ComboFix:
ComboFix 09-11-08.02 - Leah 11/08/2009 16:38.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1406.807 [GMT -5:00]
Running from: c:\documents and settings\Leah\Desktop\ComboFix.exe
AV: Windows Enterprise Suite *On-access scanning enabled* (Updated) {62A1206B-1F31-4048-B0B3-2A93BF7D6C6E}
FW: Windows Enterprise Suite *enabled* {6D7078B9-2C1C-449F-B18F-4162C44F6435}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Leah\My Documents\ZbThumbnail.info
c:\program files\Mozilla Firefox\searchplugins\search.xml
c:\recycler\NPROTECT
.
((((((((((((((((((((((((( Files Created from 2009-10-08 to 2009-11-08 )))))))))))))))))))))))))))))))
.
2009-11-06 22:23 . 2009-11-07 20:54 -------- d-----w- c:\windows\ie8updates
2009-11-06 19:35 . 2009-08-29 08:08 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-11-06 19:35 . 2009-08-29 08:08 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-06 19:35 . 2009-08-29 08:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-11-06 19:35 . 2009-08-29 08:08 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-11-06 19:35 . 2009-08-29 08:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-06 19:35 . 2009-08-29 08:08 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-11-06 06:27 . 2009-11-06 06:27 -------- d-sh--w- c:\documents and settings\Leah\IECompatCache
2009-11-06 06:27 . 2009-11-06 06:27 5908024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-11-06 06:27 . 2009-11-06 06:27 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-06 06:27 . 2009-11-06 06:27 87496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-06 06:27 . 2009-11-06 06:27 933120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-11-06 06:27 . 2009-11-06 06:27 640608 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-06 06:26 . 2009-11-06 06:26 815760 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-11-06 06:26 . 2009-11-06 06:26 822904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-11-06 06:26 . 2009-11-06 06:26 1638104 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-11-06 06:26 . 2009-11-06 06:26 788368 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-11-06 06:26 . 2009-11-06 06:26 1179232 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-11-06 06:25 . 2009-11-06 06:25 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-06 06:25 . 2009-10-03 08:15 2924848 -c--a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-11-06 06:25 . 2009-11-06 06:25 -------- d-----w- c:\program files\Lavasoft
2009-11-06 05:09 . 2009-11-06 05:09 127872 ----a-w- c:\documents and settings\Leah\Application Data\Move Networks\uninstall.exe
2009-11-06 05:09 . 2009-11-06 05:12 -------- d-----w- c:\documents and settings\Leah\Application Data\Move Networks
2009-11-06 05:06 . 2009-11-06 05:06 -------- d-sh--w- c:\documents and settings\Leah\PrivacIE
2009-11-06 05:06 . 2009-11-06 05:06 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-11-06 05:02 . 2009-11-06 05:02 -------- d-sh--w- c:\documents and settings\Leah\IETldCache
2009-11-06 04:57 . 2009-11-06 04:58 -------- dc-h--w- c:\windows\ie8
2009-11-05 05:04 . 2009-11-05 05:04 -------- d--h--w- c:\windows\PIF
2009-11-05 03:39 . 2009-11-05 03:39 -------- d-----w- c:\documents and settings\Leah\Local Settings\Application Data\Sophos
2009-11-05 03:18 . 2009-11-08 21:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Sophos
2009-11-04 22:33 . 2009-11-04 22:34 -------- d-sh--w- c:\documents and settings\Leah\Application Data\Windows Enterprise Suite
2009-11-04 22:33 . 2009-11-04 22:33 -------- d-sh--w- c:\documents and settings\All Users\Application Data\WESSys
2009-11-04 22:33 . 2009-10-29 19:30 457720 ----a-w- c:\documents and settings\All Users\Application Data\7079b28\sqlite3.dll
2009-11-04 22:33 . 2009-10-29 19:30 722424 ----a-w- c:\documents and settings\All Users\Application Data\7079b28\mozcrt19.dll
2009-11-04 22:33 . 2009-11-05 23:11 -------- d-sh--w- c:\documents and settings\All Users\Application Data\7079b28
2009-10-31 23:52 . 2009-10-31 23:52 -------- d-----w- c:\program files\iPod
2009-10-31 23:52 . 2009-10-31 23:54 -------- d-----w- c:\program files\iTunes
2009-10-31 23:46 . 2009-10-31 23:46 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-21 05:34 . 2009-09-01 17:09 65536 ----a-w- c:\documents and settings\Leah\Application Data\Mozilla\Firefox\Profiles\ny74jk0f.default\extensions\{51ef49d2-624b-4194-8b97-1c468e9b0efe}\components\Engine.dll
2009-10-21 03:40 . 2009-10-21 03:40 152576 ----a-w- c:\documents and settings\Leah\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-20 03:36 . 2009-10-20 03:36 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-08 21:24 . 2009-08-18 23:42 -------- d-----w- c:\documents and settings\Leah\Application Data\uTorrent
2009-11-06 22:40 . 2009-08-19 01:59 1 ----a-w- c:\documents and settings\Leah\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-06 06:25 . 2009-08-19 01:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-06 05:09 . 2009-06-16 06:35 4183416 ----a-w- c:\documents and settings\Leah\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-11-05 03:52 . 2009-08-18 09:49 75400 ----a-w- c:\documents and settings\Leah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-05 02:17 . 2009-08-19 03:10 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-11-05 02:17 . 2009-08-19 03:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-11-02 22:41 . 2009-08-21 02:13 -------- d-----w- c:\documents and settings\Leah\Application Data\LimeWire
2009-10-31 23:52 . 2009-08-18 18:09 -------- d-----w- c:\program files\Common Files\Apple
2009-10-30 02:29 . 2009-08-19 03:43 -------- d-----w- c:\documents and settings\Leah\Application Data\Symantec
2009-10-28 04:45 . 2009-08-18 20:35 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-22 02:27 . 2006-07-17 21:23 -------- d-----w- c:\program files\Google
2009-10-21 05:12 . 2009-08-18 23:55 -------- d-----w- c:\program files\LimeWire
2009-10-21 03:41 . 2006-07-17 21:53 -------- d-----w- c:\program files\Java
2009-10-20 02:19 . 2009-08-24 17:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-20 02:12 . 2006-07-17 22:14 -------- d-----w- c:\program files\Microsoft Works
2009-10-13 19:35 . 2009-08-28 10:24 -------- d-----w- c:\documents and settings\Leah\Application Data\vlc
2009-10-13 19:33 . 2009-08-28 10:03 -------- d-----w- c:\documents and settings\Leah\Application Data\dvdcss
2009-10-11 00:20 . 2009-08-19 01:44 -------- d-----w- c:\program files\VLC Media Player
2009-10-05 15:41 . 2009-10-05 15:41 -------- d-----w- c:\program files\Common Files\SupportSoft
2009-09-23 19:25 . 2009-09-22 08:17 -------- d-----w- c:\program files\Windows Desktop Search
2009-09-23 12:55 . 2009-11-06 06:28 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-22 09:03 . 2009-08-18 23:58 -------- d-----w- c:\documents and settings\Leah\Application Data\Temp
2009-09-22 09:01 . 2009-09-22 09:01 -------- d-----w- c:\documents and settings\Leah\Application Data\Windows Search
2009-09-22 08:32 . 2009-09-22 08:30 -------- d-----w- c:\program files\Microsoft
2009-09-22 08:31 . 2009-09-22 08:29 -------- d-----w- c:\program files\Windows Live
2009-09-22 08:31 . 2009-09-22 08:31 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-22 08:30 . 2009-09-22 08:30 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-22 08:29 . 2009-09-22 08:29 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-22 08:18 . 2009-09-22 08:18 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-22 08:18 . 2009-09-22 08:18 -------- d-----w- c:\documents and settings\Leah\Application Data\Windows Desktop Search
2009-09-22 08:00 . 2006-07-17 22:22 -------- d-----w- c:\program files\Common Files\Real
2009-09-22 08:00 . 2009-09-22 08:00 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-11 14:18 . 2006-07-17 18:24 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 10:30 . 2009-09-11 10:30 61568 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-11 10:29 . 2009-08-18 18:10 -------- d-----w- c:\documents and settings\Leah\Application Data\Apple Computer
2009-09-11 10:17 . 2009-09-11 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-11 10:15 . 2009-09-11 10:14 -------- d-----w- c:\program files\QuickTime
2009-09-11 10:09 . 2009-09-11 10:08 -------- d-----w- c:\program files\iPhone Configuration Utility
2009-09-04 21:03 . 2006-07-17 18:24 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-31 08:53 . 2009-08-31 08:48 38208 ----a-w- c:\documents and settings\LocalService\Application Data\Macromedia\Flash Player\
http://www.macromedia.com\bin\airapp...pinstaller.exe
2009-08-29 08:08 . 2006-07-17 18:24 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-28 23:42 . 2009-08-18 18:09 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-28 23:42 . 2009-08-18 18:09 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-26 08:00 . 2006-07-17 18:25 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-20 08:15 . 2009-08-20 08:15 135630545 ----a-w- c:\program files\openofficeorg1.cab
2009-08-20 08:13 . 2009-08-20 08:13 9815040 ----a-w- c:\program files\openofficeorg31.msi
2009-08-19 02:31 . 2006-07-17 18:53 77607 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-08-19 02:00 . 2009-08-19 02:00 686080 ----a-w- c:\documents and settings\Leah\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\3B.tmp_\sun-pdfimport(2).oxt\pdfimport.uno.dll
2009-08-19 02:00 . 2009-08-19 02:00 568832 ----a-w- c:\documents and settings\Leah\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\3B.tmp_\sun-pdfimport(2).oxt\msvcp90.dll
2009-08-19 02:00 . 2009-08-19 02:00 655872 ----a-w- c:\documents and settings\Leah\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\3B.tmp_\sun-pdfimport(2).oxt\msvcr90.dll
2009-08-19 02:00 . 2009-08-19 02:00 583168 ----a-w- c:\documents and settings\Leah\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\3B.tmp_\sun-pdfimport(2).oxt\xpdfimport.exe
2009-08-19 02:00 . 2009-08-19 02:00 224768 ----a-w- c:\documents and settings\Leah\Application Data\OpenOffice.org\3\user\uno_packages\cache\uno_packages\3B.tmp_\sun-pdfimport(2).oxt\msvcm90.dll
2009-08-19 01:30 . 2009-08-19 01:30 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-08-18 20:32 . 2009-08-18 20:32 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-08-18 17:56 . 2003-03-19 05:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-08-18 17:48 . 2009-08-18 17:48 152576 ----a-w- c:\documents and settings\Leah\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-18 09:50 . 2009-08-18 09:49 127 ----a-w- c:\documents and settings\Leah\Local Settings\Application Data\fusioncache.dat
2009-08-18 09:47 . 2009-08-18 09:47 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-08-18 03:33 . 2009-08-18 03:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-13 19:40 . 2009-08-31 16:32 43008 ----a-w- c:\documents and settings\Leah\Application Data\Mozilla\Firefox\Profiles\ny74jk0f.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-08-13 19:39 . 2009-08-31 16:32 340480 ----a-w- c:\documents and settings\Leah\Application Data\Mozilla\Firefox\Profiles\ny74jk0f.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-08-13 19:39 . 2009-08-31 16:32 346112 ----a-w- c:\documents and settings\Leah\Application Data\Mozilla\Firefox\Profiles\ny74jk0f.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2002-03-11 09:06 . 2002-03-11 09:06 1822520 ----a-w- c:\program files\instmsiw.exe
2002-03-11 08:45 . 2002-03-11 08:45 1708856 ----a-w- c:\program files\instmsia.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
2008-07-25 15:16 282112 ----a-w- c:\windows\system32\mscoree.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
c:\documents and settings\Leah\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\3.1.5.7613\Launcher.exe [2009-8-18 157000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Ad-Aware.lnk - c:\program files\Lavasoft\Ad-Aware\Ad-Aware.exe [2009-10-2 1638104]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\Shell ExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavaso ft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoUpdate Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
backup=c:\windows\pss\AutoUpdate Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk
backup=c:\windows\pss\RAMASST.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Leah^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\Leah\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [11/6/2009 1:28 AM 64288]
R2 AGCoreService;AG Core Services;c:\program files\AGI\core\3.1\AGCoreService.exe [8/18/2009 6:58 PM 20480]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 6:17 AM 1179232]
R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [6/28/2006 1:50 PM 98816]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [3/30/2009 3:28 PM 1533808]
S3 SVRPEDRV;SVRPEDRV;\??\c:\sysprep\PEDrv.sys --> c:\sysprep\PEDrv.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder
2009-11-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 06:26]
2009-10-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = about
:blank
uInternet Connection Wizard,ShellNext = hxxp://www.toshibadirect.com/dpdstart
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Leah\Application Data\Mozilla\Firefox\Profiles\ny74jk0f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - prefs.js: keyword.URL - hxxps://www.mypoints.com/emp/u/mysearch.vm?st=mypWeb&fctb.dns=1&q=
FF - component: c:\documents and settings\Leah\Application Data\Mozilla\Firefox\Profiles\ny74jk0f.default\extensions\{51ef49d2-624b-4194-8b97-1c468e9b0efe}\components\Engine.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrec ordext.dll
FF - plugin: c:\documents and settings\Leah\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\VLC Media Player\npvlc.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-08 16:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys atapi.sys spkg.sys hal.dll >>UNKNOWN [0x8A40A938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
atapi.sys @ 0x0 0x0 bytes
\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF7978B40 atapi.sys
\Driver\atapi IRP hooks detected !
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(604)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-11-08 16:45
ComboFix-quarantined-files.txt 2009-11-08 21:44
Pre-Run: 5,288,280,064 bytes free
Post-Run: 5,258,637,312 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 780643281680AFF798CF4ABD0F9A9505