ComboFix 12-06-01.02 - Administrator 31/12/2002 23:38:33.1.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.991.732 [GMT 0:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
AV: TalkTalk Security 9.01 *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: TalkTalk Security 9.01 *Enabled* {D4747503-0346-49EB-9262-997542F79BF4}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\QTSBandwidthCache
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Erin\WINDOWS
c:\documents and settings\Guest\WINDOWS
c:\documents and settings\Robin.PRIF\Application Data\1&1
c:\documents and settings\Robin.PRIF\WINDOWS
c:\program files\Search Settings
c:\program files\Search Settings\kb127\SearchSettings.dll
c:\program files\Search Settings\kb127\SearchSettingsRes409.dll
c:\program files\Search Settings\SearchSettings.exe
c:\windows\apppatch\apploc.exe
c:\windows\system32\65.dll
c:\windows\system32\atmlib44.exe
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\OggDSuninst.exe
c:\windows\system32\SNDALRT.log
c:\windows\system32\SNDCON.log
c:\windows\system32\SNDDBG.log
c:\windows\system32\SNDFW.log
c:\windows\system32\SNDIDS.log
c:\windows\system32\SNDSYS.log
c:\windows\system32\xvfv.dll
.
Infected copy of c:\windows\system32\msgsvc.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\msgsvc.dll
.
Infected copy of c:\windows\system32\mqbkup.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\mqbkup.exe
.
Infected copy of c:\windows\system32\mqsvc.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\mqsvc.exe
.
Infected copy of c:\windows\system32\mqtgsvc.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\mqtgsvc.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_EPSONSTATUSAGENT2
-------\Service_EPSONStatusAgent2
.
.
((((((((((((((((((((((((( Files Created from 2002-11-28 to 2002-12-31 )))))))))))))))))))))))))))))))
.
.
2012-05-28 09:59 . 2012-05-28 10:18 -------- d-----w- C:\Erase604.tmp
2012-05-24 04:15 . 2012-05-24 04:15 -------- d-----w- C:\_OTL
2012-01-30 09:42 . 2012-01-30 09:43 -------- d-----w- C:\e4c5f7d2fca106d54790b0f436
2012-01-24 14:59 . 2012-05-20 10:06 -------- d-----w- C:\dros dro
2012-01-24 14:59 . 2012-05-06 08:32 -------- d-----w- C:\teulu
2011-03-09 19:30 . 2012-05-21 15:57 -------- d-----w- C:\LLuniaur teulu
2008-08-04 09:19 . 2008-08-04 09:19 -------- d-----w- C:\NotesSQL
2008-01-13 16:09 . 2009-01-10 05:41 -------- d-----w- C:\MLBEE
2008-01-11 17:24 . 2008-01-11 17:24 -------- d-----w- C:\CanonMF
2008-01-11 17:02 . 2008-01-11 17:02 -------- d-----w- C:\3e69f417ff73acd432fc6c5d13303a
2006-02-16 16:35 . 2006-02-17 09:41 -------- d-----w- C:\RecoveryBin
2005-07-27 08:22 . 2005-08-25 08:37 -------- d-----w- C:\My MP3s
2005-07-21 12:40 . 2005-07-21 12:40 -------- d-----w- C:\My Media
2005-07-11 11:19 . 2005-07-11 11:19 -------- d-----r- C:\MSOCache
2005-05-26 12:48 . 2008-05-03 15:40 -------- d-----w- C:\EPSON
2004-07-04 18:40 . 2004-07-04 18:40 -------- d-----w- C:\adaptec
2004-06-03 11:00 . 2004-06-03 11:00 -------- d-----w- C:\unzipped
2004-05-14 11:27 . 2003-01-23 21:15 229888 ----a-w- C:\fhexdump.dll
2004-05-14 08:32 . 2004-05-14 08:32 56 --sh--w- C:\redir.sys
2004-05-13 13:10 . 2008-05-27 08:05 -------- d-----w- C:\Virus remover
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-11 13:12 . 2008-02-17 09:56 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-03-01 11:01 . 2004-02-06 17:05 916992 ----a-w- c:\windows\system32\wininet.dll
2012-02-29 14:10 . 2003-11-09 02:41 177664 ----a-w- c:\windows\system32\wintrust.dll
2011-11-25 21:57 . 2003-11-09 02:41 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-16 14:21 . 2004-08-06 07:32 354816 ----a-w- c:\windows\system32\winhttp.dll
2011-11-01 09:07 . 2012-04-04 16:49 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2011-10-18 11:13 . 2002-11-26 14:15 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-14 14:47 . 2003-11-09 02:41 176128 ----a-w- c:\windows\system32\winmm.dll
2011-09-26 11:41 . 2008-07-29 19:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-03-04 06:37 . 2003-11-09 02:41 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-02-17 12:32 . 2012-01-29 14:22 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-09 13:53 . 2002-11-26 14:15 270848 ----a-w- c:\windows\system32\sbe.dll
2010-08-27 08:02 . 2003-11-09 02:41 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2008-02-17 09:56 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-06-14 14:31 . 2003-11-09 03:51 744448 ----a-w- c:\windows\pchealth\HelpCtr\Binaries\helpsvc.exe
2010-04-16 15:36 . 2003-11-09 02:41 406016 ----a-w- c:\windows\system32\usp10.dll
2010-01-29 14:43 . 2002-07-22 15:24 307260 ----a-w- c:\windows\system32\l3codeca.acm
2009-11-27 16:07 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2001-08-17 22:36 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-21 15:51 . 2003-11-09 02:40 471552 ----a-w- c:\windows\apppatch\aclayers.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-08-26 08:00 . 2003-11-09 02:41 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-06 19:24 . 2008-01-11 16:57 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2009-08-06 19:24 . 2004-08-13 07:33 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 19:24 . 2004-08-13 07:33 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 19:24 . 2008-01-11 16:57 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2009-08-06 19:24 . 2005-05-26 03:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 19:24 . 2004-08-13 07:33 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 19:24 . 2004-08-13 07:33 217816 ----a-w- c:\windows\system32\wuaucpl.cpl
2009-08-06 19:24 . 2008-01-11 16:57 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2009-08-06 19:24 . 2003-11-09 03:50 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 19:24 . 2008-01-11 16:57 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2009-08-06 19:23 . 2004-08-13 07:33 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 19:23 . 2003-11-09 03:50 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-07-13 23:43 . 2004-05-24 13:51 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-25 08:25 . 2003-11-09 02:41 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-12 12:31 . 2003-11-09 02:41 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2003-11-09 02:41 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 06:14 . 2008-02-17 09:56 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-04-01 23:02 . 2004-05-13 23:53 604160 ----a-w- c:\windows\system32\wmspdmod.dll
2009-03-08 04:30 . 2003-11-09 02:41 66560 ----a-w- c:\windows\system32\tdc.ocx
2008-07-29 21:10 . 2008-07-29 21:10 26112 ----a-w- c:\windows\system32\TsWpfWrp.exe
2008-07-06 12:06 . 2012-01-30 09:42 575488 ------w- c:\windows\system32\xpsshhdr.dll
2008-07-06 12:06 . 2012-01-30 09:42 1676288 ------w- c:\windows\system32\xpssvcs.dll
2008-06-24 18:12 . 2006-10-18 21:47 295936 ----a-w- c:\windows\system32\wmpeffects.dll
2008-06-18 05:03 . 2004-05-13 23:53 938496 ----a-w- c:\windows\system32\WMNetmgr.dll
2008-05-30 13:19 . 2008-07-25 21:58 507400 -c--a-w- c:\windows\system32\XAudio2_1.dll
2008-05-30 13:18 . 2008-07-25 21:58 238088 -c--a-w- c:\windows\system32\xactengine3_1.dll
2008-05-30 13:17 . 2008-07-25 21:58 65032 -c--a-w- c:\windows\system32\XAPOFX1_0.dll
2008-05-30 13:17 . 2008-07-25 21:58 25608 -c--a-w- c:\windows\system32\X3DAudio1_4.dll
2008-05-09 23:23 . 2003-11-09 02:41 135168 ----a-w- c:\windows\system32\wshom.ocx
2008-05-09 10:53 . 2003-11-09 02:41 90112 ----a-w- c:\windows\system32\wshext.dll
2008-05-08 11:24 . 2003-11-09 02:41 155648 ----a-w- c:\windows\system32\wscript.exe
2008-04-14 00:13 . 2003-11-09 02:41 12168 ----a-w- c:\windows\system32\tsddd.dll
2008-04-14 00:12 . 2008-02-17 09:56 146432 ----a-w- c:\windows\system32\winspool.drv
2008-04-14 00:12 . 2003-11-09 04:10 23552 ----a-w- c:\windows\system32\wdmaud.drv
2008-04-14 00:12 . 2003-11-09 02:41 206848 ----a-w- c:\windows\system32\unimdm.tsp
2008-04-14 00:12 . 2002-08-29 03:41 294912 ----a-w- c:\windows\system32\msh263.drv
2008-04-14 00:12 . 2003-11-09 02:41 679936 ----a-w- c:\windows\system32\sstext3d.scr
2008-04-14 00:12 . 2003-11-09 02:41 610304 ----a-w- c:\windows\system32\sspipes.scr
2008-04-14 00:12 . 2003-11-09 02:41 14336 ----a-w- c:\windows\system32\ssstars.scr
2008-04-14 00:12 . 2003-11-09 02:41 47104 ----a-w- c:\windows\system32\ssmypics.scr
2008-04-14 00:12 . 2003-11-09 02:41 20992 ----a-w- c:\windows\system32\ssmarque.scr
2008-04-14 00:12 . 2003-11-09 02:41 18944 ----a-w- c:\windows\system32\ssmyst.scr
2008-04-14 00:12 . 2004-08-04 07:56 239616 ----a-w- c:\windows\system32\wstrenderer.ax
2008-04-14 00:12 . 2004-08-04 07:56 164352 ----a-w- c:\windows\system32\wstpager.ax
2008-04-14 00:12 . 2003-11-09 02:41 393216 ----a-w- c:\windows\system32\ssflwbox.scr
2008-04-14 00:12 . 2003-11-09 02:41 19968 ----a-w- c:\windows\system32\ssbezier.scr
2008-04-14 00:12 . 2003-11-09 02:41 704512 ----a-w- c:\windows\system32\ss3dfo.scr
2008-04-14 00:12 . 2004-08-04 07:56 53248 ----a-w- c:\windows\system32\vbicodec.ax
2008-04-14 00:12 . 2004-08-04 07:56 28672 ----a-w- c:\windows\system32\vidcap.ax
2008-04-14 00:12 . 2003-11-09 14:15 30208 ----a-w- c:\windows\system32\vbisurf.ax
2008-04-14 00:12 . 2003-11-09 02:41 278559 ----a-w- c:\windows\system32\wmv8ds32.ax
2008-04-14 00:12 . 2003-11-09 02:41 258048 ----a-w- c:\windows\system32\wmvds32.ax
2008-04-14 00:12 . 2003-11-09 02:41 12800 ----a-w- c:\windows\system32\tree.com
2008-04-14 00:12 . 2002-11-14 11:58 154624 ----a-w- c:\windows\system32\ivfsrc.ax
2008-04-14 00:12 . 2002-11-14 11:58 848384 ----a-w- c:\windows\system32\ir41_32.ax
2008-04-14 00:12 . 2002-11-14 11:58 199680 ----a-w- c:\windows\system32\iac25_32.ax
2008-04-14 00:12 . 2008-02-17 09:56 300544 ----a-w- c:\windows\system32\sysdm.cpl
2008-04-14 00:12 . 2004-08-04 07:56 148480 ----a-w- c:\windows\system32\wscui.cpl
2008-04-14 00:12 . 2004-08-04 07:56 13824 ----a-w- c:\windows\system32\wscntfy.exe
2008-04-14 00:12 . 2003-11-09 02:41 30720 ----a-w- c:\windows\system32\xcopy.exe
2008-04-14 00:12 . 2003-11-09 02:41 11264 ----a-w- c:\windows\system32\wpnpinst.exe
2008-04-14 00:12 . 2003-11-09 02:41 94208 ----a-w- c:\windows\system32\timedate.cpl
2008-04-14 00:12 . 2003-11-09 02:41 32256 ----a-w- c:\windows\system32\wpabaln.exe
2008-04-14 00:12 . 2003-11-09 02:41 5632 ----a-w- c:\windows\system32\winver.exe
2008-04-14 00:12 . 2003-11-09 02:41 507904 ----a-w- c:\windows\system32\winlogon.exe
2008-04-14 00:12 . 2003-11-09 02:41 65024 ----a-w- c:\windows\system32\wextract.exe
2008-04-14 00:12 . 2003-11-09 02:41 433664 ----a-w- c:\windows\system32\wiaacmgr.exe
2008-04-14 00:12 . 2008-02-17 09:56 26112 ----a-w- c:\windows\system32\userinit.exe
2008-04-14 00:12 . 2006-03-17 00:38 28672 ----a-w- c:\windows\system32\verclsid.exe
2008-04-14 00:12 . 2003-11-09 03:52 150528 ----a-w- c:\windows\pchealth\UploadLB\Binaries\uploadm.exe
2008-04-14 00:12 . 2003-11-09 02:41 289792 ----a-w- c:\windows\system32\vssvc.exe
2008-04-14 00:12 . 2003-11-09 02:41 50176 ----a-w- c:\windows\system32\utilman.exe
2008-04-14 00:12 . 2003-11-09 02:41 18432 ----a-w- c:\windows\system32\ups.exe
2008-04-14 00:12 . 2003-11-09 02:41 16896 ----a-w- c:\windows\system32\upnpcont.exe
2008-04-14 00:12 . 2003-11-09 02:41 73216 ----a-w- c:\windows\system32\tlntsvr.exe
2008-04-14 00:12 . 2003-11-09 02:41 259584 ----a-w- c:\windows\system32\tracerpt.exe
2008-04-14 00:12 . 2003-11-09 02:41 12288 ----a-w- c:\windows\system32\tracert.exe
2008-04-14 00:12 . 2003-11-09 02:40 347136 ----a-w- c:\windows\system32\tourstart.exe
2012-05-03 19:39 . 2012-01-29 14:04 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"SoundMan"="SOUNDMAN.EXE" [2003-06-10 55296]
"F-Secure Manager"="c:\program files\TalkTalk\Security\Common\FSM32.EXE" [2009-08-05 199264]
"F-Secure TNB"="c:\program files\TalkTalk\Security\FSGUI\TNBUtil.exe" [2009-08-05 2349664]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"PDFPrint"="c:\program files\PDF24\pdf24.exe" [2012-04-03 160840]
"iolo Startup"="c:\program files\iolo\Common\Lib\ioloLManager.exe" [2012-04-17 938680]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [BU]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
.
c:\documents and settings\Erin\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\Robin.PRIF\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
PMB Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2012-5-20 333088]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck smrgdf c:\documents and settings\Robin.PRIF\Application Data\iolo\\06.\0?̉?\0]\0Software\Adobe\Acrobat Reader\10.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cTopLeftView\0l\0?̉?\0]\0Software\Adobe\Acrobat Reader\10.0\RememberedViews\cNoCategoryFiles\c12\cViewDef\cTopLeftView\0\0???\0g\0Offline pages are Web pages that are stored on your computer so you can view them without being connected to the Internet. If you delete these pages now, you can still view your favorites offline later by synchronizing them. Your personalized settings for Web pages will be left intact.\0unt
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ioloSystemService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearch
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearchWHSE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinMem
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-11-04 10:30 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Scan Buttons]
2006-01-12 18:21 221184 -c--a-w- c:\program files\EPSON\Creativity Suite\PageManager\Pmsb.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"InvisibleBrowsing"=
"Nokia Tray Application"=c:\program files\Common Files\Nokia\Tools\NclTray.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"<NO NAME>"=
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"RemoteAddresses"= *
"Enabled"= 1 (0x1)
.
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [29/01/2012 14:21 44184]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [29/01/2012 14:21 82120]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23/08/2006 12:52 716272]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [19/03/2012 12:21 1047336]
S1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\TalkTalk\Security\HIPS\drivers\fshs.sys [29/01/2012 14:19 68064]
S2 bsaspi32;bsaspi32; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30/01/2012 16:02 135664]
S2 PVM Service;PVM Service;c:\program files\RingThree\bin\PvmService.exe [08/11/2007 01:02 294912]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [05/04/2012 07:20 257696]
S3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\TalkTalk\Security\Anti-Virus\minifilter\fsgk.sys [29/01/2012 14:18 148632]
S3 FSORSPClient;F-Secure ORSP Client;c:\program files\TalkTalk\Security\ORSP Client\fsorsp.exe [29/01/2012 14:19 61088]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [30/01/2012 16:02 135664]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [03/05/2012 19:40 129976]
S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [13/07/2005 15:55 234368]
S3 Z302Mic;Vimicro Z302 Mic Audio Filter Driver;c:\windows\system32\drivers\UsbMicfilt.sys [07/07/2005 10:04 22571]
S3 ZSMC302;PCL-W310;c:\windows\system32\drivers\usbvm302.sys [07/07/2005 10:04 93962]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\TalkTalk\Security\Anti-Virus\win2k\fsfilter.sys [29/01/2012 14:18 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\TalkTalk\Security\Anti-Virus\win2k\fsrec.sys [29/01/2012 14:18 25184]
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 20:33]
.
2012-05-20 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
2012-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-30 16:02]
.
2012-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-30 16:02]
.
2004-05-25 c:\windows\Tasks\new.job
- c:\windows\system32\ntbackup.exe [2003-11-09 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.boyns.net/
uInternet Settings,ProxyServer = 10.10.10.10:3128
LSP: c:\program files\TalkTalk\Security\FSPS\program\FSLSP.DLL
Trusted Zone: contentmatch.net\ny
TCP: DhcpNameServer = 192.168.1.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} - hxxp://www.nwales-traffic.co.uk/files/activex/camera.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\dewj4bc4.default\
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{0D84EF14-ED8E-475F-96D4-2123F65D701B} - (no file)
HKLM-RunOnce-SMRequiresRestart - (no file)
AddRemove-OggDS - c:\windows\system32\OggDSuninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2002-12-31 23:53
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{057AFF8E-18BB-3F80-364CCC2831522BE6}\{99AD5AFA-2676-F639-545B2C570527D246}\{9515C81F-50C9-6ACD-17AF77618A15A8EB}*]
"63AUOURV1X6YIYB2ELIFO4LTRC1"=hex:01,00,01,00,00,00,00,00,87,da,ad,38,2b,26,f8,
c3,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EA0A4278-51A3-7709-84DDEF02950ADF94}\{11936336-4B9A-79DD-A94F2AD208D83E94}\{0A7B61F5-80AE-3EB6-867F93DE000E0517}*]
"63AUOURV1X6YIYB2ELIFO4LTRC1"=hex:01,00,01,00,00,00,00,00,87,da,ad,38,2b,26,f8,
c3,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\l3codeca.acm
c:\windows\system32\DivXa32.acm
c:\windows\system32\imc32.acm
c:\windows\system32\LameACM.acm
c:\windows\system32\IEFRAME.dll
c:\windows\system32\ac3filter.acm
c:\windows\system32\l3codecp.acm
.
- - - - - - - > 'explorer.exe'(1916)
c:\windows\system32\WININET.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\iolo\System Mechanic\SystemGuardAlerter.exe
.
**************************************************************************
.
Completion time: 2003-01-01 00:03:53 - machine was rebooted
ComboFix-quarantined-files.txt 2003-01-01 00:03
ComboFix2.txt 2012-05-23 19:55
.
Pre-Run: 38,850,121,728 bytes free
Post-Run: 38,805,917,696 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - E8A343347FAC309EEF6E76FA4CC36222