ComboFix 10-02-07.06 - Owner 02/07/2010 23:45:25.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3063.2702 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\FRIEND.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\data
c:\documents and settings\All Users\Application Data\_VOIDkrl32mainweq.dll
c:\documents and settings\All Users\Application Data\_VOIDmainqt.dll
c:\windows\system32\_VOIDktkbodlsmr.log
c:\windows\system32\_VOIDmgfqxswpdn.dll
c:\windows\system32\_VOIDmqlvbwulki.dat
c:\windows\system32\_VOIDqprvkspxng.dll
c:\windows\system32\_VOIDqvnbmcwjkc.dll
c:\windows\system32\_VOIDrystholexu.dll
c:\windows\system32\_VOIDshsyst.dll
c:\windows\system32\18467.exe
c:\windows\system32\6334.exe
c:\windows\system32\drivers\_VOIDmnreetbbmu.sys
c:\windows\system32\ide.txt
c:\windows\system32\qks.txt
c:\windows\system32\xef.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service__VOIDd.sys
-------\Legacy__VOIDd.sys
((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 )))))))))))))))))))))))))))))))
.
2010-02-05 19:02 . 2010-01-20 00:00 6551808 ---ha-w- c:\documents and settings\Owner\Application Data\mjusbsp\in00000\setup.exe
2010-02-05 19:02 . 2010-01-19 23:57 730032 ---ha-w- c:\documents and settings\Owner\Application Data\mjusbsp\ar00000\install.exe
2010-02-04 15:16 . 2010-02-04 15:16 -------- d-----w- c:\documents and settings\Owner\Application Data\OpenOffice.org2
2010-02-04 03:56 . 2010-02-04 03:56 43008 ----a-w- c:\windows\system32\gpaeql8.dll
2010-02-03 18:40 . 2010-02-03 18:40 388096 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-02-03 18:40 . 2010-02-03 18:40 -------- d-----w- c:\program files\TrendMicro
2010-02-03 18:35 . 2010-02-03 18:35 -------- d-----w- c:\program files\Trend Micro
2010-02-03 13:26 . 2010-02-03 13:26 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-02-03 13:15 . 2009-07-28 20:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-03 13:01 . 2010-02-03 13:01 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-02-03 13:01 . 2010-02-03 13:01 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-02-03 13:01 . 2010-02-03 13:09 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-03 12:19 . 2010-02-03 12:19 -------- d-----w- c:\windows\Internet Logs
2010-02-03 08:33 . 2010-02-03 08:33 -------- d-----w- c:\documents and settings\Owner\Application Data\AVG8
2010-02-03 04:25 . 2010-01-28 21:57 163280 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-03 04:25 . 2010-01-28 21:54 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-03 04:25 . 2010-01-28 21:54 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-03 04:25 . 2010-01-28 21:57 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-03 04:25 . 2010-01-28 21:54 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-03 04:25 . 2010-01-28 21:54 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-03 04:25 . 2010-01-28 21:53 28240 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-03 04:25 . 2010-01-28 22:09 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-03 04:25 . 2010-01-28 22:09 152672 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-03 04:25 . 2010-02-03 04:25 -------- d-----w- c:\program files\Alwil Software
2010-02-03 04:25 . 2010-02-03 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-02-03 03:51 . 2010-02-03 03:51 -------- d-----w- c:\program files\OpenOffice.org 2.3
2010-02-03 03:49 . 2010-02-03 03:49 -------- d-----w- c:\program files\Common Files\Java
2010-02-03 03:46 . 2010-02-06 22:02 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-03 03:45 . 2005-08-25 23:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2010-02-03 03:45 . 2010-02-03 04:13 -------- d-----w- c:\program files\SpywareBlaster
2010-02-02 22:49 . 2010-02-02 22:49 -------- d-----w- c:\documents and settings\hunter cadence\Application Data\Media Player Classic
2010-01-24 09:27 . 2010-01-24 09:27 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Application Updater
2010-01-24 08:02 . 2010-01-24 08:02 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-24 08:01 . 2010-01-24 08:01 79488 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-23 03:24 . 2010-01-20 00:00 6551808 ---ha-w- c:\documents and settings\Owner\Application Data\mjusbsp\Upgrade\setup2.exe
2010-01-23 03:24 . 2010-01-19 23:57 730032 ---ha-w- c:\documents and settings\Owner\Application Data\mjusbsp\Upgrade\install2.exe
2010-01-20 00:01 . 2010-01-20 00:01 93016 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\ug00000\magicJack.dll
2010-01-20 00:00 . 2010-01-20 00:00 6551808 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\ug00000\setup.exe
2010-01-20 00:00 . 2010-01-20 00:00 416248 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\magicJackLoader.exe
2010-01-20 00:00 . 2010-01-20 00:00 480608 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\octvqe1_apiw.dll
2010-01-20 00:00 . 2010-01-20 00:00 214360 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\TjVista.dll
2010-01-20 00:00 . 2010-01-20 00:00 337240 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\TjIpSys.dll
2010-01-20 00:00 . 2010-01-20 00:00 607600 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\SJHandsetMagicJack.dll
2010-01-20 00:00 . 2010-01-20 00:00 87384 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\st00000\mjsetup.exe
2010-01-20 00:00 . 2010-01-20 00:00 93016 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\st00000\magicJack.dll
2010-01-20 00:00 . 2010-01-20 00:00 93016 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\magicJack.dll
2010-01-19 23:58 . 2010-01-19 23:58 12482904 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\magicJack.exe
2010-01-19 23:57 . 2010-01-19 23:57 730032 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\ug00000\install.exe
2010-01-19 23:57 . 2010-01-19 23:57 87384 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\in00000\mjsetup.exe
2010-01-19 23:57 . 2010-01-19 23:57 93016 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\in00000\magicJack.dll
2010-01-19 23:55 . 2010-01-19 23:55 441704 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2010-01-19 23:55 . 2010-01-19 23:55 441704 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\st00000\magicJackSplash.exe
2010-01-19 23:55 . 2010-01-19 23:55 441704 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\magicJackSplash.exe
2010-01-19 23:55 . 2010-01-19 23:55 441704 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\in00000\magicJackSplash.exe
2010-01-19 23:55 . 2010-01-19 23:55 50520 ----a-w- c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe
2010-01-18 18:42 . 2003-12-12 23:41 53248 ----a-w- c:\windows\system32\ciaXPRegSvr20.dll
2010-01-18 18:42 . 2004-11-19 08:45 200704 ----a-w- c:\windows\system32\ciaSCls20.dll
2010-01-18 18:42 . 2003-12-14 22:47 692224 ----a-w- c:\windows\system32\ciaResSvr20.dll
2010-01-18 18:41 . 2001-05-29 15:00 352256 ----a-w- c:\windows\system32\ijl15.dll
2010-01-18 18:41 . 2007-04-05 02:27 278528 ----a-w- c:\windows\system32\duzactx.dll
2010-01-18 18:41 . 2008-02-21 07:41 732656 ----a-w- c:\windows\system32\wodPop3.dll
2010-01-18 18:41 . 2008-04-04 09:14 753136 ----a-w- c:\windows\system32\wodSmtp.dll
2010-01-18 18:40 . 2010-02-03 12:53 -------- d-----w- c:\windows\FontApp
2010-01-17 22:49 . 2010-01-17 22:49 -------- d-sh--w- c:\documents and settings\hunter cadence\PrivacIE
2010-01-17 22:49 . 2010-01-17 22:49 -------- d-----w- c:\documents and settings\hunter cadence\Local Settings\Application Data\Yahoo
2010-01-17 22:49 . 2010-02-02 22:47 -------- d-----w- c:\documents and settings\hunter cadence\Application Data\Search Settings
2010-01-17 22:49 . 2010-01-17 22:49 -------- d-----w- c:\documents and settings\hunter cadence\Local Settings\Application Data\IObitCom
2010-01-17 22:49 . 2010-01-17 22:49 -------- d-----w- c:\documents and settings\hunter cadence\Local Settings\Application Data\Conduit
2010-01-17 15:49 . 2010-01-17 15:49 -------- d-----w- c:\documents and settings\Guest\Application Data\FUJIFILM
2010-01-14 02:51 . 2001-08-18 03:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-01-14 02:51 . 2008-04-14 10:42 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-01-14 02:51 . 2008-04-14 05:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-01-14 02:51 . 2008-04-14 05:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-14 02:40 . 2010-01-14 02:41 -------- d-----w- c:\program files\FinePixViewerS
2010-01-14 02:40 . 2010-01-14 02:40 -------- d-----w- c:\documents and settings\Owner\Application Data\InstallShield
2010-01-14 02:39 . 2010-01-14 02:48 -------- d-----w- c:\documents and settings\Owner\Application Data\FUJIFILM
2010-01-13 22:19 . 2010-01-14 15:51 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2010-01-13 09:24 . 2010-01-13 09:24 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\tjnet
2010-01-13 03:19 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 22:22 . 2010-01-11 22:29 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Ahead
2010-01-11 22:21 . 2010-01-11 22:50 -------- d-----w- c:\documents and settings\Owner\Application Data\Ahead
2010-01-11 22:17 . 2010-01-14 15:49 -------- d-----w- c:\program files\Common Files\Ahead
2010-01-11 22:17 . 2010-01-11 22:17 -------- d-----w- c:\program files\Nero
2010-01-11 19:22 . 2010-02-05 19:02 -------- d-----w- c:\documents and settings\Owner\Application Data\mjusbsp
2010-01-11 19:06 . 2008-04-14 05:15 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2010-01-11 19:06 . 2008-04-14 05:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-01-11 19:06 . 2008-04-14 05:15 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-01-11 19:06 . 2008-04-14 05:15 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-01-11 19:06 . 2008-04-14 05:15 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-01-11 19:06 . 2008-04-14 05:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-01-10 14:36 . 2010-02-03 08:11 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-10 14:36 . 2010-02-03 03:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-03 19:39 . 2009-06-01 04:41 -------- d-----w- c:\program files\uTorrent
2010-02-03 18:09 . 2009-10-30 02:52 15080 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-03 13:09 . 2009-05-17 15:37 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2010-02-03 13:01 . 2009-05-17 15:37 -------- d-----w- c:\program files\AVG
2010-02-03 12:46 . 2009-05-17 15:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-03 08:54 . 2009-12-16 00:08 -------- d-----w- c:\program files\CheckPoint
2010-02-03 08:38 . 2009-05-28 16:35 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-02-03 03:51 . 2009-05-28 21:56 -------- d-----w- c:\program files\Java
2010-02-02 07:22 . 2006-02-28 12:00 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-01-24 20:11 . 2009-10-27 23:14 -------- d-----w- c:\documents and settings\Guest\Application Data\Search Settings
2010-01-17 22:49 . 2010-01-06 02:19 -------- d--h--r- c:\documents and settings\hunter cadence\Application Data\yahoo!
2010-01-14 02:40 . 2009-05-17 16:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-10 14:46 . 2009-06-28 03:50 -------- d-----w- c:\documents and settings\Owner\Application Data\IObit
2010-01-10 01:47 . 2009-12-31 03:07 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-07 21:07 . 2009-05-17 15:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-05-17 15:21 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 02:19 . 2010-01-06 02:19 -------- d-----w- c:\documents and settings\hunter cadence\Application Data\Windows Desktop Search
2010-01-06 02:19 . 2010-01-06 02:19 -------- d-----w- c:\documents and settings\hunter cadence\Application Data\CheckPoint
2009-12-31 07:17 . 2009-12-31 07:17 -------- d-----w- c:\documents and settings\Owner\Application Data\Aura4You
2009-12-31 07:17 . 2009-12-31 07:17 -------- d-----w- c:\program files\Aura4You
2009-12-31 03:03 . 2009-05-28 18:41 -------- d-----w- c:\program files\CA Yahoo! Anti-Spy
2009-12-27 20:57 . 2009-12-27 20:57 -------- d-----w- c:\program files\Shanghai Mahjong
2009-12-27 20:02 . 2009-12-27 20:02 -------- d-----w- c:\documents and settings\Guest\Application Data\SpinTop
2009-12-21 19:14 . 2006-02-28 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 15:53 . 2009-12-17 15:53 -------- d-----w- c:\documents and settings\Guest\Application Data\Malwarebytes
2009-12-16 15:57 . 2009-05-28 18:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-12-16 03:09 . 2009-12-16 03:09 -------- d-----w- c:\documents and settings\Guest\Application Data\CheckPoint
2009-12-16 00:08 . 2009-12-16 00:08 -------- d-----w- c:\documents and settings\Owner\Application Data\CheckPoint
2009-12-15 22:29 . 2009-12-15 22:29 13104 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-15 16:03 . 2009-12-15 16:03 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Dealio
2009-12-15 16:03 . 2009-12-15 16:03 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Search Settings
2009-12-14 00:28 . 2009-12-14 00:28 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-21 15:51 . 2006-02-28 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2001-03-30 17:14 . 2001-03-30 17:14 32768 --sha-r- c:\windows\system32\pinoutld.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 81920]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"cdloader"="c:\documents and settings\Owner\Application Data\mjusbsp\cdloader2.exe" [2010-01-19 50520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-05-25 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-05-25 126976]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-01-28 2757512]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2010-1-13 303104]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\mjusbsp\\magicJack.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/2/2010 11:25 PM 163280]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [5/28/2009 11:36 AM 464264]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/2/2010 11:25 PM 19024]
S0 apbkffw;apbkffw;c:\windows\system32\drivers\wrxjubge.sys --> c:\windows\system32\drivers\wrxjubge.sys [?]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2/3/2010 8:01 AM 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2/3/2010 8:01 AM 30104]
S3 SDTHelper;Helper driver for SDT-Tool;c:\documents and settings\Owner\Desktop\virus protection\radix_installer_trial\SDTHLPR.sys [11/25/2007 5:01 PM 9401]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-ISW - c:\program files\CheckPoint\ZAForceField\ForceField.exe
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\documents and settings\Owner\Desktop\mbam-installer\explorer.exe
AddRemove-WinImage - c:\documents and settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8LYBC1YV\winima81[1]\winimage.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-07 23:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A163618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf763bf28
\Driver\ACPI -> ACPI.sys @ 0xf75aecb8
\Driver\atapi -> atapi.sys @ 0xf74a0852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: Intel(R) PRO/1000 MT Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf7439bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7446a21
SendHandler -> NDIS.sys @ 0xf742487b
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(724)
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
Completion time: 2010-02-07 23:57:24
ComboFix-quarantined-files.txt 2010-02-08 04:57
Pre-Run: 60,405,248,000 bytes free
Post-Run: 61,232,541,696 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - D2AFDC3B06C8049B115BDEF2CB152869