ComboFix 09-07-12.01 - Robert 07/12/2009 18:33.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1022.377 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-1592213791-1963367186-16139517-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\temp\fse
c:\windows\Installer\47fc3e2.msi
c:\windows\Installer\517b93b.msp
c:\windows\Installer\75b8c.msi
c:\windows\Installer\a8f2cca.msi
c:\windows\system32\drivers\MSIVXccwovvpmhwivumyloxvkhuptardqedmw.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\f01WtR
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXkgyibtyexnstjbrvjmdhjfxqlosxkepx.dll
c:\windows\system32\MSIVXtnmidpcvqynyeinerqiwqpicwvmgnlhf.dll
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_MSIVXserv.sys
——-\Legacy_NPF
——-\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-06-12 to 2009-07-12 )))))))))))))))))))))))))))))))
.
2009-07-12 22:48 . 2009-07-12 22:57 ——– d—–w- c:\users\Robert\AppData\Local\temp
2009-07-12 18:17 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVENG.SYS
2009-07-12 18:17 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVEX15.SYS
2009-07-12 18:17 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\EECTRL.SYS
2009-07-12 18:17 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\ECMSVR32.DLL
2009-07-12 18:17 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\CCERASER.DLL
2009-07-12 18:17 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVENG32.DLL
2009-07-12 18:17 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVEX32A.DLL
2009-07-12 18:17 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\ERASER.SYS
2009-07-12 08:26 . 2009-07-12 08:26 ——– d—–w- C:\_OTM
2009-07-12 07:25 . 2009-07-12 07:26 ——– d—–w- C:\rsit
2009-07-12 06:26 . 2009-07-12 06:26 ——– d—–w- c:\users\Robert\AppData\Roaming\Malwarebytes
2009-07-12 06:23 . 2009-06-17 15:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-12 06:23 . 2009-07-12 06:23 ——– d—–w- c:\programdata\Malwarebytes
2009-07-12 06:23 . 2009-06-17 15:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 06:23 . 2009-07-12 06:26 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-12 01:16 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX32A.DLL
2009-07-12 01:16 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG.SYS
2009-07-12 01:16 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX15.SYS
2009-07-12 01:16 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\EECTRL.SYS
2009-07-12 01:16 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ECMSVR32.DLL
2009-07-12 01:16 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\CCERASER.DLL
2009-07-12 01:16 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG32.DLL
2009-07-12 01:16 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ERASER.SYS
2009-07-11 07:09 . 2009-07-12 21:32 ——– d—–w- c:\program files\Trend Micro
2009-07-10 22:43 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\Scxpx86.dll
2009-07-10 22:43 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSvix86.sys
2009-07-10 22:43 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSco.sys
2009-07-10 22:43 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSxpx86.dll
2009-07-10 22:43 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSI.dll
2009-07-10 22:43 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSviA64.sys
2009-07-10 22:43 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDS9xx86.dll
2009-07-10 15:27 . 2009-07-10 21:40 ——– d—–w- c:\windows\.jagex_cache_32
2009-07-09 05:17 . 2009-07-09 05:31 ——– d—–w- c:\program files\MasterWriter 2.0
2009-07-07 19:38 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\Scxpx86.dll
2009-07-07 19:38 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSvix86.sys
2009-07-07 19:38 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\SymIDSco.sys
2009-07-07 19:38 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSxpx86.dll
2009-07-07 19:38 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\SymIDSI.dll
2009-07-07 19:38 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSviA64.sys
2009-07-07 19:38 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDS9xx86.dll
2009-07-07 00:25 . 2009-07-07 00:25 ——– d—–w- c:\users\Robert\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150040}
2009-07-02 12:25 . 2009-07-11 06:20 ——– d—–w- c:\users\Robert\Tracing
2009-07-02 07:30 . 2009-07-02 07:30 ——– d—–w- c:\program files\Microsoft Office Outlook Connector
2009-07-02 07:25 . 2009-07-02 07:25 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2009-07-02 07:21 . 2009-07-02 07:21 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-02 07:21 . 2009-07-11 06:39 ——– d—–w- c:\program files\Windows Live
2009-07-02 06:33 . 2009-05-09 05:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-02 06:33 . 2009-05-09 05:50 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-28 04:05 . 2009-06-28 04:05 ——– d—–w- c:\users\Robert\AppData\Roaming\QQ Games Plugin
2009-06-28 04:03 . 2009-06-28 04:08 ——– d—–w- c:\programdata\Tencent
2009-06-28 04:03 . 2009-06-28 04:03 ——– d—–w- c:\program files\Tencent
2009-06-28 04:00 . 2009-06-28 04:00 5946704 —-a-w- c:\programdata\AOL Downloads\aimqqgames\QQSetup65.exe
2009-06-28 03:59 . 2009-06-28 03:59 1144808 —-a-w- c:\programdata\AOL Downloads\aimtunes\AIMTunes.exe
2009-06-28 03:58 . 2009-06-28 03:58 ——– d—–w- c:\programdata\acccore
2009-06-28 03:56 . 2009-06-28 04:04 ——– d—–w- c:\program files\AIM6
2009-06-27 05:42 . 2009-06-27 05:42 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-06-26 19:22 . 2009-06-26 19:22 ——– d—–w- c:\users\Robert\New Folder
2009-06-26 10:22 . 2009-06-26 10:29 ——– d—–w- c:\program files\4WomenOnly
2009-06-26 10:17 . 2009-06-26 10:17 ——– d—–w- c:\program files\Advanced Woman Calendar
2009-06-26 01:40 . 2009-06-26 01:40 ——– d—–w- c:\users\Robert\AppData\Roaming\SoftOrbits
2009-06-23 15:20 . 2009-06-23 15:20 ——– d—–w- c:\users\Robert\AppData\Local\SourceTec
2009-06-20 01:10 . 2009-06-20 01:11 ——– d—–w- c:\users\Robert\AppData\Local\Deployment
2009-06-14 00:07 . 2009-04-30 12:37 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 00:07 . 2009-04-30 12:37 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-13 16:45 . 2009-03-19 20:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-13 16:45 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iPod
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iTunes
2009-06-13 16:39 . 2009-06-13 16:40 ——– d—–w- c:\program files\QuickTime
2009-06-13 16:31 . 2009-06-13 16:32 ——– d—–w- c:\program files\Apple Software Update
2009-06-13 16:28 . 2009-06-13 16:44 ——– d—–w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-12 22:50 . 2007-11-14 23:57 12 —-a-w- c:\windows\bthservsdp.dat
2009-07-11 06:24 . 2007-08-11 03:20 ——– d—–w- c:\program files\The Rosetta Stone
2009-07-11 06:23 . 2007-02-08 08:26 ——– d—–w- c:\program files\Google
2009-07-10 02:19 . 2007-03-13 01:49 115728 —-a-w- c:\users\Robert\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-07 00:31 . 2007-02-08 08:09 ——– d—–w- c:\program files\Java
2009-07-02 07:22 . 2009-01-23 16:32 ——– d—–w- c:\program files\Microsoft
2009-06-28 04:00 . 2007-03-13 23:38 ——– d—–w- c:\programdata\AOL Downloads
2009-06-28 03:58 . 2007-06-08 13:46 ——– d—–w- c:\programdata\Viewpoint
2009-06-28 03:57 . 2007-03-13 23:40 ——– d—–w- c:\program files\Common Files\AOL
2009-06-28 03:52 . 2007-03-13 23:40 ——– d—–w- c:\programdata\AOL
2009-06-13 17:11 . 2007-10-29 23:11 ——– d—–w- c:\users\Robert\AppData\Roaming\Apple Computer
2009-06-13 16:41 . 2008-02-21 01:51 ——– d—–w- c:\program files\Bonjour
2009-06-12 21:34 . 2009-06-12 21:34 ——– d—–w- c:\program files\Common Files\xing shared
2009-06-12 21:33 . 2009-03-29 23:13 ——– d—–w- c:\program files\Common Files\Real
2009-06-12 18:00 . 2009-06-12 18:00 ——– d—–w- c:\users\Robert\AppData\Roaming\TVU Networks
2009-06-12 17:58 . 2009-06-12 17:58 ——– d—–w- c:\program files\Satellite TV for PC
2009-06-10 00:25 . 2009-05-25 11:59 ——– d—–w- c:\program files\Pcsx2_0.9.4(2)
2009-06-10 00:24 . 2007-03-13 23:42 ——– d—–w- c:\program files\MySpace
2009-06-08 16:14 . 2009-06-08 16:14 ——– d—–w- c:\program files\LG Electronics
2009-06-08 16:14 . 2007-02-08 08:09 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-05 17:57 . 2009-06-05 17:57 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 15:42 . 2009-06-05 15:42 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-05 15:42 . 2009-06-05 15:42 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-06-04 21:44 . 2009-06-04 21:44 ——– d—–w- c:\program files\BitPim
2009-05-24 14:34 . 2009-05-24 14:34 ——– d—–w- c:\program files\LibUSB-Win32-0.1.10.1
2009-05-21 15:33 . 2009-01-05 11:29 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-16 12:37 . 2009-05-16 12:37 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-14 11:45 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-13 12:32 . 2009-05-13 08:00 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys
2009-05-13 12:32 . 2009-05-13 08:00 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys
2009-05-13 12:32 . 2009-05-13 08:00 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys
2009-05-13 12:32 . 2009-05-13 08:00 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll
2009-05-13 12:32 . 2009-05-13 08:00 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll
2009-05-13 12:32 . 2009-05-13 08:00 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll
2009-05-13 12:32 . 2009-05-13 08:00 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys
2009-05-13 12:32 . 2009-02-26 22:23 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll
2009-05-08 13:35 . 2008-08-14 11:57 73312 —-a-w- c:\windows\system32\drivers\adfs.sys
2009-04-23 12:43 . 2009-06-10 05:45 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 05:45 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-10 05:45 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-04-16 22:16 . 2007-04-18 02:01 7592 —-a-w- c:\users\Robert\AppData\Local\d3d9caps.dat
2009-04-01 02:47 . 2009-02-26 23:44 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2007-02-08 15:54 . 2007-02-08 15:54 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-02 4608]
"SRS Audio Sandbox"="c:\program files\SRS Labs\Audio Sandbox\SRSSSC.exe" [2007-09-08 3153920]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544]
"Advanced Woman Calendar"="c:\program files\Advanced Woman Calendar\WomanCalendar.exe" [2009-05-23 1503232]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-27 1540096]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2006-11-17 17920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-10-13 184320]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544]
"PreSonusUSBInstallApp"="c:\program files\AudioBox USB\InstPresonusUSBDrv.exe" [2008-03-07 28672]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-12 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-01-12 303104]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-2-8 50688]
QuickSet.lnk - c:\windows\Installer\{53A01CC6-14B0-4512-A2E7-10D39BF83DC4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-2-8 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DC710089-7342-417F-A0FA-EA1011418106}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{8405E45A-A992-480B-91C3-BDCC3100CC25}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{6F84580A-2584-434F-8547-37BE87270674}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4B3691E0-8E97-479D-B685-16C91E95CBE8}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{6532F09B-8FC9-40BA-8690-D94EBB1ACBDD}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"TCP Query User{176AF534-1FED-46AF-9AF6-1F2D17C4034B}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{D94FA29A-0081-455B-AAA5-77B189ACE72C}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{C6222461-1E4D-48BC-9426-06A3D575611A}"= UDP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"{26E34F77-6589-480B-8314-2F0FF6F3B35C}"= TCP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"{4F357201-4322-4748-A572-57E518BC2692}"= UDP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP)
"{33C59A06-EAA6-4B06-A8A8-A02AFB6C0450}"= TCP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP)
"TCP Query User{972126A1-FFB1-40AA-A487-EDB57C69F396}c:\\stubinstaller.exe"= UDP:C:\stubinstaller.exe:LimeWire swarmed installer
"UDP Query User{08FE4F19-82BE-41A1-981B-A6E200035140}c:\\stubinstaller.exe"= TCP:C:\stubinstaller.exe:LimeWire swarmed installer
"{39626CD8-ADEE-4ED5-A522-B8BE4367839E}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{36E3D7E5-3AC9-452B-995F-E431754D9694}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{50774B62-755F-426B-BA2A-02367C248FD8}c:\\program files\\america's army\\system\\armyops.exe"= UDP:c:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{699E8109-8EC9-45D5-B124-78D4CECC6789}c:\\program files\\america's army\\system\\armyops.exe"= TCP:c:\program files\america's army\system\armyops.exe:ArmyOps
"TCP Query User{7F12EB81-973C-42BE-B20C-8AD6CBEDE1CD}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{C99F839B-F361-48CE-8ED4-1B05B0427AB4}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"TCP Query User{11CAFF35-683B-4264-A107-0CD434DBF06B}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= UDP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"UDP Query User{9CD00152-8430-4809-9267-A35C2A4457BA}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= TCP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"{0E737215-4FCF-4A34-B3F5-12AD135DD972}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{1B111988-17EE-43ED-B972-5517B49E42DB}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{41BE85E8-EA12-4202-8761-0D4796BB177B}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{F5CF6DEF-A246-43FF-8F3C-6BE0235F11B2}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"TCP Query User{E2C7BFD9-15E5-4E1C-8224-D3584D59088C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{9C831B6D-4CB2-454F-9089-3AF58DBD4AC3}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{DBD29491-FF3D-43F9-90ED-44CC95386DCD}c:\\program files\\quicktime\\quicktimeplayer.exe"= UDP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application
"UDP Query User{A380A176-6079-43CB-A92E-32FCEEA9BEC7}c:\\program files\\quicktime\\quicktimeplayer.exe"= TCP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application
"TCP Query User{3AC313D9-B6B3-495C-8C13-500BB0EA49C7}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= UDP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe
"UDP Query User{1982024B-D1E4-4F70-839F-6635AD27A497}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= TCP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe
"TCP Query User{C05E66C8-281F-45E7-B14E-CF88DD3147B8}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:UDP:c:\program files\microsoft games\halo\halo.exe:Halo
"UDP Query User{EB58509F-411D-4429-A0FD-2CD055BA3B95}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:TCP:c:\program files\microsoft games\halo\halo.exe:Halo
"{2C13D723-369B-44D5-8C32-8135E6B16B71}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas
"{B3796AEB-60D7-4DEF-BFE5-BB9171F4803A}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas
"{DB5A49BC-BDCA-4BBB-8CF1-BEBFF13098E2}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater
"{FCB7312A-3871-4FC9-821E-71988B8544AC}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater
"{30BCEC95-2E5A-4C61-8D40-C3B9FFD3823B}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{037AC626-54D7-4530-B3D8-BB570E3D8C16}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"TCP Query User{CD6EC63F-B479-473B-B94F-56C99452F37A}c:\\program files\\kuma games\\kumaclient.exe"= UDP:c:\program files\kuma games\kumaclient.exe:KumaClient
"UDP Query User{BEB615F7-77C8-4EEF-805F-444D585E6EDA}c:\\program files\\kuma games\\kumaclient.exe"= TCP:c:\program files\kuma games\kumaclient.exe:KumaClient
"{5D1DEC78-A955-4D8A-8296-811BDF1617A0}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{DF77B589-E554-4ADC-8108-874E486BA6C6}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"TCP Query User{0C521428-3F98-4271-B54D-F6B44CF3EC49}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{6CCA7FD4-2B5B-49EB-9341-1CEACD116E8F}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"TCP Query User{0DF51FA7-6AFB-4AB0-8E51-D9A5546224D3}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= UDP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe
"UDP Query User{11D209CA-9190-4F46-8CFA-15933A36E47C}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= TCP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe
"TCP Query User{0AB1783F-77DA-428F-A04E-8190DB0A0AF7}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:utorrent
"UDP Query User{9D214FD0-B98C-47D1-8CA6-FD35255964A0}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:utorrent
"TCP Query User{50942DBF-744F-4A91-8D9B-AAF9E80C6482}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{2D2ED0DB-41F5-4E5D-9F7E-A25BC637E633}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"TCP Query User{BE578BD9-8465-4D6C-9104-D8731100F238}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:UDP:c:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{DCE00D38-E3F7-4059-AA29-0CCB1171B992}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:TCP:c:\program files\america's army\system\armyops.exe:ArmyOps
"{80CBB081-7B44-4297-BC34-684ECB632924}"= Disabled:UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11
"{D2F76F1D-9440-4DF7-AB3E-1631127E3FE9}"= Disabled:TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11
"{BA6434C4-DCAC-4FF5-82D9-D7445E776408}"= UDP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service
"{CB372408-8C36-4775-B0F0-DF0AE2280357}"= TCP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service
"{F7236639-1ECF-4334-8244-2138D2278732}"= UDP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service
"{EFFBAA4E-D072-49BD-B58B-B586E631F96B}"= TCP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service
"{34B5A9D7-4FFB-4581-AC04-B5508393A17B}"= UDP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service
"{4F730A66-4CEC-44A0-9025-6E32E7CF3626}"= TCP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service
"{6C52A495-FE39-42B0-8F73-8DEA79E5C6B4}"= UDP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface
"{AEDB5741-E4CE-4DB3-8BE5-F9B07B64DB14}"= TCP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface
"{A0A1FD56-A36B-443B-B6B4-45F537345010}"= UDP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service
"{DBCD57CA-719A-45A7-9E5B-12CE6E6FA46D}"= TCP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service
"{331A8417-C522-4DC1-A96D-99C6B0B2414F}"= Disabled:TCP:5353:LocalSubnet:LocalSubnet:mDNS-SD/Bonjour
"{F94507A9-E86D-4B26-A05D-98640DE4B435}"= Disabled:UDP:7288:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7288
"{300E4533-FBD2-44B3-BED6-E656FF52E20D}"= Disabled:UDP:7289:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7289
"{E6D88E95-3619-4618-ACDC-C6E570999B10}"= Disabled:UDP:7290:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7290
"{6A9EF052-1FC4-4048-9A0C-D71CF0A91DD5}"= Disabled:UDP:7291:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7291
"{2EC834E0-A318-4E7A-934D-DCE7F99AAEE3}"= Disabled:UDP:7292:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7292
"{F0C2ADCD-027F-4F83-ABCD-DED4E6998E14}"= Disabled:UDP:7293:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7293
"{C788FA07-7765-438F-816D-BBC57A7AD7CA}"= Disabled:UDP:7294:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7294
"{0DE58F16-EF68-4037-9D81-9E8D332C4B40}"= Disabled:UDP:7295:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7295
"{618D88A4-B71A-4619-BD24-7A172B16BBA2}"= Disabled:UDP:7296:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7296
"{3B684CB2-6380-4B11-9DAA-203686A7F59D}"= Disabled:UDP:7297:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7297
"TCP Query User{A87CEF39-79F4-495B-8107-2669E9317E71}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{C0BCEEE4-5CBC-45C4-9A2A-9252EA89B6D7}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{4AA631F1-8A10-43E2-9AF2-50D523F7D8A6}"= Disabled:UDP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{BDB164A7-08E7-4FA3-9D14-411918B25E43}"= Disabled:TCP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"TCP Query User{5047A0F9-65E8-4010-8166-8989AFB9EA7F}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{B8039892-6D92-4996-97E1-DB2E32B9868D}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{C0B7971A-92C6-49CF-A26F-4CBF0E92884B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{D11DFF62-E2DF-493F-AA1A-9D220AA03955}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{51757B52-543D-4D42-8D03-3396B16501C9}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4A5BF50F-E211-4466-B638-2CFDFED791D1}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{2AFD8F0A-EDC7-4EE6-9448-5B1ACF10122F}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™
"{DEF7D8E2-E21B-4CB6-8115-9C934F821867}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™
"{D6F2FD21-59B8-4910-97E1-408F11257E50}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™
"{04F7FCF0-DE92-40FB-B775-20035D39BC7B}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™
"TCP Query User{B6388C41-AF36-4F37-A349-A603E91640B9}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:UDP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"UDP Query User{2A133730-1F9C-4727-97CF-AFB8FCF73C83}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:TCP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"{C9D98063-9DE5-4EDD-8E0B-603BCDA3233E}"= UDP:5353:Adobe CSI CS4
"{80F6A506-94F0-4270-8C5F-44268DC3201D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{A8FDCCFA-B108-4263-9641-B5DEA85D487C}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{0D423FB4-7220-4832-847B-0E85A9DD15AF}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A1422C01-5FDB-4506-A2CB-3B046706FC5A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{29EE3451-05EE-47AF-8947-99DD5BFC854B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{F87D848E-3DA4-403D-BDDB-CFDE631A1128}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{10B415ED-2A06-4C2F-9380-57B542D4FD1A}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{3000B06D-2401-4D80-8E9F-6CE6751BEB6F}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{BF7203B0-6B85-434C-9FCD-6188A11831B7}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090709.001\IDSvix86.sys [7/10/2009 6:43 PM 272432]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe –> system32\libusbd-nt.exe [?]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 3:37 PM 149352]
R2 musm3gld;musm3gld;c:\windows\System32\drivers\musm3gld.sys [2/10/2008 9:30 AM 5513]
R2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe [3/21/2007 5:25 PM 548488]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/28/2007 6:59 PM 24652]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [3/30/2009 4:28 PM 1533808]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/10/2009 2:33 AM 101936]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\System32\drivers\libusb0.sys [5/24/2009 10:34 AM 33792]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 12:31 PM 41008]
S2 gupdate1c9eba4d5aabe4e;Google Update Service (gupdate1c9eba4d5aabe4e);c:\program files\Google\Update\GoogleUpdate.exe [6/12/2009 5:29 PM 133104]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [1/12/2008 10:32 PM 23888]
S3 ControlTransferDriver;AudioBox USB Control Transfer;c:\windows\System32\drivers\PreSonusUSB_xfer.sys [1/8/2009 5:10 PM 28576]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [7/12/2009 2:23 AM 38160]
S3 SynasUSB;SynasUSB;c:\windows\System32\drivers\synasUSB.sys [1/9/2009 10:17 AM 18432]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28]
2009-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28]
2009-07-12 c:\windows\Tasks\User_Feed_Synchronization-{16669BE4-D9F0-4EB3-8A0B-146FE0D8BE1D}.job
- c:\windows\system32\msfeedssync.exe [2009-07-02 11:31]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKCU-Run-P2kAutostart - (no file)
HKCU-Run-AdobeBridge - (no file)
HKCU-Run-Aim6 - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5070208
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\27qgbx4k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-12 18:54
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1592213791-1963367186-16139517-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:53,fe,7b,56,c5,f3,53,2f,cb,43,99,d8,dc,b0,76,63,da,43,e4,78,9c,22,74,
65,66,11,21,59,75,a0,7a,b8,5b,6d,92,2f,eb,99,16,84,3c,9d,26,7f,19,ab,56,43,\
"??"=hex:92,46,0e,fe,89,48,9d,d8,a5,2f,6e,0c,51,93,50,80
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(3300)
c:\windows\System32\NLSData0009.dll
c:\windows\system32\wpdshserviceobj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\program files\Dell\MediaDirect\Kernel\Video\CLM1Splter.ax
c:\program files\Common Files\Sonic Shared\SonicMC01\sonicMP4Demux.ax
c:\program files\Common Files\Ahead\DSFilter\NeFLVSplitter.ax
c:\program files\Real Alternative\RealMediaSplitter.ax
c:\program files\Common Files\Ahead\DSFilter\NeMP4Splitter.ax
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\Crypserv.exe
c:\windows\System32\libusbd-nt.exe
c:\program files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
.
**************************************************************************
.
Completion time: 2009-07-12 19:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-12 23:04
Pre-Run: 4,481,064,960 bytes free
Post-Run: 4,134,375,424 bytes free
480 — E O F — 2009-07-06 23:26