ComboFix 12-11-04.01 - arabbb 11/04/2012 15:54:43.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3055.2112 [GMT 9:00]
Running from: c:\documents and settings\arabbb\Desktop\ComboFix.exe
FW: Symantec Endpoint Protection *Enabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\arabbb\Local Settings\Temporary Internet Files\PreAB8.tmp
c:\documents and settings\arabbb\Local Settings\Temporary Internet Files\PreAB9.tmp
c:\documents and settings\arabbb\Local Settings\Temporary Internet Files\reggpc.bat
C:\Thumbs.db
c:\windows\Client.ini
c:\windows\system32\amgina.dll
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-10-04 to 2012-11-04 )))))))))))))))))))))))))))))))
.
.
2012-10-31 02:55 . 2012-10-31 02:55 -------- d-----w- c:\documents and settings\arabbb\Application Data\AVG
2012-10-31 02:54 . 2012-10-31 02:55 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG
2012-10-31 02:54 . 2012-10-31 02:54 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2012-10-31 02:43 . 2012-10-31 02:42 26984 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2012-10-31 02:43 . 2012-11-02 06:20 -------- d-----w- c:\program files\Common Files\AVG Secure Search
2012-10-31 02:42 . 2012-10-31 02:42 -------- d-----w- c:\windows\system32\drivers\AVG
2012-10-31 02:12 . 2012-10-31 02:12 -------- d-----w- C:\$AVG
2012-10-31 02:12 . 2012-10-31 02:12 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Avg2013
2012-10-31 02:12 . 2012-11-01 04:09 -------- d-----w- c:\program files\AVG
2012-10-31 02:10 . 2012-10-31 02:43 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2012-10-31 02:10 . 2012-10-31 02:10 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2012-10-31 02:10 . 2012-10-31 02:10 -------- d-----w- c:\documents and settings\arabbb\Local Settings\Application Data\MFAData
2012-10-31 02:10 . 2012-10-31 02:10 -------- d-----w- c:\documents and settings\arabbb\Local Settings\Application Data\Avg2013
2012-10-30 07:33 . 2012-11-01 00:58 66984 ----a-w- c:\windows\system32\Newtabs_v
2012-10-30 07:33 . 2012-10-30 07:33 -------- d-----w- c:\program files\newtabs
2012-10-19 13:44 . 2012-10-19 13:44 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2012-10-19 13:44 . 2012-10-19 13:44 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2012-10-19 13:44 . 2012-10-19 13:44 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2012-10-19 13:44 . 2012-10-19 13:44 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2012-10-19 13:44 . 2012-10-19 13:44 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2012-10-19 13:44 . 2012-10-19 13:44 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2012-10-19 13:44 . 2012-10-19 13:44 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2012-10-19 13:43 . 2012-10-19 13:44 -------- d-----w- c:\program files\QuickTime
2012-10-18 03:07 . 2012-10-18 03:07 -------- d-----w- c:\windows\ms
2012-10-10 00:05 . 2012-08-27 07:25 83488 ----a-w- c:\windows\smsrsgenctl.dll
2012-10-10 00:05 . 2012-08-27 07:25 34848 ----a-w- c:\windows\smsrsgen.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-20 18:46 . 2012-09-20 18:46 177376 ----a-w- c:\windows\system32\drivers\avglogx.sys
2012-09-05 08:16 . 2012-09-05 08:16 911 ----a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\qecrzmfd.xfe.vbs
2012-08-24 11:42 . 2012-08-24 11:42 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-08-24 06:43 . 2012-09-20 18:46 301920 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2008-08-16 22:42 . 2012-10-29 00:51 13112 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2008-08-16 22:42 . 2012-10-29 00:51 70456 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2008-08-16 22:42 . 2012-10-29 00:51 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2008-08-16 22:42 . 2012-10-29 00:51 20800 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2008-08-16 22:43 . 2012-10-29 00:51 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2008-08-16 22:42 . 2012-10-29 00:51 31032 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2008-08-16 22:42 . 2012-10-29 00:51 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2008-05-21 13:41 . 2012-10-29 00:51 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
2008-05-21 13:41 . 2012-10-29 00:51 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
2008-05-21 13:41 . 2012-10-29 00:51 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
2008-06-05 18:58 . 2012-10-29 00:51 648504 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2008-08-16 22:42 . 2012-10-29 00:51 23864 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2012-10-29 00:51 . 2012-10-29 00:51 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-04-17 3671872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-02-28 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2006-02-28 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-02-28 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 455168]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-01-22 1684776]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-04-21 737280]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-12-04 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-12-04 13933160]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2010-02-25 287800]
"AccessManager"="c:\program files\AccessManager\Client\AccessMgr.exe" [2004-03-04 618496]
"SoDA Startup"="c:\program files\Rational\SoDAWord\Wizards\SodaStartup.exe" [2008-11-14 143360]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1637496]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-07-30 2596984]
.
c:\documents and settings\arabbb\Start Menu\Programs\Startup\
Monitor My eRooms (V7).lnk - c:\program files\eRoom 7\ERClient7.exe [2010-12-20 153096]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-30 607584]
Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2011-12-3 1466384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
"NoStartMenuMyMusic"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"RecycleBinSize"= 10 (0xa)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1409082233-1229272821-725345543-197116\Scripts\Logon\0\0]
"Script"=\\a300sa04\apps01\JCISoftware\Scripts\jcisoftwarecopy.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1409082233-1229272821-725345543-197116\Scripts\Logon\1\0]
"Script"=HOL.vbs
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1409082233-1229272821-725345543-197116\Scripts\Logon\2\0]
"Script"=\\ag.na.jci.com\sysvol\ag.na.jci.com\scripts\chgcomputername.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1409082233-1229272821-725345543-233193\Scripts\Logon\0\0]
"Script"=GetNotesInfo.vbs
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1409082233-1229272821-725345543-233193\Scripts\Logon\1\0]
"Script"=\\a300sa04\apps01\JCISoftware\Scripts\jcisoftwarecopy.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1409082233-1229272821-725345543-233193\Scripts\Logon\2\0]
"Script"=HOL.vbs
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1409082233-1229272821-725345543-233193\Scripts\Logon\3\0]
"Script"=CreateELEFolder.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1409082233-1229272821-725345543-233193\Scripts\Logon\4\0]
"Script"=\\ag.na.jci.com\sysvol\ag.na.jci.com\scripts\chgcomputername.bat
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1409082233-1229272821-725345543-233193\Scripts\Logon\5\0]
"Script"=GetNotesInfo.vbs
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Runic Games\\Torchlight 2\\tl2.runic.launcher.exe"=
"c:\\Program Files\\Runic Games\\Torchlight 2\\Torchlight2.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58929:TCP"= 58929:TCP:Pando Media Booster
"58929:UDP"= 58929:UDP:Pando Media Booster
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [9/21/2012 3:45 AM 24896]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [9/21/2012 3:46 AM 177376]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/14/2012 3:05 AM 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/2/2012 3:30 AM 237408]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9/21/2012 3:46 AM 301920]
R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [10/31/2012 11:43 AM 26984]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [8/24/2012 8:42 PM 242240]
R2 AMBroker;Access Manager Configuration Service;c:\program files\AccessManager\Client\AMBroker.exe [3/5/2004 3:57 AM 81920]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [8/13/2012 3:24 AM 5167736]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 4:53 AM 193288]
R2 IBMHTTPServer6.0;IBM HTTP Server 6.0;c:\progra~1\Rational\common\rwp\IHS\bin\apache.exe [10/6/2011 9:38 PM 20538]
R2 IBMWAS6Service - RWP ReqWeb servlet;IBM WebSphere Application Server V6 - RWP ReqWeb servlet;c:\progra~1\Rational\common\rwp\EMBEDD~1\bin\wasservice.exe [10/6/2011 9:37 PM 69632]
R2 vToolbarUpdater13.2.0;vToolbarUpdater13.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe [10/31/2012 11:43 AM 711112]
R3 AESTAud;IDT AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2/11/2011 12:18 AM 113664]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [9/13/2012 3:11 AM 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 1:32 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [9/21/2012 3:45 AM 17232]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [10/1/2011 8:47 AM 227896]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [4/24/2010 3:07 AM 167080]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [5/19/2011 12:29 AM 44800]
R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [5/19/2011 12:33 AM 132352]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [5/19/2011 12:29 AM 58880]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [5/19/2011 12:29 AM 137728]
R3 rismc32;RICOH Smart Card Reader;c:\windows\system32\drivers\rismc32.sys [4/24/2010 3:12 AM 49152]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [7/4/2012 2:19 AM 160944]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\DRIVERS\motfilt.sys --> c:\windows\system32\DRIVERS\motfilt.sys [?]
S3 DAPlugin;Visual Insight DA Plugin;c:\program files\AccessManager\Client\DAPlugin.exe [3/5/2004 3:58 AM 81920]
S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y5132.sys --> c:\windows\system32\DRIVERS\e1y5132.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys --> c:\windows\system32\DRIVERS\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys --> c:\windows\system32\DRIVERS\motccgpfl.sys [?]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\DRIVERS\Motousbnet.sys --> c:\windows\system32\DRIVERS\Motousbnet.sys [?]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\DRIVERS\motusbdevice.sys --> c:\windows\system32\DRIVERS\motusbdevice.sys [?]
S3 sp_spi_da;Visual Insight Dial Analysis;c:\program files\AccessManager\SMOC\spi_da.exe [4/17/2003 10:59 PM 81920]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
2009-03-08 08:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1229272821-725345543-233193Core.job
- c:\documents and settings\arabbb\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-07-24 04:36]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1229272821-725345543-233193UA.job
- c:\documents and settings\arabbb\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-07-24 04:36]
.
2012-11-04 c:\windows\Tasks\User_Feed_Synchronization-{BC279796-AF70-48C5-8C63-CE50B0B8F30A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://hollandprint.ag.na.jci.com/
uInternet Settings,ProxyOverride = *.local;192.168.*.*
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\arabbb\Application Data\Mozilla\Firefox\Profiles\lu6grp5f.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - prefs.js: network.proxy.type - 2
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKLM-Run-vProt - c:\program files\AVG Secure Search\vprot.exe
HKLM-Run-ROC_roc_ssl_v12 - c:\program files\AVG Secure Search\ROC_roc_ssl_v12.exe
HKU-Default-RunOnce-WindowsMediaPlayer11_setup - c:\jcitemp-windowsmediaplayer11_setup\WindowsMediaPlayer11_setup.exe
AddRemove-LSI Soft Modem - c:\windows\agrsmdel
AddRemove-Mozilla Firefox 16.0.2 (x86 en-US) - c:\program files\Mozilla Firefox\uninstall\helper.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-11-04 16:03
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(5556)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\IDT\WDM\STacSV.exe
c:\windows\System32\SCardSvr.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Rational\common\rwp\IHS\bin\rotatelogs.exe
c:\program files\Rational\common\rwp\IHS\bin\rotatelogs.exe
c:\program files\Rational\common\rwp\IHS\bin\rotatelogs.exe
c:\program files\Rational\common\rwp\IHS\bin\rotatelogs.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\program files\IBM\Lotus\Notes\ntmulti.exe
c:\ora10g2\bin\omtsreco.exe
c:\program files\AccessManager\PMAC\sp_SWIns.exe
c:\windows\system32\CCM\CcmExec.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\msiexec.exe
c:\progra~1\Rational\common\rwp\EmbeddedExpress\java\bin\java.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Canon\Solution Menu EX\CNSEUPDT.EXE
c:\windows\system32\CCM\SmsClrHost.exe
.
**************************************************************************
.
Completion time: 2012-11-04 16:08:46 - machine was rebooted
ComboFix-quarantined-files.txt 2012-11-04 07:08
.
Pre-Run: 243,089,821,696 bytes free
Post-Run: 243,389,349,888 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - EF703CE6AD9E77E260F737638E0714FF