I have taken the liberty of posting this in the forum. Easier to analyse.
ComboFix 09-09-18.02 - Roshan 2009/09/20 22:24.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.932.81.1041.18.1014.530 [GMT -4:00]
Running from: c:\documents and settings\Roshan\デスクトップ\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning enabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-1454471165-879983540-682003330-500
c:\windows\Installer\129c6b58.msp
c:\windows\Installer\12aa0130.msp
c:\windows\Installer\12d9455b.msp
c:\windows\Installer\12f60bec.msp
c:\windows\Installer\146a51.msp
c:\windows\Installer\14cb5d.msp
c:\windows\Installer\15730a0.msp
c:\windows\Installer\164f960.msp
c:\windows\Installer\169167.msp
c:\windows\Installer\16b26c.msp
c:\windows\Installer\1855616f.msp
c:\windows\Installer\18556172.msp
c:\windows\Installer\18556175.msp
c:\windows\Installer\1884b1f.msp
c:\windows\Installer\188d570e.msp
c:\windows\Installer\188d5711.msp
c:\windows\Installer\21c274.msp
c:\windows\Installer\245b841f.msp
c:\windows\Installer\2662698.msp
c:\windows\Installer\2ae9cb57.msp
c:\windows\Installer\2b563c06.msp
c:\windows\Installer\2edf0.msp
c:\windows\Installer\30d0d99.msp
c:\windows\Installer\30e90643.msp
c:\windows\Installer\30e90646.msp
c:\windows\Installer\32b07d52.msp
c:\windows\Installer\32c07517.msp
c:\windows\Installer\3d429.msp
c:\windows\Installer\49185f3.msp
c:\windows\Installer\4f7ff59.msp
c:\windows\Installer\51aa1f0.msp
c:\windows\Installer\5c67e2.msp
c:\windows\Installer\6d728.msp
c:\windows\Installer\779e844.msp
c:\windows\Installer\7fdfa.msi
c:\windows\Installer\929ed5.msi
c:\windows\Installer\a457ec1.msp
c:\windows\Installer\f0ab9.msi
c:\windows\Installer\f2dd495.msp
c:\windows\system32\drivers\Sonyhcp.dll
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-08-21 to 2009-09-21 )))))))))))))))))))))))))))))))
.
2009-09-20 18:55 . 2009-09-20 21:22 0 ----a-r- c:\windows\win32k.sys
2009-09-20 18:48 . 2009-09-20 18:48 -------- d-----w- c:\documents and settings\Roshan\Application Data\WinPatrol
2009-09-20 18:48 . 2005-03-24 04:09 0 ----a-w- c:\documents and settings\Roshan\Application Data\WinPatrol\Config.sys
2009-09-20 18:48 . 2005-03-24 04:09 0 ----a-w- c:\documents and settings\Roshan\Application Data\WinPatrol\Autoexec.bat
2009-09-18 22:11 . 2009-09-18 22:11 -------- d-----w- c:\documents and settings\Roshan\Application Data\Malwarebytes
2009-09-18 22:11 . 2009-09-18 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-18 21:39 . 2009-09-20 21:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-18 17:49 . 2009-09-18 17:49 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
2009-09-08 23:01 . 2009-06-21 21:43 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-04 20:09 . 2009-09-04 20:09 2989 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2009-09-01 22:18 . 2009-09-01 22:18 -------- d-----w- c:\documents and settings\Roshan\Application Data\Foxit Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-21 01:52 . 2008-05-27 14:49 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-20 15:13 . 2008-12-26 15:58 -------- d-----w- c:\program files\Premium Booster
2009-09-19 12:52 . 2009-04-14 03:21 287630 ----a-w- c:\windows\system32\prfh0411.dat
2009-09-19 12:52 . 2009-04-14 03:21 95142 ----a-w- c:\windows\system32\prfc0411.dat
2009-09-19 12:14 . 2007-09-07 04:38 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-18 21:35 . 2005-03-24 04:02 -------- d-----w- c:\program files\Sigmatel
2009-09-18 21:32 . 2008-12-26 20:29 -------- d-----w- c:\program files\Realtek
2009-09-18 21:32 . 2008-02-10 17:54 -------- d-----w- c:\program files\Yahoo!
2009-09-18 21:21 . 2009-01-16 12:14 -------- d-----w- c:\documents and settings\Roshan\Application Data\Uniblue
2009-09-18 19:09 . 2007-11-30 16:38 -------- d-----w- c:\program files\Virtual Dimension
2009-09-18 18:09 . 2009-02-04 15:34 -------- d-----w- c:\program files\IObit
2009-09-04 20:19 . 2008-10-12 12:37 1 ----a-w- c:\documents and settings\Roshan\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-09-04 20:08 . 2009-08-01 12:30 515760 ----a-w- c:\windows\system32\SpoonUninstall.exe
2009-09-04 20:07 . 2009-08-01 12:30 15341 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2009-09-04 14:59 . 2008-01-27 22:28 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-19 12:15 . 2008-08-19 15:33 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-19 12:15 . 2008-08-19 15:33 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-19 12:15 . 2008-08-19 15:33 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-17 16:42 . 2009-08-17 16:42 -------- d-----w- c:\program files\Secunia
2009-08-14 21:04 . 2009-08-14 21:04 239088 ----a-w- c:\documents and settings\Roshan\Application Data\Mozilla\plugins\npgoogletalk.dll
2009-08-09 09:44 . 2005-05-30 10:52 -------- d-----w- c:\program files\Maruo
2009-08-09 09:06 . 2008-01-17 14:46 -------- d-----w- c:\program files\Java
2009-08-09 09:05 . 2009-08-09 08:56 152576 ----a-w- c:\documents and settings\Roshan\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-09 08:58 . 2008-10-27 17:18 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-05 08:59 . 2005-03-24 02:52 202752 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 19:07 . 2009-08-03 19:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 19:07 . 2009-08-03 19:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 19:07 . 2009-08-03 19:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-08-02 17:55 . 2005-05-30 11:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-02 16:48 . 2008-03-30 04:01 -------- d-----w- c:\documents and settings\Roshan\Application Data\Apple Computer
2009-08-01 18:19 . 2009-03-05 19:38 -------- d-----w- c:\program files\Everything
2009-08-01 17:56 . 2008-09-25 12:17 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2009-08-01 13:39 . 2009-08-01 13:36 -------- d-----w- c:\documents and settings\Roshan\Application Data\Auslogics
2009-08-01 13:17 . 2009-08-01 12:53 -------- d-----w- c:\program files\iDailyDiary
2009-08-01 12:45 . 2009-08-01 12:45 -------- d-----w- c:\program files\FreeCommander
2009-08-01 12:30 . 2009-08-01 12:30 -------- d-----w- c:\documents and settings\Roshan\Application Data\AccurateRip
2009-08-01 12:29 . 2009-08-01 12:29 -------- d-----w- c:\program files\Illustrate
2009-08-01 12:26 . 2009-01-30 00:31 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-31 11:56 . 2009-07-31 04:00 -------- d-----w- c:\program files\ExplorerXP
2009-07-29 04:34 . 2005-03-24 02:53 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:34 . 2005-03-24 02:50 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-17 19:01 . 2005-03-24 02:49 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 15:49 . 2005-05-20 02:13 112328 ----a-w- c:\documents and settings\Roshan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-14 03:43 . 2005-03-24 02:55 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 16:55 . 2005-03-24 02:53 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:24 . 2005-03-24 02:53 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:24 . 2005-03-24 02:53 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:24 . 2005-03-24 02:53 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:24 . 2005-03-24 02:52 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:24 . 2005-03-24 02:52 714752 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:24 . 2005-03-24 02:51 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2005-03-24 02:51 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2008-01-29 16:42 . 2008-01-29 16:42 28 ----a-w- c:\program files\deviceinfo
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Virtual Dimension"="c:\program files\Virtual Dimension\VirtualDimension.exe" [2005-07-09 446976]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-03-30 68856]
"DExposE2"="c:\program files\DExposE2\DExposE2.exe" [2008-05-07 450048]
"Google Update"="c:\documents and settings\Roshan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-08 133104]
"iDailyDiary"="c:\progra~1\iDailyDiary\iDD.exe" [2008-12-12 1730048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-02-12 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"Hotkey"="c:\windows\system32\hkeyman.exe" [2003-03-14 851968]
"NumLockNotif"="c:\program files\Panasonic\numlkntf\Numlkntf.exe" [2004-08-24 131072]
"PRunOnce"="c:\util\prunonce\PRunOnce.exe" [2004-08-06 110592]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"Panasonic HotKey Manager"="c:\program files\Panasonic\HotKey Appendix\HKEYAPP.EXE" [2005-03-18 929792]
"PCinfo"="c:\program files\Panasonic\PCINFO\SetDiag.exe" [2005-03-17 45056]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-19 2007832]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-04-11 68592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
"ctfmon.exe"="ctfmon.exe" - c:\windows\system32\ctfmon.exe [2008-02-12 15360]
c:\documents and settings\Roshan\スタート メニュー\プログラム\スタートアップ\
Maruo.lnk - c:\program files\Maruo\Maruo.exe [2005-5-30 1852912]
c:\documents and settings\All Users\スタート メニュー\プログラム\スタートアップ\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1041-0000-BA7E-000000000002}\SC_Acrobat.exe [2005-5-22 25214]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2005-3-28 155648]
WordWeb.lnk - c:\program files\WordWeb\wweb32.exe [2005-5-30 42168]
エコノミーモード(ECO)切り替えユーティリティ.lnk - c:\program files\Panasonic\CHGBMODE\ChgBmode.exe [2005-3-28 114688]
オプティカルディスクドライブ省電力ユーティリティ.lnk - c:\program files\Panasonic\OPDOFF\opdoff.exe [2005-3-28 155648]
ネットセレクター.lnk - c:\program files\Panasonic\NSelect\NSelect.exe [2005-3-24 712704]
ホイールパッドユーティリティ.lnk - c:\program files\Panasonic\WheelPad\wheelpad.exe [2005-3-24 335872]
無線LAN切り替えユーティリティ.lnk - c:\program files\Panasonic\WLANSW\WLANSW.EXE [2005-3-24 81920]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\Shell ExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-19 12:15 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LanchNtf]
2004-08-06 08:26 53248 ----a-w- c:\windows\system32\LanchNtf.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDef end]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^スタート メニュー^プログラム^スタートアップ^Adobe Acrobat Speed Launcher.lnk]
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^スタート メニュー^プログラム^スタートアップ^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^スタート メニュー^プログラム^スタートアップ^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^スタート メニュー^プログラム^スタートアップ^BTTray.lnk]
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^スタート メニュー^プログラム^スタートアップ^Google Updater.lnk]
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^スタート メニュー^プログラム^スタートアップ^Logitech SetPoint.lnk]
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^スタート メニュー^プログラム^スタートアップ^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Roshan^スタート メニュー^プログラム^スタートアップ^OpenOffice.org 2.3.lnk]
backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WheelMouse
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3 (0x3)
"btwdins"=2 (0x2)
"avg8emc"=3 (0x3)
"WinDefend"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"SQLAgent$MICROSOFTSMLBIZ"=3 (0x3)
"ose"=3 (0x3)
"MSSQLServerADHelper"=3 (0x3)
"MSSQL$MICROSOFTSMLBIZ"=2 (0x2)
"MCVSRte"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
"McTskshd.exe"=2 (0x2)
"McShield"=3 (0x3)
"McDetect.exe"=2 (0x2)
"matlabserver"=2 (0x2)
"LBTServ"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"RDSessMgr"=3 (0x3)
"BthServ"=2 (0x2)
"HidServ"=2 (0x2)
"gusvc"=3 (0x3)
"ERSvc"=3 (0x3)
"Alerter"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Microsoft Visual Studio\\Common\\TOOLS\\VS-Ent98\\Vanalyzr\\VARPC.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\cygwin\\usr\\X11R6\\bin\\XWin.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Documents and Settings\\Roshan\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Roshan\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\dlbtcoms.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\BsStor.sys [2005/03/28 6:02 10624]
R0 NaiFsRec;NaiFsRec;c:\windows\system32\drivers\NaiFsRec.sys [2005/05/20 11:41 4512]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008/08/19 11:33 335240]
R1 chgbmode;Panasonic Charge Mode Changer Driver;c:\program files\Panasonic\CHGBMODE\ChgBmode.sys [2005/03/28 4:19 12800]
R1 MiscOPD;Panasonic Opdoff Utility;c:\program files\Panasonic\OPDOFF\miscOPD.sys [2005/03/28 5:52 6144]
R1 WLANSW;Panasonic PC Wireless LAN Switch Driver;c:\program files\Panasonic\WLANSW\WLANSW.sys [2005/03/24 0:36 7680]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008/08/19 11:33 297752]
R2 brecal;Panasonic Battery Recalibration Driver;c:\program files\Panasonic\BRECAL\Brecal.sys [2005/03/24 0:26 7168]
R2 OPDOFFSV;Panasonic Opdoff Utility;c:\program files\Panasonic\OPDOFF\opdoffsv.exe [2005/03/28 5:52 147456]
R2 pcinfo;Panasonic PC Info. Viewer Driver;c:\program files\Panasonic\PCINFO\PCINFO.sys [2005/03/28 4:22 7168]
R2 SDKEY;Panasonic SD Misc. Function Driver;c:\program files\Panasonic\SDKEY\SDKEY.sys [2005/03/24 0:35 9216]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2005/03/23 23:01 32640]
S2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" --> c:\program files\Windows Defender\MsMpEng.exe [?]
S3 CP;CP;c:\docume~1\Roshan\LOCALS~1\Temp\CP.exe --> c:\docume~1\Roshan\LOCALS~1\Temp\CP.exe [?]
S3 NaiFiltr;NaiFiltr;c:\windows\system32\drivers\NaiFiltr.sys [2005/07/24 0:28 24496]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009/06/17 8:20 12648]
S3 V0250Dev;Live! Cam Notebook Pro;c:\windows\system32\drivers\V0250Dev.sys [2007/01/15 17:01 185504]
S3 V0250Vfx;V0250Vfx;c:\windows\system32\drivers\V0250Vfx.sys [2007/01/15 17:01 6272]
S3 WFVJXE;WFVJXE;c:\docume~1\Roshan\LOCALS~1\Temp\WFVJXE.exe --> c:\docume~1\Roshan\LOCALS~1\Temp\WFVJXE.exe [?]
S3 XRIKNEJFAUD;XRIKNEJFAUD;c:\docume~1\Roshan\LOCALS~1\Temp\XRIKNEJFAUD.exe --> c:\docume~1\Roshan\LOCALS~1\Temp\XRIKNEJFAUD.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4195690698-3893256219-861067370-1006Core.job
- c:\documents and settings\Roshan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 19:32]
2009-09-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4195690698-3893256219-861067370-1006UA.job
- c:\documents and settings\Roshan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 19:32]
2009-08-30 c:\windows\Tasks\Updtdb32.job
- c:\rs\RARE_USE\Links\locate32-3.1.8.09210\Updtdb32.exe [2009-03-05 21:19]
2009-09-20 c:\windows\Tasks\User_Feed_Synchronization-{6383BE0E-A18B-44B6-BDC8-70A59B67055C}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Adobe PDF への変換
IE: E&xport to Microsoft Excel
IE: リンクの参照先を Adobe PDF に変換
IE: リンクの参照先を既存の PDF に変換
IE: 既存の PDF に変換
IE: 選択したリンクを Adobe PDF に変換
IE: 選択したリンクを既存の PDF に変換
IE: 選択項目を Adobe PDF に変換
IE: 選択項目を既存の PDF に変換
FF - ProfilePath - c:\documents and settings\Roshan\Application Data\Mozilla\Firefox\Profiles\2dnbq1sp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source=iglk
FF - plugin: c:\documents and settings\Roshan\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Roshan\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-20 22:42
Windows 5.1.2600 Service Pack 3, v.5755 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\LocalService\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-20\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-21-4195690698-3893256219-861067370-1006\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-21-4195690698-3893256219-861067370-1006\AppEvents\Schemes\Apps\Conf\*・^\.default]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*ウ0・ン0・ヘ0・ネ0\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*ウ0・ン0・ヘ0・ネ0\CurVer]
@="BDATuner.コンポーネント.1"
[HKEY_LOCAL_MACHINE\software\Classes\Folder\shell\P*a*i*n*t* *S*h*o*p* *P*r*o* *ヨ0・ヲ0カ0\command]
@="\"c:\\PROGRA~1\\PAINTS~1\\psp.exe\" \"%L\""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Explorer\Volum eCaches\「0・、0・ケ0ネ0・・n0ミ0テ0ッ0「0テ0ラ0 *、0・・ク0]
@="{67cf8cbd-e5c0-44f7-9de5-e1d599d626d8}"
"Description"="このバージョンの Windows をアンインストールして前のオペレーティング システムに戻る場合は、これらのファイルが必要です。"
"Display"="前のオペレーティング システムのバックアップ ファイル"
"IconPath"=expand:"%SystemRoot%\\system32\\osuninst.EXE,0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\LanchNtf.dll
- - - - - - - > 'explorer.exe'(3020)
c:\program files\DExposE2\DExposE2Animation.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\dlbtcoms.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\system32\searchindexer.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
c:\documents and settings\Roshan\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
.
**************************************************************************
.
Completion time: 2009-09-21 22:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-21 02:48
Pre-Run: 14,975,049,728 バイトの空き領域
Post-Run: 14,831,157,248 バイトの空き領域
369 --- E O F --- 2009-09-20 06:13