ComboFix 09-03-06.02 - Tcg2 03/07/2009 20:04:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.1014.613 [GMT 3:00]
Running from: c:\documents and settings\Tcg2\My Documents\Downloads\Programs\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Tcg2\Application Data\.#
c:\documents and settings\Tcg2\Application Data\.#\MBX@BEC@B64130.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@BEC@B64160.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@BEC@B64190.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@D00@B64130.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@D00@B64160.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@D00@B64190.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@F34@B64130.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@F34@B64160.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@F34@B64190.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@F8C@B64130.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@F8C@B64160.###
c:\documents and settings\Tcg2\Application Data\.#\MBX@F8C@B64190.###
c:\program files\IEToolbar
c:\windows\IE4 Error Log.txt
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\kakle.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\system32\x64
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2009-02-07 to 2009-03-07 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-07 17:08 606,240 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-07 17:08 4,200 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-07 17:08 --------- d-----w c:\documents and settings\Tcg2\Application Data\DMCache
2009-03-07 17:06 20,776 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-07 17:06 2,386,976 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-07 16:42 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-06 20:25 67,960 ----a-w c:\windows\system32\drivers\btwusb.sys
2009-03-06 20:25 55,352 ----a-w c:\windows\system32\drivers\btwhid.sys
2009-03-06 20:25 539,072 ----a-w c:\windows\system32\drivers\btaudio.sys
2009-03-06 20:25 37,424 ----a-w c:\windows\system32\drivers\btport.sys
2009-03-06 20:25 37,280 ----a-w c:\windows\system32\drivers\btwmodem.sys
2009-03-06 20:25 149,123 ----a-w c:\windows\system32\drivers\btwdndis.sys
2009-03-06 17:04 --------- d-----w c:\program files\WIDCOMM
2009-03-06 16:51 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-05 21:31 --------- d-----w c:\program files\Circle Developeent
2009-03-05 06:09 --------- d-----w c:\documents and settings\Tcg2\Application Data\Skype
2009-03-05 05:43 --------- d-----w c:\documents and settings\Tcg2\Application Data\skypePM
2009-03-05 02:40 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2009-03-05 02:35 --------- d-----w c:\program files\Nero
2009-03-05 02:35 --------- d-----w c:\program files\Common Files\Nero
2009-03-05 02:35 --------- d-----w c:\documents and settings\Tcg2\Application Data\Nero
2009-02-27 16:10 --------- d-----w c:\documents and settings\All Users\Application Data\WEBREG
2009-02-27 16:08 --------- d-----w c:\program files\HP
2009-02-27 16:08 --------- d-----w c:\documents and settings\All Users\Application Data\HPSSUPPLY
2009-02-27 16:07 --------- d-----w c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-02-27 16:07 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2009-02-27 16:06 --------- d-----w c:\program files\Common Files\HP
2009-02-27 15:58 --------- d-----w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-02-27 15:36 --------- d-----w c:\program files\Common Files\SWF Studio
2009-02-24 00:42 --------- d-----w c:\documents and settings\Tcg2\Application Data\MiniDm
2009-02-23 13:38 --------- d-----w c:\documents and settings\Tcg2\Application Data\dvdcss
2009-02-23 03:03 --------- d-----w c:\documents and settings\Tcg2\Application Data\Desktopicon
2009-02-23 02:57 --------- d-----w c:\program files\FormatFactory
2009-02-23 02:50 --------- d-----w c:\documents and settings\Tcg2\Application Data\IDM
2009-02-21 01:42 --------- d-----w c:\program files\Nokia
2009-02-21 01:42 --------- d-----w c:\program files\Common Files\PCSuite
2009-02-21 01:42 --------- d-----w c:\program files\Common Files\Nokia
2009-02-21 01:41 --------- d-----w c:\program files\PC Connectivity Solution
2009-02-21 01:39 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-02-21 01:04 --------- d-----w c:\program files\Your Uninstaller 2008
2009-02-21 00:54 --------- d-----w c:\documents and settings\Tcg2\Application Data\URSoft
2009-02-20 23:25 --------- d-----w c:\documents and settings\Tcg2\Application Data\PC Suite
2009-02-20 23:25 --------- d-----w c:\documents and settings\Tcg2\Application Data\Nokia
2009-02-20 23:25 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2009-02-20 23:14 --------- d-----w c:\program files\Real Alternative
2009-02-20 22:46 --------- d-----w c:\program files\arabic2regclean
2009-02-20 22:44 --------- d-----w c:\program files\DIFX
2009-02-20 22:37 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-19 11:48 64,307 ----a-w c:\windows\BricoPackUninst.cmd
2009-02-19 11:48 6,104 ----a-w c:\windows\BricoPackFoldersDelete.cmd
2009-02-18 14:54 --------- d-----w c:\program files\SaderAndWardAccess
2009-02-18 13:46 --------- d-----w c:\program files\Zoom Player
2009-02-16 02:44 --------- d-----w c:\program files\Java
2009-02-15 09:39 --------- d-----w c:\program files\Paltalk Messenger
2009-02-15 09:39 --------- d-----w c:\documents and settings\Tcg2\Application Data\Paltalk
2009-02-14 11:35 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-02-14 11:31 2,560 ----a-w c:\windows\_MSRSTRT.EXE
2009-02-14 11:09 --------- d-----w c:\program files\Stardock
2009-02-14 00:37 --------- d-----w c:\program files\GRETECH
2009-02-14 00:31 --------- d-----w c:\documents and settings\Tcg2\Application Data\GRETECH
2009-02-14 00:28 --------- d-----w c:\documents and settings\Tcg2\Application Data\MAILFUNKWINDOW
2009-02-14 00:22 --------- d-----w c:\documents and settings\All Users\Application Data\Trans Once Mess Frag
2009-02-14 00:19 --------- d-----w c:\program files\MAILFUNKWINDOW
2009-02-14 00:18 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-14 00:13 --------- d-----w c:\program files\Webshots
2009-02-13 22:52 --------- d-----w c:\program files\Windows Live
2009-02-13 22:51 --------- d-----w c:\program files\Microsoft Sync Framework
2009-02-13 22:48 --------- d-----w c:\program files\Windows Live SkyDrive
2009-02-13 03:20 --------- d-----w c:\program files\Common Files\Real
2009-02-13 03:10 --------- d-----w c:\program files\SpeedyGuide 2
2009-02-13 03:04 --------- d-----w c:\documents and settings\Tcg2\Application Data\Media Player Classic
2009-02-13 03:02 --------- d-----w c:\program files\K-Lite Codec Pack
2009-02-13 02:41 --------- d-----w c:\documents and settings\Tcg2\Application Data\vlc
2009-02-13 02:39 --------- d-----w c:\program files\VideoLAN
2009-02-13 02:16 --------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-02-13 02:14 --------- d-----w c:\program files\Microsoft
2009-02-13 02:01 --------- d-----w c:\program files\Common Files\Skype
2009-02-13 02:01 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-02-13 02:01 --------- d-----r c:\program files\Skype
2009-02-13 01:30 --------- d-----w c:\documents and settings\Tcg2\Application Data\AdobeUM
2009-02-13 01:18 --------- d-----w c:\program files\Internet Download Manager
2009-02-13 00:58 --------- d-----w c:\documents and settings\Tcg2\Application Data\IEPro
2009-02-13 00:29 --------- d-----w c:\program files\Windows Media Connect 2
2009-02-13 00:29 --------- d-----w c:\program files\IEPro
2009-02-12 23:48 --------- d-----w c:\program files\Common Files\Windows Live
2009-02-12 09:01 --------- d-----w c:\program files\CONEXANT
2009-02-12 08:56 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-12 08:56 --------- d-----w c:\program files\SigmaTel
2009-02-12 08:50 405,504 ----a-w c:\windows\stsystra.exe
2009-02-12 08:50 1,222,840 ----a-w c:\windows\system32\drivers\sthda.sys
2009-02-12 08:27 --------- d-----w c:\program files\قاموس صخر الجديد
2009-02-12 08:20 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-12 08:20 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-12 08:20 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-12 08:09 --------- d-----w c:\program files\Kaspersky Lab
2009-02-12 08:08 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-02-12 07:59 --------- d-----w c:\program files\Microsoft.NET
2009-02-12 07:58 --------- d-----w c:\program files\Microsoft Works
2009-02-12 07:56 --------- d-----w c:\program files\UnH Solutions
2009-02-12 07:56 --------- d-----w c:\program files\mqreeb
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [02/13/2009 04:14 AM 2745776]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [02/06/2009 06:53 PM 3885408]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [12/03/2008 12:47 PM 1205760]
"Dead deaf"="c:\docume~1\Tcg2\APPLIC~1\MAILFU~1\Site 16 Dale.exe" [02/14/2009 03:19 AM 552960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell QuickSet"="c:\program files\Dell\QuickSet\Quickset.exe" [07/03/2007 01:57 PM 1228800]
"Bluetooth"="c:\program files\Windows NT\Bluetooth\bluetooth.exe" [02/16/2009 04:13 AM 270441]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [03/11/2007 09:34 PM 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Bluetooth.lnk - c:\program files\Windows NT\Bluetooth\bluetooth.exe [2009-02-16 270441]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegedit"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^PalTalk.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^قائمة ابدأ^البرامج^بدء التشغيل^سرعة تشغيل Adobe Reader.lnk]
path=c:\documents and settings\All Users\قائمة ابدأ\البرامج\بدء التشغيل\سرعة تشغيل Adobe Reader.lnk
backup=c:\windows\pss\سرعة تشغيل Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Tcg2^قائمة ابدأ^البرامج^بدء التشغيل^RocketDock.lnk]
path=c:\documents and settings\Tcg2\قائمة ابدأ\البرامج\بدء التشغيل\RocketDock.lnk
backup=c:\windows\pss\RocketDock.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bluetooth]
--a------ 02/16/2009 04:13 AM 270441 c:\program files\Windows NT\Bluetooth\bluetooth.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 08/04/2004 12:56 AM 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dead deaf]
--a------ 02/14/2009 03:19 AM 552960 c:\docume~1\Tcg2\APPLIC~1\MAILFU~1\Site 16 Dale.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a------ 07/03/2007 01:57 PM 1228800 c:\program files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DELL Webcam Manager]
--------- 06/07/2007 11:14 AM 118784 c:\program files\Dell\DELL Webcam Manager\DellWMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra------ 11/15/2007 02:32 PM 166424 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 02/13/2009 04:14 AM 2745776 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
-ra------ 11/15/2007 02:33 PM 141848 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 04/13/2006 11:09 AM 49152 c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mess frag body that]
--a------ 03/07/2009 08:07 PM 774144 c:\documents and settings\All Users\Application Data\Trans Once Mess Frag\Support proxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 02/06/2009 06:53 PM 3885408 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
--a------ 11/10/2008 03:07 PM 1253376 c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
-ra------ 05/10/2007 01:01 AM 36864 c:\windows\OEM02Mon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 12/03/2008 12:47 PM 1205760 c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
-ra------ 11/15/2007 02:33 PM 137752 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 12/07/2005 10:57 PM 30208 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 02/12/2009 11:50 AM 405504 c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 02/16/2009 05:44 AM 148888 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\Windows NT\\Accessories\\en-UK\\System"=
"c:\\Documents and Settings\\Tcg2\\سطح المكتب\\صفر 16 1430 (E)\\History.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2009-02-12 235520]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2009-02-12 7424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
*******s of the 'Scheduled Tasks' folder
2009-03-07 c:\windows\Tasks\A57FB65D91DC2DB1.job
- c:\docume~1\tcg2\applic~1\mailfu~1\SHOWTHEISO.exe [02/14/2009 03:28 AM]
2009-03-04 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [12/31/2008 05:04 PM]
2009-03-07 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [12/31/2008 05:04 PM]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://ww80.com/
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: الدليل السريع - c:\windows\ww80.html
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{46012075-ED62-464b-9554-AD0BEC35D1EC} -
DPF: Microsoft XML Parser for Java -
FF - ProfilePath - c:\documents and settings\Tcg2\Application Data\Mozilla\Firefox\Profiles\q7by5ori.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\documents and settings\Tcg2\Application Data\Mozilla\Firefox\Profiles\q7by5ori.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-03-07 20:08:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Windows NT\Accessories\en-UK\System
c:\program files\Windows NT\Accessories\en-UK\System
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
c:\program files\Windows NT\Accessories\en-UK\System
c:\program files\Windows NT\Accessories\en-UK\System
c:\windows\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 03/07/2009 20:10:33 - machine was rebooted [Tcg2]
ComboFix-quarantined-files.txt 2009-03-07 17:10:29
Pre-Run: 51,367,358,464 bytes free
Post-Run: 51,271,028,736 bytes free
307 --- E O F --- 2009-02-25 02:57:58