FIXLOG—BEGIN
Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 25-07-2012 01
Ran by [removed] at 2012-07-29 12:56:09 Run:1
Running from E:\
==============================================
HKEY_USERS\Day\Software\Microsoft\Windows\CurrentVersion\Run\\dhnsg Value deleted successfully.
C:\Users\Day\AppData\Roaming\dhnsg.dll moved successfully.
C:\Users\Day\AppData\Roaming\xsecva moved successfully.
C:\Windows\Installer\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde} moved successfully.
C:\Users\Day\AppData\Local\{49bd2ed2-e560-e76b-3efd-dd2e8c6b7cde} moved successfully.
C:\Windows\System32\services.exe moved successfully.
C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe copied successfully to C:\Windows\System32\services.exe
==== End of Fixlog ====
FIXLOG—END
COMBOFIX—BEGIN
ComboFix 12-07-29.02 - Day 07/29/2012 13:13:42.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3036.1822 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
C:\LHT2761.tmp
c:\programdata\SPL4624.tmp
c:\programdata\SPL8E3A.tmp
c:\programdata\SPL9A62.tmp
c:\programdata\SPLEBE7.tmp
c:\users\Day\AppData\Local\assembly\tmp
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome.manifest
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\background.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\browser.xul
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\crossrider.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\crossriderapi.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\dialog.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\facebox.css
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\facebox.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\b.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\bl.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\br.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\closelabel.gif
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\loading.gif
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\tl.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\facebox\Images\tr.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\faye-browser-min.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\lib\jquery-1.4.2.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\manage-apps-style.css
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\manage-apps.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\messaging.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\options.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\options.xul
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\push.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\search_dialog.xul
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\socialapi.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\update.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\utilityapi.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\chrome\content\workers_chain.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\defaults\preferences\prefs.js
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\install.rdf
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\locale\en-US\translations.dtd
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button1.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button2.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button3.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button4.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\button5.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\crossrider_statusbar.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\icon128.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\icon16.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\icon24.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\icon48.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\panelarrow-up.png
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\popup.css
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\popup.html
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\popup_binding.xml
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\skin.css
c:\users\Day\AppData\Roaming\Mozilla\Firefox\Profiles\yh5ohioo.default\extensions\[removed]\skin\update.css
c:\users\Day\Documents\~WRL0001.tmp
c:\windows\assembly\GAC\Desktop.ini
c:\windows\SwSys1.bmp
c:\windows\SwSys2.bmp
.
.
((((((((((((((((((((((((( Files Created from 2012-06-28 to 2012-07-29 )))))))))))))))))))))))))))))))
.
.
2012-07-29 20:14 . 2012-07-29 20:14 ——– d—–w- C:\FRST
2012-07-29 17:23 . 2012-07-29 17:28 ——– d—–w- c:\users\Day\AppData\Local\temp
2012-07-26 14:31 . 2012-07-26 14:39 ——– d—–w- C:\EOSRebelPics
2012-07-26 14:29 . 2012-07-26 14:29 ——– d—–w- c:\users\Day\AppData\Local\CANON_INC
2012-07-12 07:14 . 2012-06-13 13:40 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-07-11 13:37 . 2012-06-05 16:47 708608 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 13:37 . 2012-06-05 16:47 1401856 —-a-w- c:\windows\system32\msxml6.dll
2012-07-11 13:37 . 2012-06-05 16:47 1248768 —-a-w- c:\windows\system32\msxml3.dll
2012-07-11 13:37 . 2012-06-04 15:26 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-11 13:37 . 2012-06-02 00:04 278528 —-a-w- c:\windows\system32\schannel.dll
2012-07-11 13:37 . 2012-06-02 00:03 204288 —-a-w- c:\windows\system32\ncrypt.dll
2012-07-04 13:23 . 2011-05-23 09:52 153088 —-a-w- c:\windows\system32\xvid.ax
2012-07-04 13:23 . 2011-05-23 07:46 645632 —-a-w- c:\windows\system32\xvidcore.dll
2012-07-04 13:23 . 2011-05-30 13:42 240640 —-a-w- c:\windows\system32\xvidvfw.dll
2012-07-04 13:23 . 2012-07-04 13:23 ——– d—–w- c:\program files\Xvid
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-27 07:19 . 2012-04-01 16:14 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-27 07:19 . 2011-06-28 01:26 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-03 17:46 . 2011-03-29 22:30 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-03 16:21 . 2010-10-13 01:38 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 16:21 . 2011-07-30 12:58 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21 . 2010-10-13 01:38 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 16:21 . 2010-10-13 01:38 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 16:21 . 2010-10-13 01:38 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-03 16:21 . 2010-10-13 01:38 57656 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-07-03 16:21 . 2010-10-13 01:37 41224 —-a-w- c:\windows\avastSS.scr
2012-07-03 16:21 . 2010-10-13 01:37 227648 —-a-w- c:\windows\system32\aswBoot.exe
2012-06-29 08:44 . 2012-07-27 10:05 6891424 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F5B99034-0954-4DF4-892A-9471986FE45A}\mpengine.dll
2012-06-02 22:19 . 2012-06-19 04:27 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-19 04:27 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-19 04:26 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-19 04:26 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:19 . 2012-06-19 04:27 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:12 . 2012-06-19 04:27 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12 . 2012-06-19 04:26 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19 . 2012-06-19 04:26 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:12 . 2012-06-19 04:26 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-05-31 16:25 . 2010-03-21 02:13 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-05-26 22:29 . 2012-05-26 22:29 476960 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-05-26 22:29 . 2012-02-02 23:55 472864 —-a-w- c:\windows\system32\deployJava1.dll
2012-05-01 14:03 . 2012-06-13 23:52 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn1\YTNavAssist.dll" [2011-03-16 214840]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 —-a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2010-10-14 487424]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Akamai NetSession Interface"="c:\users\Day\AppData\Local\Akamai\netsession_win.exe" [2012-05-26 4327744]
"ooVoo.exe"="c:\program files\ooVoo\oovoo.exe" [2011-12-12 22459984]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-06-04 292208]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-02-19 438403]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2008-10-03 1742064]
"dldtmon.exe"="c:\program files\Dell V305\dldtmon.exe" [2010-02-10 672424]
"dldtamon"="c:\program files\Dell V305\dldtamon.exe" [2010-02-10 16040]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-08-25 442460]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-31 1616976]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-24 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-11-27 00:51 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Day^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
path=c:\users\Day\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
backup=c:\windows\pss\Dell Dock.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 —-a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2008-03-11 18:44 16384 —-a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2010-09-02 14:26 672632 —-a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-04-18 03:21 2938552 —-a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-09-02 19:15 13351304 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
LPDService REG_MULTI_SZ LPDSVC
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2012-02-03 00:25 114176 —-a-w- c:\windows\System32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-29 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 07:19]
.
2012-07-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-09-09 14:45]
.
2012-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-09 12:10]
.
2012-07-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-09 12:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
TCP: DhcpNameServer = 192.168.254.254
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-PlayNC Launcher - (no file)
HKLM-Run-NPSStartup - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-07-29 13:26
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_4f7fccd.dll"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe
c:\program files\Dell\DellDock\DockLogin.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dldtcoms.exe
c:\windows\system32\FsUsbExService.Exe
c:\windows\system32\WUDFHost.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Spybot - Search & Destroy\SDWinSec.exe
c:\program files\Dell V305\dldtMsdMon.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2012-07-29 13:35:18 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-29 17:35
.
Pre-Run: 175,524,311,040 bytes free
Post-Run: 175,825,031,168 bytes free
.
- - End Of File - - A6D9A33AD2DCDCAC19E678AC41A2646B
COMBOFIX—END