Hi,
The computer seems to be working well,no slowing down, the popup warnings have completely disappeared.
Here is the second Combofix log
ComboFix 10-03-05.03 - John 06/03/2010 15:15:37.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.375 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\John\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: PC Tools AntiVirus [removed] *On-access scanning disabled* (Updated) {832E7172-E406-4bb2-8B19-6D29F2C93A98}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\AskService.exe
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Cache\0011D6B6
c:\program files\AskBarDis\bar\Cache\0011DA7E
c:\program files\AskBarDis\bar\Cache\0011DC82.bin
c:\program files\AskBarDis\bar\Cache\0011E934.bin
c:\program files\AskBarDis\bar\Cache\0011ECED.bin
c:\program files\AskBarDis\bar\Cache\0011F0F4.bin
c:\program files\AskBarDis\bar\Cache\0011F634.bin
c:\program files\AskBarDis\bar\Cache\002CEB06.bin
c:\program files\AskBarDis\bar\Cache\002CF769.bin
c:\program files\AskBarDis\bar\Cache\002CF91F.bin
c:\program files\AskBarDis\bar\Cache\002CFA86.bin
c:\program files\AskBarDis\bar\Cache\002CFC3C.bin
c:\program files\AskBarDis\bar\Cache\008B967F
c:\program files\AskBarDis\bar\Cache\008BA5B1
c:\program files\AskBarDis\bar\Cache\008BAAB3
c:\program files\AskBarDis\bar\Cache\files.ini
c:\program files\AskBarDis\bar\History\search
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\bar\Settings\prevcfg.htm
c:\program files\AskBarDis\Thumbs.db
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\program files\AskBarDis\zonealarm.ico
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_ASKService
——-\Service_ASKService
((((((((((((((((((((((((( Files Created from 2010-02-06 to 2010-03-06 )))))))))))))))))))))))))))))))
.
2010-02-23 13:59 . 2010-02-23 13:59 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Toshiba
2010-02-23 13:59 . 2010-02-23 13:59 ——– d—–w- c:\documents and settings\All Users\Application Data\TOSHIBA
2010-02-23 13:53 . 2009-08-28 11:49 169064 —-a-w- c:\windows\system32\drivers\tosrfbd.sys
2010-02-23 13:53 . 2009-08-05 14:44 49400 —-a-w- c:\windows\system32\drivers\tosrfusb.sys
2010-02-23 13:53 . 2009-05-20 10:23 74368 —-a-w- c:\windows\system32\drivers\Tosrfhid.sys
2010-02-23 13:53 . 2009-07-24 11:31 21608 —-a-w- c:\windows\system32\drivers\tosrfnds.sys
2010-02-23 13:53 . 2009-06-11 14:05 36992 —-a-w- c:\windows\system32\drivers\tosrfbnp.sys
2010-02-23 13:53 . 2009-08-10 16:54 59888 —-a-w- c:\windows\system32\drivers\TosRfSnd.sys
2010-02-23 13:53 . 2009-07-28 20:01 69480 —-a-w- c:\windows\system32\drivers\tosrfcom.sys
2010-02-23 13:53 . 2009-06-17 11:59 46984 —-a-w- c:\windows\system32\drivers\tosporte.sys
2010-02-23 13:52 . 2010-02-23 13:52 ——– d—–w- c:\program files\Toshiba
2010-02-14 11:18 . 2010-02-14 11:18 ——– d—–w- c:\documents and settings\John\Application Data\Filter Forge Freepack 1 - Metals
2010-02-12 22:45 . 2010-02-12 22:45 ——– d—–w- c:\program files\Qtpfsgui
2010-02-12 11:22 . 2010-02-12 11:22 ——– d—–w- c:\windows\system32\Plugins
2010-02-11 18:17 . 2010-02-11 18:17 ——– d—–w- c:\documents and settings\John\Application Data\Filter Forge Freepack 2 - Photo Effects
2010-02-11 18:13 . 2010-02-11 18:23 ——– d—–w- c:\program files\virtualStudio
2010-02-11 18:11 . 2010-02-11 18:11 ——– d—–w- c:\program files\Filter Forge Freepack 4 - Distortions
2010-02-11 18:10 . 2010-02-11 18:10 ——– d—–w- c:\program files\Filter Forge Freepack 3 - Frames
2010-02-11 18:10 . 2010-02-11 18:10 ——– d—–w- c:\program files\Filter Forge Freepack 2 - Photo Effects
2010-02-11 18:10 . 2006-11-10 18:41 1030144 —-a-w- c:\windows\system32\dbghelp-xfw.dll
2010-02-11 18:10 . 2010-02-11 18:10 ——– d—–w- c:\program files\Filter Forge Freepack 1 - Metals
2010-02-11 18:07 . 2010-02-11 18:08 ——– d—–w- c:\program files\PluginSwitch
2010-02-07 22:17 . 2010-02-07 22:19 ——– d—–w- c:\program files\Blowfish Advanced CS
2010-02-07 17:35 . 2010-02-07 17:35 ——– d—–w- c:\documents and settings\All Users\Application Data\TrueCrypt
2010-02-07 17:35 . 2010-02-07 17:35 223440 —-a-w- c:\windows\system32\drivers\truecrypt.sys
2010-02-07 17:35 . 2010-02-07 17:35 ——– d—–w- c:\program files\TrueCrypt
2010-02-05 22:44 . 2010-02-05 22:44 ——– d—–w- c:\documents and settings\John\Application Data\Flexrise.9F3FBFC56E7DF11606748B3513468A7A7FB809D1.1
2010-02-05 22:43 . 2010-02-05 22:44 ——– d—–w- c:\program files\TPE
2010-02-05 22:43 . 2010-02-05 22:43 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-02-04 17:45 . 2010-02-04 17:45 ——– d—–w- c:\program files\Common Files\Macrovision Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-06 15:29 . 2007-04-28 21:57 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-03-06 11:56 . 2007-02-23 18:32 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-06 11:54 . 2009-10-18 16:57 ——– d—–w- c:\program files\PC Tools AntiVirus
2010-03-06 11:53 . 2006-11-05 13:00 ——– d—–w- c:\program files\Smart PC
2010-03-06 08:55 . 2010-01-28 11:47 ——– d—–w- c:\documents and settings\John\Application Data\MailWasherFree
2010-03-04 18:07 . 2009-10-18 17:22 389784 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-03-04 18:07 . 2009-10-18 17:21 3803208 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-03-04 18:06 . 2009-10-18 17:21 823928 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-03-04 18:06 . 2009-10-18 17:21 1181328 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-03-04 16:38 . 2005-03-30 09:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-15 22:35 . 2007-02-13 18:37 ——– d—–w- c:\program files\Picasa2
2010-02-12 17:19 . 2005-01-27 12:54 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-07 22:17 . 2010-02-07 22:17 766 —-a-r- c:\documents and settings\John\Application Data\Microsoft\Installer\{12B4E2C0-8D67-408D-86DF-119BEAAD5308}\ARPPRODUCTICON.exe
2010-02-07 22:17 . 2010-02-07 22:17 40960 —-a-r- c:\documents and settings\John\Application Data\Microsoft\Installer\{12B4E2C0-8D67-408D-86DF-119BEAAD5308}\NewShortcut1_12B4E2C08D67408D86DF119BEAAD5308.exe
2010-02-05 22:43 . 2010-02-05 22:40 38784 —-a-w- c:\documents and settings\John\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-05 22:27 . 2008-03-26 14:17 ——– d—–w- c:\program files\Bonjour
2010-02-05 18:19 . 2010-02-05 18:21 177152 —-a-w- c:\windows\Internet Logs\xDB6.tmp
2010-02-05 13:19 . 2005-03-11 23:09 214296 —-a-w- c:\documents and settings\John\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-04 23:40 . 2005-03-11 22:54 ——– d—–w- c:\program files\Common Files\Adobe
2010-02-02 17:41 . 2010-02-02 17:42 2153472 —-a-w- c:\windows\Internet Logs\xDB5.tmp
2010-02-02 13:26 . 2005-03-12 10:03 43810 —-a-w- c:\documents and settings\John\Application Data\wklnhst.dat
2010-01-28 11:54 . 2008-03-26 22:51 ——– d—–w- c:\program files\Uniblue
2010-01-28 11:35 . 2007-05-11 22:17 ——– d—–w- c:\documents and settings\John\Application Data\MailWasherPro
2010-01-23 16:34 . 2006-06-04 10:03 ——– d—–w- c:\documents and settings\John\Application Data\Blueberry
2010-01-17 23:31 . 2005-11-02 23:17 ——– d—–w- c:\program files\CCleaner
2010-01-14 11:27 . 2009-09-29 13:50 ——– d—–w- c:\program files\Jalbum
2010-01-12 00:15 . 2005-11-08 22:42 ——– d—–w- c:\documents and settings\John\Application Data\SafeIT Security
2010-01-12 00:13 . 2010-01-12 00:13 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7935BB0A-F573-4B8A-A0F8-1D087105ECFF}
2010-01-12 00:13 . 2008-03-20 17:35 ——– d—–w- c:\program files\SafeIT Security
2010-01-10 12:06 . 2005-03-19 21:42 ——– d—–w- c:\program files\PIXELA
2010-01-10 10:56 . 2005-03-19 21:41 ——– d—–w- c:\program files\FinePixViewer
2010-01-10 10:56 . 2005-11-23 23:21 ——– d—–w- c:\documents and settings\John\Application Data\FUJIFILM
2010-01-07 00:08 . 2005-03-30 09:48 ——– d—–w- c:\program files\FreshDevices
2010-01-07 00:03 . 2007-10-01 12:35 ——– d—–w- c:\program files\Britannica 7.0
2010-01-06 18:47 . 2010-01-06 18:49 1696768 —-a-w- c:\windows\Internet Logs\xDB4.tmp
2010-01-05 22:48 . 2009-04-20 13:21 10399769 —-a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-12-31 16:50 . 2005-01-26 14:32 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2005-01-26 14:32 916480 ——w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2005-01-27 12:03 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-15 18:25 . 2009-12-15 18:26 1627136 —-a-w- c:\windows\Internet Logs\xDB3.tmp
2009-12-15 16:57 . 2009-12-15 16:58 1626624 —-a-w- c:\windows\Internet Logs\xDB2.tmp
2009-12-15 15:09 . 2009-12-15 15:09 290816 —-a-w- c:\documents and settings\John\Application Data\SystemRequirementsLab\SRLProxy_nvd_4.dll
2009-12-15 15:09 . 2009-12-15 15:09 290816 —-a-w- c:\documents and settings\John\Application Data\SystemRequirementsLab\SRLProxy_nvd_3.dll
2009-12-15 15:09 . 2009-12-15 15:09 290816 —-a-w- c:\documents and settings\John\Application Data\SystemRequirementsLab\SRLProxy_nvd_2.dll
2009-12-15 15:09 . 2009-12-15 15:09 290816 —-a-w- c:\documents and settings\John\Application Data\SystemRequirementsLab\SRLProxy_nvd_1.dll
2009-12-15 09:44 . 2008-12-14 16:09 4330 —-a-w- c:\windows\system32\ealregsnapshot1.reg
2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-14 07:08 . 2005-01-26 14:32 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 . 2005-01-26 14:32 2189184 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-03 22:59 2066048 ——w- c:\windows\system32\ntkrnlpa.exe
2003-01-13 11:20 . 2005-01-27 15:34 278528 —-a-w- c:\program files\internet explorer\plugins\PanoViewer.dll
1999-04-30 16:00 . 2005-01-27 15:34 98304 —-a-w- c:\program files\internet explorer\plugins\UPjpeg.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-12-07 84480]
"CARPService"="carpserv.exe" [2003-03-18 4608]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"PCMService"="c:\program files\CyberLink\PowerCinema\PCMService.exe" [2005-01-19 110744]
"DSLAGENTEXE"="c:\program files\Voyager 105 ADSL Modem\dslagent.exe" [2004-05-27 16384]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-20 12669544]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
c:\documents and settings\John\Start Menu\Programs\Startup\
wkcalrem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-6-24 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCpl"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCTAVSvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^John^Start Menu^Programs^Startup^Registration Myst V]
path=c:\documents and settings\John\Start Menu\Programs\Startup\Registration Myst V
backup=c:\windows\pss\Registration Myst VStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 02:38 34672 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fix-It Utilities Express OLR]
2006-12-08 11:10 53248 —-a-w- c:\progra~1\BVRPSO~1\FIX-IT~1\BVRPOlr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Booster]
2008-01-18 11:55 14446592 —-a-w- c:\program files\inKline Global\PC Booster\PCBooster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Speed Up Your PC OLR]
2008-02-11 12:29 79104 —-a-w- c:\progra~1\BVRPSO~1\SPEEDU~1\BVRPOlr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-11-15 17:52 136600 —-a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerCinema\\PowerCinema.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Scribble\\Scribble.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [18/10/2009 17:23 64288]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [18/10/2009 16:57 206256]
R1 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [04/06/2006 10:03 2944]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [04/10/2004 04:47 98304]
R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [09/12/2008 23:10 24636]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [04/10/2004 03:40 118784]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [27/01/2005 12:40 945152]
R3 IMT0521;Inmax USB IMT-0521 Smartcard Reader;c:\windows\system32\drivers\IMT0521.sys [27/01/2005 12:57 34825]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 18:19 13592]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 11:17 1181328]
S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader;c:\windows\system32\drivers\SCR33X2K.sys [27/01/2005 12:57 63608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-03-04 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:06]
2010-03-04 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:06]
2010-03-04 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:06]
2010-03-04 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:06]
2010-03-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:06]
2010-02-16 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.targa.co.uk/
uInternet Settings,ProxyServer =
uInternet Settings,ProxyOverride = ;*.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: { - c:\program files\Messenger\msmsgs.exe
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
Trusted Zone: akamai.net
Trusted Zone: amazon.co.uk\www
Trusted Zone: ancestry.co.uk\content
Trusted Zone: ancestry.co.uk\search
Trusted Zone: ancestry.co.uk\secure
Trusted Zone: ancestry.co.uk\www
Trusted Zone: avg.com\akamai
Trusted Zone: avg.com\update
Trusted Zone: avg.cz\akamai
Trusted Zone: avg.cz\backup
Trusted Zone: avg.cz\download
Trusted Zone: avg.cz\files2
Trusted Zone: botanicalkeys.co.uk\www
Trusted Zone: brightminds.co.uk\www
Trusted Zone: daz3d.com\www
Trusted Zone: download.com
Trusted Zone: download.com\www
Trusted Zone: edgesuite.net\akamai.avg.com
Trusted Zone: edgesuite.net\akamai.avg.cz
Trusted Zone: edgesuite.net\akamai.grisoft.com
Trusted Zone: edgesuite.net\akamai.grisoft.cz
Trusted Zone: freebmd.org.uk\www
Trusted Zone: galaxyzoo.org\www
Trusted Zone: genesreunited.com\www
Trusted Zone: google.co.uk\www
Trusted Zone: grisoft.com\akamai
Trusted Zone: grisoft.com\free
Trusted Zone: grisoft.com\uodate
Trusted Zone: grisoft.com\www
Trusted Zone: grisoft.cz\akamai
Trusted Zone: grisoft.cz\download
Trusted Zone: grisoft.cz\files2
Trusted Zone: hotmail.com\www
Trusted Zone: lidl.co.uk\www
Trusted Zone: live.com\login
Trusted Zone: msn.co.uk\www
Trusted Zone: msn.com\by102fd.bay102.hotmail
Trusted Zone: msn.com\uk
Trusted Zone: msn.com\www
Trusted Zone: nationalarchives.gov.uk\www
Trusted Zone: netto.co.uk\www
Trusted Zone: networkmagic.com\www
Trusted Zone: open.ac.uk\www
Trusted Zone: scotlandspeople.gov.uk\www
Trusted Zone: spatial-literacy.org\www
Trusted Zone: symantec.com\www
Trusted Zone: zonealarm.com\www
FF - ProfilePath - c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\lzr4imv7.default\
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_uk&p=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\Photosynth\npPhotosynthMozilla.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-06 15:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1136272000-3068514121-1584837556-1006\Software\SecuROM\License information*]
"datasecu"=hex:82,44,c4,e9,12,c9,a8,8e,f3,1e,84,05,40,dc,0a,6d,bd,49,21,6b,1c,
f9,19,e0,d2,5e,ce,d8,47,91,f6,9d,2b,55,9d,d2,04,95,2d,53,94,0e,95,ec,1b,65,\
"rkeysecu"=hex:f1,c9,d9,0c,bb,85,91,60,89,fe,c3,34,13,96,9b,13
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(764)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
- - - - - - - > 'explorer.exe'(5252)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\windows\System32\SCardSvr.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\progra~1\VCOM\Fix-It\mxtask.exe
c:\xampp\mysql\bin\mysqld.exe
c:\program files\PC Tools AntiVirus\PCTAVSvc.exe
c:\progra~1\VCOM\Fix-It\mxtask.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\carpserv.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2010-03-06 15:36:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-06 15:36
ComboFix2.txt 2010-03-06 12:25
Pre-Run: 38,495,801,344 bytes free
Post-Run: 38,405,906,432 bytes free
- - End Of File - - 9426B06032766A05E804E3189F570DFF