ComboFix 11-05-06.05 - excell 07/05/2011 21:55:16.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3581.2362 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-04-07 to 2011-05-07 )))))))))))))))))))))))))))))))
.
.
2011-05-07 21:04 . 2011-05-07 21:04 0 —ha-w- c:\users\excell\AppData\Local\BITD70C.tmp
2011-05-07 20:51 . 2011-05-07 20:53 ——– d—–w- C:\32788R22FWJFW
2011-05-07 18:20 . 2011-05-07 18:20 ——– d—–w- c:\users\excell\AppData\Local\{AF235023-E2C4-4775-AB10-48B79016AEFA}
2011-05-06 21:48 . 2011-05-06 21:48 ——– d—–w- c:\users\excell\AppData\Local\{4C187D52-10B9-4004-9287-25340BF6652D}
2011-05-06 09:48 . 2011-05-06 09:48 ——– d—–w- c:\users\excell\AppData\Local\{F5FE8FC4-C05B-4B92-8099-984008344AF8}
2011-05-05 14:32 . 2011-05-05 14:32 ——– d—–w- c:\users\excell\AppData\Local\{9F811721-EE46-49ED-A510-5194454EEDF7}
2011-05-05 00:36 . 2011-05-05 00:37 ——– d—–w- c:\users\excell\AppData\Local\{0431DF45-3BE8-4E7E-9C12-F8A48E732B83}
2011-05-04 11:32 . 2011-05-04 11:32 ——– d—–w- c:\users\excell\AppData\Local\{BABFFBF0-CB60-477D-BE58-D05D80E8F851}
2011-05-03 18:47 . 2011-05-03 18:48 ——– d—–w- c:\users\excell\AppData\Local\{C8AC50DF-0A43-40C9-95CF-F4A9A2A43972}
2011-05-02 21:10 . 2011-05-02 21:10 ——– d—–w- c:\users\excell\AppData\Local\{620EB4B7-02F7-43FB-97F9-915CEAA22DF1}
2011-05-01 23:00 . 2011-04-14 16:41 89048 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-05-01 23:00 . 2011-04-14 16:41 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-05-01 23:00 . 2011-04-14 16:41 465880 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-05-01 23:00 . 2011-04-14 16:41 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-05-01 23:00 . 2011-04-14 16:41 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-05-01 23:00 . 2011-04-14 16:41 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-05-01 23:00 . 2010-01-01 08:00 1974616 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-05-01 23:00 . 2010-01-01 08:00 1892184 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-05-01 14:59 . 2011-05-01 14:59 ——– d—–w- c:\users\excell\AppData\Local\{C7758D0B-A31C-4FED-AFB5-ACC707FE42C5}
2011-04-30 21:13 . 2011-04-30 21:14 ——– d—–w- c:\users\excell\AppData\Local\{4CC4D866-DECF-4F4E-B243-AE53374CFE50}
2011-04-29 20:01 . 2011-04-29 20:01 ——– d—–w- c:\users\excell\AppData\Local\Adobe
2011-04-29 19:38 . 2011-04-29 19:38 ——– d—–w- c:\users\excell\AppData\Local\{3D7554E8-D491-47A7-9643-F0402014FBEA}
2011-04-28 20:58 . 2011-04-28 20:58 ——– d—–w- c:\users\excell\AppData\Local\{54E279CE-1F5C-4377-975E-9EDAD5ACAF24}
2011-04-28 08:32 . 2011-04-28 08:32 ——– d—–w- c:\users\excell\AppData\Local\{B419B144-940F-4C8E-ACFC-97D33A3B064F}
2011-04-27 21:00 . 2011-04-27 21:00 ——– d—–w- c:\users\Default\AppData\Roaming\Trusteer
2011-04-27 19:49 . 2011-03-03 15:40 28672 —-a-w- c:\windows\system32\Apphlpdm.dll
2011-04-27 19:49 . 2011-03-03 13:35 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-04-27 19:48 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-04-27 19:43 . 2011-04-27 19:43 ——– d—–w- c:\users\excell\AppData\Local\{BFFD2B0A-FF9C-4096-9AC3-2B815D52704E}
2011-04-26 21:23 . 2011-04-26 21:24 ——– d—–w- c:\users\excell\AppData\Local\{86134DE3-CAE6-46A3-B905-3DDDA4A4D0A9}
2011-04-26 09:23 . 2011-04-26 09:23 ——– d—–w- c:\users\excell\AppData\Local\{697421A0-E4A4-4586-A635-24609F485104}
2011-04-25 20:50 . 2011-04-25 20:50 ——– d—–w- c:\users\excell\AppData\Local\{645A6CC2-659D-4227-AD72-522482686AE8}
2011-04-25 01:25 . 2011-04-25 01:26 ——– d—–w- c:\users\excell\AppData\Local\{4590A734-F852-4998-B289-19F830CF9E09}
2011-04-24 12:21 . 2011-04-24 12:21 ——– d—–w- c:\users\excell\AppData\Local\{A5A1474A-F92A-4555-9C49-DA6173A0888E}
2011-04-23 11:00 . 2011-04-23 11:00 ——– d—–w- c:\users\excell\AppData\Local\{CD633A71-8ED5-4520-9882-EDC3CB209611}
2011-04-22 22:59 . 2011-04-22 22:59 ——– d—–w- c:\users\excell\AppData\Local\{5A9956A3-DF4A-45BA-9125-FA45371A1167}
2011-04-22 10:59 . 2011-04-22 10:59 ——– d—–w- c:\users\excell\AppData\Local\{A9FEEA30-56EB-4DD0-A5E7-5BF8F69892F5}
2011-04-21 22:58 . 2011-04-21 22:59 ——– d—–w- c:\users\excell\AppData\Local\{72EF516C-1967-4D28-BBAD-CB8C89BF5758}
2011-04-21 10:58 . 2011-04-21 10:58 ——– d—–w- c:\users\excell\AppData\Local\{A4A4AFD4-F201-4443-9701-BD8D6DD9C5AC}
2011-04-20 22:21 . 2011-04-20 22:22 ——– d—–w- c:\users\excell\AppData\Local\{3C97D950-DB41-4673-A7C3-BB63197B94EA}
2011-04-20 10:17 . 2011-04-20 10:17 ——– d—–w- c:\users\excell\AppData\Local\{0AF2143B-B2D3-4793-B44C-DC90C4B1EC28}
2011-04-20 00:35 . 2011-04-18 10:23 16432 —-a-w- c:\windows\system32\lsdelete.exe
2011-04-19 22:22 . 2011-04-19 00:00 64512 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-04-19 22:22 . 2011-04-19 22:22 ——– d—–w- c:\users\excell\AppData\Local\Sunbelt Software
2011-04-19 22:22 . 2011-04-19 22:22 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-19 22:20 . 2011-04-19 22:20 ——– d—–w- c:\programdata\NVIDIA Corporation
2011-04-19 22:20 . 2011-04-19 22:21 ——– d—–w- c:\program files\NVIDIA Corporation
2011-04-19 22:16 . 2011-04-19 22:16 ——– dc-h–w- c:\programdata\{AA5544E4-9BBC-419B-9204-40B5924D26AA}
2011-04-19 22:16 . 2011-04-19 22:21 ——– d—–w- c:\programdata\Lavasoft
2011-04-19 22:16 . 2011-04-19 22:16 ——– d—–w- c:\program files\Lavasoft
2011-04-19 18:09 . 2011-04-19 18:09 ——– d—–w- c:\programdata\Skype Extras
2011-04-19 18:07 . 2011-04-19 18:07 ——– d—–w- c:\program files\Common Files\Skype
2011-04-19 13:45 . 2011-04-19 13:45 ——– d—–w- c:\users\excell\AppData\Local\{C69783B7-B45B-4BBF-A63F-5E7289641227}
2011-04-17 18:51 . 2011-04-17 18:51 ——– d—–w- c:\users\excell\AppData\Local\{F7C38C3C-7FB0-482F-9070-B90B62B4E2E7}
2011-04-16 21:23 . 2011-04-16 21:23 ——– d—–w- c:\users\excell\AppData\Local\{DFEFD1AA-D8EF-4E83-AE44-B25294D83125}
2011-04-16 01:16 . 2011-04-16 01:16 ——– d—–w- c:\users\excell\AppData\Local\Trusteer
2011-04-15 15:43 . 2011-04-15 15:43 ——– d—–w- c:\users\excell\AppData\Local\{21A3C44A-E0B6-42CB-B0B7-D626B54A4350}
2011-04-14 22:34 . 2011-04-14 22:34 ——– d—–w- c:\users\excell\AppData\Local\{A4016E36-B7F0-480F-B078-33570073C6AD}
2011-04-13 23:31 . 2011-04-13 23:31 ——– d—–w- c:\users\excell\AppData\Local\{A65F3E55-EC92-490D-9980-98988A6BA311}
2011-04-13 11:30 . 2011-04-13 11:31 ——– d—–w- c:\users\excell\AppData\Local\{F6290FFD-F9E1-4A23-8E3A-BA4E83A10CD5}
2011-04-12 22:36 . 2011-04-12 22:36 ——– d—–w- c:\users\excell\AppData\Roaming\DVDVideoSoftIEHelpers
2011-04-12 22:35 . 2011-05-07 20:51 ——– d—–w- c:\program files\DVDVideoSoft
2011-04-12 22:35 . 2011-05-07 20:51 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2011-04-12 22:25 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Roaming\Publish Providers
2011-04-12 22:25 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Roaming\NetMedia Providers
2011-04-12 22:25 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Roaming\Sony
2011-04-12 22:16 . 2011-04-12 22:25 ——– d—–w- c:\users\excell\AppData\Local\Sony
2011-04-12 21:49 . 2011-04-12 21:49 ——– d—–w- c:\program files\Sony
2011-04-12 21:10 . 2011-04-12 21:10 ——– d—–w- c:\users\excell\AppData\Local\{9970EEEE-87A7-48DB-9C3E-2976749BF6E8}
2011-04-12 13:08 . 2011-04-12 13:08 ——– d—–w- c:\users\excell\AppData\Local\{AAD184F9-6D04-4A7E-BFB2-ABD889EF11BF}
2011-04-11 13:12 . 2011-04-11 13:12 ——– d—–w- c:\users\excell\AppData\Local\{5CBA3A40-787A-4005-BAE4-3B1EEB3B08A5}
2011-04-09 19:59 . 2011-04-09 19:59 ——– d—–w- c:\users\excell\AppData\Local\{1696EDF9-A04A-4187-863C-DA5769EC09DE}
2011-04-09 17:16 . 2011-04-09 17:18 ——– d—–w- c:\program files\Nuclear Coffee
2011-04-08 13:38 . 2011-04-08 13:38 ——– d—–w- c:\users\excell\AppData\Local\{A17DCD1F-0B7B-41A9-BE93-8A8D1E88C88E}
2011-04-08 09:17 . 2011-04-08 09:17 53816 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2011-04-07 21:49 . 2011-04-07 21:49 ——– d—–w- c:\users\excell\AppData\Local\{D96A1BA5-21E9-4088-A881-28AD8A332E63}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-07 21:06 . 2011-05-07 21:06 0 —ha-w- c:\users\excell\AppData\Local\BITB481.tmp
2011-03-25 23:48 . 2011-03-25 23:48 4284416 —-a-w- c:\windows\system32\GPhotos.scr
2011-03-13 21:13 . 2011-03-13 21:13 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-03-11 23:17 . 2010-06-24 11:33 18328 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-03 15:40 . 2011-04-27 19:49 173056 —-a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-04-27 19:49 542720 —-a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-04-27 19:49 458752 —-a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-04-27 19:49 2159616 —-a-w- c:\windows\apppatch\AcGenral.dll
2011-02-22 14:13 . 2011-03-23 22:39 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33 . 2011-03-23 22:39 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33 . 2011-03-23 22:39 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-02-07 12:13 . 2010-12-29 01:41 80064 —-a-w- c:\windows\system32\drivers\inspect.sys
2011-02-07 12:13 . 2010-12-29 01:41 34744 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-02-07 12:13 . 2010-12-29 01:41 236600 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-02-07 12:13 . 2010-12-29 01:41 17256 —-a-w- c:\windows\system32\drivers\cmderd.sys
2011-04-14 16:41 . 2011-05-01 23:00 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-02-01 19:17 1487240 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-01 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-09-10 15:50 2957312 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-09-10 15:50 2957312 —-a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-10-25 167936]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-08 3444736]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-02-07 2548552]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-02-15 405504]
"PSQLLauncher"="c:\program files\Fingerprint Reader Suite\launcher.exe" [2007-04-16 49168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-11-24 50688]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-16 22:04 86528 —-a-w- c:\windows\System32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Users^excell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
path=c:\users\excell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 12:49 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-30 15:45 35736 —-a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CinemaNowMediaManagerApp]
2008-09-05 09:43 2017640 —-a-w- c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowShell.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Webcam Central]
2009-01-09 13:49 405639 ——w- c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2009-06-03 14:46 206064 —-a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-02-15 01:32 1230704 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eSnips_Downloader]
2010-05-24 11:30 1234432 —-a-w- c:\program files\Logia\eSnipsDownloader\eSnips_Downloader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-06-01 10:17 5252408 —-a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-11-10 02:54 4240760 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
2007-05-09 17:01 36864 —-a-w- c:\windows\OEM02Mon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 11:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 136176]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 136176]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-04-19 15232]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 Apache2.2;Remote Access Media Server;c:\program files\Common Files\Dell\apache\bin\httpd.exe [2007-09-21 15872]
R4 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe [2008-09-05 137080]
R4 dsl-db;Remote Access DB;c:\program files\Common Files\Dell\MySQL\bin\mysqld.exe [2007-09-14 5730304]
R4 dsl-fs-sync;Remote Access File Sync Service;c:\program files\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe [2009-04-13 189680]
R4 NAUpdate;Nero Update;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-04-19 64512]
S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2011-04-08 53816]
S1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\DRIVERS\cmderd.sys [2011-02-07 17256]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-02-07 236600]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-02-07 34744]
S1 RapportCerberus_26169;RapportCerberus_26169;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\26169\RapportCerberus_26169.sys [2011-05-02 57144]
S1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [2011-04-08 66360]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2011-04-08 158904]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\aestsrv.exe [2007-09-20 73728]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-05-02 2146496]
S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-04-08 870200]
S2 uvnc_service;UltraVNC Server;c:\programdata\UltraVNC\winvnc.exe [2008-08-31 1519168]
S2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc [x]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2008-12-30 144128]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-04-19 15:14]
.
2011-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 23:18]
.
2011-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-12 23:18]
.
2011-05-06 c:\windows\Tasks\User_Feed_Synchronization-{D0486C69-5E5B-4E65-BDF3-BB232D6413F3}.job
- c:\windows\system32\msfeedssync.exe [2011-04-14 04:43]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Free YouTube to MP3 Converter - c:\users\excell\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\excell\AppData\Roaming\Mozilla\Firefox\Profiles\a9zmt3eo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://www.google.com/webhp?ie=UTF-8&oe=UTF-8
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-07 22:05
Windows 6.0.6002 Service Pack 2 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1654437360-1725257235-4155127740-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*µ*~*%\OpenWithList]
@Class="Shell"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(724)
c:\windows\system32\guard32.dll
.
- - - - - - - > 'Explorer.exe'(1372)
c:\windows\system32\guard32.dll
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Fingerprint Reader Suite\upeksvr.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\WLANExt.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\BingBar\SeaPort.EXE
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_c09c50a2\STacSV.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\windows\system32\wbem\unsecapp.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
.
**************************************************************************
.
Completion time: 2011-05-07 22:10:04 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-07 21:10
.
Pre-Run: 74,564,980,736 bytes free
Post-Run: 73,830,756,352 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=66 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,
29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,
56,57,58,59,60,61,62,63,64,65,66
- - End Of File - - 389938CC5D7609E9A8D82D1E13B9B4C7