ComboFix 09-12-04.05 - Owner 12/05/2009 12:06.1.1 - x86
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-4142028275-1974730795-1873161700-500
c:\windows\kb913800.exe
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\AVR10.exe
c:\windows\system32\biyosoru.dll
c:\windows\system32\critical_warning.html
c:\windows\system32\fayololu.dll
c:\windows\system32\feyavezi.dll
c:\windows\system32\fijiveni.dll
c:\windows\system32\hisozopa.dll
c:\windows\system32\jikotato.dll
c:\windows\system32\jirohowu.dll
c:\windows\system32\lavusita.dll
c:\windows\system32\logon.exe
c:\windows\system32\metitalu.dll
c:\windows\system32\netojeke.dll
c:\windows\system32\pihuzura.dll
c:\windows\system32\pirivazu.dll
c:\windows\system32\winhelper86.dll
c:\windows\system32\winlogon86.exe
c:\windows\system32\winupdate86.exe
c:\windows\system32\wojujive.dll
c:\windows\system32\yetugayu.dll
c:\windows\system32\yinazeku.dll
c:\windows\system32\zujaviwi.dll
c:\windows\Tasks\jdnilpwo.job
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-11-05 to 2009-12-05 )))))))))))))))))))))))))))))))
.
2009-12-04 22:23 . 2009-12-04 22:23 -------- d-----w- c:\program files\Trend Micro
2009-12-04 21:29 . 2009-12-04 21:29 -------- d-----w- c:\windows\Sun
2009-12-04 21:06 . 2009-12-04 21:06 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-12-04 21:05 . 2009-12-03 21:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 21:05 . 2009-12-05 12:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-04 21:05 . 2009-12-04 21:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-04 21:05 . 2009-12-03 21:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-04 03:08 . 2009-12-04 03:08 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Help
2009-12-03 17:05 . 2009-12-03 17:05 -------- d-----w- c:\documents and settings\Owner\Application Data\Jasc
2009-12-03 17:04 . 2009-12-03 17:04 -------- d-----w- c:\program files\Jasc Software Inc
2009-12-03 16:14 . 2009-12-03 16:14 -------- d-----w- c:\program files\Quick Screenshot Maker
2009-12-03 16:14 . 2009-12-03 16:14 -------- d-----w- C:\Screenshots
2009-12-03 12:49 . 2009-12-03 12:49 128 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\fusioncache.dat
2009-12-02 22:03 . 2009-12-02 22:03 -------- d-----w- c:\documents and settings\Owner\Application Data\AnvSoft
2009-12-02 22:03 . 2009-12-02 22:03 -------- d-----w- c:\program files\AnvSoft
2009-12-02 22:00 . 2009-12-02 22:00 -------- d-----w- c:\documents and settings\Owner\Application Data\Any Video Converter
2009-11-30 15:13 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2009-11-30 15:13 . 2009-11-30 15:14 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-11-30 08:05 . 2009-11-30 08:05 -------- d-----w- c:\windows\ServicePackFiles
2009-11-30 08:03 . 2009-11-30 08:03 -------- d-----w- c:\program files\MSXML 4.0
2009-11-29 08:42 . 2009-11-29 09:10 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-11-29 08:39 . 2008-05-01 14:30 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2009-11-29 08:39 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-11-29 08:38 . 2009-03-06 14:44 283648 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-11-29 08:38 . 2009-02-09 10:20 399360 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-11-29 08:38 . 2009-02-06 16:54 35328 -c----w- c:\windows\system32\dllcache\sc.exe
2009-11-29 08:38 . 2005-07-26 04:39 60416 -c----w- c:\windows\system32\dllcache\colbact.dll
2009-11-29 08:38 . 2009-02-09 10:20 616960 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-11-29 08:38 . 2009-02-09 10:20 473088 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-11-29 08:38 . 2009-02-09 10:20 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-11-29 08:38 . 2009-02-06 17:14 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-11-29 08:38 . 2009-02-06 16:39 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-11-29 08:38 . 2009-02-09 10:20 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-11-29 08:35 . 2009-06-05 07:42 655872 -c----w- c:\windows\system32\dllcache\mstscax.dll
2009-11-29 08:35 . 2009-07-31 04:57 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2009-11-29 08:35 . 2008-04-21 10:02 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-11-29 08:34 . 2008-06-13 13:10 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-11-29 08:34 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-11-29 08:33 . 2009-06-21 22:04 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-11-29 08:32 . 2008-05-08 12:28 202752 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-11-29 08:32 . 2008-12-11 11:57 333184 -c----w- c:\windows\system32\dllcache\srv.sys
2009-11-29 08:32 . 2009-07-10 13:42 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-11-29 08:32 . 2008-04-11 18:50 683520 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-11-29 08:32 . 2009-08-04 12:49 2142720 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-29 08:32 . 2009-08-04 12:51 2185984 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-11-29 08:32 . 2009-08-04 12:02 2020864 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-11-29 08:32 . 2009-08-04 12:02 2062976 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-11-29 08:31 . 2008-10-15 16:57 332800 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-11-29 08:29 . 2009-11-29 08:29 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee.com Personal Firewall
2009-11-29 00:15 . 2009-11-29 00:15 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-11-29 00:15 . 2009-11-29 11:09 -------- d-----w- c:\program files\DivX
2009-11-28 20:36 . 2009-11-28 20:36 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Graboid_Inc
2009-11-28 20:35 . 2009-11-28 20:36 -------- d-----w- c:\documents and settings\Owner\Application Data\MozillaControl
2009-11-28 20:35 . 2009-11-28 20:40 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Graboid
2009-11-28 20:34 . 2009-11-28 20:34 -------- d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
2009-11-28 20:29 . 2009-11-28 20:29 -------- d-----w- c:\documents and settings\Owner\Application Data\vlc
2009-11-28 20:22 . 2009-11-28 20:22 -------- d-----w- c:\program files\VideoLAN
2009-11-28 20:22 . 2009-11-28 20:34 -------- d-----w- c:\program files\Graboid
2009-11-28 17:02 . 2009-11-28 17:03 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Adobe
2009-11-28 15:05 . 2009-11-28 12:53 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2009-11-28 14:52 . 2009-11-28 14:52 -------- d-----w- c:\windows\system32\Lang
2009-11-28 14:51 . 2009-11-28 14:51 -------- d-----w- c:\windows\system32\LogFiles
2009-11-28 14:43 . 2009-11-28 14:43 -------- d-----w- c:\documents and settings\Administrator\Application Data\AOL
2009-11-28 14:32 . 2009-11-28 14:32 -------- d-----w- c:\program files\McAfee
2009-11-28 14:32 . 2009-11-28 14:32 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-28 14:32 . 2005-11-12 00:43 80640 ----a-w- c:\windows\system32\drivers\MpFirewall.sys
2009-11-28 14:32 . 2005-11-12 00:38 9216 ----a-w- c:\windows\system32\MpfApi.dll
2009-11-28 14:32 . 2009-12-05 16:56 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-11-28 14:31 . 2005-08-10 19:22 114464 ----a-w- c:\windows\system32\drivers\naiavf5x.sys
2009-11-28 14:31 . 2009-11-28 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-11-28 14:31 . 2009-11-28 14:32 -------- d-----w- c:\program files\McAfee.com
2009-11-28 14:31 . 2005-12-19 01:01 349760 ----a-w- c:\windows\system32\mcinsctl.dll
2009-11-28 14:31 . 2005-12-19 01:01 288320 ----a-w- c:\windows\system32\mcgdmgr.dll
2009-11-28 14:30 . 2003-03-25 13:00 67072 ----a-w- c:\windows\POWERCFG.EXE
2009-11-28 14:30 . 2006-01-18 11:41 80512 ----a-w- c:\windows\system32\drivers\Rtnicxp.sys
2009-11-28 14:28 . 2001-11-21 18:15 102400 ----a-w- c:\windows\system32\SimpleRegistry.dll
2009-11-28 14:27 . 2009-11-28 14:27 -------- d-----w- c:\program files\Microsoft Works
2009-11-28 14:26 . 2009-11-28 14:26 -------- d-----w- c:\program files\MSN Encarta Plus
2009-11-28 14:26 . 2009-11-28 14:26 4 ----a-w- c:\windows\Pix11.dat
2009-11-28 14:26 . 2009-11-28 14:26 -------- d-----w- c:\program files\Microsoft Digital Image 2006
2009-11-28 14:24 . 2006-03-09 10:45 364544 ----a-w- c:\windows\RtlUpd.exe
2009-11-28 14:24 . 2006-02-20 10:00 86016 ----a-w- c:\windows\SoundMan.exe
2009-11-28 14:24 . 2006-03-14 08:49 9711104 ----a-w- c:\windows\RTLCPL.exe
2009-11-28 14:24 . 2006-04-06 07:20 4258816 ----a-w- c:\windows\system32\drivers\RtkHDAud.Sys
2009-11-28 14:24 . 2006-04-04 10:44 16120832 ----a-w- c:\windows\RTHDCPL.exe
2009-11-28 14:24 . 2006-03-10 12:32 2158592 ----a-w- c:\windows\MicCal.exe
2009-11-28 14:24 . 2009-11-28 14:30 -------- d-----w- c:\program files\Realtek
2009-11-28 14:24 . 2006-03-14 08:45 2809344 ----a-w- c:\windows\alcwzrd.exe
2009-11-28 14:24 . 2005-05-03 11:43 69632 ----a-w- c:\windows\Alcmtr.exe
2009-11-28 14:24 . 2005-04-16 15:20 487424 ----a-w- c:\windows\RtlExUpd.dll
2009-11-28 14:24 . 2006-01-26 16:57 520192 ----a-w- c:\windows\system32\ati2sgag.exe
2009-11-28 14:23 . 2004-09-04 00:07 20480 ----a-w- c:\windows\system32\Marker32.exe
2009-11-28 14:22 . 2009-11-28 14:23 -------- d-----w- c:\program files\Java
2009-11-28 14:22 . 2009-11-28 14:22 -------- d-----w- c:\program files\Common Files\Java
2009-11-28 14:22 . 2009-11-28 14:22 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150020}
2009-11-28 14:22 . 2006-01-31 19:54 94208 ----a-w- c:\windows\system32\bae.dll
2009-11-28 14:22 . 2004-07-15 22:08 471300 ----a-w- c:\windows\wallpe.exe
2009-11-28 14:22 . 2009-11-28 14:22 -------- d-----w- c:\program files\Digital Media Reader
2009-11-28 14:22 . 2009-11-28 14:22 -------- d-----w- c:\windows\Downloaded Installations
2009-11-28 14:20 . 2009-11-28 12:53 -------- d-----w- c:\documents and settings\Default User\WINDOWS
2009-11-28 14:19 . 2004-03-22 22:17 25840 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2009-11-28 14:19 . 2004-03-22 22:17 24816 ----a-w- c:\windows\system32\mdimon.dll
2009-11-28 14:19 . 2009-11-28 14:19 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-11-28 14:19 . 2009-11-28 14:19 -------- d-----w- c:\windows\SHELLNEW
2009-11-28 14:18 . 2009-11-28 14:18 -------- d-----w- c:\program files\Microsoft.NET
2009-11-28 14:18 . 2009-11-28 14:18 -------- d-----r- C:\MSOCache
2009-11-28 14:18 . 2009-11-28 14:18 -------- d-----w- c:\program files\Google
2009-11-28 14:15 . 2009-11-28 14:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-28 14:15 . 2009-11-28 14:16 -------- d-----w- c:\program files\CyberLink
2009-11-28 14:15 . 2009-11-28 14:23 -------- d-----w- c:\program files\Common Files\InstallShield
2009-11-28 14:13 . 2009-11-28 14:13 -------- d-----w- c:\program files\Common Files\New Boundary
2009-11-28 14:13 . 2009-11-28 14:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Prism Deploy
2009-11-28 14:09 . 2009-11-28 14:09 -------- d-----w- c:\program files\CONEXANT
2009-11-28 14:08 . 2004-08-04 06:31 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys
2009-11-28 14:08 . 2004-08-04 08:56 7168 ----a-w- c:\windows\system32\hccoin.dll
2009-11-28 14:08 . 2004-08-04 07:08 26624 ----a-w- c:\windows\system32\drivers\usbehci.sys
2009-11-28 14:08 . 2004-08-04 07:08 17024 ----a-w- c:\windows\system32\drivers\usbohci.sys
2009-11-28 12:58 . 2009-11-28 14:33 -------- d-----w- c:\windows\creator
2009-11-28 12:57 . 2004-03-17 03:04 13059 ----a-w- c:\windows\system32\drivers\mdmxsdk.sys
2009-11-28 12:57 . 2004-03-17 03:00 86016 ----a-w- c:\windows\system32\mdmxsdk.dll
2009-11-28 12:57 . 2005-03-17 00:51 1033600 ----a-w- c:\windows\system32\drivers\HSF_DPV.sys
2009-11-28 12:57 . 2005-03-17 00:50 221440 ----a-w- c:\windows\system32\drivers\HSFHWBS2.sys
2009-11-28 12:57 . 2005-03-17 00:50 705280 ----a-w- c:\windows\system32\drivers\HSF_CNXT.sys
2009-11-28 12:57 . 2005-02-23 06:02 42858 ----a-w- c:\windows\system32\hsfci014.dll
2009-11-28 12:57 . 2009-11-28 14:28 -------- d-----w- c:\windows\SMINST
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-28 15:25 . 2005-01-10 01:26 33904 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-28 14:43 . 2009-11-28 15:06 -------- d-----w- c:\documents and settings\Owner\Application Data\AOL
2009-11-28 14:30 . 2009-11-28 14:29 -------- d-----w- c:\program files\Microsoft Money 2006
2009-11-28 14:29 . 2009-11-28 14:28 -------- d-----w- c:\program files\America Online 9.0
2009-11-28 14:29 . 2009-11-28 14:28 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-11-28 14:29 . 2009-11-28 14:28 -------- d-----w- c:\program files\Common Files\AOL
2009-11-28 14:29 . 2009-11-28 15:06 -------- d-----w- c:\documents and settings\Owner\Application Data\You've Got Pictures Screensaver
2009-11-28 14:29 . 2009-11-28 14:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\You've Got Pictures Screensaver
2009-11-28 14:29 . 2009-11-28 14:29 -------- d-----w- c:\program files\Common Files\Nullsoft
2009-11-28 14:29 . 2009-11-28 14:28 -------- d-----w- c:\program files\Common Files\aolshare
2009-11-28 14:29 . 2009-11-28 14:29 -------- d-----w- c:\program files\QuickTime
2009-11-28 14:29 . 2009-11-28 14:29 -------- d-----w- c:\documents and settings\All Users\Application Data\QuickTime
2009-11-28 14:29 . 2009-11-28 14:29 8552 ----a-w- c:\windows\system32\drivers\asctrm.sys
2009-11-28 14:29 . 2009-11-28 14:29 -------- d-----w- c:\program files\Common Files\Real
2009-11-28 14:29 . 2009-11-28 14:29 -------- d-----w- c:\program files\Real
2009-11-28 14:25 . 2009-11-28 14:25 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-28 12:53 . 2005-01-10 01:13 -------- d-----w- c:\program files\microsoft frontpage
2009-11-28 12:53 . 2005-01-10 01:06 -------- d-----w- c:\program files\Windows Plus
2009-09-25 05:56 . 2008-05-25 08:39 662016 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:56 . 2008-05-25 08:33 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2008-05-25 08:36 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-09-03 04:01 . 2009-09-03 04:01 61952 --sha-w- c:\windows\system32\bozoyipo.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"HostManager"="c:\program files\Common Files\AOL\1259418501\EE\AOLHostManager.exe" [2004-11-03 125528]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-19 79448]
"VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-09 151552]
"OASClnt"="c:\program files\McAfee.com\VSO\oasclnt.exe" [2005-08-12 53248]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-23 303104]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\McUpdate.exe" [2005-08-26 212992]
"MSKAGENTEXE"="c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 110592]
"MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-13 1121792]
"VirusScan Online"="c:\progra~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 163840]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-12 1005096]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-04-04 16120832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - c:\program files\BigFix\bigfix.exe [2009-11-28 2168360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1259418501\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
.
Contents of the 'Scheduled Tasks' folder
2009-11-28 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2008-05-25 19:00]
2009-11-28 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2008-05-25 19:00]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=W3503mStart Page =
hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=W3503IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\gm5vbau3.default\
FF - prefs.js: browser.startup.homepage -
www.google.comFF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
BHO-{a5a7d690-5dd2-4229-99d4-43cb840e0ae5} - metitalu.dll
HKLM-Run-libobazof - c:\windows\system32\jirohowu.dll
HKLM-Run-puridagoja - lavusita.dll
SharedTaskScheduler-{e994d8d2-435d-4177-a6e5-0bd62dc966b0} - c:\windows\system32\jirohowu.dll
SSODL-pemefedey-{e994d8d2-435d-4177-a6e5-0bd62dc966b0} - c:\windows\system32\jirohowu.dll
AddRemove-PictureItSuiteTrial_v11 - c:\program files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe ADDREMOVE=1 SKU=TRIAL VERSION=11
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-05 12:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Windows Workflow Foundation 3.0.0.0]
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(540)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2964)
c:\progra~1\McAfee\SPAMKI~1\mskoeplg.dll
c:\progra~1\mcafee.com\vso\McVSSkt.dll
c:\windows\system32\msls31.dll
c:\windows\system32\shdoclc.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\MSCTF.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\progra~1\COMMON~1\AOL\125941~1\EE\AOLHOS~1.EXE
c:\progra~1\COMMON~1\AOL\125941~1\EE\AOLServiceHost.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\progra~1\mcafee.com\agent\mctskshd.exe
c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\progra~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\windows\eHome\ehmsas.exe
c:\windows\SoftwareDistribution\Download\Install\dotnetfx35_x86.exe
c:\fe4bb4318b42d8885465365da918dd\dotnetfx35setup.exe
c:\c0c385864f5da17c5b\setup.exe
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\MsiExec.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
.
**************************************************************************
.
Completion time: 2009-12-05 12:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-05 17:40
Pre-Run: 52,901,031,936 bytes free
Post-Run: 53,172,768,768 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 10B14E703536EFECE62210B34DC9EEE4