Combofix log:
ComboFix 11-02-20.03 - Doreen 02/21/2011 18:41:29.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.569 [GMT -5:00]
Running from: c:\documents and settings\Doreen\My Documents\Downloads\Programs\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Doreen\Application Data\Local
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\.ddr
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\0.ddi
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\1.ddi
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\2.ddi
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\435088881127_43798.mp4.ddr
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\settings.ddi
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\.ddp
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\435088881127_43798.mp4
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\videoplayback.ddp
c:\documents and settings\Doreen\Application Data\Local\Temp\DDM\Settings\videoplayback.ddr
c:\documents and settings\Doreen\Application Data\syswin
c:\documents and settings\LocalService\Application Data\02000000b69107a01100C.manifest
c:\documents and settings\LocalService\Application Data\02000000b69107a01100O.manifest
c:\documents and settings\LocalService\Application Data\02000000b69107a01100P.manifest
c:\documents and settings\LocalService\Application Data\02000000b69107a01100S.manifest
c:\recycler\k-1-3542-4232123213-7676767-8888886
c:\windows\system32\1314020072
c:\windows\system32\SysWoW32
c:\windows\system32\SysWoW32\_u641361877v0
c:\windows\system32\SysWoW32\_u641361877v1
c:\windows\system32\SysWoW32\_u641361877v2
c:\windows\system32\SysWoW32\_u641361877v3
c:\windows\system32\SysWoW32\mu641361877v4.kwd
c:\windows\system32\SysWoW32\mu641361877v5.kwd
c:\windows\system32\SysWoW32\mu641361877v6.kwd
c:\windows\system32\SysWoW32\mu641361877v7.kwd
c:\windows\system32\SysWoW32\wu641361877v0
c:\windows\system32\SysWoW32\wu641361877v0.kwd
c:\windows\system32\SysWoW32\wu641361877v1
c:\windows\system32\SysWoW32\wu641361877v1.kwd
c:\windows\system32\SysWoW32\wu641361877v2
c:\windows\system32\SysWoW32\wu641361877v2.kwd
c:\windows\system32\SysWoW32\wu641361877v3
c:\windows\system32\SysWoW32\wu641361877v3.kwd
.
((((((((((((((((((((((((( Files Created from 2011-01-21 to 2011-02-21 )))))))))))))))))))))))))))))))
.
2011-02-20 23:21 . 2011-02-21 23:46 -------- d-----w- c:\program files\Common Files\Akamai
2011-02-19 18:37 . 2011-02-19 18:39 -------- d-----w- c:\documents and settings\Administrator
2011-02-13 00:02 . 1998-06-18 05:00 89360 ----a-w- c:\windows\system32\VB5DB.DLL
2011-02-12 02:03 . 2011-02-13 01:44 -------- d-----w- c:\documents and settings\Doreen\Application Data\IDM
2011-02-12 02:03 . 2011-02-12 02:03 -------- d-----w- c:\program files\Internet Download Manager
2011-02-12 01:55 . 2011-02-12 01:55 388096 ----a-r- c:\documents and settings\Doreen\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-12 01:55 . 2011-02-12 01:55 -------- d-----w- c:\program files\Trend Micro
2011-02-06 15:54 . 2008-12-08 17:53 57344 ----a-w- c:\windows\system32\ff_vfw.dll
2011-02-06 15:54 . 2008-06-09 03:58 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2011-02-06 15:54 . 2011-02-06 15:54 -------- d-----w- c:\program files\ffdshow
2011-02-06 15:54 . 2010-01-26 18:09 290816 ----a-w- c:\windows\system32\stFLVSource.ax
2011-02-06 15:54 . 2011-02-06 15:54 -------- d-----w- c:\program files\Common Files\SourceTec
2011-02-06 15:54 . 2009-08-17 14:54 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll
2011-02-06 15:54 . 2009-08-17 14:54 217088 ----a-w- c:\windows\system32\CoreFLACDecoder.ax
2011-02-06 15:54 . 2011-02-06 15:54 -------- d-----w- c:\program files\SourceTec
2011-02-06 15:54 . 2009-08-17 14:54 438272 ----a-w- c:\windows\system32\Mpeg2DecFilter.ax
2011-02-05 04:10 . 2011-02-05 04:10 -------- d-----w- c:\documents and settings\Doreen\Local Settings\Application Data\Downloaded Installations
2011-02-02 13:31 . 2011-02-02 13:31 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-02-02 13:31 . 2011-02-02 13:31 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-02-02 11:31 . 2011-02-02 11:31 -------- d-----w- c:\documents and settings\Doreen\Application Data\Pegasys Inc
2011-02-01 14:37 . 2011-01-25 10:40 97112 ----a-w- c:\windows\system32\drivers\idmtdi.sys
2011-01-30 19:57 . 2011-01-30 19:57 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-01-30 19:57 . 2011-01-30 19:57 103864 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2011-01-30 17:07 . 2011-01-30 17:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia
2011-01-30 17:05 . 2011-02-20 00:58 -------- d-----w- C:\GameHouse Games
2011-01-30 17:05 . 2009-07-02 16:19 102400 ----a-w- c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
2011-01-30 17:05 . 2011-01-30 17:05 -------- d-----w- c:\program files\Zylom Games
2011-01-30 17:05 . 2011-01-30 17:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom
2011-01-30 17:02 . 2011-02-20 00:58 -------- d-----w- c:\program files\RealArcade
2011-01-23 22:18 . 2011-01-23 22:25 -------- d-----w- C:\temp
2011-01-23 05:38 . 2011-01-23 05:38 -------- d-----w- c:\program files\ASIO4ALL v2
2011-01-23 05:38 . 2006-06-20 08:56 225280 ----a-w- c:\windows\system32\rewire.dll
2011-01-23 05:37 . 2009-08-02 20:09 1554944 ----a-w- c:\windows\system32\vorbis.acm
2011-01-23 05:36 . 2011-01-23 05:39 -------- d-----w- c:\program files\VstPlugins
2011-01-23 05:36 . 2011-01-23 05:36 -------- d-----w- c:\program files\Outsim
2011-01-23 05:33 . 2011-01-23 05:38 -------- d-----w- c:\program files\Image-Line
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2008-04-14 13:42 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2008-04-14 13:39 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2008-04-14 09:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-25 19:49 . 2010-12-25 19:49 203776 --sh--w- c:\windows\system32\unrar.exe
2010-12-22 12:34 . 2008-04-14 13:41 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59 . 2008-04-14 13:42 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2008-04-14 13:42 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 23:59 . 2008-04-14 13:41 43520 ------w- c:\windows\system32\licmgr10.dll
2010-12-20 17:26 . 2008-04-14 13:41 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2008-04-14 08:07 385024 ----a-w- c:\windows\system32\html.iec
2010-12-14 13:43 . 2011-01-02 16:12 31552 ----a-w- c:\windows\system32\TURegOpt.exe
2010-12-14 13:39 . 2011-01-02 16:18 29504 ----a-w- c:\windows\system32\uxtuneup.dll
2010-12-09 15:15 . 2008-04-14 13:41 718336 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2008-04-14 13:41 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:38 . 2008-04-14 08:57 2192768 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2008-04-14 00:01 2069376 ----a-w- c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-01-25 10:40 67680 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2009-04-17 95536]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2011-02-01 3265944]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 16132608]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-10-06 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-06 98304]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-06 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SNAC"=3 (0x3)
"LiveUpdate"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" start
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58855:TCP"= 58855:TCP:Pando Media Booster
"58855:UDP"= 58855:UDP:Pando Media Booster
"1034:TCP"= 1034:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
R1 IDMTDI;IDMTDI;c:\windows\system32\drivers\idmtdi.sys [2/1/2011 9:37 AM 97112]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [4/14/2008 8:42 AM 14336]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.symantec.com/enterprise/secu ... /index.jspmStart Page =
hxxp://www.yahoo.comuInternet Connection Wizard,ShellNext = iexplore
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
FF - ProfilePath - c:\documents and settings\Doreen\Application Data\Mozilla\Firefox\Profiles\q7alc8ub.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.yahoo.com/search?fr=ffsp1&p=FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage -
hxxp://en-US.start3.mozilla.com/firefox ... S:officialFF - prefs.js: keyword.URL -
hxxp://search.avg.com/route/?d=4cf38d9f ... g=en-US&q=FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Free Realms Installer: {38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1} - %profile%\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Personas:
personas@christopher.beard - %profile%\extensions\personas@christopher.beard
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\DivX\DivX Plus Web Player\firefox\wpa
FF - Ext: IDM CC:
mozilla_cc@internetdownloadmanager.com - c:\documents and settings\Doreen\Application Data\IDM\idmmzcc3
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-Download - c:\mediaholder\MediaHolder.exe
HKLM-Run-QuickTime Task - c:\program files\QuickTime\QTTask.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-21 18:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_dbc0250.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_dbc0250.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):86,e3,27,f1,0f,15,da,a8,39,98,3b,e6,af,3b,57,86,ef,e8,8c,fd,dc,
7e,ad,c6,e8,8a,69,cf,dc,dd,1a,90,04,ff,43,80,f1,0d,89,ed,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f14a683c-5dd9-4a43-a1ce-68a85e81fe29}]
@Denied: (Full) (Everyone)
"Model"=dword:0000002d
"Therad"=dword:00000001
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(924)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(4048)
c:\windows\system32\WININET.dll
c:\program files\Internet Download Manager\IDMShellExt.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Internet Download Manager\idmmkb.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WgaTray.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\program files\Internet Download Manager\IEMonitor.exe
c:\program files\HP\hpcoretech\comp\hptskmgr.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Completion time: 2011-02-21 18:52:23 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-21 23:52
Pre-Run: 122,852,954,112 bytes free
Post-Run: 123,843,952,640 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 0B0195DEBC8D2B2262EA008BDA344724