ComboFix 09-10-19.02 - sl 10/20/2009 10:48.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3037.2085 [GMT -5:00]
Running from: c:\documents and settings\sl\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\sl\Local Settings\Temporary Internet Files\TestBrowser.html
c:\windows\system32\clrviddc.dll
.
((((((((((((((((((((((((( Files Created from 2009-09-20 to 2009-10-20 )))))))))))))))))))))))))))))))
.
2009-10-20 02:53 . 2009-10-20 04:13 -------- d-----w- c:\documents and settings\sl\Application Data\FileZilla
2009-10-20 02:52 . 2009-10-20 02:52 -------- d-----w- c:\program files\FileZilla FTP Client
2009-10-18 01:31 . 2009-10-18 01:31 -------- d-----w- c:\program files\X-Chat 2
2009-10-17 04:10 . 2009-10-17 04:10 -------- d-----w- c:\documents and settings\sl\Application Data\CyberLink
2009-10-17 04:10 . 2009-10-17 04:10 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-10-15 20:38 . 2009-10-15 21:28 -------- d-----w- c:\windows\BDOSCAN8
2009-10-15 19:39 . 2009-10-15 19:39 -------- d-----w- c:\program files\Trend Micro
2009-10-15 17:49 . 2009-10-15 17:49 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-10-15 17:49 . 2009-10-15 17:50 -------- d-----w- c:\documents and settings\sl\.housecall6.6
2009-10-14 22:02 . 2009-10-14 22:02 -------- d-----w- c:\documents and settings\sl\Local Settings\Application Data\Yahoo
2009-10-14 22:00 . 2009-10-14 22:00 -------- d-----w- c:\documents and settings\sl\Application Data\Yahoo!
2009-10-14 21:59 . 2009-10-14 22:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-10-14 21:59 . 2009-10-15 17:07 -------- d-----w- c:\program files\Yahoo!
2009-10-14 17:49 . 2009-10-14 17:49 -------- d-----w- c:\documents and settings\sl\Application Data\com.seesmic.desktop.client.D89F32799270693BEF34AAA36E9B2632B59240FA.1
2009-10-13 15:44 . 2009-10-13 15:51 -------- d-----w- c:\documents and settings\sl\Application Data\Move Networks
2009-10-06 21:29 . 2009-10-06 21:29 -------- d-----w- c:\program files\Veoh Networks
2009-10-02 02:21 . 2009-10-02 02:21 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-10-01 14:15 . 2009-10-01 14:17 -------- d-----w- c:\documents and settings\sl\Application Data\Apple Computer
2009-10-01 14:15 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-01 14:15 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-10-01 14:15 . 2009-10-01 14:15 -------- d-----w- c:\program files\iPod
2009-10-01 14:15 . 2009-10-01 14:15 -------- d-----w- c:\program files\iTunes
2009-10-01 14:15 . 2009-10-01 14:15 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-01 14:14 . 2009-10-01 14:14 -------- d-----w- c:\program files\Bonjour
2009-10-01 14:14 . 2009-10-01 14:14 -------- d-----w- c:\program files\QuickTime
2009-10-01 14:14 . 2009-10-01 14:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-01 14:14 . 2009-10-01 14:14 -------- d-----w- c:\documents and settings\sl\Local Settings\Application Data\Apple
2009-10-01 14:14 . 2009-10-01 14:14 -------- d-----w- c:\program files\Apple Software Update
2009-10-01 14:13 . 2009-10-01 14:15 -------- d-----w- c:\program files\Common Files\Apple
2009-10-01 14:13 . 2009-10-01 14:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-10-01 14:13 . 2009-10-01 14:18 -------- d-----w- c:\documents and settings\sl\Local Settings\Application Data\Apple Computer
2009-10-01 07:00 . 2009-10-01 07:00 -------- d-----w- c:\documents and settings\sl\Application Data\acccore
2009-10-01 07:00 . 2009-10-01 07:00 -------- d-----w- c:\documents and settings\sl\Local Settings\Application Data\AOL
2009-10-01 07:00 . 2009-10-01 07:00 -------- d-----w- c:\documents and settings\sl\Local Settings\Application Data\AIM
2009-10-01 07:00 . 2009-10-01 07:00 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM
2009-10-01 06:59 . 2009-10-01 06:59 -------- d-----w- c:\program files\AIM
2009-10-01 06:59 . 2009-10-01 06:59 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-10-01 06:59 . 2009-10-01 06:59 -------- d-----w- c:\program files\Common Files\AOL
2009-09-21 13:22 . 2009-09-21 13:22 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-20 03:49 . 2009-09-18 04:08 -------- d-----w- c:\program files\WeFi
2009-10-20 01:50 . 2009-09-16 22:04 -------- d-----w- c:\documents and settings\sl\Application Data\X-Chat 2
2009-10-19 18:24 . 2009-09-15 16:24 -------- d-----w- c:\program files\Trillian
2009-10-19 16:34 . 2009-09-11 07:06 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-18 01:51 . 2009-09-11 07:11 39176 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-18 01:27 . 2009-09-16 22:03 -------- d-----w- c:\program files\xchat
2009-10-17 04:07 . 2009-09-15 20:44 -------- d-----w- c:\program files\WMCap
2009-10-14 23:07 . 2009-09-11 07:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-13 15:54 . 2009-09-15 20:58 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-10 01:08 . 2009-09-18 04:07 -------- d-----w- c:\documents and settings\sl\Application Data\Azureus
2009-10-07 23:12 . 2009-09-18 22:36 -------- d-----w- c:\documents and settings\sl\Application Data\mIRC
2009-09-25 14:36 . 2009-09-18 04:33 -------- d-----w- c:\documents and settings\sl\Application Data\Winamp
2009-09-25 05:37 . 2008-04-25 16:16 667136 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2008-04-25 16:16 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-19 01:24 . 2009-09-15 16:30 -------- d-----w- c:\program files\Common Files\Real
2009-09-19 01:24 . 2009-09-19 01:24 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-19 01:24 . 2009-09-16 14:52 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-09-19 01:24 . 2009-09-16 14:52 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-09-19 01:24 . 2009-09-19 01:24 -------- d-----w- c:\program files\real
2009-09-18 15:00 . 2009-09-15 16:24 -------- d-----w- c:\documents and settings\sl\Application Data\Trillian
2009-09-18 14:51 . 2009-09-16 15:25 -------- d-----w- c:\documents and settings\sl\Application Data\DivX
2009-09-18 04:33 . 2009-09-18 04:33 -------- d-----w- c:\program files\Winamp
2009-09-18 04:07 . 2009-09-18 04:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-09-18 04:07 . 2009-09-18 04:07 -------- d-----w- c:\program files\Vuze
2009-09-17 08:21 . 2009-09-11 07:14 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-17 08:21 . 2009-09-11 07:03 -------- d-----w- c:\program files\Windows Desktop Search
2009-09-17 08:15 . 2009-09-11 07:10 -------- d-----w- c:\program files\Microsoft Works
2009-09-16 17:07 . 2009-09-11 07:12 -------- d-----w- c:\program files\Windows Live
2009-09-16 15:48 . 2009-09-16 15:48 -------- d-----w- c:\documents and settings\sl\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-09-16 15:25 . 2009-09-16 15:25 -------- d-----w- c:\program files\DivX
2009-09-16 15:25 . 2009-09-16 15:25 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-09-16 14:42 . 2009-09-16 14:42 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-16 12:26 . 2009-09-11 07:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-16 12:26 . 2009-09-16 12:26 -------- d-----w- c:\program files\Sling Media
2009-09-16 12:26 . 2009-09-16 12:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Sling Media
2009-09-15 18:19 . 2009-09-15 17:02 -------- d-----w- c:\program files\TechSmith
2009-09-15 17:54 . 2009-09-15 17:54 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-09-15 17:48 . 2009-09-15 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-09-15 17:05 . 2009-09-15 17:05 -------- d-----w- c:\program files\Xvid
2009-09-15 17:02 . 2009-09-15 17:02 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-09-15 16:47 . 2009-09-15 16:47 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-15 16:47 . 2009-09-15 16:47 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-15 16:47 . 2009-09-15 16:47 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-15 16:47 . 2009-09-15 16:47 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-15 16:47 . 2009-09-15 16:47 -------- d-----w- c:\program files\AVG
2009-09-15 16:47 . 2009-09-15 16:47 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-15 16:44 . 2009-09-15 16:44 -------- d-----w- c:\documents and settings\sl\Application Data\AVG8
2009-09-15 16:42 . 2009-09-15 16:23 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-15 16:27 . 2009-09-11 07:05 -------- d-----w- c:\program files\Java
2009-09-15 16:20 . 2009-09-11 07:07 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-09-15 16:03 . 2009-09-15 16:03 -------- d-----w- c:\program files\CheckPoint
2009-09-15 15:59 . 2009-09-15 15:59 0 ----a-w- c:\windows\nsreg.dat
2009-09-15 15:41 . 2009-09-15 15:41 -------- d-----w- c:\documents and settings\sl\Application Data\Windows Search
2009-09-15 15:33 . 2009-09-15 15:33 -------- d-----w- c:\documents and settings\sl\Application Data\Dell
2009-09-11 14:18 . 2008-04-25 16:16 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 10:47 . 2009-09-11 10:47 5655 ----a-w- c:\windows\system32\drivers\1028_Dell_INS_537S.mrk
2009-09-11 07:20 . 2009-09-15 15:32 38768 ----a-w- c:\documents and settings\sl\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 07:17 . 2009-09-11 07:17 -------- d-----w- c:\program files\Dell
2009-09-11 07:17 . 2009-09-11 07:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2009-09-11 07:17 . 2009-09-11 07:17 -------- d-----w- c:\program files\CyberLink
2009-09-11 07:17 . 2009-09-11 07:11 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-11 07:17 . 2009-09-11 07:17 -------- d-----w- c:\program files\Microsoft Office Suite Activation Assistant
2009-09-11 07:16 . 2009-09-11 07:16 -------- d-----w- c:\program files\Microsoft.NET
2009-09-11 07:14 . 2009-09-11 07:14 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-11 07:14 . 2009-09-11 07:14 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-11 07:13 . 2009-09-11 07:13 -------- d-----w- c:\program files\Microsoft
2009-09-11 07:13 . 2009-09-11 07:13 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-11 07:11 . 2009-09-11 07:11 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-11 07:11 . 2009-09-11 07:11 -------- d-----w- c:\program files\Dell DataSafe Online
2009-09-11 07:11 . 2009-09-11 07:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Uninstall
2009-09-11 07:11 . 2009-09-11 07:11 -------- d-----w- c:\program files\Common Files\SureThing Shared
2009-09-11 07:11 . 2009-09-11 07:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Sonic
2009-09-11 07:11 . 2009-09-11 07:11 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-09-11 07:11 . 2009-09-11 07:11 -------- d-----w- c:\program files\Common Files\Roxio Shared
2009-09-11 07:11 . 2009-09-11 07:11 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-09-11 07:11 . 2009-09-11 07:11 -------- d-----w- c:\program files\Roxio
2009-09-11 07:04 . 2009-09-15 15:32 -------- d-----w- c:\documents and settings\sl\Application Data\Windows Desktop Search
2009-09-11 07:04 . 2009-09-15 15:32 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Windows Desktop Search
2009-09-11 07:04 . 2009-09-11 07:04 -------- d-----w- c:\documents and settings\Administrator\Application Data\Windows Desktop Search
2009-09-04 21:03 . 2008-04-25 16:16 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-26 08:00 . 2008-04-25 16:16 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-16 15:08 . 2009-09-15 17:54 178176 ----a-w- c:\windows\system32\unrar.dll
2009-08-05 09:01 . 2008-04-25 16:16 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2008-04-25 16:16 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2008-04-14 00:01 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-31 20:23 . 2009-09-11 07:06 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-29 04:37 . 2008-04-25 16:16 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2008-04-25 16:16 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-26 21:44 . 2009-07-26 21:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-14 00:16 . 2009-07-14 00:16 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\sl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-09-16 133104]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"wefi"="c:\program files\WeFi\WeFi.exe" [2009-08-23 509440]
"Aim"="c:\program files\AIM\aim.exe" [2009-09-16 3634024]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-10-06 2075384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-04 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-04 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-04 150040]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-17 2025752]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-19 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-03-04 18084864]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-15 16:47 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2006-04-10 02:24 24674 ----a-w- c:\windows\system32\ckpNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^sl^Start Menu^Programs^Startup^Dell Dock.lnk]
path=c:\documents and settings\sl\Start Menu\Programs\Startup\Dell Dock.lnk
backup=c:\windows\pss\Dell Dock.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"=
"c:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Sling Media\\SlingPlayer\\SlingPlayer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\X-Chat 2\\xchat.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/15/2009 11:47 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/15/2009 11:47 AM 108552]
R1 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [4/9/2006 9:24 PM 2234320]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/15/2009 11:47 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/15/2009 11:47 AM 297752]
R2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32\drivers\omdrv.sys [4/9/2006 9:24 PM 36400]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [12/18/2008 1:05 PM 155648]
R2 SlingAgentService;SlingAgentService;c:\program files\Sling Media\SlingAgent\SlingAgentService.exe [4/27/2009 6:09 PM 93960]
R2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\system32\drivers\vnasc.sys [4/9/2006 9:24 PM 109072]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [4/9/2006 9:24 PM 671472]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ROOTREPEAL2
*Deregistered* - rootrepeal2
.
Contents of the 'Scheduled Tasks' folder
2009-10-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1473991072-3829973469-1075336041-1005Core.job
- c:\documents and settings\sl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-16 13:50]
2009-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1473991072-3829973469-1075336041-1005UA.job
- c:\documents and settings\sl\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-16 13:50]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\sl\Application Data\Mozilla\Firefox\Profiles\uga0dgm1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\sl\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\sl\Application Data\Mozilla\Firefox\Profiles\uga0dgm1.default\extensions\justintvpublisher@justin.tv\platform\WINNT_x86-msvc\plugins\npjustintvpublish.dll
FF - plugin: c:\documents and settings\sl\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(yahoo.homepage.dontask, true.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-20 10:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: ~,10time:~,-3
ComboFix-quarantined-files.txt 2009-10-20 15:50
Pre-Run: 467,511,885,824 bytes free
Post-Run: 467,758,256,128 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - F37C70D26B0B72960E923E3634584C33