سم اخوي
ComboFix 09-04-29.01 - RAMOLG 04/30/2009 3:00.1 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1256.966.1033.18.1014.589 [GMT 3:00]
Running from: c:\documents and settings\RAMOLG\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-30 )))))))))))))))))))))))))))))))
.
2009-04-26 21:08 . 2009-04-26 21:08 -------- d-----w c:\program files\LtUcx
2009-04-24 16:47 . 2009-04-24 16:47 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-04-24 11:00 . 2009-04-24 11:00 -------- d-sh--w c:\documents and settings\RAMOLG\PrivacIE
2009-04-24 10:47 . 2009-04-24 10:47 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-04-24 10:47 . 2009-04-24 10:47 -------- d-sh--w c:\documents and settings\RAMOLG\IECompatCache
2009-04-24 10:46 . 2009-04-24 10:46 -------- d-sh--w c:\documents and settings\RAMOLG\IETldCache
2009-04-24 10:42 . 2009-04-24 10:42 -------- d-----w c:\windows\ie8updates
2009-04-24 10:40 . 2009-04-24 10:40 -------- d--h--w c:\windows\ie8
2009-04-24 10:39 . 2009-02-28 04:55 105984 ------w c:\windows\system32\dllcache\iecompat.dll
2009-04-24 10:28 . 2009-04-24 10:28 -------- d-----w c:\program files\Messenger Plus! Live
2009-04-24 06:28 . 2009-04-24 06:28 -------- d-----w c:\documents and settings\RAMOLG\Tracing
2009-04-24 01:12 . 2006-11-29 10:06 3426072 ----a-w c:\windows\system32\d3dx9_32.dll
2009-04-24 01:12 . 2009-04-24 01:12 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-04-24 01:11 . 2009-04-24 01:11 -------- d-----w c:\program files\Microsoft
2009-04-23 18:37 . 2009-04-23 18:37 -------- d-----w c:\documents and settings\RAMOLG\Application Data\Intel
2009-04-23 18:37 . 2009-04-23 18:37 -------- d-----w c:\documents and settings\LocalService\Application Data\Intel
2009-04-23 18:37 . 2009-04-23 18:37 -------- d-----w c:\documents and settings\NetworkService\Application Data\Intel
2009-04-23 18:37 . 2009-04-23 18:37 21361 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-04-23 18:37 . 2009-04-23 18:37 21361 ----a-w c:\windows\AegisP.sys
2009-04-23 18:37 . 2009-04-23 18:37 376832 ----a-w c:\windows\system32\AegisI5Installer.exe
2009-04-23 18:36 . 2009-04-23 18:36 -------- d-----w c:\documents and settings\All Users\Application Data\Intel
2009-04-23 18:36 . 2008-03-13 00:25 2530176 ----a-w c:\windows\system32\drivers\NETw4x32.sys
2009-04-23 18:36 . 2007-08-08 12:28 684032 ----a-w c:\windows\system32\NETw4c32.dll
2009-04-23 18:36 . 2007-08-08 12:29 2772992 ----a-w c:\windows\system32\NETw4r32.dll
2009-04-23 16:44 . 2009-04-23 16:44 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-23 16:07 . 2008-10-16 11:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-04-23 16:07 . 2008-10-16 11:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-04-23 13:41 . 2007-01-13 06:49 159744 ----a-w c:\windows\system32\igfxres.dll
2009-04-23 13:37 . 2009-04-23 13:37 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-23 13:36 . 2009-04-23 13:37 -------- d-----w c:\program files\Windows Live
2009-04-23 13:22 . 2008-12-04 06:31 53248 ----a-w c:\windows\system32\CSVer.dll
2009-04-23 13:20 . 2009-04-23 13:20 -------- d-----w c:\program files\Marvell
2009-04-23 13:08 . 2007-01-13 07:33 57344 ----a-w c:\windows\system32\igxprd32.dll
2009-04-23 13:08 . 2007-01-13 07:33 5672032 ----a-w c:\windows\system32\drivers\igxpmp32.sys
2009-04-23 13:08 . 2007-01-13 07:32 1563776 ----a-w c:\windows\system32\igxpdv32.dll
2009-04-23 13:08 . 2007-01-13 07:32 149504 ----a-w c:\windows\system32\igxpgd32.dll
2009-04-23 13:08 . 2007-01-13 07:46 204800 ----a-w c:\windows\system32\igfxCoIn_v4764.dll
2009-04-23 13:08 . 2007-01-13 07:33 2482688 ----a-w c:\windows\system32\igxpdx32.dll
2009-04-23 13:08 . 2006-11-10 05:25 319456 ----a-w c:\windows\system32\difxapi.dll
2009-04-23 13:08 . 2007-01-19 07:14 389120 ----a-w c:\windows\system32\igxpun.exe
2009-04-23 13:08 . 2009-04-23 13:08 -------- d-----w C:\Intel
2009-04-23 12:56 . 2009-04-23 12:56 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-23 12:45 . 2009-04-23 12:45 -------- d-----w c:\documents and settings\RAMOLG\Application Data\Paltalk
2009-04-23 12:45 . 2009-04-23 12:45 -------- d-----w c:\windows\PaltalkScene
2009-04-23 12:45 . 2009-04-23 12:45 -------- d-----w c:\program files\Paltalk Messenger
2009-04-23 12:45 . 2009-04-23 12:45 -------- d-----w c:\program files\ma-config.com
2009-04-23 12:45 . 2009-04-23 12:45 -------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-04-23 12:24 . 2009-03-10 19:26 1403264 ----a-w c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-04-23 12:24 . 2009-03-10 19:18 453512 ----a-w c:\windows\system32\KB905474\wgasetup.exe
2009-04-23 12:24 . 2009-04-23 12:24 -------- d-----w c:\windows\system32\KB905474
2009-04-23 12:23 . 2009-04-23 12:23 -------- d-----w c:\program files\MSXML 4.0
2009-04-23 10:56 . 2009-04-23 10:56 -------- d-----w c:\windows\system32\scripting
2009-04-23 10:56 . 2009-04-23 10:56 -------- d-----w c:\windows\l2schemas
2009-04-23 10:56 . 2009-04-23 10:56 -------- d-----w c:\windows\system32\en
2009-04-23 10:56 . 2009-04-23 10:56 -------- d-----w c:\windows\system32\bits
2009-04-23 10:53 . 2009-04-23 10:53 -------- d-----w c:\windows\ServicePackFiles
2009-04-23 10:43 . 2009-04-23 10:43 -------- d-----w c:\program files\Common Files\xing shared
2009-04-23 00:47 . 2008-10-15 16:34 337408 ------w c:\windows\system32\dllcache\netapi32.dll
2009-04-23 00:45 . 2008-06-13 11:05 272128 ------w c:\windows\system32\dllcache\bthport.sys
2009-04-23 00:45 . 2008-06-13 11:05 272128 ------w c:\windows\system32\drivers\bthport.sys
2009-04-23 00:42 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-23 00:42 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-23 00:40 . 2008-12-11 10:57 333952 ------w c:\windows\system32\dllcache\srv.sys
2009-04-23 00:31 . 2009-04-23 00:31 -------- d-----w c:\program files\Trend Micro
2009-04-23 00:27 . 2008-05-08 14:02 203136 ------w c:\windows\system32\dllcache\rmcast.sys
2009-04-23 00:26 . 2008-04-11 19:04 691712 ------w c:\windows\system32\dllcache\inetcomm.dll
2009-04-23 00:25 . 2009-04-23 00:26 -------- d-----w C:\Downloads
2009-04-23 00:25 . 2009-04-23 00:25 -------- d-----w c:\program files\Orbitdownloader
2009-04-23 00:25 . 2009-04-23 00:25 -------- d-----w c:\documents and settings\RAMOLG\Application Data\Orbit
2009-04-23 00:02 . 2009-04-23 00:02 0 ----a-w c:\windows\nsreg.dat
2009-04-23 00:02 . 2009-04-23 00:02 -------- d-----w c:\documents and settings\RAMOLG\Local Settings\Application Data\Mozilla
2009-04-22 22:50 . 2009-04-22 22:50 -------- d-----w c:\program files\Windows Media Connect 2
2009-04-22 22:48 . 2009-04-22 22:48 -------- d-----w c:\windows\system32\drivers\UMDF
2009-04-22 22:48 . 2009-04-22 22:48 -------- d-----w c:\windows\system32\LogFiles
2009-04-22 22:38 . 2009-04-22 22:38 -------- d-----w c:\documents and settings\RAMOLG\Application Data\IDM
2009-04-22 22:38 . 2009-04-22 22:38 -------- d-----w c:\documents and settings\RAMOLG\Application Data\DMCache
2009-04-22 22:36 . 2009-04-22 22:36 -------- d-----w c:\program files\CCleaner
2009-04-22 22:33 . 2009-04-22 22:33 -------- d-sh--w C:\FOUND.000
2009-04-22 22:00 . 2008-10-24 11:21 455296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-22 21:17 . 2009-04-22 21:17 -------- d--h--w c:\windows\$hf_mig$
2009-04-22 20:58 . 2009-04-22 20:58 -------- d-sh--w c:\documents and settings\RAMOLG\UserData
2009-04-22 20:39 . 2006-06-12 15:16 208896 ----a-w c:\windows\system32\NVUNINST.EXE
2009-04-22 20:29 . 2009-04-22 20:29 -------- d-----w c:\documents and settings\All Users\Application Data\Atheros
2009-04-22 20:29 . 2006-11-22 16:00 6963805 ----a-w c:\windows\SUYINVideoClassCam_v5.7.16.0.exe
2009-04-22 20:29 . 2006-09-26 08:47 10049570 ----a-w c:\windows\SUYINUSB20PCCam_v5.7.8.003-1.8.exe
2009-04-22 20:29 . 2006-11-10 16:19 10655802 ----a-w c:\windows\SUYINUSB20PCCam_v5.7.8.003-1.10.exe
2009-04-22 20:29 . 2006-11-15 14:39 24576 ----a-w c:\windows\DetectHWID.exe
2009-04-22 20:29 . 2009-04-22 20:29 -------- d-----w c:\windows\SUYIN NB Cam
2009-04-22 20:28 . 2009-04-22 20:28 -------- d-----w c:\windows\system32\DRVSTORE
2009-04-22 20:25 . 2006-06-13 06:57 956026 ----a-w c:\windows\system32\ialmdd5.dll
2009-04-22 20:25 . 2006-06-13 06:57 61440 ----a-w c:\windows\system32\iAlmCoIn_v4543.dll
2009-04-22 20:25 . 2007-01-13 06:47 163840 ----a-w c:\windows\system32\hkcmd.exe
2009-04-22 20:25 . 2007-01-13 06:46 102400 ----a-w c:\windows\system32\hccutils.dll
2009-04-22 19:18 . 2009-04-22 19:18 -------- d-----w c:\program files\Launch Manager
2009-04-22 19:11 . 1998-10-29 14:45 306688 ----a-w c:\windows\IsUninst.exe
2009-04-22 18:59 . 2006-07-04 14:48 64512 ------w c:\windows\system32\agrsmdel.exe
2009-04-22 18:56 . 2009-04-22 18:56 -------- d-----w c:\program files\Intel
2009-04-22 18:56 . 2009-04-22 18:56 -------- d-----w c:\windows\tiinst
2009-04-22 18:55 . 2009-04-22 18:55 -------- d-----w c:\windows\Options
2009-04-22 18:54 . 2006-07-14 09:13 5120 ----a-w c:\windows\system32\FILTRCOI.DLL
2009-04-22 18:54 . 2006-07-14 09:13 16896 ----a-w c:\windows\system32\drivers\DKbFltr.SYS
2009-04-22 18:54 . 2006-07-14 09:13 147456 ----a-w c:\windows\UNINST32.EXE
2009-04-22 18:54 . 2006-07-14 09:13 49152 ----a-w c:\windows\system32\QtBtLib.dll
2009-04-22 18:54 . 2005-12-13 18:50 88204 ----a-w c:\windows\AGRSMMSG.exe
2009-04-22 18:54 . 2005-05-03 15:10 68096 ----a-w c:\windows\agrsmdel.exe
2009-04-22 18:54 . 2005-12-13 20:08 1124097 ----a-w c:\windows\system32\drivers\AGRSM.sys
2009-04-22 17:40 . 2006-06-23 07:40 245824 ----a-r c:\windows\Instexec.exe
2009-04-22 17:40 . 2006-06-23 07:39 245824 ----a-r c:\windows\system32\InstExec.exe
2009-04-22 17:40 . 2009-04-22 17:40 -------- d-----w c:\program files\Common Files\Logitech
2009-04-22 17:40 . 2009-04-22 17:40 -------- d-----w c:\program files\Common Files\Acer
2009-04-22 17:37 . 2009-04-22 17:37 -------- d-----w c:\program files\WIDCOMM
2009-04-22 17:15 . 2009-04-22 17:15 -------- d-----w c:\program files\Common Files\Real
2009-04-22 17:15 . 2009-04-22 17:15 -------- d-----w c:\program files\Real
2009-04-22 15:18 . 2009-04-22 15:18 -------- d-----w c:\windows\system32\Lang
2009-04-22 15:16 . 2006-07-19 06:41 40960 ----a-w c:\windows\system32\ChCfg.exe
2009-04-22 15:16 . 2006-07-19 06:42 135168 ----a-w c:\windows\system32\RtlCPAPI.dll
2009-04-22 15:16 . 2009-04-22 15:16 -------- d-----w c:\windows\BUVC_AP
2009-04-22 15:16 . 2008-04-13 18:45 6272 ----a-w c:\windows\system32\drivers\splitter.sys
2009-04-22 15:16 . 2008-04-13 19:17 83072 ----a-w c:\windows\system32\drivers\wdmaud.sys
2009-04-22 15:16 . 2008-04-13 18:45 52864 ----a-w c:\windows\system32\drivers\DMusic.sys
2009-04-22 15:16 . 2008-04-13 18:45 56576 ----a-w c:\windows\system32\drivers\swmidi.sys
2009-04-22 15:16 . 2009-04-22 15:16 -------- d-----w c:\documents and settings\RAMOLG\Application Data\InstallShield
2009-04-22 15:16 . 2008-04-13 16:39 142592 ----a-w c:\windows\system32\drivers\aec.sys
2009-04-22 15:16 . 2008-04-13 18:45 172416 ----a-w c:\windows\system32\drivers\kmixer.sys
2009-04-22 15:14 . 2006-07-19 06:41 487424 ----a-w c:\windows\RtlExUpd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 00:02 . 2009-04-22 12:04 7308 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-04-30 00:02 . 2009-04-22 12:04 2296 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-04-23 10:59 . 2009-04-22 02:43 166455 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-22 21:43 . 2008-01-29 14:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-04-22 17:39 . 2009-04-22 17:39 -------- d-----w c:\program files\Acer
2009-04-22 15:15 . 2009-04-22 15:15 -------- d-----w c:\program files\Realtek
2009-04-22 02:44 . 2009-04-22 02:44 -------- d-----w c:\program files\microsoft frontpage
2009-04-22 02:43 . 2004-05-23 09:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-04-22 02:40 . 2009-04-22 02:40 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-08 01:34 . 2004-05-23 09:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2004-05-23 09:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2004-05-23 09:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2004-05-23 09:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2004-05-23 09:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2004-05-23 09:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2004-05-23 09:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2004-05-23 09:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2004-05-23 09:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2004-05-23 09:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2004-05-23 09:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-09 12:10 . 2004-05-23 09:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-05-23 09:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-05-23 09:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-05-23 09:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-05-23 09:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 16:43 . 2009-02-06 16:43 307576 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 15:52 . 2009-02-06 15:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 11:11 . 2004-05-23 09:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2004-05-23 09:00 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-05-23 09:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 19:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2004-05-23 09:00 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-03-24 1488112]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-22 206088]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-19 53248]
"LogitechCameraAssistant"="c:\program files\Acer\OrbiCam\CameraAssistant.exe" [2006-06-26 331776]
"LogitechVideo[inspector]"="c:\program files\Acer\OrbiCam\InstallHelper.exe" [2006-06-26 12:55 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2006-06-23 225280]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2006-07-14 471040]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-23 198160]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2008-03-04 999424]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2008-03-04 1101824]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-07-19 16248320]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-07-19 2879488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-1-17 618557]
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-4-23 1719496]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-04-21 216232]
S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-04-22 33808]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{62365186-3025-11de-92c7-0018deb5c595}]
\Shell\AutoRun\command - WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f031d4a-3353-11de-92d1-0018deb5c595}]
\Shell\AutoRun\command - WDSetup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-04-30 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-23 19:18]
2009-04-29 c:\windows\Tasks\User_Feed_Synchronization-{0A25D6D4-9651-41C4-ACD4-5F9B8865CBFC}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.googil.com/
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: {C171FF59-8C55-4796-A398-4F5D02B4C763} - hxxp://76.76.24.112/saudi1999/talks3n.cab
FF - ProfilePath - c:\documents and settings\RAMOLG\Application Data\Mozilla\Firefox\Profiles\6sscfwms.default\
FF - prefs.js: browser.startup.homepage -
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-04-30 03:05
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(540)
c:\windows\system32\netprovcredman.dll
- - - - - - - > 'explorer.exe'(4396)
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\INTEL\WIRELESS\BIN\S24EVMON.EXE
c:\program files\COMMON FILES\LOGITECH\LVMVFM\LVPRCSRV.EXE
c:\program files\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE
c:\program files\INTEL\WIRELESS\BIN\EVTENG.EXE
c:\program files\INTEL\WIRELESS\BIN\REGSRVC.EXE
c:\program files\LAUNCH MANAGER\QTZGACER.EXE
c:\windows\SYSTEM32\IGFXSRVC.EXE
c:\windows\SYSTEM32\IGFXEXT.EXE
c:\program files\ORBITDOWNLOADER\ORBITNET.EXE
c:\windows\system32\wscntfy.exe
c:\docume~1\RAMOLG\LOCALS~1\Temp\RtkBtMnt.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2009-04-30 3:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-30 00:06
Pre-Run: 23,849,730,048 bytes free
Post-Run: 23,760,863,232 bytes free
290 --- E O F --- 2009-04-29 12:09