ComboFix 10-07-23.02 - Blackshear 07/25/2010 18:32:44.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3191.2733 [GMT -7:00]
Running from: c:\documents and settings\Blackshear\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Blackshear\Desktop\CFScript.txt
FILE ::
"c:\windows\Ocuka.bin"
"c:\windows\Pcuguqoboxeboda.dat"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Blackshear\Local Settings\Application Data\cwfxsaqis
c:\documents and settings\Blackshear\Local Settings\Application Data\lcrjkguyh
c:\documents and settings\Blackshear\Local Settings\Application Data\sagvowvux
c:\documents and settings\Blackshear\Local Settings\Application Data\vbnipgsks
c:\windows\Ocuka.bin
c:\windows\Pcuguqoboxeboda.dat
.
((((((((((((((((((((((((( Files Created from 2010-06-26 to 2010-07-26 )))))))))))))))))))))))))))))))
.
2010-07-24 05:14 . 2010-07-24 07:46 -------- d-----w- c:\documents and settings\Blackshear\Application Data\vlc
2010-07-23 23:42 . 2010-07-23 23:42 -------- d-----w- c:\program files\uTorrent
2010-07-22 06:26 . 2010-07-26 01:26 -------- d-----w- c:\program files\TweakNow PowerPack 2009
2010-07-22 04:03 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-22 04:03 . 2010-07-22 04:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-22 04:03 . 2010-07-22 04:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-22 04:03 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-22 03:47 . 2010-07-22 05:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Update
2010-07-22 03:47 . 2010-07-26 01:42 766464 ----a-w- c:\windows\system32\drivers\vcjrn.sys
2010-07-22 01:00 . 2010-07-22 01:00 -------- d-----w- C:\EPSONREG
2010-07-22 00:53 . 2010-07-22 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
2010-07-22 00:53 . 2006-12-08 09:04 76800 ----a-w- c:\windows\system32\E_FLBCDA.DLL
2010-07-22 00:53 . 2006-04-19 09:00 62976 ----a-w- c:\windows\system32\E_FD4BCDA.DLL
2010-07-22 00:52 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-07-22 00:52 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\dllcache\usbprint.sys
2010-07-22 00:52 . 2007-03-27 07:00 67072 ----a-w- c:\windows\system32\escwiad.dll
2010-07-22 00:52 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-07-22 00:52 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\dllcache\usbscan.sys
2010-07-08 21:00 . 2010-07-08 21:00 -------- d-----w- c:\program files\iPod
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-26 01:27 . 2009-06-24 18:46 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-07-26 01:27 . 2009-06-24 18:46 -------- d-----w- c:\program files\Symantec
2010-07-26 01:27 . 2009-06-24 21:25 -------- d-----w- c:\program files\Symantec AntiVirus
2010-07-26 01:27 . 2009-06-24 18:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-07-26 01:26 . 2009-08-07 05:57 -------- d-----w- c:\documents and settings\Blackshear\Application Data\TweakNow PowerPack 2009
2010-07-26 01:25 . 2010-06-22 03:21 -------- d-----w- c:\program files\Opera
2010-07-26 01:24 . 2009-06-24 18:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-26 01:16 . 2010-05-04 04:16 63488 ----a-w- c:\documents and settings\Blackshear\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-26 01:16 . 2009-06-24 22:18 117760 -c--a-w- c:\documents and settings\Blackshear\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-25 08:34 . 2009-06-27 02:25 -------- d-----w- c:\documents and settings\Blackshear\Application Data\uTorrent
2010-07-22 21:34 . 2009-06-24 17:50 -------- d-----w- c:\program files\Java
2010-07-22 20:56 . 2009-12-09 08:22 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-22 03:53 . 2010-01-11 02:02 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-07-22 00:59 . 2010-07-22 00:58 -------- d-----w- c:\program files\epson
2010-07-14 23:12 . 2009-06-24 22:19 -------- d-----w- c:\documents and settings\Blackshear\Application Data\Hewlett-Packard
2010-07-10 23:09 . 2010-05-06 08:32 57344 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-10 23:09 . 2010-05-06 08:29 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-07-10 23:09 . 2009-06-28 00:35 -------- d-----w- c:\program files\DivX
2010-07-10 23:09 . 2010-07-10 23:09 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-10 23:09 . 2010-07-10 23:09 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-10 23:09 . 2010-07-10 23:09 84054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-07-10 23:09 . 2010-07-10 23:09 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-10 23:08 . 2010-06-03 22:22 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-07-10 23:08 . 2010-05-06 08:31 1062184 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-10 23:08 . 2010-05-06 08:31 895256 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-08 21:01 . 2009-10-31 07:19 -------- d-----w- c:\program files\iTunes
2010-07-08 21:00 . 2009-06-24 19:45 -------- d-----w- c:\program files\Common Files\Apple
2010-07-08 20:54 . 2009-06-24 19:46 -------- d-----w- c:\program files\Bonjour
2010-07-08 20:48 . 2010-07-08 20:48 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-14 14:31 . 2009-06-24 11:30 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 04:57 . 2010-05-06 08:31 500400 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DivX7\DivX Web Player\DivXWebPlayerUninstall.exe
2010-06-12 10:27 . 2010-06-12 10:09 -------- d-----w- c:\documents and settings\Blackshear\Application Data\DAEMON Tools Lite
2010-06-12 10:10 . 2010-06-12 10:10 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-06-12 10:09 . 2010-06-12 10:09 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-06-04 21:51 . 2009-06-28 01:21 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-04 01:14 . 2009-06-28 00:35 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-06-04 01:14 . 2010-06-04 01:14 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-04 01:14 . 2010-06-04 01:14 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-04 01:13 . 2010-06-04 01:13 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-04 01:12 . 2010-06-04 01:12 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-02 11:55 . 2010-06-12 10:35 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-06-02 11:55 . 2010-06-12 10:35 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-06-02 11:55 . 2010-06-12 10:34 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-05-26 18:41 . 2010-06-12 10:34 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-05-26 18:41 . 2010-06-12 10:34 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-05-26 18:41 . 2010-06-12 10:34 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-05-26 18:41 . 2010-06-12 10:34 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-05-26 18:41 . 2010-06-12 10:34 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-05-22 22:35 . 2010-05-22 22:35 503808 -c--a-w- c:\documents and settings\Blackshear\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7c548012-n\msvcp71.dll
2010-05-22 22:35 . 2010-05-22 22:35 499712 -c--a-w- c:\documents and settings\Blackshear\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7c548012-n\jmc.dll
2010-05-22 22:35 . 2010-05-22 22:35 348160 -c--a-w- c:\documents and settings\Blackshear\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7c548012-n\msvcr71.dll
2010-05-22 22:35 . 2010-05-22 22:35 61440 -c--a-w- c:\documents and settings\Blackshear\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2afbfa43-n\decora-sse.dll
2010-05-22 22:35 . 2010-05-22 22:35 12800 -c--a-w- c:\documents and settings\Blackshear\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2afbfa43-n\decora-d3d.dll
2010-05-18 23:35 . 2010-05-18 23:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-06 10:41 . 2009-06-24 11:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-06 08:31 . 2010-05-06 08:31 57054 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-05-06 08:31 . 2010-05-06 08:31 54166 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-05-06 08:31 . 2010-05-06 08:31 57532 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-05-06 08:31 . 2010-05-06 08:31 56458 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-05-06 08:31 . 2010-05-06 08:31 54174 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-05-06 08:31 . 2010-05-06 08:31 57409 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-06 08:31 . 2010-05-06 08:31 52963 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-06 08:31 . 2010-05-06 08:31 54073 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-06 08:31 . 2010-05-06 08:31 56969 -c--a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-05-05 20:38 . 2010-05-05 20:38 21035 -c--a-w- c:\windows\system32\drivers\AegisP.sys
2010-05-02 05:22 . 2009-06-24 11:33 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-27 18:40 . 2009-06-28 00:36 133616 -c----w- c:\windows\system32\pxafs.dll
2010-04-27 18:40 . 2009-06-24 18:14 126448 -c----w- c:\windows\system32\pxinsi64.exe
2010-04-27 18:40 . 2009-06-24 18:14 123888 -c----w- c:\windows\system32\pxcpyi64.exe
2010-04-27 18:40 . 2004-07-13 09:03 45648 -c----w- c:\windows\system32\drivers\pxhelp20.sys
2009-09-25 16:41 . 2009-09-25 16:41 1044480 -c--a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 -c--a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
--- c:\windows\system32\drivers\vcjrn.sys ---
Company: ------
File Description: ------
File Version: ------
Product Name: ------
Copyright: ------
Original Filename: ------
File size: 766464
Created time: 2010-07-22 03:47
Modified time: 2010-07-26 01:32
MD5: !HASH: COULD NOT OPEN FILE !!!!!
SHA1: !HASH: COULD NOT OPEN FILE !!!!!
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-07-22 2403568]
"Google Update"="c:\documents and settings\Blackshear\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-09 135664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 61952]
"SoundMan"="SOUNDMAN.EXE" [2005-09-21 86016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2010-5-12 1261568]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Adobe\\Adobe Flash CS3\\Flash.exe"=
"c:\\Documents and Settings\\Blackshear\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\NETGEAR\\WG111v2\\WG111v2.exe"=
"c:\\Program Files\\Adobe\\Adobe Dreamweaver CS3\\Dreamweaver.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [1/5/2010 8:56 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 8:56 AM 67656]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [5/12/2010 12:19 PM 194304]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 8:56 AM 12872]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/12/2010 3:10 AM 691696]
--- Other Services/Drivers In Memory ---
*Deregistered* - vcjrn
.
Contents of the 'Scheduled Tasks' folder
2009-10-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2010-07-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-336825795-975779247-2064553283-1009Core.job
- c:\documents and settings\Blackshear\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-09 04:56]
2010-07-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-336825795-975779247-2064553283-1009UA.job
- c:\documents and settings\Blackshear\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-09 04:56]
2010-07-26 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2009-06-24 00:32]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.adelphia.net/uDefault_Search_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktopuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8mSearch Bar =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktopuInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
Notify-NavLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-25 18:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vcjrn]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(952)
c:\windows\system32\RtlGina2.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2536)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dllhost.exe
c:\windows\SOUNDMAN.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-25 18:47:16 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-26 01:47
ComboFix2.txt 2010-07-24 04:49
Pre-Run: 41,028,132,864 bytes free
Post-Run: 41,019,219,968 bytes free
- - End Of File - - 60EA97DD31561492F285052A3B78E698