ComboFix 10-09-23.01 - Administrator 23-09-2010 23:34:25.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.3204 [GMT 2:00]
Running from: c:\dl\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Internet Explorer\SET735.tmp
c:\program files\Internet Explorer\SET736.tmp
c:\windows\desktop
c:\windows\desktop\Virtual Pool 3.lnk
c:\windows\system32\drivers\zbybvcdi.sys
Infected copy of c:\windows\system32\drivers\cdrom.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2010-08-23 to 2010-09-23 )))))))))))))))))))))))))))))))
.
2010-09-23 19:59 . 2010-09-23 19:59 -------- d-sh--w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache
2010-09-23 19:27 . 2004-08-03 23:15 107904 ----a-w- c:\windows\system32\drivers\mup.sys
2010-09-23 18:37 . 2010-09-23 22:51 -------- d-----w- c:\windows\tmp
2010-09-23 00:48 . 2010-09-23 00:48 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-09-22 00:18 . 2010-09-22 00:24 -------- d-----w- C:\Combo-Fix
2010-09-21 11:23 . 2010-09-21 11:23 61440 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-72a86cc3-n\decora-sse.dll
2010-09-21 11:23 . 2010-09-21 11:23 503808 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-11686197-n\msvcp71.dll
2010-09-21 11:23 . 2010-09-21 11:23 499712 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-11686197-n\jmc.dll
2010-09-21 11:23 . 2010-09-21 11:23 348160 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-11686197-n\msvcr71.dll
2010-09-21 11:23 . 2010-09-21 11:23 12800 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-72a86cc3-n\decora-d3d.dll
2010-09-21 11:22 . 2010-09-21 11:22 79488 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_21\gtapi.dll
2010-09-21 11:22 . 2010-09-21 11:22 152576 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_21\lzma.dll
2010-09-21 11:06 . 2010-09-21 11:07 -------- d-----w- c:\program files\ERUNT
2010-09-21 08:21 . 2010-09-21 08:27 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-09-20 13:06 . 2010-09-20 13:06 63488 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-20 13:06 . 2010-09-20 13:06 52224 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-09-20 12:48 . 2010-09-20 12:48 -------- d-----w- c:\program files\OO Software
2010-09-20 12:45 . 2010-09-20 12:45 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Downloaded Installations
2010-09-18 20:11 . 2010-09-18 20:11 73216 ----a-w- c:\windows\system32\drivers\pxrts.sys
2010-09-18 20:11 . 2010-09-18 20:11 24400 ----a-w- c:\windows\system32\drivers\pxkbf.sys
2010-09-12 12:50 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-09-11 14:20 . 2010-09-11 14:21 -------- d-----w- c:\documents and settings\Administrator\Application Data\Chime
2010-09-11 14:20 . 2010-09-11 14:20 -------- d-----w- c:\program files\Microsoft XNA
2010-09-10 11:02 . 2010-09-10 11:02 1556808 ----a-w- c:\windows\system32\ooscrsav.scr
2010-09-10 11:01 . 2010-09-10 11:01 275272 ----a-w- c:\windows\system32\oodbs.exe
2010-09-10 10:59 . 2010-09-10 10:59 535880 ----a-w- c:\windows\system32\oodssrs.dll
2010-09-10 10:59 . 2010-09-10 10:59 9544 ----a-w- c:\windows\system32\oodbsrs.dll
2010-09-09 19:28 . 2010-09-18 18:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\Mumble
2010-09-09 19:28 . 2010-09-09 19:28 -------- d-----w- c:\program files\Mumble
2010-09-05 12:18 . 2010-08-30 12:34 1496064 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\Administrator\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-09-05 12:18 . 2010-08-30 12:33 43008 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\Administrator\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-09-05 12:18 . 2010-08-30 12:33 338944 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\Administrator\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-09-05 12:18 . 2010-08-30 12:33 346112 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\Administrator\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-09-02 17:56 . 2010-09-02 23:35 183656 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-28 02:03 . 2010-08-28 02:03 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\2K Games
2010-08-28 01:59 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-08-28 01:59 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-08-28 01:59 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-08-28 01:59 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-08-28 01:59 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-08-28 01:59 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-08-28 01:59 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-08-28 01:59 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-23 20:04 . 2008-08-31 00:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-09-23 19:59 . 2010-09-23 19:59 3416 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2010-09-23 05:29 . 2009-03-09 21:39 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-09-23 02:42 . 2007-07-31 18:21 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
2010-09-23 02:42 . 2007-07-31 16:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\Babylon
2010-09-23 02:18 . 2007-07-31 15:37 -------- d-----w- c:\program files\GetRight
2010-09-23 00:48 . 2010-05-23 22:31 -------- d-----w- c:\program files\AIM
2010-09-23 00:46 . 2008-04-02 13:20 -------- d-----w- c:\documents and settings\Administrator\Application Data\skypePM
2010-09-21 15:11 . 2007-07-31 16:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\MailWasherPro
2010-09-21 11:32 . 2009-12-15 15:03 188152 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\Administrator\FlashGot.exe
2010-09-21 11:23 . 2007-07-31 14:39 -------- d-----w- c:\program files\Common Files\Java
2010-09-21 11:23 . 2010-06-23 13:24 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-21 11:23 . 2007-07-31 14:39 -------- d-----w- c:\program files\Java
2010-09-21 10:48 . 2007-09-06 03:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-09-20 13:06 . 2009-07-31 06:57 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-20 12:57 . 2009-05-05 14:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-20 12:09 . 2009-06-17 16:19 41 ----a-w- c:\windows\popcinfot.dat
2010-09-20 01:09 . 2007-11-15 15:11 234280 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-09-19 22:56 . 2007-11-15 15:11 137976 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-09-19 08:18 . 2007-07-31 15:37 -------- d-----w- c:\program files\TightVNC
2010-09-19 07:55 . 2008-09-04 21:34 -------- d-----w- c:\program files\Microsoft
2010-09-19 07:41 . 2007-07-31 14:50 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-18 20:33 . 2009-04-04 23:47 -------- d-----w- c:\documents and settings\Administrator\Application Data\VMware
2010-09-18 20:11 . 2009-03-02 16:00 30320 ----a-w- c:\windows\system32\drivers\pxscan.sys
2010-09-18 20:11 . 2009-03-02 16:00 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2010-09-18 20:11 . 2009-03-02 16:00 -------- d-----w- c:\program files\Prevx
2010-09-17 07:09 . 2009-07-31 06:57 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-09-17 07:07 . 2007-07-31 21:22 -------- d-----w- c:\program files\CMenu
2010-09-17 07:01 . 2007-12-18 02:34 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-17 07:00 . 2007-08-03 06:24 -------- d-----w- c:\program files\SpywareBlaster
2010-09-17 06:56 . 2007-07-31 16:37 -------- d-----w- c:\program files\Desktop Armor
2010-09-17 04:25 . 2008-08-11 17:42 10760 ----a-w- c:\windows\system32\drivers\PROCEXP90.SYS
2010-09-17 02:56 . 2007-07-31 15:37 -------- d-----w- c:\program files\Google
2010-09-12 13:09 . 2008-02-14 05:34 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-02 18:20 . 2009-03-08 01:04 -------- d-----w- c:\program files\Rockstar Games
2010-08-29 03:19 . 2007-08-02 00:15 1209 ----a-w- c:\windows\EReg223.dat
2010-08-28 01:59 . 2009-11-03 17:35 -------- d-----w- c:\program files\NVIDIA Corporation
2010-08-28 01:59 . 2007-08-09 00:23 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-08-25 23:59 . 2007-08-01 11:24 -------- d-----w- c:\program files\EvilLyrics
2010-08-13 02:27 . 2007-08-15 22:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2010-08-09 09:13 . 2009-06-06 22:24 -------- d-----w- c:\program files\Messenger Plus! Live
2010-08-08 11:49 . 2010-03-21 14:39 -------- d-----w- c:\program files\TeamSpeak 3 Client
2010-08-03 02:23 . 2008-07-18 12:48 -------- d-----w- c:\program files\Recuva
2010-07-26 17:47 . 2010-06-18 06:46 232968 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-07-26 17:47 . 2010-06-18 06:46 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-07-26 17:47 . 2010-06-18 06:46 232968 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-07-09 14:24 . 2010-07-09 14:24 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-07-09 14:24 . 2010-07-09 14:24 277608 ----a-w- c:\windows\system32\nvmccs.dll
2010-07-09 14:24 . 2010-07-09 14:24 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-07-09 14:24 . 2010-07-09 14:24 155752 ----a-w- c:\windows\system32\nvsvc32.exe
2010-07-09 14:24 . 2010-07-09 14:24 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-07-09 14:24 . 2010-07-09 14:24 13923432 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-07 11:46 . 2008-12-04 13:26 604776 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-06-30 12:31 . 2007-07-27 15:33 149504 ----a-w- c:\windows\system32\schannel.dll
2008-08-19 08:17 . 2008-08-19 08:17 8 --sh--r- c:\windows\system32\21847BA199.sys
2009-12-21 14:57 . 2008-08-19 08:17 1994 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
------- Sigcheck -------
[-] 2009-01-04 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\TCPIP.SYS
[-] 2009-01-04 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\TCPIP.SYS
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\TCPIP.SYS
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[-] 2007-07-27 . E6B15BCC470953E600EF7ADED3CAB142 . 360704 . . [5.1.2600.3002] . . c:\windows\$NtUninstallKB941644$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Desktop Armor"="c:\program files\Desktop Armor\DesktopArmor.exe" [2004-12-16 1056768]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 2808832]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ShellState"= 2400000038080000000000000000000000000000010000000d0000000000000000000000
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Qualcomm\Eudora\EuShlExt.dll" [2006-08-17 86016]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2010-09-17 07:09 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS\0bootdelete\0OODBS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\GIGABYTE\\@BIOS\\update.exe"=
"c:\\Program Files\\GIGABYTE\\@BIOS\\gwflash.exe"=
"c:\\Program Files\\GIGABYTE\\ET5\\update.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Games\\S.T.A.L.K.E.R\\bin\\XR_3DA.exe"=
"c:\\Games\\S.T.A.L.K.E.R\\bin\\dedicated\\XR_3DA.exe"=
"c:\\Games\\Gunbound\\GunboundWC\\GunBound.gme"=
"c:\\Games\\Steam\\Steam.exe"=
"c:\\Games\\Steam\\steamapps\\
[email protected]\\half-life deathmatch source\\hl2.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Games\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Games\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Games\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Games\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\Websites\\PAMPA\\PAMPA\\mysql\\bin\\mysqld-nt.exe"=
"c:\\Websites\\PAMPA\\PAMPA\\apache\\bin\\httpd.exe"=
"c:\\Games\\Catan-Insel\\Catan.exe"=
"c:\\Games\\Bionic Commando Rearmed\\bcr.exe"=
"c:\\Games\\GTA IV\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Games\\GTA IV\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\VMware\\VMware Workstation\\vmware-authd.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\launch4j-tmp\\TlkEdit2.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Games\\SWAT 4\\ContentExpansion\\System\\Swat4XDedicatedServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Games\\Gearbox Software\\Borderlands\\Binaries\\Borderlands.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Games\\Steam\\steamapps\\common\\jade empire\\JadeEmpireLauncher.exe"=
"c:\\Games\\Steam\\steamapps\\common\\jade empire\\JadeEmpireConfig.exe"=
"c:\\Games\\Mass Effect 2\\Binaries\\MassEffect2.exe"=
"c:\\Games\\Mass Effect 2\\MassEffect2Launcher.exe"=
"c:\\Games\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"c:\\Games\\Battlefield Bad Company 2\\BFBC2Game.exe"=
"c:\\Games\\GTA IV\\EFLC\\EFLC.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Games\\PazaakCantina\\PazaakCantina.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Games\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Games\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"c:\\Games\\SWAT 4\\ContentExpansion\\System\\Swat4X.exe"=
"c:\\Games\\Steam\\steamapps\\common\\alien swarm\\swarm.exe"=
"c:\\Games\\Steam\\steamapps\\common\\alien swarm\\srcds.exe"=
"c:\\Games\\Steam\\steamapps\\common\\chime\\Chime.exe"=
"c:\\Program Files\\TightVNC\\tvnserver.exe"=
"c:\\Program Files\\TightVNC\\vncviewer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*

isabled:Windows Remote Management
R0 iastor75;iastor75;c:\windows\system32\drivers\iaStor75.sys [27-7-2007 17:55 304920]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2-3-2009 18:00 30320]
R1 Ext2fs;Ext2fs;c:\windows\system32\drivers\ext2fs.sys [7-8-2007 20:23 131840]
R1 IfsDrives;IfsDrives;c:\windows\system32\drivers\IfsDrives.sys [7-8-2007 20:23 4608]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [28-7-2009 10:53 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [28-7-2009 10:53 67656]
R2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [18-9-2010 22:11 73216]
R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [26-3-2009 23:05 54960]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [25-11-2005 17:43 31896]
R3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [18-9-2010 22:11 24400]
S1 c58da826;c58da826;c:\windows\system32\drivers\c58da826.sys --> c:\windows\system32\drivers\c58da826.sys [?]
S2 axjpawva;Microsoft IntelliPoint Filter Helper;c:\windows\System32\svchost.exe -k netsvcs [4-8-2004 14:00 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18-3-2010 13:16 130384]
S3 csiscanner;CSIScanner;c:\program files\Prevx\prevx.exe [2-3-2009 18:00 6405168]
S3 hitmanpro3;Hitman Pro 3 Support Driver;\??\c:\windows\system32\drivers\hitmanpro3.sys --> c:\windows\system32\drivers\hitmanpro3.sys [?]
S3 OODefragAgent;O&O Defrag Agent;c:\program files\OO Software\Defrag\oodag.exe [10-9-2010 13:01 2320712]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [17-6-2009 14:20 12648]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [28-7-2009 10:53 12872]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4-8-2004 14:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18-3-2010 13:16 753504]
S4 gupdate1c9acbca60618c;Google Updateservice (gupdate1c9acbca60618c);c:\program files\Google\Update\GoogleUpdate.exe [24-3-2009 22:06 133104]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8-8-2007 0:53 682232]
S4 tvnserver;TightVNC Server;c:\program files\TightVNC\tvnserver.exe [8-7-2010 15:28 815704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
axjpawva
.
Contents of the 'Scheduled Tasks' folder
2010-09-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-07-31 19:59]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.babylon.com
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Administrator\Start Menu\Programs\IMVU\Run IMVU.lnk
LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\Administrator\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\Administrator\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\Administrator\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.ActionNone", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.ActionCtrl", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.ActionCtrlShift", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.ActionAlt", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.ActionAltShift", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.ActionShift", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.ActionAltCtrl", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.LocationNone", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.LocationCtrl", "1");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.LocationCtrlShift", "1");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.LocationAlt", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.LocationAltShift", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.LocationShift", "2");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.LocationAltCtrl", "0");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.contextmenuoption", true);
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.country2Search", 80);
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.hotkeySelectionToggles", false);
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.searchoption", false);
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.historyoption", true);
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.history", "googlebar");
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.maxHistCnt", 10);
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.savelastoption", false);
c:\program files\Mozilla Firefox\defaults\pref\googlebar.js - user_pref("googlebar.hidemenuoption", false);
.
- - - - ORPHANS REMOVED - - - -
Notify-cbXPhFUK - cbXPhFUK.dll
AddRemove-Aangifte inkomstenbelasting 2008 voor ondernemers - c:\program files\Belastingdienst\Aangifte inkomstenbelasting voor ondernemers\2008\wa2008u.exe
AddRemove-BugOff - d:\1\Programs\DB\BugOff.exe
AddRemove-Mafia II_is1 - c:\games\Mafia II\unins000.exe
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
AddRemove-View32 - d:\1\DVDPrograms\FR Atlas\UNINST.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-23 23:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.