-27 00:40 . 2009-10-25 22:40 -------- d-----w- c:\program files\Spyware Doctor
2009-10-27 00:40 . 2009-10-25 22:40 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-26 01:09 . 2009-10-25 21:52 -------- d-----w- c:\program files\STOPzilla!
2009-10-26 01:09 . 2009-08-16 20:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-26 01:09 . 2009-10-25 22:10 -------- d-----w- c:\program files\XoftSpySE6
2009-10-25 22:10 . 2009-10-25 22:10 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-10-25 22:10 . 2009-10-25 22:10 -------- d-----w- c:\program files\Common Files\ParetoLogic
2009-10-25 22:10 . 2009-10-25 22:10 -------- d-----w- c:\program files\Common Files\XoftSpySE
2009-10-25 22:10 . 2009-10-25 22:10 -------- d-----w- c:\documents and settings\All Users\Application Data\XoftSpySE
2009-10-25 21:53 . 2009-10-25 21:53 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-10-24 19:11 . 2008-04-29 23:59 -------- d-----w- c:\program files\Lexmark 1200 Series
2009-10-16 12:42 . 2008-09-09 14:38 -------- d-----w- c:\documents and settings\Greg Parker\Application Data\LimeWire
2009-10-16 07:08 . 2008-07-01 21:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-13 00:19 . 2008-09-09 14:37 -------- d-----w- c:\program files\Java
2009-10-12 18:53 . 2008-04-29 23:53 84744 ----a-w- c:\documents and settings\Greg Parker\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-12 04:46 . 2008-07-02 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-08 15:31 . 2009-10-25 22:45 767952 ----a-w- c:\windows\BDTSupport(2).dll
2009-10-02 18:19 . 2009-10-25 22:45 1152470 ----a-w- c:\windows\UDB.zip
2009-09-29 07:07 . 2008-07-01 22:01 -------- d-----w- c:\program files\Microsoft Works
2009-09-21 20:06 . 2009-08-16 20:51 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-09-16 14:22 . 2009-07-08 17:44 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-13 21:46 . 2009-09-13 21:46 0 ----a-w- c:\windows\nsreg.dat
2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 22:17 . 2009-04-03 20:08 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-10 18:54 . 2009-08-16 13:28 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-08-16 13:28 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2007-04-16 20:38 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2007-04-16 20:38 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 03:33 . 2009-08-18 03:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-06 23:24 . 2008-04-29 23:34 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 23:24 . 2008-04-29 23:34 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 23:24 . 2008-04-29 23:34 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 23:24 . 2007-04-16 20:38 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 23:24 . 2008-04-29 23:34 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 23:24 . 2007-04-16 20:36 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 23:23 . 2008-04-29 23:34 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 23:23 . 2008-05-02 22:29 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 23:23 . 2008-04-29 23:34 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-06 23:23 . 2007-04-16 20:37 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 00:44 . 2007-04-16 20:38 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2007-02-28 07:15 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-02 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-03-16 57344]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-09-18 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-09-18 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-09-18 118784]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"masqform.exe"="c:\program files\PureEdge\Viewer 6.0\masqform.exe" [2003-12-03 1052672]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HDAShCut.exe [2007-04-16 61952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\iTunes\\iTunesHelper.exe"=
"c:\\Program Files\\McAfee\\MSC\\mcmscsvc.exe"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/16/2009 4:06 PM 64160]
S2 0010391256613338mcinstcleanup;McAfee Application Installer Cleanup (0010391256613338);c:\windows\TEMP\001039~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\001039~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 10:49 AM 1029456]
S3 SCR131C;SCRx31 Serial Smart Card Reader;c:\windows\system32\DRIVERS\SCR131C.sys --> c:\windows\system32\DRIVERS\SCR131C.sys [?]
S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader;c:\windows\system32\DRIVERS\SCR33X2K.sys --> c:\windows\system32\DRIVERS\SCR33X2K.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - 0010391256613338MCINSTCLEANUP
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*NewlyCreated* - NOITTUKV
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
*Deregistered* - noittukv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
fcqwhxik
.
Contents of the 'Scheduled Tasks' folder
2009-10-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
2009-10-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
2009-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-12 16:22]
2009-10-12 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-12 16:22]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.usatoday.com/mSearch Bar =
hxxp://www.mirarsearch.com/?useie5=1&q=IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Greg Parker\Application Data\Mozilla\Firefox\Profiles\g68a2i10.default\
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
Toolbar-{472734EA-242A-422B-ADF8-83D1E48CC825} - c:\program files\Spyware Doctor\BDT\PCTBrowserDefender.dll
WebBrowser-{472734EA-242A-422B-ADF8-83D1E48CC825} - c:\program files\Spyware Doctor\BDT\PCTBrowserDefender.dll
HKLM-Run-XoftSpySE - c:\program files\XoftSpySE6\XoftSpySE.exe
SharedTaskScheduler-{e47186b8-2bd3-40de-871a-76adbcd23b82} - (no file)
SSODL-piyahizal-{e47186b8-2bd3-40de-871a-76adbcd23b82} - (no file)
AddRemove-Browser Defender_is1 - c:\program files\Spyware Doctor\BDT\unins000.exe
AddRemove-Spyware Doctor - c:\program files\Spyware Doctor\unins000.exe
AddRemove-{4BB05099-1963-4268-A3BB-9153964750ED} - c:\program files\XoftSpySE6\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-29 19:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1796)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\System32\SCardSvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Lexmark 1200 Series\lxczbmon.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-10-29 19:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-29 23:07
Pre-Run: 83,163,820,032 bytes free
Post-Run: 85,527,011,328 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 736B843BAE5CDFF8843035D1BAE636BF