DO NOT attach the scan results unless asked to
ComboFix 10-02-07.06 - Nick 02/07/2010 21:13:23.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3062.1697 [GMT -5:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
AV: Windows Live OneCare *On-access scanning disabled* (Updated) {427ADFC3-B354-4A51-BE34-A9D4218E45C4}
FW: Windows Live OneCare Firewall *enabled* {A3899D22-27E6-4A7E-AE4E-2C106646DAAB}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Windows Live OneCare *disabled* (Updated) {CC7E50BA-BA8C-4DDE-B5AC-EA53BC38D01B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2410190035-1707998874-356131181-500
c:\$recycle.bin\S-1-5-21-2874072062-2859935346-2614563588-500
c:\users\Nick\Autorun.inf
c:\windows\system32\AutoRun.inf
c:\windows\system32\KBL.LOG
c:\windows\system32\PCLECoInst.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 )))))))))))))))))))))))))))))))
.
2010-02-08 02:24 . 2010-02-08 02:24 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-02-06 19:44 . 2010-02-06 19:44 ——– d—–w- c:\users\Nick\AppData\Roaming\Malwarebytes
2010-02-06 19:44 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-06 19:44 . 2010-02-06 19:44 ——– d—–w- c:\programdata\Malwarebytes
2010-02-06 19:44 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-06 01:57 . 2010-02-06 19:44 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-06 00:40 . 2010-02-07 19:19 ——– d—–w- c:\users\Nick\AppData\Local\hxxsar
2010-02-01 23:46 . 2010-02-01 23:46 ——– d—–w- c:\program files\iPod
2010-02-01 23:46 . 2010-02-01 23:48 ——– d—–w- c:\program files\iTunes
2010-02-01 23:40 . 2010-02-01 23:41 ——– d—–w- c:\program files\QuickTime
2010-02-01 23:37 . 2010-02-01 23:37 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-26 04:48 . 2010-01-26 04:48 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-26 04:42 . 2009-11-20 11:08 38784 —-a-w- c:\users\Nick\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-26 04:41 . 2009-11-20 11:08 38784 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-26 04:41 . 2010-01-26 04:41 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-26 04:41 . 2010-01-26 04:41 ——– d—–w- c:\programdata\McAfee Security Scan
2010-01-26 04:41 . 2010-01-26 04:41 ——– d—–w- c:\program files\McAfee Security Scan
2010-01-26 04:41 . 2010-01-26 04:41 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2010-01-26 04:40 . 2010-01-28 23:21 ——– d—–w- c:\programdata\NOS
2010-01-26 04:23 . 2010-01-26 23:20 ——– d—–w- c:\users\Nick\AppData\Local\gqgfay
2010-01-13 00:23 . 2009-10-19 14:27 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-01-13 00:23 . 2009-10-19 14:24 72704 —-a-w- c:\windows\system32\fontsub.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-08 01:31 . 2008-06-15 17:42 ——– d—–w- c:\program files\Microsoft Windows OneCare Live
2010-02-06 19:53 . 2008-08-13 21:54 1356 —-a-w- c:\users\Nick\AppData\Local\d3d9caps.dat
2010-02-02 18:23 . 2009-11-20 00:48 439816 —-a-w- c:\users\Nick\AppData\Roaming\Real\Update\setup3.09\setup.exe
2010-02-02 18:00 . 2008-06-15 18:36 ——– d—–w- c:\programdata\Lx_cats
2010-02-01 23:46 . 2008-06-15 19:08 ——– d—–w- c:\program files\Common Files\Apple
2010-01-28 04:41 . 2008-08-31 21:01 ——– d—–w- c:\programdata\McAfee
2010-01-13 08:07 . 2008-02-18 06:38 ——– d—–w- c:\programdata\Microsoft Help
2010-01-13 08:06 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-01-09 01:16 . 2009-09-15 06:36 ——– d—–w- c:\users\Nick\AppData\Roaming\vlc
2009-12-21 19:27 . 2009-12-21 18:40 ——– d—–w- c:\program files\Audacity
2009-12-18 13:05 . 2010-01-21 18:16 833024 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 13:01 . 2010-01-21 18:16 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-12-18 10:14 . 2010-01-21 18:16 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-26 23:41 . 2009-04-30 23:09 138056 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-26 23:41 . 2009-04-30 23:09 138056 —-a-w- c:\users\Nick\AppData\Roaming\PnkBstrK.sys
2009-11-26 23:41 . 2009-04-30 23:09 138056 —-a-w- c:\users\Nick\AppData\Roaming\PnkBstrK.sys
2009-11-26 23:41 . 2009-04-30 23:09 189248 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-11-26 23:41 . 2009-11-26 23:41 2395944 —-a-w- c:\windows\system32\pbsvc_heroes.exe
2009-11-20 18:02 . 2009-11-20 18:02 118784 —-a-w- c:\users\Nick\AppData\Roaming\Real\Update\setup3.09\RUP\inst_config\compat.dll
2009-11-12 17:38 . 2009-11-12 17:35 143976 —-a-w- c:\users\Nick\AppData\Roaming\Move Networks\uninstall.exe
2009-11-12 17:38 . 2009-10-15 00:50 5642688 —-a-w- c:\users\Nick\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll
2009-11-12 17:35 . 2009-08-13 19:21 4187512 —-a-w- c:\users\Nick\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
2002-07-26 21:02 . 2009-09-12 20:01 153088 —-a-w- c:\program files\UNWISE.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-02 1783136]
"firedogadvisor"="c:\program files\firedog advisor\faAgnt.exe" [2007-10-23 470064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-08-24 171448]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-17 634880]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 4390912]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-10-24 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-12-20 468264]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 80896]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2009-07-09 65240]
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2007-12-17 660136]
"lxdnamon"="c:\program files\Lexmark 2600 Series\lxdnamon.exe" [2007-12-17 16040]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-12-17 320168]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-01 198160]
"LifeChat"="c:\program files\Microsoft LifeChat\LifeChat.exe" [2008-08-21 267296]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-21 133656]
"PCLEUSBTip"="c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"LaunchList"="c:\program files\Pinnacle\Studio 10\LaunchList.exe" [2007-01-04 50712]
"USBToolTip"="c:\program files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 faproct;Circuit City Firedog Advisor ProcessTriggerDriver;c:\windows\System32\drivers\faproct.sys [6/17/2007 8:35 AM 4864]
R2 faunidrv;UniDriver for Firedog Advisor;c:\windows\System32\drivers\faunidrv.sys [3/21/2007 2:55 PM 5376]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service –> c:\windows\system32\lxdncoms.exe -service [?]
R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxdnserv.exe [12/5/2007 4:18 AM 98984]
R2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [7/9/2009 11:15 AM 26104]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 21:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=en_us&c;=81&bd;=Pavilion&pf;=laptop
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\qei6fvo5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\users\Nick\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
FF - plugin: c:\users\Nick\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll
FF - plugin: c:\users\Nick\AppData\Roaming\Mozilla\Firefox\Profiles\qei6fvo5.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-USB2Check - c:\windows\system32\PCLECoInst.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-07 21:24
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-02-07 21:29:32
ComboFix-quarantined-files.txt 2010-02-08 02:29
Pre-Run: 114,463,080,448 bytes free
Post-Run: 114,507,612,160 bytes free
- - End Of File - - 3EE509DCAE83990F0178B3DD2C66D4CD