- ComboFix 09-07-08.04 - Compaq_Owner 2009-07-08 23:26.3 - NTFSx86
- Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3070.2146 [GMT -5:00]
- Running from: c:documents and settingsCompaq_OwnerDesktopComboFix.exe
- AV: avast! antivirus 4.8.1296 [VPS 090430-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
- FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- c:windowsDownloaded Program Filespopcaploader.dll
- c:windowsDownloaded Program Filespopcaploader.inf
- c:windowsInstaller114f97.msi
- c:windowsInstaller114f9d.msi
- c:windowsInstaller114fa3.msi
- c:windowsInstaller13d38.msi
- c:windowsInstaller146842ce.msi
- c:windowsInstaller146842d8.msi
- c:windowsInstaller1538a3b0.msi
- c:windowsInstaller1b205b5.msi
- c:windowsInstaller1e6db93.msi
- c:windowsInstaller258b8d1.msp
- c:windowsInstaller3476624.msi
- c:windowsInstaller37dba0.msi
- c:windowsInstaller37dba7.msi
- c:windowsInstaller3aadb1e.msi
- c:windowsInstaller445d8fe.msi
- c:windowsInstaller6544601.msp
- c:windowsInstaller6c75f4.msi
- c:windowsInstaller759940b.msp
- c:windowsInstaller8faf56.msi
- c:windowsInstallercc4feb.msi
- c:windowssysguard.exe
- c:windowssyssvc.exe
- c:windowssystem32otireyo.dll.tmp
- c:windowssystem32enunaruv.ini
- c:windowssystem32iehelper.dll
- c:windowssystem32lsp.dll
- c:windowssystem32ulodayow.ini
- c:windowssystem32unojuged.ini
- c:windowssystem32upubagej.ini
- c:windowssystem32wbemproquota.exe
- c:windowsSysvxd.exe
- c:windowssystem32proquota.exe was missing
- Restored copy from - c:windowsSoftwareDistributionDownloaddd9ab5193501484cf5e6884fa1d22f9eproquota.exe
- .
- ((((((((((((((((((((((((( Files Created from 2009-06-09 to 2009-07-09 )))))))))))))))))))))))))))))))
- .
- 2009-07-09 04:41 . 2008-04-14 00:12 50176 ----a-w- c:windowssystem32proquota.exe
- 2009-07-09 04:41 . 2008-04-14 00:12 50176 ----a-w- c:windowssystem32dllcacheproquota.exe
- 2009-07-05 01:57 . 2009-07-05 01:57 -------- d-----w- c:documents and settingsCompaq_OwnerApplication DataJPEGsnoop
- 2009-06-23 20:36 . 2009-06-23 20:36 -------- d-----w- C:Python25
- 2009-06-22 19:40 . 2009-06-22 19:40 -------- d-----w- c:program filesAIM Toolbar
- 2009-06-13 05:49 . 2009-06-13 05:49 -------- d-----w- C:Hotspot Shield
- 2009-06-13 05:49 . 2009-06-13 05:49 -------- d-----w- c:program filesHotspot Shield
- 2009-06-10 03:40 . 2009-06-10 03:41 -------- d-----w- c:program filesManyCam 2.4
- 2009-06-10 03:40 . 2009-06-10 03:41 -------- d-----w- c:documents and settingsCompaq_OwnerApplication DataManyCam
- 2009-06-09 23:12 . 2005-03-18 18:09 368640 ----a-w- c:windowssystem32ANIWZCS2.dll
- 2009-06-09 23:12 . 2005-03-17 00:09 143360 ----a-w- c:windowssystem32WlanApp.dll
- 2009-06-09 23:12 . 2005-02-22 20:53 221184 ----a-w- c:windowssystem32wlanapi.dll
- 2009-06-09 23:12 . 2005-02-18 16:31 212992 ----a-w- c:windowssystem32aIPH.dll
- 2009-06-09 23:12 . 2004-11-23 13:34 1323095 ----a-w- c:windowssystem32odSupp_M.dll
- 2009-06-09 23:12 . 2004-10-22 18:42 57407 ----a-w- c:windowssystem32ANICtl.dll
- 2009-06-09 23:12 . 2004-10-22 18:42 49152 ----a-w- c:windowssystem32AQCKGen.dll
- 2009-06-09 23:12 . 2004-07-27 16:20 36864 ----a-w- c:windowssystem32ANIOApi.dll
- 2009-06-09 23:12 . 2004-07-27 16:20 28205 ----a-w- c:windowssystem32ANIO.sys
- 2009-06-09 23:12 . 2004-07-27 16:20 11904 ----a-w- c:windowssystem32anio4.sys
- 2009-06-09 23:12 . 2009-06-09 23:12 -------- d-----w- c:program filesANI
- 2009-06-09 23:12 . 2009-06-09 23:12 -------- d-----w- c:program filesD-Link
- 2009-06-09 21:25 . 2009-06-09 21:25 11861 ----a-w- c:windowssystem32driversmdc8021x.sys
- 2009-06-09 21:24 . 2009-06-09 21:24 -------- d-----w- c:program filesD-Link AirPlus Xtreme G
- 2009-06-09 21:24 . 2003-12-19 19:06 351776 ----a-w- c:windowssystem32driversar52119x.sys
- 2009-06-09 21:24 . 2003-12-19 19:05 351840 ----a-w- c:windowssystem32driversar5211.sys
- 2009-06-09 21:24 . 2003-10-28 15:34 114688 ----a-w- c:windowssystem32athcfg10.dll
- 2009-06-09 21:24 . 2003-06-01 01:10 327680 ----a-r- c:windowssystem32AegisE2.dll
- 2009-06-09 21:24 . 2003-06-01 01:10 450560 ----a-r- c:windowssystem32AegisE5.dll
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2009-07-08 13:40 . 2007-12-24 05:12 -------- d-----w- c:documents and settingsAll UsersApplication DataGoogle Updater
- 2009-07-08 03:05 . 2006-12-08 23:25 -------- d-----w- c:program filesQuickTime
- 2009-07-08 03:05 . 2008-05-11 05:44 -------- d-----w- c:program filesCommon FilesApple
- 2009-07-08 02:43 . 2008-01-06 22:29 -------- d-----w- c:documents and settingsCompaq_OwnerApplication Datagtk-2.0
- 2009-07-07 04:51 . 2007-05-13 03:07 -------- d-----w- c:documents and settingsCompaq_OwnerApplication DataAzureus
- 2009-07-05 22:39 . 2009-06-01 13:09 -------- d-----w- c:program filesCrayon Physics Deluxe
- 2009-06-25 02:23 . 2008-07-19 19:17 34 ----a-w- c:documents and settingsCompaq_Ownerjagex_runescape_preferences.dat
- 2009-06-22 19:50 . 2007-02-01 22:34 -------- d-----w- c:program filesAIM6
- 2009-06-22 19:40 . 2006-09-25 02:17 -------- d-----w- c:documents and settingsAll UsersApplication DataViewpoint
- 2009-06-22 19:26 . 2007-02-01 22:32 -------- d-----w- c:documents and settingsAll UsersApplication DataAOL Downloads
- 2009-06-20 04:23 . 2006-09-25 03:17 64992 ----a-w- c:documents and settingsCompaq_OwnerLocal SettingsApplication DataGDIPFONTCACHEV1.DAT
- 2009-06-20 00:41 . 2006-09-26 02:43 -------- d-----w- c:program filesGoogle
- 2009-06-10 03:41 . 2008-09-20 00:49 -------- d-----w- c:program filesManyCam 2.3
- 2009-06-09 23:15 . 2006-08-01 18:47 -------- d--h--w- c:program filesInstallShield Installation Information
- 2009-06-09 03:45 . 2008-09-26 00:51 -------- d-----w- c:program filesSprint music manager
- 2009-06-08 20:46 . 2006-11-30 22:48 -------- d-----w- c:program filesShortKeys2
- 2009-06-08 02:49 . 2009-02-24 06:07 -------- d-----w- c:program filesNavNet
- 2009-06-08 02:49 . 2009-06-08 02:49 -------- d-----w- c:program filesNavNetApp
- 2009-06-08 02:49 . 2009-06-08 02:49 -------- d-----w- c:documents and settingsCompaq_OwnerApplication DataNavNet Solutions
- 2009-06-04 22:51 . 2008-06-11 21:30 -------- d-----w- c:documents and settingsCompaq_OwnerApplication DatamIRC
- 2009-06-04 17:01 . 2009-06-04 17:01 -------- d-----w- c:program filesmIRC
- 2009-06-02 15:44 . 2009-06-02 15:43 -------- d-----w- c:program filesChains
- 2009-06-01 18:13 . 2009-06-01 18:13 33840 ----a-w- c:windowssystem32driversHssDrv.sys
- 2009-06-01 14:24 . 2009-06-01 14:24 -------- d-----w- c:documents and settingsCompaq_OwnerApplication DataAtari
- 2009-06-01 14:14 . 2009-06-01 14:14 -------- d-----w- c:program filesAtari
- 2009-06-01 13:10 . 2009-06-01 13:09 -------- d-----w- c:documents and settingsCompaq_OwnerApplication DataCrayon Physics Deluxe
- 2009-05-31 14:16 . 2009-05-31 14:16 -------- d-----w- c:program files7-Zip
- 2009-05-30 18:41 . 2009-03-24 22:25 -------- d-----w- c:program filesAIMTunes
- 2009-05-30 01:14 . 2008-04-08 21:29 -------- d-----w- c:program filesElectronic Arts
- 2009-05-30 00:56 . 2008-03-03 04:52 7114736 ----a-w- c:documents and settingsCompaq_OwnerApplication DataAzureuspluginsazempazmplay.exe
- 2009-05-29 19:14 . 2009-05-29 19:14 -------- d-----w- c:program filesWindows Media Connect 2
- 2009-05-28 14:24 . 2007-11-28 16:44 -------- d-----w- c:program filesCommon FilesWise Installation Wizard
- 2009-05-24 17:31 . 2009-05-24 17:31 410984 ----a-w- c:windowssystem32deploytk.dll
- 2009-05-24 17:31 . 2006-08-01 18:17 -------- d-----w- c:program filesJava
- 2009-05-24 17:30 . 2009-05-24 17:30 152576 ----a-w- c:documents and settingsCompaq_OwnerApplication DataSunJavajre1.6.0_13lzma.dll
- 2009-05-22 02:51 . 2007-08-20 23:04 -------- d-----w- c:program filesMSN Messenger
- 2009-05-22 02:50 . 2009-05-22 02:50 -------- d-----w- c:program filesMicrosoft
- 2009-05-22 02:49 . 2009-05-22 02:49 -------- d-----w- c:program filesWindows Live SkyDrive
- 2009-05-22 02:49 . 2008-02-14 03:18 -------- d-----w- c:program filesWindows Live
- 2009-05-22 02:36 . 2009-05-22 02:36 -------- d-----w- c:program filesCommon FilesWindows Live
- 2009-05-19 06:36 . 2009-06-22 19:26 2884832 ----a-w- c:documents and settingsAll UsersApplication DataAOL DownloadsSUD4426vwpt.exe
- 2009-05-19 06:36 . 2009-06-22 19:26 28 ----a-w- c:documents and settingsAll UsersApplication DataAOL DownloadsSUD4426unregister.bat
- 2009-05-19 06:36 . 2009-06-22 19:26 25 ----a-w- c:documents and settingsAll UsersApplication DataAOL DownloadsSUD4426
- egister.bat
- 2009-05-19 06:36 . 2009-06-22 19:26 1484856 ----a-w- c:documents and settingsAll UsersApplication DataAOL DownloadsSUD4426 oolbar.exe
- 2009-05-19 06:36 . 2009-06-22 19:26 97072 ----a-w- c:documents and settingsAll UsersApplication DataAOL DownloadsSUD4426setutil.exe
- 2009-05-19 06:36 . 2009-06-22 19:26 142040 ----a-w- c:documents and settingsAll UsersApplication DataAOL DownloadsSUD4426alsetup.exe
- 2009-05-19 06:36 . 2009-06-22 19:26 30512 ----a-w- c:documents and settingsAll UsersApplication DataAOL DownloadsSUD4426Uninstaller.exe
- 2009-05-19 06:36 . 2009-06-22 19:26 111920 ----a-w- c:documents and settingsAll UsersApplication DataAOL DownloadsSUD4426AOLSearch.dll
- 2009-05-18 03:47 . 2008-05-22 01:14 -------- d-----w- c:program filesRealtek
- 2009-05-13 01:41 . 2009-05-13 01:41 -------- d-----w- c:program filesOGPlanet
- 2009-05-12 00:40 . 2008-02-19 22:36 -------- d-----w- c:program filesXfire
- 2009-05-11 21:35 . 2008-02-19 22:36 -------- d-----w- c:documents and settingsCompaq_OwnerApplication DataXfire
- 2009-05-11 21:09 . 2007-12-25 23:28 138168 ----a-w- c:windowssystem32driversPnkBstrK.sys
- 2009-05-11 21:09 . 2007-12-25 23:27 189472 ----a-w- c:windowssystem32PnkBstrB.exe
- 2009-05-11 04:32 . 2007-12-25 23:26 75064 ----a-w- c:windowssystem32PnkBstrA.exe
- 2009-05-10 05:49 . 2009-05-10 05:48 -------- d-----w- c:program filesJFK Reloaded
- 2009-05-07 15:44 . 2009-02-05 03:46 344064 ----a-w- c:windowssystem32localspl.dll
- 2009-05-06 18:11 . 2009-05-06 18:11 69120 ----a-w- c:documents and settingsAll UsersApplication DataAIM ToolbarieToolbar
- esourcesen-USaimtbres.dll
- 2009-05-04 01:16 . 2004-05-20 01:38 36864 ----a-w- c:windowssystem32DirSize.dll
- 2009-04-29 21:19 . 2009-04-29 21:19 41808 ----a-w- c:windowssystem32xfcodec.dll
- 2009-04-17 09:58 . 2009-02-05 03:46 1846656 ----a-w- c:windowssystem32win32k.sys
- 2009-04-15 15:11 . 2009-02-05 03:47 584192 ----a-w- c:windowssystem32
- pcrt4.dll
- 2009-04-11 18:16 . 2009-04-11 18:16 10134 ----a-r- c:documents and settingsCompaq_OwnerApplication DataMicrosoftInstaller{EA0B63C1-E579-43DD-A5F7-0DA5E9092554}ARPPRODUCTICON.exe
- 2008-06-20 21:19 . 2008-06-20 21:19 124821 ----a-w- c:program filesCrates.rar
- 2008-05-08 21:32 . 2008-05-08 21:32 390 ----a-w- c:program filesShortcut to Program Files.lnk
- 2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:program filesmozilla firefoxpluginslibdivx.dll
- 2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:program filesmozilla firefoxpluginsssldivx.dll
- 1601-01-01 00:12 . 1601-01-01 00:12 65621 --sha-w- c:windowssystem32gupurida.dll.tmp
- 1601-01-01 00:12 . 1601-01-01 00:12 61665 --sha-w- c:windowssystem32liwuwuto.dll.tmp
- 1601-01-01 00:12 . 1601-01-01 00:12 65753 --sha-w- c:windowssystem32
- ajohura.dll.tmp
- 2009-01-10 04:18 . 2009-01-10 04:18 2713 --sh--w- c:windowssystem32
- emiseza.exe
- 1601-01-01 00:12 . 1601-01-01 00:12 61665 --sha-w- c:windowssystem32pasurimu.dll.tmp
- 1601-01-01 00:12 . 1601-01-01 00:12 65621 --sha-w- c:windowssystem32
- owirisa.dll.tmp
- 1601-01-01 00:12 . 1601-01-01 00:12 65753 --sha-w- c:windowssystem32vifabihu.dll.tmp
- 1601-01-01 00:12 . 1601-01-01 00:12 65621 --sha-w- c:windowssystem32wufewoga.dll.tmp
- 1601-01-01 00:12 . 1601-01-01 00:12 65753 --sha-w- c:windowssystem32yubiwojo.dll.tmp
- .
- ((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2008-08-31 07:03 . 2009-03-24 22:27 172 c:documents and settingsCompaq_OwnerMy DocumentsOpenLieroX_0.57_beta8.win32OpenLieroXNarutoNT-1.26gfxakci.png
- 2008-08-31 07:03 . 2009-03-24 22:27 195 c:documents and settingsCompaq_OwnerMy DocumentsOpenLieroX_0.57_beta8.win32OpenLieroXNarutoNT-1.26gfxakcir.png
- 2008-08-31 07:03 . 2009-03-24 22:27 350 c:documents and settingsCompaq_OwnerMy DocumentsOpenLieroX_0.57_beta8.win32OpenLieroXNarutoNT-1.26gfxakcswall.png
- 2008-08-31 07:03 . 2009-03-24 22:27 6078 c:documents and settingsCompaq_OwnerMy DocumentsOpenLieroX_0.57_beta8.win32OpenLieroXNarutoNT-1.26gfxakDshield.png
- 2008-08-31 07:03 . 2009-03-24 22:27 255 c:documents and settingsCompaq_OwnerMy DocumentsOpenLieroX_0.57_beta8.win32OpenLieroXNarutoNT-1.26gfxakheal2.png
- 2008-08-31 07:03 . 2009-03-24 22:27 236 c:documents and settingsCompaq_OwnerMy DocumentsOpenLieroX_0.57_beta8.win32OpenLieroXNarutoNT-1.26gfxakmbtsfall.png
- 2008-08-31 07:03 . 2009-03-24 22:27 5758 c:documents and settingsCompaq_OwnerMy DocumentsOpenLieroX_0.57_beta8.win32OpenLieroXNarutoNT-1.26gfxakmirrors.png
- 2008-08-31 07:03 . 2009-03-24 22:27 12320 c:documents and settingsCompaq_OwnerMy DocumentsOpenLieroX_0.57_beta8.win32OpenLieroXNarutoNT-1.26gfxak hick4.png
- 2008-08-31 07:03 . 2009-03-24 22:27 1749 c:documents and settingsCompaq_OwnerMy DocumentsOpenLieroX_0.57_beta8.win32OpenLieroXNarutoNT-1.26gfxakwhirl1.png
- 2007-10-04 15:20 . 2007-10-04 15:20 50528 c:program filesAIM6akaim6.exe
- 2009-05-19 05:23 . 2009-05-19 05:23 49968 c:program filesAIM6aim6.exe
- 2007-05-15 02:16 . 2007-12-04 13:00 79224 c:program filesAlwil SoftwareAvast4akashDisp.exe
- 2007-05-15 02:16 . 2008-11-26 17:18 81000 c:program filesAlwil SoftwareAvast4ashDisp.exe
- 2005-02-17 13:11 . 2005-02-17 13:11 49152 c:program filesHPHP Software UpdateakHPwuSchd2.exe
- 2008-01-21 18:50 . 2007-09-25 07:11 132496 c:program filesJavajre1.6.0_03inakjusched.exe
- 2007-06-13 20:21 . 2005-06-08 23:24 458752 c:program filesLogitechVideoakISStart.exe
- 2007-06-13 20:21 . 2005-06-08 23:14 217088 c:program filesLogitechVideoakLogiTray.exe
- 2007-06-13 20:21 . 2005-06-08 22:44 196608 c:program filesLogitechVideoakManifestEngine.exe
- 2006-12-08 23:25 . 2008-01-27 07:32 385024 c:program filesQuickTimeakqttask.exe
- 2007-10-18 17:34 . 2007-10-18 17:34 5724184 c:program filesWindows LiveMessengerakMsnMsgr.Exe
- 2009-02-06 23:51 . 2009-02-06 23:51 3885408 c:program filesWindows LiveMessengermsnmsgr.exe
- 2006-08-01 18:51 . 2004-12-14 09:23 663552 c:windowsCREATORakRemind_XP.exe
- 2006-08-01 18:51 . 2005-07-23 05:14 237568 c:windowsSMINSTakRECGUARD.EXE
- 2005-07-20 01:32 . 2005-07-20 01:32 221184 c:windowssystem32akLVCOMSX.EXE
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- [HKEY_LOCAL_MACHINE~Browser Helper Objects{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
- 2009-06-13 05:49 218160 ----a-w- c:program filesHotspot ShieldhssieHssIE.dll
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers1TortoiseNormal]
- @="{C5994560-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOTCLSID{C5994560-53D9-4125-87C9-F193FC689CB2}]
- 2008-01-16 22:52 80384 ----a-w- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers2TortoiseModified]
- @="{C5994561-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOTCLSID{C5994561-53D9-4125-87C9-F193FC689CB2}]
- 2008-01-16 22:52 80384 ----a-w- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers3TortoiseConflict]
- @="{C5994562-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOTCLSID{C5994562-53D9-4125-87C9-F193FC689CB2}]
- 2008-01-16 22:52 80384 ----a-w- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers4TortoiseLocked]
- @="{C5994563-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOTCLSID{C5994563-53D9-4125-87C9-F193FC689CB2}]
- 2008-01-16 22:52 80384 ----a-w- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers5TortoiseReadOnly]
- @="{C5994564-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOTCLSID{C5994564-53D9-4125-87C9-F193FC689CB2}]
- 2008-01-16 22:52 80384 ----a-w- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers6TortoiseDeleted]
- @="{C5994565-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOTCLSID{C5994565-53D9-4125-87C9-F193FC689CB2}]
- 2008-01-16 22:52 80384 ----a-w- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers7TortoiseAdded]
- @="{C5994566-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOTCLSID{C5994566-53D9-4125-87C9-F193FC689CB2}]
- 2008-01-16 22:52 80384 ----a-w- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers8TortoiseIgnored]
- @="{C5994567-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOTCLSID{C5994567-53D9-4125-87C9-F193FC689CB2}]
- 2008-01-16 22:52 80384 ----a-w- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers9TortoiseUnversioned]
- @="{C5994568-53D9-4125-87C9-F193FC689CB2}"
- [HKEY_CLASSES_ROOTCLSID{C5994568-53D9-4125-87C9-F193FC689CB2}]
- 2008-01-16 22:52 80384 ----a-w- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- [HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
- "Aim6"="c:program filesAIM6aim6.exe" [2009-05-19 49968]
- "msnmsgr"="c:program filesWindows LiveMessengermsnmsgr.exe" [2009-02-06 3885408]
- "DAEMON Tools Lite"="c:program filesDAEMON Tools Litedaemon.exe" [2008-03-21 486856]
- "Google Update"="c:documents and settingsCompaq_OwnerLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe" [2008-12-11 133104]
- "Steam"="c:steamsteam.exe" [2009-06-12 1217784]
- "Yahoo! Pager"="c:program filesYahoo!MessengerYahooMessenger.exe" [2007-08-30 4670704]
- "igndlm.exe"="c:program filesDownload ManagerDLM.exe" [2008-08-01 1103216]
- "ManyCam"="c:program filesManyCam 2.4ManyCam.exe" [2009-04-17 1824040]
- "LowRiskFileTypes"="c:windowssysguard.exe" [N/A]
- [HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
- "avast!"="c:progra~1ALWILS~1Avast4ashDisp.exe" [2008-11-26 81000]
- "TkBellExe"="c:program filesCommon FilesRealUpdate_OB
- ealsched.exe" [2006-08-01 180269]
- "WinampAgent"="c:program filesWinampwinampa.exe" [2008-04-01 36352]
- "SunJavaUpdateSched"="c:program filesJavajre6injusched.exe" [2009-05-24 148888]
- "HPDJ Taskbar Utility"="c:windowssystem32spooldriversw32x863hpztsb11.exe" [2006-01-07 172032]
- "HPHUPD06"="c:program filesHP{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}hphupd06.exe" [2006-01-07 49152]
- "HP Component Manager"="c:program filesHPhpcoretechhpcmpmgr.exe" [2004-05-12 241664]
- "HPHmon06"="c:windowssystem32hphmon06.exe" [2006-01-07 659456]
- "NvCplDaemon"="c:windowssystem32NvCpl.dll" [2008-07-26 13570048]
- "NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2008-07-26 86016]
- "D-Link AirPlus XtremeG"="c:program filesD-LinkAirPlus XtremeGAirPlusCFG.exe" [2005-03-28 1011712]
- "ANIWZCS2Service"="c:program filesANIANIWZCS2 ServiceWZCSLDR2.exe" [2004-12-16 49152]
- "PCDrProfiler"="" [N/A]
- "nwiz"="nwiz.exe" - c:windowssystem32
- wiz.exe [2008-07-26 1657376]
- "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:windowsKHALMNPR.Exe [2007-04-11 56080]
- "RTHDCPL"="RTHDCPL.EXE" - c:windowsRTHDCPL.exe [2006-07-21 16261632]
- c:documents and settingsAdministratorStart MenuProgramsStartup
- Pin.lnk - c:hpinCLOAKER.EXE [2006-8-1 27136]
- c:documents and settingsAll UsersStart MenuProgramsStartup
- D-Link AirPlus Xtreme G Configuration Utility.lnk - c:program filesD-Link AirPlus Xtreme GAirPlus.exe [2009-6-9 512077]
- D-Link REG Utility.lnk - c:program filesD-Link AirPlus Xtreme GReg.exe [2009-6-9 24576]
- HP Digital Imaging Monitor.lnk - c:program filesHPDigital Imaginginhpqtra08.exe [2004-5-28 241664]
- hpoddt01.exe.lnk - c:program filesHPDigital Imaginginhpotdd01.exe [2003-4-9 28672]
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWdfLoadGroup]
- @=""
- [HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWinDefend]
- @="Service"
- path=
- backup=
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
- "UpdatesDisableNotify"=dword:00000001
- [HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecFirewall]
- "DisableMonitoring"=dword:00000001
- [HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
- "%windir%\system32\sessmgr.exe"=
- "c:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe"=
- "c:\Program Files\LimeWire\LimeWire.exe"=
- "c:\Program Files\EA GAMES\Battlefield 2\BF2.exe"=
- "c:\Program Files\EA GAMES\Battlefield 2\bf2_w32ded.exe"=
- "c:\Program Files\Common Files\AOL\Loader\aolload.exe"=
- "c:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe"=
- "c:\Program Files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe"=
- "c:\Program Files\Xfire\xfire.exe"=
- "c:\Program Files\Azureus\Azureus.exe"=
- "c:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"=
- "c:\Program Files\Yahoo!\Messenger\YServer.exe"=
- "c:\Program Files\Electronic Arts\Battlefield 2142 Deluxe Edition\BF2142.exe"=
- "c:\Program Files\Bonjour\mDNSResponder.exe"=
- "c:\Program Files\iTunes\iTunes.exe"=
- "c:\Program Files\TortoiseSVN\bin\TortoiseMerge.exe"=
- "c:\Program Files\TortoiseSVN\bin\TortoiseIDiff.exe"=
- "c:\Program Files\Messenger\msmsgs.exe"=
- "c:\Program Files\IEPro\MiniDM.exe"=
- "c:\Program Files\mIRC\mirc.exe"=
- "c:\Program Files\Electronic Arts\EADM\Core.exe"=
- "c:\Steam\steamapps\smithno13\garrysmod\hl2.exe"=
- "c:\Steam\steamapps\smithno13\team fortress 2\hl2.exe"=
- "c:\Steam\steamapps\smithno13\half-life 2 deathmatch\hl2.exe"=
- "c:\Steam\Steam.exe"=
- "c:\Program Files\AIM6\aim6.exe"=
- "c:\Documents and Settings\Compaq_Owner\My Documents\OpenLieroX_0.57_beta8.win32\OpenLieroX\OpenLieroX.exe"=
- "c:\Program Files\Tencent\QQ Games\QQGames.exe"=
- "c:\Program Files\Tencent\QQ Games\QQGamesD.exe"=
- "c:\Program Files\Tencent\QQ Games\Update\Update.exe"=
- "c:\Soldat\Soldat.exe"=
- "c:\Program Files\Skype\Phone\Skype.exe"=
- "c:\Steam\steamapps\smithno13\counter-strike source\hl2.exe"=
- "c:\Program Files\Ventrilo\Ventrilo.exe"=
- "c:\Program Files\CCP\EVE\bin\ExeFile.exe"=
- "c:\WINDOWS\system32\dpvsetup.exe"=
- "c:\Program Files\Windows Live\Messenger\wlcsdk.exe"=
- "c:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
- "c:\Program Files\Java\jre6\bin\java.exe"=
- R1 aswSP;avast! Self Protection;c:windowssystem32driversaswSP.sys [2009-01-12 111184]
- R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [2009-01-12 20560]
- R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:program filesFirebirdFirebird_1_5infbguard.exe -s --> c:program filesFirebirdFirebird_1_5infbguard.exe -s [?]
- R2 HssSrv;Hotspot Shield Routing Service;c:program filesHotspot ShieldHssWPRhsssrv.exe [2009-06-01 331312]
- R2 SentinelKeysServer;Sentinel Keys Server;c:program filesCommon FilesSafeNet SentinelSentinel Keys Serversntlkeyssrvr.exe [2007-04-27 316992]
- R2 Viewpoint Manager Service;Viewpoint Manager Service;c:program filesViewpointCommonViewpointService.exe [2008-02-02 24652]
- R2 WinDefend;Windows Defender;c:program filesWindows DefenderMsMpEng.exe [2006-11-03 13592]
- R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:windowssystem32driversA3AB.sys [2005-03-22 450400]
- R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:program filesFirebirdFirebird_1_5infbserver.exe -s --> c:program filesFirebirdFirebird_1_5infbserver.exe -s [?]
- R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:windowssystem32driversManyCam.sys [2008-01-14 21632]
- S2 gupdate1c99b99b8455d68;Google Update Service (gupdate1c99b99b8455d68);c:program filesGoogleUpdateGoogleUpdate.exe [2009-03-02 133104]
- S3 HssTrayService;Hotspot Shield Tray Service;c:program filesHotspot ShieldinHssTrayService.exe [2009-06-01 34352]
- S3 Revolution1;Revolution1;??c:documents and settingsCompaq_OwnerMy DocumentsProgram FilesSHAK3.sys --> c:documents and settingsCompaq_OwnerMy DocumentsProgram FilesSHAK3.sys [?]
- S3 XDva279;XDva279;??c:windowssystem32XDva279.sys --> c:windowssystem32XDva279.sys [?]
- .
- Contents of the 'Scheduled Tasks' folder
- 2009-07-03 c:windowsTasksAppleSoftwareUpdate.job
- - c:program filesApple Software UpdateSoftwareUpdate.exe [2008-07-30 18:34]
- 2009-07-09 c:windowsTasksGoogle Software Updater.job
- - c:program filesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe [2007-01-27 23:36]
- 2009-07-09 c:windowsTasksGoogleUpdateTaskMachineCore.job
- - c:program filesGoogleUpdateGoogleUpdate.exe [2009-03-03 00:47]
- 2009-07-09 c:windowsTasksGoogleUpdateTaskMachineUA.job
- - c:program filesGoogleUpdateGoogleUpdate.exe [2009-03-03 00:47]
- 2009-07-08 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-3118088493-1253333802-4265547694-1008Core.job
- - c:documents and settingsCompaq_OwnerLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2008-12-11 13:51]
- 2009-07-09 c:windowsTasksGoogleUpdateTaskUserS-1-5-21-3118088493-1253333802-4265547694-1008UA.job
- - c:documents and settingsCompaq_OwnerLocal SettingsApplication DataGoogleUpdateGoogleUpdate.exe [2008-12-11 13:51]
- 2009-07-09 c:windowsTasksHP Usg Daily FY04.job
- - c:program filesHP{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}pexpresshphped06.exe [2008-08-31 05:09]
- 2009-07-09 c:windowsTasksMP Scheduled Scan.job
- - c:program filesWindows DefenderMpCmdRun.exe [2006-11-04 01:20]
- 2009-07-09 c:windowsTasksRegCure Program Check.job
- - c:program filesRegCureRegCure.exe [2008-04-21 21:21]
- 2009-07-02 c:windowsTasksRegCure.job
- - c:program filesRegCureRegCure.exe [2008-04-21 21:21]
- .
- - - - - ORPHANS REMOVED - - - -
- BHO-{2526f901-5c73-4ecd-a08b-e38a95c8e03c} - c:windowssystem32kedisuzo.dll
- BHO-{738BD188-30E9-4BAC-8FD9-F1DE6A4795D3} - c:windowssystem32pmnnKBRl.dll
- BHO-{B5C62226-0364-4DD9-89CE-707A8D641EEA} - c:windowssystem32yaywUOiJ.dll
- Notify-dimsntfy - (no file)
- Notify-pmnoNGvU - pmnoNGvU.dll
- Notify-rqRLeFvU - rqRLeFvU.dll
- .
- ------- Supplementary Scan -------
- .
- uStart Page = hxxp://www.gaiaonline.com/
- IE: &AIM Toolbar Search - c:documents and settingsAll UsersApplication DataAIM ToolbarieToolbar
- esourcesen-USlocalsearch.html
- IE: E&xport to Microsoft Excel - c:progra~1MICROS~4Office10EXCEL.EXE/3000
- Handler: navnet - {AD6E5643-7B0C-46AA-95AD-9773FF2A857A} - c:program filesNavNetAppComUtilities.dll
- DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} - hxxp://202.213.247.128/kxhcm10.ocx
- DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxp://play.battlefield-heroes.com/static/updater/BFHUpdater_4.0.11.0.cab
- DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
- DPF: {C4F22FDF-697D-4925-A566-FC9CD1CEBD37} - hxxp://www.magnificentgizmosandgadgets.com/ActiveX/methodloader.cab
- FF - ProfilePath - c:documents and settingsCompaq_OwnerApplication DataMozillaFirefoxProfilesob6msbu7.default
- FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
- FF - prefs.js: browser.search.selectedEngine - AIM Search
- FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
- FF - component: c:program filesGoogleGoogle GearsFirefoxcomponentsgears.dll
- FF - plugin: c:documents and settingsCompaq_OwnerApplication DataMozillaFirefoxProfilesob6msbu7.defaultextensionsattlefieldheroespatcher@ea.complatformWINNT_x86-msvcplugins
- pBFHUpdater.dll
- FF - plugin: c:documents and settingsCompaq_OwnerLocal SettingsApplication DataGoogleUpdate1.2.183.7
- pGoogleOneClick8.dll
- FF - plugin: c:program filesDownload Manager
- pfpdlm.dll
- FF - plugin: c:program filesGoogleGoogle Updater2.4.1536.6592
- pCIDetect13.dll
- FF - plugin: c:program filesGoogleUpdate1.2.183.7
- pGoogleOneClick8.dll
- FF - plugin: c:program filesMicrosoft Silverlight2.0.40115.0
- pctrl.1.0.21115.0.dll
- FF - plugin: c:program filesMozilla Firefoxplugins
- pViewpoint.dll
- FF - plugin: c:program filesUnityWebPlayerloader
- pUnity3D32.dll
- FF - plugin: c:program filesVeoh NetworksVeohPlugins
- oregNPVeohVersion.dll
- FF - plugin: c:program filesViewpointViewpoint Media Player
- pViewpoint.dll
- .
- **************************************************************************
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2009-07-08 23:48
- Windows 5.1.2600 Service Pack 2 NTFS
- scanning hidden processes ...
- scanning hidden autostart entries ...
- scanning hidden files ...
- c:docume~1COMPAQ~1LOCALS~1Tempjusched.log 399 bytes
- scan completed successfully
- hidden files: 1
- **************************************************************************
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- [HKEY_USERSS-1-5-21-3118088493-1253333802-4265547694-1008SoftwareSecuROM!CAUTION! NEVER A OR CHANGE ANY KEY*]
- "??"=hex:65,a0,f0,03,fa,d2,c9,64,d2,bd,d6,3f,e1,8d,b5,f8,4f,9c,18,c4,43,56,64,
- 51,de,56,ac,33,a8,15,4c,91,b4,1b,da,37,d8,ef,d4,3f,94,c3,1a,25,ad,a4,d7,94,
- "??"=hex:3f,eb,b2,a8,d5,51,4b,c2,1b,01,ec,08,0f,18,11,95
- [HKEY_USERSS-1-5-21-3118088493-1253333802-4265547694-1008SoftwareSecuROMLicense information*]
- "datasecu"=hex:ce,c8,cc,e7,e2,ff,b5,e5,39,de,34,33,1d,e7,d8,bc,7f,cf,04,47,b0,
- c7,ca,ad,5d,3c,d1,8b,59,ff,4a,21,93,7b,c0,f9,73,71,3a,f4,d5,d9,70,50,b2,15,
- "rkeysecu"=hex:17,0c,8b,a8,75,cb,05,56,56,b0,06,85,72,9c,ba,40
- .
- --------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - - > 'explorer.exe'(2232)
- c:windowssystem32
- view.dll
- c:program filesCommon FilesTortoiseOverlaysTortoiseOverlays.dll
- c:program filesTortoiseSVNinTortoiseStub.dll
- c:program filesTortoiseSVNinTortoiseSVN.dll
- c:program filesTortoiseSVNinintl3_tsvn.dll
- c:windowssystem32ieframe.dll
- c:windowssystem32webcheck.dll
- c:windowssystem32WPDShServiceObj.dll
- c:windowssystem32PortableDeviceTypes.dll
- c:windowssystem32PortableDeviceApi.dll
- c:windowssystem32xpsp3res.dll
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:program filesAlwil SoftwareAvast4aswUpdSv.exe
- c:program filesAlwil SoftwareAvast4ashServ.exe
- c:program filesGoogleUpdate1.2.183.7GoogleCrashHandler.exe
- c:program filesCommon FilesAppleMobile Device SupportinAppleMobileDeviceService.exe
- c:program filesBonjourmDNSResponder.exe
- c:windowssystem32CTSVCCDA.EXE
- c:program filesFirebirdFirebird_1_5infbguard.exe
- c:program filesHotspot Shieldinopenvpnas.exe
- c:program filesJavajre6injqs.exe
- c:windowssystem32
- vsvc32.exe
- c:windowssystem32PnkBstrA.exe
- c:windowssystem32PnkBstrB.exe
- c:program filesCommon FilesSafeNet SentinelSentinel Protection ServerWinNTspnsrvnt.exe
- c:program filesTortoiseSVNinTSVNCache.exe
- c:windowssystem32
- undll32.exe
- c:windowssystem32
- undll32.exe
- c:program filesAlwil SoftwareAvast4ashMaiSv.exe
- c:windowssystem32wscntfy.exe
- c:program filesAlwil SoftwareAvast4ashWebSv.exe
- c:program filesFirebirdFirebird_1_5infbserver.exe
- c:documents and settingsCompaq_OwnerLocal SettingsApplication DataGoogleUpdate1.2.183.7GoogleCrashHandler.exe
- c:program filesHotspot Shieldinopenvpntray.exe
- c:program filesYahoo!MessengerYmsgr_tray.exe
- c:program filesAIM6aolsoftware.exe
- .
- **************************************************************************
- .
- Completion time: 2009-07-09 0:10 - machine was rebooted
- ComboFix-quarantined-files.txt 2009-07-09 05:10
- ComboFix2.txt 2008-10-26 04:34
- Pre-Run: 7,621,197,824 bytes free
- Post-Run: 9,571,409,920 bytes free
- 449 --- E O F --- 2009-07-08 08:01
Edit code: here. | Add this PasteBin to your website. | Report abuse.
Pasted as text by Nick on Thursday, July 9th, 2009 3:13pm