redemption
Topic Starter
Hello, my other topic was closed because I thought it was fixed, but today I was keylogged AGAIN after I thought I had got rid of it.
They logged into my World of Warcraft account, and it seems restricted to just that, as I haven't had any other passwords reset or stolen.
In the previous thread the reply was to simply download ATFCleaner and run it, which I've done, and download ComboFix and make a log, which I've done.
Here are the results.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:03, on 26/08/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Windows\Explorer.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skybroadband.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
–
End of file - 6727 bytes
ComboFix Log:
ComboFix 09-08-25.04 - Hart 26/08/2009 13:55.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3582.2722 [GMT 1:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
PEV Error: CacheFolder
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
c:\windows\system32\config\systemprofile\ntuser.dat{c92be680-c7c0-11dc-8ff1-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
c:\users\Hart\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.
2009-08-26 13:00 . 2009-08-26 13:02 ——– d—–w- c:\users\Hart\AppData\Local\temp
2009-08-26 13:00 . 2009-08-26 13:00 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-08-20 18:16 . 2009-06-24 12:23 660480 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\pmv304-0906240-0-libOctoshapeClient.dll
2009-08-20 18:16 . 2009-08-20 18:16 120088 —-a-w- c:\users\Hart\AppData\Roaming\Mozilla\Plugins\npoctoshape.dll
2009-08-20 18:16 . 2009-08-20 18:16 ——– d—–w- c:\users\Hart\AppData\Roaming\Octoshape
2009-08-20 18:16 . 2009-06-22 13:37 397824 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-0906220-0-libOctoshapeClient.dll
2009-08-20 18:16 . 2009-06-22 13:37 124184 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-0906220-0-apoctoshape.dll
2009-08-20 18:16 . 2009-06-22 13:37 120088 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-0906220-0-npoctoshape.dll
2009-08-20 18:16 . 2009-01-08 13:44 70936 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
2009-08-20 01:32 . 2009-08-20 01:32 ——– d—–w- c:\programdata\Blizzard Entertainment
2009-08-18 17:21 . 2009-08-18 17:21 782664 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-08-18 04:22 . 2009-08-18 04:22 ——– d—–w- c:\program files\iPod
2009-08-18 04:22 . 2009-08-18 04:23 ——– d—–w- c:\program files\iTunes
2009-08-17 20:04 . 2009-08-17 20:04 ——– d—–w- c:\programdata\WindowsSearch
2009-08-17 17:01 . 2009-08-17 17:54 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2009-08-17 17:01 . 2009-08-17 17:02 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-17 14:41 . 2009-08-17 14:41 ——– d—–w- c:\program files\Trend Micro
2009-08-17 13:43 . 2009-08-17 16:04 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 13:43 . 2009-08-17 16:04 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 13:43 . 2009-08-17 16:02 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-17 13:42 . 2009-08-17 16:05 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 13:42 . 2009-08-17 16:05 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 13:42 . 2009-08-17 16:10 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 13:42 . 2009-08-17 16:05 53328 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-08-17 13:42 . 2003-03-18 19:20 1060864 —-a-w- c:\windows\system32\MFC71.dll
2009-08-17 13:42 . 2009-08-17 13:42 ——– d—–w- c:\program files\Alwil Software
2009-08-13 23:22 . 2009-08-18 00:45 ——– d—–w- c:\program files\Xfire
2009-08-13 19:53 . 2009-08-13 19:53 41872 —-a-w- c:\windows\system32\xfcodec.dll
2009-08-12 23:24 . 2009-06-15 14:54 175104 —-a-w- c:\windows\system32\wdigest.dll
2009-08-12 23:24 . 2009-06-15 14:53 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-08-12 23:24 . 2009-06-15 14:52 499712 —-a-w- c:\windows\system32\kerberos.dll
2009-08-12 23:24 . 2009-06-15 23:15 439864 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-12 23:24 . 2009-06-15 14:53 72704 —-a-w- c:\windows\system32\secur32.dll
2009-08-12 23:24 . 2009-06-15 14:53 270848 —-a-w- c:\windows\system32\schannel.dll
2009-08-12 23:24 . 2009-06-15 14:52 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2009-08-12 23:24 . 2009-06-15 12:48 9728 —-a-w- c:\windows\system32\lsass.exe
2009-08-11 18:51 . 2009-07-17 13:54 71680 —-a-w- c:\windows\system32\atl.dll
2009-08-11 18:51 . 2009-06-10 11:42 160256 —-a-w- c:\windows\system32\wkssvc.dll
2009-08-11 18:51 . 2009-06-04 12:07 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-08-11 18:51 . 2009-06-10 11:38 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-08-11 18:51 . 2009-07-15 12:40 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-08-11 18:51 . 2009-07-15 12:39 313344 —-a-w- c:\windows\system32\wmpdxm.dll
2009-08-11 18:51 . 2009-07-15 12:39 4096 —-a-w- c:\windows\system32\dxmasf.dll
2009-08-11 18:51 . 2009-07-15 12:39 7680 —-a-w- c:\windows\system32\spwmp.dll
2009-08-11 02:58 . 2009-08-18 15:47 ——– d—–w- C:\Rise Against - The Sufferer & The Witness [2006] [Punk] [www.file24ever.com]
2009-08-09 16:59 . 2009-08-09 16:59 ——– d—–w- C:\ESCAPE THE FATE - DISCOGRAPHY [CHANNEL NEO]
2009-08-05 19:16 . 2009-08-25 01:18 ——– d—–w- c:\users\Hart\AppData\Local\CurseClient
2009-08-05 19:16 . 2009-08-05 19:16 ——– d—–w- c:\program files\Curse
2009-08-02 01:06 . 2009-08-02 01:08 ——– d—–w- c:\windows\system32\ca-ES
2009-08-02 01:06 . 2009-08-02 01:08 ——– d—–w- c:\windows\system32\eu-ES
2009-08-02 01:06 . 2009-08-02 01:08 ——– d—–w- c:\windows\system32\vi-VN
2009-08-02 00:16 . 2009-08-02 00:16 ——– d—–w- c:\windows\system32\EventProviders
2009-08-01 23:12 . 2009-08-01 23:12 ——– d—–w- c:\users\Hart\AppData\Roaming\skypePM
2009-08-01 23:00 . 2009-08-02 01:49 ——– d—–w- c:\programdata\Skype
2009-07-31 23:37 . 2009-04-11 05:03 12240896 —-a-w- c:\windows\system32\NlsLexicons0007.dll
2009-07-31 23:37 . 2009-04-11 06:28 1081344 —-a-w- c:\windows\system32\SLCExt.dll
2009-07-31 23:37 . 2009-04-11 06:27 3408896 —-a-w- c:\windows\system32\SLsvc.exe
2009-07-31 23:37 . 2009-04-11 06:28 2134528 —-a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2009-07-31 23:37 . 2009-04-11 06:27 65536 —-a-w- c:\windows\system32\DevicePairingWizard.exe
2009-07-31 23:37 . 2009-04-11 05:03 2644480 —-a-w- c:\windows\system32\NlsLexicons0009.dll
2009-07-31 23:37 . 2009-04-11 06:28 1480704 —-a-w- c:\windows\system32\mssrch.dll
2009-07-31 23:37 . 2009-04-11 02:52 684032 —-a-w- c:\windows\system32\drivers\spsys.sys
2009-07-31 23:37 . 2009-04-11 06:28 1576960 —-a-w- c:\windows\system32\tquery.dll
2009-07-31 23:35 . 2009-04-11 06:28 61440 —-a-w- c:\windows\system32\wscsvc.dll
2009-07-31 23:34 . 2009-04-11 06:28 83968 —-a-w- c:\windows\system32\wbem\wmiutils.dll
2009-07-31 23:34 . 2009-04-11 06:28 744448 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2009-07-31 23:34 . 2009-04-11 06:28 30208 —-a-w- c:\windows\system32\wbem\wbemprox.dll
2009-07-31 23:34 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-07-31 23:34 . 2009-04-11 06:28 189440 —-a-w- c:\windows\system32\wbem\mofd.dll
2009-07-31 23:34 . 2009-04-11 06:28 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll
2009-07-31 23:34 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\esscli.dll
2009-07-31 23:34 . 2009-04-11 06:28 705536 —-a-w- c:\windows\system32\SmiEngine.dll
2009-07-31 23:34 . 2009-04-11 06:28 218624 —-a-w- c:\windows\system32\wdscore.dll
2009-07-31 23:34 . 2009-04-11 06:27 130560 —-a-w- c:\windows\system32\PkgMgr.exe
2009-07-31 23:34 . 2009-04-11 06:28 247808 —-a-w- c:\windows\system32\drvstore.dll
2009-07-31 01:29 . 2009-07-31 01:48 ——– d—–w- c:\users\Hart\3.0.1.8874 EU PTR Installer
2009-07-29 19:12 . 2009-07-29 19:12 ——– d—–w- c:\users\Hart\AppData\Local\Ares
2009-07-29 19:12 . 2009-07-29 19:12 ——– d—–w- c:\program files\Ares
2009-07-29 02:19 . 2009-08-25 16:34 ——– d—–w- c:\users\Hart\.worldoflogs
2009-07-29 02:17 . 2009-07-25 04:23 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-29 02:16 . 2009-08-05 01:49 ——– d—–w- c:\program files\Java
2009-07-29 02:16 . 2009-07-29 02:16 ——– d—–w- c:\programdata\McAfee
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 13:02 . 2009-07-24 11:02 49552 —-a-w- c:\programdata\nvModes.dat
2009-08-26 13:01 . 2009-07-24 10:58 ——– d—–w- c:\programdata\NVIDIA
2009-08-26 06:43 . 2009-07-24 21:00 ——– d—–w- c:\program files\Steam
2009-08-25 01:21 . 2009-08-21 18:37 ——– d—–w- c:\users\Hart\AppData\Roaming\RayV
2009-08-23 16:12 . 2009-07-24 09:50 ——– d—–w- c:\programdata\avg8
2009-08-22 07:02 . 2009-07-25 02:37 ——– d—–w- c:\users\Hart\AppData\Roaming\vlc
2009-08-22 05:03 . 2009-07-24 23:13 ——– d—–w- c:\users\Hart\AppData\Roaming\uTorrent
2009-08-21 15:45 . 2009-07-24 21:00 ——– d—–w- c:\program files\Common Files\Steam
2009-08-20 14:38 . 2009-07-24 15:53 ——– d—–w- c:\users\Hart\AppData\Roaming\Xfire
2009-08-20 13:41 . 2009-07-24 15:53 ——– d—–w- c:\programdata\Xfire
2009-08-19 17:03 . 2009-07-24 10:00 ——– d—–w- c:\programdata\Microsoft Help
2009-08-18 04:22 . 2009-07-24 16:06 ——– d—–w- c:\program files\Common Files\Apple
2009-08-12 07:12 . 2009-07-24 16:54 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-08-12 02:01 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2009-08-02 01:05 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-08-01 23:12 . 2009-08-01 23:12 56 —ha-w- c:\programdata\ezsidmv.dat
2009-07-25 08:58 . 2009-07-25 08:58 ——– d—–w- c:\users\Hart\AppData\Roaming\Samsung
2009-07-25 08:57 . 2009-07-25 08:50 5632 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2009-07-25 08:50 . 2009-07-24 08:32 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-25 08:42 . 2009-07-25 08:42 ——– d—–w- c:\program files\Samsung
2009-07-25 02:00 . 2009-07-25 02:00 ——– d—–w- c:\program files\MSXML 4.0
2009-07-24 23:53 . 2009-07-24 23:53 ——– d—–w- c:\users\Hart\AppData\Roaming\Nero
2009-07-24 23:14 . 2009-07-24 23:14 ——– d—–w- c:\program files\uTorrent
2009-07-24 19:35 . 2009-07-24 19:35 ——– d—–w- c:\program files\My Company Name
2009-07-24 19:34 . 2009-07-24 08:32 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-24 19:31 . 2009-07-24 19:31 ——– d—–w- c:\program files\VideoLAN
2009-07-24 17:39 . 2009-07-24 17:39 ——– d—–w- c:\programdata\Blizzard
2009-07-24 17:11 . 2009-07-24 16:34 ——– d—–w- c:\users\Hart\AppData\Roaming\Ventrilo
2009-07-24 16:38 . 2009-07-24 16:38 ——– d—–w- c:\program files\Microsoft
2009-07-24 16:38 . 2009-07-24 16:37 ——– d—–w- c:\program files\Windows Live
2009-07-24 16:38 . 2009-07-24 16:38 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-24 16:35 . 2009-07-24 16:35 ——– d—–w- c:\program files\Common Files\Windows Live
2009-07-24 16:33 . 2009-07-24 16:33 ——– d—–w- c:\program files\Ventrilo
2009-07-24 16:32 . 2009-07-24 10:57 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-07-24 16:22 . 2009-07-24 16:09 ——– d—–w- c:\users\Hart\AppData\Roaming\Apple Computer
2009-07-24 16:09 . 2009-07-24 16:08 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-24 16:08 . 2009-07-24 16:07 ——– d—–w- c:\programdata\Apple Computer
2009-07-24 16:08 . 2009-07-24 16:08 ——– d—–w- c:\program files\Bonjour
2009-07-24 16:08 . 2009-07-24 16:07 ——– d—–w- c:\program files\QuickTime
2009-07-24 16:07 . 2009-07-24 16:07 ——– d—–w- c:\program files\Apple Software Update
2009-07-24 16:06 . 2009-07-24 16:06 ——– d—–w- c:\programdata\Apple
2009-07-24 15:46 . 2009-07-24 15:46 ——– d—–w- c:\program files\Sky Broadband
2009-07-24 15:41 . 2009-07-24 15:41 ——– d–h–w- c:\programdata\CanonBJ
2009-07-24 10:58 . 2009-07-24 10:58 ——– d—–w- c:\program files\NVIDIA Corporation
2009-07-24 10:57 . 2009-07-24 10:57 ——– d—–w- c:\program files\AGEIA Technologies
2009-07-24 10:37 . 2009-07-24 08:21 1356 —-a-w- c:\users\Hart\AppData\Local\d3d9caps.dat
2009-07-24 10:25 . 2009-07-24 10:25 ——– d—–w- c:\program files\VistaCodecPack
2009-07-24 10:21 . 2009-07-24 10:21 ——– d—–w- c:\programdata\VistaCodecs
2009-07-24 10:20 . 2009-07-24 10:20 ——– d—–w- c:\programdata\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2009-07-24 10:20 . 2009-07-24 10:20 ——– d—–w- c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2009-07-24 10:15 . 2009-07-24 08:21 58896 —-a-w- c:\users\Hart\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-24 10:02 . 2009-07-24 10:02 ——– d—–w- c:\program files\Microsoft Works
2009-07-24 10:02 . 2009-07-24 10:02 ——– d—–w- c:\program files\Microsoft.NET
2009-07-24 09:58 . 2009-07-24 09:58 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-07-24 09:50 . 2009-07-24 09:50 ——– d—–w- c:\program files\AVG
2009-07-24 09:38 . 2009-07-24 09:38 ——– d—–w- c:\program files\NeroInstall.bak
2009-07-24 09:36 . 2009-07-24 09:34 ——– d—–w- c:\program files\Common Files\Nero
2009-07-24 09:34 . 2009-07-24 09:34 ——– d—–w- c:\programdata\Nero
2009-07-24 09:34 . 2009-07-24 09:34 ——– d—–w- c:\program files\Nero
2009-07-24 09:25 . 2009-07-24 08:43 ——– d—–w- c:\programdata\NOS
2009-07-24 09:25 . 2009-07-24 08:43 ——– d—–w- c:\program files\NOS
2009-07-24 08:54 . 2009-07-24 08:54 ——– d—–w- c:\program files\ASUS
2009-07-24 08:52 . 2009-07-24 08:54 24576 —-a-w- c:\windows\system32\AsIO.dll
2009-07-24 08:52 . 2009-07-24 08:54 12400 —-a-w- c:\windows\system32\drivers\AsIO.sys
2009-07-24 08:45 . 2009-07-24 08:45 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-24 08:44 . 2009-07-24 08:44 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-07-24 08:44 . 2009-07-24 08:44 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2009-07-24 08:32 . 2009-07-24 08:32 319456 —-a-w- c:\windows\DIFxAPI.dll
2009-07-24 08:32 . 2009-07-24 08:32 ——– d—–w- c:\program files\Realtek
2009-07-24 08:32 . 2009-07-24 08:32 315392 —-a-w- c:\windows\HideWin.exe
2009-07-24 08:24 . 2009-07-24 08:24 ——– d—–w- c:\program files\Intel
2009-07-21 21:52 . 2009-07-29 02:33 915456 —-a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 02:33 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 02:33 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 02:33 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-07-20 15:09 . 2009-07-24 18:24 282624 —-a-w- c:\users\Hart\AppData\Roaming\Mozilla\Firefox\Profiles\7ikh45np.default\extensions\[removed]\Plugins\npDyyno.dll
2009-07-14 12:29 . 2009-07-14 12:29 2505248 —-a-w- c:\windows\system32\nvcpluir.dll
2009-07-13 13:22 . 2009-07-13 13:22 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-10 06:01 . 2009-07-24 10:55 485920 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-06-15 14:53 . 2009-07-24 08:49 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-06-15 14:52 . 2009-07-24 08:49 23552 —-a-w- c:\windows\system32\lpk.dll
2009-06-15 14:52 . 2009-07-24 08:49 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-06-15 14:51 . 2009-07-24 08:49 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:42 . 2009-07-24 08:49 289792 —-a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-20_19.17.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-08-24 11:11 36668 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-08-26 09:13 60370 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-24 16:03 . 2009-07-24 16:03 84661 c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-24 16:03 . 2009-08-23 16:11 84661 c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-24 08:21 . 2009-08-26 13:01 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-24 08:21 . 2009-08-20 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-24 08:21 . 2009-08-26 13:01 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-24 08:21 . 2009-08-20 18:42 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-24 08:21 . 2009-08-20 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-24 08:21 . 2009-08-26 13:01 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 07:11 . 2006-11-02 07:11 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.18046_none_0de371cfef8dc034\AcRes.dll
+ 2009-07-24 08:51 . 2008-03-08 01:58 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.18267_none_0be85e73f276bf22\AcRes.dll
+ 2009-07-24 09:23 . 2009-08-23 16:07 4410 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2009-07-24 09:23 . 2009-08-18 22:02 4410 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-07-24 08:23 . 2009-08-26 09:13 6402 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2809076371-2212094262-4108447950-1000_UserData.bin
+ 2009-07-26 09:10 . 2009-08-26 12:41 201934 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2006-11-02 10:33 . 2009-08-26 09:19 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-08-20 14:45 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-08-20 14:45 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-08-26 09:19 105448 c:\windows\System32\perfc009.dat
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-31 23:36 . 2009-04-11 06:28 1696768 c:\windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18046_none_43c188b4be7e55e2\gameux.dll
+ 2009-07-24 08:51 . 2008-03-08 04:21 1695744 c:\windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18267_none_41c67558c16754d0\gameux.dll
+ 2006-11-02 10:22 . 2009-08-26 06:33 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2009-08-13 07:30 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\System32\Macromed\Flash\NPSWF32.dll
+ 2009-07-24 09:28 . 2009-08-26 06:33 128417399 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Octoshape Streaming Services"="c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-07-03 6266880]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2008-06-25 1826816]
c:\users\Hart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(
:7f,63,b9,96,0e,13,ca,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DA5E6BCC-2D98-4D40-8995-CFC28187AC43}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{AE2BF41F-77DD-4D1F-8B0B-0353455ACAB1}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F022D00D-F6BD-473D-847F-91124814D2B3}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{03E31955-19C4-4476-90D8-46103EF0A811}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{6F0D3C08-A92B-4F01-9F86-526F0E4BAAB6}c:\\users\\hart\\documents\\d drive\\xfire\\xfire.exe"= UDP:c:\users\hart\documents\d drive\xfire\xfire.exe:xfire.exe
"UDP Query User{A680F75D-8FA4-47B4-842D-BFA59869C0E8}c:\\users\\hart\\documents\\d drive\\xfire\\xfire.exe"= TCP:c:\users\hart\documents\d drive\xfire\xfire.exe:xfire.exe
"{A5924FDE-03FF-48ED-81A7-9CFD62740B28}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{61EB6808-EE84-442E-97B7-77F977EA9F93}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{FC55767C-D9E2-4083-B86F-2210CAECDDAD}c:\\d drive\\world of warcraft\\backgrounddownloader.exe"= UDP:c:\d drive\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"UDP Query User{F80EE7F5-52FF-4A50-8529-602881C5368B}c:\\d drive\\world of warcraft\\backgrounddownloader.exe"= TCP:c:\d drive\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"{BF83E13B-22BF-43E7-AA63-181335EDBA30}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{1751FE31-7F6C-4182-9F25-2177A3345C63}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"TCP Query User{84D54768-0109-4721-A5FF-A05ACB8AB2A6}c:\\users\\hart\\appdata\\locallow\\dyyno receiver\\dppm.exe"= UDP:c:\users\hart\appdata\locallow\dyyno receiver\dppm.exe:dppm.exe
"UDP Query User{EE7823F0-F188-4FC7-BB65-9B57C78D5F29}c:\\users\\hart\\appdata\\locallow\\dyyno receiver\\dppm.exe"= TCP:c:\users\hart\appdata\locallow\dyyno receiver\dppm.exe:dppm.exe
"TCP Query User{52D88A08-C015-4E98-8364-9FB8FB959717}c:\\world of warcraft\\launcher.exe"= UDP:c:\world of warcraft\launcher.exe:Blizzard Launcher
"UDP Query User{721CD836-BD14-4D1E-97FD-C170D4B2B2CB}c:\\world of warcraft\\launcher.exe"= TCP:c:\world of warcraft\launcher.exe:Blizzard Launcher
"{6F288A60-2C34-4F62-90DE-3D854140359B}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enGB-downloader.exe:Blizzard Downloader
"{10A2DCA4-B37A-45D1-8527-DBC96F87B497}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enGB-downloader.exe:Blizzard Downloader
"{0BADB25F-2E4D-4D90-A178-FB5EC431B65C}"= UDP:3724:Blizzard Downloader: 3724
"{95A4FA98-575A-46E7-9DA1-FE39C214293E}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{DBFE6EF7-CFD3-456E-92B3-085050F354E1}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{40A93E66-8E2A-438D-8F5D-2970955F1221}c:\\program files\\steam\\steamapps\\the_bigman\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\the_bigman\counter-strike source\hl2.exe:hl2
"UDP Query User{4EFD0858-4335-433D-80EE-A1EC0F81CC99}c:\\program files\\steam\\steamapps\\the_bigman\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\the_bigman\counter-strike source\hl2.exe:hl2
"{6A8E190A-3AE6-4DFF-AA4F-7884B706FD2D}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10048-to-0.2.0.10072-enGB-downloader.exe:Blizzard Downloader
"{9DFB850B-A9DA-4A9D-9B32-BAC3C15FFB3B}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10048-to-0.2.0.10072-enGB-downloader.exe:Blizzard Downloader
"{FB898F2C-471C-4D63-AAC2-107271044862}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10072-to-0.2.0.10083-enGB-downloader.exe:Blizzard Downloader
"{EBBFADEE-3A6C-4A29-96FE-E306E688127D}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10072-to-0.2.0.10083-enGB-downloader.exe:Blizzard Downloader
"{3DBD53F5-D3E5-473D-940F-AB2D62CA3250}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\wow-0.2.0.10083-to-0.2.0.10116-enGB-downloader.exe:Blizzard Downloader
"{BB48A926-994E-4E42-952B-DDCB48D798E7}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\wow-0.2.0.10083-to-0.2.0.10116-enGB-downloader.exe:Blizzard Downloader
"{FE39BEC2-9E53-43E9-A7FA-E9A054DAD123}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10116-to-0.2.0.10128-enGB-downloader.exe:Blizzard Downloader
"{C791A3C2-7BF4-4933-8B94-178F2CCBE428}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10116-to-0.2.0.10128-enGB-downloader.exe:Blizzard Downloader
"{FD13FE4F-8167-4F39-8A39-E9F8CEA7D844}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10128-to-0.2.0.10147-enGB-downloader.exe:Blizzard Downloader
"{F37F4D57-F80B-4A45-9F60-DDD0DC1DD70F}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10128-to-0.2.0.10147-enGB-downloader.exe:Blizzard Downloader
"{20D6BC59-7AFD-4309-9CA6-7D9F4DBAA1B1}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10147-to-0.2.0.10170-enGB-downloader.exe:Blizzard Downloader
"{F387C577-8CA6-4FF3-963D-ADDBABA7BBEA}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10147-to-0.2.0.10170-enGB-downloader.exe:Blizzard Downloader
"{01678A26-0F18-4BAD-B4E1-B43B90A0053D}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10170-to-0.2.0.10179-enGB-downloader.exe:Blizzard Downloader
"{FE512B6A-2914-4C14-B827-E0A9BEB8FB6B}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10170-to-0.2.0.10179-enGB-downloader.exe:Blizzard Downloader
"{8D6D4A7F-59DE-4C4D-9E98-A4B6A18D68E9}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10179-to-0.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{64A9BC09-18C2-4CCD-AD49-E4B2D4DC1508}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10179-to-0.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{EFE6E42C-DBC5-4F0B-8E7C-94C5ECD8C91C}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{9BFF6FD9-DC55-46B0-9B5E-900E78DD287F}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{AF35F03A-0E84-4786-81DE-E83F15FC4F73}"= UDP:c:\program files\Curse\CurseClient.exe:Curse Client
"{804A03D9-4BA3-4C4A-8569-0C7DF17396B8}"= TCP:c:\program files\Curse\CurseClient.exe:Curse Client
"TCP Query User{277E3B24-D751-4D8B-A444-1563537CD3F1}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{7269B75B-E452-4A75-824F-D0FB8385FC33}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{9A5FA208-2F9B-486B-A389-19B259B30A5C}c:\\program files\\xfire\\xfire.exe"= UDP:c:\program files\xfire\xfire.exe:Xfire
"UDP Query User{0EC630CC-D154-4FAF-A559-B20682FB9FE7}c:\\program files\\xfire\\xfire.exe"= TCP:c:\program files\xfire\xfire.exe:Xfire
"{0D6039D9-C765-4223-88E6-00CF3A2F28C9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{544F42B1-C1B9-4D96-B601-7A20307D792E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{1016EA34-8E33-4AB2-AD6D-D452AF57952F}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:Blizzard Downloader
"{EB0FD12C-95CC-48A4-B79B-1C62EA54F997}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:Blizzard Downloader
"TCP Query User{9F64B24A-084E-42A1-B7EE-B6A72F20A658}c:\\program files\\rayv\\rayv\\rayv.exe"= UDP:c:\program files\rayv\rayv\rayv.exe:RayV
"UDP Query User{A1C75037-E712-4082-BE77-EEA749DDE75D}c:\\program files\\rayv\\rayv\\rayv.exe"= TCP:c:\program files\rayv\rayv\rayv.exe:RayV
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [17/08/2009 14:42 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [17/08/2009 14:42 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [17/08/2009 14:42 53328]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [14/07/2009 12:28 239648]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\l160x86.sys [24/07/2009 09:34 46592]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-26 c:\windows\Tasks\User_Feed_Synchronization-{C6F7EF7B-F0D7-4475-8F74-C275E15C8FD8}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.skybroadband.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\users\Hart\AppData\Roaming\Mozilla\Firefox\Profiles\7ikh45np.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\users\Hart\AppData\Roaming\Mozilla\Firefox\Profiles\7ikh45np.default\extensions\[removed]\plugins\npDyyno.dll
FF - plugin: c:\users\Hart\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-26 14:01
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\nvvsvc.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\IoctlSvc.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-08-26 14:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-26 13:05
ComboFix2.txt 2009-08-20 19:18
Pre-Run: 204,761,321,472 bytes free
Post-Run: 204,615,528,448 bytes free
433 — E O F — 2009-08-20 23:32
Any amount of help would be appreciated as this is becoming extremely frustrating, thanks.
Oh, the Malwarebytes' Anti-Walware log:
Malwarebytes' Anti-Malware 1.40
Database version: 2699
Windows 6.0.6002 Service Pack 2
26/08/2009 17:24:48
mbam-log-2009-08-26 (17-24-48).txt
Scan type: Full Scan (C:\|)
Objects scanned: 199943
Time elapsed: 40 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Oops, was supposed to be an edit :/
They logged into my World of Warcraft account, and it seems restricted to just that, as I haven't had any other passwords reset or stolen.
In the previous thread the reply was to simply download ATFCleaner and run it, which I've done, and download ComboFix and make a log, which I've done.
Here are the results.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:03, on 26/08/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Windows\Explorer.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.skybroadband.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
–
End of file - 6727 bytes
ComboFix Log:
ComboFix 09-08-25.04 - Hart 26/08/2009 13:55.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3582.2722 [GMT 1:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
PEV Error: CacheFolder
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
c:\windows\system32\config\systemprofile\ntuser.dat{c92be680-c7c0-11dc-8ff1-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
c:\users\Hart\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.
2009-08-26 13:00 . 2009-08-26 13:02 ——– d—–w- c:\users\Hart\AppData\Local\temp
2009-08-26 13:00 . 2009-08-26 13:00 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-08-20 18:16 . 2009-06-24 12:23 660480 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\pmv304-0906240-0-libOctoshapeClient.dll
2009-08-20 18:16 . 2009-08-20 18:16 120088 —-a-w- c:\users\Hart\AppData\Roaming\Mozilla\Plugins\npoctoshape.dll
2009-08-20 18:16 . 2009-08-20 18:16 ——– d—–w- c:\users\Hart\AppData\Roaming\Octoshape
2009-08-20 18:16 . 2009-06-22 13:37 397824 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-0906220-0-libOctoshapeClient.dll
2009-08-20 18:16 . 2009-06-22 13:37 124184 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-0906220-0-apoctoshape.dll
2009-08-20 18:16 . 2009-06-22 13:37 120088 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-0906220-0-npoctoshape.dll
2009-08-20 18:16 . 2009-01-08 13:44 70936 —-a-w- c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
2009-08-20 01:32 . 2009-08-20 01:32 ——– d—–w- c:\programdata\Blizzard Entertainment
2009-08-18 17:21 . 2009-08-18 17:21 782664 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-08-18 04:22 . 2009-08-18 04:22 ——– d—–w- c:\program files\iPod
2009-08-18 04:22 . 2009-08-18 04:23 ——– d—–w- c:\program files\iTunes
2009-08-17 20:04 . 2009-08-17 20:04 ——– d—–w- c:\programdata\WindowsSearch
2009-08-17 17:01 . 2009-08-17 17:54 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2009-08-17 17:01 . 2009-08-17 17:02 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-17 14:41 . 2009-08-17 14:41 ——– d—–w- c:\program files\Trend Micro
2009-08-17 13:43 . 2009-08-17 16:04 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 13:43 . 2009-08-17 16:04 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 13:43 . 2009-08-17 16:02 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-17 13:42 . 2009-08-17 16:05 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 13:42 . 2009-08-17 16:05 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 13:42 . 2009-08-17 16:10 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 13:42 . 2009-08-17 16:05 53328 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-08-17 13:42 . 2003-03-18 19:20 1060864 —-a-w- c:\windows\system32\MFC71.dll
2009-08-17 13:42 . 2009-08-17 13:42 ——– d—–w- c:\program files\Alwil Software
2009-08-13 23:22 . 2009-08-18 00:45 ——– d—–w- c:\program files\Xfire
2009-08-13 19:53 . 2009-08-13 19:53 41872 —-a-w- c:\windows\system32\xfcodec.dll
2009-08-12 23:24 . 2009-06-15 14:54 175104 —-a-w- c:\windows\system32\wdigest.dll
2009-08-12 23:24 . 2009-06-15 14:53 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-08-12 23:24 . 2009-06-15 14:52 499712 —-a-w- c:\windows\system32\kerberos.dll
2009-08-12 23:24 . 2009-06-15 23:15 439864 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-12 23:24 . 2009-06-15 14:53 72704 —-a-w- c:\windows\system32\secur32.dll
2009-08-12 23:24 . 2009-06-15 14:53 270848 —-a-w- c:\windows\system32\schannel.dll
2009-08-12 23:24 . 2009-06-15 14:52 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2009-08-12 23:24 . 2009-06-15 12:48 9728 —-a-w- c:\windows\system32\lsass.exe
2009-08-11 18:51 . 2009-07-17 13:54 71680 —-a-w- c:\windows\system32\atl.dll
2009-08-11 18:51 . 2009-06-10 11:42 160256 —-a-w- c:\windows\system32\wkssvc.dll
2009-08-11 18:51 . 2009-06-04 12:07 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-08-11 18:51 . 2009-06-10 11:38 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-08-11 18:51 . 2009-07-15 12:40 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-08-11 18:51 . 2009-07-15 12:39 313344 —-a-w- c:\windows\system32\wmpdxm.dll
2009-08-11 18:51 . 2009-07-15 12:39 4096 —-a-w- c:\windows\system32\dxmasf.dll
2009-08-11 18:51 . 2009-07-15 12:39 7680 —-a-w- c:\windows\system32\spwmp.dll
2009-08-11 02:58 . 2009-08-18 15:47 ——– d—–w- C:\Rise Against - The Sufferer & The Witness [2006] [Punk] [www.file24ever.com]
2009-08-09 16:59 . 2009-08-09 16:59 ——– d—–w- C:\ESCAPE THE FATE - DISCOGRAPHY [CHANNEL NEO]
2009-08-05 19:16 . 2009-08-25 01:18 ——– d—–w- c:\users\Hart\AppData\Local\CurseClient
2009-08-05 19:16 . 2009-08-05 19:16 ——– d—–w- c:\program files\Curse
2009-08-02 01:06 . 2009-08-02 01:08 ——– d—–w- c:\windows\system32\ca-ES
2009-08-02 01:06 . 2009-08-02 01:08 ——– d—–w- c:\windows\system32\eu-ES
2009-08-02 01:06 . 2009-08-02 01:08 ——– d—–w- c:\windows\system32\vi-VN
2009-08-02 00:16 . 2009-08-02 00:16 ——– d—–w- c:\windows\system32\EventProviders
2009-08-01 23:12 . 2009-08-01 23:12 ——– d—–w- c:\users\Hart\AppData\Roaming\skypePM
2009-08-01 23:00 . 2009-08-02 01:49 ——– d—–w- c:\programdata\Skype
2009-07-31 23:37 . 2009-04-11 05:03 12240896 —-a-w- c:\windows\system32\NlsLexicons0007.dll
2009-07-31 23:37 . 2009-04-11 06:28 1081344 —-a-w- c:\windows\system32\SLCExt.dll
2009-07-31 23:37 . 2009-04-11 06:27 3408896 —-a-w- c:\windows\system32\SLsvc.exe
2009-07-31 23:37 . 2009-04-11 06:28 2134528 —-a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2009-07-31 23:37 . 2009-04-11 06:27 65536 —-a-w- c:\windows\system32\DevicePairingWizard.exe
2009-07-31 23:37 . 2009-04-11 05:03 2644480 —-a-w- c:\windows\system32\NlsLexicons0009.dll
2009-07-31 23:37 . 2009-04-11 06:28 1480704 —-a-w- c:\windows\system32\mssrch.dll
2009-07-31 23:37 . 2009-04-11 02:52 684032 —-a-w- c:\windows\system32\drivers\spsys.sys
2009-07-31 23:37 . 2009-04-11 06:28 1576960 —-a-w- c:\windows\system32\tquery.dll
2009-07-31 23:35 . 2009-04-11 06:28 61440 —-a-w- c:\windows\system32\wscsvc.dll
2009-07-31 23:34 . 2009-04-11 06:28 83968 —-a-w- c:\windows\system32\wbem\wmiutils.dll
2009-07-31 23:34 . 2009-04-11 06:28 744448 —-a-w- c:\windows\system32\wbem\wbemcore.dll
2009-07-31 23:34 . 2009-04-11 06:28 30208 —-a-w- c:\windows\system32\wbem\wbemprox.dll
2009-07-31 23:34 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-07-31 23:34 . 2009-04-11 06:28 189440 —-a-w- c:\windows\system32\wbem\mofd.dll
2009-07-31 23:34 . 2009-04-11 06:28 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll
2009-07-31 23:34 . 2009-04-11 06:28 265728 —-a-w- c:\windows\system32\wbem\esscli.dll
2009-07-31 23:34 . 2009-04-11 06:28 705536 —-a-w- c:\windows\system32\SmiEngine.dll
2009-07-31 23:34 . 2009-04-11 06:28 218624 —-a-w- c:\windows\system32\wdscore.dll
2009-07-31 23:34 . 2009-04-11 06:27 130560 —-a-w- c:\windows\system32\PkgMgr.exe
2009-07-31 23:34 . 2009-04-11 06:28 247808 —-a-w- c:\windows\system32\drvstore.dll
2009-07-31 01:29 . 2009-07-31 01:48 ——– d—–w- c:\users\Hart\3.0.1.8874 EU PTR Installer
2009-07-29 19:12 . 2009-07-29 19:12 ——– d—–w- c:\users\Hart\AppData\Local\Ares
2009-07-29 19:12 . 2009-07-29 19:12 ——– d—–w- c:\program files\Ares
2009-07-29 02:19 . 2009-08-25 16:34 ——– d—–w- c:\users\Hart\.worldoflogs
2009-07-29 02:17 . 2009-07-25 04:23 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-29 02:16 . 2009-08-05 01:49 ——– d—–w- c:\program files\Java
2009-07-29 02:16 . 2009-07-29 02:16 ——– d—–w- c:\programdata\McAfee
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 13:02 . 2009-07-24 11:02 49552 —-a-w- c:\programdata\nvModes.dat
2009-08-26 13:01 . 2009-07-24 10:58 ——– d—–w- c:\programdata\NVIDIA
2009-08-26 06:43 . 2009-07-24 21:00 ——– d—–w- c:\program files\Steam
2009-08-25 01:21 . 2009-08-21 18:37 ——– d—–w- c:\users\Hart\AppData\Roaming\RayV
2009-08-23 16:12 . 2009-07-24 09:50 ——– d—–w- c:\programdata\avg8
2009-08-22 07:02 . 2009-07-25 02:37 ——– d—–w- c:\users\Hart\AppData\Roaming\vlc
2009-08-22 05:03 . 2009-07-24 23:13 ——– d—–w- c:\users\Hart\AppData\Roaming\uTorrent
2009-08-21 15:45 . 2009-07-24 21:00 ——– d—–w- c:\program files\Common Files\Steam
2009-08-20 14:38 . 2009-07-24 15:53 ——– d—–w- c:\users\Hart\AppData\Roaming\Xfire
2009-08-20 13:41 . 2009-07-24 15:53 ——– d—–w- c:\programdata\Xfire
2009-08-19 17:03 . 2009-07-24 10:00 ——– d—–w- c:\programdata\Microsoft Help
2009-08-18 04:22 . 2009-07-24 16:06 ——– d—–w- c:\program files\Common Files\Apple
2009-08-12 07:12 . 2009-07-24 16:54 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-08-12 02:01 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2009-08-02 01:09 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2009-08-02 01:05 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-08-01 23:12 . 2009-08-01 23:12 56 —ha-w- c:\programdata\ezsidmv.dat
2009-07-25 08:58 . 2009-07-25 08:58 ——– d—–w- c:\users\Hart\AppData\Roaming\Samsung
2009-07-25 08:57 . 2009-07-25 08:50 5632 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2009-07-25 08:50 . 2009-07-24 08:32 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-25 08:42 . 2009-07-25 08:42 ——– d—–w- c:\program files\Samsung
2009-07-25 02:00 . 2009-07-25 02:00 ——– d—–w- c:\program files\MSXML 4.0
2009-07-24 23:53 . 2009-07-24 23:53 ——– d—–w- c:\users\Hart\AppData\Roaming\Nero
2009-07-24 23:14 . 2009-07-24 23:14 ——– d—–w- c:\program files\uTorrent
2009-07-24 19:35 . 2009-07-24 19:35 ——– d—–w- c:\program files\My Company Name
2009-07-24 19:34 . 2009-07-24 08:32 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-24 19:31 . 2009-07-24 19:31 ——– d—–w- c:\program files\VideoLAN
2009-07-24 17:39 . 2009-07-24 17:39 ——– d—–w- c:\programdata\Blizzard
2009-07-24 17:11 . 2009-07-24 16:34 ——– d—–w- c:\users\Hart\AppData\Roaming\Ventrilo
2009-07-24 16:38 . 2009-07-24 16:38 ——– d—–w- c:\program files\Microsoft
2009-07-24 16:38 . 2009-07-24 16:37 ——– d—–w- c:\program files\Windows Live
2009-07-24 16:38 . 2009-07-24 16:38 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-07-24 16:35 . 2009-07-24 16:35 ——– d—–w- c:\program files\Common Files\Windows Live
2009-07-24 16:33 . 2009-07-24 16:33 ——– d—–w- c:\program files\Ventrilo
2009-07-24 16:32 . 2009-07-24 10:57 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-07-24 16:22 . 2009-07-24 16:09 ——– d—–w- c:\users\Hart\AppData\Roaming\Apple Computer
2009-07-24 16:09 . 2009-07-24 16:08 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-24 16:08 . 2009-07-24 16:07 ——– d—–w- c:\programdata\Apple Computer
2009-07-24 16:08 . 2009-07-24 16:08 ——– d—–w- c:\program files\Bonjour
2009-07-24 16:08 . 2009-07-24 16:07 ——– d—–w- c:\program files\QuickTime
2009-07-24 16:07 . 2009-07-24 16:07 ——– d—–w- c:\program files\Apple Software Update
2009-07-24 16:06 . 2009-07-24 16:06 ——– d—–w- c:\programdata\Apple
2009-07-24 15:46 . 2009-07-24 15:46 ——– d—–w- c:\program files\Sky Broadband
2009-07-24 15:41 . 2009-07-24 15:41 ——– d–h–w- c:\programdata\CanonBJ
2009-07-24 10:58 . 2009-07-24 10:58 ——– d—–w- c:\program files\NVIDIA Corporation
2009-07-24 10:57 . 2009-07-24 10:57 ——– d—–w- c:\program files\AGEIA Technologies
2009-07-24 10:37 . 2009-07-24 08:21 1356 —-a-w- c:\users\Hart\AppData\Local\d3d9caps.dat
2009-07-24 10:25 . 2009-07-24 10:25 ——– d—–w- c:\program files\VistaCodecPack
2009-07-24 10:21 . 2009-07-24 10:21 ——– d—–w- c:\programdata\VistaCodecs
2009-07-24 10:20 . 2009-07-24 10:20 ——– d—–w- c:\programdata\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
2009-07-24 10:20 . 2009-07-24 10:20 ——– d—–w- c:\program files\Activation Assistant for the 2007 Microsoft Office suites
2009-07-24 10:15 . 2009-07-24 08:21 58896 —-a-w- c:\users\Hart\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-24 10:02 . 2009-07-24 10:02 ——– d—–w- c:\program files\Microsoft Works
2009-07-24 10:02 . 2009-07-24 10:02 ——– d—–w- c:\program files\Microsoft.NET
2009-07-24 09:58 . 2009-07-24 09:58 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-07-24 09:50 . 2009-07-24 09:50 ——– d—–w- c:\program files\AVG
2009-07-24 09:38 . 2009-07-24 09:38 ——– d—–w- c:\program files\NeroInstall.bak
2009-07-24 09:36 . 2009-07-24 09:34 ——– d—–w- c:\program files\Common Files\Nero
2009-07-24 09:34 . 2009-07-24 09:34 ——– d—–w- c:\programdata\Nero
2009-07-24 09:34 . 2009-07-24 09:34 ——– d—–w- c:\program files\Nero
2009-07-24 09:25 . 2009-07-24 08:43 ——– d—–w- c:\programdata\NOS
2009-07-24 09:25 . 2009-07-24 08:43 ——– d—–w- c:\program files\NOS
2009-07-24 08:54 . 2009-07-24 08:54 ——– d—–w- c:\program files\ASUS
2009-07-24 08:52 . 2009-07-24 08:54 24576 —-a-w- c:\windows\system32\AsIO.dll
2009-07-24 08:52 . 2009-07-24 08:54 12400 —-a-w- c:\windows\system32\drivers\AsIO.sys
2009-07-24 08:45 . 2009-07-24 08:45 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-24 08:44 . 2009-07-24 08:44 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-07-24 08:44 . 2009-07-24 08:44 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2009-07-24 08:32 . 2009-07-24 08:32 319456 —-a-w- c:\windows\DIFxAPI.dll
2009-07-24 08:32 . 2009-07-24 08:32 ——– d—–w- c:\program files\Realtek
2009-07-24 08:32 . 2009-07-24 08:32 315392 —-a-w- c:\windows\HideWin.exe
2009-07-24 08:24 . 2009-07-24 08:24 ——– d—–w- c:\program files\Intel
2009-07-21 21:52 . 2009-07-29 02:33 915456 —-a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 02:33 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 02:33 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 02:33 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-07-20 15:09 . 2009-07-24 18:24 282624 —-a-w- c:\users\Hart\AppData\Roaming\Mozilla\Firefox\Profiles\7ikh45np.default\extensions\[removed]\Plugins\npDyyno.dll
2009-07-14 12:29 . 2009-07-14 12:29 2505248 —-a-w- c:\windows\system32\nvcpluir.dll
2009-07-13 13:22 . 2009-07-13 13:22 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-10 06:01 . 2009-07-24 10:55 485920 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-06-15 14:53 . 2009-07-24 08:49 156672 —-a-w- c:\windows\system32\t2embed.dll
2009-06-15 14:52 . 2009-07-24 08:49 23552 —-a-w- c:\windows\system32\lpk.dll
2009-06-15 14:52 . 2009-07-24 08:49 72704 —-a-w- c:\windows\system32\fontsub.dll
2009-06-15 14:51 . 2009-07-24 08:49 10240 —-a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:42 . 2009-07-24 08:49 289792 —-a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-20_19.17.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-08-24 11:11 36668 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-08-26 09:13 60370 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-24 16:03 . 2009-07-24 16:03 84661 c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-24 16:03 . 2009-08-23 16:11 84661 c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-24 08:21 . 2009-08-26 13:01 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-24 08:21 . 2009-08-20 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-24 08:21 . 2009-08-26 13:01 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-24 08:21 . 2009-08-20 18:42 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-24 08:21 . 2009-08-20 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-24 08:21 . 2009-08-26 13:01 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 07:11 . 2006-11-02 07:11 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.18046_none_0de371cfef8dc034\AcRes.dll
+ 2009-07-24 08:51 . 2008-03-08 01:58 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.18267_none_0be85e73f276bf22\AcRes.dll
+ 2009-07-24 09:23 . 2009-08-23 16:07 4410 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2009-07-24 09:23 . 2009-08-18 22:02 4410 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-07-24 08:23 . 2009-08-26 09:13 6402 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2809076371-2212094262-4108447950-1000_UserData.bin
+ 2009-07-26 09:10 . 2009-08-26 12:41 201934 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2006-11-02 10:33 . 2009-08-26 09:19 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-08-20 14:45 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-08-20 14:45 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-08-26 09:19 105448 c:\windows\System32\perfc009.dat
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-31 23:36 . 2009-04-11 06:28 1696768 c:\windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18046_none_43c188b4be7e55e2\gameux.dll
+ 2009-07-24 08:51 . 2008-03-08 04:21 1695744 c:\windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18267_none_41c67558c16754d0\gameux.dll
+ 2006-11-02 10:22 . 2009-08-26 06:33 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2009-08-13 07:30 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\System32\Macromed\Flash\NPSWF32.dll
+ 2009-07-24 09:28 . 2009-08-26 06:33 128417399 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Octoshape Streaming Services"="c:\users\Hart\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" [2009-01-08 70936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-07-03 6266880]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2008-06-25 1826816]
c:\users\Hart\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DA5E6BCC-2D98-4D40-8995-CFC28187AC43}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{AE2BF41F-77DD-4D1F-8B0B-0353455ACAB1}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F022D00D-F6BD-473D-847F-91124814D2B3}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{03E31955-19C4-4476-90D8-46103EF0A811}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{6F0D3C08-A92B-4F01-9F86-526F0E4BAAB6}c:\\users\\hart\\documents\\d drive\\xfire\\xfire.exe"= UDP:c:\users\hart\documents\d drive\xfire\xfire.exe:xfire.exe
"UDP Query User{A680F75D-8FA4-47B4-842D-BFA59869C0E8}c:\\users\\hart\\documents\\d drive\\xfire\\xfire.exe"= TCP:c:\users\hart\documents\d drive\xfire\xfire.exe:xfire.exe
"{A5924FDE-03FF-48ED-81A7-9CFD62740B28}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{61EB6808-EE84-442E-97B7-77F977EA9F93}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{FC55767C-D9E2-4083-B86F-2210CAECDDAD}c:\\d drive\\world of warcraft\\backgrounddownloader.exe"= UDP:c:\d drive\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"UDP Query User{F80EE7F5-52FF-4A50-8529-602881C5368B}c:\\d drive\\world of warcraft\\backgrounddownloader.exe"= TCP:c:\d drive\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"{BF83E13B-22BF-43E7-AA63-181335EDBA30}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{1751FE31-7F6C-4182-9F25-2177A3345C63}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"TCP Query User{84D54768-0109-4721-A5FF-A05ACB8AB2A6}c:\\users\\hart\\appdata\\locallow\\dyyno receiver\\dppm.exe"= UDP:c:\users\hart\appdata\locallow\dyyno receiver\dppm.exe:dppm.exe
"UDP Query User{EE7823F0-F188-4FC7-BB65-9B57C78D5F29}c:\\users\\hart\\appdata\\locallow\\dyyno receiver\\dppm.exe"= TCP:c:\users\hart\appdata\locallow\dyyno receiver\dppm.exe:dppm.exe
"TCP Query User{52D88A08-C015-4E98-8364-9FB8FB959717}c:\\world of warcraft\\launcher.exe"= UDP:c:\world of warcraft\launcher.exe:Blizzard Launcher
"UDP Query User{721CD836-BD14-4D1E-97FD-C170D4B2B2CB}c:\\world of warcraft\\launcher.exe"= TCP:c:\world of warcraft\launcher.exe:Blizzard Launcher
"{6F288A60-2C34-4F62-90DE-3D854140359B}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enGB-downloader.exe:Blizzard Downloader
"{10A2DCA4-B37A-45D1-8527-DBC96F87B497}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.0.9.9551-to-3.1.0.9767-enGB-downloader.exe:Blizzard Downloader
"{0BADB25F-2E4D-4D90-A178-FB5EC431B65C}"= UDP:3724:Blizzard Downloader: 3724
"{95A4FA98-575A-46E7-9DA1-FE39C214293E}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{DBFE6EF7-CFD3-456E-92B3-085050F354E1}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{40A93E66-8E2A-438D-8F5D-2970955F1221}c:\\program files\\steam\\steamapps\\the_bigman\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\the_bigman\counter-strike source\hl2.exe:hl2
"UDP Query User{4EFD0858-4335-433D-80EE-A1EC0F81CC99}c:\\program files\\steam\\steamapps\\the_bigman\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\the_bigman\counter-strike source\hl2.exe:hl2
"{6A8E190A-3AE6-4DFF-AA4F-7884B706FD2D}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10048-to-0.2.0.10072-enGB-downloader.exe:Blizzard Downloader
"{9DFB850B-A9DA-4A9D-9B32-BAC3C15FFB3B}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10048-to-0.2.0.10072-enGB-downloader.exe:Blizzard Downloader
"{FB898F2C-471C-4D63-AAC2-107271044862}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10072-to-0.2.0.10083-enGB-downloader.exe:Blizzard Downloader
"{EBBFADEE-3A6C-4A29-96FE-E306E688127D}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10072-to-0.2.0.10083-enGB-downloader.exe:Blizzard Downloader
"{3DBD53F5-D3E5-473D-940F-AB2D62CA3250}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\wow-0.2.0.10083-to-0.2.0.10116-enGB-downloader.exe:Blizzard Downloader
"{BB48A926-994E-4E42-952B-DDCB48D798E7}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\wow-0.2.0.10083-to-0.2.0.10116-enGB-downloader.exe:Blizzard Downloader
"{FE39BEC2-9E53-43E9-A7FA-E9A054DAD123}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10116-to-0.2.0.10128-enGB-downloader.exe:Blizzard Downloader
"{C791A3C2-7BF4-4933-8B94-178F2CCBE428}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10116-to-0.2.0.10128-enGB-downloader.exe:Blizzard Downloader
"{FD13FE4F-8167-4F39-8A39-E9F8CEA7D844}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10128-to-0.2.0.10147-enGB-downloader.exe:Blizzard Downloader
"{F37F4D57-F80B-4A45-9F60-DDD0DC1DD70F}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10128-to-0.2.0.10147-enGB-downloader.exe:Blizzard Downloader
"{20D6BC59-7AFD-4309-9CA6-7D9F4DBAA1B1}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10147-to-0.2.0.10170-enGB-downloader.exe:Blizzard Downloader
"{F387C577-8CA6-4FF3-963D-ADDBABA7BBEA}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10147-to-0.2.0.10170-enGB-downloader.exe:Blizzard Downloader
"{01678A26-0F18-4BAD-B4E1-B43B90A0053D}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10170-to-0.2.0.10179-enGB-downloader.exe:Blizzard Downloader
"{FE512B6A-2914-4C14-B827-E0A9BEB8FB6B}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10170-to-0.2.0.10179-enGB-downloader.exe:Blizzard Downloader
"{8D6D4A7F-59DE-4C4D-9E98-A4B6A18D68E9}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10179-to-0.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{64A9BC09-18C2-4CCD-AD49-E4B2D4DC1508}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-0.2.0.10179-to-0.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{EFE6E42C-DBC5-4F0B-8E7C-94C5ECD8C91C}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{9BFF6FD9-DC55-46B0-9B5E-900E78DD287F}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.1.3.9947-to-3.2.0.10192-enGB-downloader.exe:Blizzard Downloader
"{AF35F03A-0E84-4786-81DE-E83F15FC4F73}"= UDP:c:\program files\Curse\CurseClient.exe:Curse Client
"{804A03D9-4BA3-4C4A-8569-0C7DF17396B8}"= TCP:c:\program files\Curse\CurseClient.exe:Curse Client
"TCP Query User{277E3B24-D751-4D8B-A444-1563537CD3F1}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{7269B75B-E452-4A75-824F-D0FB8385FC33}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"TCP Query User{9A5FA208-2F9B-486B-A389-19B259B30A5C}c:\\program files\\xfire\\xfire.exe"= UDP:c:\program files\xfire\xfire.exe:Xfire
"UDP Query User{0EC630CC-D154-4FAF-A559-B20682FB9FE7}c:\\program files\\xfire\\xfire.exe"= TCP:c:\program files\xfire\xfire.exe:Xfire
"{0D6039D9-C765-4223-88E6-00CF3A2F28C9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{544F42B1-C1B9-4D96-B601-7A20307D792E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{1016EA34-8E33-4AB2-AD6D-D452AF57952F}"= UDP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:Blizzard Downloader
"{EB0FD12C-95CC-48A4-B79B-1C62EA54F997}"= TCP:c:\users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-3.2.0.10192-to-3.2.0.10314-enGB-downloader.exe:Blizzard Downloader
"TCP Query User{9F64B24A-084E-42A1-B7EE-B6A72F20A658}c:\\program files\\rayv\\rayv\\rayv.exe"= UDP:c:\program files\rayv\rayv\rayv.exe:RayV
"UDP Query User{A1C75037-E712-4082-BE77-EEA749DDE75D}c:\\program files\\rayv\\rayv\\rayv.exe"= TCP:c:\program files\rayv\rayv\rayv.exe:RayV
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [17/08/2009 14:42 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [17/08/2009 14:42 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [17/08/2009 14:42 53328]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [14/07/2009 12:28 239648]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\l160x86.sys [24/07/2009 09:34 46592]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-26 c:\windows\Tasks\User_Feed_Synchronization-{C6F7EF7B-F0D7-4475-8F74-C275E15C8FD8}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.skybroadband.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\users\Hart\AppData\Roaming\Mozilla\Firefox\Profiles\7ikh45np.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\users\Hart\AppData\Roaming\Mozilla\Firefox\Profiles\7ikh45np.default\extensions\[removed]\plugins\npDyyno.dll
FF - plugin: c:\users\Hart\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-26 14:01
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\nvvsvc.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\IoctlSvc.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-08-26 14:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-26 13:05
ComboFix2.txt 2009-08-20 19:18
Pre-Run: 204,761,321,472 bytes free
Post-Run: 204,615,528,448 bytes free
433 — E O F — 2009-08-20 23:32
Any amount of help would be appreciated as this is becoming extremely frustrating, thanks.
Oh, the Malwarebytes' Anti-Walware log:
Malwarebytes' Anti-Malware 1.40
Database version: 2699
Windows 6.0.6002 Service Pack 2
26/08/2009 17:24:48
mbam-log-2009-08-26 (17-24-48).txt
Scan type: Full Scan (C:\|)
Objects scanned: 199943
Time elapsed: 40 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Oops, was supposed to be an edit :/