Evo konacno ComboFix logfile
ComboFix 09-10-07.05 - xxx 10/08/2009 22:51.1.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.265 [GMT 2:00]
Running from: c:\documents and settings\xxx\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\windows\clofghls.dll
c:\windows\Installer\1d2f3.msi
c:\windows\start.exe
c:\windows\system32\Data
c:\windows\Web\default.htt
Infected copy of c:\windows\System32\Drivers\dtscsi.sys was found and disinfected
Kitty ate it :)
.
((((((((((((((((((((((((( Files Created from 2009-09-08 to 2009-10-08 )))))))))))))))))))))))))))))))
.
2009-10-05 18:28 . 2009-10-05 18:28 4096 ----a-w- c:\windows\d3dx.dat
2009-10-05 18:10 . 2009-10-05 18:10 -------- d-----w- c:\program files\PC Wizard 2007
2009-10-05 15:16 . 2009-10-05 15:16 -------- d-----w- c:\documents and settings\xxx\Local Settings\Application Data\Apple_Inc
2009-10-01 21:56 . 2009-10-01 21:56 -------- d-----w- c:\documents and settings\xxx\Application Data\Ice Age 2
2009-10-01 18:11 . 2007-10-22 01:39 267272 ----a-w- c:\windows\system32\xactengine2_10.dll
2009-10-01 18:11 . 2007-10-12 13:14 1374232 ----a-w- c:\windows\system32\D3DCompiler_36.dll
2009-10-01 18:11 . 2007-10-02 07:56 444776 ----a-w- c:\windows\system32\d3dx10_36.dll
2009-10-01 18:11 . 2007-10-12 13:14 3734536 ----a-w- c:\windows\system32\d3dx9_36.dll
2009-10-01 16:36 . 2009-10-01 16:36 -------- d-----w- c:\documents and settings\xxx\Application Data\SEGA
2009-09-27 14:42 . 2009-09-27 14:42 -------- d-----w- c:\program files\PowerISO
2009-09-27 09:18 . 2009-09-27 09:18 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-27 08:50 . 2009-09-27 08:50 -------- d-----w- c:\documents and settings\xxx\Local Settings\Application Data\Thinstall
2009-09-26 22:13 . 2009-09-26 22:13 -------- d-----w- c:\program files\AdvancedDefrag
2009-09-25 20:09 . 2009-09-25 20:09 -------- d-----w- c:\program files\Eidos Interactive
2009-09-24 21:32 . 2009-09-24 21:32 -------- d-----w- c:\documents and settings\xxx\Application Data\GameHouse
2009-09-22 21:41 . 2009-09-22 21:41 156995 ----a-w- c:\windows\Toy Story 2 Uninstaller.exe
2009-09-22 21:40 . 2009-09-22 21:40 -------- d-----w- c:\program files\Toy Story 2
2009-09-21 21:23 . 2009-09-21 21:23 278984 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-09-21 21:22 . 2009-09-21 21:23 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-09-15 16:58 . 2009-09-15 16:58 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-15 15:36 . 2009-09-15 15:36 -------- d-----w- c:\program files\Hewlett-Packard
2009-09-15 15:22 . 2004-08-03 21:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-09-15 15:22 . 2004-08-03 21:01 25856 ----a-w- c:\windows\system32\dllcache\usbprint.sys
2009-09-11 21:15 . 2009-09-11 21:15 -------- d-----w- c:\documents and settings\xxx\Local Settings\Application Data\Graphisoft
2009-09-11 21:15 . 2009-09-11 21:15 -------- d-----w- c:\documents and settings\xxx\Graphisoft
2009-09-11 21:15 . 2009-09-11 21:15 -------- d-----w- c:\documents and settings\xxx\Application Data\Graphisoft
2009-09-11 21:08 . 2007-05-09 09:00 516096 ----a-w- c:\windows\system32\WibuXpm4J32.dll
2009-09-11 21:08 . 2007-05-09 09:00 479232 ----a-w- c:\windows\system32\wibuKJni.dll
2009-09-11 21:08 . 2007-05-09 09:00 348160 ----a-w- c:\windows\system32\WkExt32.dll
2009-09-11 21:08 . 2007-05-09 09:00 57552 ----a-w- c:\windows\system32\WkDos.exe
2009-09-11 21:08 . 2007-05-09 09:00 16384 ----a-w- c:\windows\system32\drivers\Wibukey2.sys
2009-09-11 21:08 . 2007-05-09 09:00 72704 ----a-w- c:\windows\system32\drivers\WibuKey.sys
2009-09-11 21:08 . 2007-05-09 09:00 159744 ----a-w- c:\windows\system32\WkWin32.dll
2009-09-11 21:08 . 2009-09-11 21:08 -------- d-----w- c:\program files\WIBUKEY
2009-09-11 21:08 . 2009-09-11 21:08 -------- d-----w- c:\program files\WIBU-SYSTEMS
2009-09-11 21:06 . 2009-09-11 21:06 -------- d-----w- c:\program files\Graphisoft
2009-09-11 21:04 . 2009-09-11 21:04 -------- d-----w- c:\program files\Java
2009-09-11 21:04 . 2009-09-11 21:04 -------- d-----w- c:\program files\Common Files\Java
2009-09-11 17:25 . 2009-09-11 17:25 -------- d-----w- C:\Downloads
2009-09-11 13:47 . 2009-09-11 13:48 -------- d-----w- c:\program files\iPhone Configuration Utility
2009-09-11 13:34 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-11 13:34 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-11 13:33 . 2009-09-11 13:33 -------- d-----w- c:\program files\iPod
2009-09-11 13:33 . 2009-09-11 13:33 -------- d-----w- c:\program files\iTunes
2009-09-11 13:33 . 2009-09-11 13:33 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-11 13:30 . 2009-09-11 13:30 -------- d-----w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 20:58 . 2009-07-11 18:58 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2009-10-08 20:58 . 2009-07-11 18:58 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2009-10-08 20:58 . 2008-12-24 17:16 2576 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-08 20:58 . 2008-12-24 17:16 1372704 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-08 20:58 . 2008-12-24 17:16 131104 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-08 20:58 . 2008-12-24 17:16 12852 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-08 20:57 . 2009-07-11 22:32 836 ----a-w- c:\windows\bthservsdp.dat
2009-10-05 15:22 . 2009-10-05 15:22 10862 ----a-w- c:\program files\hijackthis.log
2009-09-27 09:33 . 2008-12-23 13:25 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2009-09-27 09:33 . 2008-12-23 13:25 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2009-09-22 12:03 . 2008-12-24 17:16 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-09-22 12:03 . 2008-12-24 17:16 107547 ----a-w- c:\windows\system32\drivers\klin.dat
2009-09-06 12:27 . 2009-09-06 12:27 -------- d-----w- c:\program files\Srpski Recnik
2009-09-04 19:37 . 2009-09-04 19:37 -------- d-----w- c:\documents and settings\xxx\Application Data\PTGui
2009-09-04 09:41 . 2009-09-04 09:41 109184 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-04 09:19 . 2009-09-04 09:19 -------- d-----w- c:\program files\Safari
2009-09-04 09:18 . 2009-09-04 09:18 -------- d-----w- c:\program files\Bonjour
2009-09-03 13:15 . 2009-09-03 13:15 -------- d-----w- c:\program files\Tomb Raider - Anniversary
2009-08-15 20:22 . 2009-08-15 20:22 -------- d-----w- c:\program files\VersalSoft
2009-08-15 20:21 . 2009-08-15 20:21 -------- d-----w- c:\program files\Universal
2009-08-14 17:38 . 2006-08-14 13:48 132280 ----a-w- c:\documents and settings\xxx\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-14 08:31 . 2009-08-14 08:30 -------- d-----w- c:\program files\MSBuild
2009-08-14 08:30 . 2009-08-14 08:30 -------- d-----w- c:\program files\Reference Assemblies
2009-08-06 17:24 . 2006-08-14 13:12 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2006-08-14 13:12 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2008-10-16 12:09 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2006-08-14 13:12 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2005-03-11 10:52 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2002-08-28 23:40 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2006-08-14 13:12 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2005-03-11 10:52 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:11 . 2005-03-11 11:21 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55 . 2002-08-28 23:40 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 08:08 . 2004-08-10 23:45 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-01-05 15:51 . 2009-01-05 15:51 9433600 ----a-w- c:\program files\GameShadow.msi
2009-01-05 15:50 . 2009-01-05 15:51 3584 ----a-w- c:\program files\1033.MST
2005-12-24 16:04 . 2006-01-20 10:36 532480 ----a-w- c:\program files\cwshredder.exe
2005-04-13 17:34 . 2005-05-12 13:59 218112 ----a-w- c:\program files\HijackThis1991.exe
2003-03-28 09:16 . 2003-03-28 09:16 11079 ---h--w- c:\program files\folder.htt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-08 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
"MtdAcqu"="c:\program files\Creative\MediaSource5\MtdAcqu.exe" [2008-10-30 278528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-04 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-04 81920]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-06-03 564496]
"QuickTime Task"="c:\program files\K-Lite Codec Pack\QuickTime\QTTask.exe" [2009-09-04 417792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-15 149280]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-30 198160]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-07-21 208616]
"nwiz"="nwiz.exe" - c:\windows\SYSTEM32\nwiz.exe [2007-12-04 1626112]
"P17Helper"="P17.dll" - c:\windows\SYSTEM32\P17.dll [2005-05-03 64512]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\SYSTEM32\bthprops.cpl [2004-08-03 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
c:\documents and settings\xxx\Start Menu\Programs\Startup\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-3-19 630784]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-12-23 1205840]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"<NO NAME>"= 00000000
"NoLogoff"= 01000000
"NoFavoritesMenu"= 01000000
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"<NO NAME>"= 00000000
"NoLogoff"= 01000000
"NoFavoritesMenu"= 01000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ComPlusSetup]
2005-07-26 03:39 625152 ----a-w- c:\windows\SYSTEM32\catsrvut.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"Tweak UI"=RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\System32\\SPOOL\\drivers\\W32X86\\3\\HP1005MC.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\dna\\btdna.exe"=
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\SYSTEM32\DRIVERS\BtHidBus.sys [1/7/2009 23:39 20744]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\SYSTEM32\DRIVERS\klbg.sys [1/29/2008 17:29 33808]
R0 ViBus;ViBus;c:\windows\SYSTEM32\DRIVERS\ViBus.sys [2/1/2008 13:33 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\SYSTEM32\DRIVERS\ViPrt.sys [2/1/2008 13:33 53248]
R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\SYSTEM32\DRIVERS\e4usbaw.sys [12/23/2008 14:55 104344]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\SYSTEM32\DRIVERS\klfltdev.sys [3/13/2008 18:02 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\SYSTEM32\DRIVERS\klim5.sys [4/30/2008 17:06 24592]
S0 viasraid;viasraid;c:\windows\system32\DRIVERS\viasraid.sys --> c:\windows\system32\DRIVERS\viasraid.sys [?]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);c:\windows\SYSTEM32\DRIVERS\e4ldr.sys [12/23/2008 14:55 69656]
S2 gupdate1c9d1b7480b420c;Google Update Service (gupdate1c9d1b7480b420c);c:\program files\Google\Update\GoogleUpdate.exe [5/10/2009 23:35 133104]
S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\SYSTEM32\DRIVERS\btnetBus.sys [12/7/2008 12:44 30088]
S3 cpuz126;cpuz126;c:\program files\PC Wizard 2007\pcwiz32.sys [10/5/2009 20:10 7808]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\SYSTEM32\DRIVERS\IvtBtBus.sys [7/2/2008 14:58 26248]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S4 Cpl_hcrtrs;Cpl_hcrtrs; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
c:\windows\SYSTEM32\updcrl.exe -e -u c:\windows\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
2009-10-08 c:\windows\Tasks\Uninstall Expiration Reminder.job
- c:\windows\System32\OOBE\oobebaln.exe [2005-03-11 22:56]
2009-10-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-10 21:35]
2009-10-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-10 21:35]
2009-09-26 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2009-01-13 14:59]
2009-10-08 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2009-01-13 14:59]
2009-09-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-09-20 c:\windows\Tasks\Wise Disk Cleaner 4.job
- c:\program files\Wise Disk Cleaner\WiseDiskCleaner.exe [2009-01-11 13:35]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: &Download with &DAP
IE: Dodaj u zaštitu od reklama - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: bancaintesabeograd.com\online
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\SYSTEM\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {76326493-E84F-4D4B-939C-1E07B50037F2} - hxxps://online.bancaintesabeograd.com/RetailDLL/SGCMSCCD.DLL
DPF: {A7C346A3-B076-46B3-97F0-D00F6B479451} - hxxps://online.bancaintesabeograd.com/RetailDLL/FSINT.dll
FF - ProfilePath - c:\documents and settings\xxx\Application Data\Mozilla\Firefox\Profiles\d9qnq4i5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://search.bearshare.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: c:\documents and settings\xxx\Application Data\Mozilla\Firefox\Profiles\d9qnq4i5.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Mozilla Firefox\extensions\
[email protected]\components\Shim.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin5.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - (no file)
ShellIconOverlayIdentifiers-{7D688A77-C613-11D0-999B-00C04FD655E1} - (no file)
Notify-AtiExtEvent - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-08 22:59
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2524)
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
c:\program files\BONJOUR\MDNSRESPONDER.EXE
c:\windows\system32\CTsvcCDA.exe
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\COMMON FILES\LOGISHRD\LVCOMSER\LVCOMSER.EXE
c:\program files\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
c:\windows\SYSTEM32\NVSVC32.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\COMMON FILES\LOGISHRD\LVCOMSER\LVCOMSER.EXE
c:\windows\system32\wscntfy.exe
c:\windows\System32\spool\DRIVERS\W32X86\3\HP1005MC.EXE
.
**************************************************************************
.
Completion time: 2009-10-08 23:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-08 21:03
Pre-Run: 10,988,732,416 bytes free
Post-Run: 10,931,322,880 bytes free
311 --- E O F --- 2009-09-18 18:55