ComboFix 09-06-26.02 - Arrone 06/28/2009 21:36.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3070.1674 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\msa.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 )))))))))))))))))))))))))))))))
.
2009-06-29 01:48 . 2009-06-29 01:48 ——– d—–w- c:\users\Arrone\AppData\Local\temp
2009-06-28 14:38 . 2009-06-28 14:38 ——– d—–w- c:\program files\DivX
2009-06-28 14:38 . 2009-06-28 14:38 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-06-23 02:01 . 2009-06-23 02:01 1003344 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-06-23 00:07 . 2009-06-23 00:07 ——– d—–w- c:\programdata\RealArcade
2009-06-23 00:07 . 2009-03-30 21:13 98304 —-a-w- c:\programdata\RealArcade\npraclient.dll
2009-06-23 00:07 . 2009-06-23 00:07 ——– d—–w- c:\programdata\Zylom
2009-06-23 00:07 . 2009-06-23 00:07 ——– d—–w- c:\program files\Zylom Games
2009-06-23 00:07 . 2009-03-03 14:51 98304 —-a-w- c:\programdata\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
2009-06-23 00:07 . 2004-12-20 16:17 147456 —-a-w- c:\programdata\Zylom\ZylomGamesPlayer\zylomgamesplayer.dll
2009-06-23 00:05 . 2009-06-23 01:22 ——– d—–w- c:\users\Public\RealArcade
2009-06-23 00:04 . 2009-06-23 00:14 ——– d—–w- c:\program files\RealArcade
2009-06-19 04:57 . 2009-06-19 04:57 35 —-a-w- c:\users\Arrone\AppData\Roaming\SetValue.bat
2009-06-14 14:49 . 2009-04-30 12:37 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 14:49 . 2009-04-30 12:37 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-13 03:36 . 2009-06-13 03:36 456304 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtbC09E.tmp.exe
2009-06-09 12:14 . 2009-06-09 12:14 ——– d—–w- c:\programdata\WindowsSearch
2009-06-06 02:47 . 2009-06-06 02:01 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-06 02:01 . 2009-06-06 02:01 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-06 02:01 . 2009-06-06 02:01 15688 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-06-06 02:01 . 2009-06-06 02:01 83808 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-06-06 02:01 . 2009-06-06 02:01 212848 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-06-06 02:01 . 2009-06-06 02:01 64160 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-06-06 02:01 . 2009-06-06 02:01 40288 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-06-06 01:59 . 2009-06-06 01:59 ——– dc-h–w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-06-06 01:59 . 2009-01-18 21:43 2892112 -c–a-w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
2009-06-06 01:58 . 2009-06-06 02:01 ——– d—–w- c:\programdata\Lavasoft
2009-06-06 01:58 . 2009-06-06 01:58 ——– d—–w- c:\program files\Lavasoft
2009-06-05 21:07 . 2009-06-05 21:07 ——– d—–w- c:\program files\Funcom
2009-06-04 23:39 . 2009-06-04 23:39 ——– d—–w- c:\program files\iPod
2009-06-04 23:39 . 2009-06-04 23:39 ——– d—–w- c:\program files\iTunes
2009-06-04 23:37 . 2009-06-04 23:38 ——– d—–w- c:\program files\QuickTime
2009-06-04 23:30 . 2009-06-04 23:30 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-03 18:32 . 2009-06-03 18:32 ——– d—–w- c:\users\Arrone\AppData\Roaming\GARMIN
2009-06-03 18:30 . 2009-06-03 18:30 ——– d—–w- c:\program files\Garmin GPS Plugin
2009-06-03 18:30 . 2009-06-03 18:30 ——– d—–w- c:\program files\DIFX
2009-06-03 18:29 . 2009-06-03 18:29 ——– d—–w- c:\program files\Garmin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 01:12 . 2009-03-14 12:08 ——– d—–w- c:\program files\Steam
2009-06-23 18:17 . 2009-03-14 12:08 ——– d—–w- c:\program files\Common Files\Steam
2009-06-23 00:07 . 2009-02-21 03:40 ——– d—–w- c:\program files\Google
2009-06-19 05:02 . 2009-02-20 17:37 1356 —-a-w- c:\users\Arrone\AppData\Local\d3d9caps.dat
2009-06-19 04:57 . 2009-06-19 04:57 691 —-a-w- c:\users\Arrone\AppData\Roaming\GetValue.vbs
2009-06-19 04:39 . 2009-02-21 02:20 ——– d—–w- c:\program files\Lx_cats
2009-06-15 07:04 . 2009-02-20 18:48 ——– d—–w- c:\programdata\Microsoft Help
2009-06-11 16:48 . 2009-02-21 14:27 ——– d—–w- c:\users\Arrone\AppData\Roaming\uTorrent
2009-06-11 16:45 . 2009-04-20 02:04 281760 —-a-w- c:\windows\system32\drivers\atksgt.sys
2009-06-11 16:45 . 2009-04-20 02:04 25888 —-a-w- c:\windows\system32\drivers\lirsgt.sys
2009-06-11 01:45 . 2009-04-20 01:25 ——– d—–w- c:\program files\EGOSOFT
2009-06-04 23:39 . 2009-02-21 01:00 ——– d—–w- c:\program files\Common Files\Apple
2009-05-26 02:45 . 2009-05-16 13:50 ——– d—–w- c:\program files\X Plugin Manager
2009-05-13 00:41 . 2009-05-12 01:09 ——– d—–w- c:\users\Arrone\AppData\Roaming\DAEMON Tools Lite
2009-05-12 20:22 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-12 01:09 . 2009-05-12 01:09 ——– d—–w- c:\programdata\DAEMON Tools Lite
2009-05-12 01:09 . 2009-05-12 01:09 ——– d—–w- c:\program files\DAEMON Tools Lite
2009-05-12 01:09 . 2009-05-12 01:09 ——– d—–w- c:\program files\DAEMON Tools Toolbar
2009-05-11 23:25 . 2009-05-11 23:25 ——– d—–w- c:\program files\DAEMON Tools Pro
2009-04-24 16:05 . 2009-06-11 14:18 827904 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-11 14:18 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-11 14:18 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-23 12:43 . 2009-06-11 14:18 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-11 14:18 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-11 14:18 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-04-20 01:18 . 2009-02-20 18:33 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-04-18 03:49 . 2009-02-20 17:26 105312 —-a-w- c:\users\Arrone\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-05-03 10:06 . 2009-02-26 03:14 163328 –sh–r- c:\windows\System32\flvDX.dll
2007-02-21 11:47 . 2009-02-26 03:14 31232 –sh–r- c:\windows\System32\msfDX.dll
2008-03-16 13:30 . 2009-02-26 03:14 216064 –sh–r- c:\windows\System32\nbDX.dll
2008-04-09 23:35 . 2008-04-09 23:35 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-21 39408]
"Steam"="c:\program files\Steam\Steam.exe" [2009-06-12 1217784]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-01 222592]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-25 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-25 92704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2007-11-01 151552]
"Flashget"="c:\program files\FlashGet\FlashGet.exe" [2007-09-25 2007088]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
"VX3000"="c:\windows\vVX3000.exe" [2008-08-04 721936]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"LXCICATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\LXCItime.dll" [2006-11-21 106496]
"lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2007-05-11 205744]
"EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2007-05-11 103344]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-20 518488]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-10-25 4702208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C62B8DDA-7916-4ABC-B27B-4BFA8091264E}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{FAB72AFF-61F2-49EC-B0EA-13396B2F24B0}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{7DA6CADF-0ACB-4EFA-8AAD-B4252EEAD39F}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{24E54FDF-7D9D-4194-A9CB-26449B3AA270}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5B01579E-4338-4143-B088-7BFD9BD04B87}"= UDP:c:\program files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"{6FE159C4-EB40-4E11-99A8-A9FE0892E740}"= TCP:c:\program files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"TCP Query User{575E82F6-F0CB-4B71-AFA4-5FA8C2975785}c:\\program files\\adobe\\adobe dreamweaver cs3\\dreamweaver.exe"= UDP:c:\program files\adobe\adobe dreamweaver cs3\dreamweaver.exe:Adobe Dreamweaver CS3
"UDP Query User{E33CF0F9-3845-40DD-9DC5-06DBC97B14B4}c:\\program files\\adobe\\adobe dreamweaver cs3\\dreamweaver.exe"= TCP:c:\program files\adobe\adobe dreamweaver cs3\dreamweaver.exe:Adobe Dreamweaver CS3
"{5C8DDFA0-D881-4154-96BE-AB9A82FF0BEE}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{4988A49C-934E-4B4E-95FC-9B0242AA0883}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{EB3C4FB8-7327-456B-8BCC-2230F813C48E}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{71DC78C6-9C13-46C4-BEA1-B9B7671837DD}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"TCP Query User{C9E9EBB6-2653-4BF3-8232-E6E2CD1923A4}c:\\games\\freespace2\\fs2_open_r_20060425_kara.exe"= UDP:c:\games\freespace2\fs2_open_r_20060425_kara.exe:FreeSpace
"UDP Query User{3DCD1A4C-E60F-4D2D-8B09-9FE28F1BBBF0}c:\\games\\freespace2\\fs2_open_r_20060425_kara.exe"= TCP:c:\games\freespace2\fs2_open_r_20060425_kara.exe:FreeSpace
"{2C0F148F-EDEF-4EB5-A5A2-BEFF77E60C13}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{2ABBDF45-CF6B-4BC7-A7C1-6DBF6F4A8F42}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{9E158C95-D5BC-4832-86E9-2E7DA29D87C9}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{F47104E1-CED9-41B2-A17F-28111CF23FA8}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{FCEDC4DA-A7AC-426C-A0A7-30AAA7FEBD86}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{61D2E61F-AB97-4D89-BD8D-5BBB0EC2E2A8}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{21AD0672-6BE2-4265-8960-9416FBFB7F4B}"= c:\program files\CyberLink\PowerDirector Express\PDX.EXE:CyberLink PowerDirector Express
"{F9C64CE9-C6BE-4FDA-8953-E843C0965086}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{645E7832-64C9-4A6A-A846-892198FF71DE}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{F39D3FA4-D2EE-454E-9F2F-69CD2C0C248B}"= UDP:c:\program files\Microsoft LifeCam\LifeEnC2.exe:LifeEnC2.exe
"{E68C5B7F-5061-49E5-B7CD-480DE322CE77}"= TCP:c:\program files\Microsoft LifeCam\LifeEnC2.exe:LifeEnC2.exe
"{B939BE25-D5AB-46F0-BEFF-AE876D2E9754}"= UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{81970365-FA26-4354-981A-80CB7295EB14}"= TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{92FAAEC0-C7DC-42C4-9482-7DA4E98637FE}"= UDP:c:\program files\Microsoft LifeCam\LifeTray.exe:LifeTray.exe
"{2B4E25BC-983B-427D-A854-FD7DC84C35CB}"= TCP:c:\program files\Microsoft LifeCam\LifeTray.exe:LifeTray.exe
"TCP Query User{57B5472A-EC13-4ADB-9412-417C0C3D6E90}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:FlashGet
"UDP Query User{3409456B-28CD-43A7-BE1D-EAFBD6859AA6}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:FlashGet
"{ABEB90AD-5594-4026-9297-C81E66471DD8}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{05BE2F4C-5623-4645-8F1C-AAE768A27B7D}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{FFA14AFE-AA57-4CD9-90C9-13D4EC0AEF79}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{81F6E41C-586E-4A9D-9E2B-B07FCF3A0DDB}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B4F6173A-A18E-4589-9DCC-F43A38DB0036}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{12B1453E-E498-48D8-8F9B-6E627AC12B31}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{5C2EDF93-65AB-48A6-AA7F-8A00768D7F4E}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{73B2F1CC-7A31-409A-8C68-E10CC124B92E}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{F7202034-6F04-4973-A041-D9E5DF0B5BC1}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{2F80FCA1-7D16-4A61-ACEF-36A86E12A60F}"= UDP:c:\windows\System32\lxcicoms.exe:Lexmark Communications System
"{2C258A8D-46EF-495C-9830-BD25674233FA}"= TCP:c:\windows\System32\lxcicoms.exe:Lexmark Communications System
"{0A996ED3-D57B-4E73-A4FA-D057942FF9CF}"= UDP:c:\windows\System32\lxcicoms.exe:Lexmark Communications System
"{532D59E1-CB98-4683-816B-E92BD0AC7FB9}"= TCP:c:\windows\System32\lxcicoms.exe:Lexmark Communications System
"{503DF280-F28F-4091-A285-9D1674166AD9}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxcipswx.exe:Printer Status Window
"{24AC4553-5BC8-4F53-A1E7-FCAF35A47FDE}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxcipswx.exe:Printer Status Window
"TCP Query User{30C04AF7-4EA3-4B39-B075-64D3F97F5F8C}c:\\program files\\gamespy\\comrade\\comrade.exe"= UDP:c:\program files\gamespy\comrade\comrade.exe:Comrade
"UDP Query User{7EC6CC72-77E4-492B-9506-52E7EE56C340}c:\\program files\\gamespy\\comrade\\comrade.exe"= TCP:c:\program files\gamespy\comrade\comrade.exe:Comrade
"{60F23F73-8CC7-4BB4-9489-224DFE214C01}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FFA1D73D-83F2-46BF-AA73-E1DF6DAADB14}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C309DB3E-E863-4F07-9EED-427714C40130}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{0AF9CB9F-5CFA-4D73-A2A7-A322BD149C52}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{3B4C172A-5303-4786-A4BE-B9EBBD728E6A}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{D5B46648-A961-4F98-B95A-1DB0970E0DD1}c:\\users\\arrone\\downloads\\anarchyonline_17.9.1-large.exe"= UDP:c:\users\arrone\downloads\anarchyonline_17.9.1-large.exe:anarchyonline_17.9.1-large.exe
"UDP Query User{D6D55D86-365A-4DFB-BBE1-C55B3FA5FA89}c:\\users\\arrone\\downloads\\anarchyonline_17.9.1-large.exe"= TCP:c:\users\arrone\downloads\anarchyonline_17.9.1-large.exe:anarchyonline_17.9.1-large.exe
"{EF133537-FC6D-4CEC-910E-1BCC9F64B646}"= UDP:c:\program files\Funcom\Anarchy Online\Anarchy.exe:Anarchy Online
"{AF7B02D4-92A5-4037-A290-8F0FA8A53043}"= TCP:c:\program files\Funcom\Anarchy Online\Anarchy.exe:Anarchy Online
R0 amacpi;Microsoft Away Mode System;c:\windows\System32\drivers\null.sys [1/20/2008 22:21 4608]
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [6/5/2009 22:01 64160]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NAV\1002000.007\BHDrvx86.sys [2/21/2009 09:54 255536]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NAV\1002000.007\cchpx86.sys [2/21/2009 09:54 362544]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090303.001\IDSvix86.sys [3/4/2009 16:55 292912]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 17:34 1003344]
R2 lxci_device;lxci_device;c:\windows\system32\lxcicoms.exe -service –> c:\windows\system32\lxcicoms.exe -service [?]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe [2/21/2009 09:54 115560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/1/2009 05:00 101936]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\NAV\1002000.007\symndisv.sys [2/21/2009 09:54 40496]
S2 gupdate1c9be07ca20ada7;Google Update Service (gupdate1c9be07ca20ada7);c:\program files\Google\Update\GoogleUpdate.exe [4/15/2009 16:21 133104]
S3 VST_DPV;VST_DPV;c:\windows\System32\drivers\VSTDPV3.SYS [1/20/2008 22:21 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\System32\drivers\VSTBS23.SYS [1/20/2008 22:21 251904]
— Other Services/Drivers In Memory —
*NewlyCreated* - AUJASNKJ
*Deregistered* - aujasnkj
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B3688A53-AB2A-4b1d-8CEF-8F93D8C51C24}]
%SystemRoot%\system32\soundschemes2.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder
2009-06-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 02:01]
2009-06-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-15 20:21]
2009-06-29 c:\windows\Tasks\User_Feed_Synchronization-{6FBBD91E-AE62-47EE-9651-11168433E38D}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:23]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Download; All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download; with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {AF79B0ED-FF34-4635-AE35-50ECB6D48C1A} = 192.168.0.106
FF - ProfilePath - c:\users\Arrone\AppData\Roaming\Mozilla\Firefox\Profiles\5evcv0o7.default\
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\extensions\[removed]\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npraclient.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\programdata\RealArcade\npraclient.dll
FF - plugin: c:\programdata\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-28 21:48
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCICATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-29 21:50
ComboFix-quarantined-files.txt 2009-06-29 01:50
Pre-Run: 35,630,542,848 bytes free
Post-Run: 39,791,239,168 bytes free
272 — E O F — 2009-06-25 20:46