ComboFix 10-05-05.02 - Maxim 05/05/2010 15:25:11.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3326.2975 [GMT -4:00]
Running from: c:\documents and settings\Maxim\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Maxim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
c:\documents and settings\Maxim\Local Settings\Temporary Internet Files\_tm4C4.tmp
c:\documents and settings\Maxim\Local Settings\Temporary Internet Files\_tm5B8.tmp
c:\documents and settings\Maxim\Local Settings\Temporary Internet Files\_tm610.tmp
c:\documents and settings\Maxim\Local Settings\Temporary Internet Files\stb06759.tmp
c:\documents and settings\Maxim\Start Menu\Programs\Startup\MagicDisc.lnk
c:\progra~1\OfficeKB\OfficeKB.EXE
c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe
c:\program files\Analog Devices\Core\smax4pnp.exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm.exe
c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
c:\program files\Common Files\Real\Update_OB\realsched.exe
c:\program files\CyberLink\PowerDVD\Language\Language.exe
c:\program files\CyberLink\PowerDVD\pdvdserv.exe
c:\program files\iTunes\ituneshelper.exe
c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
c:\program files\Mozilla Firefox\khalmnpr.exe
c:\program files\Mozilla Firefox\rundll32 .exe
c:\program files\NVIDIA Corporation\nView\nwiz.exe
c:\program files\Pando Networks\Media Booster\PMB.exe
c:\program files\QuickTime\qttask.exe
c:\program files\WindowsUpdate
c:\windows\run.log
c:\windows\system32\ctfmon .exe
c:\windows\system32\drivers\kdvegt.sys
c:\windows\system32\driVERs\qnzdbec.sys
c:\windows\system32\drivers\zfibn.sys
----- File Replicators -----
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\athena02\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\athena02\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\CammyCustom\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\CammyCustom\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\CIEL\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\CIEL\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\jotaroanmc\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\jotaroanmc\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\Judith\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\Judith\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\juggy2\charsffdtow.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\juggy2\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\shinobi\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\shinobi\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\spiderman\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\spiderman\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\superman01\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\superman01\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\WARCUEID\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\WARCUEID\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\athena02\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\athena02\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\CammyCustom\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\CammyCustom\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\CIEL\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\CIEL\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\jotaroanmc\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\jotaroanmc\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\Judith\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\Judith\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\juggy2\charsffdtow.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\juggy2\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\shinobi\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\shinobi\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\spiderman\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\spiderman\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\superman01\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\superman01\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\WARCUEID\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\WARCUEID\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Abyss2\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Abyss2\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\AOSHI\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\AOSHI\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Armored Spiderman\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Armored Spiderman\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Baby Bonnie Hood\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Baby Bonnie Hood\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Chang\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\clara\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\cvsbenimaru\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\cvsbenimaru\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\cvsbison2\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\cvsbison2\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\EvilRanger\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\EvilRanger\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\FOXY\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\hken\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\kensou\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\pepe\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\ProfessorZoom\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\ProfessorZoom\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\ProfessorZoom\ProfessorZoom\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\ProfessorZoom\ProfessorZoom\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\RedRanger\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\RedRanger\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\act\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\act\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\cns\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\cns\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\act\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\act\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\cns\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\cns\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\act\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\act\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\cns\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\cns\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\The Kingpin v1.0bk\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\The Kingpin v1.0bk\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\TigreNegro\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\TigreNegro\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\usagent\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\usagent\dos2win.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\victor\CharSffDtoW.exe
c:\documents and settings\HelpAssistant\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\victor\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\athena02\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\athena02\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\CammyCustom\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\CammyCustom\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\CIEL\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\CIEL\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\jotaroanmc\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\jotaroanmc\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\Judith\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\Judith\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\juggy2\charsffdtow.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\juggy2\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\shinobi\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\shinobi\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\spiderman\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\spiderman\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\superman01\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\superman01\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\WARCUEID\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen Fighting Jam v2 slim\chars\WARCUEID\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\athena02\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\athena02\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\CammyCustom\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\CammyCustom\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\CIEL\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\CIEL\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\jotaroanmc\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\jotaroanmc\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\Judith\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\Judith\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\juggy2\charsffdtow.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\juggy2\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\shinobi\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\shinobi\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\spiderman\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\spiderman\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\superman01\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\superman01\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\WARCUEID\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\Mugen fighting jam v2\Mugen Fighting Jam v2 slim\chars\WARCUEID\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Abyss2\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Abyss2\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\AOSHI\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\AOSHI\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Armored Spiderman\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Armored Spiderman\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Baby Bonnie Hood\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Baby Bonnie Hood\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\Chang\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\clara\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\cvsbenimaru\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\cvsbenimaru\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\cvsbison2\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\cvsbison2\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\EvilRanger\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\EvilRanger\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\FOXY\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\hken\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\kensou\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\pepe\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\ProfessorZoom\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\ProfessorZoom\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\ProfessorZoom\ProfessorZoom\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\ProfessorZoom\ProfessorZoom\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\RedRanger\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\RedRanger\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\act\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\act\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\cns\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\cns\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_blaze\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\act\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\act\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\cns\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\cns\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_dark\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\act\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\act\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\cns\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\cns\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\so_sonic\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\The Kingpin v1.0bk\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\The Kingpin v1.0bk\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\TigreNegro\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\TigreNegro\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\usagent\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\usagent\dos2win.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\victor\CharSffDtoW.exe
c:\documents and settings\Maxim\Desktop\Max\Games\MUGEN Fury - Battle Of The Masses\chars\victor\dos2win.exe
.
Infected copy of c:\windows\system32\drivers\isapnp.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_qnzdbec
-------\Service_qnzdbec
((((((((((((((((((((((((( Files Created from 2010-04-05 to 2010-05-05 )))))))))))))))))))))))))))))))
.
2010-05-05 19:13 . 2010-05-05 19:15 -------- d-----w- C:\Combo-Fix
2010-05-05 02:08 . 2010-05-05 02:08 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2010-05-05 01:31 . 2010-05-05 01:31 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Identities
2010-05-05 00:35 . 2010-05-05 00:35 -------- d-----w- c:\documents and settings\HelpAssistant\Incomplete
2010-05-05 00:35 . 2010-05-05 00:35 -------- d-----w- c:\documents and settings\HelpAssistant\ImperialGuard5thEdition
2010-05-05 00:35 . 2010-05-05 00:35 -------- d-----w- c:\documents and settings\HelpAssistant\Hentai Legacy Megapack uncen.dvdrip.dual.audio.complete
2010-05-05 00:35 . 2010-05-05 00:35 -------- d-----w- c:\documents and settings\HelpAssistant\Dynasty Warrirors 4 Hper
2010-05-05 00:35 . 2010-05-05 00:35 -------- d-----w- c:\documents and settings\HelpAssistant\Diablo 2
2010-05-05 00:23 . 2010-05-05 00:23 -------- d-----w- c:\documents and settings\HelpAssistant\D2 Keygens
2010-05-05 00:22 . 2010-05-05 00:23 -------- d-----w- c:\documents and settings\HelpAssistant\Contacts
2010-05-05 00:22 . 2010-05-05 00:22 -------- d-----w- c:\documents and settings\HelpAssistant\Bible Black Complete
2010-05-05 00:22 . 2010-05-05 00:22 -------- d-----w- c:\documents and settings\HelpAssistant\Baki - Son of Ogre
2010-05-04 23:48 . 2010-05-04 23:48 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Conduit
2010-05-04 23:48 . 2010-05-04 23:48 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\free-downloads.net
2010-05-04 23:47 . 2010-05-04 23:47 -------- d-----w- c:\documents and settings\Maxim\Local Settings\Application Data\jodpehbio
2010-05-04 23:47 . 2010-05-04 23:47 -------- d-----w- c:\documents and settings\Maxim\Local Settings\Application Data\wngpefagk
2010-04-16 20:08 . 2010-04-16 20:40 -------- d-----w- c:\documents and settings\Maxim\Local Settings\Application Data\PMB Files
2010-04-16 20:08 . 2010-04-16 20:08 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-04-16 20:07 . 2010-04-16 20:07 -------- d-----w- c:\program files\Pando Networks
2010-04-10 19:11 . 2010-04-10 19:11 -------- d-----w- c:\program files\Veetle
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-05 19:36 . 2008-03-03 02:24 -------- d-----w- c:\documents and settings\Maxim\Application Data\OpenOffice.org2
2010-05-05 19:31 . 2008-06-20 01:59 -------- d-----w- c:\program files\QuickTime
2010-05-05 19:31 . 2008-06-20 02:00 -------- d-----w- c:\program files\iTunes
2010-05-05 19:31 . 2007-06-23 23:47 -------- d-----w- c:\program files\OfficeKB
2010-05-05 19:24 . 2007-07-03 06:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-05-04 23:47 . 2009-08-24 03:52 -------- d-----w- c:\program files\free-downloads.net
2010-05-03 16:08 . 2007-06-22 20:40 -------- d-----w- c:\program files\World of Warcraft
2010-04-29 19:39 . 2009-08-09 21:50 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2009-08-09 21:50 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-21 05:15 . 2009-03-18 06:15 -------- d-----w- c:\program files\Steam
2010-03-11 12:38 . 2006-02-28 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2006-02-28 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2006-02-28 12:00 17408 ------w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2006-02-28 12:00 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-02-27 02:27 . 2009-08-09 20:36 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-24 13:11 . 2006-02-28 12:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 2006-02-28 12:00 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2006-02-28 12:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2006-02-28 12:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2009-08-10 18:31 . 2009-08-10 18:31 286 ----a-w- c:\program files\qjhnfze.txt
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
Code:
<pre>
c:\program files\Alcohol Soft\Alcohol 120\axcmd .exe
c:\program files\Analog Devices\Core\smax4pnp .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\Ahead\Lib\nerocheck .exe
c:\program files\Common Files\Ahead\Lib\nmbgmonitor .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\CyberLink\PowerDVD\pdvdserv .exe
c:\program files\CyberLink\PowerDVD\Language\language .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\OfficeKB\officekb .exe
c:\program files\Pando Networks\Media Booster\pmb .exe
c:\program files\QuickTime\qttask .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2010-05-04 2349080]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2010-05-04 2349080]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2010-05-04 2349080]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [N/A]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"Google Update"="c:\documents and settings\Maxim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [N/A]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [N/A]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [N/A]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [N/A]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [N/A]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [N/A]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [N/A]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-10-21 29696]
"OfficeKB"="c:\progra~1\OfficeKB\OfficeKB.EXE" [N/A]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [N/A]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [N/A]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [N/A]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [N/A]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [N/A]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RealUpgradeHelper"="c:\program files\Common Files\Real\Update_OB\upgrdhlp.exe" [2010-02-02 136744]
c:\documents and settings\Maxim\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Loadout Manager.lnk - c:\program files\Belkin\Nostromo\nost_LM.exe [2003-6-24 442368]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-6-23 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2007-6-23 581632]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Apprentice\\Appr.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\THQ\\Dawn Of War\\W40kWA.exe"=
"c:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\GGclient.exe"=
"c:\\Program Files\\THQ\\Dawn Of War\\W40k.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Tortun\\gui.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Documents and Settings\\Maxim\\Desktop\\Max\\Pokemon Game.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.8.9506-to-3.0.9.9551-enUS-downloader.exe"=
"c:\\Program Files\\Dawn of War 2\\DOW2.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Riot Games\\League of Legends\\air\\LolClient.exe"=
"c:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dawn of war 2\\DOW2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP_CLI.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP_Launcher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP_DX11.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP.exe"=
"c:\\Riot Games\\League of Legends\\lol.launcher.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"4000:TCP"= 4000:TCP:diablo
"8375:TCP"= 8375:TCP:League of Legends Launcher
"8375:UDP"= 8375:UDP:League of Legends Launcher
"8376:TCP"= 8376:TCP:League of Legends Launcher
"8376:UDP"= 8376:UDP:League of Legends Launcher
"6987:TCP"= 6987:TCP:League of Legends Launcher
"6987:UDP"= 6987:UDP:League of Legends Launcher
"8377:TCP"= 8377:TCP:League of Legends Launcher
"8377:UDP"= 8377:UDP:League of Legends Launcher
"6943:TCP"= 6943:TCP:League of Legends Launcher
"6943:UDP"= 6943:UDP:League of Legends Launcher
"58328:TCP"= 58328:TCP:Pando Media Booster
"58328:UDP"= 58328:UDP:Pando Media Booster
"6926:TCP"= 6926:TCP:League of Legends Launcher
"6926:UDP"= 6926:UDP:League of Legends Launcher
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"7921:TCP"= 7921:TCP:Services
"7922:TCP"= 7922:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"8393:TCP"= 8393:TCP:League of Legends Lobby
"8393:UDP"= 8393:UDP:League of Legends Lobby
"8390:TCP"= 8390:TCP:League of Legends Game Client
"8390:UDP"= 8390:UDP:League of Legends Game Client
"6960:TCP"= 6960:TCP:League of Legends Launcher
"6960:UDP"= 6960:UDP:League of Legends Launcher
"6971:TCP"= 6971:TCP:League of Legends Launcher
"6971:UDP"= 6971:UDP:League of Legends Launcher
"8020:TCP"= 8020:TCP:Services
"8021:TCP"= 8021:TCP:Services
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/9/2009 6:35 PM 297752]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/1/2008 10:47 AM 24652]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2/27/2010 11:44 AM 57248]
S3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [7/23/2003 3:16 PM 22821]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/9/2009 5:50 PM 38224]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/13/2007 12:28 AM 722416]
.
Contents of the 'Scheduled Tasks' folder
2010-05-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]
2010-05-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-07-03 21:27]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = localhost
FF - ProfilePath - c:\documents and settings\Maxim\Application Data\Mozilla\Firefox\Profiles\pu9jai39.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\documents and settings\Maxim\Application Data\Mozilla\Firefox\Profiles\pu9jai39.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\Maxim\Application Data\Mozilla\Firefox\Profiles\pu9jai39.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\Maxim\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-05 15:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A9B3C18]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb80ecf28
\Driver\ACPI -> 0x8a9b3c18
\Driver\atapi -> atapi.sys @ 0xb7e00852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: NVIDIA nForce Networking Controller -> SendCompleteHandler -> 0x8a27f5c0
PacketIndicateHandler -> NDIS.sys @ 0xb7d11a21
SendHandler -> NDIS.sys @ 0xb7cef87b
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x02542D6C1
malicious code @ sector 0x02542D6C4 !
PE file found in sector at 0x02542D6DA !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3024)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\program files\Belkin\Nostromo\nost_FSH.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Logitech\SetPoint\KHALMNPR.EXE
c:\program files\OpenOffice.org 2.3\program\soffice.exe
c:\program files\OpenOffice.org 2.3\program\soffice.BIN
.
**************************************************************************
.
Completion time: 2010-05-05 15:46:19 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-05 19:46
ComboFix2.txt 2009-08-10 21:15
Pre-Run: 144,844,152,832 bytes free
Post-Run: 145,845,043,200 bytes free
- - End Of File - - C9B502AC6B8039981D7FD36151FD9387