Hi there
I ran Malwarebytes and it detected 3 trojans and deleted them on reboot. it wont run Firefox now but WILL run IE. the trojans were located in the Firefox folder.
I cant disable or uninstall AVG internet security thats installed. However, i still ran combofix and hijack this. Its a little better but still VERY slow.
heres the logs:
HIJACKTHIS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:49:19, on 07/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\WINDOWS\vVX6000.exe
C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - *{0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (file missing)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-21-2052111302-1336601894-725345543-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0413775653
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 0430515484
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 7864 bytes
COMBOFIX
ComboFix 09-09-06.06 - ALL 07/09/2009 16:36.1.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1790.1317 [GMT 1:00]
Running from: E:\ComboFix.exe
AV: AVG Internet Security 3-pack *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\8e82a.msi
.
((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.
2009-08-29 15:52 . 2009-09-07 10:08 -------- d-----w- c:\program files\CDex_150
2009-08-21 02:05 . 2009-08-21 02:05 -------- d-----w- C:\e625d13149515dd8c2108a2320ef5f
2009-08-12 19:25 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-21 02:19 . 2009-04-22 22:00 69232 ----a-w- c:\documents and settings\ALL\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-15 12:46 . 2009-07-18 18:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-13 02:02 . 2009-07-18 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-05 09:01 . 2002-06-25 21:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 12:36 . 2009-07-18 18:55 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 12:36 . 2009-07-18 18:55 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-30 17:25 . 2009-04-22 18:29 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-30 17:25 . 2009-04-22 18:29 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-30 17:25 . 2009-04-22 18:29 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-26 11:23 . 2009-04-25 13:06 -------- d-----w- c:\documents and settings\ALL\Application Data\Canon
2009-07-20 10:21 . 2009-07-20 10:21 -------- d-----w- c:\program files\Windows Media Connect 2
2009-07-18 19:02 . 2009-07-18 19:02 -------- d-----w- c:\program files\Microsoft Works
2009-07-18 19:01 . 2009-04-24 19:55 -------- d-----w- c:\program files\MSBuild
2009-07-18 19:00 . 2009-07-18 19:00 -------- d-----w- c:\program files\Microsoft.NET
2009-07-18 18:59 . 2009-07-18 18:59 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-07-18 18:55 . 2009-07-18 18:55 -------- d-----w- c:\documents and settings\ALL\Application Data\Malwarebytes
2009-07-18 18:55 . 2009-07-18 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-18 18:53 . 2009-07-18 18:53 -------- d-----w- c:\program files\D-Tools
2009-07-17 19:01 . 2002-06-25 21:36 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2004-08-04 07:56 286208 ------w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2002-03-05 07:56 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 ------w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2002-06-25 21:37 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2002-06-25 21:49 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2002-06-25 21:45 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2002-06-25 21:45 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2002-06-25 21:42 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2002-06-25 21:40 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2002-06-25 21:39 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2002-06-25 21:39 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2002-06-25 21:47 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2002-06-25 21:38 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2002-06-25 21:48 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2002-06-25 21:36 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 08:19 . 2009-04-22 04:03 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2002-06-25 21:50 132096 ----a-w- c:\windows\system32\wkssvc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-02 12:38 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-12 2007832]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-22 148888]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\ALL\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-30 17:25 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [22/04/2009 19:29 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [22/04/2009 19:29 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [22/04/2009 19:29 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [24/04/2009 19:51 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [23/04/2009 18:50 297752]
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [24/04/2009 19:51 1370488]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [22/04/2009 19:27 29208]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [22/04/2009 19:27 29208]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [18/07/2009 19:55 38160]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14/05/2007 10:26 508288]
S3 PAC7302;PAC7302 VGA USB Camera;c:\windows\system32\drivers\PAC7302.SYS [21/06/2009 21:21 457856]
S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [23/04/2009 18:20 2077840]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-GEST - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ie/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-07 16:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\MSCompPackV1.log 8181 bytes
c:\windows\msdfmap.ini 1405 bytes
c:\windows\msgsocm.log 25639 bytes
c:\windows\MSI30-KB884016.log 5245 bytes
c:\windows\msxml4-KB954430-enu.LOG 335172 bytes
c:\windows\mui
c:\windows\network diagnostic
c:\windows\NIRCMD.exe 31232 bytes executable
c:\windows\NLSDownlevelMapping.log 6826 bytes
c:\windows\notepad.exe 69120 bytes executable
c:\windows\nsreg.dat 0 bytes
c:\windows\ntdtcsetup.log 106921 bytes
c:\windows\setuplog.txt 792676 bytes
c:\windows\SHELLNEW
c:\windows\SkyTel.exe 1826816 bytes executable
c:\windows\slrundll.exe 32866 bytes executable
c:\windows\Soap Bubbles.bmp 65978 bytes
c:\windows\SoftwareDistribution
c:\windows\SOUNDMAN.EXE 77824 bytes executable
c:\windows\spupdsvc.log 149584 bytes
c:\windows\spupdsvc.log.1.log 187 bytes
c:\windows\srchasst
c:\windows\Sti_Trace.log 0 bytes
c:\windows\Sun
c:\windows\svcpack.log 881755 bytes
c:\windows\SWREG.exe 161792 bytes executable
c:\windows\SWSC.exe 136704 bytes executable
c:\windows\SWXCACLS.exe 212480 bytes executable
c:\windows\SxsCaPendDel
c:\windows\system.ini 231 bytes
c:\windows\system32
c:\windows\TASKMAN.EXE 15360 bytes executable
c:\windows\Tasks
c:\windows\temp
c:\windows\tsoc.log 197639 bytes
c:\windows\twain.dll 94784 bytes
c:\windows\twain_32
c:\windows\twain_32.dll 50688 bytes executable
c:\windows\twunk_16.exe 49680 bytes
c:\windows\twunk_32.exe 25600 bytes executable
c:\windows\updspapi.log 145048 bytes
c:\windows\USetup.iss 553 bytes
c:\windows\ERDNT
c:\windows\explorer.exe 1033728 bytes executable
c:\windows\explorer.scf 80 bytes
c:\windows\FaxSetup.log 504838 bytes
c:\windows\FeatherTexture.bmp 16730 bytes
c:\windows\Fonts
c:\windows\gdrv.sys 16608 bytes executable
c:\windows\Gone Fishing.bmp 17336 bytes
c:\windows\Greenstone.bmp 26582 bytes
c:\windows\grep.exe 80412 bytes executable
c:\windows\Help
c:\windows\hh.exe 10752 bytes executable
c:\windows\HideWin.exe 319488 bytes executable
c:\windows\IDNMitigationAPIs.log 8702 bytes
c:\windows\ie7
c:\windows\ie7.log 38956 bytes
c:\windows\ie7updates
c:\windows\ie7_main.log 35559 bytes
c:\windows\ie8_main.log 39850 bytes
c:\windows\iis6.log 78316 bytes
c:\windows\repair
c:\windows\Resources
c:\windows\Rhododendron.bmp 17362 bytes
c:\windows\River Sumida.bmp 26680 bytes
c:\windows\RTHDCPL.EXE 16851456 bytes executable
c:\windows\RtkUpd.exe 1200128 bytes executable
c:\windows\RTLCPL.EXE 9715200 bytes executable
c:\windows\RtlExUpd.dll 528384 bytes executable
c:\windows\RtlUpd.exe 1200128 bytes executable
c:\windows\Santa Fe Stucco.bmp 65832 bytes
c:\windows\SchedLgU.Txt 20620 bytes
c:\windows\security
c:\windows\sed.exe 98816 bytes executable
c:\windows\ServicePackFiles
c:\windows\sessmgr.setup.log 1536 bytes
c:\windows\SET1B.tmp 178803 bytes
c:\windows\SET3.tmp 1085913 bytes
c:\windows\SET7.tmp 13608 bytes
c:\windows\SETD.tmp 7046 bytes
c:\windows\setupact.log 175734 bytes
c:\windows\setupapi.log 606659 bytes
c:\windows\setupapi.log.0.old 1141941 bytes
c:\windows\vbaddin.ini 37 bytes
c:\windows\vmmreg32.dll 18944 bytes executable
c:\windows\vVX6000.exe 713744 bytes executable
c:\windows\VX6000.src 13022 bytes
c:\windows\VX6KStd.ini 15497 bytes
c:\windows\WBEM
c:\windows\Web
c:\windows\WFT-E3Utility.INI 108 bytes
c:\windows\wiadebug.log 159 bytes
c:\windows\wiaservc.log 48 bytes
c:\windows\win.ini 891 bytes
c:\windows\Windows Update.log 240 bytes
c:\windows\WindowsShell.Manifest 749 bytes
c:\windows\WindowsUpdate.log 1936287 bytes
c:\windows\COM+.log 1436 bytes
c:\windows\EHome
c:\windows\ime
c:\windows\KB938464-v2.log 12780 bytes
c:\windows\KB952954.log 27633 bytes
c:\windows\KB961501.log 15148 bytes
c:\windows\msapps
c:\windows\Q308677.log 30265 bytes
c:\windows\regopt.log 1630 bytes
c:\windows\setuperr.log 0 bytes
c:\windows\vb.ini 36 bytes
c:\windows\winhelp.exe 256192 bytes
c:\windows\Q308928.log 7369 bytes
c:\windows\Q309056.log 431 bytes
c:\windows\Q310051.log 4072 bytes
c:\windows\Q310601.log 28602 bytes
c:\windows\Q311542.log 10988 bytes
c:\windows\Q311822.log 2239 bytes
c:\windows\Q311889.log 26888 bytes
c:\windows\Q311967.log 5591 bytes
c:\windows\Q313596.log 21961 bytes
c:\windows\Q314147.log 8981 bytes
c:\windows\Q315000.log 20249 bytes
c:\windows\Q315403.log 12701 bytes
c:\windows\Q316134.log 18746 bytes
c:\windows\Q316253.log 23526 bytes
c:\windows\Q317277.log 16994 bytes
c:\windows\Q319580.log 7948 bytes
c:\windows\regedit.exe 146432 bytes executable
c:\windows\Registration
c:\windows\REGLOCS.OLD 8192 bytes
c:\windows\comsetup.log 177469 bytes
c:\windows\Config
c:\windows\Connection Wizard
c:\windows\control.ini 0 bytes
c:\windows\Cursors
c:\windows\daemon.dll 69120 bytes executable
c:\windows\Debug
c:\windows\desktop.ini 2 bytes
c:\windows\DirectX.log 244180 bytes
c:\windows\Downloaded Installations
c:\windows\Downloaded Program Files
c:\windows\Driver Cache
c:\windows\DtcInstall.log 586 bytes
c:\windows\imsins.BAK 1374 bytes
c:\windows\imsins.log 1374 bytes
c:\windows\inf
c:\windows\Installer
c:\windows\java
c:\windows\KB842773.log 9790 bytes
c:\windows\KB888111.log 4801 bytes
c:\windows\KB892130.log 9876 bytes
c:\windows\KB898461.log 6743 bytes
c:\windows\KB915865.log 2061 bytes
c:\windows\KB923561.log 9615 bytes
c:\windows\KB929399.log 8471 bytes
c:\windows\KB932823-v3.log 22545 bytes
c:\windows\KB936782.log 7946 bytes
c:\windows\KB938127-v2-IE7.log 6523 bytes
c:\windows\0.log 0 bytes
c:\windows\002234_.tmp 19528 bytes
c:\windows\004965_.tmp 19569 bytes
c:\windows\addins
c:\windows\ALCMTR.EXE 57344 bytes executable
c:\windows\ALCWZRD.EXE 2808832 bytes executable
c:\windows\AMCap.exe 163840 bytes executable
c:\windows\AppPatch
c:\windows\assembly
c:\windows\atiogl.xml 14849 bytes
c:\windows\ativpsrm.bin 0 bytes
c:\windows\Blue Lace 16.bmp 1272 bytes
c:\windows\bootstat.dat 2048 bytes
c:\windows\clock.avi 82944 bytes
c:\windows\cmsetacl.log 373 bytes
c:\windows\Coffee Bean.bmp 17062 bytes
c:\windows\KB954154.log 4321 bytes
c:\windows\KB954459.log 12110 bytes
c:\windows\KB954600.log 11973 bytes
c:\windows\KB955069.log 11763 bytes
c:\windows\KB955839.log 39349 bytes
c:\windows\KB956572.log 22227 bytes
c:\windows\KB956744.log 13668 bytes
c:\windows\KB956802.log 16219 bytes
c:\windows\KB956803.log 20120 bytes
c:\windows\KB957097.log 14979 bytes
c:\windows\KB958644.log 12287 bytes
c:\windows\KB958687.log 14901 bytes
c:\windows\KB958690.log 18987 bytes
c:\windows\KB959426.log 27255 bytes
c:\windows\KB959772.log 5275 bytes
c:\windows\KB960225.log 25169 bytes
c:\windows\KB960715.log 14390 bytes
c:\windows\KB960803.log 17757 bytes
c:\windows\KB960859.log 23845 bytes
c:\windows\KB961118.log 4825 bytes
c:\windows\KB961371.log 11147 bytes
c:\windows\KB961373.log 26266 bytes
c:\windows\KB961503.log 10871 bytes
c:\windows\KB963027.log 16939 bytes
c:\windows\KB967715.log 20274 bytes
c:\windows\KB968389.log 15439 bytes
c:\windows\KB968537.log 11912 bytes
c:\windows\KB969897.log 16191 bytes
c:\windows\KB969898.log 7853 bytes
c:\windows\KB970238.log 12246 bytes
c:\windows\KB970653-v3.log 33794 bytes
c:\windows\KB971557.log 23409 bytes
c:\windows\KB971633.log 11713 bytes
c:\windows\KB971657.log 23905 bytes
c:\windows\KB972260-IE7.log 70369 bytes
c:\windows\KB972260.log 14729 bytes
c:\windows\KB973346.log 12764 bytes
c:\windows\KB973354.log 13022 bytes
c:\windows\KB973507.log 24052 bytes
c:\windows\KB973540.log 13386 bytes
c:\windows\KB973815.log 22590 bytes
c:\windows\KB973869.log 13273 bytes
c:\windows\l2schemas
c:\windows\MAXLINK.INI 412 bytes
c:\windows\Media
c:\windows\MicCal.exe 2165760 bytes executable
c:\windows\Microsoft.NET
c:\windows\msagent
c:\windows\ocgen.log 256525 bytes
c:\windows\ocmsn.log 28185 bytes
c:\windows\ODBCINST.INI 4161 bytes
c:\windows\OEWABLog.txt 1514 bytes
c:\windows\Offline Web Pages
c:\windows\OPTIONS
c:\windows\PCHEALTH
c:\windows\peernet
c:\windows\PEV.exe 230912 bytes executable
c:\windows\PixArt
c:\windows\Prairie Wind.bmp 65954 bytes
c:\windows\Prefetch
c:\windows\provisioning
c:\windows\Q306676.log 14930 bytes
c:\windows\Q308387.log 25176 bytes
c:\windows\Q308402.log 25176 bytes
c:\windows\KB939683.log 8191 bytes
c:\windows\KB941569.log 10790 bytes
c:\windows\KB942288-v3.log 9551 bytes
c:\windows\KB946648.log 20624 bytes
c:\windows\KB950760.log 13954 bytes
c:\windows\KB950762.log 14921 bytes
c:\windows\KB950974.log 25835 bytes
c:\windows\KB951066.log 14456 bytes
c:\windows\KB951376-v2.log 21921 bytes
c:\windows\KB951748.log 19821 bytes
c:\windows\KB951978.log 13960 bytes
c:\windows\KB952004.log 21779 bytes
c:\windows\KB952069.log 12352 bytes
c:\windows\KB952287.log 14600 bytes
c:\windows\$NtUninstallKB969898$
c:\windows\$NtUninstallKB970238$
c:\windows\$NtUninstallKB970653-v3$
c:\windows\$NtUninstallKB971557$
c:\windows\$NtUninstallKB971633$
c:\windows\$NtUninstallKB971657$
c:\windows\$NtUninstallKB972260$
c:\windows\$NtUninstallKB973346$
c:\windows\$NtUninstallKB973354$
c:\windows\$NtUninstallKB973507$
c:\windows\$NtUninstallKB973540_WM9$
c:\windows\$NtUninstallKB973815$
c:\windows\$NtUninstallKB973869$
c:\windows\$NtUninstallMSCompPackV1$
c:\windows\$NtUninstallWMFDist11$
c:\windows\$NtUninstallwmp11$
c:\windows\$NtUninstallWudf01000$
c:\windows\winhlp32.exe 283648 bytes executable
c:\windows\winnt.bmp 48680 bytes
c:\windows\winnt256.bmp 48680 bytes
c:\windows\WinSxS
c:\windows\WMFDist11.log 107343 bytes
c:\windows\wmp11.log 21129 bytes
c:\windows\wmsetup.log 13547 bytes
c:\windows\wmsetup10.log 394 bytes
c:\windows\WMSysPr9.prx 316640 bytes
c:\windows\WMSysPrx.prx 299552 bytes
c:\windows\WORDPAD.INI 754 bytes
c:\windows\Wudf01000Inst.log 10380 bytes
c:\windows\Zapotec.bmp 9522 bytes
c:\windows\zip.exe 68096 bytes executable
c:\windows\_default.pif 707 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Finnish.bin 22868 bytes
c:\docume~1\ALL\LOCALS~1\Temp\French.bin 27246 bytes
c:\docume~1\ALL\LOCALS~1\Temp\gaopdx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\German.bin 25764 bytes
c:\docume~1\ALL\LOCALS~1\Temp\geyekr000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Greek.bin 25093 bytes
c:\docume~1\ALL\LOCALS~1\Temp\gxvxc000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Hebrew.bin 19564 bytes
c:\docume~1\ALL\LOCALS~1\Temp\hjgrui000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\hsperfdata_ALL
c:\docume~1\ALL\LOCALS~1\Temp\Hungarian.bin 26094 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Italian.bin 27465 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Japanese.bin 24340 bytes
c:\docume~1\ALL\LOCALS~1\Temp\java_install_reg.log 582 bytes
c:\docume~1\ALL\LOCALS~1\Temp\jusched.log 3549 bytes
c:\docume~1\ALL\LOCALS~1\Temp\kbiwkm000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Korean.bin 20145 bytes
c:\docume~1\ALL\LOCALS~1\Temp\kungsf000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\d2Farec0BPd38AwkgBzAFxL1e0fg= 2330 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\ErrorResponse.xml 1984 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\G82vH7n3+PsFISdIk3ciAqK6BFY= 374130 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\QJwDfPchunK6+PZOmuBiMS51WO4= 29379 bytes
c:\docume~1\ALL\LOCALS~1\Temp\MessengerCache\Sounds
c:\docume~1\ALL\LOCALS~1\Temp\msivx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\msqpdx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Norwegian.bin 21975 bytes
c:\docume~1\ALL\LOCALS~1\Temp\ose00000.exe 145184 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\outlook logging
c:\docume~1\ALL\LOCALS~1\Temp\outlook logging\firstrun.log 111 bytes
c:\docume~1\ALL\LOCALS~1\Temp\ovfsth000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Polish.bin 24232 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Portuguese(Brazil).bin 25082 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Portuguese.bin 26271 bytes
c:\docume~1\ALL\LOCALS~1\Temp\quadra000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\rotscx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Russian.bin 26136 bytes
c:\docume~1\ALL\LOCALS~1\Temp\seneka000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\set7B.tmp 121064 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\SimChin.bin 16420 bytes
c:\docume~1\ALL\LOCALS~1\Temp\skynet000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Spanish.bin 27764 bytes
c:\docume~1\ALL\LOCALS~1\Temp\SWEDISH.bin 24099 bytes
c:\docume~1\ALL\LOCALS~1\Temp\tdss000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Thai.bin 21987 bytes
c:\docume~1\ALL\LOCALS~1\Temp\TradChin.bin 16962 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Turkish.bin 22263 bytes
c:\docume~1\ALL\LOCALS~1\Temp\uac000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\vsfoce000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\wmplog00.sqm 2004 bytes
c:\docume~1\ALL\LOCALS~1\Temp\WPDNSE
c:\docume~1\ALL\LOCALS~1\Temp\wzszx000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\ytasfw000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_1MIMjDFg3exAgEVKwVMo 28704 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_7yYKJWbC6DLaDq7t7KSr 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_CMjcjfLDwbKb15K69YEk 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_cnbFkVvruneuE5obkUqE 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_e9x62ffIXRRuAPBOVkZA 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_HFFnYjN1H9gANbWJiFIu 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_KCwBhUDYBvw1ICO8VzNd 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_XssudSABpVd5G5V4VNA6 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_yAGvX24XF0E39gmKrmBb 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_yqwXMzplR31f8CoZWift 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Arabic.bin 20991 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Av-test.txt 72 bytes
c:\docume~1\ALL\LOCALS~1\Temp\avg8inst.log 69415 bytes
c:\docume~1\ALL\LOCALS~1\Temp\catchme.dll 53248 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\CEOSUTL
c:\docume~1\ALL\LOCALS~1\Temp\cmd.execf 389120 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\Czech.bin 24321 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Danish.bin 22794 bytes
c:\docume~1\ALL\LOCALS~1\Temp\dgm000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\Dutch.bin 25758 bytes
c:\docume~1\ALL\LOCALS~1\Temp\English.bin 21944 bytes
c:\docume~1\ALL\LOCALS~1\Temp\esqul000 0 bytes
c:\docume~1\ALL\LOCALS~1\Temp\etilqs_0sPWJHWW9d2OGiQ6MUcJ 12304 bytes
c:\docume~1\ALL\LOCALS~1\Temp\_is1.exe 460248 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\_w7UKS7t.pdf.part 195721 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{83BD5167-4996-4DF8-A187-EBC0DA81F647}
c:\docume~1\ALL\LOCALS~1\Temp\{83BD5167-4996-4DF8-A187-EBC0DA81F647}\ISSetup.dll 492164 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\{83BD5167-4996-4DF8-A187-EBC0DA81F647}\setup.isn 64392 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{83BD5167-4996-4DF8-A187-EBC0DA81F647}\_Setup.dll 373680 bytes executable
c:\docume~1\ALL\LOCALS~1\Temp\{8C04BD2C-B1BB-44D3-BD74-71964D99B87E}
c:\docume~1\ALL\LOCALS~1\Temp\{8C04BD2C-B1BB-44D3-BD74-71964D99B87E}\{E8AEA11B-E60A-455E-B008-E4E763604612}
c:\docume~1\ALL\LOCALS~1\Temp\{8C04BD2C-B1BB-44D3-BD74-71964D99B87E}\{E8AEA11B-E60A-455E-B008-E4E763604612}\urlhooks.txt 40 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{99663C9E-00F3-420A-A136-4ADC0126250F}
c:\docume~1\ALL\LOCALS~1\Temp\{99663C9E-00F3-420A-A136-4ADC0126250F}\setup.isn 256664 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{C79E7FFD-AD4E-4ABA-9D93-80D1E071F0C1}
c:\docume~1\ALL\LOCALS~1\Temp\{C79E7FFD-AD4E-4ABA-9D93-80D1E071F0C1}\setup.isn 256664 bytes
c:\docume~1\ALL\LOCALS~1\Temp\{FC6BA59A-C07F-459B-9C80-AD363AC43994}
c:\docume~1\ALL\LOCALS~1\Temp\{FC6BA59A-C07F-459B-9C80-AD363AC43994}\setup.isn 256664 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DF8ACB.tmp 311296 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DF9662.tmp 311296 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DFDF49.tmp 311296 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DFEBA7.tmp 311296 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DFFBE6.tmp 16384 bytes
c:\docume~1\ALL\LOCALS~1\Temp\~DFFBF1.tmp 512 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Extensions
c:\documents and settings\ALL\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
c:\documents and settings\ALL\Application Data\Mozilla\Firefox
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009040821 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009042316 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009060215 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009070611 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Crash Reports\InstallTime2009073022 10 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Desktop Background.bmp
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\blocklist.xml 2644 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-08-30.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-08-31.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-09-01.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-09-02.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarkbackups\bookmarks-2009-09-05.json 11202 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\bookmarks.html 7139 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\cert8.db 114688 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\chrome
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\chrome\userChrome-example.css 1078 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\chrome\userContent-example.css 663 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\compatibility.ini 180 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\compreg.dat 146533 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\content-prefs.sqlite 7168 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\cookies.sqlite 203776 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\downloads.sqlite 19456 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome\chrome_user.jar 27394 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome.manifest 2005 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences\defaults.js 424 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\install.rdf 1271 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions.cache 791 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions.ini 494 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\extensions.rdf 5241 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\formhistory.sqlite 24576 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\key3.db 16384 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\localstore.rdf 7435 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\mimeTypes.rdf 3286 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\minidumps
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\minidumps\1e1a3c01-21b2-4d0b-94db-d2877e97e67a.dmp 0 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\permissions.sqlite 15360 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\places.sqlite 1777664 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\pluginreg.dat 3889 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\prefs.js 6811 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\search.sqlite 2048 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\secmod.db 16384 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\signons3.txt 57 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\urlclassifierkey3.txt 154 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\webappsstore.sqlite 26624 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\Profiles\k0qarpcj.default\xpti.dat 97053 bytes
c:\documents and settings\ALL\Application Data\Mozilla\Firefox\profiles.ini 111 bytes
scan completed successfully
hidden files: 438
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\æHõwæ*]
"DisplayName"="??È\17?\11\09"
"DeviceDesc"="??È\17?\11\09"
"ProviderName"="???\11?\18?\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.8"
"DeviceInstanceIds"=multi:"d:\\chipset\\7-ser\\xp\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1052)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-09-07 16:50
ComboFix-quarantined-files.txt 2009-09-07 15:50
Pre-Run: 117,633,208,320 bytes free
Post-Run: 117,620,563,968 bytes free
596 --- E O F --- 2009-09-02 02:00

