I ran Combofix in safe mode,it couldn't install Rescue and Recovery due to the lack of an internet connection.
Also, upon restarting the machine my anti virus software will not start (I'm using Mcafee)so I now have no virus protection at all.
Here's the combofix log:
-------------------------------------
ComboFix 10-07-31.04 - admin 01/08/2010 17:24:46.1.2 - x86 MINIMAL
Running from: c:\documents and settings\admin\Desktop\svchost.com.exe
FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\CEPx5A7A.tmp
C:\CEPx5A7C.tmp
C:\CEPx5A7F.tmp
C:\CEPx5A82.tmp
C:\CEPx5A86.tmp
C:\CEPx5A89.tmp
C:\CEPx5A8C.tmp
C:\CEPx5A8F.tmp
C:\CEPx5A96.tmp
C:\CEPx5A97.tmp
C:\CEPx5A9A.tmp
C:\CEPx5AA0.tmp
C:\CEPx5AA3.tmp
C:\CEPx5AA6.tmp
C:\CEPx5AAA.tmp
C:\CEPx5AAD.tmp
C:\CEPx5AB0.tmp
C:\CEPx5AB2.tmp
C:\CEPx5AB3.tmp
C:\CEPx5AB5.tmp
C:\CEPx5AB8.tmp
C:\CEPx5ABE.tmp
C:\CEPx5ABF.tmp
C:\CEPx5AC1.tmp
C:\CEPx5AC4.tmp
C:\CEPx5AC9.tmp
C:\CEPx5AD0.tmp
C:\CEPx5AD1.tmp
C:\CEPx5AD3.tmp
C:\CEPx5ADA.tmp
C:\CEPx5ADD.tmp
C:\CEPx5AE0.tmp
C:\CEPx5AE3.tmp
C:\CEPx5AE5.tmp
C:\CEPx5B05.tmp
C:\CEPx5B08.tmp
C:\CEPx5B0E.tmp
C:\CEPx5B0F.tmp
C:\CEPx5B14.tmp
C:\CEPx5B15.tmp
C:\CEPx5B17.tmp
C:\CEPx5B1A.tmp
C:\CEPx5B1F.tmp
C:\CEPx5B20.tmp
C:\CEPx5B22.tmp
C:\CEPx5B29.tmp
C:\CEPx5B2A.tmp
C:\CEPx9F25.tmp
c:\documents and settings\admin\8tw3W.com
c:\documents and settings\admin\Application Data\ogix.exe
c:\documents and settings\admin\ddenwg.exe
c:\documents and settings\admin\Local Settings\Application Data\8tw3W.exe
c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
c:\documents and settings\admin\secupdat.dat
c:\documents and settings\All Users\Application Data\8tw3W.exe
c:\documents and settings\All Users\Application Data\Adobe\sp.Dll
c:\documents and settings\All Users\Application Data\hpe19F.dll
c:\documents and settings\All Users\Start Menu\HP Image Zone .lnk
c:\documents and settings\NetworkService\Local Settings\Application Data\8tw3W.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\progra~1\McAfee.com\Agent\McUpdate .exe
c:\progra~1\McAfee.com\Agent\McUpdate.exe
c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
c:\program files\Common Files\Java\Java Update\jusched.exe
c:\program files\CyberLink\PowerStarter\PowerBar.exe
c:\program files\McAfee.com\VSO\oasclnt.exe
c:\program files\MultiScreen\MultiScreen.exe
c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask.exe
c:\windows\AUTOLNCH.REG
c:\windows\Fonts\8tw3W.com
c:\windows\Hook.dll
c:\windows\system32\config\systemprofile\8tw3W.com
c:\windows\system32\images
c:\windows\system32\images\3models.gif
c:\windows\system32\images\but3_off.gif
c:\windows\system32\images\but3_on.gif
c:\windows\system32\images\main_bot.gif
c:\windows\system32\images\main_mid.gif
c:\windows\system32\images\main_top.gif
c:\windows\system32\images\model1.gif
c:\windows\system32\images\panel_bot.gif
c:\windows\system32\images\panel_top.gif
c:\windows\system32\images\pc.gif
c:\windows\system32\images\pcw_award_cover.gif
c:\windows\system32\images\pcwcover.gif
c:\windows\system32\images\Thumbs.db
c:\windows\system32\images\topoff.gif
c:\windows\system32\images\topon.gif
c:\windows\system32\images\webscreen.gif
c:\windows\system32\Thumbs.db
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
<pre>
c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate .exe ---^> c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager .exe ---^> c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
c:\program files\Common Files\Ahead\Lib\NMBgMonitor .exe ---^> c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
c:\program files\Common Files\Java\Java Update\jusched .exe ---^> c:\program files\Common Files\Java\Java Update\jusched.exe
c:\program files\CyberLink\PowerStarter\PowerBar .exe ---^> c:\program files\CyberLink\PowerStarter\PowerBar.exe
c:\program files\McAfee.com\VSO\oasclnt .exe ---^> c:\program files\McAfee.com\VSO\oasclnt.exe
c:\program files\MultiScreen\MultiScreen .exe ---^> c:\program files\MultiScreen\MultiScreen.exe
c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan .exe ---^> c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe
c:\program files\QuickTime\qttask .exe ---^> c:\program files\QuickTime\qttask.exe
</pre>
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SPService
((((((((((((((((((((((((( Files Created from 2010-07-01 to 2010-08-01 )))))))))))))))))))))))))))))))
.
2010-08-01 16:17 . 2010-08-01 16:17 -------- d-----w- C:\svchost.com19763s
2010-08-01 16:17 . 2010-08-01 16:17 -------- d-----w- C:\svchost.com
2010-07-30 23:31 . 2010-07-30 23:30 36876 ----a-w- c:\windows\system32\8tw3W.com
2010-07-30 08:30 . 2010-07-30 08:30 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-29 09:14 . 2010-07-29 09:14 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-14 16:33 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-07 13:16 . 2010-07-08 16:58 -------- d-----w- c:\program files\Multimedia Fusion 2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-01 16:45 . 2009-07-15 17:54 -------- d-----w- c:\program files\MultiScreen
2010-08-01 16:43 . 2009-06-05 19:54 -------- d-----w- c:\program files\QuickTime
2010-08-01 16:03 . 2009-10-17 23:53 -------- d-----w- c:\documents and settings\admin\Application Data\uTorrent
2010-08-01 09:17 . 2010-02-03 21:06 -------- d-----w- c:\documents and settings\admin\Application Data\vlc
2010-08-01 04:21 . 2007-03-26 18:44 -------- d-----w- c:\program files\Azureus
2010-07-31 09:05 . 2004-08-03 22:59 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-07-30 23:35 . 2008-07-25 19:43 32352 ----a-w- c:\windows\system32\drivers\UimBus.sys
2010-07-30 23:27 . 2005-09-09 22:03 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
2010-07-30 23:14 . 2010-07-30 23:04 112 ----a-w- c:\documents and settings\All Users\Application Data\18dydK371.dat
2010-07-30 23:09 . 2006-02-20 20:54 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-07-30 22:57 . 2008-07-25 19:43 38448 ----a-w- c:\windows\system32\drivers\hotcore3.sys
2010-07-30 18:11 . 2004-10-27 15:21 36868 ----a-w- c:\windows\system32\HDAShCut.exe
2010-07-29 09:14 . 2006-10-02 16:21 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-21 21:30 . 2006-02-20 21:52 112520 -c--a-w- c:\documents and settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-14 17:03 . 2008-09-15 14:57 -------- d-----w- c:\program files\truespace6
2010-07-13 13:29 . 2008-12-03 19:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-13 13:10 . 2010-07-13 13:09 34144256 ----a-w- C:\CEPx5A75.tmp
2010-07-07 13:18 . 2008-05-15 14:49 -------- d-----w- c:\documents and settings\admin\Application Data\Clickteam
2010-06-14 20:34 . 2010-06-14 20:34 -------- d-----w- c:\documents and settings\admin\Application Data\Facebook
2010-05-04 17:20 . 2005-09-09 22:03 832512 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2005-09-09 22:03 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2005-09-09 22:03 17408 ----a-w- c:\windows\system32\corpol.dll
2005-07-25 07:41 . 2005-05-26 02:17 110657 -c--a-w- c:\program files\Common Files\UninstallDrv.exe
2009-09-25 16:41 . 2009-09-25 16:41 1044480 -c--a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2007-12-10 17:40 . 2007-12-10 17:40 6275816 -c--a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 -c--a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
<pre>
c:\windows\system32\HDAShCut .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2010-08-01 36872]
"uTorrent"="c:\program files\uTorrent\uTorrent .exe" [N/A]
"Google Update"="c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-08-01 36872]
"AdobeBridge"="" [N/A]
"PowerBar"="c:\program files\CyberLink\PowerStarter\PowerBar.exe" [2010-08-01 36872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="realsched.exe -osboot" [X]
"QuickTime Task"="c:\program files\QuickTime\qttask .exe -atboottime" [X]
"VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [N/A]
"VirusScan Online"="c:\program files\McAfee.com\VSO\mcvsshld.exe" [N/A]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 118784]
"OASClnt"="c:\program files\McAfee.com\VSO\oasclnt.exe" [2010-08-01 36872]
"nwiz"="nwiz.exe" [2005-10-10 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784]
"MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2006-11-07 1121280]
"MPSExe"="c:\progra~1\mcafee.com\mps\mscifapp.exe" [2006-03-30 296488]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [N/A]
"MCUpdateExe"="c:\progra~1\McAfee.com\Agent\McUpdate.exe" [N/A]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [N/A]
"McafWelcome"="c:\program files\McAfee.com\Agent\mcwelcom.exe" [N/A]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-05-07 172032]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2010-07-30 36868]
"adiras"="adiras.exe" [N/A]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"MultiScreen"="c:\program files\MultiScreen\MultiScreen.exe" [2010-08-01 36872]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2010-08-01 36872]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-08-01 36872]
"NBKeyScan"="c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe" [2010-08-01 36872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\admin\Start Menu\Programs\Startup\
2stez03.exe [2010-7-26 36352]
3ytz86g.exe [2010-7-30 43008]
3yy3alw.exe [2010-7-31 36352]
5njefk8.exe [2010-7-29 43008]
5q1ghm8.exe [2010-7-27 36352]
60rmns8.exe [2010-7-27 36352]
75s0jk6.exe [2010-7-26 36352]
91qbcxd.exe [2010-7-31 43008]
9tu0k3w.exe [2010-7-29 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 23:46 57344 -c--a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 16:10 35696 -c--a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-08-01 16:45 36872 ----a-w- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-12-22 08:38 241664 -c--a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 15:24 54840 -c--a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-05-30 11:30 292136 -c--a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2010-08-01 16:45 36872 ----a-w- c:\program files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2005-01-14 18:21 110744 -c--a-w- c:\program files\CyberLink\PowerCinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar]
2010-08-01 16:45 36872 ----a-w- c:\program files\CyberLink\PowerStarter\PowerBar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QAGENT]
2001-05-24 16:00 94208 -c--a-w- c:\quickenw\qagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 16:18 413696 ----a-w- c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 20:24 32768 -c--a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
2009-09-24 14:41 434176 ----a-w- c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
c:\program files\uTorrent\uTorrent.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
c:\program files\Windows Media Player\WMPNSCFG.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{1290A33C-85F5-4164-A1BE-7DD299D4986A}]
2004-06-08 18:33 69721 -c--a-w- c:\program files\CyberLink\PowerBackup\PBKScheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerCinema\\PowerCinema.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\iView Media\\IVIEW_M.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Soulseek-Test\\slsk.exe"=
"c:\\Program Files\\Adobe\\After Effects 6.0\\Support Files\\AfterFX.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Documents and Settings\\admin\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\admin\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\MagicTune Premium\\MagicTune.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dllcache\\iexplore.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Sony Ericsson\\SEMC OMSI Module\\SEMC OMSI Module.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19820:UDP"= 19820:UDP:azureus
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"14786:TCP"= 14786:TCP:spport
"11054:TCP"= 11054:TCP:spport
"16001:TCP"= 16001:TCP:spport
"21750:TCP"= 21750:TCP:spport
"28045:TCP"= 28045:TCP:spport
"29667:TCP"= 29667:TCP:spport
"21941:TCP"= 21941:TCP:spport
"23302:TCP"= 23302:TCP:spport
"13842:TCP"= 13842:TCP:spport
"20543:TCP"= 20543:TCP:spport
R2 gupdate1c9907df6b45076;Google Update Service (gupdate1c9907df6b45076);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-16 133104]
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 16512]
R3 dcvsthrq;dcvsthrq;c:\windows\System32\Drivers\dcvsthrq.sys [x]
R3 dqbmwxvz;dqbmwxvz;c:\windows\System32\Drivers\dqbmwxvz.sys [x]
R3 DTV_Capture_2X0;DVB-T Receiver;c:\windows\system32\Drivers\DTV_Capture_2X0.sys [2004-09-06 18432]
R3 DTV_Loader_2X1;DVB-T Loader;c:\windows\system32\Drivers\DTV_Loader_2X1.sys [2005-06-29 19328]
R3 eovzzcmo;eovzzcmo;c:\windows\System32\Drivers\eovzzcmo.sys [x]
R3 ffseligy;ffseligy;c:\windows\System32\Drivers\ffseligy.sys [x]
R3 fwxmpdup;fwxmpdup;c:\windows\System32\Drivers\fwxmpdup.sys [x]
R3 gbzrhwbo;gbzrhwbo;c:\windows\System32\Drivers\gbzrhwbo.sys [x]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2009-04-06 13224]
R3 gzgagndc;gzgagndc;c:\windows\System32\Drivers\gzgagndc.sys [x]
R3 jcaxwquq;jcaxwquq;c:\windows\System32\Drivers\jcaxwquq.sys [x]
R3 kbhaugwz;kbhaugwz;c:\windows\System32\Drivers\kbhaugwz.sys [x]
R3 mabnfayi;mabnfayi;c:\windows\System32\Drivers\mabnfayi.sys [x]
R3 mnqpuenj;mnqpuenj;c:\windows\System32\Drivers\mnqpuenj.sys [x]
R3 nxcateut;nxcateut;c:\windows\System32\Drivers\nxcateut.sys [x]
R3 qllhkily;qllhkily;c:\windows\System32\Drivers\qllhkily.sys [x]
R3 qqsxzuxu;qqsxzuxu;c:\windows\System32\Drivers\qqsxzuxu.sys [x]
R3 qzysskuj;qzysskuj;c:\windows\System32\Drivers\qzysskuj.sys [x]
R3 rejmzuut;rejmzuut;c:\windows\System32\Drivers\rejmzuut.sys [x]
R3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\system32\DRIVERS\s3017bus.sys [2007-12-10 83880]
R3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s3017mdfl.sys [2007-12-10 15016]
R3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s3017mdm.sys [2007-12-10 110632]
R3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s3017mgmt.sys [2007-12-10 104616]
R3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\system32\DRIVERS\s3017nd5.sys [2007-12-10 25512]
R3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s3017obex.sys [2007-12-10 100648]
R3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\system32\DRIVERS\s3017unic.sys [2007-12-10 110120]
R3 saafypwo;saafypwo;c:\windows\System32\Drivers\saafypwo.sys [x]
R3 sdfpoqol;sdfpoqol;c:\windows\System32\Drivers\sdfpoqol.sys [x]
R3 swxvqfgg;swxvqfgg;c:\windows\System32\Drivers\swxvqfgg.sys [x]
R3 syhwjfjd;syhwjfjd;c:\windows\System32\Drivers\syhwjfjd.sys [x]
R3 tgisafbh;tgisafbh;c:\windows\System32\Drivers\tgisafbh.sys [x]
R3 udfpt;udfpt;c:\windows\system32\drivers\udfpt.sys [x]
R3 vclixntg;vclixntg;c:\windows\System32\Drivers\vclixntg.sys [x]
R3 W8100XP;Marvell Libertas 802.11b/g SoftAP Driver for Windows XP ;c:\windows\system32\DRIVERS\mrv8ka51.sys [2004-05-20 258560]
R3 xzhvhxvi;xzhvhxvi;c:\windows\System32\Drivers\xzhvhxvi.sys [x]
R3 zfuuawsp;zfuuawsp;c:\windows\System32\Drivers\zfuuawsp.sys [x]
R4 m5287;m5287;c:\windows\system32\DRIVERS\m5287.sys [2005-02-05 85888]
R4 m5289;m5289;c:\windows\system32\DRIVERS\m5289.sys [2004-12-01 51840]
S0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [2010-07-30 38448]
S2 EmmaDevMgmtSvc;Emma Device Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe [2010-02-25 306296]
S2 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe [2010-02-25 162936]
S2 mrtRate;mrtRate; [x]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
.
Contents of the 'Scheduled Tasks' folder
2010-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2010-08-01 c:\windows\Tasks\At193.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At194.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At195.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At196.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At197.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At198.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At199.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At200.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At201.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At202.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At203.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At204.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At205.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At206.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At207.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At208.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At209.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At210.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At211.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At212.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At213.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At214.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At215.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-08-01 c:\windows\Tasks\At216.job
- c:\documents and settings\All Users\Application Data\8kY6m125.exe [2010-08-01 16:50]
2010-07-30 c:\windows\Tasks\At25.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At26.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At27.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At28.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At29.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-08-01 c:\windows\Tasks\At30.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At31.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At32.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At33.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At34.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-08-01 c:\windows\Tasks\At35.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-08-01 c:\windows\Tasks\At36.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-08-01 c:\windows\Tasks\At37.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-08-01 c:\windows\Tasks\At38.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-08-01 c:\windows\Tasks\At39.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-08-01 c:\windows\Tasks\At40.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-08-01 c:\windows\Tasks\At41.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-31 c:\windows\Tasks\At42.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-31 c:\windows\Tasks\At43.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-31 c:\windows\Tasks\At44.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-31 c:\windows\Tasks\At45.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At46.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At47.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-30 c:\windows\Tasks\At48.job
- c:\windows\system32\8tw3W.com [2010-07-30 23:30]
2010-07-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-16 21:31]
2010-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-16 21:31]
2010-07-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-844380032-2981759145-68477085-1006Core.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-10 16:45]
2010-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-844380032-2981759145-68477085-1006UA.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-10 16:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mWindow Title = Tiscali Internet Access
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\mclsp.dll
DPF: {00000000-A6C3-4023-AE3A-22F2983D851D} - hxxps://authenticate.gateway.gov.uk/ClientObjects/SignatureControlInstaller.CAB
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\mtzxz5mg.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
FF - plugin: c:\documents and settings\admin\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\admin\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\admin\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\admin\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\admin\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.2\Plugins\npybrowserplus_2.9.2.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMGWRAP.DLL
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
FF - plugin: c:\windows\system32\Clickteam\Vitalize\v4\npcnc32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-{96AFBE69-C3B0-4b00-8578-D933D2896EE2} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
SafeBoot-klmdb.sys
SafeBoot-Wdf01000.sys
AddRemove-Vitalize! 4 - c:\windows\system32\Clickteam\Vitalize\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-01 17:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\jkrowling.com\jkrowling.sol 140 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\a\i\ligans\kids\common\flash\nav-1.6.swf\navData.sol 40 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\cosmos.bcst.yahoo.com\ver\230b\popup-2007-05-07-1251\swf\POP_tray.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\cosmos.bcst.yahoo.com\ver\242\embed-2007-08-28-1213\swf\yup_embed_module.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\cosmos.bcst.yahoo.com\ver\250.1\embed-2007-11-14-1422\swf\yup_embed_module.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\cosmos.bcst.yahoo.com\ver\251.1\embed-2007-12-03-1552\swf\yup_embed_module.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\cosmos.bcst.yahoo.com\ver\251.6\popup-2007-12-18-1554\swf\POP_meta.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\cosmos.bcst.yahoo.com\ver\256.0\embed-2008-01-23-1334\swf\yup_embed_module.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\cosmos.bcst.yahoo.com\ver\262.1\embed-2008-04-22-1515\swf\yup_embed_module.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\LCOMMENGINEMGR.sol 3649 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\m\ver\270.0\embed-2008-08-14-1438\swf\yup_embed_module.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\m\ver\271.16\embed-2009-08-27-1348\swf\yup_embed_module.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\m\ver\271.3\embed-2009-03-26-1329\swf\yup_embed_module.swf\TestMovie_Config_Info.sol 341 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\VolumePrefs.sol 55 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\YEPBWPrefs.sol 71 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l.yimg.com\[[IMPORT]]\d.yimg.com\ks\yfp\AdPlugin.swf\session.sol 76 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\l3.c.ooyala.com\orl.sol 68015 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\lads.myspace.com\videos\myspacetv_vplayer0005.swf\preferences.sol 136 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\lads.myspace.com\videos\vplayer.swf\preferences.sol 153 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\lads.myspacecdn.com\player.sol 98 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\lads.myspacecdn.com\videos\Main.swf\MSMediaPlayerClosedClients.sol
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\lads.myspacecdn.com\videos\Main.swf\MSMediaPlayerCurrentlyPlaying.sol
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\lads.myspacecdn.com\videos\Main.swf\preferences.sol
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\layouts1.lovemyflash.com\com.quantserve.sol 74 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\login.yahoo.com\loginCache.sol 250 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\ebaystatic.com\ft1693-1.sol
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\ebaystatic.com\ft681-1.sol 72 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\ebaystatic.com\ft681-19.sol 73 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\ebaystatic.com\ft681-20.sol 73 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\effectivemeasure.net\EM_APP.sol 100 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\empirecinemas.co.uk\BookingData.sol 64 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\empirecinemas.co.uk\CustomerPaymentData.sol 102 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\en.qoob.tv\swf\adept.swf\qoob_adept.sol 57 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\es.youtube.com\soundData.sol 58 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\es.youtube.com\videostats.sol 85 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\eur.a1.yimg.com\java.europe.yimg.com\eu\any\350x200uk3.swf\yD.sol 64 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\eur.a1.yimg.com\java.europe.yimg.com\eu\sp\eurosport01\350x200uk.swf\yD.sol 64 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\whdn.williamhill.com\cms\images\bingo\site\main_promotion_holder14.swf\whBingoPromo.sol 72 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\whisperaudio.com\flash_navigators\navigator_top_5.swf\visitRecord.sol 67 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\wiad-playlist.appspot.com\analytics.sol 446 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\widget-c9.slide.com\ratings.sol 51 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\widget-d6.slide.com\ratings.sol 51 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\widget.meebo.com\mm.sol 235 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\widget.nbc.com\5c66bb00-6bd7-11dd-ad8b-0800200c9a67.sol 339 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\widgets.clearspring.com\clearspring.sol
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\widgets.nbc.com\clearspring.sol 1331 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\widgets.nbcuni.com\GTSVolume.sol 56 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\wp.vizu.com\vizuUserData.sol
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\www.adjservices.net\scripts\UserId.swf\theAdjustablesUserID.sol 90 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\www.aintitcool.com\com.jeroenwijering.sol 53 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\pagead2.googlesyndication.com\pagead\googleadplayer.swf\mediaPlayerUserSettings.sol 94 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\pfa.levexis.com\pffc.sol
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\pl05.load.tubemogul.com\StreamMinerInfo.sol 70 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\images.metacafe.com\MetacafeFlashVideoPlayer.sol 64 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\seeqpod.cachefly.net\cache_prod\seeqpodSlimlineEmbed.swf\osprey.sol 35 bytes
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\us.mg1.mail.yahoo.com\cookies.sol
c:\documents and settings\admin\Application Data\Macromedia\Flash Player\#SharedObjects\TSYC8C8D\video.google.co.uk\googleplayer.swf\mediaPlayerUserSettings.sol
scan completed successfully
hidden files: 57
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
@DACL=(02 0000)
@="Microsoft Disk Quota"
"NoMachinePolicy"=dword:00000000
"NoUserPolicy"=dword:00000001
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"RequiresSuccessfulRegistry"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000000
"DllName"=expand:"dskquota.dll"
"ProcessGroupPolicy"="ProcessGroupPolicy"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
@DACL=(02 0000)
@="Internet Explorer Zonemapping"
"DllName"=expand:"iedkcs32.dll"
"ProcessGroupPolicy"="ProcessGroupPolicyForZoneMap"
"NoGPOListChanges"=dword:00000001
"RequiresSucessfulRegistry"=dword:00000001
"DisplayName"=expand:"@iedkcs32.dll,-3051"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
@DACL=(02 0000)
"ProcessGroupPolicy"="SceProcessSecurityPolicyGPO"
"GenerateGroupPolicy"="SceGenerateGroupPolicy"
"ExtensionRsopPlanningDebugLevel"=dword:00000001
"ProcessGroupPolicyEx"="SceProcessSecurityPolicyGPOEx"
"ExtensionDebugLevel"=dword:00000001
"DllName"=expand:"scecli.dll"
@="Security"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"EnableAsynchronousProcessing"=dword:00000001
"MaxNoGPOListChangesInterval"=dword:000003c0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
@DACL=(02 0000)
"ProcessGroupPolicyEx"="ProcessGroupPolicyEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"ProcessGroupPolicy"="ProcessGroupPolicy"
"DllName"="iedkcs32.dll"
@="Internet Explorer Branding"
"NoSlowLink"=dword:00000001
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000001
"NoMachinePolicy"=dword:00000001
"DisplayName"=expand:"@iedkcs32.dll,-3014"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
@DACL=(02 0000)
"ProcessGroupPolicy"="SceProcessEFSRecoveryGPO"
"DllName"=expand:"scecli.dll"
@="EFS recovery"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
"RequiresSuccessfulRegistry"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}]
@DACL=(02 0000)
@="802.3 Group Policy"
"DisplayName"=expand:"@dot3gpclnt.dll,-100"
"ProcessGroupPolicyEx"="ProcessLANPolicyEx"
"GenerateGroupPolicy"="GenerateLANPolicy"
"DllName"=expand:"dot3gpclnt.dll"
"NoUserPolicy"=dword:00000001
"NoGPOListChanges"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}]
@DACL=(02 0000)
@="Microsoft Offline Files"
"DllName"=expand:"%SystemRoot%\\System32\\cscui.dll"
"EnableAsynchronousProcessing"=dword:00000000
"NoBackgroundPolicy"=dword:00000000
"NoGPOListChanges"=dword:00000000
"NoMachinePolicy"=dword:00000000
"NoSlowLink"=dword:00000000
"NoUserPolicy"=dword:00000001
"PerUserLocalSettings"=dword:00000000
"ProcessGroupPolicy"="ProcessGroupPolicy"
"RequiresSuccessfulRegistry"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
@DACL=(02 0000)
@="Software Installation"
"DllName"=expand:"appmgmts.dll"
"ProcessGroupPolicyEx"="ProcessGroupPolicyObjectsEx"
"GenerateGroupPolicy"="GenerateGroupPolicy"
"NoBackgroundPolicy"=dword:00000000
"RequiresSucessfulRegistry"=dword:00000000
"NoSlowLink"=dword:00000001
"PerUserLocalSettings"=dword:00000001
"EventSources"=multi:"(Application Management,Application)\00(MsiInstaller,Application)\00\00"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
@DACL=(02 0000)
"DllName"="c:\\Program Files\\SUPERAntiSpyware\\SASWINLO.DLL"
"Logon"="SABWINLOLogon"
"Logoff"="SABWINLOLogoff"
"Startup"="SABWINLOStartup"
"Shutdown"="SABWINLOShutdown"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=expand:"crypt32.dll"
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=expand:"cryptnet.dll"
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
@DACL=(02 0000)
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
@DACL=(02 0000)
"Asynchronous"=dword:00000001
"DllName"=expand:"%SystemRoot%\\System32\\dimsntfy.dll"
"Startup"="WlDimsStartup"
"Shutdown"="WlDimsShutdown"
"Logon"="WlDimsLogon"
"Logoff"="WlDimsLogoff"
"StartShell"="WlDimsStartShell"
"Lock"="WlDimsLock"
"Unlock"="WlDimsUnlock"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
@DACL=(02 0000)
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"DllName"=expand:"wlnotify.dll"
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
@DACL=(02 0000)
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=expand:"sclgntfy.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
@DACL=(02 0000)
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
@DACL=(02 0000)
"Asynchronous"=dword:00000000
"DllName"=expand:"wlnotify.dll"
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
@DACL=(02 0000)
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList]
@DACL=(02 0000)
"HelpAssistant"=dword:00000000
"TsInternetUser"=dword:00000000
"SQLAgentCmdExec"=dword:00000000
"NetShowServices"=dword:00000000
"IWAM_"=dword:00010000
"IUSR_"=dword:00010000
"VUSR_"=dword:00010000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(896)
c:\windows\system32\mclsp.dll
c:\windows\system32\SPORDER.dll
c:\windows\system32\mclsphlr\gdlsphlr.dll
c:\windows\system32\McRtl32.dll
- - - - - - - > 'explorer.exe'(2768)
c:\windows\system32\WININET.dll
c:\program files\MultiScreen\ServiceHook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\ASWLSVC.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\MagicTune Premium\MagicTuneEngine.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\agent\mctskshd.exe
c:\windows\system32\ASWL2K.exe
c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
c:\progra~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\HPZipm12.exe
c:\program files\MagicTune Premium\MagicTune.exe
c:\windows\system32\rundll32.exe
c:\program files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 2010-08-01 18:01:10 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-01 17:01
Pre-Run: 9,446,088,704 bytes free
Post-Run: 10,345,607,168 bytes free
- - End Of File - - AEF390FFF354C7EE15DB567F2585F2ED