This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] TrojanDownloader/Win32/I.O

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix 09-07-12.01 - Robert 07/12/2009 18:33.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1022.377 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-1592213791-1963367186-16139517-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\temp\fse
c:\windows\Installer\47fc3e2.msi
c:\windows\Installer\517b93b.msp
c:\windows\Installer\75b8c.msi
c:\windows\Installer\a8f2cca.msi
c:\windows\system32\drivers\MSIVXccwovvpmhwivumyloxvkhuptardqedmw.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\f01WtR
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXkgyibtyexnstjbrvjmdhjfxqlosxkepx.dll
c:\windows\system32\MSIVXtnmidpcvqynyeinerqiwqpicwvmgnlhf.dll
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSIVXserv.sys
——-\Legacy_NPF
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-06-12 to 2009-07-12 )))))))))))))))))))))))))))))))
.

2009-07-12 22:48 . 2009-07-12 22:57 ——– d—–w- c:\users\Robert\AppData\Local\temp
2009-07-12 18:17 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVENG.SYS
2009-07-12 18:17 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVEX15.SYS
2009-07-12 18:17 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\EECTRL.SYS
2009-07-12 18:17 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\ECMSVR32.DLL
2009-07-12 18:17 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\CCERASER.DLL
2009-07-12 18:17 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVENG32.DLL
2009-07-12 18:17 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVEX32A.DLL
2009-07-12 18:17 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\ERASER.SYS
2009-07-12 08:26 . 2009-07-12 08:26 ——– d—–w- C:\_OTM
2009-07-12 07:25 . 2009-07-12 07:26 ——– d—–w- C:\rsit
2009-07-12 06:26 . 2009-07-12 06:26 ——– d—–w- c:\users\Robert\AppData\Roaming\Malwarebytes
2009-07-12 06:23 . 2009-06-17 15:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-12 06:23 . 2009-07-12 06:23 ——– d—–w- c:\programdata\Malwarebytes
2009-07-12 06:23 . 2009-06-17 15:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 06:23 . 2009-07-12 06:26 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-12 01:16 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX32A.DLL
2009-07-12 01:16 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG.SYS
2009-07-12 01:16 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX15.SYS
2009-07-12 01:16 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\EECTRL.SYS
2009-07-12 01:16 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ECMSVR32.DLL
2009-07-12 01:16 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\CCERASER.DLL
2009-07-12 01:16 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG32.DLL
2009-07-12 01:16 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ERASER.SYS
2009-07-11 07:09 . 2009-07-12 21:32 ——– d—–w- c:\program files\Trend Micro
2009-07-10 22:43 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\Scxpx86.dll
2009-07-10 22:43 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSvix86.sys
2009-07-10 22:43 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSco.sys
2009-07-10 22:43 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSxpx86.dll
2009-07-10 22:43 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSI.dll
2009-07-10 22:43 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSviA64.sys
2009-07-10 22:43 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDS9xx86.dll
2009-07-10 15:27 . 2009-07-10 21:40 ——– d—–w- c:\windows\.jagex_cache_32
2009-07-09 05:17 . 2009-07-09 05:31 ——– d—–w- c:\program files\MasterWriter 2.0
2009-07-07 19:38 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\Scxpx86.dll
2009-07-07 19:38 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSvix86.sys
2009-07-07 19:38 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\SymIDSco.sys
2009-07-07 19:38 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSxpx86.dll
2009-07-07 19:38 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\SymIDSI.dll
2009-07-07 19:38 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSviA64.sys
2009-07-07 19:38 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDS9xx86.dll
2009-07-07 00:25 . 2009-07-07 00:25 ——– d—–w- c:\users\Robert\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150040}
2009-07-02 12:25 . 2009-07-11 06:20 ——– d—–w- c:\users\Robert\Tracing
2009-07-02 07:30 . 2009-07-02 07:30 ——– d—–w- c:\program files\Microsoft Office Outlook Connector
2009-07-02 07:25 . 2009-07-02 07:25 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2009-07-02 07:21 . 2009-07-02 07:21 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-02 07:21 . 2009-07-11 06:39 ——– d—–w- c:\program files\Windows Live
2009-07-02 06:33 . 2009-05-09 05:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-02 06:33 . 2009-05-09 05:50 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-28 04:05 . 2009-06-28 04:05 ——– d—–w- c:\users\Robert\AppData\Roaming\QQ Games Plugin
2009-06-28 04:03 . 2009-06-28 04:08 ——– d—–w- c:\programdata\Tencent
2009-06-28 04:03 . 2009-06-28 04:03 ——– d—–w- c:\program files\Tencent
2009-06-28 04:00 . 2009-06-28 04:00 5946704 —-a-w- c:\programdata\AOL Downloads\aimqqgames\QQSetup65.exe
2009-06-28 03:59 . 2009-06-28 03:59 1144808 —-a-w- c:\programdata\AOL Downloads\aimtunes\AIMTunes.exe
2009-06-28 03:58 . 2009-06-28 03:58 ——– d—–w- c:\programdata\acccore
2009-06-28 03:56 . 2009-06-28 04:04 ——– d—–w- c:\program files\AIM6
2009-06-27 05:42 . 2009-06-27 05:42 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-06-26 19:22 . 2009-06-26 19:22 ——– d—–w- c:\users\Robert\New Folder
2009-06-26 10:22 . 2009-06-26 10:29 ——– d—–w- c:\program files\4WomenOnly
2009-06-26 10:17 . 2009-06-26 10:17 ——– d—–w- c:\program files\Advanced Woman Calendar
2009-06-26 01:40 . 2009-06-26 01:40 ——– d—–w- c:\users\Robert\AppData\Roaming\SoftOrbits
2009-06-23 15:20 . 2009-06-23 15:20 ——– d—–w- c:\users\Robert\AppData\Local\SourceTec
2009-06-20 01:10 . 2009-06-20 01:11 ——– d—–w- c:\users\Robert\AppData\Local\Deployment
2009-06-14 00:07 . 2009-04-30 12:37 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 00:07 . 2009-04-30 12:37 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-13 16:45 . 2009-03-19 20:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-13 16:45 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iPod
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iTunes
2009-06-13 16:39 . 2009-06-13 16:40 ——– d—–w- c:\program files\QuickTime
2009-06-13 16:31 . 2009-06-13 16:32 ——– d—–w- c:\program files\Apple Software Update
2009-06-13 16:28 . 2009-06-13 16:44 ——– d—–w- c:\program files\Common Files\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-12 22:50 . 2007-11-14 23:57 12 —-a-w- c:\windows\bthservsdp.dat
2009-07-11 06:24 . 2007-08-11 03:20 ——– d—–w- c:\program files\The Rosetta Stone
2009-07-11 06:23 . 2007-02-08 08:26 ——– d—–w- c:\program files\Google
2009-07-10 02:19 . 2007-03-13 01:49 115728 —-a-w- c:\users\Robert\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-07 00:31 . 2007-02-08 08:09 ——– d—–w- c:\program files\Java
2009-07-02 07:22 . 2009-01-23 16:32 ——– d—–w- c:\program files\Microsoft
2009-06-28 04:00 . 2007-03-13 23:38 ——– d—–w- c:\programdata\AOL Downloads
2009-06-28 03:58 . 2007-06-08 13:46 ——– d—–w- c:\programdata\Viewpoint
2009-06-28 03:57 . 2007-03-13 23:40 ——– d—–w- c:\program files\Common Files\AOL
2009-06-28 03:52 . 2007-03-13 23:40 ——– d—–w- c:\programdata\AOL
2009-06-13 17:11 . 2007-10-29 23:11 ——– d—–w- c:\users\Robert\AppData\Roaming\Apple Computer
2009-06-13 16:41 . 2008-02-21 01:51 ——– d—–w- c:\program files\Bonjour
2009-06-12 21:34 . 2009-06-12 21:34 ——– d—–w- c:\program files\Common Files\xing shared
2009-06-12 21:33 . 2009-03-29 23:13 ——– d—–w- c:\program files\Common Files\Real
2009-06-12 18:00 . 2009-06-12 18:00 ——– d—–w- c:\users\Robert\AppData\Roaming\TVU Networks
2009-06-12 17:58 . 2009-06-12 17:58 ——– d—–w- c:\program files\Satellite TV for PC
2009-06-10 00:25 . 2009-05-25 11:59 ——– d—–w- c:\program files\Pcsx2_0.9.4(2)
2009-06-10 00:24 . 2007-03-13 23:42 ——– d—–w- c:\program files\MySpace
2009-06-08 16:14 . 2009-06-08 16:14 ——– d—–w- c:\program files\LG Electronics
2009-06-08 16:14 . 2007-02-08 08:09 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-05 17:57 . 2009-06-05 17:57 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 15:42 . 2009-06-05 15:42 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-05 15:42 . 2009-06-05 15:42 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-06-04 21:44 . 2009-06-04 21:44 ——– d—–w- c:\program files\BitPim
2009-05-24 14:34 . 2009-05-24 14:34 ——– d—–w- c:\program files\LibUSB-Win32-0.1.10.1
2009-05-21 15:33 . 2009-01-05 11:29 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-16 12:37 . 2009-05-16 12:37 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-14 11:45 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-13 12:32 . 2009-05-13 08:00 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys
2009-05-13 12:32 . 2009-05-13 08:00 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys
2009-05-13 12:32 . 2009-05-13 08:00 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys
2009-05-13 12:32 . 2009-05-13 08:00 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll
2009-05-13 12:32 . 2009-05-13 08:00 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll
2009-05-13 12:32 . 2009-05-13 08:00 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll
2009-05-13 12:32 . 2009-05-13 08:00 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys
2009-05-13 12:32 . 2009-02-26 22:23 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll
2009-05-08 13:35 . 2008-08-14 11:57 73312 —-a-w- c:\windows\system32\drivers\adfs.sys
2009-04-23 12:43 . 2009-06-10 05:45 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 05:45 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-10 05:45 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-04-16 22:16 . 2007-04-18 02:01 7592 —-a-w- c:\users\Robert\AppData\Local\d3d9caps.dat
2009-04-01 02:47 . 2009-02-26 23:44 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2007-02-08 15:54 . 2007-02-08 15:54 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-02 4608]
"SRS Audio Sandbox"="c:\program files\SRS Labs\Audio Sandbox\SRSSSC.exe" [2007-09-08 3153920]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544]
"Advanced Woman Calendar"="c:\program files\Advanced Woman Calendar\WomanCalendar.exe" [2009-05-23 1503232]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-27 1540096]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2006-11-17 17920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-10-13 184320]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544]
"PreSonusUSBInstallApp"="c:\program files\AudioBox USB\InstPresonusUSBDrv.exe" [2008-03-07 28672]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-12 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-01-12 303104]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-2-8 50688]
QuickSet.lnk - c:\windows\Installer\{53A01CC6-14B0-4512-A2E7-10D39BF83DC4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-2-8 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DC710089-7342-417F-A0FA-EA1011418106}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{8405E45A-A992-480B-91C3-BDCC3100CC25}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{6F84580A-2584-434F-8547-37BE87270674}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4B3691E0-8E97-479D-B685-16C91E95CBE8}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{6532F09B-8FC9-40BA-8690-D94EBB1ACBDD}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"TCP Query User{176AF534-1FED-46AF-9AF6-1F2D17C4034B}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{D94FA29A-0081-455B-AAA5-77B189ACE72C}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{C6222461-1E4D-48BC-9426-06A3D575611A}"= UDP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"{26E34F77-6589-480B-8314-2F0FF6F3B35C}"= TCP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"{4F357201-4322-4748-A572-57E518BC2692}"= UDP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP)
"{33C59A06-EAA6-4B06-A8A8-A02AFB6C0450}"= TCP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP)
"TCP Query User{972126A1-FFB1-40AA-A487-EDB57C69F396}c:\\stubinstaller.exe"= UDP:C:\stubinstaller.exe:LimeWire swarmed installer
"UDP Query User{08FE4F19-82BE-41A1-981B-A6E200035140}c:\\stubinstaller.exe"= TCP:C:\stubinstaller.exe:LimeWire swarmed installer
"{39626CD8-ADEE-4ED5-A522-B8BE4367839E}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{36E3D7E5-3AC9-452B-995F-E431754D9694}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{50774B62-755F-426B-BA2A-02367C248FD8}c:\\program files\\america's army\\system\\armyops.exe"= UDP:c:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{699E8109-8EC9-45D5-B124-78D4CECC6789}c:\\program files\\america's army\\system\\armyops.exe"= TCP:c:\program files\america's army\system\armyops.exe:ArmyOps
"TCP Query User{7F12EB81-973C-42BE-B20C-8AD6CBEDE1CD}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{C99F839B-F361-48CE-8ED4-1B05B0427AB4}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"TCP Query User{11CAFF35-683B-4264-A107-0CD434DBF06B}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= UDP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"UDP Query User{9CD00152-8430-4809-9267-A35C2A4457BA}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= TCP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"{0E737215-4FCF-4A34-B3F5-12AD135DD972}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{1B111988-17EE-43ED-B972-5517B49E42DB}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{41BE85E8-EA12-4202-8761-0D4796BB177B}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{F5CF6DEF-A246-43FF-8F3C-6BE0235F11B2}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"TCP Query User{E2C7BFD9-15E5-4E1C-8224-D3584D59088C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{9C831B6D-4CB2-454F-9089-3AF58DBD4AC3}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{DBD29491-FF3D-43F9-90ED-44CC95386DCD}c:\\program files\\quicktime\\quicktimeplayer.exe"= UDP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application
"UDP Query User{A380A176-6079-43CB-A92E-32FCEEA9BEC7}c:\\program files\\quicktime\\quicktimeplayer.exe"= TCP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application
"TCP Query User{3AC313D9-B6B3-495C-8C13-500BB0EA49C7}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= UDP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe
"UDP Query User{1982024B-D1E4-4F70-839F-6635AD27A497}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= TCP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe
"TCP Query User{C05E66C8-281F-45E7-B14E-CF88DD3147B8}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:UDP:c:\program files\microsoft games\halo\halo.exe:Halo
"UDP Query User{EB58509F-411D-4429-A0FD-2CD055BA3B95}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:TCP:c:\program files\microsoft games\halo\halo.exe:Halo
"{2C13D723-369B-44D5-8C32-8135E6B16B71}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas
"{B3796AEB-60D7-4DEF-BFE5-BB9171F4803A}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas
"{DB5A49BC-BDCA-4BBB-8CF1-BEBFF13098E2}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater
"{FCB7312A-3871-4FC9-821E-71988B8544AC}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater
"{30BCEC95-2E5A-4C61-8D40-C3B9FFD3823B}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{037AC626-54D7-4530-B3D8-BB570E3D8C16}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"TCP Query User{CD6EC63F-B479-473B-B94F-56C99452F37A}c:\\program files\\kuma games\\kumaclient.exe"= UDP:c:\program files\kuma games\kumaclient.exe:KumaClient
"UDP Query User{BEB615F7-77C8-4EEF-805F-444D585E6EDA}c:\\program files\\kuma games\\kumaclient.exe"= TCP:c:\program files\kuma games\kumaclient.exe:KumaClient
"{5D1DEC78-A955-4D8A-8296-811BDF1617A0}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{DF77B589-E554-4ADC-8108-874E486BA6C6}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"TCP Query User{0C521428-3F98-4271-B54D-F6B44CF3EC49}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{6CCA7FD4-2B5B-49EB-9341-1CEACD116E8F}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"TCP Query User{0DF51FA7-6AFB-4AB0-8E51-D9A5546224D3}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= UDP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe
"UDP Query User{11D209CA-9190-4F46-8CFA-15933A36E47C}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= TCP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe
"TCP Query User{0AB1783F-77DA-428F-A04E-8190DB0A0AF7}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:utorrent
"UDP Query User{9D214FD0-B98C-47D1-8CA6-FD35255964A0}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:utorrent
"TCP Query User{50942DBF-744F-4A91-8D9B-AAF9E80C6482}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{2D2ED0DB-41F5-4E5D-9F7E-A25BC637E633}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"TCP Query User{BE578BD9-8465-4D6C-9104-D8731100F238}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:UDP:c:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{DCE00D38-E3F7-4059-AA29-0CCB1171B992}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:TCP:c:\program files\america's army\system\armyops.exe:ArmyOps
"{80CBB081-7B44-4297-BC34-684ECB632924}"= Disabled:UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11
"{D2F76F1D-9440-4DF7-AB3E-1631127E3FE9}"= Disabled:TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11
"{BA6434C4-DCAC-4FF5-82D9-D7445E776408}"= UDP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service
"{CB372408-8C36-4775-B0F0-DF0AE2280357}"= TCP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service
"{F7236639-1ECF-4334-8244-2138D2278732}"= UDP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service
"{EFFBAA4E-D072-49BD-B58B-B586E631F96B}"= TCP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service
"{34B5A9D7-4FFB-4581-AC04-B5508393A17B}"= UDP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service
"{4F730A66-4CEC-44A0-9025-6E32E7CF3626}"= TCP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service
"{6C52A495-FE39-42B0-8F73-8DEA79E5C6B4}"= UDP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface
"{AEDB5741-E4CE-4DB3-8BE5-F9B07B64DB14}"= TCP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface
"{A0A1FD56-A36B-443B-B6B4-45F537345010}"= UDP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service
"{DBCD57CA-719A-45A7-9E5B-12CE6E6FA46D}"= TCP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service
"{331A8417-C522-4DC1-A96D-99C6B0B2414F}"= Disabled:TCP:5353:LocalSubnet:LocalSubnet:mDNS-SD/Bonjour
"{F94507A9-E86D-4B26-A05D-98640DE4B435}"= Disabled:UDP:7288:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7288
"{300E4533-FBD2-44B3-BED6-E656FF52E20D}"= Disabled:UDP:7289:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7289
"{E6D88E95-3619-4618-ACDC-C6E570999B10}"= Disabled:UDP:7290:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7290
"{6A9EF052-1FC4-4048-9A0C-D71CF0A91DD5}"= Disabled:UDP:7291:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7291
"{2EC834E0-A318-4E7A-934D-DCE7F99AAEE3}"= Disabled:UDP:7292:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7292
"{F0C2ADCD-027F-4F83-ABCD-DED4E6998E14}"= Disabled:UDP:7293:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7293
"{C788FA07-7765-438F-816D-BBC57A7AD7CA}"= Disabled:UDP:7294:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7294
"{0DE58F16-EF68-4037-9D81-9E8D332C4B40}"= Disabled:UDP:7295:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7295
"{618D88A4-B71A-4619-BD24-7A172B16BBA2}"= Disabled:UDP:7296:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7296
"{3B684CB2-6380-4B11-9DAA-203686A7F59D}"= Disabled:UDP:7297:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7297
"TCP Query User{A87CEF39-79F4-495B-8107-2669E9317E71}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{C0BCEEE4-5CBC-45C4-9A2A-9252EA89B6D7}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{4AA631F1-8A10-43E2-9AF2-50D523F7D8A6}"= Disabled:UDP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{BDB164A7-08E7-4FA3-9D14-411918B25E43}"= Disabled:TCP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"TCP Query User{5047A0F9-65E8-4010-8166-8989AFB9EA7F}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{B8039892-6D92-4996-97E1-DB2E32B9868D}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{C0B7971A-92C6-49CF-A26F-4CBF0E92884B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{D11DFF62-E2DF-493F-AA1A-9D220AA03955}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{51757B52-543D-4D42-8D03-3396B16501C9}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4A5BF50F-E211-4466-B638-2CFDFED791D1}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{2AFD8F0A-EDC7-4EE6-9448-5B1ACF10122F}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™
"{DEF7D8E2-E21B-4CB6-8115-9C934F821867}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™
"{D6F2FD21-59B8-4910-97E1-408F11257E50}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™
"{04F7FCF0-DE92-40FB-B775-20035D39BC7B}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™
"TCP Query User{B6388C41-AF36-4F37-A349-A603E91640B9}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:UDP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"UDP Query User{2A133730-1F9C-4727-97CF-AFB8FCF73C83}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:TCP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"{C9D98063-9DE5-4EDD-8E0B-603BCDA3233E}"= UDP:5353:Adobe CSI CS4
"{80F6A506-94F0-4270-8C5F-44268DC3201D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{A8FDCCFA-B108-4263-9641-B5DEA85D487C}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{0D423FB4-7220-4832-847B-0E85A9DD15AF}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A1422C01-5FDB-4506-A2CB-3B046706FC5A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{29EE3451-05EE-47AF-8947-99DD5BFC854B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{F87D848E-3DA4-403D-BDDB-CFDE631A1128}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{10B415ED-2A06-4C2F-9380-57B542D4FD1A}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{3000B06D-2401-4D80-8E9F-6CE6751BEB6F}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{BF7203B0-6B85-434C-9FCD-6188A11831B7}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090709.001\IDSvix86.sys [7/10/2009 6:43 PM 272432]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe –> system32\libusbd-nt.exe [?]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 3:37 PM 149352]
R2 musm3gld;musm3gld;c:\windows\System32\drivers\musm3gld.sys [2/10/2008 9:30 AM 5513]
R2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe [3/21/2007 5:25 PM 548488]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/28/2007 6:59 PM 24652]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [3/30/2009 4:28 PM 1533808]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/10/2009 2:33 AM 101936]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\System32\drivers\libusb0.sys [5/24/2009 10:34 AM 33792]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 12:31 PM 41008]
S2 gupdate1c9eba4d5aabe4e;Google Update Service (gupdate1c9eba4d5aabe4e);c:\program files\Google\Update\GoogleUpdate.exe [6/12/2009 5:29 PM 133104]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [1/12/2008 10:32 PM 23888]
S3 ControlTransferDriver;AudioBox USB Control Transfer;c:\windows\System32\drivers\PreSonusUSB_xfer.sys [1/8/2009 5:10 PM 28576]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [7/12/2009 2:23 AM 38160]
S3 SynasUSB;SynasUSB;c:\windows\System32\drivers\synasUSB.sys [1/9/2009 10:17 AM 18432]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28]

2009-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28]

2009-07-12 c:\windows\Tasks\User_Feed_Synchronization-{16669BE4-D9F0-4EB3-8A0B-146FE0D8BE1D}.job
- c:\windows\system32\msfeedssync.exe [2009-07-02 11:31]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKCU-Run-P2kAutostart - (no file)
HKCU-Run-AdobeBridge - (no file)
HKCU-Run-Aim6 - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5070208
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\27qgbx4k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-12 18:54
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1592213791-1963367186-16139517-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:53,fe,7b,56,c5,f3,53,2f,cb,43,99,d8,dc,b0,76,63,da,43,e4,78,9c,22,74,
65,66,11,21,59,75,a0,7a,b8,5b,6d,92,2f,eb,99,16,84,3c,9d,26,7f,19,ab,56,43,\
"??"=hex:92,46,0e,fe,89,48,9d,d8,a5,2f,6e,0c,51,93,50,80

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(3300)
c:\windows\System32\NLSData0009.dll
c:\windows\system32\wpdshserviceobj.dll
c:\program files\Roxio\Drag-to-Disc\Shellex.dll
c:\windows\system32\DLAAPI_W.DLL
c:\program files\Roxio\Drag-to-Disc\ShellRes.dll
c:\program files\Dell\MediaDirect\Kernel\Video\CLM1Splter.ax
c:\program files\Common Files\Sonic Shared\SonicMC01\sonicMP4Demux.ax
c:\program files\Common Files\Ahead\DSFilter\NeFLVSplitter.ax
c:\program files\Real Alternative\RealMediaSplitter.ax
c:\program files\Common Files\Ahead\DSFilter\NeMP4Splitter.ax
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\BCMWLTRY.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\Crypserv.exe
c:\windows\System32\libusbd-nt.exe
c:\program files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
.
**************************************************************************
.
Completion time: 2009-07-12 19:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-12 23:04

Pre-Run: 4,481,064,960 bytes free
Post-Run: 4,134,375,424 bytes free

480 — E O F — 2009-07-06 23:26
I completed combo fix with my cell phone disconnected bc it died and with my harddrive disconnected bc that it what i back up all of my photos to.
Hey Adam. My laptop is running much faster. When firefox opens i no longer recieve the error message in reference to global root. Windows defender has not given me an error message yet. I am not definite of this virus stuff so I am waiting for confirmation of success from you before i resume my normal pc activity. Once again thank you.
Nope, it's not clean yet.

Run ComboFix

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=-
RegNull::
[HKEY_USERS\S-1-5-21-1592213791-1963367186-16139517-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
RegLock::
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Uninstall Bad Programs
We are going to uninstall some bad stuff now.
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if found):

    J2SE Runtime Environment 5.0 Update 4
    Java™ 6 Update 6
    Java™ 6 Update 7
    Java™ SE Runtime Environment 6

Now you can close Add/Remove Programs.

Update your Adobe Reader
Your version of Adobe Reader is old and may contain security leaks. Please first uninstall the older version, then download and install the newest version from here.

Kaspersky Online Scanner
Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply, please include:
  • ComboFix log
  • Kaspersky report
  • A new HijackThis log

Regards,
Adam
Log creating after running combofix:

ComboFix 09-07-12.03 - Robert 07/13/2009 4:05.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1022.322 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-06-13 to 2009-07-13 )))))))))))))))))))))))))))))))
.

2009-07-13 08:14 . 2009-07-13 08:14 ——– d—–w- c:\users\Robert\AppData\Local\temp
2009-07-13 07:59 . 2009-07-13 08:03 ——– d-s—w- C:\ComboFix
2009-07-13 03:07 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\NAVENG.SYS
2009-07-13 03:07 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\NAVEX15.SYS
2009-07-13 03:07 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\NAVENG32.DLL
2009-07-13 03:07 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\NAVEX32A.DLL
2009-07-13 03:07 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\EECTRL.SYS
2009-07-13 03:07 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\ECMSVR32.DLL
2009-07-13 03:07 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\CCERASER.DLL
2009-07-13 03:07 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\ERASER.SYS
2009-07-13 02:48 . 2009-07-13 02:48 ——– d—–w- c:\program files\AskBarDis
2009-07-13 02:46 . 2009-07-13 07:57 ——– d—–w- c:\users\Robert\AppData\Roaming\uTorrent
2009-07-12 18:17 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVENG.SYS
2009-07-12 18:17 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVEX15.SYS
2009-07-12 18:17 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\EECTRL.SYS
2009-07-12 18:17 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\ECMSVR32.DLL
2009-07-12 18:17 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\CCERASER.DLL
2009-07-12 18:17 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVENG32.DLL
2009-07-12 18:17 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVEX32A.DLL
2009-07-12 18:17 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\ERASER.SYS
2009-07-12 08:26 . 2009-07-12 08:26 ——– d—–w- C:\_OTM
2009-07-12 07:25 . 2009-07-12 07:26 ——– d—–w- C:\rsit
2009-07-12 06:26 . 2009-07-12 06:26 ——– d—–w- c:\users\Robert\AppData\Roaming\Malwarebytes
2009-07-12 06:23 . 2009-06-17 15:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-12 06:23 . 2009-07-12 06:23 ——– d—–w- c:\programdata\Malwarebytes
2009-07-12 06:23 . 2009-06-17 15:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 06:23 . 2009-07-12 06:26 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-12 01:16 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX32A.DLL
2009-07-12 01:16 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG.SYS
2009-07-12 01:16 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX15.SYS
2009-07-12 01:16 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\EECTRL.SYS
2009-07-12 01:16 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ECMSVR32.DLL
2009-07-12 01:16 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\CCERASER.DLL
2009-07-12 01:16 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG32.DLL
2009-07-12 01:16 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ERASER.SYS
2009-07-11 07:09 . 2009-07-12 21:32 ——– d—–w- c:\program files\Trend Micro
2009-07-10 22:43 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\Scxpx86.dll
2009-07-10 22:43 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSvix86.sys
2009-07-10 22:43 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSco.sys
2009-07-10 22:43 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSxpx86.dll
2009-07-10 22:43 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSI.dll
2009-07-10 22:43 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSviA64.sys
2009-07-10 22:43 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDS9xx86.dll
2009-07-10 15:27 . 2009-07-13 00:59 ——– d—–w- c:\windows\.jagex_cache_32
2009-07-09 05:17 . 2009-07-09 05:31 ——– d—–w- c:\program files\MasterWriter 2.0
2009-07-07 19:38 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\Scxpx86.dll
2009-07-07 19:38 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSvix86.sys
2009-07-07 19:38 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\SymIDSco.sys
2009-07-07 19:38 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSxpx86.dll
2009-07-07 19:38 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\SymIDSI.dll
2009-07-07 19:38 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSviA64.sys
2009-07-07 19:38 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDS9xx86.dll
2009-07-07 00:25 . 2009-07-07 00:25 ——– d—–w- c:\users\Robert\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150040}
2009-07-02 12:25 . 2009-07-11 06:20 ——– d—–w- c:\users\Robert\Tracing
2009-07-02 07:30 . 2009-07-02 07:30 ——– d—–w- c:\program files\Microsoft Office Outlook Connector
2009-07-02 07:25 . 2009-07-02 07:25 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2009-07-02 07:21 . 2009-07-02 07:21 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-02 07:21 . 2009-07-11 06:39 ——– d—–w- c:\program files\Windows Live
2009-07-02 06:33 . 2009-05-09 05:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-02 06:33 . 2009-05-09 05:50 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-28 04:05 . 2009-06-28 04:05 ——– d—–w- c:\users\Robert\AppData\Roaming\QQ Games Plugin
2009-06-28 04:03 . 2009-06-28 04:08 ——– d—–w- c:\programdata\Tencent
2009-06-28 04:03 . 2009-06-28 04:03 ——– d—–w- c:\program files\Tencent
2009-06-28 04:00 . 2009-06-28 04:00 5946704 —-a-w- c:\programdata\AOL Downloads\aimqqgames\QQSetup65.exe
2009-06-28 03:59 . 2009-06-28 03:59 1144808 —-a-w- c:\programdata\AOL Downloads\aimtunes\AIMTunes.exe
2009-06-28 03:58 . 2009-06-28 03:58 ——– d—–w- c:\programdata\acccore
2009-06-28 03:56 . 2009-06-28 04:04 ——– d—–w- c:\program files\AIM6
2009-06-27 05:42 . 2009-06-27 05:42 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-06-26 19:22 . 2009-06-26 19:22 ——– d—–w- c:\users\Robert\New Folder
2009-06-26 10:22 . 2009-06-26 10:29 ——– d—–w- c:\program files\4WomenOnly
2009-06-26 10:17 . 2009-06-26 10:17 ——– d—–w- c:\program files\Advanced Woman Calendar
2009-06-26 01:40 . 2009-06-26 01:40 ——– d—–w- c:\users\Robert\AppData\Roaming\SoftOrbits
2009-06-23 15:20 . 2009-06-23 15:20 ——– d—–w- c:\users\Robert\AppData\Local\SourceTec
2009-06-20 01:10 . 2009-06-20 01:11 ——– d—–w- c:\users\Robert\AppData\Local\Deployment
2009-06-14 00:07 . 2009-04-30 12:37 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 00:07 . 2009-04-30 12:37 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-13 16:45 . 2009-03-19 20:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-13 16:45 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iPod
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iTunes
2009-06-13 16:39 . 2009-06-13 16:40 ——– d—–w- c:\program files\QuickTime
2009-06-13 16:31 . 2009-06-13 16:32 ——– d—–w- c:\program files\Apple Software Update
2009-06-13 16:28 . 2009-06-13 16:44 ——– d—–w- c:\program files\Common Files\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-12 22:50 . 2007-11-14 23:57 12 —-a-w- c:\windows\bthservsdp.dat
2009-07-11 06:24 . 2007-08-11 03:20 ——– d—–w- c:\program files\The Rosetta Stone
2009-07-11 06:23 . 2007-02-08 08:26 ——– d—–w- c:\program files\Google
2009-07-10 02:19 . 2007-03-13 01:49 115728 —-a-w- c:\users\Robert\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-07 00:31 . 2007-02-08 08:09 ——– d—–w- c:\program files\Java
2009-07-02 07:22 . 2009-01-23 16:32 ——– d—–w- c:\program files\Microsoft
2009-06-28 04:00 . 2007-03-13 23:38 ——– d—–w- c:\programdata\AOL Downloads
2009-06-28 03:58 . 2007-06-08 13:46 ——– d—–w- c:\programdata\Viewpoint
2009-06-28 03:57 . 2007-03-13 23:40 ——– d—–w- c:\program files\Common Files\AOL
2009-06-28 03:52 . 2007-03-13 23:40 ——– d—–w- c:\programdata\AOL
2009-06-13 17:11 . 2007-10-29 23:11 ——– d—–w- c:\users\Robert\AppData\Roaming\Apple Computer
2009-06-13 16:41 . 2008-02-21 01:51 ——– d—–w- c:\program files\Bonjour
2009-06-12 21:34 . 2009-06-12 21:34 ——– d—–w- c:\program files\Common Files\xing shared
2009-06-12 21:33 . 2009-03-29 23:13 ——– d—–w- c:\program files\Common Files\Real
2009-06-12 18:00 . 2009-06-12 18:00 ——– d—–w- c:\users\Robert\AppData\Roaming\TVU Networks
2009-06-12 17:58 . 2009-06-12 17:58 ——– d—–w- c:\program files\Satellite TV for PC
2009-06-10 00:25 . 2009-05-25 11:59 ——– d—–w- c:\program files\Pcsx2_0.9.4(2)
2009-06-10 00:24 . 2007-03-13 23:42 ——– d—–w- c:\program files\MySpace
2009-06-08 16:14 . 2009-06-08 16:14 ——– d—–w- c:\program files\LG Electronics
2009-06-08 16:14 . 2007-02-08 08:09 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-05 17:57 . 2009-06-05 17:57 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 15:42 . 2009-06-05 15:42 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-05 15:42 . 2009-06-05 15:42 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-06-04 21:44 . 2009-06-04 21:44 ——– d—–w- c:\program files\BitPim
2009-05-24 14:34 . 2009-05-24 14:34 ——– d—–w- c:\program files\LibUSB-Win32-0.1.10.1
2009-05-21 15:33 . 2009-01-05 11:29 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-16 12:37 . 2009-05-16 12:37 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-14 11:45 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-13 12:32 . 2009-05-13 08:00 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys
2009-05-13 12:32 . 2009-05-13 08:00 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys
2009-05-13 12:32 . 2009-05-13 08:00 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys
2009-05-13 12:32 . 2009-05-13 08:00 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll
2009-05-13 12:32 . 2009-05-13 08:00 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll
2009-05-13 12:32 . 2009-05-13 08:00 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll
2009-05-13 12:32 . 2009-05-13 08:00 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys
2009-05-13 12:32 . 2009-02-26 22:23 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll
2009-05-08 13:35 . 2008-08-14 11:57 73312 —-a-w- c:\windows\system32\drivers\adfs.sys
2009-04-23 12:43 . 2009-06-10 05:45 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 05:45 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-10 05:45 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-04-16 22:16 . 2007-04-18 02:01 7592 —-a-w- c:\users\Robert\AppData\Local\d3d9caps.dat
2009-04-01 02:47 . 2009-02-26 23:44 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2007-02-08 15:54 . 2007-02-08 15:54 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-07-12_22.54.55 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-03-13 02:44 . 2009-07-12 22:52 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-03-13 02:44 . 2009-07-13 07:15 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-03-13 02:44 . 2009-07-13 07:15 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-03-13 02:44 . 2009-07-12 22:52 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-03-13 02:44 . 2009-07-13 07:15 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-03-13 02:44 . 2009-07-12 22:52 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 16:47 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-02 4608]
"SRS Audio Sandbox"="c:\program files\SRS Labs\Audio Sandbox\SRSSSC.exe" [2007-09-08 3153920]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544]
"Advanced Woman Calendar"="c:\program files\Advanced Woman Calendar\WomanCalendar.exe" [2009-05-23 1503232]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-27 1540096]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2006-11-17 17920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-10-13 184320]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544]
"PreSonusUSBInstallApp"="c:\program files\AudioBox USB\InstPresonusUSBDrv.exe" [2008-03-07 28672]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-12 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-01-12 303104]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-2-8 50688]
QuickSet.lnk - c:\windows\Installer\{53A01CC6-14B0-4512-A2E7-10D39BF83DC4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-2-8 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DC710089-7342-417F-A0FA-EA1011418106}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{8405E45A-A992-480B-91C3-BDCC3100CC25}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{6F84580A-2584-434F-8547-37BE87270674}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4B3691E0-8E97-479D-B685-16C91E95CBE8}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{6532F09B-8FC9-40BA-8690-D94EBB1ACBDD}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"TCP Query User{176AF534-1FED-46AF-9AF6-1F2D17C4034B}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{D94FA29A-0081-455B-AAA5-77B189ACE72C}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{C6222461-1E4D-48BC-9426-06A3D575611A}"= UDP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"{26E34F77-6589-480B-8314-2F0FF6F3B35C}"= TCP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"{4F357201-4322-4748-A572-57E518BC2692}"= UDP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP)
"{33C59A06-EAA6-4B06-A8A8-A02AFB6C0450}"= TCP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP)
"TCP Query User{972126A1-FFB1-40AA-A487-EDB57C69F396}c:\\stubinstaller.exe"= UDP:C:\stubinstaller.exe:LimeWire swarmed installer
"UDP Query User{08FE4F19-82BE-41A1-981B-A6E200035140}c:\\stubinstaller.exe"= TCP:C:\stubinstaller.exe:LimeWire swarmed installer
"{39626CD8-ADEE-4ED5-A522-B8BE4367839E}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{36E3D7E5-3AC9-452B-995F-E431754D9694}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{50774B62-755F-426B-BA2A-02367C248FD8}c:\\program files\\america's army\\system\\armyops.exe"= UDP:c:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{699E8109-8EC9-45D5-B124-78D4CECC6789}c:\\program files\\america's army\\system\\armyops.exe"= TCP:c:\program files\america's army\system\armyops.exe:ArmyOps
"TCP Query User{7F12EB81-973C-42BE-B20C-8AD6CBEDE1CD}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{C99F839B-F361-48CE-8ED4-1B05B0427AB4}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"TCP Query User{11CAFF35-683B-4264-A107-0CD434DBF06B}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= UDP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"UDP Query User{9CD00152-8430-4809-9267-A35C2A4457BA}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= TCP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"{0E737215-4FCF-4A34-B3F5-12AD135DD972}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{1B111988-17EE-43ED-B972-5517B49E42DB}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{41BE85E8-EA12-4202-8761-0D4796BB177B}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{F5CF6DEF-A246-43FF-8F3C-6BE0235F11B2}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"TCP Query User{E2C7BFD9-15E5-4E1C-8224-D3584D59088C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{9C831B6D-4CB2-454F-9089-3AF58DBD4AC3}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{DBD29491-FF3D-43F9-90ED-44CC95386DCD}c:\\program files\\quicktime\\quicktimeplayer.exe"= UDP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application
"UDP Query User{A380A176-6079-43CB-A92E-32FCEEA9BEC7}c:\\program files\\quicktime\\quicktimeplayer.exe"= TCP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application
"TCP Query User{3AC313D9-B6B3-495C-8C13-500BB0EA49C7}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= UDP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe
"UDP Query User{1982024B-D1E4-4F70-839F-6635AD27A497}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= TCP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe
"TCP Query User{C05E66C8-281F-45E7-B14E-CF88DD3147B8}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:UDP:c:\program files\microsoft games\halo\halo.exe:Halo
"UDP Query User{EB58509F-411D-4429-A0FD-2CD055BA3B95}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:TCP:c:\program files\microsoft games\halo\halo.exe:Halo
"{2C13D723-369B-44D5-8C32-8135E6B16B71}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas
"{B3796AEB-60D7-4DEF-BFE5-BB9171F4803A}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas
"{DB5A49BC-BDCA-4BBB-8CF1-BEBFF13098E2}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater
"{FCB7312A-3871-4FC9-821E-71988B8544AC}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater
"{30BCEC95-2E5A-4C61-8D40-C3B9FFD3823B}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{037AC626-54D7-4530-B3D8-BB570E3D8C16}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"TCP Query User{CD6EC63F-B479-473B-B94F-56C99452F37A}c:\\program files\\kuma games\\kumaclient.exe"= UDP:c:\program files\kuma games\kumaclient.exe:KumaClient
"UDP Query User{BEB615F7-77C8-4EEF-805F-444D585E6EDA}c:\\program files\\kuma games\\kumaclient.exe"= TCP:c:\program files\kuma games\kumaclient.exe:KumaClient
"{5D1DEC78-A955-4D8A-8296-811BDF1617A0}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{DF77B589-E554-4ADC-8108-874E486BA6C6}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"TCP Query User{0C521428-3F98-4271-B54D-F6B44CF3EC49}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{6CCA7FD4-2B5B-49EB-9341-1CEACD116E8F}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"TCP Query User{0DF51FA7-6AFB-4AB0-8E51-D9A5546224D3}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= UDP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe
"UDP Query User{11D209CA-9190-4F46-8CFA-15933A36E47C}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= TCP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe
"TCP Query User{0AB1783F-77DA-428F-A04E-8190DB0A0AF7}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:utorrent
"UDP Query User{9D214FD0-B98C-47D1-8CA6-FD35255964A0}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:utorrent
"TCP Query User{50942DBF-744F-4A91-8D9B-AAF9E80C6482}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{2D2ED0DB-41F5-4E5D-9F7E-A25BC637E633}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"TCP Query User{BE578BD9-8465-4D6C-9104-D8731100F238}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:UDP:c:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{DCE00D38-E3F7-4059-AA29-0CCB1171B992}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:TCP:c:\program files\america's army\system\armyops.exe:ArmyOps
"{80CBB081-7B44-4297-BC34-684ECB632924}"= Disabled:UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11
"{D2F76F1D-9440-4DF7-AB3E-1631127E3FE9}"= Disabled:TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11
"{BA6434C4-DCAC-4FF5-82D9-D7445E776408}"= UDP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service
"{CB372408-8C36-4775-B0F0-DF0AE2280357}"= TCP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service
"{F7236639-1ECF-4334-8244-2138D2278732}"= UDP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service
"{EFFBAA4E-D072-49BD-B58B-B586E631F96B}"= TCP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service
"{34B5A9D7-4FFB-4581-AC04-B5508393A17B}"= UDP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service
"{4F730A66-4CEC-44A0-9025-6E32E7CF3626}"= TCP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service
"{6C52A495-FE39-42B0-8F73-8DEA79E5C6B4}"= UDP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface
"{AEDB5741-E4CE-4DB3-8BE5-F9B07B64DB14}"= TCP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface
"{A0A1FD56-A36B-443B-B6B4-45F537345010}"= UDP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service
"{DBCD57CA-719A-45A7-9E5B-12CE6E6FA46D}"= TCP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service
"{331A8417-C522-4DC1-A96D-99C6B0B2414F}"= Disabled:TCP:5353:LocalSubnet:LocalSubnet:mDNS-SD/Bonjour
"{F94507A9-E86D-4B26-A05D-98640DE4B435}"= Disabled:UDP:7288:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7288
"{300E4533-FBD2-44B3-BED6-E656FF52E20D}"= Disabled:UDP:7289:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7289
"{E6D88E95-3619-4618-ACDC-C6E570999B10}"= Disabled:UDP:7290:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7290
"{6A9EF052-1FC4-4048-9A0C-D71CF0A91DD5}"= Disabled:UDP:7291:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7291
"{2EC834E0-A318-4E7A-934D-DCE7F99AAEE3}"= Disabled:UDP:7292:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7292
"{F0C2ADCD-027F-4F83-ABCD-DED4E6998E14}"= Disabled:UDP:7293:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7293
"{C788FA07-7765-438F-816D-BBC57A7AD7CA}"= Disabled:UDP:7294:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7294
"{0DE58F16-EF68-4037-9D81-9E8D332C4B40}"= Disabled:UDP:7295:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7295
"{618D88A4-B71A-4619-BD24-7A172B16BBA2}"= Disabled:UDP:7296:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7296
"{3B684CB2-6380-4B11-9DAA-203686A7F59D}"= Disabled:UDP:7297:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7297
"TCP Query User{A87CEF39-79F4-495B-8107-2669E9317E71}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{C0BCEEE4-5CBC-45C4-9A2A-9252EA89B6D7}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{4AA631F1-8A10-43E2-9AF2-50D523F7D8A6}"= Disabled:UDP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{BDB164A7-08E7-4FA3-9D14-411918B25E43}"= Disabled:TCP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"TCP Query User{5047A0F9-65E8-4010-8166-8989AFB9EA7F}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{B8039892-6D92-4996-97E1-DB2E32B9868D}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{C0B7971A-92C6-49CF-A26F-4CBF0E92884B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{D11DFF62-E2DF-493F-AA1A-9D220AA03955}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{51757B52-543D-4D42-8D03-3396B16501C9}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4A5BF50F-E211-4466-B638-2CFDFED791D1}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{2AFD8F0A-EDC7-4EE6-9448-5B1ACF10122F}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™
"{DEF7D8E2-E21B-4CB6-8115-9C934F821867}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™
"{D6F2FD21-59B8-4910-97E1-408F11257E50}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™
"{04F7FCF0-DE92-40FB-B775-20035D39BC7B}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™
"TCP Query User{B6388C41-AF36-4F37-A349-A603E91640B9}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:UDP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"UDP Query User{2A133730-1F9C-4727-97CF-AFB8FCF73C83}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:TCP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"{C9D98063-9DE5-4EDD-8E0B-603BCDA3233E}"= UDP:5353:Adobe CSI CS4
"{80F6A506-94F0-4270-8C5F-44268DC3201D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{A8FDCCFA-B108-4263-9641-B5DEA85D487C}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{0D423FB4-7220-4832-847B-0E85A9DD15AF}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A1422C01-5FDB-4506-A2CB-3B046706FC5A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{29EE3451-05EE-47AF-8947-99DD5BFC854B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{F87D848E-3DA4-403D-BDDB-CFDE631A1128}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{10B415ED-2A06-4C2F-9380-57B542D4FD1A}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{3000B06D-2401-4D80-8E9F-6CE6751BEB6F}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{BF7203B0-6B85-434C-9FCD-6188A11831B7}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090709.001\IDSvix86.sys [7/10/2009 6:43 PM 272432]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe –> system32\libusbd-nt.exe [?]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 3:37 PM 149352]
R2 musm3gld;musm3gld;c:\windows\System32\drivers\musm3gld.sys [2/10/2008 9:30 AM 5513]
R2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe [3/21/2007 5:25 PM 548488]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/28/2007 6:59 PM 24652]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [3/30/2009 4:28 PM 1533808]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/10/2009 2:33 AM 101936]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\System32\drivers\libusb0.sys [5/24/2009 10:34 AM 33792]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 12:31 PM 41008]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [7/12/2009 10:49 PM 234888]
S2 gupdate1c9eba4d5aabe4e;Google Update Service (gupdate1c9eba4d5aabe4e);c:\program files\Google\Update\GoogleUpdate.exe [6/12/2009 5:29 PM 133104]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [1/12/2008 10:32 PM 23888]
S3 ControlTransferDriver;AudioBox USB Control Transfer;c:\windows\System32\drivers\PreSonusUSB_xfer.sys [1/8/2009 5:10 PM 28576]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [7/12/2009 2:23 AM 38160]
S3 SynasUSB;SynasUSB;c:\windows\System32\drivers\synasUSB.sys [1/9/2009 10:17 AM 18432]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28]

2009-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28]

2009-07-13 c:\windows\Tasks\User_Feed_Synchronization-{16669BE4-D9F0-4EB3-8A0B-146FE0D8BE1D}.job
- c:\windows\system32\msfeedssync.exe [2009-07-02 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5070208
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\27qgbx4k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-13 04:14
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\users\Robert\AppData\Local\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1592213791-1963367186-16139517-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:53,fe,7b,56,c5,f3,53,2f,cb,43,99,d8,dc,b0,76,63,da,43,e4,78,9c,22,74,
65,66,11,21,59,75,a0,7a,b8,5b,6d,92,2f,eb,99,16,84,3c,9d,26,7f,19,ab,56,43,\
"??"=hex:92,46,0e,fe,89,48,9d,d8,a5,2f,6e,0c,51,93,50,80

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-07-13 4:23
ComboFix-quarantined-files.txt 2009-07-13 08:22
ComboFix2.txt 2009-07-12 23:06

Pre-Run: 2,300,080,128 bytes free
Post-Run: 1,993,854,976 bytes free

448 — E O F — 2009-07-06 23:26
this is the log for the script CFScript:

ComboFix 09-07-12.03 - Robert 07/13/2009 4:31.3.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1022.200 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\users\Robert\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-06-13 to 2009-07-13 )))))))))))))))))))))))))))))))
.

2009-07-13 08:40 . 2009-07-13 08:40 ——– d—–w- c:\users\Robert\AppData\Local\temp
2009-07-13 07:59 . 2009-07-13 08:03 ——– d-s—w- C:\ComboFix
2009-07-13 03:07 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\NAVENG.SYS
2009-07-13 03:07 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\NAVEX15.SYS
2009-07-13 03:07 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\NAVENG32.DLL
2009-07-13 03:07 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\NAVEX32A.DLL
2009-07-13 03:07 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\EECTRL.SYS
2009-07-13 03:07 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\ECMSVR32.DLL
2009-07-13 03:07 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\CCERASER.DLL
2009-07-13 03:07 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.035\ERASER.SYS
2009-07-13 02:48 . 2009-07-13 02:48 ——– d—–w- c:\program files\AskBarDis
2009-07-13 02:46 . 2009-07-13 07:57 ——– d—–w- c:\users\Robert\AppData\Roaming\uTorrent
2009-07-12 18:17 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVENG.SYS
2009-07-12 18:17 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVEX15.SYS
2009-07-12 18:17 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\EECTRL.SYS
2009-07-12 18:17 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\ECMSVR32.DLL
2009-07-12 18:17 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\CCERASER.DLL
2009-07-12 18:17 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVENG32.DLL
2009-07-12 18:17 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\NAVEX32A.DLL
2009-07-12 18:17 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090712.003\ERASER.SYS
2009-07-12 08:26 . 2009-07-12 08:26 ——– d—–w- C:\_OTM
2009-07-12 07:25 . 2009-07-12 07:26 ——– d—–w- C:\rsit
2009-07-12 06:26 . 2009-07-12 06:26 ——– d—–w- c:\users\Robert\AppData\Roaming\Malwarebytes
2009-07-12 06:23 . 2009-06-17 15:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-12 06:23 . 2009-07-12 06:23 ——– d—–w- c:\programdata\Malwarebytes
2009-07-12 06:23 . 2009-06-17 15:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 06:23 . 2009-07-12 06:26 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-12 01:16 . 2009-05-13 12:32 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX32A.DLL
2009-07-12 01:16 . 2009-05-13 12:32 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG.SYS
2009-07-12 01:16 . 2009-05-13 12:32 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVEX15.SYS
2009-07-12 01:16 . 2009-05-13 12:32 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\EECTRL.SYS
2009-07-12 01:16 . 2009-05-13 12:32 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ECMSVR32.DLL
2009-07-12 01:16 . 2009-05-13 12:32 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\CCERASER.DLL
2009-07-12 01:16 . 2009-05-13 12:32 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\NAVENG32.DLL
2009-07-12 01:16 . 2009-05-13 12:32 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090711.024\ERASER.SYS
2009-07-11 07:09 . 2009-07-12 21:32 ——– d—–w- c:\program files\Trend Micro
2009-07-10 22:43 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\Scxpx86.dll
2009-07-10 22:43 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSvix86.sys
2009-07-10 22:43 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSco.sys
2009-07-10 22:43 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSxpx86.dll
2009-07-10 22:43 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\SymIDSI.dll
2009-07-10 22:43 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDSviA64.sys
2009-07-10 22:43 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090709.001\IDS9xx86.dll
2009-07-10 15:27 . 2009-07-13 00:59 ——– d—–w- c:\windows\.jagex_cache_32
2009-07-09 05:17 . 2009-07-09 05:31 ——– d—–w- c:\program files\MasterWriter 2.0
2009-07-07 19:38 . 2009-03-06 17:25 439672 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\Scxpx86.dll
2009-07-07 19:38 . 2009-02-09 22:59 272432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSvix86.sys
2009-07-07 19:38 . 2009-02-09 22:59 251768 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\SymIDSco.sys
2009-07-07 19:38 . 2009-02-09 22:59 685432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSxpx86.dll
2009-07-07 19:38 . 2009-02-09 22:59 173432 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\SymIDSI.dll
2009-07-07 19:38 . 2009-02-09 22:59 370224 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDSviA64.sys
2009-07-07 19:38 . 2009-02-06 04:55 157120 —-a-w- c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20090707.001\IDS9xx86.dll
2009-07-07 00:25 . 2009-07-07 00:25 ——– d—–w- c:\users\Robert\AppData\Local\{3248F0A6-6813-11D6-A77B-00B0D0150040}
2009-07-02 12:25 . 2009-07-11 06:20 ——– d—–w- c:\users\Robert\Tracing
2009-07-02 07:30 . 2009-07-02 07:30 ——– d—–w- c:\program files\Microsoft Office Outlook Connector
2009-07-02 07:25 . 2009-07-02 07:25 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2009-07-02 07:21 . 2009-07-02 07:21 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-02 07:21 . 2009-07-11 06:39 ——– d—–w- c:\program files\Windows Live
2009-07-02 06:33 . 2009-05-09 05:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-02 06:33 . 2009-05-09 05:50 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-28 04:05 . 2009-06-28 04:05 ——– d—–w- c:\users\Robert\AppData\Roaming\QQ Games Plugin
2009-06-28 04:03 . 2009-06-28 04:08 ——– d—–w- c:\programdata\Tencent
2009-06-28 04:03 . 2009-06-28 04:03 ——– d—–w- c:\program files\Tencent
2009-06-28 04:00 . 2009-06-28 04:00 5946704 —-a-w- c:\programdata\AOL Downloads\aimqqgames\QQSetup65.exe
2009-06-28 03:59 . 2009-06-28 03:59 1144808 —-a-w- c:\programdata\AOL Downloads\aimtunes\AIMTunes.exe
2009-06-28 03:58 . 2009-06-28 03:58 ——– d—–w- c:\programdata\acccore
2009-06-28 03:56 . 2009-06-28 04:04 ——– d—–w- c:\program files\AIM6
2009-06-27 05:42 . 2009-06-27 05:42 746744 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-06-26 19:22 . 2009-06-26 19:22 ——– d—–w- c:\users\Robert\New Folder
2009-06-26 10:22 . 2009-06-26 10:29 ——– d—–w- c:\program files\4WomenOnly
2009-06-26 10:17 . 2009-06-26 10:17 ——– d—–w- c:\program files\Advanced Woman Calendar
2009-06-26 01:40 . 2009-06-26 01:40 ——– d—–w- c:\users\Robert\AppData\Roaming\SoftOrbits
2009-06-23 15:20 . 2009-06-23 15:20 ——– d—–w- c:\users\Robert\AppData\Local\SourceTec
2009-06-20 01:10 . 2009-06-20 01:11 ——– d—–w- c:\users\Robert\AppData\Local\Deployment
2009-06-14 00:07 . 2009-04-30 12:37 428544 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 00:07 . 2009-04-30 12:37 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-13 16:45 . 2009-03-19 20:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-13 16:45 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iPod
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-13 16:44 . 2009-06-13 16:44 ——– d—–w- c:\program files\iTunes
2009-06-13 16:39 . 2009-06-13 16:40 ——– d—–w- c:\program files\QuickTime
2009-06-13 16:31 . 2009-06-13 16:32 ——– d—–w- c:\program files\Apple Software Update
2009-06-13 16:28 . 2009-06-13 16:44 ——– d—–w- c:\program files\Common Files\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-12 22:50 . 2007-11-14 23:57 12 —-a-w- c:\windows\bthservsdp.dat
2009-07-11 06:24 . 2007-08-11 03:20 ——– d—–w- c:\program files\The Rosetta Stone
2009-07-11 06:23 . 2007-02-08 08:26 ——– d—–w- c:\program files\Google
2009-07-10 02:19 . 2007-03-13 01:49 115728 —-a-w- c:\users\Robert\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-07 00:31 . 2007-02-08 08:09 ——– d—–w- c:\program files\Java
2009-07-02 07:22 . 2009-01-23 16:32 ——– d—–w- c:\program files\Microsoft
2009-06-28 04:00 . 2007-03-13 23:38 ——– d—–w- c:\programdata\AOL Downloads
2009-06-28 03:58 . 2007-06-08 13:46 ——– d—–w- c:\programdata\Viewpoint
2009-06-28 03:57 . 2007-03-13 23:40 ——– d—–w- c:\program files\Common Files\AOL
2009-06-28 03:52 . 2007-03-13 23:40 ——– d—–w- c:\programdata\AOL
2009-06-13 17:11 . 2007-10-29 23:11 ——– d—–w- c:\users\Robert\AppData\Roaming\Apple Computer
2009-06-13 16:41 . 2008-02-21 01:51 ——– d—–w- c:\program files\Bonjour
2009-06-12 21:34 . 2009-06-12 21:34 ——– d—–w- c:\program files\Common Files\xing shared
2009-06-12 21:33 . 2009-03-29 23:13 ——– d—–w- c:\program files\Common Files\Real
2009-06-12 18:00 . 2009-06-12 18:00 ——– d—–w- c:\users\Robert\AppData\Roaming\TVU Networks
2009-06-12 17:58 . 2009-06-12 17:58 ——– d—–w- c:\program files\Satellite TV for PC
2009-06-10 00:25 . 2009-05-25 11:59 ——– d—–w- c:\program files\Pcsx2_0.9.4(2)
2009-06-10 00:24 . 2007-03-13 23:42 ——– d—–w- c:\program files\MySpace
2009-06-08 16:14 . 2009-06-08 16:14 ——– d—–w- c:\program files\LG Electronics
2009-06-08 16:14 . 2007-02-08 08:09 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-05 17:57 . 2009-06-05 17:57 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 15:42 . 2009-06-05 15:42 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-05 15:42 . 2009-06-05 15:42 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-06-04 21:44 . 2009-06-04 21:44 ——– d—–w- c:\program files\BitPim
2009-05-24 14:34 . 2009-05-24 14:34 ——– d—–w- c:\program files\LibUSB-Win32-0.1.10.1
2009-05-21 15:33 . 2009-01-05 11:29 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-16 12:37 . 2009-05-16 12:37 416128 —-a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2009-05-14 11:45 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-13 12:32 . 2009-05-13 08:00 89104 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys
2009-05-13 12:32 . 2009-05-13 08:00 876144 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys
2009-05-13 12:32 . 2009-05-13 08:00 371248 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys
2009-05-13 12:32 . 2009-05-13 08:00 2414128 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll
2009-05-13 12:32 . 2009-05-13 08:00 177520 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll
2009-05-13 12:32 . 2009-05-13 08:00 1181040 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll
2009-05-13 12:32 . 2009-05-13 08:00 101936 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys
2009-05-13 12:32 . 2009-02-26 22:23 259368 —-a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ecmsvr32.dll
2009-05-08 13:35 . 2008-08-14 11:57 73312 —-a-w- c:\windows\system32\drivers\adfs.sys
2009-04-23 12:43 . 2009-06-10 05:45 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 05:45 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-10 05:45 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-04-16 22:16 . 2007-04-18 02:01 7592 —-a-w- c:\users\Robert\AppData\Local\d3d9caps.dat
2009-04-01 02:47 . 2009-02-26 23:44 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2007-02-08 15:54 . 2007-02-08 15:54 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-07-12_22.54.55 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-03-13 02:44 . 2009-07-12 22:52 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-03-13 02:44 . 2009-07-13 08:21 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-03-13 02:44 . 2009-07-13 08:21 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-03-13 02:44 . 2009-07-12 22:52 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-03-13 02:44 . 2009-07-13 08:21 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-03-13 02:44 . 2009-07-12 22:52 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 16:47 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-02 4608]
"SRS Audio Sandbox"="c:\program files\SRS Labs\Audio Sandbox\SRSSSC.exe" [2007-09-08 3153920]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544]
"Advanced Woman Calendar"="c:\program files\Advanced Woman Calendar\WomanCalendar.exe" [2009-05-23 1503232]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-27 1540096]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2006-11-17 17920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2006-10-13 184320]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 202544]
"PreSonusUSBInstallApp"="c:\program files\AudioBox USB\InstPresonusUSBDrv.exe" [2008-03-07 28672]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-12 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-01-12 303104]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-2-8 50688]
QuickSet.lnk - c:\windows\Installer\{53A01CC6-14B0-4512-A2E7-10D39BF83DC4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-2-8 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DC710089-7342-417F-A0FA-EA1011418106}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{8405E45A-A992-480B-91C3-BDCC3100CC25}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{6F84580A-2584-434F-8547-37BE87270674}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4B3691E0-8E97-479D-B685-16C91E95CBE8}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{6532F09B-8FC9-40BA-8690-D94EBB1ACBDD}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"TCP Query User{176AF534-1FED-46AF-9AF6-1F2D17C4034B}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{D94FA29A-0081-455B-AAA5-77B189ACE72C}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{C6222461-1E4D-48BC-9426-06A3D575611A}"= UDP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"{26E34F77-6589-480B-8314-2F0FF6F3B35C}"= TCP:c:\program files\Gizmo Project\Gizmo.exe:Gizmo Project
"{4F357201-4322-4748-A572-57E518BC2692}"= UDP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP)
"{33C59A06-EAA6-4B06-A8A8-A02AFB6C0450}"= TCP:c:\program files\DAP\DAP.exe:Download Accelerator Plus (DAP)
"TCP Query User{972126A1-FFB1-40AA-A487-EDB57C69F396}c:\\stubinstaller.exe"= UDP:C:\stubinstaller.exe:LimeWire swarmed installer
"UDP Query User{08FE4F19-82BE-41A1-981B-A6E200035140}c:\\stubinstaller.exe"= TCP:C:\stubinstaller.exe:LimeWire swarmed installer
"{39626CD8-ADEE-4ED5-A522-B8BE4367839E}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{36E3D7E5-3AC9-452B-995F-E431754D9694}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{50774B62-755F-426B-BA2A-02367C248FD8}c:\\program files\\america's army\\system\\armyops.exe"= UDP:c:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{699E8109-8EC9-45D5-B124-78D4CECC6789}c:\\program files\\america's army\\system\\armyops.exe"= TCP:c:\program files\america's army\system\armyops.exe:ArmyOps
"TCP Query User{7F12EB81-973C-42BE-B20C-8AD6CBEDE1CD}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{C99F839B-F361-48CE-8ED4-1B05B0427AB4}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"TCP Query User{11CAFF35-683B-4264-A107-0CD434DBF06B}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= UDP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"UDP Query User{9CD00152-8430-4809-9267-A35C2A4457BA}c:\\program files\\nero\\nero 7\\nero home\\nerohome.exe"= TCP:c:\program files\nero\nero 7\nero home\nerohome.exe:Nero Home
"{0E737215-4FCF-4A34-B3F5-12AD135DD972}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{1B111988-17EE-43ED-B972-5517B49E42DB}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{41BE85E8-EA12-4202-8761-0D4796BB177B}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{F5CF6DEF-A246-43FF-8F3C-6BE0235F11B2}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"TCP Query User{E2C7BFD9-15E5-4E1C-8224-D3584D59088C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{9C831B6D-4CB2-454F-9089-3AF58DBD4AC3}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{DBD29491-FF3D-43F9-90ED-44CC95386DCD}c:\\program files\\quicktime\\quicktimeplayer.exe"= UDP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application
"UDP Query User{A380A176-6079-43CB-A92E-32FCEEA9BEC7}c:\\program files\\quicktime\\quicktimeplayer.exe"= TCP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player Application
"TCP Query User{3AC313D9-B6B3-495C-8C13-500BB0EA49C7}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= UDP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe
"UDP Query User{1982024B-D1E4-4F70-839F-6635AD27A497}c:\\users\\robert\\appdata\\local\\temp\\emsinstall.exe"= TCP:c:\users\robert\appdata\local\temp\emsinstall.exe:emsinstall.exe
"TCP Query User{C05E66C8-281F-45E7-B14E-CF88DD3147B8}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:UDP:c:\program files\microsoft games\halo\halo.exe:Halo
"UDP Query User{EB58509F-411D-4429-A0FD-2CD055BA3B95}c:\\program files\\microsoft games\\halo\\halo.exe"= Disabled:TCP:c:\program files\microsoft games\halo\halo.exe:Halo
"{2C13D723-369B-44D5-8C32-8135E6B16B71}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas
"{B3796AEB-60D7-4DEF-BFE5-BB9171F4803A}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Game.exe:Rainbow Six Vegas
"{DB5A49BC-BDCA-4BBB-8CF1-BEBFF13098E2}"= Disabled:UDP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater
"{FCB7312A-3871-4FC9-821E-71988B8544AC}"= Disabled:TCP:c:\program files\Ubisoft\Tom Clancy's Rainbow Six Vegas\Binaries\R6Vegas_Launcher.exe:Rainbow Six Vegas Updater
"{30BCEC95-2E5A-4C61-8D40-C3B9FFD3823B}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"{037AC626-54D7-4530-B3D8-BB570E3D8C16}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe:BlueSoleilCS
"TCP Query User{CD6EC63F-B479-473B-B94F-56C99452F37A}c:\\program files\\kuma games\\kumaclient.exe"= UDP:c:\program files\kuma games\kumaclient.exe:KumaClient
"UDP Query User{BEB615F7-77C8-4EEF-805F-444D585E6EDA}c:\\program files\\kuma games\\kumaclient.exe"= TCP:c:\program files\kuma games\kumaclient.exe:KumaClient
"{5D1DEC78-A955-4D8A-8296-811BDF1617A0}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{DF77B589-E554-4ADC-8108-874E486BA6C6}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"TCP Query User{0C521428-3F98-4271-B54D-F6B44CF3EC49}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{6CCA7FD4-2B5B-49EB-9341-1CEACD116E8F}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"TCP Query User{0DF51FA7-6AFB-4AB0-8E51-D9A5546224D3}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= UDP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe
"UDP Query User{11D209CA-9190-4F46-8CFA-15933A36E47C}c:\\users\\robert\\desktop\\13056_ps3proxy_ef\\ps3proxy.exe"= TCP:c:\users\robert\desktop\13056_ps3proxy_ef\ps3proxy.exe:ps3proxy.exe
"TCP Query User{0AB1783F-77DA-428F-A04E-8190DB0A0AF7}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:utorrent
"UDP Query User{9D214FD0-B98C-47D1-8CA6-FD35255964A0}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:utorrent
"TCP Query User{50942DBF-744F-4A91-8D9B-AAF9E80C6482}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{2D2ED0DB-41F5-4E5D-9F7E-A25BC637E633}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"TCP Query User{BE578BD9-8465-4D6C-9104-D8731100F238}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:UDP:c:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{DCE00D38-E3F7-4059-AA29-0CCB1171B992}c:\\program files\\america's army\\system\\armyops.exe"= Disabled:TCP:c:\program files\america's army\system\armyops.exe:ArmyOps
"{80CBB081-7B44-4297-BC34-684ECB632924}"= Disabled:UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11
"{D2F76F1D-9440-4DF7-AB3E-1631127E3FE9}"= Disabled:TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire 4.12.11
"{BA6434C4-DCAC-4FF5-82D9-D7445E776408}"= UDP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service
"{CB372408-8C36-4775-B0F0-DF0AE2280357}"= TCP:c:\program files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe:TiVo Beacon Service
"{F7236639-1ECF-4334-8244-2138D2278732}"= UDP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service
"{EFFBAA4E-D072-49BD-B58B-B586E631F96B}"= TCP:c:\program files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe:TiVo Transfer Service
"{34B5A9D7-4FFB-4581-AC04-B5508393A17B}"= UDP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service
"{4F730A66-4CEC-44A0-9025-6E32E7CF3626}"= TCP:c:\program files\TiVo\Desktop\TiVoServer.exe:TiVo Server Service
"{6C52A495-FE39-42B0-8F73-8DEA79E5C6B4}"= UDP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface
"{AEDB5741-E4CE-4DB3-8BE5-F9B07B64DB14}"= TCP:c:\program files\TiVo\Desktop\TiVoDesktop.exe:TiVo Desktop User Interface
"{A0A1FD56-A36B-443B-B6B4-45F537345010}"= UDP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service
"{DBCD57CA-719A-45A7-9E5B-12CE6E6FA46D}"= TCP:c:\program files\TiVo\Desktop\curl.exe:TiVo Curl Service
"{331A8417-C522-4DC1-A96D-99C6B0B2414F}"= Disabled:TCP:5353:LocalSubnet:LocalSubnet:mDNS-SD/Bonjour
"{F94507A9-E86D-4B26-A05D-98640DE4B435}"= Disabled:UDP:7288:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7288
"{300E4533-FBD2-44B3-BED6-E656FF52E20D}"= Disabled:UDP:7289:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7289
"{E6D88E95-3619-4618-ACDC-C6E570999B10}"= Disabled:UDP:7290:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7290
"{6A9EF052-1FC4-4048-9A0C-D71CF0A91DD5}"= Disabled:UDP:7291:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7291
"{2EC834E0-A318-4E7A-934D-DCE7F99AAEE3}"= Disabled:UDP:7292:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7292
"{F0C2ADCD-027F-4F83-ABCD-DED4E6998E14}"= Disabled:UDP:7293:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7293
"{C788FA07-7765-438F-816D-BBC57A7AD7CA}"= Disabled:UDP:7294:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7294
"{0DE58F16-EF68-4037-9D81-9E8D332C4B40}"= Disabled:UDP:7295:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7295
"{618D88A4-B71A-4619-BD24-7A172B16BBA2}"= Disabled:UDP:7296:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7296
"{3B684CB2-6380-4B11-9DAA-203686A7F59D}"= Disabled:UDP:7297:LocalSubnet:LocalSubnet:TiVo HME Host: Port 7297
"TCP Query User{A87CEF39-79F4-495B-8107-2669E9317E71}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{C0BCEEE4-5CBC-45C4-9A2A-9252EA89B6D7}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{4AA631F1-8A10-43E2-9AF2-50D523F7D8A6}"= Disabled:UDP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{BDB164A7-08E7-4FA3-9D14-411918B25E43}"= Disabled:TCP:c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"TCP Query User{5047A0F9-65E8-4010-8166-8989AFB9EA7F}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{B8039892-6D92-4996-97E1-DB2E32B9868D}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{C0B7971A-92C6-49CF-A26F-4CBF0E92884B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{D11DFF62-E2DF-493F-AA1A-9D220AA03955}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{51757B52-543D-4D42-8D03-3396B16501C9}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4A5BF50F-E211-4466-B638-2CFDFED791D1}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{2AFD8F0A-EDC7-4EE6-9448-5B1ACF10122F}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™
"{DEF7D8E2-E21B-4CB6-8115-9C934F821867}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War™
"{D6F2FD21-59B8-4910-97E1-408F11257E50}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™
"{04F7FCF0-DE92-40FB-B775-20035D39BC7B}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War™
"TCP Query User{B6388C41-AF36-4F37-A349-A603E91640B9}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:UDP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"UDP Query User{2A133730-1F9C-4727-97CF-AFB8FCF73C83}c:\\program files\\myspace\\im\\myspaceim.exe"= Disabled:TCP:c:\program files\myspace\im\myspaceim.exe:MySpace Instant Messenger
"{C9D98063-9DE5-4EDD-8E0B-603BCDA3233E}"= UDP:5353:Adobe CSI CS4
"{80F6A506-94F0-4270-8C5F-44268DC3201D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{A8FDCCFA-B108-4263-9641-B5DEA85D487C}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{0D423FB4-7220-4832-847B-0E85A9DD15AF}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A1422C01-5FDB-4506-A2CB-3B046706FC5A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{29EE3451-05EE-47AF-8947-99DD5BFC854B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{F87D848E-3DA4-403D-BDDB-CFDE631A1128}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{10B415ED-2A06-4C2F-9380-57B542D4FD1A}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{3000B06D-2401-4D80-8E9F-6CE6751BEB6F}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{BF7203B0-6B85-434C-9FCD-6188A11831B7}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-04-02 234888]
R2 gupdate1c9eba4d5aabe4e;Google Update Service (gupdate1c9eba4d5aabe4e);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 133104]
R3 ControlTransferDriver;AudioBox USB Control Transfer;c:\windows\system32\Drivers\PreSonusUsb_xfer.sys [2008-02-18 28576]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-06-17 38160]
R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2006-11-23 18432]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090709.001\IDSvix86.sys [2009-02-09 272432]
S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;c:\windows\system32\libusbd-nt.exe [2005-03-10 18944]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
S2 musm3gld;musm3gld;c:\windows\system32\drivers\musm3gld.sys [2006-02-24 5513]
S2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe [2007-03-21 548488]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
S3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-05-13 101936]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-03-10 33792]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2009-02-19 41008]


— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28]

2009-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-12 21:28]

2009-07-13 c:\windows\Tasks\User_Feed_Synchronization-{16669BE4-D9F0-4EB3-8A0B-146FE0D8BE1D}.job
- c:\windows\system32\msfeedssync.exe [2009-07-02 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=5070208
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\27qgbx4k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-13 04:40
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(5440)
c:\windows\System32\NLSLexicons0009.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2009-07-13 4:48
ComboFix-quarantined-files.txt 2009-07-13 08:48
ComboFix2.txt 2009-07-13 08:23
ComboFix3.txt 2009-07-12 23:06

Pre-Run: 2,092,818,432 bytes free
Post-Run: 1,882,316,800 bytes free

390 — E O F — 2009-07-06 23:26
the kasperky scan was unsuccesful. Im guessing my internet timed out or something becuase it just froze in the middle of it. I came back to check it and the time had stoped and froze at 04:45:42 and the progress was at 24%.
Here is my new hijackthis log file. I will retry kaspersky online scan:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:31:16 PM, on 7/13/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\sttray.exe
C:\Program Files\AudioBox USB\InstPresonusUSBDrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Advanced Woman Calendar\WomanCalendar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Windows\Explorer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\blah.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [PreSonusUSBInstallApp] C:\Program Files\AudioBox USB\InstPresonusUSBDrv.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1noarp
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SRS Audio Sandbox] "C:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [Advanced Woman Calendar] "C:\Program Files\Advanced Woman Calendar\WomanCalendar.exe" -m
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_14.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_14.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BsHelpCS - Brother Industries Ltd. - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c9eba4d5aabe4e) (gupdate1c9eba4d5aabe4e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - C:\Windows\system32\libusbd-nt.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 11273 bytes
Try this one:

Eset Online Scanner

Please go to Eset website to perform an online scan. Please use Internet Explorer as it uses ActiveX.

  • Check (tick) this box: YES, I accept the Terms of Use.
  • Click on the Start button next to it.
  • When prompted to run ActiveX. click Yes.
  • You will be asked to install an ActiveX. Click Install.
  • Once installed, the scanner will be initialized.
  • After the scanner is initialized, click Start.
  • Uncheck (untick) Remove found threats box.
  • Check (tick) Scan unwanted applications.
  • Click on Scan.
  • It will start scanning. Please be patient.
  • Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt. Please post this log in your next reply.

Scan with Malwarebytes' Anti-Malware

  • Double click on the Malwarebytes' Anti-Malware icon on your desktop.
  • Once the program has loaded, click on the Update tab and click on Check for Updates.
  • Click on the Scanner tab.
  • Select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply.
  • If you accidently close it, the log file is saved here and will be named like this: C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

In your next reply, please include:
  • ESET log
  • MBAM log
  • A new HijackThis log

Regards,
Adam
This post is to notify you that I am still here i just got home so I am going to begin the scan momentarily. Thank you Adam.
Eset Online Scan was succesfully completed and here is the log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.5886 # api_version=3.0.2 # EOSSerial=25622d6ee448cd45b77c2814b13099c1 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-07-17 03:55:35 # local_time=2009-07-17 11:55:35 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=6.0.6001 NT Service Pack 1 # compatibility_mode=5889 61 66 100 471178164978357 # scanned=349923 # found=5 # cleaned=0 # scan_time=8656 C:\Qoobox\Quarantine\C\Windows\System32\drivers\MSIVXccwovvpmhwivumyloxvkhuptardqedmw.sys.vir Win32/TrojanClicker.Agent.NGF trojan 00000000000000000000000000000000 I F:\Program\FL Studio XXL Producer Edition v8.0.0 [TSRh Crack][h33t][matt14]\flstudio_8.0_install.exe probably a variant of Win32/Delf trojan 00000000000000000000000000000000 I F:\Program\My Plugins\AudioRealism BassLine VSTi v2.1.0 Incl.Keygen - AiR\Setup.exe probably a variant of Win32/TrojanDropper.Agent trojan 00000000000000000000000000000000 I F:\Program\My Plugins\Sonalksis.All.Plugins.Bundle.VST.DX.RTAS.v2.04.Incl.Keygen-AiR\Keygen.exe probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I F:\Program\Nero 7\Nero-7.8.5.0_eng_trial.exe Win32/Toolbar.AskSBar application 00000000000000000000000000000000 I
When mbam was finished the log came up and it indicated to me that the needs to be reseted to finish and i remebered that in your post it said that it would save a backup log so i didnt save it…but it didnt make a back up log or i guess i cant find it. I remember some of it though: It said that there were 2 files infected. one being the rootkit which was in the qoobox folder and the other was like a rogue trace its location was in win32, the specifics idk sorry for the inconvenience i should have still saved it

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI