combo-fix:
ComboFix 09-07-22.01 - mw 23/07/2009 22:34.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.3070.1775 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\users\mw\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
file zipped: c:\users\mw\AppData\Roaming\License.v.10.31.exe
file zipped: c:\users\user\AppData\Roaming\License.v.10.31.exe
file zipped: c:\windows\system32\Socks.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\mw\AppData\Roaming\License.v.10.31.exe
c:\users\user\AppData\Roaming\License.v.10.31.exe
c:\windows\system32\Socks.exe
.
((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 )))))))))))))))))))))))))))))))
.
2009-07-23 21:36 . 2009-07-23 21:36 ——– d—–w- c:\users\user\AppData\Local\temp
2009-07-23 21:36 . 2009-07-23 21:36 ——– d—–w- c:\users\Mrs Boss\AppData\Local\temp
2009-07-22 19:30 . 2009-07-22 19:30 ——– d—–w- c:\users\mw\AppData\Local\Apple Computer
2009-07-22 19:26 . 2009-07-22 19:26 ——– d—–w- c:\users\mw\AppData\Local\Adobe
2009-07-22 12:49 . 2009-06-15 15:24 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-07-22 12:49 . 2009-06-15 15:20 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-07-22 12:49 . 2009-06-15 15:20 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-07-22 12:49 . 2009-06-15 12:52 289792 —-a-w- c:\windows\system32\atmfd.dll
2009-07-22 10:12 . 2009-07-22 10:12 ——– d—–w- c:\program files\ERUNT
2009-07-22 07:48 . 2009-07-22 07:48 ——– d—–w- c:\progra~2\Simply Super Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-23 21:36 . 2008-06-26 19:19 ——– d—–w- c:\progra~2\Kontiki
2009-07-23 21:34 . 2008-04-06 16:16 ——– d—–w- c:\users\mw\AppData\Roaming\DNA
2009-07-23 18:59 . 2008-11-04 17:45 1 —-a-w- c:\users\mw\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-23 07:15 . 2008-11-04 17:32 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-23 06:55 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-07-22 07:22 . 2008-07-04 21:32 ——– d—–w- c:\progra~2\avg8
2009-07-21 19:14 . 2008-04-09 21:12 ——– d—–w- c:\progra~2\Apple Computer
2009-07-21 19:11 . 2008-04-06 16:16 ——– d—–w- c:\users\mw\AppData\Roaming\BitTorrent
2009-07-21 18:59 . 2009-02-01 12:33 ——– d—–w- c:\program files\QuickTime
2009-07-21 17:16 . 2009-03-04 22:22 ——– d—–w- c:\users\mw\AppData\Roaming\Spotify
2009-07-17 10:41 . 2008-07-04 21:33 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-27 07:59 . 2008-07-04 21:33 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-27 07:59 . 2008-04-06 21:00 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-02 16:05 . 2009-06-02 16:05 ——– d—–w- c:\program files\jZip
2009-05-12 08:38 . 2009-02-05 12:27 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-09 05:50 . 2009-06-15 07:15 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-15 07:15 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-04-30 12:37 . 2009-06-15 07:16 293376 —-a-w- c:\windows\system32\psisdecd.dll
2009-04-30 12:37 . 2009-06-15 07:16 428544 —-a-w- c:\windows\system32\EncDec.dll
2008-04-06 20:59 . 2008-04-06 20:38 35960792 —-a-w- c:\program files\avg75free_519a1276.exe
2008-04-06 16:16 . 2008-04-06 16:16 874448 —-a-w- c:\program files\BitTorrent-6.0.3.exe
2009-07-22 09:34 . 2008-07-12 10:35 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-22_21.55.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-22 12:49 . 2009-06-15 14:58 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 14:58 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 14:58 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 12:45 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\atmlib.dll
+ 2009-07-22 12:49 . 2009-06-15 14:52 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 14:52 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 14:51 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\dciman32.dll
+ 2009-07-22 12:49 . 2009-04-11 06:28 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\atmlib.dll
+ 2009-07-22 12:49 . 2009-06-15 15:22 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 15:20 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 15:19 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 15:19 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\atmlib.dll
+ 2009-07-22 12:49 . 2009-06-15 15:20 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 15:20 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 15:04 24064 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 15:03 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 15:02 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 15:02 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\atmlib.dll
+ 2009-07-22 12:49 . 2009-06-15 15:23 24064 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\lpk.dll
+ 2009-07-22 12:49 . 2009-06-15 15:22 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\fontsub.dll
+ 2009-07-22 12:49 . 2009-06-15 15:21 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\dciman32.dll
+ 2009-07-22 12:49 . 2009-06-15 15:20 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\atmlib.dll
+ 2008-04-05 14:52 . 2009-07-23 12:41 51366 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-07-23 12:41 74194 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-05 13:09 . 2009-07-23 07:18 15562 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4018408940-227347569-2150742145-1001_UserData.bin
+ 2008-04-05 11:59 . 2009-07-23 18:26 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-05 11:59 . 2009-07-22 21:55 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-05 11:59 . 2009-07-22 21:55 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-05 11:59 . 2009-07-23 18:26 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-05 11:59 . 2009-07-22 21:55 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-05 11:59 . 2009-07-23 18:26 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-23 12:34 . 2009-07-23 12:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-07-23 12:34 . 2009-07-23 12:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-22 12:49 . 2009-06-30 11:31 101376 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.22895_none_8405f92d60197b7e\iecompat.dll
+ 2009-07-22 12:49 . 2009-06-30 03:37 101376 c:\windows\winsxs\x86_microsoft-windows-ie-iecompat_31bf3856ad364e35_8.0.6001.18805_none_83ddad9446b2dd62\iecompat.dll
+ 2009-07-22 12:49 . 2009-06-15 12:45 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 12:42 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 12:56 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 12:52 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 12:53 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 13:03 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\atmfd.dll
+ 2009-07-22 12:49 . 2009-06-15 15:00 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6002.22152_none_b7fc28a4355e72c9\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 14:53 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6002.18051_none_b7718b8f1c41b9a8\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 15:26 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6001.22450_none_b613b6283839eaf7\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 15:24 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6001.18272_none_b57678331f2ab896\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 15:09 156160 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6000.21067_none_b4297fd83b155d73\t2embed.dll
+ 2009-07-22 12:49 . 2009-06-15 15:29 156160 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6000.16870_none_b38e38f92205f4f7\t2embed.dll
+ 2008-04-05 17:11 . 2009-07-23 18:24 283968 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-11-02 10:33 . 2009-07-23 12:40 598660 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-07-23 12:40 104580 c:\windows\System32\perfc009.dat
+ 2009-06-02 07:10 . 2009-07-23 12:34 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-06-02 07:10 . 2009-07-22 21:55 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-22 12:49 . 2009-06-17 08:02 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22160_none_f4b74f0181eee730\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18056_none_f43e83de68c3c37f\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:30 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22459_none_f2e4af9f84b85a2a\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18278_none_f24470cc6babdbc4\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21074_none_f0e3a5eb87a6b883\OESpamFilter.dat
+ 2009-07-22 12:49 . 2009-06-17 07:36 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16876_none_f05c31926e871825\OESpamFilter.dat
- 2006-11-02 10:22 . 2009-07-22 12:48 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-07-23 12:47 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 12:47 . 2009-07-23 07:16 1588024 c:\windows\System32\FNTCACHE.DAT
- 2006-11-02 12:47 . 2009-07-22 20:48 1588024 c:\windows\System32\FNTCACHE.DAT
+ 2009-07-23 21:32 . 2009-07-23 21:33 6299648 c:\windows\ERDNT\Hiv-backup\schema.dat
+ 2006-11-02 10:24 . 2009-07-07 15:10 24539592 c:\windows\System32\mrt.exe
+ 2009-07-23 06:55 . 2009-07-23 06:55 15706112 c:\windows\Installer\66ece.msp
+ 2009-06-02 09:23 . 2009-07-23 06:55 171961867 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2008-07-03 812952]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"StrokeIt"="c:\program files\Strokeit\strokeit.exe" [2005-02-17 21504]
"BitTorrent DNA"="c:\users\mw\Program Files\DNA\btdna.exe" [2008-12-19 342848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 185896]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-27 1948440]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]
c:\users\mw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
GammaTray.lnk - c:\program files\MagicTune Premium\GammaTray.exe [2008-8-5 36864]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2008-8-5 49220]
NETGEAR WG111T Smart Wizard.lnk - c:\program files\NETGEAR\WG111T\wlan111t.exe [2008-8-8 884840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{83E8A40A-D1EE-4EEC-B21F-524578647B36}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{3CA09B8A-5D6E-48B0-9448-66E8C1E77C33}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{CF8CCE9D-85EA-4672-91F8-7AC69DDBB7E4}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{6258875D-EED7-473E-A0A2-46D87FEFBFCC}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{79CD550E-D5C0-4855-B865-BE33641FFA11}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{BFED147C-F51E-4D82-9361-20D5A2401443}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"TCP Query User{3FF0AC97-B8D6-48CE-B31F-007E2B4FDFD9}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{44103EED-3424-49A4-9725-4DAABB8DD82C}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"{5A7DAC17-D42F-4C61-999A-4896DA3FC2E7}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{F3FFEDEC-48A4-4959-81FC-81F012EF09C3}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{86FCB1E4-2800-4CBC-A25B-906222934890}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{658DA40A-2CB1-4784-89A5-0DFE15D8E6D0}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{1B7968C2-F69C-4243-8469-A82E4F16A28F}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"{262B262D-04FB-4057-8DDA-F2AED735A549}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{9916B9C5-5B5A-42AA-A06E-E351EC619127}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{2D123E90-0440-4B5D-9709-342375B88D43}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{F9BCCCA2-5648-40AA-9B6D-11D8A8C40C96}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{6EDC104F-F90D-4EA8-A3E4-56F5F3E24BB6}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{C93C9C75-E941-4E4A-BC94-A12BD6CAF6EE}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{CCAA6C73-FB41-4DA3-B8C7-383F6ABDB1A0}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{86526343-A0E1-4179-B36C-8C2AAAC3C024}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{13AF98C9-2539-4F75-82D0-165EF407EF8E}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{4691734B-CD6A-4E20-BCE0-B8F0C0816E8B}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{24F3DC76-9748-4B57-AB01-9876B6DC2F55}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{DEE48412-1268-48F1-991E-19D57A8E66D1}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{A4963C03-6429-4638-8B99-4AC8CF4B51F3}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
"UDP Query User{A2321309-CB60-49D8-9F83-4889BA49B839}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify
"{C040CB8F-F30A-4BAD-9C75-BDD97469A871}"= UDP:16800:tv
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [04/07/2008 22:33 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [05/02/2009 13:27 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [17/07/2009 11:41 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [04/07/2008 22:32 298776]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [05/04/2008 18:21 747912]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {DEA7C946-B8CF-7B5F-1232-EC23295FF138} /qb
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bbc.co.uk/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\mw\AppData\Roaming\Mozilla\Firefox\Profiles\p5hghz8l.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=home#/home.php?ref=home|http://forums.whatthetech.com/Help_removing_renos_OI_virus_Vista_t105440.html#entry580634|http://cgi.ebay.co.uk/Canon-Outlet-EOS-40D-Refurbished_W0QQitemZ270430134549QQcmdZViewItemQQptZUK_CamerasPhoto_DigitalCamer
as_DigitalCameras_JN?hash=item3ef6e46115&_trksid=p4634.c0.m14.l1262&_trkparms=%7C293%3A1%7C294%3A30
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npBBCPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\users\mw\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-23 22:36
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\users\mw\AppData\Local\Temp\catchme.dll 53248 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2009-07-23 22:38
ComboFix-quarantined-files.txt 2009-07-23 21:38
ComboFix2.txt 2009-07-22 22:08
Pre-Run: 104,100,601,856 bytes free
Post-Run: 104,068,620,288 bytes free
243 — E O F — 2009-07-23 06:55
EBAM:
Malwarebytes' Anti-Malware 1.39
Database version: 2490
Windows 6.0.6001 Service Pack 1
23/07/2009 22:52:22
mbam-log-2009-07-23 (22-52-22).txt
Scan type: Quick Scan
Objects scanned: 90526
Time elapsed: 2 minute(s), 28 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Kaspersky:
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Friday, July 24, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Friday, July 24, 2009 08:38:54
Records in database: 2524646
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
Scan statistics:
Files scanned: 175050
Threat name: 4
Infected objects: 7
Suspicious objects: 0
Duration of the scan: 01:47:27
File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\Users\mw\AppData\Roaming\1.exe.vir Infected: Trojan-Spy.Win32.Agent.aygh 1
C:\Qoobox\Quarantine\C\Windows\System32\ESQULfomnbtcqhftpeodryviqrolxfxdshvni.dll.vir Infected: Packed.Win32.Tdss.w 1
C:\Qoobox\Quarantine\C\Windows\System32\ESQULykbmcauqxipmdcrswtrdoqpmdbxugiht.dll.vir Infected: Packed.Win32.Tdss.w 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-23_22.33.56.zip Infected: Packed.Win32.Tdss.x 1
C:\Qoobox\Quarantine\[4]-Submit_2009-07-23_22.33.56.zip Infected: Trojan-Downloader.Win32.VB.pjh 1
C:\STUFF\Music\Downloads\QuickTime_Pro_v7.60.92\QuickTime Pro v7.60.92\Keygen.exe Infected: Trojan-Downloader.Win32.VB.pjh 1
C:\STUFF\Music\Downloads\QuickTime_Pro_v7.60.92\QuickTime Pro v7.60.92\QuickTimeInstaller.exe Infected: Trojan-Downloader.Win32.VB.pjh 1
The selected area was scanned.