ComboFix 11-06-25.05 - theonyxserpent 06/26/2011 11:15:49.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.125 [GMT -4:00]
Running from: c:\documents and settings\theonyxserpent\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\install.rdf
c:\documents and settings\LocalService\Application Data\02000000f12dedc91270C.manifest
c:\documents and settings\LocalService\Application Data\02000000f12dedc91270O.manifest
c:\documents and settings\LocalService\Application Data\02000000f12dedc91270P.manifest
c:\documents and settings\LocalService\Application Data\02000000f12dedc91270S.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\install.rdf
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\install.rdf
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{410951ef-6ec8-4a82-9edf-2326feded017}\install.rdf
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{79fc8e7d-f139-4472-8239-1bc2386bef51}\install.rdf
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\install.rdf
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\install.rdf
c:\documents and settings\theonyxserpent\Application Data\dwm.exe
c:\documents and settings\theonyxserpent\Application Data\Microsoft\conhost.exe
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\chrome.manifest
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\chrome\xulcache.jar
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\defaults\preferences\xulcache.js
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{02f2bf09-f910-4c12-9090-1c4a7646a895}\install.rdf
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\chrome.manifest
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\chrome\xulcache.jar
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\defaults\preferences\xulcache.js
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{3cb6c568-ca5b-4b41-8a2c-9cfe0d13c63c}\install.rdf
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\chrome.manifest
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\chrome\xulcache.jar
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\defaults\preferences\xulcache.js
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{e1a852cd-b45a-4656-b124-e020f6e257cb}\install.rdf
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\chrome.manifest
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\chrome\xulcache.jar
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\defaults\preferences\xulcache.js
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{ffb9df16-4c73-49a1-9a00-5aaaf2092ab0}\install.rdf
.
c:\windows\system32\sfcfiles.dll was missing
Restored copy from - c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sfcfiles.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-05-26 to 2011-06-26 )))))))))))))))))))))))))))))))
.
.
2011-06-26 15:21 . 2008-04-14 00:12 1614848 ----a-w- c:\windows\system32\sfcfiles.dll
2011-06-24 20:56 . 2011-06-24 20:56 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-06-24 20:56 . 2011-06-24 20:56 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-06-23 23:06 . 2011-06-23 23:06 568832 ----a-w- c:\windows\system32\avifile32.exe
2011-06-23 23:06 . 2011-06-23 23:06 568832 ----a-w- c:\windows\system32\dpnaddr32.exe
2011-06-23 23:06 . 2011-06-23 23:06 568832 ----a-w- c:\windows\system32\schedsvc32.exe
2011-06-23 23:06 . 2011-06-23 23:06 369664 ----a-w- c:\windows\system32\avifile32.dll
2011-06-23 22:44 . 2011-06-23 22:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2011-06-23 22:34 . 2011-06-23 22:34 -------- d-----w- C:\f02976e5e14006106d
2011-06-23 22:33 . 2011-06-23 22:33 -------- d-----w- c:\windows\system32\drivers\UMDF
2011-06-23 22:33 . 2011-06-23 22:33 -------- d-----w- c:\windows\system32\LogFiles
2011-06-23 02:01 . 2011-06-23 02:01 -------- d-----w- C:\_OTL
2011-06-22 02:14 . 2011-06-22 03:14 20552 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-06-22 02:12 . 2011-06-22 02:12 -------- d-----w- c:\program files\Hitman Pro 3.5
2011-06-09 03:18 . 2011-06-09 03:18 -------- d-----w- c:\documents and settings\theonyxserpent\Local Settings\Application Data\Identities
2011-06-05 03:13 . 2011-06-23 10:37 -------- d-----w- c:\windows\system32\MpEngineStore
2011-06-02 00:35 . 2011-06-02 00:35 -------- d-----w- c:\program files\CleanUp!
2011-06-02 00:32 . 2011-06-22 02:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
2011-05-31 02:15 . 2011-05-31 02:15 0 ---ha-w- c:\documents and settings\theonyxserpent\wbczjdzfrr.tmp
2011-05-31 02:09 . 2011-05-31 02:09 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-24 20:56 . 2011-05-10 03:01 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 . D8E14A61ACC1D4A6CD0D38AEBAC7FA3B . 57856 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\spoolsv.exe
[7] 2005-06-11 . AD3D9D191AEA7B5445FE1D82FFBB4788 . 57856 . . [5.1.2600.2696] . . c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[7] 2005-06-10 . DA81EC57ACD4CDC3D4C51CF3D409AF9F . 57856 . . [5.1.2600.2696] . . c:\windows\system32\dllcache\spoolsv.exe
[7] 2004-08-04 . 7435B108B935E42EA92CA94F59C8E717 . 57856 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB896423$\spoolsv.exe
.
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\sfcfiles.dll
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
[7] 2004-08-04 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\sfcfiles.dll
.
c:\windows\System32\spoolsv.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06182B75-C684-4FC5-9490-2C0401937762}]
2011-06-23 23:06 369664 ----a-w- c:\windows\system32\avifile32.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
2010-01-18 19:28 815104 ----a-w- c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2009-08-05 224712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RandMAC"="c:\extracted\MadMACs\MadMACs.exe" [2008-08-06 253245]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2003-04-07 04:07 114688 ----a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2003-04-07 04:19 155648 ----a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-01-26 20:31 2144088 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-12-12 22:47 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\avifile32.exe"=
"c:\\WINDOWS\\system32\\schedsvc32.exe"=
"c:\\WINDOWS\\system32\\dpnaddr32.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/14/2009 1:20 PM 722416]
R2 UPS32;Uninterruptible Power Supply ;c:\windows\system32\schedsvc32.exe [6/23/2011 7:06 PM 568832]
R2 winmgmt32;Windows Management Instrumentation ;c:\windows\system32\dpnaddr32.exe [6/23/2011 7:06 PM 568832]
R3 {E6759E0C-470B-44DC-A4A1-627E68BB3A85};AIM 3.0 SI164;c:\windows\system32\drivers\a302.sys [5/10/2005 3:35 PM 11319]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys --> c:\windows\system32\DRIVERS\ewusbnet.sys [?]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [6/21/2011 10:14 PM 20552]
S3 VNCTEMP;Gencontrol WinVNC temporary service;c:\vnctemp\WinVNC.exe [6/16/2009 6:18 PM 469504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 17:42]
.
2011-06-25 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-12-12 21:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:57980
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 57980
FF - prefs.js: network.proxy.type - 1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-26 11:22
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-06-26 11:25:41
ComboFix-quarantined-files.txt 2011-06-26 15:25
ComboFix2.txt 2011-05-29 13:07
ComboFix3.txt 2009-06-16 22:59
.
Pre-Run: 8,343,834,624 bytes free
Post-Run: 8,325,505,024 bytes free
.
- - End Of File - - 21F4B0EDDE50DBCDB1B98E4B88F5FC2C
Edited by jerosakireno, 26 June 2011 - 09:33 AM.