ComboFix 10-10-22.04 - Owner 10/22/2010 21:17:38.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.554 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\Owner\Application Data\BBCC51E517DBE825F88FD0409D626AEE\enemies-names.txt
c:\documents and settings\Owner\Application Data\BBCC51E517DBE825F88FD0409D626AEE\local.ini
c:\documents and settings\Owner\Application Data\BBCC51E517DBE825F88FD0409D626AEE\lsrslt.ini
c:\documents and settings\Owner\Application Data\Ygage\doxan.tmp
c:\documents and settings\Owner\Application Data\Ygage\doxan.ypx
c:\documents and settings\Owner\Local Settings\Application Data\{1068339F-B76B-4FD8-8724-685ADD2C2EB1}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{1068339F-B76B-4FD8-8724-685ADD2C2EB1}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{1068339F-B76B-4FD8-8724-685ADD2C2EB1}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{1068339F-B76B-4FD8-8724-685ADD2C2EB1}\install.rdf
c:\windows\expert\Apps\Help.ico
c:\windows\expert\Apps\Home.exe
c:\windows\expert\Apps\Install.ico
c:\windows\expert\Apps\PDF.ICO
c:\windows\expert\Apps\Readme.ico
c:\windows\expert\Apps\Register.exe
c:\windows\expert\Apps\Support.exe
c:\windows\expert\X6820.INI
c:\windows\expert\X6820REG.INI
c:\windows\expert\XSNCR.INI
c:\windows\icayitegigusobo.dll
c:\windows\system32\drivers\hwinterface.sys
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
-- Previous Run --
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\winlogon.exe
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\winlogon.exe
Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\explorer.exe
--------
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_hwinterface
-------\Service_hwinterface
((((((((((((((((((((((((( Files Created from 2010-09-23 to 2010-10-23 )))))))))))))))))))))))))))))))
.
2010-10-21 07:48 . 2010-10-21 07:48 191 ----a-w- c:\documents and settings\Owner\Application Data\7130.bat
2010-10-21 07:48 . 2010-10-21 07:48 -------- d-----w- c:\documents and settings\All Users\Application Data\WSTB
2010-10-21 07:48 . 2010-10-22 02:27 -------- d-----w- c:\documents and settings\Owner\Application Data\Tadi
2010-10-13 01:02 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 01:02 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 01:02 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-09-28 05:23 . 2010-09-28 05:23 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2010-09-28 05:14 . 2010-09-28 05:24 -------- d-----w- c:\documents and settings\Owner\Application Data\HP
2010-09-28 05:13 . 2009-04-16 21:08 312832 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp70v.dll
2010-09-28 05:13 . 2009-04-16 21:08 123904 ----a-w- c:\windows\system32\hpf3l70v.dll
2010-09-28 05:13 . 2009-04-15 20:53 452408 ----a-r- c:\windows\system32\hpzids01.dll
2010-09-28 05:12 . 2009-02-10 19:03 966656 ----a-r- c:\windows\system32\hpost_p02c.dll
2010-09-28 05:12 . 2009-02-10 19:03 712704 ----a-r- c:\windows\system32\hposwia_p02c.dll
2010-09-28 05:12 . 2009-02-10 19:03 315392 ----a-r- c:\windows\system32\hposc_p02a.dll
2010-09-28 05:12 . 2008-10-28 09:27 372736 ----a-r- c:\windows\system32\hppldcoi.dll
2010-09-28 05:12 . 2008-10-28 09:27 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-09-28 05:12 . 2001-08-17 20:53 6784 -c--a-w- c:\windows\system32\dllcache\serscan.sys
2010-09-28 05:12 . 2001-08-17 20:53 6784 ----a-w- c:\windows\system32\drivers\serscan.sys
2010-09-28 05:11 . 2010-09-28 05:11 -------- d-----w- c:\program files\Coupons
2010-09-28 05:10 . 2010-09-28 05:10 -------- d-----w- c:\program files\HP Photo Creations
2010-09-28 05:10 . 2010-09-28 05:10 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Photo Creations
2010-09-28 05:10 . 2010-10-06 06:15 -------- d-----w- c:\documents and settings\Owner\Application Data\HpUpdate
2010-09-28 05:09 . 2010-09-28 05:09 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-09-28 05:08 . 2010-09-28 05:08 -------- d-----w- c:\program files\Common Files\HP
2010-09-28 05:08 . 2010-09-28 05:08 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-09-28 05:08 . 2010-09-28 05:15 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2010-09-28 05:06 . 2008-04-13 18:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-09-28 05:06 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-09-28 05:05 . 2010-09-28 05:10 -------- d-----w- c:\program files\HP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 19:23 . 2001-08-23 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2001-08-23 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2001-08-23 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2001-08-23 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58 . 2001-08-23 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2001-08-23 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2001-08-23 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-07 15:12 . 2010-08-05 02:08 38848 ----a-w- c:\windows\avastSS.scr
2010-09-07 15:11 . 2010-08-05 02:08 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-09-07 14:52 . 2010-08-05 02:08 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-07 14:52 . 2010-08-05 02:08 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-07 14:47 . 2010-08-05 02:08 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-07 14:47 . 2010-08-05 02:08 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-07 14:47 . 2010-08-05 02:08 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-07 14:47 . 2010-08-05 02:08 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-07 14:46 . 2010-08-05 02:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-01 11:51 . 2001-08-23 12:00 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2001-08-23 12:00 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2001-08-23 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2001-08-23 12:00 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2001-08-23 12:00 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-14 22:55 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2001-08-23 12:00 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2001-08-23 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2001-08-23 12:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-08-10 12:15 . 2010-08-10 12:15 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-08-10 12:15 . 2010-08-10 12:15 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-07-28 01:44 . 2010-07-28 01:44 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-07-28 01:44 . 2010-07-28 01:44 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-07-28 01:44 . 2010-07-28 01:44 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-07-28 01:44 . 2010-07-28 01:44 107808 ----a-w- c:\windows\system32\dns-sd.exe
2004-03-16 01:51 . 2004-03-16 01:51 114688 -c--a-w- c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 18:32 . 2006-01-23 18:32 131072 -c--a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 18:48 . 2007-02-08 18:48 133920 ----a-w- c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
2007-07-25 03:03 . 2007-07-25 03:03 118784 ----a-w- c:\program files\internet explorer\plugins\LV85ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2010-05-18 2515552]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2010-05-18 00:34 2515552 ----a-w- c:\program files\free-downloads.net\tbfre0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2010-05-18 2515552]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2010-05-18 2515552]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-13 133104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-14 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-10-08 131072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-23 202256]
"avast5"="d:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"AirPort Base Station Agent"="d:\program files\Airport\APAgent.exe" [2009-11-11 771360]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 718688]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Trillian.lnk - d:\program files\Trillian\trillian.exe [2010-8-23 2068832]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
NETGEAR WPN311 Smart Wizard.lnk - c:\program files\NETGEAR\WPN311\wlancfg5.exe [2006-12-4 1503232]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2010-4-1 1073152]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\frd.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Airport\\APAgent.exe"=
"d:\\Program Files\\Airport\\APUtil.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57275:TCP"= 57275:TCP

ando Media Booster
"57275:UDP"= 57275:UDP

ando Media Booster
"5353:UDP"= 5353:UDP:Bonjour
R0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\system32\drivers\nipbcfk.sys [7/10/2007 9:08 PM 15448]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8/4/2010 7:08 PM 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/4/2010 7:08 PM 17744]
R2 ni488enumsvc;NI-488.2 Enumeration Service;c:\windows\system32\nipalsm.exe [2/16/2007 12:21 PM 12696]
R2 nidevldu;NI Device Loader;c:\windows\system32\nipalsm.exe [2/16/2007 12:21 PM 12696]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmkl.sys [2/22/2007 1:18 PM 11552]
R2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [7/19/2007 12:56 PM 11360]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [7/16/2008 2:30 PM 3032360]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/28/2008 4:40 PM 24652]
R3 nidimk;nidimk;c:\windows\system32\drivers\nidimkl.sys [7/12/2007 7:18 PM 11360]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2kl.sys [7/24/2007 1:19 PM 11360]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstskl.sys [7/13/2007 9:00 PM 11360]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [7/16/2008 2:30 PM 15144]
S2 EZWINIT;EZWINIT;c:\windows\system32\drivers\ezwinit.sys [6/6/2005 10:18 AM 14494]
S2 EZWRITER;EZWRITER;c:\windows\system32\drivers\ezwriter.sys [1/12/2006 4:09 PM 12544]
S2 gupdate1c8e2652b6be648;Google Update Service (gupdate1c8e2652b6be648);c:\program files\Google\Update\GoogleUpdate.exe [7/17/2008 12:27 PM 133104]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 EloBus;Elobus Filter Driver;c:\windows\system32\drivers\EloBus.sys [12/26/2007 9:56 AM 14848]
S3 elomoufiltr;ELO TouchSystems-SRV2;c:\windows\system32\drivers\EloFiltr.sys [12/26/2007 9:56 AM 28160]
S3 EloSer;Elo Serial Driver;c:\windows\system32\drivers\EloSer.Sys [12/26/2007 9:56 AM 81408]
S3 EloUsb;ELO TouchSystems-SRV;c:\windows\system32\drivers\EloUsb.sys [12/26/2007 9:56 AM 66560]
S3 FXDRV;FXDRV;\??\e:\fxdrv.sys --> e:\Fxdrv.sys [?]
S3 LJ_Usb;LabJack USB Driver;c:\windows\system32\drivers\LabJackusb.sys [7/6/2007 1:23 PM 25654]
S3 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.sys [1/11/2007 11:18 AM 20256]
S3 ni1006k;NI PXI-1006 Chassis Pilot;c:\windows\system32\drivers\ni1006k.sys [2/22/2007 1:40 PM 25888]
S3 ni1045k;NI PXI-1045 Chassis Pilot;c:\windows\system32\drivers\ni1045kl.sys [2/22/2007 1:43 PM 11552]
S3 ni1065k;NI PXIe-1065 Chassis Pilot;c:\windows\system32\drivers\ni1065k.sys [5/25/2007 2:26 PM 22360]
S3 ni488lock;NI-488.2 Locking Service;c:\windows\system32\drivers\ni488lock.sys [2/26/2007 1:40 PM 16672]
S3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrkl.sys [7/15/2007 6:44 PM 11352]
S3 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfkl.sys [7/13/2007 11:38 PM 11336]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsarkl.sys [7/19/2007 4:06 AM 11344]
S3 niemrk;niemrk;c:\windows\system32\drivers\niemrkl.sys [7/24/2007 8:37 PM 11336]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrkl.sys [7/24/2007 8:37 PM 11336]
S3 nifslk;nifslk;c:\windows\system32\drivers\nifslkl.sys [7/15/2007 7:31 PM 11352]
S3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrkl.sys [7/18/2007 11:47 AM 11392]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [6/21/2007 1:19 AM 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [6/21/2007 1:19 AM 151683]
S3 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpkl.sys [7/13/2007 9:01 PM 11368]
S3 ninshsdk;ninshsdk;c:\windows\system32\drivers\ninshsdkl.sys [7/19/2007 2:49 PM 11360]
S3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys [7/18/2007 10:11 PM 11904]
S3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys [7/18/2007 10:12 PM 11896]
S3 nipxigpk;NI PXI Generic Chassis Pilot;c:\windows\system32\drivers\nipxigpk.sys [2/22/2007 1:45 PM 20768]
S3 niscdk;niscdk;c:\windows\system32\drivers\niscdkl.sys [7/19/2007 3:32 AM 11376]
S3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigkl.sys [7/17/2007 1:27 AM 11352]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftkl.sys [7/16/2007 1:52 PM 11344]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdkl.sys [7/19/2007 3:32 AM 11376]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrkl.sys [7/24/2007 8:37 PM 11336]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2kl.sys [7/15/2007 5:48 PM 11312]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrkl.sys [7/15/2007 6:50 PM 11360]
S3 niswdk;niswdk;c:\windows\system32\drivers\niswdkl.sys [7/17/2007 5:18 AM 11336]
S3 nitiork;nitiork;c:\windows\system32\drivers\nitiorkl.sys [7/18/2007 11:15 PM 11360]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [7/19/2007 12:48 PM 11384]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [7/19/2007 12:56 PM 11360]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrkl.sys [7/24/2007 8:37 PM 11336]
S3 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrkl.sys [7/24/2007 8:38 PM 11336]
S3 nixsrkw;nixsrkw;c:\windows\system32\drivers\nixsrkw.sys [7/24/2007 8:38 PM 11336]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 usb6xxxk;usb6xxxk;\??\c:\windows\system32\drivers\usb6xxxkl.sys --> c:\windows\system32\drivers\usb6xxxkl.sys [?]
S4 dacfddfcadbca;09d248a3323fd52eedfcb4187aac582b;c:\windows\dacfddfcadbca.exe /s --> c:\windows\dacfddfcadbca.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/6/2008 11:24 PM 721904]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - NIPALK
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-10-22 c:\windows\Tasks\Auslogics Console Defragmentation.job
- c:\program files\Auslogics\Auslogics BoostSpeed\cdefrag.exe [2010-01-10 01:44]
2010-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-07-17 21:22]
2010-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-07-17 21:22]
2010-10-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1767777339-839522115-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-08 12:05]
2010-10-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1767777339-839522115-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-08 12:05]
2010-10-23 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1390067357-1767777339-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 05:09]
2010-10-21 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1390067357-1767777339-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 05:09]
2010-10-23 c:\windows\Tasks\VersionCheck.job
- c:\documents and settings\All Users\Application Data\WSTB\drv8.0.3.exe [2010-10-20 15:37]
2010-01-12 c:\windows\Tasks\videopadSevenDaysInit.job
- c:\program files\NCH Software\VideoPad\videopad.exe [2010-01-12 05:12]
2010-05-04 c:\windows\Tasks\videopadShakeIcon.job
- c:\program files\NCH Software\VideoPad\videopad.exe [2010-01-12 05:12]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Owner\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\64rcuxax.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1396957&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&query=
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\64rcuxax.default\extensions\{f592709f-ff4a-4862-b659-4afabda56312}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\64rcuxax.default\extensions\{f592709f-ff4a-4862-b659-4afabda56312}\components\RadioWMPCore.dll
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - component: c:\program files\PayPal\PayPal Plug-In\components\PayPalPlugin.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\64rcuxax.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nplv85win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\OverTheEdge\Unity\WebPlayer\loader\npUnityWeb32.dll
FF - plugin: c:\program files\Sony\Media Go\npmediago.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: d:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.search.selectedEngine - Search
FF - user.js: browser.search.order.1 - Search
FF - user.js: keyword.URL - hxxp://search.fast-find.net/?sid=10101066100&s=c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.search-clsid", "{042BEB8A-AFDF-44C7-961E-6D5D7A8E55A7}");
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Ahofoteho - c:\windows\icayitegigusobo.dll
AddRemove-Cave Story Deluxe - f:\cave_story_deluxe\Uninstal.exe
AddRemove-EloTouchscreen - c:\program files\EloTouchSystems\EloSetup
AddRemove-M2416447 - c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
AddRemove-M928367 - c:\windows\Microsoft.NET\Framework\v1.0.3705\Updates\hotfix.exe
AddRemove-M979906 - c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe
AddRemove-pepakura_designer2_en - f:\pepakura\epuninst.exe
AddRemove-Ragnarok Online - c:\windows\IFinst27.exe
AddRemove-Ragnarok Sakray - c:\windows\IFinst27.exe
AddRemove-Sonic 3D - f:\sonic3dpc\directx\setup
AddRemove-StepMania - f:\stepmania\uninstall.exe
AddRemove-Super Card_is1 - f:\supercard lite\SC\unins000.exe
AddRemove-_{0C180787-F8C8-42FD-A9D3-689BA44BEAAF} - d:\corel painter essentials 3\MSILauncher {0C180787-F8C8-42FD-A9D3-689BA44BEAAF}
AddRemove-Advanced Archive Password Recovery - c:\documents and settings\Owner\Desktop\STUFF\rarpasscrack\Advanced Archive Password Recovery\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-10-22 21:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1390067357-1767777339-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5AFADB1B-327F-CFDA-C903-91EC12F1671A}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iadmfakclipfcffjbe"=hex:6a,61,6e,68,6e,6b,63,6b,63,6e,6e,6b,63,70,61,6d,6f,6d,
6f,69,00,f1
"hajkpaihflpjiodd"=hex:6a,61,61,69,6b,6b,63,64,66,6c,6f,6d,66,6a,6c,61,6b,6c,
6e,70,00,00
[HKEY_USERS\S-1-5-21-1390067357-1767777339-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b9,90,01,6b,c6,fc,7a,94,a1,68,01,47,4e,4d,a6,68,f8,96,91,1c,7d,e6,23,
23,17,0d,a7,86,ec,2e,5f,50,ba,6f,60,cb,74,58,1e,d0,09,35,02,02,05,c2,d6,e9,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1032)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(4852)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\ieframe.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\msi.dll
.
Completion time: 2010-10-22 21:25:38
ComboFix-quarantined-files.txt 2010-10-23 04:25
Pre-Run: 15,257,300,992 bytes free
Post-Run: 15,209,902,080 bytes free
- - End Of File - - 23FE633A1F54D4ADFE824BE10B7589F6