ComboFix 11-11-18.02 - Cameron Self 11/18/2011 22:56:22.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1528 [GMT -5:00]
Running from: c:\documents and settings\Cameron Self\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Cameron Self\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.
ADS - WINDOWS: deleted 0 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Crack.dll
c:\documents and settings\All Users\Application Data\Tarma Installer
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TorrentEasy\extensions.exe
c:\documents and settings\All Users\Application Data\TorrentEasy\fdmbtsupp.dll
c:\documents and settings\Cameron Self\Application Data\Mozilla\Firefox\Profiles\s7knhbie.default\searchplugins\bing-zugo.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Cameron Self\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Cameron Self\Local Settings\Application Data\0abbde10
c:\documents and settings\Cameron Self\Local Settings\Application Data\0abbde10\@
c:\documents and settings\Cameron Self\Local Settings\Application Data\0abbde10\X
c:\documents and settings\Cameron Self\WINDOWS
C:\Install.exe
c:\program files\Internet Explorer\SET729.tmp
c:\program files\Internet Explorer\SET72E.tmp
C:\Thumbs.db
c:\windows\$NtUninstallKB11092$\1978166194
c:\windows\CSC\d6
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Driver Cache\i386\Temp\program.exe
c:\windows\system32\
c:\windows\system32\c_92464.nl_
c:\windows\system32\c_92464.nls
c:\windows\system32\winio.vxd
C:\z.tmp
c:\windows\$NtUninstallKB11092$ . . . . Failed to delete
.
Infected copy of c:\windows\system32\drivers\afd.sys was found and disinfected
Restored copy from - The cat found it
Infected copy of c:\windows\system32\drivers\imapi.sys was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\imapi.sys
.
Infected copy of c:\windows\system32\drivers\ipsec.sys was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\ipsec.sys
.
Infected copy of c:\windows\system32\drivers\redbook.sys was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\redbook.sys
.
Infected copy of c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP149\A0042246.exe
.
Infected copy of c:\program files\Application Updater\ApplicationUpdater.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP149\A0042247.exe
.
Infected copy of c:\windows\system32\Ati2evxx.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP149\A0042245.exe
.
Infected copy of c:\program files\Google\Update\GoogleUpdate.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP155\A0046590.exe
.
Infected copy of c:\program files\iPod\bin\iPodService.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP148\A0041952.sys
.
Infected copy of c:\program files\Java\jre6\bin\jqs.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP149\A0042248.exe
.
Infected copy of c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP149\A0042249.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_.afd
-------\Service_.ipsec
-------\Service_.redbook
-------\Service_abbde10
.
.
((((((((((((((((((((((((( Files Created from 2011-10-19 to 2011-11-19 )))))))))))))))))))))))))))))))
.
.
2011-11-19 03:48 . 2008-08-14 10:34 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-11-19 03:48 . 2008-08-14 10:34 138496 ----a-w- c:\windows\system32\dllcache\afd.sys
2011-11-18 22:19 . 2011-11-18 22:20 -------- d-----w- c:\windows\CD6E97C6310B487A945E18965FF0E20E.TMP
2011-11-15 21:26 . 2011-11-16 00:05 361600 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-15 21:26 . 2008-06-20 11:59 361600 ----a-w- C:\tcpip.sys
2011-11-15 02:10 . 2011-11-15 02:10 -------- d-----w- C:\NVIDIA
2011-11-15 01:36 . 2008-04-13 18:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-11-15 01:36 . 2008-04-13 18:40 62976 ----a-w- c:\windows\system32\dllcache\cdrom.sys
2011-11-14 21:43 . 2011-11-14 21:43 -------- d-----w- C:\found.002
2011-11-13 00:41 . 2011-11-13 00:41 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\BitTorrentBar
2011-11-11 04:48 . 2011-11-11 04:48 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2011-11-10 02:01 . 2011-11-11 23:24 -------- d-----w- c:\program files\STOPzilla!
2011-11-10 02:01 . 2011-11-10 02:01 -------- d-----w- c:\program files\Common Files\iS3
2011-11-10 02:01 . 2011-11-11 23:24 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2011-11-10 00:17 . 2009-03-09 20:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2011-11-09 22:09 . 2011-11-09 22:09 -------- d-----w- c:\program files\BitTorrentBar
2011-11-09 22:08 . 2011-11-19 04:31 -------- d-----w- c:\documents and settings\Cameron Self\Application Data\BitTorrent
2011-11-09 22:08 . 2011-11-09 22:08 -------- d-----w- c:\documents and settings\Cameron Self\Local Settings\Application Data\BitTorrent
2011-11-09 21:33 . 2011-11-09 21:33 -------- d--h--r- c:\documents and settings\Cameron Self\Application Data\SecuROM
2011-11-09 21:21 . 2011-11-09 21:21 -------- d-----w- c:\program files\Roni Music
2011-11-09 02:02 . 2011-11-09 20:53 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2011-11-07 21:56 . 2011-11-07 21:56 -------- d-----w- c:\documents and settings\All Users\Uniblue
2011-11-07 16:02 . 2011-11-07 16:02 -------- d-----w- c:\program files\Conduit
2011-11-02 22:21 . 2011-11-02 22:21 -------- d-----w- c:\documents and settings\Cameron Self\Application Data\pymclevel
2011-11-02 22:20 . 2011-11-02 22:20 -------- d-----w- c:\documents and settings\Cameron Self\Local Settings\Application Data\MCEdit
2011-10-31 21:06 . 2011-10-31 21:06 -------- d-----w- c:\documents and settings\Cameron Self\Application Data\Blender Foundation
2011-10-30 19:16 . 2011-10-30 19:16 -------- d-----w- c:\program files\Blender Foundation
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-09 02:07 . 2008-12-12 01:46 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-08-31 21:00 . 2011-01-28 22:57 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-31 03:05 . 2011-08-31 03:05 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-08-31 03:05 . 2011-08-31 03:05 73064 ----a-w- c:\windows\system32\dnssd.dll
2007-11-15 20:05 . 2007-12-07 21:54 89088 ----a-w- c:\program files\mozilla firefox\plugins\atl71.dll
2007-11-15 20:05 . 2007-12-07 21:54 53248 ----a-w- c:\program files\mozilla firefox\plugins\boost_filesystem-vc71-mt-1_33_1.dll
2007-11-15 20:05 . 2007-12-07 21:54 499712 ----a-w- c:\program files\mozilla firefox\plugins\msvcp71.dll
2007-11-15 20:05 . 2007-12-07 21:54 348160 ----a-w- c:\program files\mozilla firefox\plugins\msvcr71.dll
2007-11-15 20:05 . 2007-12-07 21:54 110592 ----a-w- c:\program files\mozilla firefox\plugins\v22_base.dll
2007-11-15 20:05 . 2007-12-07 21:54 114688 ----a-w- c:\program files\mozilla firefox\plugins\v22_compression.dll
2007-11-15 20:05 . 2007-12-07 21:54 106496 ----a-w- c:\program files\mozilla firefox\plugins\v22_connect.dll
2007-11-15 20:05 . 2007-12-07 21:54 229376 ----a-w- c:\program files\mozilla firefox\plugins\v22_update.dll
2007-11-15 20:05 . 2007-12-07 21:54 196608 ----a-w- c:\program files\mozilla firefox\plugins\v22_utility.dll
2007-11-15 20:05 . 2007-12-07 21:54 159744 ----a-w- c:\program files\mozilla firefox\plugins\v22_winapplib.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{c2db4fe6-8409-45ce-8010-189a7b5cce86}"= "c:\program files\NCH\prxtbNC2.dll" [2011-01-17 175912]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\prxtbBitT.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{c2db4fe6-8409-45ce-8010-189a7b5cce86}]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3AA8347C-4AA5-4DC2-8350-2F556BABF0AA}]
2005-08-08 00:03 444928 ----a-w- c:\progra~1\SMARTM~1\IEHelper.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
2011-05-09 09:49 176936 ----a-w- c:\program files\Softonic-Eng7\prxtbSof2.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2011-05-09 09:49 176936 ----a-w- c:\program files\BitTorrentBar\prxtbBitT.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bb6d9528-45f5-4c75-91c9-93290710ec4c}]
2011-05-09 09:49 176936 ----a-w- c:\program files\Device_Doctor\prxtbDev2.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2db4fe6-8409-45ce-8010-189a7b5cce86}]
2011-01-17 14:54 175912 ----a-w- c:\program files\NCH\prxtbNC2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}"= "c:\program files\Softonic-Eng7\prxtbSof2.dll" [2011-05-09 176936]
"{bb6d9528-45f5-4c75-91c9-93290710ec4c}"= "c:\program files\Device_Doctor\prxtbDev2.dll" [2011-05-09 176936]
"{c2db4fe6-8409-45ce-8010-189a7b5cce86}"= "c:\program files\NCH\prxtbNC2.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\prxtbBitT.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}]
.
[HKEY_CLASSES_ROOT\clsid\{bb6d9528-45f5-4c75-91c9-93290710ec4c}]
.
[HKEY_CLASSES_ROOT\clsid\{c2db4fe6-8409-45ce-8010-189a7b5cce86}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-07-29 17361032]
"BitTorrent"="c:\program files\BitTorrent\BitTorrent.exe" [2011-11-09 5960560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-23 402432]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe" [2011-09-28 894304]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-04-06 98304]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\Cameron Self\Start Menu\Programs\Startup\
RollerCoaster Tycoon 3 Registration.lnk - c:\documents and settings\Cameron Self\Local Settings\Temp\{C11A4A17-F4CE-4CCB-80A3-0256CA2E3C38}\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\ATR1.exe [N/A]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Nikon Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Nikon Monitor.lnk
backup=c:\windows\pss\Nikon Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Cameron Self^Start Menu^Programs^Startup^RollerCoaster Tycoon 3 Registration.lnk]
path=c:\documents and settings\Cameron Self\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk
backup=c:\windows\pss\RollerCoaster Tycoon 3 Registration.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 06:12 483328 ----a-w- c:\program files\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Version Cue CS2]
2005-04-04 22:58 856064 ----a-w- c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
2005-11-30 15:35 49152 ----a-w- c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2011-04-20 16:48 58656 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
2010-05-04 21:05 311296 ----a-r- c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link RangeBooster G WDA-2320]
2005-12-15 17:21 2490368 ----a-w- c:\program files\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
2007-09-06 13:08 136136 ----a-w- c:\program files\DAEMON Tools Pro\DTProAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2006-08-29 02:57 395776 ----a-w- c:\program files\Dell Support\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
2005-09-08 10:20 122940 ------w- c:\windows\system32\DLA\DLACTRLW.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-05 08:12 94208 ----a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-06-02 11:54 136176 ----atw- c:\documents and settings\Cameron Self\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 20:50 54576 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2008-08-20 14:54 150016 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2006-07-06 12:15 151552 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 21:50 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 21:50 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 22:06 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 21:00 449608 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 22:36 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
2002-02-05 03:32 53248 ------w- c:\program files\REGSHAVE\REGSHAVE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-07-24 22:20 282624 ----a-w- c:\windows\stsystra.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2011-04-06 01:44 98304 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 16:59 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-05-26 22:18 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-02-25 12:11 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WMP54Gv4SVC"=2 (0x2)
"wlidsvc"=2 (0x2)
"WinVNC4"=2 (0x2)
"Viewpoint Manager Service"=2 (0x2)
"PnkBstrA"=2 (0x2)
"ose"=3 (0x3)
"NMSAccess"=2 (0x2)
"MDM"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"IAANTMON"=2 (0x2)
"gusvc"=3 (0x3)
"gupdate"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"CLPSLS"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"astcc"=2 (0x2)
"ANIWZCSdService"=2 (0x2)
"Adobe Version Cue CS2"=2 (0x2)
"Adobe LM Service"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\{2D250E57-9890-44a6-B08F-5C02C991EF24}\\setup\\hpznui01.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58819:TCP"= 58819:TCP

ando Media Booster
"58819:UDP"= 58819:UDP

ando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/26/2010 5:17 PM 697328]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [11/18/2011 11:21 PM 745880]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/28/2011 5:57 PM 366152]
R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [4/19/2011 3:57 PM 17984]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [1/14/2008 5:06 AM 21632]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [1/28/2011 5:57 PM 22216]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys --> c:\windows\system32\drivers\is3srv.sys [?]
S0 rrtxho;rrtxho;c:\windows\system32\drivers\ekyfhxh.sys --> c:\windows\system32\drivers\ekyfhxh.sys [?]
S0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys --> c:\windows\system32\DRIVERS\szkg.sys [?]
S0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys --> c:\windows\system32\drivers\szkgfs.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.SYS --> c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [?]
S2 Akamai;Akamai;c:\windows\System32\svchost.exe -k Akamai [8/11/2004 5:00 PM 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [8/25/2005 3:00 PM 466880]
S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [4/9/2011 8:21 PM 29184]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe /medsvc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S3 PortTalk;PortTalk;c:\windows\system32\Drivers\PortTalk.sys --> c:\windows\system32\Drivers\PortTalk.sys [?]
S3 SaiH0461;SaiH0461;c:\windows\system32\drivers\SaiH0461.sys [5/31/2007 6:50 PM 182528]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]
S3 TiglUsb;TiglUsb.sys TI-GRAPH / DIRECT LINK USB driver;c:\windows\system32\Drivers\TiglUsb.sys --> c:\windows\system32\Drivers\TiglUsb.sys [?]
S3 USBTINSP;TI-Nspire(TM) Handheld Device Driver;c:\windows\system32\drivers\tinspusb.sys [9/10/2009 3:50 PM 123392]
S3 VSPerfDrv100;Performance Tools Driver 10.0;c:\program files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys [12/8/2009 8:24 PM 48128]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe --> c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [?]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/22/2009 10:08 PM 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [3/30/2009 2:09 AM 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [3/30/2009 2:23 AM 366936]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/7/2008 3:27 PM 24652]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-16 c:\windows\Tasks\AdobeAAMUpdater-1.0-FAMILY-Cameron Self.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-05-11 07:44]
.
2011-11-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 21:57]
.
2011-11-13 c:\windows\Tasks\File Helper.job
- c:\program files\File Helper\1.1.0.4\FileHelper.exe [2009-10-20 17:49]
.
2011-11-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3876382765-934903326-3795222865-1013Core.job
- c:\documents and settings\Cameron Self\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-30 11:54]
.
2011-11-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3876382765-934903326-3795222865-1013UA.job
- c:\documents and settings\Cameron Self\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-30 11:54]
.
2011-11-19 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3876382765-934903326-3795222865-1013.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-09 23:38]
.
2011-11-16 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3876382765-934903326-3795222865-1013.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-09 23:38]
.
2010-09-20 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Swift Sound\Switch\switch.exe [2010-05-26 23:44]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.babylon.com/home?AF=17708
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &Download All using 4shared Desktop - c:\program files\4shared Desktop\down_all.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
FF - ProfilePath - c:\documents and settings\Cameron Self\Application Data\Mozilla\Firefox\Profiles\s7knhbie.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=382950&p=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Click to call with Skype: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: Ghostery:
[email protected] - %profile%\extensions\
[email protected]
FF - Ext: Search Toolbar:
[email protected] - %profile%\extensions\
[email protected]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
FF - Ext: Yontoo Layers:
[email protected] - %profile%\extensions\
[email protected]
FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - %profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Java Quick Starter:
[email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - user.js: extentions.y2layers.installId - 2747202e-126d-470c-938b-ede13a3f7e06
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - (no file)
BHO-{0b876028-b388-4f6d-922f-f52faec8535f} - (no file)
Toolbar-{09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - (no file)
Toolbar-{0b876028-b388-4f6d-922f-f52faec8535f} - (no file)
HKCU-Run-Window Hide Tool - c:\program files\Window Hide Tool\Window Hide Tool.exe
HKCU-Run-RGSC - c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
HKLM-Run-BabylonToolbar - c:\program files\BabylonToolbar\BabylonToolbar\1.4.19.5\BabylonToolbarsrv.exe
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
Notify-!SASWinLogon - c:\program files\SUPERAntiSpyware\SASWINLO.DLL
Notify-TPSvc - TPSvc.dll
SafeBoot-klmdb.sys
MSConfigStartUp-COMODO Internet Security - c:\program files\COMODO\COMODO Internet Security\cfp.exe
MSConfigStartUp-cwcptray - c:\program files\ContentWatch\Internet Protection\cwtray.exe
MSConfigStartUp-NVIDIA driver monitor - c:\windows\nvsvc32.exe
MSConfigStartUp-Steam - c:\program files\Steam\Steam.exe
MSConfigStartUp-tvncontrol - c:\program files\TightVNC\tvnserver.exe
MSConfigStartUp-VirtualCloneDrive - c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
AddRemove-Dtab_is1 - c:\program files\Dtab\unins000.exe
AddRemove-thriXXX WebLaunch - c:\program files\thriXXX\WebLaunch\WebLaunchUninstall.exe
AddRemove-{10B75CF6-5A54-4D7B-9169-70AD17181DE1}_is1 - c:\program files\Oxin's Style!\3D Sexvilla 2\Binaries\unins000.exe
AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\docume~1\ALLUSE~1\APPLIC~1\TARMAI~1\{889DF~1\Setup.exe
AddRemove-FolderLock6 - c:\program files\Folder Lock\Uninstall.exe
AddRemove-s3pe - c:\program files\s3pe\uninst-s3pe.exe
AddRemove-UnityWebPlayer - c:\documents and settings\Cameron Self\Local Settings\Application Data\Unity\WebPlayer\Uninstall.exe
AddRemove-{C0A47779-CB82-41C2-B4A0-F3D2685BDEF6} - c:\documents and settings\Cameron Self\Local Settings\Application Data\{3378F47C-DCD7-4800-B225-9D4C45395A8D}\FireDaemon-Pro-x86-3.0.2437.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-18 23:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\windows\system32\drivers\mbamswissarmy.sys
c:\windows\system32\WinFLdrv.sys 17984 bytes executable
c:\windows\system32\sys_drv.dat 7028 bytes
c:\windows\system32\sys_drv_2.dat 6024 bytes
.
scan completed successfully
hidden files: 4
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\.imapi]
"ImagePath"="\*"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3876382765-934903326-3795222865-1013\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{136F2399-5356-1157-7118-C885526CE18E}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-3876382765-934903326-3795222865-1013\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2519885F-CC9F-A193-3FD0-5E3CC0D0840A}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaggiidcenaebdhibd"=hex:6a,61,6a,6c,6f,6e,6f,6e,69,68,61,6c,68,63,66,66,67,63,
63,6d,00,00
"hamhgjfknkbnldgh"=hex:6a,61,6a,6c,6f,6e,6f,6e,69,68,61,6c,68,63,66,66,67,63,
63,6d,00,1d
.
[HKEY_USERS\S-1-5-21-3876382765-934903326-3795222865-1013\Software\SecuROM\License information*]
"datasecu"=hex:d2,4b,16,ec,d0,de,bf,ab,66,06,8d,c5,31,67,72,a0,41,35,8e,4d,41,
e0,01,38,d6,20,84,45,3b,ea,2b,34,58,88,6e,29,24,6e,70,dc,9a,b4,86,74,c2,d2,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(524)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(2724)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\program files\NCH\prxtbNC2.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2011-11-18 23:42:18 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-19 04:41
.
Pre-Run: 34,123,575,296 bytes free
Post-Run: 45,883,654,144 bytes free
.
- - End Of File - - BD9F007BC98414DF97C2D520F640FD81