That was relatively painless.
ComboFix 09-07-07.A2 - Owner 07/07/2009 19:53.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1982.1576 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\MSIVXxbqipdpbnmdbyrvir klrbfpyoqpxmbpf.sys
c:\windows\system32\launcher.exe
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXptspybndqlkmiqhwmogpevirb fffdchr.dll
c:\windows\system32\MSIVXqjxjebcfsxvfoowfwiwuqgsaj qevstym.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MSIVXserv.sys
((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
.
2009-07-06 20:24 . 2009-07-06 20:24 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-07-06 12:26 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-06 12:26 . 2009-07-06 12:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-06 12:26 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-06 05:11 . 2009-07-06 21:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-04 16:10 . 2009-07-07 10:26 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-01 12:58 . 2009-07-01 12:58 -------- d-----w- c:\documents and settings\Owner\Application Data\AVG8
2009-06-27 23:54 . 2009-04-10 13:58 6327408 ---ha-w- c:\documents and settings\Owner\Application Data\mjusbsp\in00000\setup.exe
2009-06-27 23:54 . 2009-04-10 13:55 725296 ---ha-w- c:\documents and settings\Owner\Application Data\mjusbsp\ar00000\install.exe
2009-06-27 23:54 . 2008-02-29 12:42 386496 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\ar00000\magicJackSplash.exe
2009-06-27 23:52 . 2009-04-10 13:58 6327408 ---ha-w- c:\documents and settings\Owner\Application Data\mjusbsp\Upgrade\setup2.exe
2009-06-27 23:52 . 2009-04-10 13:55 725296 ---ha-w- c:\documents and settings\Owner\Application Data\mjusbsp\Upgrade\install2.exe
2009-06-21 04:37 . 2009-06-21 04:37 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-06-20 04:39 . 2009-06-21 04:57 -------- d-----w- c:\documents and settings\Owner\Application Data\Xfire
2009-06-20 04:39 . 2009-06-21 10:55 -------- d-----w- c:\program files\Xfire
2009-06-20 04:07 . 2009-06-20 04:07 -------- d-----w- c:\program files\Advanced Spyware Remover
2009-06-20 03:56 . 2009-06-20 03:56 -------- d-----w- c:\program files\Trend Micro
2009-06-20 03:29 . 2004-05-04 16:53 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2009-06-20 03:29 . 2009-06-20 03:29 -------- d-----w- c:\program files\BurnAware Free
2009-06-19 20:26 . 2009-06-19 20:28 -------- d-----w- c:\program files\Wise Registry Cleaner
2009-06-17 05:26 . 2009-06-17 05:26 -------- d-----w- c:\windows\system32\config\systemprofile\Applicati on Data\AdobeUM
2009-06-17 05:25 . 2009-06-17 05:25 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-06-17 05:24 . 2009-06-17 05:24 -------- d-----w- c:\windows\system32\config\systemprofile\Applicati on Data\Yahoo!
2009-06-13 22:58 . 2009-06-13 22:59 5525282 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\GameManager\GameDB\F5057T1L 1\setup_gF5057T1L1_d552754470_l1_s1.exe
2009-06-11 22:29 . 2009-06-11 22:29 41808 ----a-w- c:\windows\system32\xfcodec.dll
2009-06-10 02:11 . 2009-06-10 02:11 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-08 18:41 . 2009-06-08 18:41 -------- d-----w- c:\documents and settings\Owner\Application Data\ViquaSoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-07-07 23:30 . 2008-05-28 21:06 -------- d-----w- c:\program files\Mozilla Firefox 3
2009-07-06 12:33 . 2008-04-20 01:28 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-06 05:18 . 2007-06-15 16:53 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2009-07-01 23:58 . 2009-05-03 06:15 -------- d-----w- c:\program files\Sony Online Entertainment
2009-07-01 13:24 . 2008-06-25 14:51 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-07-01 12:57 . 2008-06-25 14:52 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-01 12:57 . 2008-06-25 14:52 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-01 12:57 . 2008-06-25 14:51 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-27 23:54 . 2008-06-05 11:00 -------- d-----w- c:\documents and settings\Owner\Application Data\mjusbsp
2009-06-20 17:18 . 2009-03-09 00:46 -------- d-----w- c:\program files\PopCap Games
2009-06-20 17:17 . 2009-01-05 23:18 -------- d-----w- c:\program files\MythwarII
2009-06-20 17:16 . 2007-07-19 17:17 -------- d-----w- c:\documents and settings\Owner\Application Data\Move Networks
2009-06-20 17:15 . 2008-10-31 20:04 -------- d-----w- c:\program files\Oberon Media
2009-06-20 17:14 . 2009-02-23 16:50 -------- d-----w- c:\program files\Galaxy Online
2009-06-20 04:32 . 2005-12-16 20:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-20 03:18 . 2009-02-13 13:21 -------- d-----w- c:\program files\CDBurnerXP
2009-06-19 22:23 . 2007-06-06 01:59 -------- d-----w- c:\documents and settings\Owner\Application Data\IGN_DLM
2009-06-19 20:04 . 2008-09-30 02:01 -------- d-----w- c:\program files\CCleaner
2009-06-16 01:19 . 2007-02-14 19:01 -------- d-----w- c:\documents and settings\Owner\Application Data\GetRightToGo
2009-06-14 13:08 . 2009-03-27 17:57 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-06-13 00:54 . 2007-06-06 01:59 -------- d-----w- c:\program files\Download Manager
2009-06-11 23:36 . 2009-03-27 17:57 -------- d-----w- c:\program files\bfgclient
2009-06-11 15:14 . 2009-05-19 02:52 -------- d-----w- c:\program files\Megaplex Madness - Now Playing
2009-06-10 02:13 . 2005-12-16 20:25 -------- d-----w- c:\program files\Java
2009-06-07 13:16 . 2007-07-04 03:33 -------- d-----w- c:\program files\Taldren
2009-05-26 23:30 . 2009-05-26 23:30 390664 ----a-w- c:\documents and settings\Owner\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-26 03:21 . 2009-05-26 03:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Slapdash Games
2009-05-21 15:33 . 2008-12-15 00:47 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-07 15:44 . 2008-08-27 05:37 344064 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 18:23 . 2009-05-07 05:03 372736 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jgnar59d.default\ext ensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes. dll
2009-05-01 14:10 . 2008-06-25 14:52 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-01 06:30 . 2009-05-01 06:30 97144 ----a-w- c:\documents and settings\Owner\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-04-29 04:31 . 2004-08-04 12:00 668160 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:31 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 09:58 . 2008-08-27 05:37 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:11 . 2004-08-04 12:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-10 13:58 . 2009-04-10 13:58 86360 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\ug00000\magicJack.dll
2009-04-10 13:58 . 2009-04-10 13:58 6327408 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\ug00000\setup.exe
2009-04-10 13:58 . 2009-04-10 13:58 412784 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\magicJackLoader.exe
2009-04-10 13:58 . 2009-04-10 13:58 480608 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\octvqe1_apiw.dll
2009-04-10 13:58 . 2009-04-10 13:58 214360 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\TjVista.dll
2009-04-10 13:58 . 2009-04-10 13:58 325040 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\TjIpSys.dll
2009-04-10 13:57 . 2009-04-10 13:57 398696 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\SJHandsetTigerJet.dll
2009-04-10 13:57 . 2009-04-10 13:57 87384 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\st00000\mjsetup.exe
2009-04-10 13:57 . 2009-04-10 13:57 86360 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\st00000\magicJack.dll
2009-04-10 13:57 . 2009-04-10 13:57 86360 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\magicJack.dll
2009-04-10 13:56 . 2009-04-10 13:56 11871576 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\magicJack.exe
2009-04-10 13:55 . 2009-04-10 13:55 725296 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\ug00000\install.exe
2009-04-10 13:55 . 2009-04-10 13:55 87384 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\in00000\mjsetup.exe
2009-04-10 13:55 . 2009-04-10 13:55 86360 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\in00000\magicJack.dll
2009-04-10 13:53 . 2009-04-10 13:53 456040 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2009-04-10 13:53 . 2009-04-10 13:53 456040 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\st00000\magicJackSplash.exe
2009-04-10 13:53 . 2009-04-10 13:53 456040 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\magicJackSplash.exe
2009-04-10 13:53 . 2009-04-10 13:53 456040 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\in00000\magicJackSplash.exe
2009-04-10 13:53 . 2009-04-10 13:53 50520 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe
2008-08-06 15:24 . 2008-08-06 15:24 0 ----a-w- c:\program files\temp01
2008-12-18 14:50 . 2005-12-16 20:15 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-18 14:50 . 2005-12-16 20:15 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-18 14:50 . 2007-09-24 16:59 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-18 14:50 . 2007-09-24 16:59 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-18 14:50 . 2005-12-16 20:15 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1BE275B-78BF-4A33-81AB-380699CFF329}]
2008-12-31 23:07 1249280 ----a-w- c:\program files\Gaia Online Toolbar\Toolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2009-04-10 50520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-11 13529088]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-01 1948440]
"Tarantula"="c:\program files\Razer\Tarantula\razerhid.exe" [2007-05-07 159744]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2008-04-11 86016]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-04-11 1630208]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
GA311 Smart Wizard Utility.lnk - c:\program files\NETGEAR GA311 Adapter\GA311.exe [2003-11-6 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-01 12:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^desktop_minion4260671805.lnk]
backup=c:\windows\pss\desktop_minion4260671805.lnk Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3 (0x3)
"IDriverT"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\p ol.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octosh ape.exe"=
"c:\\Program Files\\Vivox\\Voon for Ten Ton Hammer\\Voon.exe"=
"c:\\Program Files\\Puzzle Quest Galactrix\\Galactrix.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox 3\\firefox.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"20217:TCP"= 20217:TCP:BitComet 20217 TCP
"20217:UDP"= 20217:UDP:BitComet 20217 UDP
"48990:TCP"= 48990:TCP:utorrent
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [1/2/2008 11:08 PM 17920]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/25/2008 10:52 AM 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/25/2008 10:52 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2008 2:34 PM 906520]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/1/2009 10:10 AM 298776]
R2 LANPkt;Realtek LANPkt Protocol;c:\windows\system32\drivers\LANPkt.sys [9/17/2003 3:57 PM 8440]
R3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag 69xp.sys [8/15/2003 2:55 AM 11237]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [2/10/2008 12:37 AM 45440]
S3 XDva007;XDva007;\??\c:\windows\system32\XDva007.sy s --> c:\windows\system32\XDva007.sys [?]
.
- - - - ORPHANS REMOVED - - - -
Notify-dimsntfy - (no file)
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = <local>
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download All by FlashGet - c:\program files\FlashGet\jc_all.htm
IE: Download using FlashGet - c:\program files\FlashGet\jc_link.htm
Trusted Zone: tenderfoot.com
DPF: {C4D6755D-2123-4EEF-BAA0-94B22F1C2271} - hxxps://www.hostilespace.com/Portal/IAHSOCX20019.CAB
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jgnar59d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=58819&ei=utf-8&yahoo_domain=search.yahoo.com&p=
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jgnar59d.default\ext ensions\{916ab64c-bc3e-471b-8e60-29551922a7ba}\components\Engine.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jgnar59d.default\ext ensions\flashplugin@idm\platform\WINNT\plugins\npi dmdcp.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\jgnar59d.default\ext ensions\OberonGameHost@OberonGames.com\platform\WI NNT_x86-msvc\plugins\npOberonGameHost.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox 3\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-07-07 20:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-839522115-527237240-2147062339-1003\Software\Microsoft\Windows\CurrentVersion\Exp lorer\CLSID]
@Denied: (Full) (LocalSystem)
[HKEY_USERS\S-1-5-21-839522115-527237240-2147062339-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d5,d7,ed,42,55,92,b4,6e,a5,d1,d8,99,05,39 ,4f,de,0a,90,80,15,de,f9,b8,
e2,e5,45,45,c4,f5,50,98,0c,31,61,b9,89,a2,3e,0c,bc ,06,db,89,2b,f4,72,e7,1f,\
"??"=hex:43,87,80,79,59,07,01,34,a5,e8,4f,b7,12,f9 ,4e,65
[HKEY_USERS\S-1-5-21-839522115-527237240-2147062339-1003\Software\SecuROM\License information*]
"datasecu"=hex:14,91,47,2c,1a,fc,70,25,2a,a9,9b,3d ,00,bc,8d,56,34,90,07,01,18,
4a,29,52,5a,c8,59,0e,e2,99,6c,a5,39,e8,bc,e6,41,74 ,73,90,71,d9,5b,59,d0,93,\
"rkeysecu"=hex:57,94,b2,4d,4c,cd,fe,bf,32,a3,20,a6 ,ce,19,23,b7
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2964)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\nexon\Mabinogi\npkcmsvc.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
.
************************************************** ************************
.
Completion time: 2009-07-08 20:09 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-08 00:08
Pre-Run: 24,846,721,024 bytes free
Post-Run: 24,958,783,488 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
268 --- E O F --- 2009-06-12 03:10