Hi guys
Thats one mean peice of software, make you nervous just running it.
logs for both combofix and OTlist below, and can load programmes again by the looks of it although not run any yet until you give all clear, hats off to you, thanks again for helping us not so cleverones.
OTListIt logfile created on: 09/04/2009 22:01:12 - Run 2
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Documents and Settings\peter\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1023.48 Mb Total Physical Memory | 632.76 Mb Available Physical Memory | 61.82% Memory free
2.40 Gb Paging File | 2.06 Gb Available in Paging File | 85.65% Paging File free
Paging file location(s): C:\pagefile.sys 0 0;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 52.99 Gb Free Space | 71.10% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PETERS
Current User Name: peter
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe ()
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Comodo\BackUp\CmdBkSvc.exe (COMODO)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
PRC - C:\Program Files\btbb_wcm\McciTrayApp.exe (Motive Communications, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Yahoo!\browser\ycommon.exe (Yahoo!, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\COMODO\SafeSurf\cssurf.exe (COMODO)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Eraser\eraser.exe (Heidi Computers Ltd)
PRC - C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
PRC - C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe (Yahoo! Inc.)
PRC - C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE (Logitech Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cfp.exe ()
PRC - C:\Documents and Settings\peter\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (BlueSoleil Hid Service [Disabled | Stopped]) – C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()
SRV - (clr_optimization_v2.0.50727_32 [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (cmdAgent [Auto | Running]) – C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe ()
SRV - (ComodoBackupService [Auto | Running]) – C:\Program Files\Comodo\BackUp\CmdBkSvc.exe (COMODO)
SRV - (gupdate1c99152d3ef0640 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – File not found
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [Disabled | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (InCDsrv [Disabled | Stopped]) – C:\Program Files\Ahead\InCD\InCDsrv.exe (Ahead Software AG)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KService [Disabled | Stopped]) – C:\Program Files\Kontiki\KService.exe (Kontiki Inc.)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (ServiceLayer [Disabled | Stopped]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (STI Simulator [Disabled | Stopped]) – C:\WINDOWS\System32\PAStiSvc.exe ()
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (YPCService [On_Demand | Stopped]) – C:\WINDOWS\system32\YPcservice.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV - (alcan5wn [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\alcan5wn.sys (THOMSON)
DRV - (alcaudsl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\alcaudsl.sys (THOMSON)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ATTSCAP [Auto | Running]) – C:\WINDOWS\system32\drivers\attscap.sys (AVerMedia Technologies, Inc.)
DRV - (ATVCAP [Auto | Running]) – C:\WINDOWS\system32\drivers\atvcap.sys (AVerMedia Technologies, Inc.)
DRV - (ATXBAR [Auto | Running]) – C:\WINDOWS\system32\drivers\ATXBAR.sys (AVerMedia Technologies, Inc.)
DRV - (BlueletAudio [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\blueletaudio.sys (IVT Corporation)
DRV - (BlueletSCOAudio [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys (IVT Corporation)
DRV - (BT [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\btnetdrv.sys (IVT Corporation)
DRV - (Btcsrusb [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\btcusb.sys (IVT Corporation)
DRV - (BTHidEnum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\vbtenum.sys ()
DRV - (BTHidMgr [Boot | Running]) – C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation)
DRV - (BTNetFilter [On_Demand | Stopped]) – C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys ()
DRV - (Cam5603C [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\VdCap03C.sys ()
DRV - (catchme [Disabled | Running]) – File not found
DRV - (cmdGuard [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdguard.sys (COMODO)
DRV - (cmdHlp [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdhlp.sys (COMODO)
DRV - (cmuda [On_Demand | Running]) – C:\WINDOWS\system32\drivers\cmuda.sys (C-Media Inc)
DRV - (ENTECH [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ENTECH.SYS (EnTech Taiwan)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (InCDfs [Disabled | Running]) – C:\WINDOWS\System32\drivers\incdfs.sys (Ahead Software AG)
DRV - (InCDPass [System | Running]) – C:\WINDOWS\System32\DRIVERS\InCDPass.sys (Ahead Software AG)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (L8042Kbd [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys (Logitech, Inc.)
DRV - (L8042mou [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\L8042mou.Sys (Logitech, Inc.)
DRV - (LMouKE [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LMouKE.Sys (Logitech, Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Running]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (nmwcd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcd.sys (Nokia)
DRV - (nmwcdc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdc.sys (Nokia)
DRV - (nmwcdcj [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdcj.sys (Nokia)
DRV - (nmwcdcm [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdcm.sys (Nokia)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv4 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4.sys (NVIDIA Corporation)
DRV - (PAC7311 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS (PixArt Imaging Inc.)
DRV - (pcouffin [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ROOTMODEM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (Ser2pl [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\ser2pl.sys (Prolific Technology Inc.)
DRV - (SiS7018 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ac97sis.sys (Silicon Integrated Systems Corp.)
DRV - (sisagp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (TVICHW32 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS (EnTech Taiwan)
DRV - (USB_RNDIS [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\usb8023.sys (Microsoft Corporation)
DRV - (VComm [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\VComm.sys (IVT Corporation)
DRV - (VcommMgr [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\VcommMgr.sys (IVT Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.bt.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google.co.uk"
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}:6.0.10
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/10 23:24:13 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/31 21:25:35 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/29 17:03:44 | 00,000,000 | —D | M]
[2008/07/05 17:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Extensions
[2008/07/05 17:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/08 23:06:16 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Firefox\Profiles\oo3sxysz.default\extensions
[2008/12/12 01:17:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\mozilla\Firefox\Profiles\oo3sxysz.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/04/08 23:06:16 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/03/29 17:03:44 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/05/17 16:54:13 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/11/17 00:43:36 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
[2009/03/10 23:24:34 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/02 21:43:44 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/03/29 17:03:35 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/29 17:03:35 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/11/15 22:49:30 | 00,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2008/11/15 22:49:30 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/11/15 22:49:30 | 00,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2008/11/15 22:49:30 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/15 22:49:30 | 00,000,759 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2008/11/15 22:49:30 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/11/15 22:49:30 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/11/15 22:49:30 | 00,000,831 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SidebarAutoLaunch Class) - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe (Motive Communications, Inc.)
O4 - HKLM..\Run: [COMODO Internet Security] "C:\Program Files\Comodo\COMODO Internet Security\cfp.exe" -h ()
O4 - HKLM..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s (COMODO)
O4 - HKLM..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" (Lexmark International, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide (Heidi Computers Ltd)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~2\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200 (Google Inc.)
O9 - Extra Button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4}
http://download.microsoft.com/download/7/0…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} C:\Program Files\Yahoo!\common\yucconfig.dll (yucsetreg Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll (Installation Support)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab (Reg Error: Key error.)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000}
http://download.yahoo.com/dl/installs/ymail/ymmapi.dll (Yahoo! MailTo)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://download.yahoo.com/dl/installs/yab_af.cab (YAddBook Class)
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70}
http://help.broadbandassist.com/bbdesktop/…tivePreQual.cab (PreQualifier Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4}
http://eu.download.games.yahoo.com/zylom/a…zylomloader.cab (Zylom Loader Object)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8}
http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe (Virtools WebPlayer Class)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941}
http://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{EFBA1530-5D85-4113-95C6-41FD82DA661C}\\NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\cssdll32.dll) - C:\WINDOWS\system32\cssdll32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
========== Files/Folders - Created Within 30 Days ==========
[5 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\peter\Application Data\*.tmp files]
[2009/04/09 21:51:32 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood
[2009/04/09 21:24:31 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/04/09 21:24:31 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/04/09 21:24:31 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/04/09 21:24:31 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/04/09 21:24:31 | 00,089,504 | —- | C] (Smallfrogs Studio) – C:\WINDOWS\fdsv.exe
[2009/04/09 21:24:31 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/04/09 21:24:31 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/04/09 21:24:31 | 00,049,152 | —- | C] () – C:\WINDOWS\VFIND.exe
[2009/04/09 21:24:31 | 00,029,696 | —- | C] () – C:\WINDOWS\NIRCMD.exe
[2009/04/09 21:23:57 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/04/09 21:23:56 | 00,000,000 | —D | C] – C:\Combo-Fix
[2009/04/09 21:22:16 | 00,073,728 | —- | C] () – C:\pv.exe
[2009/04/09 21:21:37 | 03,067,803 | R— | C] () – C:\Documents and Settings\peter\Desktop\Combo-Fix.exe
[2009/04/09 17:47:11 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware2
[2009/04/09 17:30:02 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/09 17:30:00 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/09 17:21:03 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/04/09 15:38:50 | 00,019,456 | —- | C] () – C:\Documents and Settings\peter\My Documents\covering letter questionnaire.doc
[2009/04/08 22:41:45 | 00,500,736 | —- | C] (OldTimer Tools) – C:\Documents and Settings\peter\Desktop\OTListIt2.exe
[2009/04/07 18:20:47 | 03,067,803 | —- | C] () – C:\Documents and Settings\peter\Desktop\ComboFix.exe
[2009/04/07 17:46:12 | 00,000,933 | —- | C] () – C:\Documents and Settings\peter\Desktop\Spybot - Search & Destroy.lnk
[2009/04/05 23:05:12 | 00,000,064 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/04/02 17:37:45 | 00,000,737 | —- | C] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T (2).lnk
[2009/04/02 17:35:51 | 00,000,000 | —D | C] – C:\Documents and Settings\peter\Desktop\bristow and sutor
[2009/03/31 00:03:51 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2009/03/27 23:54:51 | 00,243,200 | —- | C] () – C:\Documents and Settings\peter\Local Settings\Application Data\umwoegi.exe
[2009/03/24 19:11:34 | 00,000,737 | —- | C] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T.lnk
[2009/03/23 00:19:15 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/03/23 00:19:15 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/03/22 00:01:07 | 00,000,000 | —D | C] – C:\WINDOWS\.jagex_cache_32
[2009/03/20 19:12:02 | 00,000,000 | —D | C] – C:\Documents and Settings\peter\Application Data\Media Player Classic
[2009/03/16 21:09:59 | 00,022,016 | —- | C] () – C:\Documents and Settings\peter\My Documents\bristow march09.doc
[2009/03/15 11:11:37 | 00,000,000 | —D | C] – C:\finalburner
[2009/03/14 10:57:55 | 00,000,000 | —D | C] – C:\Program Files\FinalBurner
[2008/12/12 01:16:58 | 00,155,384 | —- | C] () – C:\WINDOWS\System32\guard32.dll
[2008/08/30 23:33:33 | 02,076,672 | —- | C] () – C:\WINDOWS\System32\dz3delight.dll
[2008/08/30 23:33:31 | 06,131,712 | —- | C] () – C:\WINDOWS\System32\daz-qt-mt.dll
[2008/08/30 23:33:31 | 01,785,856 | —- | C] () – C:\WINDOWS\System32\daz-qsa.dll
[2008/01/06 11:32:26 | 00,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/08/22 23:44:31 | 00,000,049 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/08/19 17:13:57 | 00,394,240 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2007/07/25 15:24:30 | 01,559,040 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2007/03/30 00:00:40 | 00,203,264 | R— | C] () – C:\WINDOWS\System32\CddbCdda.dll
[2007/01/03 00:19:02 | 00,001,275 | —- | C] () – C:\WINDOWS\AVerDVBT.ini
[2006/12/30 21:16:35 | 00,000,441 | —- | C] () – C:\WINDOWS\lexstat.ini
[2006/12/30 21:01:55 | 00,003,972 | —- | C] () – C:\WINDOWS\System32\drivers\PciBus.sys
[2006/12/30 17:48:16 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/12/30 17:34:42 | 00,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2006/12/29 19:25:09 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/04/14 10:14:12 | 00,014,312 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2006/03/31 21:57:42 | 00,000,966 | —- | C] () – C:\WINDOWS\videoimp.ini
[2006/03/31 21:57:12 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2006/03/31 21:56:51 | 00,000,021 | —- | C] () – C:\WINDOWS\VI_setup.ini
[2006/03/31 21:55:24 | 00,295,374 | —- | C] () – C:\WINDOWS\System32\drivers\VdCap03C.sys
[2006/03/31 21:55:19 | 00,081,920 | —- | C] () – C:\WINDOWS\System32\VfwExtC.dll
[2006/03/31 21:55:19 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\VfwECamC.dll
[2006/03/31 21:55:19 | 00,015,190 | —- | C] () – C:\WINDOWS\VdTwn03C.ini
[2006/02/26 16:08:28 | 00,585,728 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2006/01/13 23:33:03 | 00,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2005/07/30 08:21:32 | 00,011,988 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[2003/08/18 15:46:38 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\LXBKLCNP.DLL
[2002/11/13 20:40:22 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\lxbkvs.dll
[2002/09/13 16:40:06 | 00,000,266 | —- | C] () – C:\WINDOWS\System32\lxbkcoin.ini
[2001/08/23 13:00:00 | 00,001,049 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 13:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2001/07/25 13:00:10 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\HWINV.DLL
[2001/07/25 13:00:10 | 00,026,572 | —- | C] () – C:\WINDOWS\System32\INV16.DLL
[1999/01/22 19:46:58 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 09:00:00 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\regobj.dll
========== Files - Modified Within 30 Days ==========
[3 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\peter\Application Data\*.tmp files]
[1 C:\Documents and Settings\peter\My Documents\*.tmp files]
[2009/04/09 21:57:46 | 00,002,473 | —- | M] () – C:\Documents and Settings\peter\Desktop\Microsoft Word.lnk
[2009/04/09 21:42:46 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/09 21:41:27 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/09 21:40:37 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/09 21:40:32 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/09 21:21:44 | 03,067,803 | R— | M] () – C:\Documents and Settings\peter\Desktop\Combo-Fix.exe
[2009/04/09 15:50:33 | 00,000,441 | —- | M] () – C:\WINDOWS\lexstat.ini
[2009/04/09 15:38:50 | 00,019,456 | —- | M] () – C:\Documents and Settings\peter\My Documents\covering letter questionnaire.doc
[2009/04/08 22:41:45 | 00,500,736 | —- | M] (OldTimer Tools) – C:\Documents and Settings\peter\Desktop\OTListIt2.exe
[2009/04/08 01:53:12 | 00,001,275 | —- | M] () – C:\WINDOWS\AVerDVBT.ini
[2009/04/08 01:23:06 | 00,000,000 | —- | M] () – C:\mediatype.dat
[2009/04/07 18:21:16 | 03,067,803 | —- | M] () – C:\Documents and Settings\peter\Desktop\ComboFix.exe
[2009/04/07 17:46:12 | 00,000,933 | —- | M] () – C:\Documents and Settings\peter\Desktop\Spybot - Search & Destroy.lnk
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/05 23:56:18 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/04/05 23:05:12 | 00,000,064 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/04/04 15:57:54 | 00,245,760 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/02 17:37:45 | 00,000,737 | —- | M] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T (2).lnk
[2009/04/01 22:19:46 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/29 21:28:18 | 00,471,326 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/29 21:28:18 | 00,401,064 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/03/29 21:28:18 | 00,062,344 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/03/29 03:30:00 | 00,000,394 | —- | M] () – C:\WINDOWS\tasks\ErrorEasy Scheduled Scan.job
[2009/03/27 23:54:51 | 00,243,200 | —- | M] () – C:\Documents and Settings\peter\Local Settings\Application Data\umwoegi.exe
[2009/03/24 19:11:34 | 00,000,737 | —- | M] () – C:\Documents and Settings\peter\Desktop\AVerTV DVB-T.lnk
[2009/03/23 00:19:15 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/03/22 11:22:17 | 00,001,049 | —- | M] () – C:\WINDOWS\win.ini
[2009/03/22 11:20:59 | 00,002,335 | —- | M] () – C:\Documents and Settings\peter\Desktop\AmCap (2).lnk
[2009/03/20 19:15:14 | 00,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2009/03/20 19:15:14 | 00,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2009/03/20 19:14:07 | 00,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2009/03/16 21:16:09 | 00,022,016 | —- | M] () – C:\Documents and Settings\peter\My Documents\bristow march09.doc
[2009/03/14 09:42:28 | 00,253,688 | —- | M] (COMODO) – C:\WINDOWS\System32\cssdll32.dll
[2009/03/11 01:56:51 | 00,000,049 | —- | M] () – C:\WINDOWS\NeroDigital.ini
========== LOP Check ==========
[2009/04/09 17:21:10 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2006/12/29 19:36:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2006/07/16 01:21:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/12/12 01:11:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avg7
[2008/02/06 21:48:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bluetooth
[2006/03/13 22:49:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/02/22 22:30:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Channel4
[2009/02/19 20:21:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comodo
[2006/12/29 19:33:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/03/24 02:47:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\dslic
[2007/11/22 00:30:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/02/09 21:20:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2008/02/04 20:35:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2008/02/23 11:23:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kontiki
[2008/10/17 23:54:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/11/07 22:53:39 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/02/04 17:05:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2008/07/31 17:58:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Software
[2008/07/31 17:58:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008/02/04 20:38:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2007/01/07 12:39:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QubeSoft
[2006/12/29 19:28:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBT
[2009/04/07 17:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/07/25 21:54:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/04/15 16:25:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2008/09/15 22:38:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/01/08 15:25:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/07/13 18:12:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2008/05/15 16:41:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\yahoo!
[2006/10/05 21:48:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2006/01/28 20:43:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[1 C:\Documents and Settings\peter\Application Data\*.tmp files]
[2009/04/09 17:21:09 | 00,000,000 | RH-D | M] – C:\Documents and Settings\peter\Application Data
[2006/12/07 00:28:18 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Adobe
[2007/07/22 21:32:03 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Ahead
[2007/02/04 17:55:51 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Apple Computer
[2007/09/16 10:50:41 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\ATI
[2006/02/19 23:35:00 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\AverAlbum
[2008/12/12 01:11:41 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\AVG7
[2009/03/03 21:35:37 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Comodo
[2008/09/15 22:33:21 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\ErrorEasy
[2006/01/19 02:04:06 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Google
[2007/02/02 21:36:50 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Help
[2007/09/16 12:09:10 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\IGN_DLM
[2009/02/18 00:20:08 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Joost
[2006/01/13 23:11:12 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Lavasoft
[2006/12/25 11:42:27 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Logitech
[2006/04/16 10:21:43 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Macromedia
[2008/10/17 23:54:14 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Malwarebytes
[2009/03/20 19:12:02 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Media Player Classic
[2009/04/08 23:07:01 | 00,000,000 | –SD | M] – C:\Documents and Settings\peter\Application Data\Microsoft
[2008/07/26 08:43:36 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Motive
[2008/07/05 17:27:47 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Mozilla
[2008/10/05 01:57:24 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\NCH Swift Sound
[2008/03/27 23:48:24 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Nokia
[2009/03/22 13:35:10 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Nokia Multimedia Player
[2007/01/27 21:09:07 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\OTVREG
[2008/02/04 20:38:16 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\PC Suite
[2006/01/08 02:58:26 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Real
[2007/01/25 22:09:18 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\SlipStream
[2006/01/21 01:07:37 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Sun
[2008/08/12 21:47:10 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Ulead Systems
[2007/09/11 21:24:35 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Uniblue
[2009/03/22 23:54:18 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\uTorrent
[2008/05/28 23:53:30 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\vghd
[2007/03/09 00:14:06 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Vso
[2007/09/27 23:43:22 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\WinRAR
[2008/08/09 10:59:58 | 00,000,000 | —D | M] – C:\Documents and Settings\peter\Application Data\Yahoo!
[2001/08/23 13:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/03/29 03:30:00 | 00,000,394 | —- | M] () – C:\WINDOWS\Tasks\ErrorEasy Scheduled Scan.job
[2009/04/09 21:40:37 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\eli car.mpg:SummaryInformation
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:EB68C370
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
and Combofix
ComboFix 09-04-04.01 - peter 2009-04-09 21:34:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.724 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
AV: COMODO Antivirus *On-access scanning enabled* (Updated)
FW: COMODO Firewall *enabled*
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\peter\Local Settings\Application Data\geaia_navps.dat
C:\Program Files\ADS Plugins
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\drivers\UACpxetjkvx.sys
C:\WINDOWS\system32\Show Pink Zone.ico
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\UACboylltiv.dll
C:\WINDOWS\system32\UACekcampui.log
C:\WINDOWS\system32\UACibakpgod.dll
C:\WINDOWS\system32\UACilbabrvj.dll
C:\WINDOWS\system32\uacinit.dll
C:\WINDOWS\system32\UACkkfvnsdr.dat
C:\WINDOWS\system32\UACrbitsmkn.log
C:\WINDOWS\system32\UACuipmyxym.log
C:\WINDOWS\system32\UACutewqxwp.dll
C:\WINDOWS\system32\UACwqptqscg.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat . . . . failed to delete
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat . . . . failed to delete
—– BITS: Possible infected sites —–
hxxp://tubeloyaln.com
hxxp://sunmicro.ht.rd.llnw.net
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-03-09 to 2009-04-09 )))))))))))))))))))))))))))))))
.
2009-04-09 21:22 . 2006-03-03 00:42 73,728 –a—— C:\pv.exe
2009-04-09 17:47 . 2009-04-09 18:09 d——– C:\Program Files\Malwarebytes' Anti-Malware2
2009-04-09 17:30 . 2009-04-06 15:32 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-04-09 17:30 . 2009-04-06 15:32 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2009-04-09 17:21 . 2009-04-09 17:21 d——– C:\_OTListIt
2009-04-05 23:05 . 2009-04-05 23:05 64 –a—— C:\WINDOWS\wininit.ini
2009-03-31 00:03 . 2009-03-31 00:03 d——– C:\Program Files\Microsoft Silverlight
2009-03-23 00:19 . 2009-04-05 23:56 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2009-03-23 00:19 . 2009-03-23 00:19 1,409 –a—— C:\WINDOWS\QTFont.for
2009-03-22 00:01 . 2009-03-22 00:01 d——– C:\WINDOWS\.jagex_cache_32
2009-03-22 00:01 . 2009-03-22 00:02 34 –a—— C:\Documents and Settings\peter\jagex_runescape_preferences.dat
2009-03-20 19:12 . 2009-03-20 19:12 d——– C:\Documents and Settings\peter\Application Data\Media Player Classic
2009-03-15 11:11 . 2009-03-15 11:11 d——– C:\finalburner
2009-03-14 10:57 . 2009-03-14 10:58 d——– C:\Program Files\FinalBurner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-09 20:31 ——— d—–w C:\Program Files\Eraser
2009-04-09 16:44 ——— d—–w C:\Program Files\Malwarebytes' Anti-Malware
2009-04-09 14:50 ——— d—–w C:\Program Files\Lexmark X1100 Series
2009-04-08 22:07 ——— d—–w C:\Program Files\DreamStripper Professional Demo
2009-04-08 00:53 ——— d—–w C:\Program Files\AVerTV DVB-T
2009-04-08 00:23 0 —-a-w C:\mediatype.dat
2009-04-07 16:46 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2009-04-07 16:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-02 20:43 ——— d—–w C:\Program Files\Java
2009-03-22 22:54 ——— d—–w C:\Documents and Settings\peter\Application Data\uTorrent
2009-03-22 12:35 ——— d—–w C:\Documents and Settings\peter\Application Data\Nokia Multimedia Player
2009-03-14 08:42 253,688 —-a-w C:\WINDOWS\system32\cssdll32.dll
2009-03-13 17:32 ——— d—–w C:\Program Files\Common Files\Ahead
2009-03-13 17:32 ——— d—–w C:\Program Files\Ahead
2009-03-09 04:19 410,984 —-a-w C:\WINDOWS\system32\deploytk.dll
2009-03-03 20:35 ——— d—–w C:\Documents and Settings\peter\Application Data\Comodo
2009-03-03 20:30 ——— d—–w C:\Program Files\Comodo
2009-02-26 21:57 155,384 —-a-w C:\WINDOWS\system32\guard32.dll
2009-02-26 21:56 110,992 —-a-w C:\WINDOWS\system32\drivers\cmdguard.sys
2009-02-19 19:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Comodo
2009-02-19 19:17 24,336 —-a-w C:\WINDOWS\system32\drivers\cmdhlp.sys
2009-02-17 23:20 ——— d—–w C:\Documents and Settings\peter\Application Data\Joost
2009-02-17 22:55 ——— d—–w C:\Program Files\Google
2009-02-09 20:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-03-08 23:14 87,608 —-a-w C:\Documents and Settings\peter\Application Data\ezpinst.exe
2007-03-08 23:14 47,360 —-a-w C:\Documents and Settings\peter\Application Data\pcouffin.sys
2008-09-04 19:55 32,768 –sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090420080905\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-06 16:20 279944 –a—— C:\Program Files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 16:20 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 16:20 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~2\YAHOOM~1.EXE" [2007-08-30 17:43 4670704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 01:12 15360]
"Eraser"="C:\Program Files\Eraser\eraser.exe" [2006-08-07 22:07 634880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 17:19 129536]
"btbb_wcm_McciTrayApp"="C:\Program Files\btbb_wcm\McciTrayApp.exe" [2005-12-29 11:22 543232]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 16:41 45056]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 15:43 57344]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-01-08 02:56 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-16 01:18 282624]
"COMODO SafeSurf"="C:\Program Files\COMODO\SafeSurf\cssurf.exe" [2009-03-14 09:42 278264]
"COMODO Internet Security"="C:\Program Files\Comodo\COMODO Internet Security\cfp.exe" [2009-02-26 22:56 1851128]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-03-09 05:19 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 01:12 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 11:17 1241088]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-12-25 11:34:27 450560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\cssdll32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.dvsd"= pdvcodec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BT Broadband Desktop Help.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BT Broadband Desktop Help.lnk
backup=C:\WINDOWS\pss\BT Broadband Desktop Help.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^peter^Start Menu^Programs^Startup^VirtuaGirl HD.LNK]
path=C:\Documents and Settings\peter\Start Menu\Programs\Startup\VirtuaGirl HD.LNK
backup=C:\WINDOWS\pss\VirtuaGirl HD.LNKStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_McciTrayApp]
——— 2007-05-23 07:22 936960 C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
–a—— 2006-08-07 22:07 634880 C:\Program Files\Eraser\eraser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
——— 2004-03-24 11:41 1294446 C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
–a—— 2007-04-23 12:23 1032640 C:\Program Files\Kontiki\KHost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 01:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
–a—— 2007-06-18 16:10 271360 C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickDVBT]
–a—— 2004-03-17 14:28 196608 C:\Program Files\AVerTV DVB-T\QuickDVB-T.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-07-16 01:18 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 14:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SWHelper]
–a—— 2009-03-22 11:52 53248 C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2006-01-08 02:56 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-08-30 17:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
–a—— 2008-04-14 01:12 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"STI Simulator"=2 (0x2)
"ServiceLayer"=3 (0x3)
"KService"=2 (0x2)
"InCDsrv"=2 (0x2)
"IDriverT"=3 (0x3)
"BlueSoleil Hid Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
R2 gupdate1c99152d3ef0640;Google Update Service (gupdate1c99152d3ef0640);C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-17 23:55 133104]
R3 PAC7311;VGA SoC PC-Camera;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS [2005-10-18 12:48 154752]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2009-02-26 22:56 110992]
S1 cmdHlp;COMODO Internet Security Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2009-02-19 20:17 24336]
S2 ATTSCAP;AVerMedia, WDM MPEG-2 TS Capture (DVBT);C:\WINDOWS\system32\drivers\attscap.sys [2003-06-24 12:19 18048]
S2 ATVCAP;AVerMedia, DVB-T WDM Video Capture;C:\WINDOWS\system32\drivers\atvcap.sys [2003-06-24 12:22 56320]
S2 ATXBAR;AVerMedia, DVB-T WDM Crossbar;C:\WINDOWS\system32\drivers\ATXBAR.sys [2003-06-24 12:23 8576]
S2 ComodoBackupService;ComodoBackupService;C:\Program Files\Comodo\BackUp\CmdBkSvc.exe [2009-03-03 21:30 1023488]
— Other Services/Drivers In Memory —
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - Ati HotKey Poller
*Deregistered* - ATI Smart
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - BlueletAudio
*Deregistered* - BlueletSCOAudio
*Deregistered* - Browser
*Deregistered* - BT
*Deregistered* - BTHidEnum
*Deregistered* - BTHidMgr
*Deregistered* - BthServ
*Deregistered* - Cdfs
*Deregistered* - cmdAgent
*Deregistered* - cmdGuard
*Deregistered* - cmdHlp
*Deregistered* - ComodoBackupService
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - gupdate1c99152d3ef0640
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - ImapiService
*Deregistered* - InCDfs
*Deregistered* - Inspect
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LexBceS
*Deregistered* - LmHosts
*Deregistered* - mnmdd
*Deregistered* - Modem
*Deregistered* - MountMgr
*Deregistered* - MRENDIS5
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - UMWdf
*Deregistered* - Update
*Deregistered* - VComm
*Deregistered* - VcommMgr
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WmiApSrv
*Deregistered* - WS2IFSL
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder
2009-03-29 C:\WINDOWS\Tasks\ErrorEasy Scheduled Scan.job
- C:\Program Files\ErrorEasy\ErrorEasy.exe []
2009-03-29 C:\WINDOWS\Tasks\ErrorEasy Scheduled Scan.job
- C:\Program Files\ErrorEasy []
.
- - - - ORPHANS REMOVED - - - -
BHO-{4F06B779-D0FD-4580-8C9B-6EAEB70F10AE} - (no file)
HKCU-Run-geaia - c:\documents and settings\peter\local settings\application data\geaia.exe
MSConfigStartUp-ISTray - C:\Program Files\Spyware Doctor\pctsTray.exe
MSConfigStartUp-Motive SmartBridge - C:\PROGRA~1\BTBROA~1\SMARTB~1\BTHelpNotifier.exe
MSConfigStartUp-NeroFilterCheck - C:\WINDOWS\system32\NeroCheck.exe
MSConfigStartUp-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
MSConfigStartUp-Veoh - C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
MSConfigStartUp-Cmaudio - cmicnfg.cpl
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bt.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
IE: Add to Google Photos Screensa&ver; - C:\WINDOWS\system32\GPhotos.scr/200
TCP: {EFBA1530-5D85-4113-95C6-41FD82DA661C} = 208.67.220.220,208.67.222.222
DPF: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
FF - ProfilePath - C:\Documents and Settings\peter\Application Data\Mozilla\Firefox\Profiles\oo3sxysz.default\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - plugin: C:\Program Files\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npJoostPlugin.dll
FF - plugin: C:\Program Files\Virtual Earth 3D\npVE3D.dll
.
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1003\0*" ¨*!*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"WriteErrorLog"="No"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(904)
C:\WINDOWS\system32\guard32.dll
C:\WINDOWS\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(964)
C:\WINDOWS\system32\guard32.dll
- - - - - - - > 'explorer.exe'(1032)
C:\WINDOWS\system32\guard32.dll
C:\Program Files\Logitech\SetPoint\lgscroll.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~2\Ymsgr_tray.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2009-04-09 21:46:47 - machine was rebooted [peter]
ComboFix-quarantined-files.txt 2009-04-09 20:46:38
Pre-Run: 56,930,127,872 bytes free
Post-Run: 57,020,588,032 bytes free
390 — E O F — 2008-12-10 22:06:37