ComboFix 10-02-12.01 - Tre Banks 02/17/2010 21:27:44.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.195 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Therman Banks\Local Settings\Application Data\{9D27F40E-46A9-4012-A465-56753A96BB84}
c:\documents and settings\Therman Banks\Local Settings\Application Data\{9D27F40E-46A9-4012-A465-56753A96BB84}\chrome.manifest
c:\documents and settings\Therman Banks\Local Settings\Application Data\{9D27F40E-46A9-4012-A465-56753A96BB84}\chrome\content\_cfg.js
c:\documents and settings\Therman Banks\Local Settings\Application Data\{9D27F40E-46A9-4012-A465-56753A96BB84}\chrome\content\overlay.xul
c:\documents and settings\Therman Banks\Local Settings\Application Data\{9D27F40E-46A9-4012-A465-56753A96BB84}\install.rdf
c:\documents and settings\Tre Banks\Local Settings\Application Data\{A4E60AF5-DF38-479C-BD98-CF4752CAEF5F}
c:\documents and settings\Tre Banks\Local Settings\Application Data\{A4E60AF5-DF38-479C-BD98-CF4752CAEF5F}\chrome.manifest
c:\documents and settings\Tre Banks\Local Settings\Application Data\{A4E60AF5-DF38-479C-BD98-CF4752CAEF5F}\chrome\content\_cfg.js
c:\documents and settings\Tre Banks\Local Settings\Application Data\{A4E60AF5-DF38-479C-BD98-CF4752CAEF5F}\chrome\content\overlay.xul
c:\documents and settings\Tre Banks\Local Settings\Application Data\{A4E60AF5-DF38-479C-BD98-CF4752CAEF5F}\install.rdf
c:\recycler\S-1-5-21-2072303661-2577636831-3931479383-1003
c:\windows\aferizazowe.dll
c:\windows\system32\srcr.dat
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))
.
2010-02-17 00:48 . 2010-02-17 00:48 ——– d—–w- c:\documents and settings\Tre Banks\Application Data\Malwarebytes
2010-02-17 00:48 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-17 00:48 . 2010-02-17 00:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-17 00:48 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-17 00:48 . 2010-02-17 00:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-13 19:39 . 2010-02-13 18:48 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-02-13 18:48 . 2009-12-02 13:19 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-02-13 18:48 . 2010-02-13 18:48 862040 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-02-13 18:48 . 2010-02-13 18:48 15880 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-02-13 18:48 . 2010-02-13 18:48 206944 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-02-13 18:48 . 2010-02-13 18:48 390288 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-02-13 18:48 . 2010-02-13 18:48 537576 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-02-13 18:48 . 2010-02-13 18:48 389784 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-02-13 18:48 . 2010-02-13 18:48 163728 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-02-13 18:46 . 2010-02-13 18:46 6296864 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-02-13 18:46 . 2010-02-13 18:46 327000 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-02-13 18:46 . 2010-02-13 18:46 87496 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-02-13 18:45 . 2010-02-13 18:46 933120 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-02-13 18:45 . 2010-02-13 18:45 3803208 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-13 18:45 . 2010-02-13 18:45 816784 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-02-13 18:45 . 2010-02-13 18:45 823928 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-13 18:45 . 2010-02-13 18:45 1643272 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-02-13 18:45 . 2010-02-13 18:45 788880 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-02-13 18:45 . 2010-02-13 18:45 1181328 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-13 18:43 . 2010-02-13 18:43 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-02-13 18:43 . 2009-12-07 14:10 2953352 -c–a-w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
2010-02-13 18:42 . 2010-02-13 18:42 ——– d—–w- c:\program files\Lavasoft
2010-02-13 07:09 . 2010-02-13 07:09 ——– d—–w- c:\windows\system32\MpEngineStore
2010-02-13 04:49 . 2010-02-13 04:49 ——– d—–w- c:\program files\Trend Micro
2010-02-12 23:28 . 2010-02-12 23:28 ——– d—–w- c:\documents and settings\Therman Banks\Application Data\Windows Search
2010-02-12 23:09 . 2010-02-12 23:09 864520 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-11 03:51 . 2006-04-06 01:38 110592 —-a-w- c:\documents and settings\Therman Banks\Application Data\U3\temp\cleanup.exe
2010-02-11 03:20 . 2010-02-11 04:10 ——– d—–w- c:\documents and settings\Therman Banks\Application Data\U3
2010-02-11 02:23 . 2010-02-11 02:23 ——– d—–w- c:\documents and settings\Therman Banks\Local Settings\Application Data\IsolatedStorage
2010-02-11 02:22 . 2010-02-11 02:22 ——– d—–w- c:\documents and settings\Therman Banks\Local Settings\Application Data\Intuit
2010-02-08 01:17 . 2010-02-08 01:17 36832 —-a-w- c:\documents and settings\Therman Banks\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-07 04:38 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-02-07 04:29 . 2010-01-05 10:00 52224 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-02-07 04:29 . 2010-01-05 10:00 459264 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-02-07 04:29 . 2010-01-05 10:00 268288 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-02-07 04:29 . 2009-12-31 15:33 13824 -c—-w- c:\windows\system32\dllcache\ieudinit.exe
2010-02-07 04:29 . 2010-01-05 10:00 6067200 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-02-07 04:29 . 2010-01-05 10:00 380928 -c—-w- c:\windows\system32\dllcache\ieapfltr.dll
2010-02-07 04:29 . 2010-01-05 10:00 63488 -c—-w- c:\windows\system32\dllcache\icardie.dll
2010-02-07 04:29 . 2009-06-29 08:33 2452872 -c—-w- c:\windows\system32\dllcache\ieapfltr.dat
2010-02-07 04:16 . 2010-02-13 07:17 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-25 07:11 . 2008-04-13 16:45 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2010-01-25 07:11 . 2008-04-13 16:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2010-01-23 02:16 . 2010-02-13 07:02 ——– d—–w- c:\documents and settings\Therman Banks\Local Settings\Application Data\AskToolbar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-18 01:48 . 2009-12-27 16:28 0 —-a-w- c:\windows\Xvitalegetek.bin
2010-02-18 01:48 . 2009-12-27 16:28 120 —-a-w- c:\windows\Rtijodet.dat
2010-02-13 18:42 . 2009-11-04 22:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-02-13 18:30 . 2009-11-04 12:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-11 04:11 . 2005-07-28 21:16 ——– d—–w- c:\program files\Common Files\Intuit
2010-02-11 02:22 . 2009-11-04 03:09 ——– d—–w- c:\documents and settings\Therman Banks\Application Data\Intuit
2010-01-05 10:00 . 2005-07-28 18:48 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2005-07-28 18:47 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2005-07-28 18:47 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2005-07-28 18:48 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-26 20:33 . 2009-11-10 17:12 ——– d—–w- c:\documents and settings\Tre Banks\Application Data\FrostWire
2009-12-26 05:50 . 2009-11-14 01:58 36832 —-a-w- c:\documents and settings\Tre Banks\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-26 05:35 . 2009-11-04 23:32 ——– d—–w- c:\documents and settings\Tre Banks\Application Data\Intuit
2009-12-26 05:35 . 2009-12-26 05:35 ——– d—–w- c:\program files\Common Files\AnswerWorks 5.0
2009-12-26 05:30 . 2005-07-28 21:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Intuit
2009-12-26 05:28 . 2009-12-26 05:28 ——– d—–w- c:\program files\TurboTax
2009-12-22 23:16 . 2009-11-14 07:55 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-16 18:43 . 2005-07-28 20:08 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2005-07-28 18:47 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-04 18:22 . 2005-07-28 18:47 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-29 13:05 . 2009-11-29 13:05 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2009-11-29 13:04 . 2009-11-29 13:04 1216 —-a-w- c:\windows\system32\ealregsnapshot1.reg
2009-11-27 17:11 . 2005-07-28 18:48 1291776 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2004-08-04 00:56 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2005-07-28 18:47 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 —-a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2005-07-28 18:47 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2005-07-28 18:47 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-04 00:56 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-21 15:51 . 2005-07-28 18:47 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-02 22:56 1175944 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-04-05 73728]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2005-08-10 356352]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-08 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-04-12 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-12 88358]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"TFncKy"="TFncKy.exe" [BU]
"TPSMain"="TPSMain.exe" [2005-06-01 282624]
"NDSTray.exe"="NDSTray.exe" [BU]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 1077301]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 122880]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-23 303104]
"MCUpdateExe"="c:\progra~1\McAfee.com\Agent\McUpdate.exe" [2006-01-11 212992]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-18 151552]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2005-7-28 155648]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-27 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 19:27 110592 —-a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/13/2010 12:48 PM 64288]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/2/2009 7:19 AM 1181328]
S3 NaiFiltr;NaiFiltr;c:\windows\system32\DRIVERS\NaiFiltr.sys –> c:\windows\system32\DRIVERS\NaiFiltr.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-02-18 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 18:45]
2010-02-18 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 18:45]
2010-02-18 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 18:45]
2010-02-18 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 18:45]
2010-02-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 18:45]
2009-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2009-11-26 c:\windows\Tasks\NSSstub.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2009-11-12 05:44]
2010-02-18 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-09-02 22:56]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ask.com?o=13170&l=dis
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: intuit.com\ttlc
FF - ProfilePath - c:\documents and settings\Tre Banks\Application Data\Mozilla\Firefox\Profiles\5e9kwsta.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=FWV5&o=14193&locale=en_US&q=
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Fmawubalikoq - c:\windows\aferizazowe.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-17 21:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3857899318-3851387967-2664802281-1007\Software\SecuROM\License information*]
"datasecu"=hex:d8,af,61,e0,61,42,e6,56,6c,8c,30,9d,62,57,da,f9,ea,8b,42,e4,6e,
b8,ad,db,58,78,d7,db,ce,ab,a7,89,d4,d0,26,27,fa,39,8d,65,13,df,6f,1b,0e,f5,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1032)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'explorer.exe'(3680)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\Software Suite\PhotoImpression\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\agent\mctskshd.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Intel\Wireless\Bin\ZcfgSvc.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\windows\AGRSMMSG.exe
c:\program files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\system32\TPSBattM.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-02-17 21:39:01 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-18 03:38
Pre-Run: 61,027,713,024 bytes free
Post-Run: 60,989,677,568 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
Current=7 Default=7 Failed=6 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
- - End Of File - - 9D16526F03D487D56B240E2A7B21B5E5
My computer runs much faster than before.