Hello again.
Here are the logs you requested.
VirSCAN.org Scanned Report :
Scanned time : 2009/10/29 18:04:23 (EDT)
Scanner results: Scanners did not find malware!
File Name : daff.dll
File Size : 210944 byte
File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
MD5 : 88af7b222fbd1901f04880c9236c0121
SHA1 : b9eee03645b7d244dc6f76bfbceebbd31edc0b4c
Online report :
http://virscan.org/report/1c93c2d5c3e720bb…53fa3adb8d.html
Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 00040000000000 0004-00-00 7.11 -
AhnLab V3 2009.10.29.04 2009.10.29 2009-10-29 0.90 -
AntiVir 8.2.1.50 7.1.6.168 2009-10-29 0.29 -
Antiy 2.0.18 20091029.3153836 2009-10-29 0.02 -
Arcavir 2009 200910290807 2009-10-29 0.06 -
Authentium 5.1.1 200910291823 2009-10-29 1.70 -
AVAST! 4.7.4 091029-0 2009-10-29 0.02 -
AVG 8.5.288 270.14.39/2468 2009-10-30 0.92 -
BitDefender 7.81008.4478883 7.28644 2009-10-30 3.90 -
CA (VET) 35.1.0 7088 2009-10-28 8.14 -
ClamAV 0.95.2 9959 2009-10-29 0.05 -
Comodo 3.12 2772 2009-10-29 0.76 -
CP Secure 1.3.0.5 2009.10.29 2009-10-29 0.07 -
Dr.Web 4.44.0.9170 2009.10.29 2009-10-29 6.12 -
F-Prot 4.4.4.56 20091029 2009-10-29 1.65 -
F-Secure 7.02.73807 2009.10.29.17 2009-10-29 8.85 -
Fortinet 2.81-3.120 11.0 2009-10-29 0.19 -
GData 19.8637/19.527 20091029 2009-10-29 5.39 -
ViRobot 20091029 2009.10.29 2009-10-29 0.41 -
Ikarus T3.1.01.72 2009.10.29.74326 2009-10-29 4.33 -
JiangMin 11.0.800 2009.10.26 2009-10-26 4.04 -
Kaspersky 5.5.10 2009.10.29 2009-10-29 0.06 -
KingSoft 2009.2.5.15 2009.10.29.16 2009-10-29 0.50 -
McAfee 5.3.00 5786 2009-10-29 3.36 -
Microsoft 1.5202 2009.10.29 2009-10-29 6.14 -
Norman 6.01.09 6.01.00 2009-10-29 4.01 -
Panda 9.05.01 2009.10.29 2009-10-29 3.61 -
Trend Micro 8.700-1004 6.588.02 2009-10-29 0.05 -
Quick Heal 10.00 2009.10.29 2009-10-29 1.26 -
Rising 20.0 21.53.34.00 2009-10-29 0.82 -
Sophos 3.00.1 4.46 2009-10-30 2.78 -
Sunbelt 5476 5476 2009-10-29 1.85 -
Symantec 1.3.0.24 20091029.005 2009-10-29 0.05 -
nProtect 20091029.01 6046753 2009-10-29 7.86 -
The Hacker 6.5.0.2 v00056 2009-10-28 0.85 -
VBA32 3.12.10.11 20091028.1155 2009-10-28 1.92 -
VirusBuster 4.5.11.10 10.113.1/2021054 2009-10-29 2.51 -
****************** *********************** ****************************
ComboFix 09-10-28.08 - jayFREE 10/29/2009 18:40.2.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.958.316 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\jayFREE\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active
FILE ::
"c:\windows\tqfqfkpi.knn"
.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-29 )))))))))))))))))))))))))))))))
.
2009-10-29 22:39 . 2009-04-11 06:32 19944 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-10-29 22:39 . 2008-01-19 07:42 45112 —-a-w- c:\windows\system32\drivers\nvstor.sys
2009-10-29 22:39 . 2007-10-26 22:51 110624 —-a-w- c:\windows\system32\drivers\nvstor32.sys
2009-10-29 01:59 . 2009-10-29 23:05 ——– d—–w- c:\users\jayFREE\AppData\Local\temp
2009-10-27 23:56 . 2009-10-28 02:14 ——– d—–w- c:\users\jayFREE\AppData\Roaming\KeePass
2009-10-27 23:27 . 2009-10-27 23:27 ——– d—–w- c:\program files\KeePass Password Safe 2
2009-10-27 23:19 . 2009-09-10 14:58 310784 —-a-w- c:\windows\system32\unregmp2.exe
2009-10-27 23:19 . 2009-09-10 14:59 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-10-26 03:28 . 2009-10-26 03:28 ——– d—–w- c:\users\jayFREE\AppData\Local\Apple
2009-10-25 18:54 . 2009-10-25 18:54 ——– d—–w- c:\windows\Sun
2009-10-25 17:51 . 2009-10-25 18:12 ——– d—–w- c:\users\jayFREE\AppData\Local\Adobe
2009-10-25 16:39 . 2009-10-25 16:39 ——– d—–w- c:\users\jayFREE\AppData\Local\Apple Computer
2009-10-25 15:34 . 2009-10-25 15:36 ——– d—–w- c:\windows\system32\ca-ES
2009-10-25 15:34 . 2009-10-25 15:36 ——– d—–w- c:\windows\system32\eu-ES
2009-10-25 15:34 . 2009-10-25 15:35 ——– d—–w- c:\windows\system32\vi-VN
2009-10-25 15:12 . 2009-10-25 15:12 ——– d—–w- c:\windows\system32\EventProviders
2009-10-25 15:09 . 2009-10-25 15:09 319456 —-a-w- c:\windows\DIFxAPI.dll
2009-10-14 06:40 . 2009-09-10 16:48 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-10-14 06:40 . 2009-08-04 12:34 3600456 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 06:40 . 2009-08-04 12:34 3548216 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-10-14 06:40 . 2009-05-08 12:53 604672 —-a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-14 06:36 . 2009-09-04 11:41 60928 —-a-w- c:\windows\system32\msasn1.dll
2009-10-14 06:36 . 2009-09-14 09:29 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2009-10-10 15:24 . 2009-10-10 15:24 ——– d—–w- c:\users\jayFREE\Office Genuine Advantage
2009-10-10 01:03 . 2005-06-15 07:00 102400 —-a-w- c:\windows\system32\tsccvid.dll
2009-10-01 05:07 . 2009-10-01 05:07 ——– d—–w- c:\users\jayFREE\AppData\Roaming\Malwarebytes
2009-10-01 05:07 . 2009-09-10 18:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-01 05:07 . 2009-10-01 05:07 ——– d—–w- c:\programdata\Malwarebytes
2009-10-01 05:07 . 2009-09-10 18:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-10-01 05:07 . 2009-10-25 16:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-30 21:41 . 2009-08-07 02:24 44768 —-a-w- c:\windows\system32\wups2.dll
2009-09-30 21:41 . 2009-08-07 02:24 53472 —-a-w- c:\windows\system32\wuauclt.exe
2009-09-30 21:41 . 2009-08-07 01:45 2421760 —-a-w- c:\windows\system32\wucltux.dll
2009-09-30 21:41 . 2009-08-07 02:23 1929952 —-a-w- c:\windows\system32\wuaueng.dll
2009-09-30 21:40 . 2009-08-07 02:24 35552 —-a-w- c:\windows\system32\wups.dll
2009-09-30 21:40 . 2009-08-07 02:23 575704 —-a-w- c:\windows\system32\wuapi.dll
2009-09-30 21:40 . 2009-08-07 01:44 87552 —-a-w- c:\windows\system32\wudriver.dll
2009-09-30 21:38 . 2009-08-06 23:23 171608 —-a-w- c:\windows\system32\wuwebv.dll
2009-09-30 21:38 . 2009-08-06 22:44 33792 —-a-w- c:\windows\system32\wuapp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-29 22:02 . 2009-03-14 15:20 ——– d—–w- c:\program files\LogMeIn
2009-10-28 23:33 . 2008-06-20 23:30 ——– d—–w- c:\programdata\Google Updater
2009-10-25 15:36 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2009-10-25 15:36 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-10-25 15:36 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2009-10-25 15:36 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2009-10-25 15:36 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2009-10-25 15:36 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2009-10-25 15:36 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2009-10-25 15:09 . 2008-04-01 11:06 ——– d—–w- c:\program files\Viewpoint
2009-10-25 15:05 . 2008-03-31 19:16 ——– d—–w- c:\program files\McAfee
2009-10-18 00:30 . 2009-05-10 20:30 ——– d—–w- c:\users\jayFREE\AppData\Roaming\Move Networks
2009-10-14 07:06 . 2008-04-01 11:52 ——– d—–w- c:\programdata\Microsoft Help
2009-10-01 05:22 . 2008-05-24 19:21 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-09-30 22:41 . 2008-04-23 15:13 ——– d—–w- c:\users\jayFREE\AppData\Roaming\LimeWire
2009-09-16 14:22 . 2008-03-31 19:18 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 14:22 . 2008-03-31 19:18 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 14:22 . 2008-03-31 19:18 214664 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 14:22 . 2008-03-31 19:18 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 14:22 . 2008-03-31 19:18 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-10 07:14 . 2008-05-15 04:08 ——– d—–w- c:\program files\Microsoft Silverlight
2009-09-10 00:57 . 2008-03-31 19:04 ——– d—–w- c:\programdata\McAfee
2009-08-29 00:27 . 2009-09-02 21:31 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-02 21:31 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2009-08-27 05:22 . 2009-10-14 06:38 916480 —-a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-14 06:38 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-08-27 05:17 . 2009-10-14 06:38 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-08-27 03:42 . 2009-10-14 06:38 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-08-18 03:33 . 2009-08-18 03:33 1193832 —-a-w- c:\windows\system32\FM20.DLL
2009-08-14 16:27 . 2009-09-09 21:50 904776 —-a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-09 21:50 17920 —-a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-09 21:50 9728 —-a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-09 21:50 17920 —-a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-09 21:50 11264 —-a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-09 21:50 27136 —-a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-09 21:50 19968 —-a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-09 21:50 8704 —-a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-09 21:50 10240 —-a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-09 21:50 30720 —-a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-09 21:50 105984 —-a-w- c:\windows\system32\netiohlp.dll
2009-08-03 19:07 . 2009-08-03 19:07 403816 —-a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 19:07 . 2009-08-03 19:07 322928 —-a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 19:07 . 2009-08-03 19:07 230768 —-a-w- c:\windows\system32\OGAEXEC.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-10-29_01.55.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-01 09:53 . 2009-10-29 22:34 40946 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-10-29 22:35 44060 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02 . 2009-10-29 23:06 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-10-29 01:55 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-10-29 01:55 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-10-29 23:06 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-10-29 23:06 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 13:02 . 2009-10-29 01:55 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-01 09:53 . 2009-10-29 22:35 6684 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4130002868-1829355866-1881414188-1000_UserData.bin
- 2009-10-28 07:24 . 2009-10-28 07:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-10-29 22:53 . 2009-10-29 22:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-10-29 22:53 . 2009-10-29 22:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-10-28 07:24 . 2009-10-28 07:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-04-05 04:43 . 2009-10-29 22:02 229008 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2006-11-02 10:33 . 2009-10-29 23:01 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-10-28 07:32 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-10-28 07:32 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-10-29 23:01 101144 c:\windows\System32\perfc009.dat
- 2009-06-22 21:20 . 2009-10-28 22:51 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-06-22 21:20 . 2009-10-29 22:54 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-20 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-13 148888]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
c:\users\jayFREE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
YPOPs.lnk.disabled [2008-10-25 651]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk.disabled [2008-4-5 2009]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Aim6"="c:\program files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(

:c8,e5,90,b6,89,55,ca,01
R0 SCMNdisP;General NDIS Protocol Driver;c:\windows\System32\drivers\SCMNdisP.sys [8/20/2009 7:01 PM 21728]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\System32\drivers\LMIRfsDriver.sys [3/14/2009 11:21 AM 47640]
S2 gupdate1c98669f8a5f3ce;Google Update Service (gupdate1c98669f8a5f3ce);c:\program files\Google\Update\GoogleUpdate.exe [2/3/2009 9:43 PM 133104]
S3 MotDev;Motorola Inc. USB Device;c:\windows\System32\drivers\motodrv.sys [10/10/2007 5:41 PM 42112]
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\System32\drivers\wg111v2.sys [8/20/2009 7:01 PM 206336]
S3 VST_DPV;VST_DPV;c:\windows\System32\drivers\VSTDPV3.SYS [11/2/2006 6:25 AM 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\System32\drivers\VSTBS23.SYS [11/2/2006 6:25 AM 251904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2009-10-26 c:\windows\Tasks\Defrag.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 16:22]
2009-10-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-20 23:28]
2009-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 01:43]
2009-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 01:43]
2009-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 16:22]
2009-10-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 16:22]
2009-10-29 c:\windows\Tasks\User_Feed_Synchronization-{0CBB3BFF-CBBC-4137-AAD2-55BFC1D339FE}.job
- c:\windows\system32\msfeedssync.exe [2009-10-14 03:41]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/
mSearch Bar = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\jayFREE\AppData\Roaming\Mozilla\Firefox\Profiles\4bex005d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/
FF - component: c:\users\jayFREE\AppData\Roaming\Mozilla\Firefox\Profiles\4bex005d.default\extensions\{39124730-0779-11de-8c30-0800200c9a66}\components\daff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\users\jayFREE\AppData\Roaming\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\users\jayFREE\AppData\Roaming\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\users\jayFREE\AppData\Roaming\Mozilla\plugins\NPAbacheck.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: keyword.enabled - true
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\System32\WinService.exe
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Spybot - Search & Destroy\SDWinSec.exe
c:\windows\system32\WUDFHost.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\iPod\bin\iPodService.exe
c:\hp\kbd\kbd.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-10-29 19:11 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-29 23:11
ComboFix2.txt 2009-10-29 01:59
Pre-Run: 108,365,348,864 bytes free
Post-Run: 108,324,274,176 bytes free
- - End Of File - - CFB8785B09FCE7A66EBAE96F63D5E8A8