ComboFix 10-06-17.03 - memoirs 06/18/2010 18:01:22.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2920 [GMT -7:00]
Running from: c:\documents and settings\memoirs\Desktop\ComboFix.exe
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000013_.tmp.dll
c:\windows\system32\win.com
.
((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.
2010-06-19 03:42 . 2010-06-19 03:42 -------- d-----w- c:\documents and settings\memoirs\Application Data\Malwarebytes
2010-06-19 03:42 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-19 03:42 . 2010-06-19 03:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-19 03:42 . 2010-06-19 03:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-19 03:42 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-18 23:07 . 2010-06-18 23:11 -------- d-----w- c:\documents and settings\memoirs\Application Data\vlc
2010-06-18 04:10 . 2010-06-18 04:10 -------- d-----w- C:\_OTL
2010-06-18 04:09 . 2010-06-19 03:48 -------- d-----w- c:\documents and settings\memoirs\Local Settings\Application Data\hadkdjvi
2010-06-18 04:09 . 2010-06-19 03:48 -------- d-----w- c:\documents and settings\memoirs\Local Settings\Application Data\hnekrik
2010-06-17 05:10 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\Adrian\Local Settings\Application Data\tnfaof
2010-06-17 05:07 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\Adrian\Local Settings\Application Data\dhaegd
2010-06-17 05:04 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\Adrian\Local Settings\Application Data\qdswimv
2010-06-17 05:00 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\Adrian\Local Settings\Application Data\jclgsnask
2010-06-17 04:00 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\John Connor\Local Settings\Application Data\snoafjp
2010-06-17 03:55 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\John Connor\Local Settings\Application Data\qvveagw
2010-06-17 03:18 . 2010-06-17 05:56 -------- d-----w- c:\documents and settings\John Connor\Tracing
2010-06-17 03:02 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\John Connor\Local Settings\Application Data\fdhwbksk
2010-06-16 03:47 . 2010-06-16 03:48 -------- d-----w- c:\documents and settings\memoirs\Application Data\Mount&Blade Warband
2010-06-15 23:23 . 2010-06-16 01:23 -------- d-----w- c:\documents and settings\memoirs\Local Settings\Application Data\SecondLife
2010-06-15 23:23 . 2010-06-15 23:30 -------- d-----w- c:\documents and settings\memoirs\Application Data\SecondLife
2010-06-15 23:20 . 2010-06-15 23:20 -------- d-----w- c:\program files\SecondLifeViewer2
2010-06-15 20:58 . 2010-06-15 20:58 -------- d-s---w- c:\documents and settings\memoirs\UserData
2010-06-15 04:53 . 2010-06-19 00:30 -------- d-----w- c:\program files\PeerBlock
2010-06-15 04:51 . 2010-06-15 05:00 -------- d-----w- c:\documents and settings\memoirs\Application Data\gtk-2.0
2010-06-15 04:51 . 2010-06-15 04:51 -------- d-----w- c:\documents and settings\memoirs\Application Data\Python-Eggs
2010-06-15 04:48 . 2010-06-15 04:48 -------- d-----w- c:\program files\GTK2-Runtime
2010-06-15 04:46 . 2010-06-15 04:47 -------- d-----w- c:\program files\Deluge
2010-06-15 04:41 . 2010-06-17 02:52 -------- d-----w- c:\documents and settings\memoirs\Application Data\deluge
2010-06-14 23:44 . 2009-09-05 00:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-06-14 23:44 . 2009-09-05 00:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-06-14 23:44 . 2009-03-09 22:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2010-06-14 23:44 . 2010-06-16 03:48 -------- d-----w- c:\program files\Mount&Blade Warband
2010-06-14 22:41 . 2010-06-19 04:04 -------- d-----w- c:\documents and settings\memoirs\Tracing
2010-06-14 22:35 . 2010-06-14 22:35 -------- d-----w- c:\program files\Microsoft
2010-06-14 22:35 . 2010-06-14 22:35 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-06-14 22:32 . 2010-06-14 22:32 -------- d-----w- c:\program files\Common Files\Windows Live
2010-06-14 22:30 . 2010-06-14 22:30 -------- d-----w- c:\documents and settings\memoirs\Contacts
2010-06-13 20:37 . 2010-06-13 20:37 -------- d-----w- c:\documents and settings\John Connor\Local Settings\Application Data\My Games
2010-06-13 20:36 . 2010-06-13 20:36 -------- d-----w- C:\ProgramData
2010-06-13 14:50 . 2010-06-17 02:16 -------- d-----w- c:\documents and settings\memoirs\Application Data\Xfire
2010-06-13 14:44 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-06-13 14:44 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-06-13 14:44 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-06-13 14:44 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-06-13 14:41 . 2010-05-21 21:14 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-06-10 20:02 . 2010-06-19 01:02 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-06-10 20:02 . 2010-06-10 21:44 -------- d-----w- c:\program files\eBoostr
2010-06-09 21:06 . 2010-06-09 21:06 -------- d-----w- c:\program files\Scanti
2010-06-09 20:56 . 2010-06-09 20:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-06-09 20:56 . 2010-06-09 20:57 -------- d-----w- c:\program files\NVIDIA Corporation
2010-06-09 20:55 . 2010-04-03 22:55 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-06-09 20:55 . 2010-04-03 22:55 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-06-03 20:48 . 2010-06-03 20:48 -------- d-----w- c:\program files\NTCore
2010-05-28 00:09 . 2010-05-28 00:09 41872 ----a-w- c:\windows\system32\xfcodec.dll
2010-05-25 02:35 . 2010-06-02 19:04 -------- d-----w- c:\program files\Mass Effect 2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-18 20:26 . 2008-11-15 02:48 -------- d-----w- c:\program files\Steam
2010-06-17 05:07 . 2008-11-03 14:25 23304 ----a-w- c:\documents and settings\Adrian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-17 03:01 . 2009-12-30 00:32 23304 ----a-w- c:\documents and settings\John Connor\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-15 01:47 . 2008-11-14 23:05 -------- d-----w- c:\program files\Xfire
2010-06-15 01:47 . 2008-11-15 05:43 -------- d-----w- c:\program files\Zune
2010-06-15 01:46 . 2010-06-15 01:46 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_zumbus_01009.Wdf
2010-06-15 01:46 . 2010-06-15 01:46 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-06-14 22:41 . 2009-06-04 21:19 23304 ----a-w- c:\documents and settings\memoirs\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-14 22:34 . 2008-11-14 19:53 -------- d-----w- c:\program files\Windows Live
2010-06-13 14:42 . 2008-11-27 05:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-10 20:12 . 2009-11-22 22:30 -------- d-----w- c:\documents and settings\memoirs\Application Data\U3
2010-06-09 21:09 . 2010-05-10 23:21 -------- d-----w- c:\program files\FaceGen Modeller 3.4 Free
2010-06-06 04:30 . 2008-11-03 17:31 -------- d-----w- c:\program files\Bethesda Softworks
2010-06-04 17:24 . 2008-11-19 02:12 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-06-04 17:15 . 2009-02-06 04:57 -------- d-----w- c:\program files\Paradox Interactive
2010-06-04 17:12 . 2008-11-03 15:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-04 16:58 . 2009-02-19 15:53 -------- d-----w- c:\program files\Maxis
2010-06-04 16:43 . 2009-03-03 04:17 -------- d-----w- c:\program files\AOE II & III
2010-06-03 23:04 . 2009-09-11 23:26 -------- d-----w- c:\documents and settings\memoirs\Application Data\dvdcss
2010-05-30 19:58 . 2010-04-06 05:02 -------- d-----w- c:\documents and settings\memoirs\Application Data\Grand Ages Rome
2010-05-29 18:37 . 2010-02-03 23:38 -------- d-----w- c:\documents and settings\memoirs\Application Data\Any Audio Converter
2010-05-25 02:54 . 2010-04-25 23:18 -------- d-----w- c:\program files\Common Files\BioWare
2010-05-19 07:35 . 2009-07-07 01:59 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-18 22:04 . 2010-04-25 22:54 -------- d-----w- c:\program files\Mass Effect
2010-05-16 15:15 . 2008-11-03 21:26 -------- d-----w- c:\program files\Warcraft III
2010-05-12 21:31 . 2010-05-12 21:31 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2010-05-12 21:31 . 2010-05-12 21:31 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2010-05-11 22:38 . 2010-05-11 01:30 -------- d-----w- c:\program files\Alcohol 120
2010-05-11 21:55 . 2010-05-10 23:01 -------- d-----w- c:\program files\roms
2010-05-11 01:24 . 2009-01-09 10:04 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-05-10 23:22 . 2010-05-10 23:22 -------- d-----w- c:\documents and settings\memoirs\Application Data\FaceGen
2010-05-10 23:21 . 2010-05-10 23:21 766 ----a-r- c:\documents and settings\memoirs\Application Data\Microsoft\Installer\{05156799-4EC3-4885-864E-E190A429B307}\_6FEFF9B68218417F98F549.exe
2010-05-10 23:21 . 2010-05-10 23:21 766 ----a-r- c:\documents and settings\memoirs\Application Data\Microsoft\Installer\{05156799-4EC3-4885-864E-E190A429B307}\_061D43A5181EFECA1957E0.exe
2010-05-02 05:22 . 2004-08-03 23:17 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-04 00:56 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 16:09 . 2004-08-04 00:56 667136 ----a-w- c:\windows\system32\wininet.dll
2010-04-16 16:09 . 2004-08-04 00:56 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-04-08 01:58 . 2008-11-03 13:54 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-04-04 02:23 . 2010-04-04 02:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-04 02:23 . 2010-04-04 02:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-04 02:23 . 2010-04-04 02:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-04 02:23 . 2010-04-04 02:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-04 02:23 . 2010-04-04 02:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-04 02:22 . 2010-04-04 02:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-04-03 22:55 . 2009-05-01 05:02 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-04-03 22:55 . 2009-05-01 05:02 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-04-03 22:55 . 2009-05-01 05:02 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-04-03 22:55 . 2008-11-03 14:07 600680 ----a-w- c:\windows\system32\nvudisp.exe
2010-04-03 22:55 . 2008-10-07 20:33 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-04-03 22:55 . 2008-10-07 20:33 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-04-03 22:55 . 2008-10-07 20:33 227944 ----a-w- c:\windows\system32\nvcodins.dll
2010-04-03 22:55 . 2008-10-07 20:33 227944 ----a-w- c:\windows\system32\nvcod.dll
2010-04-03 22:55 . 2008-10-07 20:33 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-04-03 22:55 . 2008-10-07 20:33 1097728 ----a-w- c:\windows\system32\nvapi.dll
2010-04-03 22:55 . 2008-10-07 20:33 10232128 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"PeerBlock"="c:\program files\PeerBlock\peerblock.exe" [2010-06-10 1843312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 16862208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\jdk\bin\jusched.exe" [2009-05-10 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-04 13670504]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-04 110696]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-01-07 158448]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2008-8-8 1011320]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"\\\\GOLLUM\\SID MEIER'S CIVILIZATION 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\insurgency\\hl2.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Warcraft III\\war3.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\source sdk base 2007\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\age of chivalry\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\counter-strike\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\condition zero deleted scenes\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Warcraft II BNE\\Warcraft II BNE.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Ubisoft\\Heroes of Might and Magic V\\bin\\H5_Game.exe"=
"c:\\JDK\\bin\\java.exe"=
"c:\\xampp\\apache\\bin\\httpd.exe"=
"c:\\xampp\\mysql\\bin\\mysqld.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Sid Meier's Civilization IV Colonization\\Colonization.exe"=
"c:\\Program Files\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Mass Effect\\Binaries\\MassEffect.exe"=
"c:\\Program Files\\Mass Effect\\MassEffectLauncher.exe"=
"c:\\Program Files\\Mass Effect 2\\Binaries\\MassEffect2.exe"=
"c:\\Program Files\\Mass Effect 2\\MassEffect2Launcher.exe"=
"c:\\Program Files\\EA Games\\EADM\\Core.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Deluge\\Deluge-Python\\deluge.exe"=
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\EBoost.sys [8/8/2008 5:17 AM 96376]
R2 EBOOSTRSVC;eBoostr Service;c:\program files\eBoostr\EBstrSvc.exe [8/8/2008 5:17 AM 843384]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1/9/2009 3:04 AM 721904]
S3 jatmlano;jatmlano;\??\c:\docume~1\memoirs\LOCALS~1\Temp\jatmlano.sys --> c:\docume~1\memoirs\LOCALS~1\Temp\jatmlano.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 2:10 PM 32512]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
2010-06-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyServer = http=127.0.0.1:1032
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\memoirs\Application Data\Mozilla\Firefox\Profiles\0a4zo8ah.default\
FF - plugin: c:\jdk\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\jdk\bin\new_plugin\npjp2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-nwiz - nwiz.exe
AddRemove-Age of Empires 2.0 - c:\program files\Microsoft Games\Age of Empires II\UNINSTAL.EXE
AddRemove-Age of Empires II: The Conquerors Expansion 1.0 - c:\program files\Microsoft Games\Age of Empires II\UNINSTALX.EXE
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
AddRemove-OpenAL - c:\program files\OpenAL\oalinst.exe
AddRemove-Wilderness Sounds 3.0 by Puma Man - c:\program files\Bethesda Softworks\Morrowind\Data Files\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-18 18:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\COMRes.dll
.
Completion time: 2010-06-18 18:08:28
ComboFix-quarantined-files.txt 2010-06-19 01:08
Pre-Run: 97,680,326,656 bytes free
Post-Run: 97,776,287,744 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 197C71DBEFDABFD60275F7FD8A783C3B
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2920 [GMT -7:00]
Running from: c:\documents and settings\memoirs\Desktop\ComboFix.exe
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000013_.tmp.dll
c:\windows\system32\win.com
.
((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.
2010-06-19 03:42 . 2010-06-19 03:42 -------- d-----w- c:\documents and settings\memoirs\Application Data\Malwarebytes
2010-06-19 03:42 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-19 03:42 . 2010-06-19 03:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-19 03:42 . 2010-06-19 03:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-19 03:42 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-18 23:07 . 2010-06-18 23:11 -------- d-----w- c:\documents and settings\memoirs\Application Data\vlc
2010-06-18 04:10 . 2010-06-18 04:10 -------- d-----w- C:\_OTL
2010-06-18 04:09 . 2010-06-19 03:48 -------- d-----w- c:\documents and settings\memoirs\Local Settings\Application Data\hadkdjvi
2010-06-18 04:09 . 2010-06-19 03:48 -------- d-----w- c:\documents and settings\memoirs\Local Settings\Application Data\hnekrik
2010-06-17 05:10 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\Adrian\Local Settings\Application Data\tnfaof
2010-06-17 05:07 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\Adrian\Local Settings\Application Data\dhaegd
2010-06-17 05:04 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\Adrian\Local Settings\Application Data\qdswimv
2010-06-17 05:00 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\Adrian\Local Settings\Application Data\jclgsnask
2010-06-17 04:00 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\John Connor\Local Settings\Application Data\snoafjp
2010-06-17 03:55 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\John Connor\Local Settings\Application Data\qvveagw
2010-06-17 03:18 . 2010-06-17 05:56 -------- d-----w- c:\documents and settings\John Connor\Tracing
2010-06-17 03:02 . 2010-06-18 07:25 -------- d-----w- c:\documents and settings\John Connor\Local Settings\Application Data\fdhwbksk
2010-06-16 03:47 . 2010-06-16 03:48 -------- d-----w- c:\documents and settings\memoirs\Application Data\Mount&Blade Warband
2010-06-15 23:23 . 2010-06-16 01:23 -------- d-----w- c:\documents and settings\memoirs\Local Settings\Application Data\SecondLife
2010-06-15 23:23 . 2010-06-15 23:30 -------- d-----w- c:\documents and settings\memoirs\Application Data\SecondLife
2010-06-15 23:20 . 2010-06-15 23:20 -------- d-----w- c:\program files\SecondLifeViewer2
2010-06-15 20:58 . 2010-06-15 20:58 -------- d-s---w- c:\documents and settings\memoirs\UserData
2010-06-15 04:53 . 2010-06-19 00:30 -------- d-----w- c:\program files\PeerBlock
2010-06-15 04:51 . 2010-06-15 05:00 -------- d-----w- c:\documents and settings\memoirs\Application Data\gtk-2.0
2010-06-15 04:51 . 2010-06-15 04:51 -------- d-----w- c:\documents and settings\memoirs\Application Data\Python-Eggs
2010-06-15 04:48 . 2010-06-15 04:48 -------- d-----w- c:\program files\GTK2-Runtime
2010-06-15 04:46 . 2010-06-15 04:47 -------- d-----w- c:\program files\Deluge
2010-06-15 04:41 . 2010-06-17 02:52 -------- d-----w- c:\documents and settings\memoirs\Application Data\deluge
2010-06-14 23:44 . 2009-09-05 00:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-06-14 23:44 . 2009-09-05 00:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-06-14 23:44 . 2009-03-09 22:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2010-06-14 23:44 . 2010-06-16 03:48 -------- d-----w- c:\program files\Mount&Blade Warband
2010-06-14 22:41 . 2010-06-19 04:04 -------- d-----w- c:\documents and settings\memoirs\Tracing
2010-06-14 22:35 . 2010-06-14 22:35 -------- d-----w- c:\program files\Microsoft
2010-06-14 22:35 . 2010-06-14 22:35 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-06-14 22:32 . 2010-06-14 22:32 -------- d-----w- c:\program files\Common Files\Windows Live
2010-06-14 22:30 . 2010-06-14 22:30 -------- d-----w- c:\documents and settings\memoirs\Contacts
2010-06-13 20:37 . 2010-06-13 20:37 -------- d-----w- c:\documents and settings\John Connor\Local Settings\Application Data\My Games
2010-06-13 20:36 . 2010-06-13 20:36 -------- d-----w- C:\ProgramData
2010-06-13 14:50 . 2010-06-17 02:16 -------- d-----w- c:\documents and settings\memoirs\Application Data\Xfire
2010-06-13 14:44 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-06-13 14:44 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-06-13 14:44 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-06-13 14:44 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-06-13 14:41 . 2010-05-21 21:14 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-06-10 20:02 . 2010-06-19 01:02 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-06-10 20:02 . 2010-06-10 21:44 -------- d-----w- c:\program files\eBoostr
2010-06-09 21:06 . 2010-06-09 21:06 -------- d-----w- c:\program files\Scanti
2010-06-09 20:56 . 2010-06-09 20:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-06-09 20:56 . 2010-06-09 20:57 -------- d-----w- c:\program files\NVIDIA Corporation
2010-06-09 20:55 . 2010-04-03 22:55 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-06-09 20:55 . 2010-04-03 22:55 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-06-03 20:48 . 2010-06-03 20:48 -------- d-----w- c:\program files\NTCore
2010-05-28 00:09 . 2010-05-28 00:09 41872 ----a-w- c:\windows\system32\xfcodec.dll
2010-05-25 02:35 . 2010-06-02 19:04 -------- d-----w- c:\program files\Mass Effect 2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-18 20:26 . 2008-11-15 02:48 -------- d-----w- c:\program files\Steam
2010-06-17 05:07 . 2008-11-03 14:25 23304 ----a-w- c:\documents and settings\Adrian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-17 03:01 . 2009-12-30 00:32 23304 ----a-w- c:\documents and settings\John Connor\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-15 01:47 . 2008-11-14 23:05 -------- d-----w- c:\program files\Xfire
2010-06-15 01:47 . 2008-11-15 05:43 -------- d-----w- c:\program files\Zune
2010-06-15 01:46 . 2010-06-15 01:46 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_zumbus_01009.Wdf
2010-06-15 01:46 . 2010-06-15 01:46 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-06-14 22:41 . 2009-06-04 21:19 23304 ----a-w- c:\documents and settings\memoirs\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-14 22:34 . 2008-11-14 19:53 -------- d-----w- c:\program files\Windows Live
2010-06-13 14:42 . 2008-11-27 05:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-10 20:12 . 2009-11-22 22:30 -------- d-----w- c:\documents and settings\memoirs\Application Data\U3
2010-06-09 21:09 . 2010-05-10 23:21 -------- d-----w- c:\program files\FaceGen Modeller 3.4 Free
2010-06-06 04:30 . 2008-11-03 17:31 -------- d-----w- c:\program files\Bethesda Softworks
2010-06-04 17:24 . 2008-11-19 02:12 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-06-04 17:15 . 2009-02-06 04:57 -------- d-----w- c:\program files\Paradox Interactive
2010-06-04 17:12 . 2008-11-03 15:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-04 16:58 . 2009-02-19 15:53 -------- d-----w- c:\program files\Maxis
2010-06-04 16:43 . 2009-03-03 04:17 -------- d-----w- c:\program files\AOE II & III
2010-06-03 23:04 . 2009-09-11 23:26 -------- d-----w- c:\documents and settings\memoirs\Application Data\dvdcss
2010-05-30 19:58 . 2010-04-06 05:02 -------- d-----w- c:\documents and settings\memoirs\Application Data\Grand Ages Rome
2010-05-29 18:37 . 2010-02-03 23:38 -------- d-----w- c:\documents and settings\memoirs\Application Data\Any Audio Converter
2010-05-25 02:54 . 2010-04-25 23:18 -------- d-----w- c:\program files\Common Files\BioWare
2010-05-19 07:35 . 2009-07-07 01:59 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-18 22:04 . 2010-04-25 22:54 -------- d-----w- c:\program files\Mass Effect
2010-05-16 15:15 . 2008-11-03 21:26 -------- d-----w- c:\program files\Warcraft III
2010-05-12 21:31 . 2010-05-12 21:31 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2010-05-12 21:31 . 2010-05-12 21:31 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2010-05-11 22:38 . 2010-05-11 01:30 -------- d-----w- c:\program files\Alcohol 120
2010-05-11 21:55 . 2010-05-10 23:01 -------- d-----w- c:\program files\roms
2010-05-11 01:24 . 2009-01-09 10:04 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-05-10 23:22 . 2010-05-10 23:22 -------- d-----w- c:\documents and settings\memoirs\Application Data\FaceGen
2010-05-10 23:21 . 2010-05-10 23:21 766 ----a-r- c:\documents and settings\memoirs\Application Data\Microsoft\Installer\{05156799-4EC3-4885-864E-E190A429B307}\_6FEFF9B68218417F98F549.exe
2010-05-10 23:21 . 2010-05-10 23:21 766 ----a-r- c:\documents and settings\memoirs\Application Data\Microsoft\Installer\{05156799-4EC3-4885-864E-E190A429B307}\_061D43A5181EFECA1957E0.exe
2010-05-02 05:22 . 2004-08-03 23:17 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-04 00:56 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 16:09 . 2004-08-04 00:56 667136 ----a-w- c:\windows\system32\wininet.dll
2010-04-16 16:09 . 2004-08-04 00:56 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-04-08 01:58 . 2008-11-03 13:54 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-04-04 02:23 . 2010-04-04 02:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-04 02:23 . 2010-04-04 02:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-04 02:23 . 2010-04-04 02:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-04 02:23 . 2010-04-04 02:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-04 02:23 . 2010-04-04 02:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-04 02:22 . 2010-04-04 02:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-04-03 22:55 . 2009-05-01 05:02 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-04-03 22:55 . 2009-05-01 05:02 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-04-03 22:55 . 2009-05-01 05:02 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-04-03 22:55 . 2008-11-03 14:07 600680 ----a-w- c:\windows\system32\nvudisp.exe
2010-04-03 22:55 . 2008-10-07 20:33 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-04-03 22:55 . 2008-10-07 20:33 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-04-03 22:55 . 2008-10-07 20:33 227944 ----a-w- c:\windows\system32\nvcodins.dll
2010-04-03 22:55 . 2008-10-07 20:33 227944 ----a-w- c:\windows\system32\nvcod.dll
2010-04-03 22:55 . 2008-10-07 20:33 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-04-03 22:55 . 2008-10-07 20:33 1097728 ----a-w- c:\windows\system32\nvapi.dll
2010-04-03 22:55 . 2008-10-07 20:33 10232128 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"PeerBlock"="c:\program files\PeerBlock\peerblock.exe" [2010-06-10 1843312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 16862208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\jdk\bin\jusched.exe" [2009-05-10 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-04 13670504]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-04 110696]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-01-07 158448]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2008-8-8 1011320]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"\\\\GOLLUM\\SID MEIER'S CIVILIZATION 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\insurgency\\hl2.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Warcraft III\\war3.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\source sdk base 2007\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\age of chivalry\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\counter-strike\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\condition zero deleted scenes\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\adrianwar\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Warcraft II BNE\\Warcraft II BNE.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Ubisoft\\Heroes of Might and Magic V\\bin\\H5_Game.exe"=
"c:\\JDK\\bin\\java.exe"=
"c:\\xampp\\apache\\bin\\httpd.exe"=
"c:\\xampp\\mysql\\bin\\mysqld.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Sid Meier's Civilization IV Colonization\\Colonization.exe"=
"c:\\Program Files\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Mass Effect\\Binaries\\MassEffect.exe"=
"c:\\Program Files\\Mass Effect\\MassEffectLauncher.exe"=
"c:\\Program Files\\Mass Effect 2\\Binaries\\MassEffect2.exe"=
"c:\\Program Files\\Mass Effect 2\\MassEffect2Launcher.exe"=
"c:\\Program Files\\EA Games\\EADM\\Core.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\empire total war\\Empire.exe"=
"c:\\Program Files\\Deluge\\Deluge-Python\\deluge.exe"=
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\EBoost.sys [8/8/2008 5:17 AM 96376]
R2 EBOOSTRSVC;eBoostr Service;c:\program files\eBoostr\EBstrSvc.exe [8/8/2008 5:17 AM 843384]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1/9/2009 3:04 AM 721904]
S3 jatmlano;jatmlano;\??\c:\docume~1\memoirs\LOCALS~1\Temp\jatmlano.sys --> c:\docume~1\memoirs\LOCALS~1\Temp\jatmlano.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 2:10 PM 32512]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
2010-06-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyServer = http=127.0.0.1:1032
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\memoirs\Application Data\Mozilla\Firefox\Profiles\0a4zo8ah.default\
FF - plugin: c:\jdk\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\jdk\bin\new_plugin\npjp2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-nwiz - nwiz.exe
AddRemove-Age of Empires 2.0 - c:\program files\Microsoft Games\Age of Empires II\UNINSTAL.EXE
AddRemove-Age of Empires II: The Conquerors Expansion 1.0 - c:\program files\Microsoft Games\Age of Empires II\UNINSTALX.EXE
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
AddRemove-OpenAL - c:\program files\OpenAL\oalinst.exe
AddRemove-Wilderness Sounds 3.0 by Puma Man - c:\program files\Bethesda Softworks\Morrowind\Data Files\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-18 18:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\COMRes.dll
.
Completion time: 2010-06-18 18:08:28
ComboFix-quarantined-files.txt 2010-06-19 01:08
Pre-Run: 97,680,326,656 bytes free
Post-Run: 97,776,287,744 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 197C71DBEFDABFD60275F7FD8A783C3B