ComboFix 09-10-07.05 - Ming 9/2009 Fri 0:32.1.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.936.86.1033.18.2038.1442 [GMT -4:00] execution locaton: c:\documents and settings\Ming\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( The deleted files ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Ming\Application Data\wiaserva.log c:\documents and settings\Ming\Start Menu\Programs\Startup\ikowin32.exe c:\program files\StormII c:\program files\WinPCap c:\program files\WinPCap\rpcapd.exe c:\recycler\S-1-5-21-295744625-3439129356-3889171002-500 C:\text.txt c:\windows\emMON.exe c:\windows\Installer\8023f76.msp c:\windows\kb913800.exe c:\windows\system32\Cache c:\windows\system32\drivers\npf.sys c:\windows\system32\Packet.dll c:\windows\system32\pthreadVC.dll c:\windows\system32\WanPacket.dll c:\windows\system32\wpcap.dll c:\windows\ubawujon.dll . ((((((((((((((((((((((((((((((((((((((( drive/service ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_npf -------\Service_NPF ((((((((((((((((((((((((( new folders/files between 2009-09-09 and 2009-10-09 ))))))))))))))))))))))))))))))) . 2009-10-07 01:25 . 2009-10-07 01:25 -------- d-----w- C:\HEGames 2009-10-04 17:45 . 2009-10-04 17:45 290816 ----a-w- C:\wf59d7t5.exe 2009-10-04 17:41 . 2009-10-07 00:30 -------- d-----w- C:\error_fix 2009-10-04 17:39 . 2009-10-04 17:39 361369 ----a-w- C:\dds.scr 2009-10-04 17:03 . 2009-10-04 17:03 284160 ----a-w- C:\exeHelper.com 2009-10-01 11:50 . 2009-10-05 22:42 120 ----a-w- c:\documents and settings\jessica\Local Settings\Application Data\Hzebohu.dat 2009-09-28 17:17 . 2009-09-28 17:17 -------- d-----w- c:\documents and settings\jessica\Application Data\RapidTyping 2009-09-28 00:33 . 2009-09-28 00:33 -------- d-----w- c:\program files\Trend Micro 2009-09-27 00:59 . 2009-09-27 00:59 812344 ----a-w- C:\HJTInstall.exe 2009-09-27 00:39 . 2009-09-27 02:58 -------- d-----w- c:\documents and settings\Ming\.housecall6.6 2009-09-26 17:40 . 2009-09-26 17:40 -------- d-----w- c:\documents and settings\Ming\Application Data\RapidTyping 2009-09-26 17:40 . 2009-09-26 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\RapidTyping 2009-09-26 17:40 . 2009-09-26 17:40 -------- d-----w- c:\program files\RapidTyping 2009-09-26 17:40 . 2009-09-26 17:40 1967100 ----a-w- C:\RapidTyping_Setup_2.9.6.exe 2009-09-20 14:41 . 2009-09-20 14:41 10570670 ----a-w- C:\XmlPad3_02a.zip 2009-09-19 01:21 . 2009-09-29 23:50 0 ----a-w- c:\windows\system32\drivers\c10ec788.sys 2009-09-16 15:02 . 2009-09-16 15:02 -------- d-----w- c:\documents and settings\Ming\Application Data\WMHelp 2009-09-16 15:02 . 2009-09-16 15:02 -------- d-----w- c:\program files\WMHelp Software 2009-09-12 00:21 . 2009-09-21 12:28 15688 ----a-w- c:\windows\system32\lsdelete.exe 2009-09-11 12:29 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-09-11 12:26 . 2009-09-11 12:26 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864} 2009-09-11 12:26 . 2009-09-11 12:26 -------- d-----w- c:\program files\Lavasoft . (((((((((((((((((((((((((((((((((((((((( The files have been modified within three months )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-09 02:50 . 2007-11-04 19:33 664 ----a-w- c:\windows\system32\d3d9caps.dat 2009-10-08 03:37 . 2007-10-25 02:09 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-10-08 00:29 . 2009-08-30 02:14 120 ----a-w- c:\windows\Hzebohu.dat 2009-10-06 01:13 . 2009-05-02 14:06 -------- d-----w- c:\documents and settings\Ming\Application Data\OpenOffice.org2 2009-10-04 18:10 . 2008-02-28 04:30 -------- d-----w- c:\program files\Flock 2009-10-04 18:09 . 2009-07-12 14:25 -------- d-----w- c:\program files\PokerStars 2009-10-04 18:08 . 2007-11-10 03:50 -------- d-----w- c:\documents and settings\Ming\Application Data\QQUpdate 2009-10-04 18:08 . 2007-11-03 03:48 -------- d-----w- c:\documents and settings\Ming\Application Data\QQ 2009-09-25 16:35 . 2008-07-31 22:17 44944 ------w- c:\windows\system32\drivers\pxhelp20.sys 2009-09-16 22:58 . 2009-08-30 01:02 0 ----a-w- c:\windows\system32\drivers\610138fc.sys 2009-09-16 12:00 . 2008-02-10 03:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-09-03 01:37 . 2009-09-03 01:37 60744 ----a-w- c:\documents and settings\jessica\g2mdlhlpx.exe 2009-08-30 18:03 . 2008-08-12 02:12 -------- d-----w- c:\program files\PPLive 2009-08-24 01:23 . 2009-08-24 01:07 -------- d-----w- c:\documents and settings\Ming\Application Data\LimeWire 2009-08-23 00:40 . 2009-08-23 00:26 -------- d-----w- c:\program files\PartyGaming 2009-08-17 02:38 . 2005-01-10 01:26 45440 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-08-05 09:01 . 2007-10-21 04:28 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-07-17 19:01 . 2007-10-21 04:24 58880 ----a-w- c:\windows\system32\atl.dll 2009-07-14 03:43 . 2007-10-21 04:30 286208 ----a-w- c:\windows\system32\wmpdxm.dll 2007-06-17 06:22 . 2007-06-17 06:22 62784 ----a-w- c:\program files\mozilla firefox\components\QQDownloadFFH.dll 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . ------- Sigcheck ------- [7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys [7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys [7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys [-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys [7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys [7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys [7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys [7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys [-] 2007-10-30 . 90CAFF4B094573449A0872A0F919B178 . 360064 . . [5.1.2600.3244] . . c:\windows\$NtUninstallKB951748_0$\tcpip.sys [-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys [-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys [-] 2006-04-20 . 1DBF125862891817F374F407626967F4 . 359808 . . [5.1.2600.2892] . . c:\windows\$NtUninstallKB941644$\tcpip.sys [-] 2004-08-10 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB917953$\tcpip.sys . ((((((((((((((((((((((((((((((((((((( An important entry point )))))))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\documents and settings\Ming\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-04 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952] "IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032] "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-09-20 144792] "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 563984] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 2027792] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792] "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 667718] "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 602182] "EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2005-12-28 569413] "Google IME Autoupdater"="c:\program files\Google\Google Pinyin\GooglePinyinDaemon.exe" [2008-10-17 308720] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-26 198160] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-12-27 413696] "SMSERIAL"="sm56hlpr.exe" - c:\windows\sm56hlpr.exe [2006-01-11 544768] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-9-6 113664] Bluetooth Mouse.lnk - c:\program files\Bluetooth Mouse\MulMouse.exe [2007-12-2 245760] Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-8 67128] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-10-22 106560] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli ca3950.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lavasoft ad-aware service] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Tencent\\QQMusic\\QzoneMusic.exe"= "c:\\Program Files\\Juniper Networks\\Secure Application Manager\\dsSamProxy.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Documents and Settings\\Ming\\Application Data\\Juniper Networks\\Juniper Citrix Services Client\\dsCitrixProxy.exe"= "c:\\xampp\\apache\\bin\\httpd.exe"= "c:\\xampp\\mysql\\bin\\mysqld.exe"= R0 lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [9/11/2009 8:29 AM 64160] R1 NEOFLTR_600_12507;Juniper Networks TDI Filter Driver (NEOFLTR_600_12507);c:\windows\system32\drivers\NEOFLTR_600_12507.sys [12/27/2007 11:23 PM 64160] R1 NEOFLTR_630_13725;Juniper Networks TDI Filter Driver (NEOFLTR_630_13725);c:\windows\system32\drivers\NEOFLTR_630_13725.sys [11/21/2008 4:37 AM 64480] R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [12/9/2008 7:10 PM 24636] R2 lavasoft ad-aware service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 10:49 AM 1028432] R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2/23/2005 3:56 PM 53248] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/27/2008 5:24 AM 24652] S1 610138fc;610138fc;c:\windows\system32\drivers\610138fc.sys [8/29/2009 9:02 PM 0] S1 c10ec788;c10ec788;c:\windows\system32\drivers\c10ec788.sys [9/18/2009 9:21 PM 0] S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\drivers\IcdUsb2.sys [8/6/2008 8:39 PM 39048] S3 Si670m;WayTech Bluetooth USB Filter Driver;c:\windows\system32\drivers\Si670m.sys [12/2/2007 12:27 AM 13312] S4 MsDtsServer;SQL Server Integration Services;c:\program files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [3/3/2007 11:12 PM 202096] S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [12/2/2006 7:17 AM 2805000] S4 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSSQL.4\Reporting Services\ReportServer\bin\ReportingServicesService.exe [3/3/2007 11:09 PM 17264] . conten in ��task�� folder 2009-10-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 12:28] 2009-10-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3872471544-4230950355-2361766433-1006Core.job - c:\documents and settings\Ming\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 03:50] 2009-10-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3872471544-4230950355-2361766433-1006UA.job - c:\documents and settings\Ming\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 03:50] 2009-10-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3872471544-4230950355-2361766433-1035Core.job - c:\documents and settings\jessica\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-06 01:09] 2009-10-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3872471544-4230950355-2361766433-1035UA.job - c:\documents and settings\jessica\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-06 01:09] . . ------- extra scan ------- . uStart Page = https://pcln06.corp.priceline.com/dana-na/auth/url_default/welcome.cgi uInternet Settings,ProxyServer = hxxp://nw-proxy.corp.priceline.com/proxy.pac uInternet Settings,ProxyOverride = *.local IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: open with xmlpad - c:\program files\WMHelp Software\WMHelp XmlPad\WmhASPP.dll/101 IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html IE: ����?����?QQ����?�� - c:\program files\Tencent\QQ\AddEmotion.htm IE: ���͵� Bluetooth �豸(&B)... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: ���ӵ�QQ���� - c:\program files\Tencent\QQ\AddEmotion.htm TCP: {C97AE255-EEEE-45FC-8C2A-F9AB9638DC33} = 208.67.222.222,208.67.220.220 Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll Handler: wmh - {A1428E78-2D00-4590-A071-0CC9700A7768} - c:\program files\WMHelp Software\WMHelp XmlPad\WmhASPP.dll DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} - hxxp://t.live.cctv.com/ieocx/CCTVUpdateInstall.dll FF - ProfilePath - c:\documents and settings\Ming\Application Data\Mozilla\Firefox\Profiles\bze6tqx0.default\ FF - prefs.js: network.proxy.type - 4 FF - component: c:\program files\Mozilla Firefox\components\QQDownloadFFH.dll FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll FF - plugin: c:\documents and settings\Ming\Application Data\Mozilla\Firefox\Profiles\bze6tqx0.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll FF - plugin: c:\documents and settings\Ming\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll FF - plugin: c:\windows\system32\npmirage.dll FF - plugin: c:\windows\system32\npwmsdrm.dll FF - HiddenExtension: XUL Cache: {69794326-27D2-41E2-8A3F-ADB89C7E9128} - c:\documents and settings\Ming\Local Settings\Application Data\{69794326-27D2-41E2-8A3F-ADB89C7E9128} . . ------- file type ------- . txtfile=c:\windows\notepad.exe %1 . - - - - ORPHANS REMOVED - - - - WebBrowser-{65F8A3D2-4C22-4A33-9633-73167EAEEC45} - (no file) HKCU-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe HKCU-Run-Weather - c:\program files\AWS\WeatherBug\Weather.exe HKCU-Run-FormAutoFiller - c:\program files\FormAutoFiller\faf.exe HKCU-Run-Aim6 - (no file) HKLM-Run-FixCamera - c:\windows\FixCamera.exe HKLM-Run-Xkenufoqiwu - c:\windows\ubawujon.dll HKLM-Run-emMON - emMON.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-09 00:54 Windows 5.1.2600 Service Pack 3 NTFS scan hidden processes... scan hidden start group... scan hidden files ... scan complete hidden archive:0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet002\Services\msftesql] "ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe\" -s:MSSQL.2 -f:MSSQLSERVER" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-3872471544-4230950355-2361766433-1006\Software\Microsoft\Internet Explorer\MenuExt\�m�R0RQ*Q*h��`] @="c:\\Program Files\\Tencent\\QQ\\AddEmotion.htm" "contexts"=dword:00000002 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- Running processes with dynamic link library --------------------- - - - - - - - > 'lsass.exe'(616) c:\windows\ca3950.dll - - - - - - - > 'explorer.exe'(5580) c:\windows\system32\btmmhook.dll c:\program files\Kingsoft\PowerWord Lite\CBSText.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\btncopy.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\windows\ca3950.dll c:\program files\Juniper Networks\Secure Application Manager\samnsp.dll c:\program files\Bonjour\mdnsNSP.dll . ------------------------ other running processes ------------------------ . c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Juniper Networks\Common Files\dsNcService.exe c:\windows\ehome\ehrecvr.exe c:\windows\ehome\ehSched.exe c:\windows\system32\inetsrv\inetinfo.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\xampp\mysql\bin\mysqld.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\windows\ehome\mcrdsvc.exe c:\windows\system32\dllhost.exe c:\windows\system32\wbem\unsecapp.exe c:\windows\ehome\ehmsas.exe c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE c:\program files\iPod\bin\iPodService.exe c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe c:\windows\system32\mdm.exe . ************************************************************************** . finished time: 2009-10-09 1:01 - computer already restarted. ComboFix-quarantined-files.txt 2009-10-09 05:01 Pre-Run: 2,459,983,872 bytes free Post-Run: 3,569,369,088 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-CHS.exe [boot loader] default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect 308 --- E O F --- 2009-08-27 07:00