ComboFix 11-08-29.03 - theonyxserpent 08/30/2011 1:31.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.309 [GMT -4:00]
Running from: c:\documents and settings\theonyxserpent\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\install.rdf
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\install.rdf
c:\documents and settings\All Users\Application Data\defender.exe
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\install.rdf
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\install.rdf
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\install.rdf
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\install.rdf
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\chrome.manifest
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\chrome\xulcache.jar
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\defaults\preferences\xulcache.js
c:\documents and settings\Mouth\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\install.rdf
c:\documents and settings\theonyxserpent\Application Data\47D2.A7B
c:\documents and settings\theonyxserpent\Application Data\dwm.exe
c:\documents and settings\theonyxserpent\Application Data\Microsoft\conhost.exe
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\chrome.manifest
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\chrome\xulcache.jar
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\defaults\preferences\xulcache.js
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{1bea190a-a5a8-468d-b10f-c1c2166dd90c}\install.rdf
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\chrome.manifest
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\chrome\xulcache.jar
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\defaults\preferences\xulcache.js
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{20865922-f6b8-4386-bc6d-09cf3a167844}\install.rdf
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\chrome.manifest
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\chrome\xulcache.jar
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\defaults\preferences\xulcache.js
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{6e63418e-b8ef-434f-8d0e-55c24833d871}\install.rdf
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\chrome.manifest
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\chrome\xulcache.jar
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\defaults\preferences\xulcache.js
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{da24410f-e635-488c-bb93-4b2c818e15c6}\install.rdf
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\chrome.manifest
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\chrome\xulcache.jar
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\defaults\preferences\xulcache.js
c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\extensions\{f2901742-7aee-485b-881e-11e8906e3763}\install.rdf
c:\documents and settings\theonyxserpent\wbczjdzfrr.tmp
c:\windows\$NtUninstallKB58346$
c:\windows\$NtUninstallKB58346$\592837978
c:\windows\$NtUninstallKB58346$\639187468\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
c:\windows\$NtUninstallKB58346$\639187468\click.tlb
c:\windows\$NtUninstallKB58346$\639187468\L\xcuixrhe
c:\windows\$NtUninstallKB58346$\639187468\loader.tlb
c:\windows\$NtUninstallKB58346$\639187468\U\@00000001
c:\windows\$NtUninstallKB58346$\639187468\U\@000000c0
c:\windows\$NtUninstallKB58346$\639187468\U\@000000cb
c:\windows\$NtUninstallKB58346$\639187468\U\@000000cf
c:\windows\$NtUninstallKB58346$\639187468\U\@80000000
c:\windows\$NtUninstallKB58346$\639187468\U\@800000c0
c:\windows\$NtUninstallKB58346$\639187468\U\@800000cb
c:\windows\$NtUninstallKB58346$\639187468\U\@800000cf
c:\windows\system32\c_16333.nls
.
Infected copy of c:\windows\system32\drivers\afd.sys was found and disinfected
Restored copy from - The cat found it
Infected copy of c:\windows\system32\wuauclt.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\wuauclt.exe
.
Infected copy of c:\program files\Java\jre6\bin\jqs.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{C1610B7D-08C0-4A78-981D-4F6E8DFCA536}\RP33\A0015733.exe
.
Infected copy of c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE was found and disinfected
Restored copy from - c:\system volume information\_restore{C1610B7D-08C0-4A78-981D-4F6E8DFCA536}\RP33\A0015732.EXE
.
Infected copy of c:\windows\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe was found and disinfected
Restored copy from - c:\system volume information\_restore{C1610B7D-08C0-4A78-981D-4F6E8DFCA536}\RP33\A0015731.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_26193a0c
.
.
((((((((((((((((((((((((( Files Created from 2011-07-28 to 2011-08-30 )))))))))))))))))))))))))))))))
.
.
2011-08-30 05:26 . 2008-08-14 10:34 138496 -c--a-w- c:\windows\system32\dllcache\afd.sys
2011-08-30 05:26 . 2008-08-14 10:34 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-29 20:04 . 2011-07-06 23:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-29 20:04 . 2011-08-29 20:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-29 20:04 . 2011-07-06 23:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-25 23:54 . 2004-08-04 12:00 25600 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-08-25 23:49 . 2011-08-25 23:49 -------- d-----w- c:\program files\Windows Media Connect 2
2011-08-25 23:17 . 2011-08-25 23:17 -------- d-----w- C:\0b567addfd69ab4749e4a2a6
2011-08-21 01:15 . 2011-08-21 01:15 -------- dc----w- c:\windows\system32\DRVSTORE
2011-08-21 01:14 . 2006-09-28 20:04 68888 ----a-w- c:\windows\system32\xinput1_3.dll
2011-08-21 00:28 . 2008-03-21 17:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2011-08-09 21:05 . 2004-08-04 03:07 59264 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2011-08-09 21:05 . 2004-08-04 03:07 59264 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-18 21:50 . 2011-05-31 02:09 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-22 03:14 . 2011-06-22 02:14 20552 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-08-18 21:41 . 2011-05-10 03:01 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
2010-01-18 19:28 815104 ----a-w- c:\program files\Burn4Free Toolbar\v3.3.0.3\Burn4Free_Toolbar.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2009-08-05 224712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RandMAC"="c:\extracted\MadMACs\MadMACs.exe" [2008-08-06 253245]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2003-04-07 04:07 114688 ----a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2003-04-07 04:19 155648 ----a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-01-26 20:31 2144088 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-12-12 22:47 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/14/2009 1:20 PM 722416]
R3 {E6759E0C-470B-44DC-A4A1-627E68BB3A85};AIM 3.0 SI164;c:\windows\system32\drivers\a302.sys [5/10/2005 3:35 PM 11319]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys --> c:\windows\system32\DRIVERS\ewusbnet.sys [?]
S3 hitmanpro35;Hitman Pro 3.5 Support Driver;c:\windows\system32\drivers\hitmanpro35.sys [6/21/2011 10:14 PM 20552]
S3 VNCTEMP;Gencontrol WinVNC temporary service;c:\vnctemp\WinVNC.exe [6/16/2009 6:18 PM 469504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 17:42]
.
2011-08-30 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-12-12 22:47]
.
2011-07-13 c:\windows\Tasks\photostageShakeIcon.job
- c:\program files\NCH Software\PhotoStage\photostage.exe [2011-07-03 15:29]
.
2011-08-21 c:\windows\Tasks\videopadDowngrade.job
- c:\program files\NCH Software\VideoPad\videopad.exe [2011-07-03 15:28]
.
2011-08-08 c:\windows\Tasks\videopadShakeIcon.job
- c:\program files\NCH Software\VideoPad\videopad.exe [2011-07-03 15:28]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:56848
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\theonyxserpent\Application Data\Mozilla\Firefox\Profiles\og0g7s2n.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 56848
FF - prefs.js: network.proxy.type - 1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-30 07:01
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2696)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
c:\windows\system32\CCM\CcmExec.exe
.
**************************************************************************
.
Completion time: 2011-08-30 07:07:01 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-30 11:06
.
Pre-Run: 8,710,938,624 bytes free
Post-Run: 8,697,049,088 bytes free
.
- - End Of File - - 88545F7747CA47675AF901D500895F88