ComboFix 10-02-22.07 - Jonathan Murray 02/23/2010 15:24:54.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.223 [GMT -5:00]
Running from: c:\documents and settings\Jonathan Murray\Desktop\blackpudding.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\gotomon.log
c:\windows\wpe pro.INI
.
---- Previous Run -------
.
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-01-23 to 2010-02-23 )))))))))))))))))))))))))))))))
.
2010-02-23 02:30 . 2010-02-23 02:30 -------- d-----w- C:\blackpudding
2010-02-23 02:21 . 2010-02-23 02:45 -------- d-----w- C:\32788R22FWJFW.1.tmp
2010-02-19 21:54 . 2010-02-19 21:55 6885744 ----a-w- c:\program files\WindowsUpdateAgent30-x64.exe
2010-02-19 05:52 . 2010-02-19 05:52 1266056 ----a-w- C:\WindowsXP-KB927891.exe
2010-02-19 05:51 . 2010-02-19 05:51 3038 ----a-w- C:\fix_svchost.bat
2010-02-19 05:50 . 2010-02-19 05:50 6216032 ----a-w- C:\windowsupdateagent30-x86.exe
2010-02-19 02:09 . 2010-02-19 02:13 8327264 ----a-w- c:\program files\Firefox Setup 3.6.exe
2010-02-15 21:03 . 2010-02-15 21:05 -------- d-----w- c:\program files\WhatsRunning
2010-02-15 19:43 . 2010-02-15 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo
2010-02-15 19:43 . 2010-02-15 19:43 87104 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-02-15 19:43 . 2010-02-15 19:43 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-02-15 19:43 . 2010-02-15 19:43 171552 ----a-w- c:\windows\system32\guard32.dll
2010-02-15 19:43 . 2010-02-15 19:43 134344 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2010-02-15 19:31 . 2010-02-15 19:36 45174032 ----a-w- c:\program files\CIS_Setup_3.14.130099.587_XP_Vista_x32.exe
2010-02-15 19:22 . 2010-02-15 19:23 9034488 ----a-w- c:\program files\mssefullinstall-x86fre-en-us-xp.exe
2010-02-06 03:14 . 2010-02-06 03:14 -------- d-----w- c:\documents and settings\Jonathan Murray\Application Data\AVG8
2010-02-04 04:15 . 2010-02-04 04:15 -------- d-----w- c:\documents and settings\All Users\Application Data\GoBit Games
2010-02-03 23:15 . 2010-02-03 23:15 -------- d-----w- C:\_OTL
2010-01-28 04:25 . 2010-01-29 22:41 -------- d-----w- C:\ComboFix
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 18:32 . 2010-01-07 18:43 580065 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-02-23 02:40 . 2008-05-16 01:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-19 23:55 . 2010-01-07 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-17 21:50 . 2004-03-24 01:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-02-15 19:43 . 2010-01-07 18:34 -------- d-----w- c:\program files\COMODO
2010-02-15 18:47 . 2010-01-07 18:00 891248 ----a-w- c:\program files\avg_free_stb_all_9_40_cnet.exe
2010-02-06 23:37 . 2010-01-10 22:03 0 ----a-w- c:\documents and settings\Jonathan Murray\Local Settings\Application Data\prvlcl.dat
2010-02-04 22:57 . 2009-12-04 00:27 -------- d-----w- c:\documents and settings\Jonathan Murray\Application Data\BitTorrent
2010-01-28 00:54 . 2010-01-28 19:45 82 ----a-w- c:\program files\CFScript.txt
2010-01-22 04:27 . 2010-01-22 04:27 173119 ----a-w- c:\program files\Rooter.exe
2010-01-21 23:21 . 2010-01-11 04:40 165840 ----a-w- c:\windows\PCTBDRes.dll
2010-01-21 23:21 . 2010-01-11 04:40 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-01-21 23:21 . 2010-01-11 04:40 1652688 ----a-w- c:\windows\PCTBDCore.dll
2010-01-21 23:21 . 2010-01-11 04:40 767952 ----a-w- c:\windows\BDTSupport.dll
2010-01-21 04:56 . 2010-01-21 04:56 1956528 ----a-w- c:\program files\install_flash_player_ax.exe
2010-01-20 23:29 . 2009-10-11 22:11 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-20 23:24 . 2010-01-16 05:11 152576 ----a-w- c:\documents and settings\Jonathan Murray\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-20 23:20 . 2010-01-16 05:09 79488 ----a-w- c:\documents and settings\Jonathan Murray\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-20 03:53 . 2010-01-16 19:51 -------- d-----w- c:\program files\hpHosts
2010-01-18 03:11 . 2004-03-25 03:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-18 02:54 . 2010-01-18 02:53 595499 ----a-w- c:\program files\Autoruns.zip
2010-01-16 05:12 . 2004-12-01 21:15 -------- d-----w- c:\program files\Java
2010-01-16 05:09 . 2010-01-16 05:09 800544 ----a-w- c:\program files\jre-6u17-windows-i586-iftw-rv.exe
2010-01-16 05:05 . 2004-03-24 01:01 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-16 04:59 . 2010-01-16 04:55 27386256 ----a-w- c:\program files\AdbeRdr930_en_US.exe
2010-01-15 22:07 . 2010-01-15 22:07 843187 ----a-w- c:\program files\SecurityCheck.exe
2010-01-14 23:13 . 2010-01-14 23:13 2672312 ----a-w- c:\program files\esetsmartinstaller_enu.exe
2010-01-13 17:55 . 2008-05-16 23:20 -------- d-----w- c:\program files\Spyware Doctor
2010-01-13 05:24 . 2009-06-01 23:24 0 ----a-w- C:\qinfo.dat
2010-01-11 22:26 . 2010-01-05 18:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-11 22:15 . 2010-01-11 22:15 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-11 18:32 . 2005-01-08 16:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-11 18:21 . 2009-06-02 20:26 -------- d-----w- c:\program files\Spybot - Search & Destroy1
2010-01-11 04:08 . 2010-01-11 04:04 34628432 ----a-w- c:\program files\sdsetup.exe
2010-01-10 23:41 . 2010-01-10 23:41 117760 ----a-w- c:\documents and settings\Administrator.JONATHAN\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-10 23:40 . 2010-01-10 23:40 -------- d-----w- c:\documents and settings\Administrator.JONATHAN\Application Data\SUPERAntiSpyware.com
2010-01-07 21:07 . 2010-01-05 18:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2010-01-05 18:42 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 18:33 . 2010-01-07 18:28 40603920 ----a-w- c:\program files\CIS_Setup_3.13.125662.579_XP_Vista_x32.exe
2010-01-05 22:50 . 2010-01-05 22:50 117760 ----a-w- c:\documents and settings\Jonathan Murray\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-05 22:45 . 2010-01-05 22:45 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-05 22:45 . 2010-01-05 22:44 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-05 22:44 . 2010-01-05 22:44 -------- d-----w- c:\documents and settings\Jonathan Murray\Application Data\SUPERAntiSpyware.com
2010-01-05 22:44 . 2010-01-05 22:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-05 22:44 . 2010-01-05 22:42 7451168 ----a-w- c:\program files\SUPERAntiSpywarePro.exe
2010-01-05 18:43 . 2010-01-05 18:43 -------- d-----w- c:\documents and settings\Jonathan Murray\Application Data\Malwarebytes
2010-01-05 18:42 . 2010-01-05 18:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-05 18:41 . 2010-01-05 18:40 5061520 ----a-w- c:\program files\mbam-setup.exe
2010-01-05 05:20 . 2010-01-02 02:55 8086544 ----a-w- c:\program files\Firefox Setup 3.5.6.exe
2010-01-04 06:55 . 2009-08-31 05:12 -------- d-----w- c:\program files\WildGames
2010-01-04 06:29 . 2010-01-04 06:29 44024 ----a-w- c:\program files\bookmarks1-3-09.html
2009-12-31 16:50 . 2003-11-08 12:00 353792 ------w- c:\windows\system32\drivers\srv.sys
2009-12-31 05:26 . 2006-01-30 19:12 44240 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-23 19:32 . 2004-04-07 23:57 44240 ----a-w- c:\documents and settings\Jonathan Murray\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-22 19:17 . 2009-12-22 19:17 10134 ----a-r- c:\documents and settings\Jonathan Murray\Application Data\Microsoft\Installer\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}\ARPPRODUCTICON.exe
2009-12-22 05:21 . 2003-11-08 12:00 667136 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:20 . 2009-02-17 01:22 81920 ------w- c:\windows\system32\ieencode.dll
2009-12-14 07:08 . 2003-11-08 12:00 33280 ------w- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 . 2003-11-08 12:00 2189184 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2002-08-29 01:04 2066048 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-05 06:33 . 2009-12-05 06:08 214167816 ----a-w- c:\program files\Nero-9.4.26.0_trial.exe
2009-12-04 23:35 . 2009-12-04 23:35 2081039 ----a-w- c:\program files\dvd-author.exe
2009-12-04 23:29 . 2009-12-04 23:29 3119665 ----a-w- c:\program files\dvd-burner.exe
2009-12-04 23:26 . 2009-12-04 23:24 15672013 ----a-w- c:\program files\avc-free.exe
2009-12-04 23:23 . 2009-12-04 22:56 47360 ----a-w- c:\documents and settings\Jonathan Murray\Application Data\pcouffin.sys
2009-12-04 23:23 . 2009-12-04 22:56 47360 ----a-w- c:\documents and settings\Jonathan Murray\Application Data\pcouffin.sys
2009-12-04 22:56 . 2009-12-04 22:56 47360 ------w- c:\windows\system32\drivers\pcouffin.sys
2009-12-04 22:54 . 2009-12-04 22:52 18026336 ----a-w- c:\program files\vsoConvertXtoDVD4_setup.exe
2009-12-04 19:51 . 2009-12-04 19:49 23804080 ----a-w- c:\program files\DivXInstaller.exe
2009-12-04 19:14 . 2009-12-04 19:14 6104788 ----a-w- c:\program files\burnaware_free242.exe
2009-12-04 18:22 . 2003-11-08 12:00 455424 ------w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-04 00:14 . 2009-12-04 00:13 3066744 ----a-w- c:\program files\BitTorrent-6.3c.exe
2009-12-02 23:12 . 2009-12-02 23:12 8084968 ----a-w- c:\program files\Firefox Setup 3.5.5.exe
2009-11-27 17:11 . 2003-11-08 12:00 1291776 ------w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2001-08-17 22:36 17920 ------w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2003-11-08 12:00 28672 ------w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 ------w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2003-11-08 12:00 84992 ------w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2003-11-08 12:00 11264 ------w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2001-08-17 22:36 48128 ------w- c:\windows\system32\iyuv_32.dll
2009-10-07 20:01 . 2009-10-07 20:01 3340064 ----a-w- c:\program files\UnityWebPlayer.exe
2009-10-04 17:12 . 2009-10-04 17:11 12541248 ----a-w- c:\program files\RLCSetup.exe
2009-09-15 19:44 . 2009-09-15 19:42 25685128 ----a-w- c:\program files\wordview_en-us.exe
2009-09-15 19:26 . 2009-09-15 19:26 13824 ----a-r- c:\program files\TRU_Unicru_92908.doc
2009-09-12 20:16 . 2009-09-12 20:16 4122416 ----a-w- c:\program files\freeclip.exe
2009-09-11 23:10 . 2009-09-11 22:55 52736 ----a-w- c:\program files\oown_resume_template.doc
2009-09-04 19:49 . 2009-09-04 19:47 11729274 ----a-w- c:\program files\installeasyjob.exe
2009-09-02 19:29 . 2009-09-02 19:29 8050536 ----a-w- c:\program files\Firefox Setup 3.5.2.exe
2009-07-07 23:46 . 2009-07-07 23:45 359656 ----a-w- c:\program files\msicuu2.exe
2009-02-17 01:18 . 2009-02-16 04:28 16939888 ----a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2008-11-23 17:56 . 2008-11-23 17:56 25740144 ----a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2008-09-06 03:18 . 2005-01-03 03:29 1505160 ----a-w- c:\program files\install_easyshare.exe
2008-07-04 00:24 . 2008-07-04 00:21 1445888 ----a-w- c:\program files\WinsockxpFix.exe
2008-05-31 02:17 . 2008-05-31 02:07 9723880 ----a-w- c:\program files\spybotsd152.exe
2008-05-29 00:21 . 2008-05-29 00:21 1244712 ----a-w- c:\program files\SetupOneCare.exe
2008-05-28 03:12 . 2008-05-28 03:12 7608344 ----a-w- c:\program files\spyhunterFULL.exe
2008-05-09 13:47 . 2008-05-09 13:47 1206366 ----a-w- c:\program files\wrar371.exe
2008-05-09 13:43 . 2008-05-09 13:43 244784 ----a-w- c:\program files\gnie_s_dvd4-iml2iso.rar
2008-05-09 03:44 . 2008-05-09 03:44 10121656 ----a-w- c:\program files\Alcohol120_trial_1.9.7.6221.exe
2008-05-09 03:28 . 2008-05-09 03:28 1385051 ----a-w- c:\program files\cddvdgen.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 217544]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2007-09-05 1261384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2009-10-26 15872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-20 149280]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-02-15 1800464]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
NETGEAR WG311v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG311v3\wlancfg5.exe [2006-1-26 1486848]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=c:\windows\pss\Kodak software updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
NvQTwk [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
2002-01-03 03:06 4608 ------w- c:\windows\system32\carpserv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
2008-03-01 19:49 826880 ----a-w- c:\program files\dvd43\DVD43_Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2001-08-18 22:00 44032 ----a-w- c:\windows\ime\imkr6_1\imekrmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-04 05:31 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2009-11-18 17:47 1243088 ----a-w- c:\program files\Spyware Doctor\pctsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
2000-07-13 20:00 311350 ----a-w- c:\program files\Microsoft Works\wkssb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2000-07-13 20:00 28739 ----a-w- c:\program files\Microsoft Works\WkDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
2001-10-12 23:45 69632 ----a-w- c:\program files\Analog Devices\SoundMAX\SMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
c:\program files\Java\j2re1.4.2_06\bin\jusched.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
2000-07-13 20:00 24576 ----a-w- c:\program files\Microsoft Works\wkfud.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MCVSRte"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [06/01/2009 11:10 PM 207792]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [02/15/2010 2:43 PM 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [02/15/2010 2:43 PM 25160]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/16/2009 4:26 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/16/2009 4:26 PM 74480]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\DRIVERS\avgfwdx.sys --> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwdx.sys --> c:\windows\system32\DRIVERS\avgfwdx.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/16/2009 4:27 PM 7408]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ylmolrez
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 18:24 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-02-23 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]
2010-02-11 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 21:21]
2004-03-28 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\System32\OOBE\oobebaln.exe [2006-04-09 00:12]
2004-03-23 c:\windows\Tasks\Registration reminder 2.job
- c:\windows\System32\OOBE\oobebaln.exe [2006-04-09 00:12]
2004-04-08 c:\windows\Tasks\Registration reminder 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2006-04-09 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/mWindow Title =
IE: &AOL Toolbar Search
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} -
hxxp://downloads.ewido.net/ewidoOnlineScan.cabDPF: {2C8EEB84-6D60-11D4-BD64-0050048A82BF} -
hxxp://tech-c.mhi.aol.com/netagent/objects/custappx2.CABFF - ProfilePath - c:\documents and settings\Jonathan Murray\Application Data\Mozilla\Firefox\Profiles\2tis2day.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-HostManager - c:\program files\Common Files\AOL\1155679928\ee\AOLSoftware.exe
Notify-avgrsstarter - avgrsstx.dll
MSConfigStartUp-AOLDialer - c:\program files\Common Files\AOL\ACS\AOLDial.exe
AddRemove-Window Washer - c:\windows\Unwash6.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-23 15:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(896)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2010-02-23 16:25:01
ComboFix-quarantined-files.txt 2010-02-23 21:24
ComboFix2.txt 2010-01-19 22:24
ComboFix3.txt 2010-01-13 22:03
Pre-Run: 16,056,885,248 bytes free
Post-Run: 16,637,517,824 bytes free
Current=2 Default=2 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - A7607FC740ACD5E1881A82396133A579