ComboFix 10-10-21.02 - mike 10/22/2010 0:18.1.1 - x86
Running from: c:\documents and settings\mike\Desktop\Combo-Fix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\101athrez959955.ocx
c:\windows\10554spamzot6989.cpl
c:\windows\10753no9-a-viruz7d.dll
c:\windows\109235pz39.exe
c:\windows\10addz59e33.ocx
c:\windows\10z035irus379.dll
c:\windows\11253t5oj39z.cpl
c:\windows\11465spz549.cpl
c:\windows\1176659rm5z8.exe
c:\windows\119etzi9f5253.dll
c:\windows\120z9sp5mbot9b4.cpl
c:\windows\12373zacktool4395.dll
c:\windows\123z0worm495.cpl
c:\windows\130zadd5are9581.cpl
c:\windows\13325zroj957.dll
c:\windows\134z0sp9m5ot25d.ocx
c:\windows\13z95ackdoor49.cpl
c:\windows\14255szy92f.exe
c:\windows\14304trz91735.cpl
c:\windows\14688z95m1ff.dll
c:\windows\1538woz958e.ocx
c:\windows\15475zr9j5c2.dll
c:\windows\15589ownl5adzr1752.cpl
c:\windows\15591spy486z.cpl
c:\windows\159285roj2z1.cpl
c:\windows\15z89worm72c.cpl
c:\windows\1600z9rus585.ocx
c:\windows\16080hacktz5l9a3.dll
c:\windows\1629zvi5us5699.dll
c:\windows\164285oz-a-virus918.cpl
c:\windows\16900z5oj2fa.cpl
c:\windows\16903wo5m695z.exe
c:\windows\169395irus6z2.ocx
c:\windows\170269otza-vir5s3ae.ocx
c:\windows\179z3worm5d8.ocx
c:\windows\18154spamb9t5z.ocx
c:\windows\1837ztroj5b39.exe
c:\windows\184z6not-a-59rus13c.cpl
c:\windows\190969z5us547.ocx
c:\windows\19404virusz9d5.ocx
c:\windows\19585n9t-a-virusz24.exe
c:\windows\19zworm3465.dll
c:\windows\1b8dth5ef24z99.exe
c:\windows\1bd7dow9loa5zr1743.cpl
c:\windows\1d05d5wnloadez5499.ocx
c:\windows\1d55steal5z069.dll
c:\windows\1e885ddwa9e1z.ocx
c:\windows\1z296spa5bot212.exe
c:\windows\2060t9reaz25231.cpl
c:\windows\2099thzeat25415.dll
c:\windows\209c5i9579z.exe
c:\windows\211z9w59m32.dll
c:\windows\2170hzc5tool7d29.cpl
c:\windows\21976hackzool305.ocx
c:\windows\219csparsez575.dll
c:\windows\219z2tro95eb.dll
c:\windows\2259zackdoor5523.ocx
c:\windows\22714sp9225z.exe
c:\windows\22755notza-vir9s42b.dll
c:\windows\2281s9yz415.cpl
c:\windows\24594no9-azvirus399.exe
c:\windows\24709szy45a.cpl
c:\windows\24898wor9zd5.exe
c:\windows\24898z5rm47b.cpl
c:\windows\2499threat418z5.cpl
c:\windows\24z29worm7475.cpl
c:\windows\2500spazbot395.ocx
c:\windows\25628hazktool491.exe
c:\windows\2599spyware1231z.cpl
c:\windows\25a4spyware2z129.ocx
c:\windows\25b7downloade93179z.dll
c:\windows\25z59ddware88.ocx
c:\windows\2600a5dware29z0.dll
c:\windows\261fztea54459.exe
c:\windows\26705orm7z49.cpl
c:\windows\267335ot9a-virzs9.cpl
c:\windows\26950nz9-a-virus6.cpl
c:\windows\27015tr5z7a89.exe
c:\windows\27126haczt5o94f0.exe
c:\windows\271599pz5d.ocx
c:\windows\2749virz775.dll
c:\windows\279615orm2c7z.dll
c:\windows\27991zot-a-viru559.dll
c:\windows\279zv9rus4935.ocx
c:\windows\2818zhacktool952.ocx
c:\windows\28575v9rusz3c.ocx
c:\windows\2961zs9ambot65b.dll
c:\windows\29652s9yz5.cpl
c:\windows\29729hzcktool3515.ocx
c:\windows\2a69z5ckdoor260.exe
c:\windows\2b81s9y5are122z.exe
c:\windows\2be1backdoz93225.ocx
c:\windows\2d55tz5eat246439.dll
c:\windows\2d9z5ownloader1847.exe
c:\windows\2f1dsp9za5e1054.dll
c:\windows\2f69addzare20935.cpl
c:\windows\30090v5rzs6f3.exe
c:\windows\305z5viru9265.cpl
c:\windows\30e4t59ef29z4.cpl
c:\windows\31055hacztool903.cpl
c:\windows\3115hackt5ol469z.exe
c:\windows\3141v5zus669.cpl
c:\windows\31d1spyware9575z.cpl
c:\windows\32030zackt5ol499.ocx
c:\windows\32150virz9225.dll
c:\windows\3585addwarez9.exe
c:\windows\35fd9pyware32z3.ocx
c:\windows\3895vizus3b5.cpl
c:\windows\39575orm4cz.dll
c:\windows\3984azdwar5567.cpl
c:\windows\3991hackto5lzc9.cpl
c:\windows\399spywarez7995.ocx
c:\windows\39a5szarse1852.dll
c:\windows\3a635ir931z.exe
c:\windows\3a68ad5zare27529.ocx
c:\windows\3b35adzwa9e384.exe
c:\windows\3b97steaz2595.exe
c:\windows\3b99sp5zar92982.exe
c:\windows\3d85addw9rez505.dll
c:\windows\3ec9t5iez2640.cpl
c:\windows\3z8485py97.dll
c:\windows\4009hzckto9l7265.dll
c:\windows\40a5spywa5917z8.dll
c:\windows\4295vir96z.exe
c:\windows\43705ir24z9.cpl
c:\windows\442fth59f233z.ocx
c:\windows\44dzt9reat261325.dll
c:\windows\458dtzief2909.ocx
c:\windows\4594adzware1975.exe
c:\windows\459estezl355.exe
c:\windows\45z5sparse959.exe
c:\windows\45zteal5079.ocx
c:\windows\46195py540z.dll
c:\windows\4690addw9ze6645.ocx
c:\windows\47829zckdoo5915.cpl
c:\windows\47ec95ief299z.cpl
c:\windows\47z25ddwa9e2682.exe
c:\windows\4865doznl9ader968.dll
c:\windows\48fbspa5se2964z.exe
c:\windows\490steal9z35.dll
c:\windows\4cebad5ware95z5.ocx
c:\windows\4cf7thrzat25159.dll
c:\windows\4e5z5tea933.ocx
c:\windows\4f38back9oo51z84.exe
c:\windows\4fd05h9ef321z.ocx
c:\windows\50319no9-a-zirus669.ocx
c:\windows\504dadd9are3z88.cpl
c:\windows\5189spy95z.dll
c:\windows\51czba9kdoor5236.cpl
c:\windows\52z2not-a-v9rus25b.ocx
c:\windows\5352ztro9360.dll
c:\windows\537zsp9rse71.cpl
c:\windows\539esteal247z.exe
c:\windows\53ezsp5rse14049.cpl
c:\windows\55283haz9tool3b0.cpl
c:\windows\552zp9470.dll
c:\windows\555thizf691.cpl
c:\windows\5566thief9232z.cpl
c:\windows\5580dzwnlo5d9r987.dll
c:\windows\5584zs9y75f.ocx
c:\windows\559zvir28539.exe
c:\windows\55c5backdooz1942.ocx
c:\windows\55zt9ief1658.cpl
c:\windows\56489zoj4f2.ocx
c:\windows\56cvirz799.dll
c:\windows\579tzief13569.ocx
c:\windows\5805bac9z5or681.dll
c:\windows\58398trzj417.dll
c:\windows\584backdzor2992.ocx
c:\windows\589bvi51031z.ocx
c:\windows\59255dzware1315.ocx
c:\windows\59380spamboz2d7.ocx
c:\windows\594stzal1996.cpl
c:\windows\5959zir2959.dll
c:\windows\597dbackdo5r2z0.exe
c:\windows\5989hazktoole5.cpl
c:\windows\59b8spyware5z71.exe
c:\windows\59e0bzck9o5r610.cpl
c:\windows\5a259irz030.ocx
c:\windows\5a5v59z615.dll
c:\windows\5b53downloade92496z.cpl
c:\windows\5cz6spywar92933.exe
c:\windows\5d9cs5ywaze1469.exe
c:\windows\5df0downlozder2189.dll
c:\windows\5ef5bac59oor1123z.ocx
c:\windows\5f59addwar5z890.ocx
c:\windows\5f96down9oader25z9.dll
c:\windows\5z121virus429.dll
c:\windows\5z395worm28.cpl
c:\windows\5zb5spar9e5606.exe
c:\windows\5zb7spywa9e844.ocx
c:\windows\5zb9threat8308.ocx
c:\windows\627zbackdoor9595.exe
c:\windows\639st5al1997z.ocx
c:\windows\6459spywar5498z.ocx
c:\windows\65349irz596.dll
c:\windows\6587vizu569a9.ocx
c:\windows\6589wo9m5e5z.dll
c:\windows\66a7thr5a9993z.cpl
c:\windows\66b99zwnloader6955.exe
c:\windows\66cbb5ck9oor207z.ocx
c:\windows\679fzir563.exe
c:\windows\6860s95zbota6.exe
c:\windows\689d5zeal708.ocx
c:\windows\69c9spyware5z50.ocx
c:\windows\6cc3zh9eat5542.exe
c:\windows\6effthz591321.ocx
c:\windows\6ezsteal20965.ocx
c:\windows\6f58zir759.exe
c:\windows\6z53spyware2009.dll
c:\windows\6zb5ba5kdoo91098.ocx
c:\windows\70359ot-z-virus353.ocx
c:\windows\703e5irz179.ocx
c:\windows\725a9hiez1861.ocx
c:\windows\7282spyza5e1159.exe
c:\windows\733f5hreat38z9.dll
c:\windows\743ath5eat25729z.ocx
c:\windows\74529roj18fz.cpl
c:\windows\74z1hacktoo59f.ocx
c:\windows\755btzief379.exe
c:\windows\75a6sze9l494.cpl
c:\windows\75d9addwarz1198.cpl
c:\windows\75f4vir3z559.exe
c:\windows\7679spar5z9247.cpl
c:\windows\7707vzr9539.exe
c:\windows\7765thizf2559.exe
c:\windows\7842w5r9zb1.exe
c:\windows\78d9addwar520z2.ocx
c:\windows\79aste5l24z6.cpl
c:\windows\79f79hrezt1225.exe
c:\windows\7c54zteal955.cpl
c:\windows\7c95downlzader7405.exe
c:\windows\7d59spar9e4z7.ocx
c:\windows\7f64z5wn9oader449.ocx
c:\windows\7z92a5dware1928.ocx
c:\windows\806hac5to9lza.dll
c:\windows\81z45acktoo919d.cpl
c:\windows\8219zot-a-v9rus7a5.exe
c:\windows\859wozm55d.dll
c:\windows\8673not-a-5irus9b9z.exe
c:\windows\88339irusz885.dll
c:\windows\9084zspy1695.cpl
c:\windows\90898spazbot6615.cpl
c:\windows\91viz5094.exe
c:\windows\9208z5iruse2.dll
c:\windows\9235wzrmec.ocx
c:\windows\92423za5ktool292.cpl
c:\windows\92z25spy29c.cpl
c:\windows\933z9spambot5fd.exe
c:\windows\948z7troj5df.ocx
c:\windows\9506tr9j55z.cpl
c:\windows\95182trojz15.cpl
c:\windows\951sp9mzot5ec.ocx
c:\windows\956z3wo5m7e3.ocx
c:\windows\957cbackdoorz07.ocx
c:\windows\959zsteal1049.ocx
c:\windows\95a2thzef2491.cpl
c:\windows\9688spy5zb.cpl
c:\windows\96faspz5are291.ocx
c:\windows\9750vir9sz99.dll
c:\windows\9839threat1521z.ocx
c:\windows\995zvir5105.cpl
c:\windows\99d5v5r252z.cpl
c:\windows\9b76t5zef377.cpl
c:\windows\9bdz5ddware1437.dll
c:\windows\9z15v5r3109.dll
c:\windows\ca9dwarz1850.exe
c:\windows\d779par5ez481.cpl
c:\windows\fz2spyw5re9858.exe
c:\windows\system32\10348zor92a15.dll
c:\windows\system32\11258zacktool59d9.dll
c:\windows\system32\11787ha9ktozl255.dll
c:\windows\system32\11z39hackt59l63c.exe
c:\windows\system32\123zthr5at9293.exe
c:\windows\system32\125z5not-a-vir9s571.ocx
c:\windows\system32\12958sp59z.ocx
c:\windows\system32\1305trzj698.dll
c:\windows\system32\139z25irus97.ocx
c:\windows\system32\141d59arsz2148.ocx
c:\windows\system32\1447spz9bot5b95.dll
c:\windows\system32\145z9virus50c.ocx
c:\windows\system32\14900not-9-5irus51z.dll
c:\windows\system32\14z8dow5loader978.ocx
c:\windows\system32\1510zworm6399.dll
c:\windows\system32\15145tro9z295.ocx
c:\windows\system32\151dz9reat16390.dll
c:\windows\system32\153249rojz16.cpl
c:\windows\system32\1589steal2z59.ocx
c:\windows\system32\1592zddware2481.ocx
c:\windows\system32\15963wzrm5f9.exe
c:\windows\system32\159zba5kdoor1150.cpl
c:\windows\system32\15d8viz499.dll
c:\windows\system32\1729baczd5or954.exe
c:\windows\system32\1735spywa5ez922.dll
c:\windows\system32\17551v9rzs3de.dll
c:\windows\system32\175dstzal95.ocx
c:\windows\system32\1912do5nloader9909z.dll
c:\windows\system32\19359spzm5ot554.cpl
c:\windows\system32\19569spzmbot795.cpl
c:\windows\system32\198spzm5ot101.exe
c:\windows\system32\1999zspy5e8.exe
c:\windows\system32\19a0thizf2595.dll
c:\windows\system32\19d5szyware4205.ocx
c:\windows\system32\1bc5backdoor2998z.dll
c:\windows\system32\1dc59dzwar53120.ocx
c:\windows\system32\1dc8t9reaz29507.cpl
c:\windows\system32\1e55vir29z5.exe
c:\windows\system32\1e5ethzeat93554.cpl
c:\windows\system32\1f5c9parsez44.ocx
c:\windows\system32\1z07v9r514.exe
c:\windows\system32\1z095troj768.exe
c:\windows\system32\1z520s5y19.ocx
c:\windows\system32\1z6viru59a3.cpl
c:\windows\system32\2009downloaderz865.ocx
c:\windows\system32\21982vz9us151.ocx
c:\windows\system32\22496tzoj765.cpl
c:\windows\system32\225z9not5a-virus759.ocx
c:\windows\system32\22645zot-a-9iru56cc.exe
c:\windows\system32\22717not-5-vzrus4d19.ocx
c:\windows\system32\22849hacktzol985.cpl
c:\windows\system32\230z4h5cktool299.dll
c:\windows\system32\23232spambz95d.dll
c:\windows\system32\234fv5r789z.ocx
c:\windows\system32\235115r9j6dz.exe
c:\windows\system32\2355bazkd95r551.cpl
c:\windows\system32\23820t5o977z.ocx
c:\windows\system32\23cfadzwa951183.exe
c:\windows\system32\23fzspars5194.cpl
c:\windows\system32\2451zvi5usc49.dll
c:\windows\system32\2462haz95ool45a.dll
c:\windows\system32\24963w5rm4zf.ocx
c:\windows\system32\2508viru95a9z.cpl
c:\windows\system32\2509z9dware1977.cpl
c:\windows\system32\25302vizus391.dll
c:\windows\system32\255069orm447z.exe
c:\windows\system32\2550spzrse22509.ocx
c:\windows\system32\255b9irz26.exe
c:\windows\system32\255c9hizf1354.dll
c:\windows\system32\25995worm689z.dll
c:\windows\system32\25cdth9eat7578z.ocx
c:\windows\system32\26053noz-a-virus79d.cpl
c:\windows\system32\267z69pambot5f8.dll
c:\windows\system32\26934not-a-5zrus33d.cpl
c:\windows\system32\26z9thi5f499.exe
c:\windows\system32\27205acktozl9b2.ocx
c:\windows\system32\27892hacktooz5f.exe
c:\windows\system32\27z22spambot659.cpl
c:\windows\system32\2895stealz939.ocx
c:\windows\system32\28bd5par9z704.exe
c:\windows\system32\290325py129z.exe
c:\windows\system32\29559spazbot265.ocx
c:\windows\system32\29z1spy6b85.cpl
c:\windows\system32\2b4et9iefz545.cpl
c:\windows\system32\2d72back5zo91028.dll
c:\windows\system32\2ee8s5y9arz2358.cpl
c:\windows\system32\2z134wo9m259.dll
c:\windows\system32\3079s5z427.exe
c:\windows\system32\31001haczt5ol917.exe
c:\windows\system32\3145a9ktoolz41.ocx
c:\windows\system32\315viz959.dll
c:\windows\system32\31692sza9bo539c.cpl
c:\windows\system32\319z7ha9ktoo556b.ocx
c:\windows\system32\31b9spz5are16589.ocx
c:\windows\system32\3358addzare8579.cpl
c:\windows\system32\33695zoj1cf9.dll
c:\windows\system32\3475zddware559.dll
c:\windows\system32\359adownloader5z4.ocx
c:\windows\system32\35z3w9rm390.ocx
c:\windows\system32\35z4back9oor2731.exe
c:\windows\system32\3691spzware1053.dll
c:\windows\system32\39175iz158.dll
c:\windows\system32\391bzdd5are2844.exe
c:\windows\system32\39222troj515z.ocx
c:\windows\system32\39595ownl9ader8z9.cpl
c:\windows\system32\3999ir215z.cpl
c:\windows\system32\39ev5z93.ocx
c:\windows\system32\39zfspa5se9139.dll
c:\windows\system32\3a8b9teal5125z.dll
c:\windows\system32\3c4bv5rz4959.ocx
c:\windows\system32\3ccdo5n9oader4z5.cpl
c:\windows\system32\3d4f5ownloader3z29.cpl
c:\windows\system32\3ddc9hi5f2625z.cpl
c:\windows\system32\3fback5oor95z.ocx
c:\windows\system32\3z1bac9door3153.cpl
c:\windows\system32\3z3edow95oader816.cpl
c:\windows\system32\3z7do9nloader2505.cpl
c:\windows\system32\3z95thief25129.exe
c:\windows\system32\3za5spyw5re2957.exe
c:\windows\system32\4051thre9t6z71.dll
c:\windows\system32\406et5r9at25z70.ocx
c:\windows\system32\427zw95m3ea.ocx
c:\windows\system32\428bs59alz831.cpl
c:\windows\system32\4359pyz3f.ocx
c:\windows\system32\43f2s9yw5re2z35.dll
c:\windows\system32\4528addwzre419.exe
c:\windows\system32\4599rozc6.cpl
c:\windows\system32\45fcadd9arz7545.cpl
c:\windows\system32\46edv9r5z36.dll
c:\windows\system32\4926ste5l174z.ocx
c:\windows\system32\4951z5y134.dll
c:\windows\system32\4989thief17z5.dll
c:\windows\system32\4994spazbot357.exe
c:\windows\system32\4b26szyw9r595.dll
c:\windows\system32\4b569zief388.dll
c:\windows\system32\4c8dspyw9re5574z.cpl
c:\windows\system32\4d86downlo9der2535z.cpl
c:\windows\system32\4d9a9parse1z25.ocx
c:\windows\system32\50589zief3252.exe
c:\windows\system32\5090v9rus69z.ocx
c:\windows\system32\509sp97az.exe
c:\windows\system32\50c0back5oor10z79.dll
c:\windows\system32\52225tr9z192.ocx
c:\windows\system32\52498spamboz298.exe
c:\windows\system32\52c2spywarez5539.dll
c:\windows\system32\5351vi5z319.exe
c:\windows\system32\5375ba9kdoor121z.exe
c:\windows\system32\53z9t5ief2764.ocx
c:\windows\system32\5419t5oz6bc9.cpl
c:\windows\system32\54cztea92655.ocx
c:\windows\system32\5520trzj2919.dll
c:\windows\system32\5550spaz59t705.exe
c:\windows\system32\5552thzef1195.ocx
c:\windows\system32\55f7spzware32239.dll
c:\windows\system32\5622spy5are91z4.dll
c:\windows\system32\56693spamboz775.cpl
c:\windows\system32\5682zpy692.dll
c:\windows\system32\5787bac5doo91911z.cpl
c:\windows\system32\579znot-a-virus4a9.ocx
c:\windows\system32\57b5thze9397.exe
c:\windows\system32\5809ste5l9z38.dll
c:\windows\system32\58185hack9ozl49f.dll
c:\windows\system32\58f8zhreat94425.exe
c:\windows\system32\5913spambzt5a9.exe
c:\windows\system32\598d5tealz94.ocx
c:\windows\system32\59adaddwaze2599.cpl
c:\windows\system32\59f8st95lz689.dll
c:\windows\system32\5b15zpy5are9319.exe
c:\windows\system32\5b52dow5load9r247z.dll
c:\windows\system32\5c64s5e9lz357.cpl
c:\windows\system32\5ce9th5efz625.dll
c:\windows\system32\5d85s59rse49z.cpl
c:\windows\system32\5dc6thre9t79z5.exe
c:\windows\system32\5e9e5iz1969.cpl
c:\windows\system32\5ec3v9r2995z.dll
c:\windows\system32\5fa4addwar93z5.cpl
c:\windows\system32\61e8back95or1446z.exe
c:\windows\system32\6530trzj49.cpl
c:\windows\system32\655threaz24955.exe
c:\windows\system32\6592downloader15z8.exe
c:\windows\system32\65dedownlo95ez299.ocx
c:\windows\system32\65f9ad9warz164.cpl
c:\windows\system32\6748spz9b5t2bc.exe
c:\windows\system32\685cvi91865z.cpl
c:\windows\system32\691eazdware5779.dll
c:\windows\system32\6bc5parsez196.cpl
c:\windows\system32\6bfcbz9kdoor3605.dll
c:\windows\system32\6d75pa9ze359.dll
c:\windows\system32\7151nzt-a-virus359.cpl
c:\windows\system32\7152zot-a-5i9us40f.ocx
c:\windows\system32\7156troj18z9.ocx
c:\windows\system32\74905owzloade92173.ocx
c:\windows\system32\750dbackdoz91744.ocx
c:\windows\system32\75f49ackzoo543.cpl
c:\windows\system32\7675pambzt95.cpl
c:\windows\system32\76b5zh9eat25195.ocx
c:\windows\system32\7792szam9ot75.dll
c:\windows\system32\77a09zreat15839.ocx
c:\windows\system32\7859thrzat22993.dll
c:\windows\system32\79895py931z.dll
c:\windows\system32\798worm50z5.exe
c:\windows\system32\7992vir5z3c6.dll
c:\windows\system32\79czb5ckdoor29.ocx
c:\windows\system32\7b89zhre5t5942.cpl
c:\windows\system32\7d56dzwn9oader938.ocx
c:\windows\system32\7dcca5dzare2091.exe
c:\windows\system32\8017haczt5ol9b6.exe
c:\windows\system32\83015p926z.exe
c:\windows\system32\8331sp9mboz325.exe
c:\windows\system32\8339s5ambo9z79.cpl
c:\windows\system32\8397not-a-vz59s526.exe
c:\windows\system32\8953hac9zool1dd.cpl
c:\windows\system32\90z09w5rm5ea.exe
c:\windows\system32\91615viruz788.exe
c:\windows\system32\9190zac95ool62b.exe
c:\windows\system32\92z9spambo55d.ocx
c:\windows\system32\9352spazse2932.exe
c:\windows\system32\9359ackdoo5107z.exe
c:\windows\system32\93z8tro5573.exe
c:\windows\system32\941z3wor578a.ocx
c:\windows\system32\958spyz5re1499.cpl
c:\windows\system32\95z59worm5e7.cpl
c:\windows\system32\96z65hief3117.dll
c:\windows\system32\9740not-a-zi5us169.cpl
c:\windows\system32\97500zorm6bd.dll
c:\windows\system32\9891hack5ozl9d4.exe
c:\windows\system32\98956zpy25f.dll
c:\windows\system32\9988dzwnlo5der1817.cpl
c:\windows\system32\9988spyz6f5.dll
c:\windows\system32\99zspywa5e823.cpl
c:\windows\system32\9ce0thiez2546.exe
c:\windows\system32\9d2evirz525.ocx
c:\windows\system32\9z1fvi51309.cpl
c:\windows\system32\9z71vi9us56.cpl
c:\windows\system32\9zaa95ware1144.cpl
c:\windows\system32\9zbac5door3172.dll
c:\windows\system32\a89backdoo5z314.dll
c:\windows\system32\ae5zhief9685.ocx
c:\windows\system32\b9dzpyware18645.cpl
c:\windows\system32\c79downzoad5r3156.cpl
c:\windows\system32\ce759wnlzader1243.dll
c:\windows\system32\fedtzre9515419.cpl
c:\windows\system32\fthiez9755.ocx
c:\windows\system32\fthr9at514z5.cpl
c:\windows\system32\z146wo9m5895.dll
c:\windows\system32\z1779t5oj689.exe
c:\windows\system32\z1945v5rus10c.dll
c:\windows\system32\z365steal2958.dll
c:\windows\system32\z3abac9door254.cpl
c:\windows\system32\z49b9parse5053.dll
c:\windows\system32\z54viru9395.ocx
c:\windows\system32\z57985roj79d.ocx
c:\windows\system32\z587tro5609.cpl
c:\windows\system32\z638v5r9970.exe
c:\windows\system32\z6725worm590.ocx
c:\windows\system32\z9459ir5829.exe
c:\windows\system32\z96astea52497.exe
c:\windows\system32\z980not-a-v5rus52c.ocx
c:\windows\system32\z9830troj5f9.dll
c:\windows\system32\z9c85hreat971.dll
c:\windows\system32\ze01spars524589.ocx
c:\windows\z09199roj5e7.ocx
c:\windows\z15509py2ac.ocx
c:\windows\z37es9arse4615.ocx
c:\windows\z5102troj499.ocx
c:\windows\z5515tro928a.cpl
c:\windows\z558thief2979.cpl
c:\windows\z59fsparse1754.exe
c:\windows\z6955worm735.cpl
c:\windows\z7489sp551f.dll
c:\windows\z835vir32699.dll
c:\windows\z8e5s5eal9569.dll
c:\windows\z8ethi9f1655.dll
c:\windows\z98fspy5are2277.exe
c:\windows\z998stea56299.exe
c:\windows\z9c05py9are2867.dll
c:\windows\zb37s9ywar5994.dll
c:\windows\zd9thre5t17229.ocx
c:\windows\ze3cbac5doo91727.cpl
c:\windows\zf10sp5rse16579.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_gxvxcserv.sys
-------\Service_gxvxcserv.sys
((((((((((((((((((((((((( Files Created from 2010-09-22 to 2010-10-22 )))))))))))))))))))))))))))))))
.
2010-10-20 21:15 . 2010-10-20 21:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-10-19 07:42 . 2010-10-19 07:42 -------- d-----w- c:\windows\Digital Rescue 4 Premium
2010-10-19 07:42 . 2010-10-19 07:42 -------- d-----w- c:\program files\Migo Software
2010-10-19 07:22 . 2010-10-19 07:22 -------- d-----w- c:\program files\Convar
2010-10-19 07:14 . 2010-10-19 07:14 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-10-19 07:06 . 2010-10-19 07:06 -------- d-----w- c:\documents and settings\mike\Application Data\Avira
2010-10-19 06:48 . 2010-03-01 17:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-19 06:48 . 2010-02-16 21:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-19 06:48 . 2009-05-11 19:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-19 06:48 . 2009-05-11 19:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-19 06:48 . 2010-10-19 06:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-10-19 05:35 . 2010-10-19 05:35 -------- d-----w- c:\windows\system32\wbem\Repository
2010-10-18 19:33 . 2010-10-20 08:11 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2010-10-18 10:29 . 2010-10-18 10:29 -------- d-----w- c:\program files\DiskInternals
2010-10-18 08:53 . 2010-10-19 05:34 -------- d-----w- c:\program files\Recover Files
2010-09-23 01:10 . 2010-09-23 01:10 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-03-16 868352]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-27 185872]
"M-Audio Taskbar Icon"="c:\windows\system32\M-AudioTaskBarIcon.exe" [2009-11-09 643592]
"DigidesignMMERefresh"="c:\program files\Digidesign\Drivers\MMERefresh.exe" [2008-12-04 77824]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"QuickTime Task"="d:\additional programs\quicktime\qttask.exe" [2009-05-27 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave5"=Digi32.dll
"MIDI5"=diomidi.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Additional Programs\\Itunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Additional Programs\\vuze\\Azureus.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"1032:TCP"= 1032:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [10/18/2010 11:48 PM 135336]
R2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [5/30/2010 5:49 PM 16400]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/8/2010 6:35 PM 135664]
S3 iLokDrvr;Usb Driver;c:\windows\system32\drivers\iLokDrvr.sys [12/23/2009 11:36 AM 54328]
S3 MAUSBFASTTRACKPRO;Service for M-Audio FastTrack Pro;c:\windows\system32\drivers\MAudioFastTrackPro.sys [5/31/2010 7:51 PM 158600]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [8/23/2001 5:00 AM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-10-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-12 20:34]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 01:35]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 01:35]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://yahoo.com/IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\mike\Application Data\Mozilla\Firefox\Profiles\wbsonsmt.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - plugin: c:\documents and settings\mike\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\documents and settings\mike\Application Data\Mozilla\Firefox\Profiles\wbsonsmt.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Web Platform Installer\NPWPIDetector.dll
FF - plugin: c:\program files\NOS\bin\np_gp.dll
FF - plugin: c:\program files\PACE Anti-Piracy\iLok\NPPaceILok.dll
FF - plugin: d:\additional programs\Divx\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: d:\additional programs\Divx\DivX Web Player\npdivx32.dll
FF - plugin: d:\additional programs\Itunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\additional programs\quicktime\Plugins\npqtplugin.dll
FF - plugin: d:\additional programs\quicktime\Plugins\npqtplugin2.dll
FF - plugin: d:\additional programs\quicktime\Plugins\npqtplugin3.dll
FF - plugin: d:\additional programs\quicktime\Plugins\npqtplugin4.dll
FF - plugin: d:\additional programs\quicktime\Plugins\npqtplugin5.dll
FF - plugin: d:\additional programs\quicktime\Plugins\npqtplugin6.dll
FF - plugin: d:\additional programs\quicktime\Plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Avira AntiVir Desktop - c:\program files\Avira\AntiVir Desktop\setup.exe
AddRemove-{9F1D8E17-2AE6-4608-901D-42146D7D9C68} - c:\program files\InstallShield Installation Information\{9F1D8E17-2AE6-4608-901D-42146D7D9C68}\setup.exe
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x840F7446]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\atapi -> atapi.sys @ 0xb9f11852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579014
ParseProcedure -> ntkrnlpa.exe @ 0x80577c76
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579014
ParseProcedure -> ntkrnlpa.exe @ 0x80577c76
NDIS: Broadcom NetLink (TM) Gigabit Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xb9de6bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9df3a21
SendHandler -> NDIS.sys @ 0xb9dd187b
user & kernel MBR OK
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1715567821-573735546-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:0a,8c,c7,7d,92,1c,23,2b,e9,78,f4,19,57,8f,51,cd,8b,bb,8c,79,ec,
02,0a,8f,32,42,1f,4a,9f,73,2d,1b,1f,58,11,7a,96,3c,66,1e,c9,a2,09,5b,52,13,\
"rkeysecu"=hex:bb,ef,ff,78,01,c0,e5,fd,0a,13,dd,82,78,16,2e,c1
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(248)
c:\windows\system32\hnetcfg.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Canon\CAL\CALMAIN.exe
.
**************************************************************************
.
Completion time: 2010-10-22 00:44:01 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-22 07:44
ComboFix2.txt 2009-11-18 05:50
Pre-Run: 10,891,247,616 bytes free
Post-Run: 12,075,728,896 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 8CB2D239A4D3DA7432090A9DFC225788