offline
- Springfield
- Moderator foruma
- 100%Milanista
- Information Technology
- Pridružio: 23 Avg 2008
- Poruke: 2634
- Gde živiš: Milan, Italy
|
ComboFix 12-08-14.05 - user 15.08.2012 2:20.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.280 [GMT 2:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\user\Start Menu\Programs\Download programs.url
c:\documents and settings\user\Start Menu\Programs\Games.url
c:\documents and settings\user\Start Menu\Programs\Translator.url
c:\documents and settings\user\Start Menu\Programs\Videos.url
c:\documents and settings\user\WINDOWS
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\drivers\etc\hosts.ics
.
.
((((((((((((((((((((((((( Files Created from 2012-07-15 to 2012-08-15 )))))))))))))))))))))))))))))))
.
.
2012-08-15 00:09 . 2012-08-15 00:09 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2012-08-15 00:06 . 2012-08-15 00:06 -------- d-sh--w- c:\documents and settings\user\IETldCache
2012-08-15 00:04 . 2012-08-15 00:05 -------- dc-h--w- c:\windows\ie8
2012-08-14 23:11 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2012-08-14 23:10 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2012-08-14 23:10 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2012-08-14 23:09 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2012-08-14 23:08 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2012-08-14 23:08 . 2010-08-27 08:02 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2012-08-14 23:08 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2012-08-14 23:07 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2012-08-14 23:06 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2012-08-14 23:06 . 2012-07-04 14:05 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2012-08-14 23:03 . 2012-05-28 18:16 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2012-08-14 23:01 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2012-08-14 23:00 . 2009-03-08 02:33 759296 -c--a-w- c:\windows\system32\dllcache\VGX.dll
2012-08-14 23:00 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2012-08-14 22:59 . 2012-01-11 19:06 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-08-14 22:59 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-08-14 22:55 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2012-08-14 22:54 . 2010-08-16 08:45 590848 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2012-08-14 02:15 . 2008-04-14 03:42 294912 ------w- c:\program files\Windows Media Player\dlimport.exe
2012-08-14 01:58 . 2012-08-14 03:08 -------- d-----w- C:\e134cd84a4a3136cb4b9
2012-07-24 22:15 . 2012-08-09 21:38 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-17 02:56 . 2012-07-17 02:58 -------- d-----w- c:\documents and settings\user\Application Data\Notepad++
2012-07-17 02:56 . 2012-07-17 02:56 -------- d-----w- c:\program files\Notepad++
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-09 21:38 . 2012-02-04 19:00 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-13 21:30 . 2007-11-11 19:13 196608 ----a-w- c:\windows\system32\drivers\aStandard.bin
2012-07-06 13:58 . 2004-08-04 01:07 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2007-11-11 18:38 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2004-08-04 01:07 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-03 11:46 . 2010-12-20 17:30 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-05 15:50 . 2004-08-04 01:07 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2004-08-04 01:07 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2007-07-30 17:18 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2007-11-11 18:39 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2007-11-11 18:39 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2007-11-11 18:39 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2007-07-30 17:19 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2007-11-11 18:39 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2007-11-11 18:39 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2007-07-30 17:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2007-07-30 17:19 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2004-08-04 01:07 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2007-07-30 17:18 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2007-11-11 18:39 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2007-11-11 18:39 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2004-08-04 01:07 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-07-14 00:17 . 2012-08-11 04:14 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 14:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2010-11-29 14:26 3908192 ----a-w- c:\program files\BS_Player\tbBS_P.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_P.dll" [2010-11-29 3908192]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_P.dll" [2010-11-29 3908192]
.
[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 16116224]
"LXDDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll" [2007-01-22 102400]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^Warcraft Config.lnk]
path=c:\documents and settings\user\Start Menu\Programs\Startup\Warcraft Config.lnk
backup=c:\windows\pss\Warcraft Config.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^windows.pif]
path=c:\documents and settings\user\Start Menu\Programs\Startup\windows.pif
backup=c:\windows\pss\windows.pifStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2006-09-25 08:12 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 03:42 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
2007-02-13 00:00 312240 ----a-w- c:\program files\Lexmark Fax Solutions\fm3032.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-10-21 06:30 136176 ----atw- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon]
2007-02-05 23:32 20480 ----a-w- c:\program files\Lexmark 2500 Series\lxddamon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddmon.exe]
2007-02-12 23:58 291760 ----a-w- c:\program files\Lexmark 2500 Series\lxddmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-07-03 11:46 462920 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 03:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
2010-04-08 07:15 3233752 ----a-w- c:\program files\Registry Mechanic\RegMech.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 10:04 2879488 ------r- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 12:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2007-10-10 05:28 36352 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\lxddcoms.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\lxddamon.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\App4R.exe"=
"c:\\Program Files\\PopCap Games\\Zuma Deluxe\\Zuma.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\ATI Technologies\\ATI\\Mirc.exe"=
"c:\\Program Files\\Warcraft III Reign of Chaos & The Frozen Throne\\war3.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2435:TCP"= 2435:TCP:mypgmmon
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.12.2010 19:53 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.12.2010 19:53 17744]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [20.12.2010 19:30 22344]
S2 ivjwjmqqv;Update Support;c:\windows\system32\svchost.exe -k netsvcs [4.8.2004 3:07 14336]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
mtwglv
yoziqnbbr
ivjwjmqqv
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-01 00:15]
.
2012-08-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-01 00:15]
.
2012-08-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-602609370-725345543-1003Core.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-01-05 06:30]
.
2012-08-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-602609370-725345543-1003UA.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-01-05 06:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TCP: Interfaces\{A39DA86B-9064-4D5E-98BA-4D7108E94797}: NameServer = 195.66.189.137 195.66.189.138
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\rorkc3h3.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
.
- - - - ORPHANS REMOVED - - - -
.
Notify-WgaLogon - (no file)
MSConfigStartUp-Advanced WindowsCare 3 - c:\program files\IObit\Advanced WindowsCare 3 Beta\AWC.exe
MSConfigStartUp-avast! - c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
MSConfigStartUp-HService - c:\windows\msservice.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-Sys32 - c:\windows\Sys32.exe
AddRemove-GTA2 - c:\program files\GTA2 DEMO\Uninst.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-15 02:28
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXDDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\A]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0228e38a-0c5b-11e0-a647-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1ae1eb1e-cc44-11dd-94f1-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{454c329e-8ff3-11dc-a39a-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{454c329f-8ff3-11dc-a39a-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,df,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{454c32a1-8ff3-11dc-a39a-806d6172696f}]
@DACL=(02 0000)
"BaseClass"="Drive"
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{501dd708-a2ae-11dd-94c4-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,cf,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{51979390-2787-11de-a3c9-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,cf,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{52a7709a-94b2-11dd-94be-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6640045c-3e2c-11dd-944c-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,cf,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6afeea86-ed8a-11dd-950b-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6bf4738c-aa64-11dc-93e4-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7b5c8346-a5c5-11dd-94c7-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8efb215a-45d5-11dd-9454-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,00,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9350d7bc-8bd1-11dd-94bb-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9c82786a-485d-11dd-945a-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a166b6bd-7bac-11dd-94ae-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a166b6d8-7bac-11dd-94ae-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,00,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a4bd7fd0-c0bc-11dd-94e1-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b6088d18-3319-11de-a3da-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bead24bc-7738-11dd-94ad-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d441f650-6803-11df-a56d-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,00,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e44ae51e-4601-11de-a41b-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,00,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea71d84e-4ce7-11dd-9460-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,cf,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{edeebd1f-40d6-11de-a408-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,cf,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc0420c9-d0a8-11df-a5cb-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,00,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fc0420ca-d0a8-11df-a5cb-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,00,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe73c058-51e4-11dd-9464-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
[HKEY_USERS\S-1-5-21-1417001333-602609370-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe73c059-51e4-11dd-9464-001bfc1fdefc}]
@DACL=(02 0000)
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,df,5f,5f,5f,5f,df,df,5f,5f,
5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f,5f,01,00,01,01,ee,ff,ff,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(796)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2012-08-15 02:31:31
ComboFix-quarantined-files.txt 2012-08-15 00:31
.
Pre-Run: 58.416.332.800 bytes free
Post-Run: 58.347.257.856 bytes free
.
- - End Of File - - 9D6EEEB836748823BE7E721A4F0EE163
|