Completed.
Completed.
after running combofix and rebooting I got a RUNDLL error for part of the virus that was removed. owekomemap.dll
Here is my Log:
ComboFix 10-02-06.01 - Mark 02/06/2010 22:33:21.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2684 [GMT -5:00]
Running from: c:\documents and settings\Mark\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mark\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\windows\owekomemap.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mark\Local Settings\Application Data\{6121AF1E-4494-41AE-8D1C-AB6A2F395D25}
c:\documents and settings\Mark\Local Settings\Application Data\{6121AF1E-4494-41AE-8D1C-AB6A2F395D25}\chrome.manifest
c:\documents and settings\Mark\Local Settings\Application Data\{6121AF1E-4494-41AE-8D1C-AB6A2F395D25}\chrome\content\_cfg.js
c:\documents and settings\Mark\Local Settings\Application Data\{6121AF1E-4494-41AE-8D1C-AB6A2F395D25}\chrome\content\overlay.xul
c:\documents and settings\Mark\Local Settings\Application Data\{6121AF1E-4494-41AE-8D1C-AB6A2F395D25}\install.rdf
c:\documents and settings\Mark\Local Settings\Application Data\jxswbc
c:\documents and settings\Mark\Local Settings\Application Data\jxswbc\xasbsftav.exe
c:\windows\owekomemap.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-07 to 2010-02-07 )))))))))))))))))))))))))))))))
.
2010-02-07 02:15 . 2010-02-07 02:15 -------- d-----w- c:\program files\CCleaner
2010-02-07 01:55 . 2009-11-25 16:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-07 01:55 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-02-07 01:55 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-02-07 01:55 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-02-07 01:55 . 2010-02-07 01:55 -------- d-----w- c:\program files\Avira
2010-02-07 01:55 . 2010-02-07 01:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-02-07 01:47 . 2010-02-07 01:47 388096 ----a-r- c:\documents and settings\Mark\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-02-07 01:47 . 2010-02-07 01:47 -------- d-----w- c:\program files\TrendMicro
2010-02-02 23:29 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-02-02 23:29 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-02-02 23:26 . 2010-02-02 23:26 414672 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-02 23:23 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-02 23:22 . 2009-08-04 15:13 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-02-02 23:22 . 2009-08-04 14:20 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-02-02 23:22 . 2009-08-04 14:20 2066048 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-02-02 23:22 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-01-29 22:10 . 2008-10-10 09:52 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2010-01-29 22:10 . 2008-10-10 09:52 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2010-01-29 22:10 . 2008-10-10 09:52 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2010-01-29 22:10 . 2010-01-29 22:11 -------- d-----w- c:\program files\Heroes of Newerth
2010-01-28 15:51 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-28 15:51 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-28 14:28 . 2010-01-28 14:28 -------- d-----w- c:\documents and settings\Mark\Local Settings\Application Data\My Games
2010-01-28 14:20 . 2007-06-21 01:46 266088 ----a-w- c:\windows\system32\xactengine2_8.dll
2010-01-28 14:20 . 2007-06-21 01:45 18280 ----a-w- c:\windows\system32\x3daudio1_2.dll
2010-01-28 14:20 . 2007-05-16 21:45 443752 ----a-w- c:\windows\system32\d3dx10_34.dll
2010-01-28 14:20 . 2007-05-16 21:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2010-01-28 14:20 . 2007-05-16 21:45 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll
2010-01-28 14:09 . 2010-01-28 14:09 -------- d-----w- c:\program files\Firaxis Games
2010-01-28 14:09 . 2005-05-26 20:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2010-01-28 14:03 . 2010-01-28 14:03 -------- d-----w- c:\program files\Common Files\Java
2010-01-28 14:03 . 2010-01-28 14:03 61440 ----a-w- c:\documents and settings\Mark\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4053c8a5-n\decora-sse.dll
2010-01-28 14:03 . 2010-01-28 14:03 503808 ----a-w- c:\documents and settings\Mark\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-76a0273a-n\msvcp71.dll
2010-01-28 14:03 . 2010-01-28 14:03 499712 ----a-w- c:\documents and settings\Mark\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-76a0273a-n\jmc.dll
2010-01-28 14:03 . 2010-01-28 14:03 348160 ----a-w- c:\documents and settings\Mark\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-76a0273a-n\msvcr71.dll
2010-01-28 14:03 . 2010-01-28 14:03 12800 ----a-w- c:\documents and settings\Mark\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4053c8a5-n\decora-d3d.dll
2010-01-28 13:47 . 2010-01-28 13:47 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-01-28 13:47 . 2010-01-28 13:48 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-28 13:46 . 2010-02-02 23:31 -------- d-----w- c:\documents and settings\Mark\Application Data\DAEMON Tools Lite
2010-01-28 13:46 . 2010-01-28 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-01-20 21:34 . 2010-01-20 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Razer
2010-01-20 21:33 . 2010-01-20 21:33 -------- d-----w- c:\documents and settings\Mark\Application Data\InstallShield
2010-01-16 05:13 . 2010-01-16 05:13 -------- d-----w- c:\documents and settings\Mark\Local Settings\Application Data\Identities
2010-01-15 22:30 . 2010-01-15 22:30 52224 ----a-w- c:\documents and settings\Mark\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-15 22:30 . 2010-02-07 02:17 117760 ----a-w- c:\documents and settings\Mark\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-15 22:30 . 2010-01-15 22:30 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-15 22:30 . 2010-02-07 00:07 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-15 22:30 . 2010-01-15 22:30 -------- d-----w- c:\documents and settings\Mark\Application Data\SUPERAntiSpyware.com
2010-01-15 22:19 . 2010-01-15 22:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-15 22:16 . 2010-02-06 22:14 2984 ----a-w- c:\windows\Idiqequ.dat
2010-01-15 22:16 . 2010-02-06 18:12 0 ----a-w- c:\windows\Xyata.bin
2010-01-11 14:27 . 2010-01-11 14:27 -------- d-----w- c:\documents and settings\Mark\Application Data\DivX
2010-01-11 04:25 . 2010-01-11 04:25 -------- d-----w- c:\windows\Sun
2010-01-11 04:25 . 2009-12-17 22:14 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-11 04:24 . 2010-01-28 14:03 -------- d-----w- c:\program files\Java
2010-01-11 04:24 . 2010-01-11 04:24 152576 ----a-w- c:\documents and settings\Mark\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-11 04:24 . 2010-01-11 04:24 79488 ----a-w- c:\documents and settings\Mark\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-11 04:20 . 2008-09-16 00:14 120056 ------w- c:\windows\system32\pxcpyi64.exe
2010-01-11 04:20 . 2008-09-16 00:14 118520 ------w- c:\windows\system32\pxinsi64.exe
2010-01-11 04:17 . 2010-01-11 04:20 -------- d-----w- c:\program files\DivX
2010-01-11 04:17 . 2010-01-11 04:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-10 19:15 . 2010-01-27 01:42 -------- d-----w- c:\documents and settings\Mark\Application Data\Ventrilo
2010-01-10 19:15 . 2010-01-10 19:15 -------- d-----w- c:\program files\Ventrilo
2010-01-10 19:15 . 2010-01-15 22:30 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-10 08:05 . 2010-01-28 11:41 -------- d-----w- c:\documents and settings\Mark\Application Data\BitTorrent
2010-01-10 08:05 . 2010-01-10 08:05 -------- d-----w- c:\program files\BitTorrent
2010-01-10 07:11 . 2010-01-10 07:11 -------- d-----w- c:\documents and settings\Mark\Local Settings\Application Data\Blizzard Entertainment
2010-01-10 07:02 . 2010-01-30 14:26 -------- d-----w- c:\documents and settings\Mark\Local Settings\Application Data\Deployment
2010-01-10 06:58 . 2010-01-10 06:58 -------- d-----w- c:\windows\system32\XPSViewer
2010-01-10 06:58 . 2010-01-10 06:58 -------- d-----w- c:\program files\MSBuild
2010-01-10 06:58 . 2010-01-10 06:58 -------- d-----w- c:\program files\Reference Assemblies
2010-01-10 06:57 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-01-10 06:57 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-10 06:57 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-10 06:57 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-01-10 06:57 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-01-10 06:57 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-01-10 06:57 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-01-10 06:57 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-10 06:57 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-01-10 06:24 . 2010-01-10 06:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2010-01-10 06:12 . 2010-01-10 06:12 -------- d-----w- c:\documents and settings\Mark\Application Data\acccore
2010-01-10 06:12 . 2010-01-10 06:12 -------- d-----w- c:\documents and settings\Mark\Application Data\LAIM
2010-01-10 06:12 . 2010-01-10 06:12 -------- d-----w- c:\program files\AIM Lite
2010-01-10 06:02 . 2010-01-10 06:02 -------- d-----r- C:\AHCache
2010-01-10 04:35 . 2010-02-06 23:11 -------- d-----w- c:\program files\World of Warcraft
2010-01-10 04:35 . 2010-01-10 05:55 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-01-10 04:20 . 2007-10-11 16:10 30008 ----a-w- c:\windows\system32\drivers\ET5Drv.sys
2010-01-10 04:18 . 2010-01-10 04:18 -------- d-----w- C:\RaidTool
2010-01-10 04:18 . 2007-08-29 08:55 1966080 ------r- c:\windows\system32\xRaidSetup.exe
2010-01-10 04:18 . 2007-08-20 05:31 151552 ------r- c:\windows\system32\xRaidAPI.dll
2010-01-10 04:18 . 2008-01-03 14:10 105856 ----a-r- c:\windows\system32\drivers\Rtenicxp.sys
2010-01-10 04:18 . 2007-09-29 05:30 65024 ----a-r- c:\windows\system32\drivers\jraid.sys
2010-01-10 04:18 . 2010-01-10 04:18 -------- d-----w- c:\windows\RaidTool
2010-01-10 04:15 . 2006-05-04 08:26 2808832 ------r- c:\windows\alcwzrd.exe
2010-01-10 04:15 . 2010-01-10 04:15 315392 ----a-w- c:\windows\HideWin.exe
2010-01-10 04:15 . 2007-07-26 09:09 520192 ------r- c:\windows\RtlExUpd.dll
2010-01-10 04:12 . 2007-12-12 07:56 53248 ----a-r- c:\windows\system32\CSVer.dll
2010-01-10 04:12 . 2010-01-10 04:12 -------- d-----w- c:\program files\Intel
2010-01-10 04:12 . 2010-01-10 04:12 -------- d-----w- C:\Intel
2010-01-10 04:12 . 2010-01-10 04:12 -------- d-----w- c:\program files\GIGABYTE
2010-01-10 04:11 . 2010-01-10 07:00 16608 ----a-w- c:\windows\gdrv.sys
2010-01-10 03:25 . 2008-07-09 07:38 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-01-10 03:25 . 2010-02-03 19:42 -------- d--h--w- c:\windows\$hf_mig$
2010-01-10 03:24 . 2009-08-07 00:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-01-10 03:23 . 2010-01-10 03:23 -------- d-s---w- c:\documents and settings\Mark\UserData
2010-01-10 03:23 . 2010-01-13 04:49 -------- d-----w- c:\program files\Creative
2010-01-10 03:23 . 2003-03-05 17:19 15840 ------w- c:\windows\system32\drivers\PFMODNT.SYS
2010-01-10 01:12 . 2010-01-10 01:12 -------- d-----w- c:\program files\World of Warcraft.temp
2010-01-10 01:12 . 2010-01-10 01:12 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment.temp
2010-01-10 01:03 . 2009-11-21 16:18 1673216 ----a-w- c:\windows\system32\BootMan.exe
2010-01-10 01:03 . 2009-09-16 21:55 8456 ----a-w- c:\windows\system32\EuGdiDrv.sys
2010-01-10 01:03 . 2009-09-14 14:21 14848 ----a-w- c:\windows\system32\EuEpmGdi.dll
2010-01-10 01:03 . 2009-08-26 17:45 13192 ----a-w- c:\windows\system32\epmntdrv.sys
2010-01-10 01:03 . 2009-04-22 19:28 86408 ----a-w- c:\windows\system32\setupempdrv03.exe
2010-01-10 00:59 . 2010-01-10 00:59 -------- d-----w- C:\CPM
2010-01-10 00:42 . 2010-01-10 00:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard
2010-01-09 23:28 . 2010-01-09 23:28 0 ----a-w- c:\windows\nsreg.dat
2010-01-09 23:28 . 2010-01-09 23:28 -------- d-----w- c:\documents and settings\Mark\Local Settings\Application Data\Mozilla
2010-01-09 23:28 . 2010-01-10 00:54 -------- d-----w- c:\windows\system32\NtmsData
2010-01-09 23:23 . 2010-01-10 07:01 12328 ----a-w- c:\documents and settings\Mark\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-09 23:23 . 2010-01-09 23:23 -------- d-----w- c:\documents and settings\Mark\Local Settings\Application Data\ATI
2010-01-09 23:23 . 2010-01-09 23:23 -------- d-----w- c:\documents and settings\Mark\Application Data\ATI
2010-01-09 23:23 . 2010-01-09 23:23 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-28 14:16 . 2010-01-09 19:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-10 19:28 . 2010-01-10 17:52 -------- d-----w- c:\documents and settings\Mark\Application Data\Winamp
2010-01-10 17:54 . 2010-01-10 17:52 -------- d-----w- c:\program files\Winamp
2010-01-10 17:52 . 2010-01-10 17:52 -------- d-----w- c:\program files\Winamp Detect
2010-01-10 04:18 . 2010-01-10 04:15 -------- d-----w- c:\program files\Realtek
2010-01-10 04:12 . 2010-01-09 19:16 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-09 23:12 . 2010-01-09 19:16 -------- d-----w- c:\program files\ATI Technologies
2010-01-09 23:11 . 2010-01-09 23:11 0 ----a-w- c:\windows\ativpsrm.bin
2010-01-09 23:11 . 2010-01-09 23:11 10134 ----a-r- c:\documents and settings\Mark\Application Data\Microsoft\Installer\{D45CF2D7-DA97-1ED5-2D6B-B005C245DA20}\ARPPRODUCTICON.exe
2009-11-21 15:51 . 2008-04-14 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LinksysDiag"="c:\program files\Linksys\LinksysDiag\LinksysDiag" [X]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-11-29 98304]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"laim"="c:\program files\AIM Lite\aimlite.exe" [2007-06-07 765952]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-12-21 39424]
"V0410Mon.exe"="c:\windows\V0410Mon.exe" [2007-06-07 32768]
"Lachesis"="c:\program files\Razer\Lachesis\razerhid.exe" [2008-10-14 172032]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\Heroes of Newerth\\hon.exe"=
"c:\\Documents and Settings\\Mark\\Local Settings\\Apps\\2.0\\43B4QHHD.TH5\\YP09AKZY.5Y8\\curs..tion_eee711038731a406_0004.0000_1430d97334050788\\CurseClient.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1/28/2010 8:47 AM 691696]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2/6/2010 8:55 PM 108289]
R3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [1/9/2010 2:21 PM 12032]
R3 V0410Afx;Creative Camera VF0410 Audio Effects Driver;c:\windows\system32\drivers\V0410AFX.sys [1/12/2010 11:49 PM 142656]
R3 V0410Aud;Creative Camera VF0410 Noise Cancellation APO;c:\windows\system32\drivers\V0410Aud.sys [1/12/2010 11:49 PM 94720]
R3 V0410Dev;Creative Camera VF0410 Driver;c:\windows\system32\drivers\V0410Dev.sys [1/12/2010 11:49 PM 244704]
R3 V0410Vfx;Creative Camera VF0410 Video VFX Driver;c:\windows\system32\drivers\V0410Vfx.sys [1/12/2010 11:49 PM 7168]
S2 LANPkt;Linksys LANPkt Protocol Driver;c:\windows\system32\drivers\LANPkt.sys [1/9/2010 4:15 PM 8568]
S3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [1/9/2010 4:15 PM 11351]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [1/9/2010 8:03 PM 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [1/9/2010 8:03 PM 8456]
S3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [1/9/2010 11:12 PM 47624]
S3 RTLVLANXP;Linksys VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLANXP.SYS [1/9/2010 4:15 PM 15360]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = <local>
FF - ProfilePath - c:\documents and settings\Mark\Application Data\Mozilla\Firefox\Profiles\q0ifoxa4.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Gxomolovolo - c:\windows\owekomemap.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-06 22:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spfk.sys >>UNKNOWN [0x8A51D938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf74fbf28
\Driver\ACPI -> ACPI.sys @ 0xf7253cb8
\Driver\atapi -> atapi.sys @ 0xf720eb40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Linksys EG1032 v3 Instant Gigabit Desktop Network Adapter Drive -> SendCompleteHandler -> NDIS.sys @ 0xf7117bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7124a21
SendHandler -> NDIS.sys @ 0xf710287b
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1132)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\RTHDCPL.EXE
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\devldr32.exe
c:\program files\Razer\Lachesis\OSD.exe
c:\program files\Razer\Lachesis\razertra.exe
c:\program files\Razer\Lachesis\razerofa.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2010-02-06 22:38:22 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-07 03:38
Pre-Run: 33,481,584,640 bytes free
Post-Run: 33,561,448,448 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - DD890AC90173B1E5DCBD81DF59B17A0A