OK, i'm back from the weekend. here is the log. i turned McAfee anti virus back on and turn will turn off the pc...
ComboFix 10-07-15.05 - Miguel 07/18/2010 20:00:50.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.867 [GMT -4:00]
Running from: c:\documents and settings\Miguel\Desktop\Virus remove stuff\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Miguel\Application Data\SystemProc
c:\documents and settings\Miguel\Application Data\SystemProc\lsass.exe
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\iqafebocovofa.dll
c:\windows\oderifuc.dll
c:\windows\uwilarejucowoz.dll
c:\windows\xpsp1hfm.log
E:\autorun.inf
Infected copy of c:\windows\system32\drivers\termdd.sys was found and disinfected
Restored copy from - Kitty had a snack
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
.
2010-07-19 00:20 . 2008-04-14 00:12 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2010-07-19 00:20 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2010-07-17 07:04 . 2010-07-17 07:04 -------- d-----w- c:\windows\system32\MpEngineStore
2010-07-17 05:02 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-15 04:09 . 2010-07-16 00:18 52432 ----a-w- c:\windows\system32\drivers\klmd.sys
2010-07-14 23:46 . 2010-07-14 23:46 -------- d-----w- c:\program files\Bonjour
2010-07-14 23:44 . 2010-07-14 23:44 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-07-09 02:39 . 2010-07-10 18:21 0 ----a-w- c:\windows\Smukis.dat
2010-07-09 02:39 . 2010-07-09 05:52 0 ----a-w- c:\windows\Dlufuy.bin
2010-07-09 02:38 . 2010-07-09 02:39 -------- d-----w- c:\documents and settings\Miguel\Local Settings\Application Data\{B32868DE-87B3-4034-B74C-E846128680A8}
2010-07-09 02:38 . 2010-07-09 02:38 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-07-09 02:32 . 2010-07-19 00:22 766464 ----a-w- c:\windows\system32\drivers\gmdbkgiy.sys
2010-07-09 02:32 . 2010-07-09 02:32 -------- d-----w- c:\documents and settings\Miguel\Local Settings\Application Data\tmaqnlsga
2010-06-24 11:56 . 2010-06-24 11:56 -------- d-----w- c:\program files\Safari
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-14 23:55 . 2006-11-03 19:55 -------- d-----w- c:\program files\iTunes
2010-07-14 23:53 . 2006-01-30 05:27 -------- d-----w- c:\program files\iPod
2010-07-14 23:53 . 2007-07-06 02:11 -------- d-----w- c:\program files\Common Files\Apple
2010-07-10 15:32 . 2010-01-26 03:00 -------- d-----w- c:\program files\ERUNT
2010-07-09 02:32 . 2006-02-12 20:49 -------- d-----w- c:\documents and settings\Miguel\Application Data\BitTorrent
2010-07-04 22:46 . 2010-01-23 14:10 -------- d-----w- c:\documents and settings\Melinda.LYCAEUM\Application Data\Apple Computer
2010-06-29 23:21 . 2007-12-25 23:36 -------- d-----w- c:\documents and settings\Miguel\Application Data\ZoomBrowser EX
2010-06-29 23:14 . 2009-10-12 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2010-06-24 11:54 . 2008-12-15 22:13 -------- d-----w- c:\documents and settings\Miguel\Application Data\Move Networks
2010-06-14 14:31 . 2006-01-27 00:34 744448 ----a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-04 16:29 . 2010-06-04 16:29 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-05-28 03:10 . 2009-11-14 22:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-06 10:41 . 2006-06-23 15:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2002-09-03 17:11 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-28 10:29 . 2010-01-07 02:07 256 ----a-w- c:\documents and settings\Miguel\pool.bin
2010-04-27 21:16 . 2010-04-23 11:27 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-04-27 21:16 . 2010-04-23 11:27 95568 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-04-27 21:16 . 2010-04-23 11:27 88480 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2010-04-27 21:16 . 2010-04-23 11:27 83496 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-04-27 21:16 . 2010-04-23 11:27 82952 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2010-04-27 21:16 . 2010-04-23 11:27 55456 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-04-27 21:16 . 2010-04-23 11:27 51688 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-04-27 21:16 . 2010-04-23 11:27 385880 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-04-27 21:16 . 2010-04-23 11:27 312616 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-04-27 21:16 . 2010-04-23 11:27 152320 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-04-20 05:30 . 2002-09-03 16:27 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-20 00:47 . 2009-06-18 11:57 3062048 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-04-20 00:47 . 2008-07-16 17:20 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2006-05-03 09:06 . 2007-03-27 01:07 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2007-03-27 01:07 31232 -csh--r- c:\windows\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2004-07-01 21:20 . 2004-07-01 21:20 212992 c:\bak\Updater.exe
2007-11-07 22:59 . 2007-10-11 00:51 39792 c:\program files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
2008-01-12 02:16 . 2008-01-12 02:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
2003-09-14 02:36 . 2003-09-14 02:36 50688 c:\program files\Common Files\Microsoft Shared\Works Shared\bak\WkUFind.exe
2007-03-26 11:07 . 2007-03-26 11:07 228088 c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\bak\RoxWatchTray9.exe
2007-08-16 13:56 . 2007-08-16 13:56 236016 c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
2007-12-26 02:29 . 2007-12-26 02:29 290112 c:\program files\DNA\bak\btdna.exe
2006-01-27 02:22 . 2003-12-18 21:37 184320 c:\program files\HP DVD\Umbrella\bak\DVDBitSet.exe
2006-01-27 02:22 . 2003-07-23 17:42 69632 c:\program files\HP DVD\Umbrella\bak\DVDTray.exe
2007-07-31 22:44 . 2007-07-31 22:44 271672 c:\program files\iTunes\bak\iTunesHelper.exe
2010-06-15 20:33 . 2010-06-15 20:33 141624 c:\program files\iTunes\iTunesHelper.exe
2007-10-29 12:51 . 2007-09-25 05:11 132496 c:\program files\Java\jre1.6.0_03\bin\bak\jusched.exe
2006-11-13 17:39 . 2006-11-13 17:39 1289000 c:\program files\Microsoft ActiveSync\bak\wcescomm.exe
2007-06-29 10:24 . 2007-06-29 10:24 286720 c:\program files\QuickTime\bak\qttask.exe
2010-03-18 01:53 . 2010-03-18 01:53 421888 c:\program files\QuickTime\QTTask.exe
2002-09-03 16:29 . 2004-08-04 07:56 15360 c:\windows\system32\bak\ctfmon.exe
2002-09-03 16:29 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe
2002-03-19 21:30 . 2002-03-19 21:30 45632 c:\windows\system32\bak\taskswitch.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-18 39408]
"Hnidahifureqijol"="c:\windows\cfseror.dll" [N/A]
"nrlolaiy"="c:\documents and settings\Miguel\Local Settings\Application Data\tmaqnlsga\kbaalsjtssd.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-07-28 4841472]
"nwiz"="nwiz.exe" [2003-07-28 323584]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-06-25 1193848]
"Ljatowayewecig"="c:\windows\iqafebocovofa.dll" [N/A]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"MRT"="c:\windows\system32\MRT.exe" [2010-07-02 34045896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\System32\NVMCTRAY.DLL" [2003-07-28 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 02:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2008-12-16 20:16 637232 ----a-w- c:\program files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A940]
2003-02-08 22:42 86102 ------w- c:\program files\Dell AIO Printer A940\dlbabmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-09-04 19:17 133104 ----atw- c:\documents and settings\Miguel\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2003-07-13 07:49 155648 -c--a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 01:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-18 16:02 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2008-02-18 10:58 206184 -c--a-w- c:\program files\TomTom HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TapiSrv"=3 (0x3)
"Schedule"=2 (0x2)
"Bonjour Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:*:Disabled:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:*:Disabled:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:*:Disabled:@xpsp2res.dll,-22017
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [11/14/2009 6:18 PM 64288]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [4/23/2010 7:27 AM 82952]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [11/24/2009 2:15 PM 206096]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/23/2010 7:27 AM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [4/23/2010 7:27 AM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [4/23/2010 7:27 AM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [4/23/2010 7:27 AM 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [4/23/2010 7:27 AM 55456]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [4/23/2010 7:27 AM 312616]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [4/23/2010 7:27 AM 88480]
S1 4K23357a;4K23357a;c:\windows\system32\drivers\4k23357a.sys [1/26/2010 3:42 AM 0]
S1 emrzszsi;emrzszsi;\??\c:\windows\system32\drivers\emrzszsi.sys --> c:\windows\system32\drivers\emrzszsi.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/26/2010 8:37 PM 135664]
S3 asbp2poa;asbp2poa;\??\c:\docume~1\Miguel\LOCALS~1\Temp\asbp2poa.sys --> c:\docume~1\Miguel\LOCALS~1\Temp\asbp2poa.sys [?]
S3 klmd23;klmd23;c:\windows\system32\drivers\klmd.sys [7/15/2010 12:09 AM 52432]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 7:17 AM 1181328]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [4/23/2010 7:27 AM 88480]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [4/23/2010 7:27 AM 83496]
S3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [5/28/2007 5:04 PM 7548]
S4 Samosdbecto;Samosdbecto; [x]
--- Other Services/Drivers In Memory ---
*Deregistered* - gmdbkgiy
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
2010-01-26 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:11]
2010-01-26 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:11]
2010-01-26 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:11]
2010-01-26 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:11]
2010-01-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:11]
2008-10-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]
2010-06-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0d018b5720a4.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-27 00:36]
2009-10-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1592454029-2147250837-1004Core1ca59fb881124ee.job
- c:\documents and settings\Miguel\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 19:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp:/www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Send To &Bluetooth - c:\program files\DLink\Bluetooth Software\btsendto_ie_ctx.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://216.128.199.100:2202/activex/AMC.cab
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-4K23357a
SafeBoot-klmd23.sys
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-18 20:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gmdbkgiy]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-725345543-1592454029-2147250837-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-725345543-1592454029-2147250837-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-725345543-1592454029-2147250837-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-725345543-1592454029-2147250837-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-725345543-1592454029-2147250837-1004\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000002
.
Completion time: 2010-07-18 20:28:24
ComboFix-quarantined-files.txt 2010-07-19 00:28
Pre-Run: 13,411,848,192 bytes free
Post-Run: 13,527,121,920 bytes free
- - End Of File - - 8860002A3486B29CAFCC47F26D955024