| | |
Re: Windows Police Pro, can't run mba..
![]() |
OK, good.
When that's done, post the log for me and then see if you are able to run combofix as per the linky below:
http://www.bleepingcomputer.com/comb...o-use-combofix
If it runs, post me that log too. If not, we'll have to try it a bit differently.
PP
When that's done, post the log for me and then see if you are able to run combofix as per the linky below:
http://www.bleepingcomputer.com/comb...o-use-combofix
If it runs, post me that log too. If not, we'll have to try it a bit differently.
PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer
ASAP
~ J. Robert Oppenheimer
ASAP
•
•
Join Date: Sep 2009
Posts: 8
Reputation:
Solved Threads: 0
Just got out of work, here is the log for the MBAM *full* scan:
Malwarebytes' Anti-Malware 1.40
Database version: 2727
Windows 5.1.2600 Service Pack 3
9/1/2009 10:26:17 PM
mbam-log-2009-09-01 (22-26-17).txt
Scan type: Full Scan (C:\|)
Objects scanned: 184734
Time elapsed: 40 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\Y2BIXXEZ\c73a719[1].flv (Rootkit.TDSS) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.40
Database version: 2727
Windows 5.1.2600 Service Pack 3
9/1/2009 10:26:17 PM
mbam-log-2009-09-01 (22-26-17).txt
Scan type: Full Scan (C:\|)
Objects scanned: 184734
Time elapsed: 40 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\Y2BIXXEZ\c73a719[1].flv (Rootkit.TDSS) -> Quarantined and deleted successfully.
•
•
•
•
Just got out of work, here is the log for the MBAM *full* scan:

Let's do this now:
If you already have combofix on your machine, DELETE it.
Then follow the instructions in the link below to DL a fresh Combofix and run it:
http://www.bleepingcomputer.com/comb...o-use-combofix
What I want you to do, though, is this:
When you download it and it ask you to "Save File As," rename combofix to Bunnyfix.exe and then download it to your desktop as that and follow the instructions in the linky to run it and post the log.
I will check in tomorrow and have a look at the log and we'll go from there.
PP
Last edited by PhilliePhan; Sep 2nd, 2009 at 12:16 am.
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer
ASAP
~ J. Robert Oppenheimer
ASAP
•
•
Join Date: Sep 2009
Posts: 8
Reputation:
Solved Threads: 0
Ah, I didn't see your latest post until after I ran Combofix - but I never had it installed before so it was a "fresh" copy. It ran without problems (no need to rename) and here is the log:
ComboFix 09-09-01.04 - Owner 09/01/2009 22:47.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.466 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\INSTALL.LOG
c:\recycler\NPROTECT
c:\recycler\S-1-5-21-515967899-861567501-682003330-1005
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\Installer\156fd.msi
c:\windows\Palace.reg
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
c:\windows\system32\drivers\kbiwkmthxwbuth.sys
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\kbiwkmewbfalqp.dll
c:\windows\system32\kbiwkmqqmcnupk.dat
c:\windows\system32\kbiwkmsexeooby.dll
c:\windows\system32\kbiwkmtsppdrch.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_kbiwkmnrerxnmf
-------\Legacy_kbiwkmnrerxnmf
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.
2009-09-02 03:04 . 2009-09-02 03:04 -------- d-----w- c:\windows\LastGood
2009-09-01 04:59 . 2009-09-01 05:00 -------- d-----w- c:\program files\Windows Live Safety Center
2009-09-01 04:36 . 2009-09-01 04:05 -------- d-----w- C:\KILLBAD
2009-09-01 04:17 . 2009-09-01 04:17 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-09-01 04:17 . 2009-09-01 04:17 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-09-01 04:17 . 2009-09-01 04:17 -------- d-----w- c:\program files\Prevx
2009-09-01 04:17 . 2009-09-01 04:18 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-09-01 03:53 . 2008-06-19 21:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-09-01 03:52 . 2009-09-01 03:52 -------- d-----w- c:\program files\Panda Security
2009-09-01 02:49 . 2009-09-01 04:54 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-09-01 02:43 . 2009-09-01 02:43 -------- d-----w- c:\program files\STOPzilla!
2009-09-01 02:43 . 2009-09-01 20:06 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-09-01 02:43 . 2009-09-01 02:43 -------- d-----w- c:\program files\Common Files\iS3
2009-08-31 18:15 . 2009-08-31 18:15 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2009-08-31 17:42 . 2009-08-31 17:42 36168 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-31 17:39 . 2009-08-31 17:39 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-08-31 17:27 . 2009-08-31 17:27 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-08-30 23:29 . 2009-08-30 23:29 -------- d-----w- c:\program files\PopCap Games
2009-08-29 19:13 . 2009-08-29 19:13 -------- d-----w- c:\program files\DinerTown Detective Agency
2009-08-29 04:24 . 2009-08-29 04:24 -------- d-----w- c:\program files\Diner Dash Flo Through Time
2009-08-29 04:24 . 2009-08-29 04:24 -------- d-----w- c:\windows\Diner Dash Flo Through Time
2009-08-28 16:44 . 2005-10-19 12:59 163840 ----a-w- c:\windows\system32\igfxres.dll
2009-08-27 19:34 . 2009-08-27 19:34 -------- dc-h--w- c:\windows\ie8
2009-08-27 03:47 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-27 03:47 . 2009-09-01 20:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-27 03:47 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-27 03:36 . 2009-08-27 03:36 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-08-27 03:36 . 2009-08-27 03:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-26 02:29 . 2009-08-26 02:29 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-25 15:09 . 2009-08-25 15:09 -------- d-----w- c:\windows\Diner Dash Seasonal Snack Pack
2009-08-23 15:01 . 2009-08-23 15:01 -------- d-----w- c:\documents and settings\Owner\Application Data\TigerPlayer
2009-08-23 14:58 . 2009-08-23 14:59 -------- d-----w- c:\program files\MpcStar
2009-08-21 00:11 . 2009-08-21 00:11 -------- d-sh--w- c:\documents and settings\Owner\PrivacIE
2009-08-20 23:45 . 2009-08-20 23:45 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-20 23:45 . 2009-08-20 23:45 -------- d-sh--w- c:\documents and settings\Owner\IETldCache
2009-08-20 23:41 . 2009-08-27 18:46 -------- d-----w- c:\windows\ie8updates
2009-08-20 23:35 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-08-20 23:35 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-20 23:34 . 2009-07-01 07:08 101376 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-08-19 18:28 . 2009-08-19 18:28 -------- d-----w- c:\program files\Wedding Dash - Ready Aim Love
2009-08-19 18:28 . 2009-08-19 18:28 -------- d-----w- c:\windows\Wedding Dash - Ready Aim Love
2009-08-18 15:17 . 2009-08-18 15:17 -------- d-----w- c:\windows\Cooking Dash - DinerTown Studios
2009-08-18 15:17 . 2009-08-18 15:17 -------- d-----w- c:\program files\Cooking Dash - DinerTown Studios
2009-08-18 14:57 . 2009-08-18 14:57 1032192 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
2009-08-18 14:57 . 2009-08-31 15:15 -------- d-----w- c:\program files\BitComet
2009-08-18 14:52 . 2009-04-01 07:03 634880 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\cookingdash.exe
2009-08-18 14:52 . 2009-04-01 07:03 1425408 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\game\cookingdash.exe
2009-08-18 14:52 . 2009-02-09 22:28 57344 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\pfinstall.dll
2009-08-18 14:52 . 2002-07-26 21:02 153088 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\UNWISE.EXE
2009-08-17 02:31 . 2009-08-11 21:34 2203648 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\game\cookingdash2.exe
2009-08-17 02:31 . 2009-08-11 21:34 1376256 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\cookingdash2.exe
2009-08-17 02:31 . 2009-06-12 20:23 57344 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\pfinstall.dll
2009-08-17 02:31 . 2002-07-26 21:02 153088 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\UNWISE.EXE
2009-08-14 15:49 . 2009-08-14 16:02 -------- d-----w- c:\program files\support.com
2009-08-14 15:48 . 2009-08-14 15:48 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\SupportSoft
2009-08-14 15:48 . 2009-08-14 15:48 -------- d-----w- c:\program files\Common Files\SupportSoft
2009-08-13 12:46 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 03:19 . 2009-08-13 03:47 -------- d-----w- c:\documents and settings\Owner\Application Data\LimeWire
2009-08-06 04:41 . 2009-08-06 04:41 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-06 04:41 . 2009-08-06 04:41 -------- d-----w- c:\program files\MSBuild
2009-08-06 04:40 . 2009-08-06 04:40 -------- d-----w- c:\program files\Reference Assemblies
2009-08-06 04:40 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-06 04:40 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-06 04:40 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-06 04:40 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-06 04:40 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-06 04:40 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-06 04:40 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-06 04:40 . 2009-08-06 04:40 -------- d-----w- C:\8fdd0779ed77368804d5908c87c1629c
2009-08-06 04:40 . 2009-09-01 20:17 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-01 18:10 . 2007-03-06 18:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-01 05:24 . 2004-01-31 01:27 43 -c--a-w- c:\windows\popcinfo.dat
2009-09-01 02:28 . 2008-10-07 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-29 19:19 . 2007-03-13 14:14 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-08-29 19:19 . 2005-11-20 04:35 -------- d-----w- c:\documents and settings\Owner\Application Data\PlayFirst
2009-08-27 19:21 . 2005-10-09 04:37 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-08-26 13:06 . 2009-06-02 12:40 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 13:06 . 2009-06-02 12:40 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 13:06 . 2009-06-02 12:40 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-22 03:49 . 2007-03-13 14:33 -------- d-----w- c:\program files\PlayFirst
2009-08-21 00:11 . 2009-06-29 14:28 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-17 02:31 . 2009-03-24 17:40 466944 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\pfHarness\pfHarness.dll
2009-08-13 03:19 . 2005-08-20 07:21 -------- d-----w- c:\program files\LimeWire
2009-08-06 17:17 . 2008-10-07 20:50 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-06 11:54 . 2003-12-18 03:12 36168 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 17:45 . 2005-10-09 04:37 -------- d-----w- c:\program files\World of Warcraft
2009-08-05 09:01 . 2004-09-13 00:39 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-26 02:48 . 2009-06-02 12:58 -------- d-----w- c:\program files\Sony Online Entertainment
2009-07-24 17:24 . 2003-12-18 02:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 17:24 . 2009-07-24 17:24 -------- d-----w- c:\program files\Sony
2009-07-21 13:03 . 2009-07-21 04:35 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-07-21 04:35 . 2009-07-21 04:35 -------- d-----w- c:\program files\bfgclient
2009-07-20 20:09 . 2009-07-24 15:28 282624 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\NPDyyno@dyyno.com\Plugins\npDyyno.dll
2009-07-20 18:57 . 2009-07-20 18:57 17408 ----a-r- c:\windows\system32\SZIO5.dll
2009-07-20 18:56 . 2009-07-20 18:56 311296 ----a-r- c:\windows\system32\SZBase5.dll
2009-07-20 18:56 . 2009-07-20 18:56 540672 ----a-r- c:\windows\system32\SZComp5.dll
2009-07-17 22:51 . 2009-03-24 17:39 139264 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\PlayFirst.EXE
2009-07-17 19:01 . 2004-09-13 00:39 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 17:02 . 2009-07-15 17:01 -------- d-----w- c:\program files\WebEx
2009-07-15 17:01 . 2009-07-15 17:01 8892928 ----a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2009-07-14 17:40 . 2008-11-05 00:38 -------- d-----w- c:\program files\Hawking
2009-07-14 17:38 . 2008-11-05 00:39 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-14 17:38 . 2009-07-14 17:38 -------- d-----w- c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor
2009-07-14 03:43 . 2004-09-13 00:41 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 19:52 . 2009-07-09 19:52 126976 ----a-r- c:\windows\system32\IS3HTUI5.dll
2009-07-09 19:52 . 2009-07-09 19:52 393216 ----a-r- c:\windows\system32\IS3DBA5.dll
2009-07-09 19:51 . 2009-07-09 19:51 385024 ----a-r- c:\windows\system32\IS3UI5.dll
2009-07-09 19:51 . 2009-07-09 19:51 61440 ----a-r- c:\windows\system32\IS3Hks5.dll
2009-07-09 19:51 . 2009-07-09 19:51 23040 ----a-r- c:\windows\system32\IS3XDat5.dll
2009-07-09 19:50 . 2009-07-09 19:50 225280 ----a-r- c:\windows\system32\IS3Win325.dll
2009-07-09 19:50 . 2009-07-09 19:50 94208 ----a-r- c:\windows\system32\IS3Inet5.dll
2009-07-09 19:50 . 2009-07-09 19:50 90112 ----a-r- c:\windows\system32\IS3Svc5.dll
2009-07-09 19:47 . 2009-07-09 19:47 724992 ----a-r- c:\windows\system32\IS3Base5.dll
2009-07-03 17:09 . 2004-08-24 01:32 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-09-13 00:39 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-09-13 00:39 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-09-13 00:38 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-09-13 00:38 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-09-13 00:38 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-09-13 00:38 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-24 11:18 . 2004-09-13 00:38 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-09-13 00:38 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2001-08-18 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-14 20:07 . 2009-07-15 17:19 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-12 12:31 . 2004-09-13 00:38 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-09-13 00:39 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2004-09-13 00:39 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-09-13 00:38 132096 ----a-w- c:\windows\system32\wkssvc.dll
2005-11-24 01:46 . 2005-11-24 01:47 774144 ----a-w- c:\program files\RngInterstitial.dll
2006-11-14 16:31 . 2006-11-14 16:31 34384 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2006-11-14 16:31 . 2006-11-14 16:31 93848 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 13:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-12 98304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-26 2007832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GoBack.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\GoBack.lnk
backup=c:\windows\pss\GoBack.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNUpdate.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNUtil.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNTray.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNCfg.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.2.9901-to-3.1.3.9947-enUS-downloader.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"7476:TCP"= 7476:TCP:BitComet 7476 TCP
"7476:UDP"= 7476:UDP:BitComet 7476 UDP
"14749:TCP"= 14749:TCP:BitComet 14749 TCP
"14749:UDP"= 14749:UDP:BitComet 14749 UDP
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/31/2009 11:53 PM 28544]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [9/1/2009 12:17 AM 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [9/1/2009 12:17 AM 27656]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/2/2009 8:40 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/2/2009 8:40 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/29/2009 10:27 AM 297752]
R2 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/29/2009 10:27 AM 908056]
S2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [9/1/2009 12:17 AM 4368952]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S3 MN130;Microsoft(R) PCI Adapter MN-130;c:\windows\system32\drivers\MN130-51.sys [5/29/2002 2:25 PM 38400]
S3 UNDPX2K;UNDPX2K;\??\c:\windows\system32\drivers\UNDPX2K.SYS --> c:\windows\system32\drivers\UNDPX2K.SYS [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-31 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
WebBrowser-{9D69F5EE-E293-4834-8587-4B94296E84E6} - (no file)
ShellExecuteHooks-{6809e580-a3a7-11d1-9a00-00a0c945b006} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: { - c:\documents and settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} - hxxp://thesims.ea.com/teleport/superstar/MaxisSuperstarTeleX.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\NPDyyno@dyyno.com\plugins\npDyyno.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-01 23:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-515967899-861567501-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(688)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
- - - - - - - > 'explorer.exe'(3368)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\ati2evxx.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Roxio\GoBack\GBPoll.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
.
**************************************************************************
.
Completion time: 2009-09-02 23:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-02 03:10
Pre-Run: 68,243,374,080 bytes free
Post-Run: 68,216,741,888 bytes free
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=,1,2,3,4,5,6,7,8,9
375 --- E O F --- 2009-09-02 02:31
ComboFix 09-09-01.04 - Owner 09/01/2009 22:47.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.466 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\INSTALL.LOG
c:\recycler\NPROTECT
c:\recycler\S-1-5-21-515967899-861567501-682003330-1005
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\Installer\156fd.msi
c:\windows\Palace.reg
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
c:\windows\system32\drivers\kbiwkmthxwbuth.sys
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\kbiwkmewbfalqp.dll
c:\windows\system32\kbiwkmqqmcnupk.dat
c:\windows\system32\kbiwkmsexeooby.dll
c:\windows\system32\kbiwkmtsppdrch.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_kbiwkmnrerxnmf
-------\Legacy_kbiwkmnrerxnmf
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.
2009-09-02 03:04 . 2009-09-02 03:04 -------- d-----w- c:\windows\LastGood
2009-09-01 04:59 . 2009-09-01 05:00 -------- d-----w- c:\program files\Windows Live Safety Center
2009-09-01 04:36 . 2009-09-01 04:05 -------- d-----w- C:\KILLBAD
2009-09-01 04:17 . 2009-09-01 04:17 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-09-01 04:17 . 2009-09-01 04:17 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-09-01 04:17 . 2009-09-01 04:17 -------- d-----w- c:\program files\Prevx
2009-09-01 04:17 . 2009-09-01 04:18 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-09-01 03:53 . 2008-06-19 21:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-09-01 03:52 . 2009-09-01 03:52 -------- d-----w- c:\program files\Panda Security
2009-09-01 02:49 . 2009-09-01 04:54 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-09-01 02:43 . 2009-09-01 02:43 -------- d-----w- c:\program files\STOPzilla!
2009-09-01 02:43 . 2009-09-01 20:06 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-09-01 02:43 . 2009-09-01 02:43 -------- d-----w- c:\program files\Common Files\iS3
2009-08-31 18:15 . 2009-08-31 18:15 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2009-08-31 17:42 . 2009-08-31 17:42 36168 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-31 17:39 . 2009-08-31 17:39 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-08-31 17:27 . 2009-08-31 17:27 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-08-30 23:29 . 2009-08-30 23:29 -------- d-----w- c:\program files\PopCap Games
2009-08-29 19:13 . 2009-08-29 19:13 -------- d-----w- c:\program files\DinerTown Detective Agency
2009-08-29 04:24 . 2009-08-29 04:24 -------- d-----w- c:\program files\Diner Dash Flo Through Time
2009-08-29 04:24 . 2009-08-29 04:24 -------- d-----w- c:\windows\Diner Dash Flo Through Time
2009-08-28 16:44 . 2005-10-19 12:59 163840 ----a-w- c:\windows\system32\igfxres.dll
2009-08-27 19:34 . 2009-08-27 19:34 -------- dc-h--w- c:\windows\ie8
2009-08-27 03:47 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-27 03:47 . 2009-09-01 20:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-27 03:47 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-27 03:36 . 2009-08-27 03:36 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-08-27 03:36 . 2009-08-27 03:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-26 02:29 . 2009-08-26 02:29 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-25 15:09 . 2009-08-25 15:09 -------- d-----w- c:\windows\Diner Dash Seasonal Snack Pack
2009-08-23 15:01 . 2009-08-23 15:01 -------- d-----w- c:\documents and settings\Owner\Application Data\TigerPlayer
2009-08-23 14:58 . 2009-08-23 14:59 -------- d-----w- c:\program files\MpcStar
2009-08-21 00:11 . 2009-08-21 00:11 -------- d-sh--w- c:\documents and settings\Owner\PrivacIE
2009-08-20 23:45 . 2009-08-20 23:45 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-20 23:45 . 2009-08-20 23:45 -------- d-sh--w- c:\documents and settings\Owner\IETldCache
2009-08-20 23:41 . 2009-08-27 18:46 -------- d-----w- c:\windows\ie8updates
2009-08-20 23:35 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-08-20 23:35 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-20 23:34 . 2009-07-01 07:08 101376 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-08-19 18:28 . 2009-08-19 18:28 -------- d-----w- c:\program files\Wedding Dash - Ready Aim Love
2009-08-19 18:28 . 2009-08-19 18:28 -------- d-----w- c:\windows\Wedding Dash - Ready Aim Love
2009-08-18 15:17 . 2009-08-18 15:17 -------- d-----w- c:\windows\Cooking Dash - DinerTown Studios
2009-08-18 15:17 . 2009-08-18 15:17 -------- d-----w- c:\program files\Cooking Dash - DinerTown Studios
2009-08-18 14:57 . 2009-08-18 14:57 1032192 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
2009-08-18 14:57 . 2009-08-31 15:15 -------- d-----w- c:\program files\BitComet
2009-08-18 14:52 . 2009-04-01 07:03 634880 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\cookingdash.exe
2009-08-18 14:52 . 2009-04-01 07:03 1425408 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\game\cookingdash.exe
2009-08-18 14:52 . 2009-02-09 22:28 57344 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\pfinstall.dll
2009-08-18 14:52 . 2002-07-26 21:02 153088 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\UNWISE.EXE
2009-08-17 02:31 . 2009-08-11 21:34 2203648 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\game\cookingdash2.exe
2009-08-17 02:31 . 2009-08-11 21:34 1376256 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\cookingdash2.exe
2009-08-17 02:31 . 2009-06-12 20:23 57344 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\pfinstall.dll
2009-08-17 02:31 . 2002-07-26 21:02 153088 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\UNWISE.EXE
2009-08-14 15:49 . 2009-08-14 16:02 -------- d-----w- c:\program files\support.com
2009-08-14 15:48 . 2009-08-14 15:48 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\SupportSoft
2009-08-14 15:48 . 2009-08-14 15:48 -------- d-----w- c:\program files\Common Files\SupportSoft
2009-08-13 12:46 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 03:19 . 2009-08-13 03:47 -------- d-----w- c:\documents and settings\Owner\Application Data\LimeWire
2009-08-06 04:41 . 2009-08-06 04:41 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-06 04:41 . 2009-08-06 04:41 -------- d-----w- c:\program files\MSBuild
2009-08-06 04:40 . 2009-08-06 04:40 -------- d-----w- c:\program files\Reference Assemblies
2009-08-06 04:40 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-06 04:40 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-06 04:40 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-06 04:40 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-06 04:40 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-06 04:40 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-06 04:40 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-06 04:40 . 2009-08-06 04:40 -------- d-----w- C:\8fdd0779ed77368804d5908c87c1629c
2009-08-06 04:40 . 2009-09-01 20:17 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-01 18:10 . 2007-03-06 18:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-01 05:24 . 2004-01-31 01:27 43 -c--a-w- c:\windows\popcinfo.dat
2009-09-01 02:28 . 2008-10-07 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-29 19:19 . 2007-03-13 14:14 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-08-29 19:19 . 2005-11-20 04:35 -------- d-----w- c:\documents and settings\Owner\Application Data\PlayFirst
2009-08-27 19:21 . 2005-10-09 04:37 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-08-26 13:06 . 2009-06-02 12:40 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 13:06 . 2009-06-02 12:40 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 13:06 . 2009-06-02 12:40 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-22 03:49 . 2007-03-13 14:33 -------- d-----w- c:\program files\PlayFirst
2009-08-21 00:11 . 2009-06-29 14:28 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-17 02:31 . 2009-03-24 17:40 466944 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\pfHarness\pfHarness.dll
2009-08-13 03:19 . 2005-08-20 07:21 -------- d-----w- c:\program files\LimeWire
2009-08-06 17:17 . 2008-10-07 20:50 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-06 11:54 . 2003-12-18 03:12 36168 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 17:45 . 2005-10-09 04:37 -------- d-----w- c:\program files\World of Warcraft
2009-08-05 09:01 . 2004-09-13 00:39 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-26 02:48 . 2009-06-02 12:58 -------- d-----w- c:\program files\Sony Online Entertainment
2009-07-24 17:24 . 2003-12-18 02:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 17:24 . 2009-07-24 17:24 -------- d-----w- c:\program files\Sony
2009-07-21 13:03 . 2009-07-21 04:35 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-07-21 04:35 . 2009-07-21 04:35 -------- d-----w- c:\program files\bfgclient
2009-07-20 20:09 . 2009-07-24 15:28 282624 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\NPDyyno@dyyno.com\Plugins\npDyyno.dll
2009-07-20 18:57 . 2009-07-20 18:57 17408 ----a-r- c:\windows\system32\SZIO5.dll
2009-07-20 18:56 . 2009-07-20 18:56 311296 ----a-r- c:\windows\system32\SZBase5.dll
2009-07-20 18:56 . 2009-07-20 18:56 540672 ----a-r- c:\windows\system32\SZComp5.dll
2009-07-17 22:51 . 2009-03-24 17:39 139264 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\PlayFirst.EXE
2009-07-17 19:01 . 2004-09-13 00:39 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 17:02 . 2009-07-15 17:01 -------- d-----w- c:\program files\WebEx
2009-07-15 17:01 . 2009-07-15 17:01 8892928 ----a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2009-07-14 17:40 . 2008-11-05 00:38 -------- d-----w- c:\program files\Hawking
2009-07-14 17:38 . 2008-11-05 00:39 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-14 17:38 . 2009-07-14 17:38 -------- d-----w- c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor
2009-07-14 03:43 . 2004-09-13 00:41 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 19:52 . 2009-07-09 19:52 126976 ----a-r- c:\windows\system32\IS3HTUI5.dll
2009-07-09 19:52 . 2009-07-09 19:52 393216 ----a-r- c:\windows\system32\IS3DBA5.dll
2009-07-09 19:51 . 2009-07-09 19:51 385024 ----a-r- c:\windows\system32\IS3UI5.dll
2009-07-09 19:51 . 2009-07-09 19:51 61440 ----a-r- c:\windows\system32\IS3Hks5.dll
2009-07-09 19:51 . 2009-07-09 19:51 23040 ----a-r- c:\windows\system32\IS3XDat5.dll
2009-07-09 19:50 . 2009-07-09 19:50 225280 ----a-r- c:\windows\system32\IS3Win325.dll
2009-07-09 19:50 . 2009-07-09 19:50 94208 ----a-r- c:\windows\system32\IS3Inet5.dll
2009-07-09 19:50 . 2009-07-09 19:50 90112 ----a-r- c:\windows\system32\IS3Svc5.dll
2009-07-09 19:47 . 2009-07-09 19:47 724992 ----a-r- c:\windows\system32\IS3Base5.dll
2009-07-03 17:09 . 2004-08-24 01:32 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-09-13 00:39 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-09-13 00:39 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-09-13 00:38 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-09-13 00:38 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-09-13 00:38 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-09-13 00:38 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-24 11:18 . 2004-09-13 00:38 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-09-13 00:38 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2001-08-18 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-14 20:07 . 2009-07-15 17:19 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-12 12:31 . 2004-09-13 00:38 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-09-13 00:39 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2004-09-13 00:39 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-09-13 00:38 132096 ----a-w- c:\windows\system32\wkssvc.dll
2005-11-24 01:46 . 2005-11-24 01:47 774144 ----a-w- c:\program files\RngInterstitial.dll
2006-11-14 16:31 . 2006-11-14 16:31 34384 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2006-11-14 16:31 . 2006-11-14 16:31 93848 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 13:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-12 98304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-26 2007832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GoBack.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\GoBack.lnk
backup=c:\windows\pss\GoBack.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNUpdate.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNUtil.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNTray.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNCfg.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.2.9901-to-3.1.3.9947-enUS-downloader.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"7476:TCP"= 7476:TCP:BitComet 7476 TCP
"7476:UDP"= 7476:UDP:BitComet 7476 UDP
"14749:TCP"= 14749:TCP:BitComet 14749 TCP
"14749:UDP"= 14749:UDP:BitComet 14749 UDP
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/31/2009 11:53 PM 28544]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [9/1/2009 12:17 AM 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [9/1/2009 12:17 AM 27656]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/2/2009 8:40 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/2/2009 8:40 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/29/2009 10:27 AM 297752]
R2 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/29/2009 10:27 AM 908056]
S2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [9/1/2009 12:17 AM 4368952]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S3 MN130;Microsoft(R) PCI Adapter MN-130;c:\windows\system32\drivers\MN130-51.sys [5/29/2002 2:25 PM 38400]
S3 UNDPX2K;UNDPX2K;\??\c:\windows\system32\drivers\UNDPX2K.SYS --> c:\windows\system32\drivers\UNDPX2K.SYS [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-31 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
WebBrowser-{9D69F5EE-E293-4834-8587-4B94296E84E6} - (no file)
ShellExecuteHooks-{6809e580-a3a7-11d1-9a00-00a0c945b006} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: { - c:\documents and settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} - hxxp://thesims.ea.com/teleport/superstar/MaxisSuperstarTeleX.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\NPDyyno@dyyno.com\plugins\npDyyno.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-01 23:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-515967899-861567501-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(688)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
- - - - - - - > 'explorer.exe'(3368)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\ati2evxx.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Roxio\GoBack\GBPoll.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
.
**************************************************************************
.
Completion time: 2009-09-02 23:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-02 03:10
Pre-Run: 68,243,374,080 bytes free
Post-Run: 68,216,741,888 bytes free
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=,1,2,3,4,5,6,7,8,9
375 --- E O F --- 2009-09-02 02:31
•
•
•
•
Ah, I didn't see your latest post until after I ran Combofix - but I never had it installed before so it was a "fresh" copy. It ran without problems (no need to rename) and here is the log:

I will have a look at the log in more detail tomorrow and post any necessary manual fixes then.
You can go ahead and delete C:\KILLBAD - it didn't have much effect, lol!
PP
Last edited by PhilliePhan; Sep 2nd, 2009 at 12:20 am.
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer
ASAP
~ J. Robert Oppenheimer
ASAP
•
•
•
•
I will have a look at the log in more detail tomorrow and post any necessary manual fixes then.
Everything looks OK to me. I think you are good to go.
Let's remove Combofix and the files/folders it created:
• Click Start > Run
• Type or Copy&Paste Combofix /u into the Run box. (Be sure there is a space between the x and the / if you type it)
• Click OK
This will remove Combofix and it’s components from your machine.
It will also reset your clock, re-hide System and Hidden Files and hide File Extensions.
Last, but certainly not least, doing this will reset System Restore.
**You should be careful about the P2P stuff and File Sharing, etc . . . That's likely how you got infected.
That's the extent of my lecture......
Cheers

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer
ASAP
~ J. Robert Oppenheimer
ASAP
•
•
Join Date: Sep 2009
Posts: 8
Reputation:
Solved Threads: 0
•
•
•
•
**You should be careful about the P2P stuff and File Sharing, etc . . . That's likely how you got infected.
That's the extent of my lecture......
Cheers
PP
Thank you so much Phillie I can't thank you enough - I would have had no idea how to fix this problem on my own.
And ty for the warning, I believe that is how I got infected also and will certainly be much more careful in the future !!!
Thanks again -
Steph
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer
ASAP
~ J. Robert Oppenheimer
ASAP
![]() |
Similar Threads
- Need Help - Windows Police Pro?? Totally Locked Up. (Viruses, Spyware and other Nasties)
- Windows Police Pro, can't run mba.. (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Windows Police Pro, can't run mba..
- Next Thread: Nasty (Elusive) Virus
| Thread Tools | Search this Thread |
Tag cloud for Viruses, Spyware and other Nasties
acrobat adobe adware anti-malware anti-virussitesaccessissue antivirus apple attack avg backtoschoolspeech bar blackhat botnet botnets censorship china combofix commercial conficker connect control cyber cybercrime cyberwarfare ddos education email europe exam exploit fake fancheckvirus gaming gtaiv halloween herss.exe hijack hosting internet iphone legal logfiles malware mcafee messagelabs microsoft mobile msn nazi news obama onlinethreats paedophile parents patch pdf phishing police policeprovirusmba-mblockedinternetaccess president pro redirect report research rogueantivirus rootkit samhain sans scareware search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec system teen threat translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses vista volume vulnerability war warning windows worm yahoo zero-day zeroday






