ComboFix 09-01-01.02 - Administrator 2009-01-02 19:53:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1344 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090102-0] *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\crugd.cfg
c:\windows\system32\drivers\npf.sys
c:\windows\system32\ektvm.cfg
c:\windows\system32\froppfxj.ini
c:\windows\system32\msoscqit.dat
c:\windows\system32\packet.dll
c:\windows\system32\senekankrjkdsx.dll.vir
c:\windows\system32\wl.exe
c:\windows\system32\wmsat.cfg
c:\windows\system32\wpcap.dll
c:\windows\system32\xmszs.dll
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CQIT
-------\Legacy_MHFP
-------\Legacy_MSFPFIS64
-------\Service_cqit
-------\Service_mhfp
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-12-03 to 2009-01-03 )))))))))))))))))))))))))))))))
.
2009-01-02 19:55 . 2009-01-02 19:55 <DIR> d-------- c:\windows\system32\xircom
2009-01-02 19:55 . 2009-01-02 19:55 <DIR> d-------- c:\program files\microsoft frontpage
2009-01-02 03:12 . 2009-01-02 04:00 <DIR> d-------- c:\program files\EsetOnlineScanner
2009-01-02 01:34 . 2009-01-02 01:34 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-02 01:34 . 2009-01-02 01:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-02 01:34 . 2009-01-02 01:34 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-01-02 01:34 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-02 01:34 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-01 11:56 . 2009-01-01 11:56 <DIR> d-------- c:\program files\Trojan Remover
2009-01-01 11:56 . 2009-01-01 11:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-01-01 11:56 . 2009-01-01 11:56 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Simply Super Software
2009-01-01 11:56 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-01-01 11:56 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-01-01 11:56 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-01-01 11:56 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2009-01-01 11:56 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-01-01 01:22 . 2009-01-01 01:22 <DIR> d-------- c:\documents and settings\Administrator\DoctorWeb
2008-12-20 21:27 . 2008-12-20 21:27 <DIR> d-------- C:\AeriaGames
2008-12-09 00:44 . 2008-12-09 00:46 <DIR> d-------- C:\YoutubeMusicDownloader
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-01-03 00:56 --------- d-----w c:\documents and settings\Administrator\Application Data\uTorrent
2009-01-02 05:33 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-01 23:13 --------- d-----w c:\program files\mTC
2008-12-31 07:07 --------- d-----w c:\program files\Easy RealMedia Tools
2008-12-24 19:54 --------- d-----w c:\program files\Starcraft
2008-12-24 19:22 --------- d-----w c:\program files\Electronic Arts
2008-12-23 15:52 --------- d-----w c:\documents and settings\Administrator\Application Data\Skype
2008-12-23 15:29 --------- d-----w c:\documents and settings\Administrator\Application Data\skypePM
2008-12-23 15:10 --------- d-----w c:\documents and settings\Administrator\Application Data\CoreFTP
2008-12-22 00:27 --------- d-----w c:\documents and settings\Administrator\Application Data\codeblocks
2008-12-16 17:08 --------- d-----w c:\program files\AllToAVI
2008-12-11 17:14 138,184 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-30 21:02 --------- d-----w c:\program files\iPhoneBrowser
2008-11-30 02:32 --------- d-----w c:\documents and settings\Administrator\Application Data\Apple Computer
2008-11-24 05:28 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-21 20:05 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-21 20:05 --------- d-----w c:\program files\AGEIA Technologies
2008-11-21 04:49 --------- d-----w c:\documents and settings\Administrator\Application Data\Leadertech
2008-11-21 04:40 --------- d-----w c:\program files\EA Games
2008-11-20 17:06 --------- d-----w c:\program files\SystemRequirementsLab
2008-11-20 17:05 --------- d-----w c:\documents and settings\Administrator\Application Data\SystemRequirementsLab
2008-11-19 16:44 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-19 14:55 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-17 05:44 --------- d-----w c:\program files\G-Collections
2008-11-16 21:10 --------- d-----w c:\documents and settings\Administrator\Application Data\Vso
2008-11-16 08:09 --------- d-----w c:\program files\Rockstar Games
2008-11-16 04:57 --------- d-----w c:\documents and settings\Administrator\Application Data\Webcammax
2008-11-10 04:10 --------- d-----w c:\documents and settings\Administrator\Application Data\ooVoo Details
2008-11-10 04:08 --------- d-----w c:\program files\ooVoo
2008-11-05 04:07 --------- d-----w c:\program files\Apple Software Update
2008-11-04 02:56 --------- d-----w c:\program files\iTunes
2008-11-04 02:56 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-04 02:55 --------- d-----w c:\program files\QuickTime
2008-11-04 02:55 --------- d-----w c:\program files\iPod
2008-11-04 02:55 --------- d-----w c:\program files\Common Files\Apple
2008-11-04 02:37 --------- d-----w c:\program files\Bonjour
2006-06-15 19:33 233,472 ----a-w c:\program files\mozilla firefox\plugins\CrazyTalk4Native.dll
2006-05-25 17:43 204,895 ----a-w c:\program files\mozilla firefox\plugins\ctdomemhelper.dll
2005-09-29 13:41 77,824 ----a-w c:\program files\mozilla firefox\plugins\ctframeplayerobject.dll
2006-06-19 12:10 426,081 ----a-w c:\program files\mozilla firefox\plugins\ctplayerobject.dll
2005-02-02 11:19 458,752 ----a-w c:\program files\mozilla firefox\plugins\imagickrt.dll
2006-04-10 17:35 139,264 ----a-w c:\program files\mozilla firefox\plugins\rlcontentclass.dll
2005-11-09 10:10 204,800 ----a-w c:\program files\mozilla firefox\plugins\RLMusicPacker.dll
2005-11-09 10:42 106,496 ----a-w c:\program files\mozilla firefox\plugins\RLMusicUnpacker.dll
2006-01-04 10:22 212,992 ----a-w c:\program files\mozilla firefox\plugins\RLVoicePacker.dll
2006-01-04 10:21 167,936 ----a-w c:\program files\mozilla firefox\plugins\RLVoiceUnpacker.dll
2008-05-07 17:35 76 --sh--r c:\windows\CT4CET.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"AIM"="c:\program files\AIM\aim.exe" [2008-09-17 67112]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2008-10-09 270128]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-10-01 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"oovoo.exe"="c:\program files\ooVoo\oovoo.exe" [2008-09-14 14174000]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"Splash screen for Avast!"="c:\program files\Alwil Software\Avast4\ashAvast.exe" [2008-11-26 274640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-04 8523776]
"WUSB54GS"="c:\program files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe" [2004-04-19 24576]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2007-12-04 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-23 185896]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2008-12-10 1230728]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 c:\windows\RTHDCPL.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-09-03 01:38 352256 c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run-]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe"
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"Creative Live! Cam Manager"="c:\program files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"SUPERAntiSpyware"=c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NeroFilterCheck"=c:\program files\Common Files\Nero\Lib\NeroCheck.exe
"V0380Mon.exe"=c:\windows\V0380Mon.exe
"Start WingMan Profiler"=c:\program files\Logitech\Gaming Software\LWEMon.exe /noui
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"KBD"=c:\hp\KBD\KBD.EXE
"KernelFaultCheck"=%systemroot%\system32\dumpr ep 0 -k
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
"mW[ˆ־`=˜v%S8’>grl>*\†=Ÿ۱"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Valve\\Steam\\steamapps\\itzbilly\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"6891:TCP"= 6891:TCP:aim
"443:UDP"= 443:UDP:*

isabled

oVoo UDP port 443
"37674:TCP"= 37674:TCP:*

isabled

oVoo TCP port 37674
"37674:UDP"= 37674:UDP:*

isabled

oVoo UDP port 37674
"37675:UDP"= 37675:UDP:*

isabled

oVoo UDP port 37675
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-08-09 111184]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-05-13 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-05-13 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswF sBlk.sys [2008-08-09 20560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-04-19 24652]
R2 WUSB54GSSVC;WUSB54GSSVC;"c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54GS.exe" [2008-04-28 41025]
R3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\Drivers\DB3G.sys [2008-06-04 13225]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;c:\windows\system32\DRIVERS\livecamv.sys [2008-05-07 31616]
R3 SaiK0728;SaiK0728;c:\windows\system32\DRIVERS\SaiK 0728.sys [2008-02-18 104960]
R3 V0380Afx;Creative Camera VF0380 Audio Effects Driver;c:\windows\system32\DRIVERS\V0380Afx.sys [2008-09-21 142656]
R3 V0380Aud;Creative Camera VF0380 Noise Cancellation APO;c:\windows\system32\DRIVERS\V0380Aud.sys [2008-09-21 94976]
R3 V0380Dev;Creative Camera VF0380 Driver;c:\windows\system32\DRIVERS\V0380Vid.sys [2008-09-21 274400]
R3 V0380Vfx;Creative Camera VF0380 Video VFX Driver;c:\windows\system32\DRIVERS\V0380Vfx.sys [2008-09-21 7168]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\DRIVERS\motfilt.sys [2008-07-26 6016]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\DRIVERS\motodrv.sys [2008-07-26 40832]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\DRIVERS\Motousbnet.sys [2008-07-26 22016]
S3 RTCore32;RTCore32;\??\c:\program files\RMClock\RTCore32.sys [2008-06-04 4608]
S3 SaiH0728;SaiH0728;c:\windows\system32\DRIVERS\SaiH 0728.sys [2008-09-26 136448]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-05-13 7408]
S3 XDva134;XDva134;\??\c:\windows\system32\XDva134.sy s []
S3 XDva168;XDva168;\??\c:\windows\system32\XDva168.sy s []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{53b49703-2b30-11dd-a1af-001217a7525e}]
\Shell\AutoRun\command - setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{ca09236b-0cb9-11dd-831e-001217a7525e}]
\shell\explore\Command - F:\mlburmh.exe
\shell\open\Command - F:\mlburmh.exe
*Newly Created Service* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
2009-01-03 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-04-16 03:59]
2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{4893206A-77A7-4EBD-9BD7-B2673992399F} - (no file)
BHO-{7EACA8A6-1390-44C5-B00B-E0C09F642E8D} - (no file)
BHO-{FA2C9293-814A-4877-A0AC-02DB89C12EEF} - (no file)
HKLM-Run-Pqalufujufux - c:\windows\alamohuxewoteho.dll
HKU-Default-Run-msiexec.exe - msiconf.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: ??? Microsoft Excel(&x) - c:\progra~1\MICROS~1\Office10\EXCEL.EXE/3000
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w8hex428.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRLCT4Player.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
ATTENTION: FIREFOX POLICES IS IN FORCE
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v1.02.11
.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-02 19:56:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\Administrator\Software\Microsoft\Intern et Explorer\MenuExt\[Q0R *NULL*M*NULL*i*NULL*c*NULL*r*NULL*o*NULL*s*NULL*o* NULL*f*NULL*t*NULL* *NULL*E*NULL*x*NULL*c*NULL*e*NULL*l*NULL*(*NULL*&* NULL*x*NULL*)*NULL*]
@="res://c:\\PROGRA~1\\MICROS~1\\Office10\\EXCEL.EXE/3000"
"Contexts"=dword:00000001
[HKEY_USERS\Administrator\Software\Microsoft\Office \10.0\Common\Open Find\Microsoft Word\Settings\Sb*NULL*_\File Name MRU]
"Value"=multi:"\
00\
00"
"Maximum Entries"=dword:0000000a
[HKEY_USERS\Administrator\Software\Microsoft\Office \10.0\Common\Open Find\Microsoft Word\Settings\Sb*NULL*_\View]
"Data"=hex:04,16,00,47,28,14,14,14,0d,01,02,01,00, 18,41,00,0d,00,fa,08,00,00,\
8b,44,0d,00,fa,08,00,00,8b,44,0d,00,fa,08,00,00,8b ,44,0d,00,fa,08,00,00,8b,\
44,0d,00,fa,08,00,00,8b,44,0d,00,fa,08,00,00,8b,44 ,0d,00,fa,20,00,00,8b,44,\
0d,00,fa,08,00,00,8b,44,0d,00,fa,08,00,00,8b,44,0d ,00,fa,04,00,0c,51,00,0d,\
00,18,04,00,0c,52,00,0d,00,10,40,00,08,42,00,0d,00 ,08,20,00,08,21,00,0d,00,\
fa,20,00,00,8b,44,0d,00,fa,01,00,00,8b,44,0d,00,fa ,20,00,00,8b,44,0d,00,fa,\
20,00,00,90,04,0d,00,fa,20,00,00,8b,44,0d,00,fa,04 ,00,00,8b,44,0d,00,fa,01,\
00,00,8b,44,0d,00,fa,08,00,00,8b,44
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\nexon\Mabinogi\npkcmsvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GS.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\InfoMyCa.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
.
************************************************** ************************
.
Completion time: 2009-01-02 19:59:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-03 00:59:30
Pre-Run: 205,462,286,336 bytes free
Post-Run: 205,327,568,896 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /noexecute=optin /fastdetect
324 --- E O F --- 2008-06-19 19:45:07