ComboFix 10-09-21.01 - Voodoo 21/09/2010 23:48:36.8.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.648 [GMT 1:00]
Running from: c:\documents and settings\Voodoo\Desktop\Combo-Fix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-08-21 to 2010-09-21 )))))))))))))))))))))))))))))))
.
2010-09-17 16:22 . 2010-08-02 21:09 3683248 ----a-w- c:\documents and settings\Voodoo\Application Data\Simply Super Software\Trojan Remover\xdg29.exe
2010-09-13 22:07 . 2010-09-13 22:07 -------- d-----w- c:\program files\Microsoft Research
2010-09-13 17:42 . 2010-09-13 17:42 -------- d-----w- c:\documents and settings\Voodoo\Application Data\FILEminimizerPictures
2010-09-11 16:15 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-09-11 16:15 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-09-11 16:15 . 2010-06-02 03:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-09-11 16:15 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-09-11 16:15 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-09-11 16:15 . 2010-05-26 10:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-09-11 16:15 . 2010-05-26 10:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-09-11 16:15 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-09-11 16:13 . 2008-05-30 13:17 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll
2010-09-11 16:00 . 2010-09-11 16:00 -------- d-----w- c:\program files\NVIDIA Corporation
2010-09-11 15:53 . 2010-09-11 16:02 -------- d-----w- c:\program files\spectra
2010-09-10 12:14 . 2010-09-10 12:18 -------- d-----w- c:\documents and settings\Voodoo\Livestation
2010-09-10 12:14 . 2010-09-10 12:14 -------- d-----w- c:\documents and settings\Voodoo\Application Data\Mchid
2010-09-10 12:14 . 2010-09-10 12:14 -------- d-----w- c:\documents and settings\Voodoo\Application Data\Livestation
2010-09-10 12:14 . 2010-09-10 12:14 -------- d-----w- c:\program files\OpenAL
2010-09-10 12:14 . 2010-09-10 12:14 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-09-10 12:14 . 2010-09-10 12:14 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-09-10 12:14 . 2010-09-10 12:14 -------- d-----w- c:\program files\Livestation
2010-09-09 14:54 . 2010-09-09 14:55 -------- d-----w- c:\program files\SopCast
2010-09-06 17:20 . 2010-09-06 17:20 180224 ----a-w- c:\windows\system32\WinVd32.sys
2010-09-06 17:20 . 2010-09-06 17:20 7680 ----a-w- c:\windows\system32\WinFLsrv.exe
2010-09-06 17:19 . 2010-09-06 17:37 -------- d-----w- c:\program files\Folder Lock 6
2010-09-06 14:19 . 2010-09-06 14:20 -------- d-----w- c:\program files\Nsasoft
2010-08-31 13:09 . 2010-08-31 13:09 -------- d-----w- c:\documents and settings\Voodoo\Local Settings\Application Data\Cooliris
2010-08-31 13:08 . 2010-06-14 11:08 4687872 ----a-w- c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-08-31 13:08 . 2010-06-14 11:08 103424 ----a-w- c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-08-31 13:08 . 2010-06-14 11:08 545280 ----a-w- c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-08-31 13:08 . 2010-06-14 11:08 4687360 ----a-w- c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-08-31 13:08 . 2010-06-14 11:08 425984 ----a-w- c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-08-31 13:08 . 2010-06-14 11:08 152064 ----a-w- c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-08-31 13:08 . 2010-06-14 11:08 57856 ----a-w- c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-08-23 20:52 . 2008-04-14 05:42 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-21 22:36 . 2009-03-14 14:10 -------- d-----w- c:\program files\XYplorer
2010-09-21 22:33 . 2009-03-14 14:22 -------- d-----w- c:\documents and settings\Voodoo\Application Data\foobar2000
2010-09-21 18:51 . 2010-05-05 10:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-09-21 18:51 . 2009-03-31 15:24 -------- d-----w- c:\documents and settings\Voodoo\Application Data\Media Player Classic
2010-09-19 19:13 . 2009-03-13 18:44 -------- d-----w- c:\documents and settings\Voodoo\Application Data\Orbit
2010-09-18 14:40 . 2009-03-22 22:15 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-17 14:17 . 2009-06-21 16:01 -------- d-----w- c:\program files\SpywareBlaster
2010-09-17 11:52 . 2010-05-04 09:52 63488 ----a-w- c:\documents and settings\Voodoo\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-17 11:52 . 2009-12-30 01:46 117760 ----a-w- c:\documents and settings\Voodoo\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-13 19:01 . 2009-05-25 13:17 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-13 17:49 . 2010-07-28 18:38 -------- d-----w- c:\program files\RapidSolution
2010-09-13 17:46 . 2010-06-01 13:56 -------- d-----w- c:\program files\OO Software
2010-09-13 17:43 . 2010-01-15 00:32 -------- d-----w- c:\program files\FLV Player
2010-09-11 15:59 . 2010-01-25 16:01 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-09-11 13:23 . 2009-04-07 22:59 -------- d-----w- c:\documents and settings\Voodoo\Application Data\Thinstall
2010-09-06 23:47 . 2009-03-23 18:08 -------- d-----w- c:\program files\CCleaner
2010-09-06 09:50 . 2010-07-26 11:23 -------- d-----w- c:\documents and settings\Voodoo\Application Data\vlc
2010-09-03 15:32 . 2010-08-05 20:24 -------- d-----w- c:\program files\RapidShareManager
2010-08-31 21:09 . 2009-08-02 15:45 -------- d-----w- c:\program files\SOWPODS (SCRABBLE) Dictionary
2010-08-31 00:50 . 2009-03-13 15:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-08-25 14:03 . 2010-03-14 23:06 -------- d-----w- c:\documents and settings\Voodoo\Application Data\PrimoPDF
2010-08-20 17:03 . 2010-08-20 17:03 -------- d-----w- c:\documents and settings\Voodoo\Application Data\Intermedia Software
2010-08-20 17:03 . 2010-08-20 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Intermedia Software
2010-08-20 17:02 . 2010-08-20 17:02 -------- d-----w- c:\program files\Intermedia Software
2010-08-18 14:11 . 2010-08-20 17:03 1630720 ---ha-w- c:\documents and settings\All Users\Application Data\Intermedia Software\Helium 7\Data\LicenseManager2010.dll
2010-08-18 13:54 . 2010-08-20 23:13 2392064 ----a-w- c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\firetorrent@radicalsoft.com\components\firetorrent.dll
2010-08-17 13:17 . 2003-07-16 16:40 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 17:25 . 2009-07-14 11:22 -------- d-----w- c:\program files\Anti Trojan Elite
2010-08-15 10:33 . 2009-03-13 15:04 -------- d-----w- c:\program files\7-Zip
2010-08-12 17:32 . 2010-08-12 17:32 -------- d-----w- c:\documents and settings\Voodoo\Application Data\Nero
2010-08-12 17:30 . 2010-08-12 17:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2010-08-12 17:30 . 2010-08-12 17:28 -------- d-----w- c:\program files\Nero
2010-08-12 17:29 . 2010-08-12 17:28 -------- d-----w- c:\program files\Common Files\Nero
2010-08-09 19:08 . 2010-08-09 19:08 -------- d-----w- c:\program files\WinLemm
2010-08-09 17:54 . 2010-05-23 19:25 -------- d-----w- c:\program files\SnapDragon Games
2010-08-09 17:51 . 2010-08-09 17:06 -------- d-----w- c:\program files\Ahead
2010-08-02 21:09 . 2010-03-17 17:10 3683248 ----a-w- c:\documents and settings\Voodoo\Application Data\Simply Super Software\Trojan Remover\mgeB45.exe
2010-07-29 10:48 . 2010-07-29 10:48 -------- d-----w- c:\program files\Audacity
2010-07-28 19:21 . 2010-07-28 19:20 -------- d-----w- c:\program files\Freecorder
2010-07-28 18:41 . 2010-07-28 18:41 -------- d-----w- c:\program files\PixiePack Codec Pack
2010-07-28 18:40 . 2010-07-28 18:40 77664 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgSoundclick.dll
2010-07-28 18:40 . 2010-07-28 18:40 59232 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgPandora.dll
2010-07-28 18:40 . 2010-07-28 18:40 87904 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgMyspace.dll
2010-07-28 18:40 . 2010-07-28 18:40 84320 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgImeem.dll
2010-07-28 18:40 . 2010-07-28 18:40 103264 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgLastfm.dll
2010-07-28 18:40 . 2010-07-28 18:40 62816 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgIJigg.dll
2010-07-28 18:40 . 2010-07-28 18:40 114528 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgHypemachine.dll
2010-07-28 18:40 . 2010-07-28 18:40 94560 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgGeneral.dll
2010-07-28 18:40 . 2010-07-28 18:40 89952 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgDeezer.dll
2010-07-28 18:40 . 2010-07-28 18:40 46944 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\PlgDefault.dll
2010-07-28 18:40 . 2010-07-28 18:40 347488 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker_2009\RadioRip\RadioRip.dll
2010-07-28 18:38 . 2009-10-01 21:25 -------- d-----w- c:\documents and settings\All Users\Application Data\RapidSolution
2010-07-27 13:46 . 2010-07-27 13:46 -------- d-----w- c:\program files\PowerISO
2010-07-26 11:20 . 2010-05-09 17:51 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-07-26 11:20 . 2010-05-10 10:11 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-26 11:20 . 2009-04-23 21:31 -------- d-----w- c:\documents and settings\Voodoo\Application Data\dvdcss
2010-07-26 11:19 . 2010-07-26 11:19 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-26 11:19 . 2009-09-25 12:04 -------- d-----w- c:\program files\DivX
2010-07-26 11:19 . 2010-07-26 11:19 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-26 11:17 . 2010-07-26 11:17 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-26 11:16 . 2010-05-10 10:11 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-26 11:14 . 2010-05-10 10:11 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-22 15:49 . 2002-11-07 17:47 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-14 22:32 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-06-30 13:56 . 2010-06-30 13:56 306688 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-06-30 12:31 . 2003-07-16 16:37 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 21:35 . 2009-05-10 17:27 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-24 12:10 . 2009-03-13 14:38 81920 ------w- c:\windows\system32\ieencode.dll
2010-06-24 12:10 . 2003-07-16 16:45 667136 ----a-w- c:\windows\system32\wininet.dll
2010-01-25 15:21 . 2010-01-25 15:21 2 --shatr- c:\windows\winstart.bat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Safely Remove"="c:\program files\USB Safely Remove\USBSafelyRemove.exe" [2009-12-06 3911680]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HS3_AutoRun"="c:\program files\Farstone\HackerSmacker\FWMain.exe" [2005-07-23 323584]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]
"Freecorder FLV Service"="c:\program files\Freecorder\FLVSrvc.exe" [2010-06-26 167936]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2010-08-02 1167808]
c:\documents and settings\Voodoo\Start Menu\Programs\Startup\
ESET Smart Security.lnk - c:\program files\ESET\ESET Smart Security\egui.exe [2009-2-6 2021400]
Malwarebytes' Anti-Malware.lnk.disabled [2010-8-11 696]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2010-6-30 3450608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HackerSmacker 3.0.lnk - c:\program files\Farstone\HackerSmacker\FWMain.exe [2005-7-23 323584]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE}"= "c:\program files\GPSoftware\Directory Opus\dopuslib.dll" [2010-01-08 836056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2003-06-20 07:03 110592 ----a-w- c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eBoostr Control Panel.lnk]
backup=c:\windows\pss\eBoostr Control Panel.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Orbit.lnk]
backup=c:\windows\pss\Orbit.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Voodoo^Start Menu^Programs^Startup^MemTurbo.lnk]
backup=c:\windows\pss\MemTurbo.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Voodoo^Start Menu^Programs^Startup^WordWeb Pro.lnk]
backup=c:\windows\pss\WordWeb Pro.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Voodoo^Start Menu^Programs^Startup^WordWeb.lnk]
backup=c:\windows\pss\WordWeb.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2003-08-20 20:24 151552 ----a-w- c:\program files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
2005-11-10 18:44 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-07-29 12:30 335872 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Directory Opus Desktop Dblclk]
2010-01-08 09:45 271840 ----a-w- c:\program files\GPSoftware\Directory Opus\dopusrt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2009-06-10 13:22 334224 ----a-w- c:\program files\Eraser\Eraser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Freecorder FLV Service]
2010-06-26 17:09 167936 ----a-w- c:\program files\Freecorder\FLVSrvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
2005-10-22 23:00 385024 ----a-w- c:\program files\Syncrosoft\POS\H2O\cledx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HS3_AutoRun]
2005-07-23 17:49 323584 ----a-w- c:\program files\Farstone\HackerSmacker\FWMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Livestation]
2010-06-24 19:08 4657152 ----a-w- c:\program files\Livestation\Livestation.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
2003-05-28 17:32 86016 ----a-w- c:\program files\Intel\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2010-04-12 08:40 180224 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2010-04-17 10:56 394984 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-03-11 12:00 24095528 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 10:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-08-31 00:50 2424560 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WordWeb]
2009-11-08 22:18 65216 ------w- c:\program files\WordWeb\wweb32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"BthServ"=2 (0x2)
"Ati HotKey Poller"=3 (0x3)
"SbieSvc"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"Directory Opus Desktop Dblclk"="c:\program files\GPSoftware\Directory Opus\dopusrt.exe" /dblclk
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28/01/2009 12:34 125544]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [06/02/2009 15:23 106208]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [05/01/2010 08:56 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 08:56 67656]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [06/02/2009 15:23 727720]
R2 fsnet;fsnet;c:\windows\system32\drivers\fsnet.sys [23/03/2009 17:59 18882]
R2 KillTheHooker;KillTheHooker;c:\documents and settings\Voodoo\Desktop\MalwareAndSpyware\New Folder\TizerBruteForceEx.sys [14/05/2010 11:58 22320]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [13/03/2009 17:21 304464]
R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [04/05/2010 12:07 503080]
R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [01/07/2010 12:26 261456]
R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [06/09/2010 18:20 17984]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [13/03/2009 21:31 33792]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [13/03/2009 20:51 115312]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [13/03/2009 17:21 20952]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [06/04/2009 13:19 23064]
S2 ATE_PROCMON;ATE_PROCMON;\\??\\c:\\Program Files\\Anti Trojan Elite\\ATEPMon.sys --> \\c:\\Program Files\\Anti Trojan Elite\\ATEPMon.sys [?]
S3 EWAVE;EWAVE;c:\windows\system32\drivers\ew.sys [30/04/2010 20:48 1447040]
S3 FILESPY;FILESPY;c:\windows\system32\drivers\filespy.sys [30/04/2010 20:48 26992]
S3 FWCOM;FWCOM;c:\program files\Farstone\HackerSmacker\FWCOM.exe [18/07/2005 19:27 69632]
S3 JakNDisMP;JakNDisMP;c:\windows\system32\DRIVERS\JakNDis.sys --> c:\windows\system32\DRIVERS\JakNDis.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\4A22.tmp --> c:\windows\system32\4A22.tmp [?]
S3 NSTATION;NSTATION;c:\windows\system32\drivers\nstation.sys [30/04/2010 20:48 18944]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 08:56 12872]
S4 EBOOSTRSVC;eBoostr Service;c:\program files\eBoostr\EBstrSvc.exe [28/01/2009 12:34 634488]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [05/04/2009 13:10 691696]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 18:02 114688 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
2010-09-19 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-01-23 17:08]
2010-09-21 c:\windows\Tasks\WECPUpdate.job
- c:\program files\Essentials Codec Pack\WECPUpdate.exe [2009-02-25 14:28]
.
.
------- Supplementary Scan -------
.
uStart Page = www.google.com
uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Send To &Bluetooth
DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
FF - ProfilePath - c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - component: c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Voodoo\Application Data\Mozilla\Firefox\Profiles\55x8pt7q.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
FF - component: c:\program files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-{7514BBA2-951B-45A0-BA2B-CA259968C9ED} - c:\docume~1\ALLUSE~1\APPLIC~1\TARMAI~1\{7514B~1\Setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-21 23:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\sys_drv.dat 7028 bytes
c:\windows\system32\sys_drv_2.dat 6024 bytes
c:\windows\system32\WinFLdrv.sys 17984 bytes executable
c:\documents and settings\Voodoo\Application Data\systemfl.$dk 990 bytes
scan completed successfully
hidden files: 4
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\atapi]
"ImagePath"=multi:"system32\drivers\atapi.sys\00\00ImagePath\00AppInit_DLLs\00\00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\atapi]
"ImagePath"=multi:"system32\drivers\atapi.sys\00\00ImagePath\00AppInit_DLLs\00\00"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\4A22.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1644491937-1580818891-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{57AE0684-9F60-473D-9BD6-A5EA421779DB}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abplbcfgommlbiknilmokbjgecnhflhjkj"=hex:61,62,62,6c,65,6c,66,6f,6f,68,6a,65,
66,6b,67,66,64,69,68,6f,66,67,6e,69,69,70,6e,6e,68,6b,6e,6c,69,68,00,00
"bbplbcfgommlbiknilbpbdpfhaeigcibjdcg"=hex:61,62,67,6c,6d,6b,61,6f,67,6b,63,6b,
64,6a,63,68,64,6d,6e,63,70,6f,64,67,69,6a,67,6e,6a,6c,6e,6a,64,67,00,00
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG12.00.00.01PROFESSIONAL"="83EDC7D649F9EC5F53DBFBE889484F41BA035D8350BF5CBEC761EF84FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DBA7FD869164D6794BA7FD869164D679410AECF649C222455881B92C2CFF5DE9073E18CBFA09692D24B72482406A5406255AC1AA5C03C93587072D3570D4EBB96305BC12428191050CAE87E62A5AB0F1C5151926E15751F1FC25DE4586FE92C40625177A867B210F06863812772F2C981FC4F44BFB398068A84E7436AB13E75DD3CC5C3AFD3217C16A50199B6BDA0A0A3C67D4C5EEF52DD7AB2C08470C021B2C1E6E14D61988412227802A51810BF171611535E544DB68E54BAB94E183DCD50C17DF1D0279360E5FC48C99498A4BB847231F0BFEE843B560302CBDC4D7DE4113991649EB1589CDD92F263ED47EB6695D471964BBE013C45725D10FE428B690986264F9B742E07B4D1C97AC9F88876C8DD102B6E18E3F4BF17184618EE24C2A40B33E8BE258C50F82F90605645D183F231BEB82D96030BFE6372519F8A3ABB1FB0248C953FA48B0FA2820AD209540DBB79A3EB1C95E40290D29DB7209571848C5FDA3CBF82D7B1ABA64A1097E4CE719D625918E53647C6D3E243A4395224AF51852B9A7172BCA05ABA8AAF8BBBB479EA1CECB2C95E9926FD957BE61F465FB62718DAEF72D41F9579635749ACB5AECC455CE0551936025297EE577118BAE5F19B8C28A7A036FB37BD293A638BBF16F8255AAABDB9ACD8637E7AD8DB003E2C2212DC42D1EAE4070E2C95B0244F0A7D6FD654B54E2670A852E2C4775FC5245BEBBE874D225674A4051F3AAA5A2F09A505790B5E0DEEF834FD49609E5CEB81D254AB91E0F07A3CF16DC6298EF67AF287748041F823B2FDEE290AE12CD50BB02249377E893B0556BCFB25FA330E11C6CDD9344048602AFD02F8D2E2F3F0CDCF8F1813DBC79EB4A28649104CE7596742D93731D50AB39FB748792482BDFAF3419575C3360FDFDD4586CF35BAEB34096A3CF1E452E8B46FB3D49853614361CFAA607824A047E76A23277210EA76221288BE531609091E8D38E9A788A4B3364976D19B63B24C41D4E908747504AE463326DC89DAD47FCB00D3025DC0F6B2B25C5300BF0186EE1D2E07F9FD0C33B169B29645A49E1156C161D6C756CB0657B017B3B3A7D2BA724D992D841CCDA51279E9EA5B9AA11E8CA45FD61D8D4F82AB2E9CCB6AFA84F18E4CD155E1BE8911530545FD37C5786012BDBBAD166844A12F4FA51755C41252EFB4A03A003A632C6E44466AA4610A41507C4DF7FAAA7720555A7CD4DBF3CE8737C5E7D903C65033D00F0210A191922E9D72FE16C80188B705BA018416DCDEBE78E41B77BF819BE55CE0A394645AA016CAD44E2E30F76E2D997EA5EE52B73CACB919C31C"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1080)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LgNotify.dll
.
Completion time: 2010-09-21 23:55:54
ComboFix-quarantined-files.txt 2010-09-21 22:55
ComboFix2.txt 2010-05-10 22:50
Pre-Run: 6,594,367,488 bytes free
Post-Run: 6,573,723,648 bytes free
- - End Of File - - 66BD05A8B3FB4C2D5CCB3BC35927DD40
Last edited by Voods on 21st September 2010, 11:11 pm; edited 1 time in total (Reason for editing : Missed part off)