ComboFix 10-09-04.05 - Danny Nguyen 05/09/2010 16:12:51.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2894 [GMT 10:00]
Running from: c:\documents and settings\Danny Nguyen\Desktop\Combo-Fix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Danny Nguyen\.COMMgr
c:\documents and settings\Danny Nguyen\Application Data\6200AE0B8C951DD1AAA016C8F78D6AB1
c:\documents and settings\Danny Nguyen\Application Data\6200AE0B8C951DD1AAA016C8F78D6AB1\enemies-names.txt
c:\documents and settings\Danny Nguyen\Application Data\6200AE0B8C951DD1AAA016C8F78D6AB1\local.ini
c:\documents and settings\Danny Nguyen\Local Settings\Application Data\{491BF40F-58E3-4870-B095-1D53D8EBEB4D}
c:\documents and settings\Danny Nguyen\Local Settings\Application Data\{491BF40F-58E3-4870-B095-1D53D8EBEB4D}\chrome.manifest
c:\documents and settings\Danny Nguyen\Local Settings\Application Data\{491BF40F-58E3-4870-B095-1D53D8EBEB4D}\chrome\content\_cfg.js
c:\documents and settings\Danny Nguyen\Local Settings\Application Data\{491BF40F-58E3-4870-B095-1D53D8EBEB4D}\chrome\content\overlay.xul
c:\documents and settings\Danny Nguyen\Local Settings\Application Data\{491BF40F-58E3-4870-B095-1D53D8EBEB4D}\install.rdf
c:\documents and settings\Danny Nguyen\Local Settings\Application Data\Windows Server
c:\documents and settings\Danny Nguyen\Local Settings\Application Data\Windows Server\flags.ini
c:\documents and settings\Danny Nguyen\Local Settings\Application Data\Windows Server\server.dat
c:\documents and settings\Danny Nguyen\Local Settings\Application Data\Windows Server\uses32.dat
c:\windows\daemon.dll
c:\windows\system32\90980.dll
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe
.
\\.\PhysicalDrive0 - Bootkit Agent was found and disinfected
.
\\.\PhysicalDrive0 - Bootkit Agent was found and disinfected
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2010-08-05 to 2010-09-05 )))))))))))))))))))))))))))))))
.
2010-09-04 09:49 . 2010-09-04 09:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2010-09-04 09:18 . 2010-09-04 09:44 -------- d-----w- c:\windows\system32\wbem\Repository.001
2010-09-04 09:18 . 2008-04-13 19:42 1306624 -c----w- c:\windows\system32\dllcache\msxml6.dll
2010-09-04 09:18 . 2008-04-13 19:40 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll
2010-09-04 09:18 . 2008-04-13 12:57 79872 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2010-09-04 09:12 . 2010-09-04 09:12 -------- d-----w- c:\windows\ServicePackFiles
2010-09-04 07:34 . 2001-08-23 12:00 9728 -c--a-w- c:\windows\system32\dllcache\query.exe
2010-09-04 07:33 . 2001-08-23 12:00 45568 -c--a-w- c:\windows\system32\dllcache\browscap.dll
2010-09-04 07:32 . 2008-04-13 19:42 45568 ----a-w- c:\windows\system32\safrslv.dll
2010-09-04 07:31 . 2008-04-13 19:42 226816 -c--a-w- c:\windows\system32\dllcache\npdrmv2.dll
2010-09-04 07:30 . 2008-04-13 19:42 67072 ----a-w- c:\windows\system32\rdshost.exe
2010-09-04 07:22 . 2008-04-13 14:15 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-09-04 07:22 . 2008-04-13 14:15 52864 ----a-w- c:\windows\system32\drivers\dmusic.sys
2010-09-04 07:21 . 2008-04-13 19:41 4096 ----a-w- c:\windows\system32\ksuser.dll
2010-09-04 07:21 . 2008-04-13 14:10 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2010-09-04 07:21 . 2008-04-13 19:43 40840 ----a-w- c:\windows\system32\drivers\termdd.sys
2010-09-04 07:21 . 2008-04-13 14:02 196224 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2010-09-04 07:20 . 2008-04-13 19:42 146432 ----a-w- c:\windows\system\winspool.drv
2010-09-04 07:20 . 2008-04-13 14:24 11264 ----a-w- c:\windows\system32\drivers\irenum.sys
2010-09-04 07:20 . 2001-08-23 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2010-09-04 07:20 . 2001-08-23 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-09-04 07:20 . 2001-08-23 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2010-09-04 07:20 . 2001-08-23 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2010-09-04 07:20 . 2008-04-13 19:42 74752 ----a-w- c:\windows\system32\storprop.dll
2010-09-04 01:45 . 2008-04-14 08:00 82432 ---h-tw- c:\windows\system32\d0d0404.dll
2010-09-04 01:45 . 2008-04-14 08:00 82432 ---h-tw- c:\windows\system32\156743a.dll
2010-09-03 09:20 . 2010-09-03 09:20 -------- d-----w- c:\windows\XSxS
2010-09-03 09:20 . 2010-09-03 09:20 -------- d-----w- c:\program files\Xenocode
2010-09-03 09:20 . 2010-09-03 09:20 -------- d-----w- c:\documents and settings\Danny Nguyen\Local Settings\Application Data\Xenocode
2010-09-03 08:48 . 2010-09-03 08:48 -------- d--h--w- c:\windows\system32\GroupPolicy
2010-09-03 07:49 . 2010-09-03 07:49 0 ----a-w- c:\windows\Hyozusoya.bin
2010-09-03 07:49 . 2010-09-03 07:49 120 ----a-w- c:\windows\Fwabilobakamode.dat
2010-09-03 07:47 . 2010-09-03 08:37 -------- d-----w- c:\documents and settings\Danny Nguyen\Local Settings\Application Data\mnkcrbusq
2010-09-03 07:47 . 2010-09-03 08:37 -------- d-----w- c:\documents and settings\Danny Nguyen\Local Settings\Application Data\obpcrjhbc
2010-09-03 07:46 . 2010-09-04 15:52 -------- d-----w- c:\documents and settings\Danny Nguyen\Local Settings\Application Data\maldqpghu
2010-09-03 07:46 . 2010-09-03 08:37 -------- d-----w- c:\documents and settings\Danny Nguyen\Application Data\maldqpghu
2010-08-29 05:05 . 2010-08-29 05:05 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonIJSolutionMenu
2010-08-29 05:04 . 2010-08-29 05:04 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonIJMyPrinter
2010-08-29 05:04 . 2010-09-01 11:04 -------- d-----w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2010-08-29 05:03 . 2009-04-03 06:00 1310720 ----a-w- c:\windows\system32\CNC560C.dll
2010-08-29 05:03 . 2009-04-03 05:59 110592 ----a-w- c:\windows\system32\CNC560I.dll
2010-08-29 05:03 . 2009-04-03 05:57 106496 ----a-w- c:\windows\system32\CNC560U.dll
2010-08-29 05:03 . 2009-03-19 04:38 303104 ----a-w- c:\windows\system32\CNC560L.dll
2010-08-29 05:03 . 2008-08-25 08:02 15872 ----a-w- c:\windows\system32\CNHMCA.dll
2010-08-29 05:02 . 2010-08-29 05:02 -------- d-----w- c:\program files\Common Files\CANON
2010-08-29 04:59 . 2010-08-29 04:59 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonBJ
2010-08-29 04:58 . 2009-03-23 19:00 70656 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPPA0.DLL
2010-08-29 04:58 . 2009-03-23 19:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPDA0.DLL
2010-08-29 04:58 . 2009-03-23 19:00 272384 ----a-w- c:\windows\system32\CNMLMA0.DLL
2010-08-29 04:58 . 2010-08-29 04:58 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2010-08-29 04:58 . 2009-02-04 13:17 90112 ----a-w- c:\windows\system32\CNC560O.dll
2010-08-29 04:58 . 2009-03-18 09:09 178176 ----a-w- c:\windows\system32\CNMIUA0.DLL
2010-08-29 04:58 . 2010-08-29 04:58 -------- d--h--w- c:\program files\CanonBJ
2010-08-29 04:57 . 2010-08-29 04:57 -------- d-----w- c:\windows\system32\STRING
2010-08-29 04:57 . 2009-04-03 16:51 137216 ----a-w- c:\windows\system32\CNMNPUI.DLL
2010-08-29 04:57 . 2009-04-03 16:51 353792 ----a-w- c:\windows\system32\CNMNPPM.DLL
2010-08-29 04:57 . 2010-08-29 04:57 -------- d-----w- c:\windows\system32\CHM
2010-08-29 04:57 . 2010-08-29 05:04 -------- d-----w- c:\program files\Canon
2010-08-16 06:54 . 2008-04-14 08:00 82432 ---h-tw- c:\windows\system32\85f0af4.dll
2010-08-16 06:54 . 2008-04-14 08:00 82432 ---h-tw- c:\windows\system32\1a9620e.dll
2010-08-16 06:40 . 2008-04-14 08:00 82432 ---h-tw- c:\windows\system32\2acd802.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-05 06:21 . 2010-04-21 07:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-09-05 06:21 . 2009-09-14 14:39 16608 ----a-w- c:\windows\gdrv.sys
2010-09-04 11:38 . 2009-09-14 14:29 -------- d-----w- c:\program files\Windows Media Connect 2
2010-09-04 09:49 . 2009-09-14 14:56 69624 ----a-w- c:\documents and settings\Danny Nguyen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-04 09:48 . 2009-12-14 12:39 -------- d-----w- c:\program files\ATI
2010-09-04 07:53 . 2010-05-17 23:38 -------- d-----w- c:\program files\ATI Technologies
2010-09-04 07:33 . 2010-09-04 07:33 558142 ----a-w- c:\windows\java\Packages\FDN3VPFP.ZIP
2010-09-04 07:33 . 2010-09-04 07:33 2678 ----a-w- c:\windows\java\Packages\Data\5ZBZXB9Z.DAT
2010-09-04 07:33 . 2010-09-04 07:33 2678 ----a-w- c:\windows\java\Packages\Data\YZT7J7BL.DAT
2010-09-04 07:33 . 2010-09-04 07:33 155995 ----a-w- c:\windows\java\Packages\IIAJTNHZ.ZIP
2010-09-04 07:33 . 2010-09-04 07:33 2678 ----a-w- c:\windows\java\Packages\Data\WG0TV3Z3.DAT
2010-09-04 07:33 . 2010-09-04 07:33 2678 ----a-w- c:\windows\java\Packages\Data\BRBFLRVZ.DAT
2010-09-04 07:33 . 2010-09-04 07:33 2678 ----a-w- c:\windows\java\Packages\Data\7BJNDBTZ.DAT
2010-09-04 07:31 . 2009-09-14 14:29 22720 -c--a-w- c:\windows\system32\emptyregdb.dat
2010-09-04 01:59 . 2010-08-17 07:50 288080 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Bases\avengine.dll
2010-09-04 01:54 . 2010-09-04 01:54 288080 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Data\Updater\Temporary Files\temporaryFolder\bases\av\kdb\i386\win\avengine.dll
2010-09-04 01:33 . 2009-09-29 07:27 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-04 01:23 . 2010-04-21 07:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2010-09-04 01:22 . 2010-04-21 07:37 -------- d-----w- c:\program files\Kaspersky Lab
2010-09-03 09:29 . 2010-04-21 07:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-03 06:12 . 2009-09-14 16:15 -------- d-----w- c:\documents and settings\Danny Nguyen\Application Data\uTorrent
2010-09-02 21:15 . 2010-03-21 10:51 256 ----a-w- c:\windows\system32\pool.bin
2010-09-02 05:24 . 2009-09-14 16:16 -------- d-----w- c:\program files\uTorrent
2010-08-31 07:37 . 2009-11-23 22:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2010-08-31 05:35 . 2009-11-23 22:03 -------- d-----w- c:\program files\Messenger Plus! Live
2010-08-29 05:07 . 2009-10-07 22:50 -------- d-----w- c:\program files\Brother
2010-08-29 05:07 . 2009-09-14 14:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-27 07:00 . 2010-08-27 07:00 68256 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2011 11.0.1.400\English\setup.exe
2010-08-26 13:14 . 2009-09-28 11:13 -------- d-----w- c:\documents and settings\Danny Nguyen\Application Data\FrostWire
2010-08-24 09:18 . 2009-09-14 15:56 -------- d-----w- c:\program files\Warcraft III
2010-08-19 23:52 . 2010-05-15 23:49 -------- d-----w- c:\program files\MapleStory
2010-08-18 05:47 . 2010-05-15 23:49 765952 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2010-08-18 04:16 . 2010-08-18 04:16 271696 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Bases\sys_critical_obj.dll
2010-08-16 22:04 . 2009-10-07 22:12 -------- d-----w- c:\documents and settings\Danny Nguyen\Application Data\Nero
2010-08-16 14:43 . 2009-10-07 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2010-08-16 14:43 . 2009-10-07 22:11 -------- d-----w- c:\program files\Nero
2010-08-16 14:36 . 2009-10-07 22:11 -------- d-----w- c:\program files\Common Files\Nero
2010-08-14 07:21 . 2009-12-12 05:25 -------- d-----r- c:\program files\Modern Warfare 2
2010-08-14 07:02 . 2009-12-15 00:35 -------- d-----w- c:\program files\Left 4 Dead 2
2010-08-12 01:59 . 2009-09-29 08:06 -------- d-----w- c:\program files\Cheat Engine
2010-08-01 03:43 . 2010-05-22 04:32 256 ----a-w- c:\documents and settings\Danny Nguyen\pool.bin
2010-07-29 16:48 . 2010-04-21 07:38 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-07-29 16:48 . 2010-04-21 07:38 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-07-26 05:47 . 2010-07-26 05:47 -------- d-----w- c:\program files\Free WMA to MP3 Converter
2010-07-25 22:18 . 2010-06-24 14:14 -------- d-----w- c:\program files\WinSCP
2010-07-25 13:37 . 2010-07-25 13:37 -------- d-----w- c:\program files\Wide Angle Software
2010-07-25 13:32 . 2010-06-24 14:20 -------- d-----w- c:\documents and settings\Danny Nguyen\Application Data\DiskAid
2010-07-25 01:32 . 2009-09-23 13:41 -------- d-----w- c:\documents and settings\Danny Nguyen\Application Data\DivX
2010-07-24 03:04 . 2009-09-15 03:37 -------- d-----w- c:\program files\Steam
2010-07-22 05:19 . 2010-07-22 05:19 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-07-22 05:19 . 2010-07-22 05:19 -------- d-----w- c:\program files\DVD Shrink
2010-07-16 23:29 . 2010-07-05 02:26 96 ---ha-w- c:\windows\system32\HsInfo.dat
2010-07-14 22:37 . 2010-06-08 03:54 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-14 22:37 . 2010-06-08 03:45 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-07-14 22:36 . 2010-07-14 22:36 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-14 22:36 . 2009-09-23 13:41 -------- d-----w- c:\program files\DivX
2010-07-14 22:36 . 2010-07-14 22:36 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-14 22:35 . 2010-07-14 22:35 84054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-07-14 22:35 . 2010-07-14 22:35 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-14 22:33 . 2010-06-08 03:54 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-14 22:33 . 2010-06-08 03:54 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-07 07:22 . 2010-07-07 07:22 1861000 ----a-w- c:\documents and settings\All Users\Application Data\Nexon\Common\NMService.exe
2010-07-07 07:22 . 2010-07-07 07:22 1774992 ----a-w- c:\documents and settings\All Users\Application Data\Nexon\Common\nmconew.dll
2010-07-01 11:35 . 2010-07-01 11:35 228024 ----a-w- c:\windows\system32\klogon.dll
2010-06-30 08:43 . 2010-06-30 08:43 247120 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Bases\uds.dll
2010-06-30 08:43 . 2010-06-30 08:43 1037648 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Bases\klavasyswatch.dll
2010-06-30 08:42 . 2010-06-30 08:42 132432 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP11\Bases\dns_client.dll
2010-06-16 20:33 . 2010-06-16 20:33 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2010-06-16 20:33 . 2010-06-16 20:33 32768 ----a-w- c:\windows\system32\drivers\taphss.sys
2010-06-15 10:01 . 2010-06-15 10:01 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-11 06:51 . 2010-06-11 06:51 3055600 ----a-w- c:\documents and settings\Danny Nguyen\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
2010-06-11 06:36 . 2010-06-11 06:36 275952 ----a-w- c:\documents and settings\Danny Nguyen\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-06-09 23:01 . 2010-07-14 22:35 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-06-09 23:01 . 2010-07-14 22:35 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-06-09 23:01 . 2010-07-14 22:35 45648 ----a-w- c:\windows\system32\drivers\PxHelp20.sys
2010-06-09 23:01 . 2010-07-14 22:35 133616 ------w- c:\windows\system32\pxafs.dll
2010-06-09 23:01 . 2010-06-08 03:53 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-06-09 23:01 . 2010-06-08 03:53 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-06-09 07:43 . 2010-06-09 07:43 11352 ----a-w- c:\windows\system32\drivers\kl2.sys
2010-06-09 07:43 . 2010-06-09 07:43 132184 ----a-w- c:\windows\system32\drivers\kl1.sys
2010-06-08 03:54 . 2010-06-08 03:54 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-08 03:54 . 2010-06-08 03:54 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-06-08 03:53 . 2010-06-08 03:53 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-07-01 357096]
"RTHDCPL"="RTHDCPL.EXE" [2010-03-26 19522592]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-06 102400]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2002-08-29 40960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Danny Nguyen^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PopRock
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-02-17 08:37 177472 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-09-20 05:35 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackBerryAutoUpdate]
2010-03-10 12:32 648536 ----a-w- c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-10-19 02:12 1983816 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-09-04 01:43 767312 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
2004-08-22 07:05 81920 ----a-w- c:\program files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-04-28 12:55 136176 ----atw- c:\documents and settings\Danny Nguyen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2007-08-30 00:50 205480 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-06-15 06:33 141624 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 05:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBAgent]
2010-03-26 00:52 1234216 ----a-w- c:\program files\Nero\Nero 10\Nero BackItUp\NBAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-09-19 23:51 1836328 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 05:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2009-10-27 04:10 401728 -c--a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-03-07 06:50 2937528 ----a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2009-03-15 10:15 180224 -c--a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 12:16 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
2009-09-11 02:31 2836440 -c--a-w- c:\program files\Registry Mechanic\RegMech.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-11-28 13:50 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-09-01 13:09 328568 ----a-w- c:\program files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Warcraft III\\w3l.exe"=
"c:\\Program Files\\Warcraft III\\war3.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\CODWAW-KaOs\\CoDWaW.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Windows Live\\Contacts\\wlcomm.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Danny Nguyen\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Steam\\steamapps\\bathroom_\\counter-strike\\hl.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57437:TCP"= 57437:TCP:Pando Media Booster
"57437:UDP"= 57437:UDP:Pando Media Booster
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [9/24/2009 1:33 PM 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [9/24/2009 1:33 PM 5248]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [6/9/2010 5:43 PM 11352]
R2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\essvr.exe [9/15/2009 12:39 AM 68136]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS --> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [3/25/2010 2:39 PM 490280]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [9/14/2009 2:42 PM 32856]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [6/25/2010 4:18 PM 28160]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/17/2009 11:52 PM 722416]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/28/2010 10:57 PM 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [9/15/2009 12:41 AM 1691480]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [10/2/2009 7:39 PM 19472]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [12/2/2009 7:03 PM 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [12/2/2009 7:03 PM 8320]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/3/2005 7:10 AM 32512]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
2010-09-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0c447879d1b0.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-28 12:55]
2010-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-2111687655-725345543-1003Core1cb0c44b7efa93c.job
- c:\documents and settings\Danny Nguyen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-28 12:55]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {D78F4511-3B80-4015-8891-D94F6EA92FB5} = 220.233.0.4,220.223.0.3
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Danny Nguyen\Application Data\Mozilla\Firefox\Profiles\v9b0dtyp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - component: c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Danny Nguyen\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Danny Nguyen\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\Danny Nguyen\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
Notify-avgrsstarter - avgrsstx.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-05 16:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8AFEB008]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba10cf28
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\atapi -> 0x8afeb008
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8168C(P)/8111C(P) PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xb9cd9bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9ce6a21
SendHandler -> NDIS.sys @ 0xb9cc487b
Warning: possible MBR rootkit infection !
user & kernel MBR OK
copy of MBR has been found in sector 5 !
copy of MBR has been found in sector 9 !
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(564)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
- - - - - - - > 'explorer.exe'(1380)
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Hotspot Shield\bin\hsswd.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-09-05 16:26:51 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-05 06:26
Pre-Run: 300,078,444,544 bytes free
Post-Run: 302,299,480,064 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /usepmtimer /NoExecute=OptIn
Current=4 Default=4 Failed=0 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 68BD22972D65E3B5A59C00CD488BEBB3