Reboot still took forever, but some applications still seem to be running quicker, not as fast as they used to be… haven't tested Guild Wars yet, as it takes several minutes (sometimes up to 20mins) before Guild Wars slows down to 6fps…
ComboFix 09-01-09.01 - Timothy 2009-01-09 20:36:52.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2030.1424 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Timothy\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\bwUnin-6.1.4.68-8876480L.exe
c:\windows\system32\drivers\sp_rsdrv2.sys
c:\windows\system32\xa207039750.exe
c:\windows\system32\xa207040109.exe
c:\windows\system32\xa251165781.exe
c:\windows\system32\xa251166031.exe
c:\windows\system32\xa251284734.exe
c:\windows\system32\xa251284953.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Spyware Terminator
c:\documents and settings\All Users\Application Data\Spyware Terminator\BIN_IFL.SPT
c:\documents and settings\All Users\Application Data\Spyware Terminator\BIN_RSSID.SPT
c:\documents and settings\All Users\Application Data\Spyware Terminator\BIN_STDATA2.SPT
c:\documents and settings\All Users\Application Data\Spyware Terminator\BIN_STFDB.SPT
c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\BIN_STREVIEWS.SPT
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\info.htm
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\AllowMode.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\appguard0.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\appguard1.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\appguard2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\appguard3.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\appguard4.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\bg01.gif
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\bg02.gif
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\bg07.gif
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\clamguard0.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\clamguard1.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\DenyMode.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\Enhance_security.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\GeneralHips.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\GeneralRtp.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\info.ini
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\InstalDetected.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\Install_wsg.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\intguard0.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\intguard1.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\intguard2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\intguard3.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\intguard4.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\intguard5.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\language.inf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\language.ini
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\li.gif
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\li2.gif
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\ListShield.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\ListSource.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\ListType.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\offlinehelp.html
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\ScanAdvanced2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\scancustom.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\scancustom2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\ScanExtension2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\scanfast.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\scanfast2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\scanfull.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\scanfull2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\Scanfullvirus2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\scansmart2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\Scanvirus2a.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\Scanvirus2b.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\Scanvirus2c.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\SecurityCheck.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\SetHipsReb.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\sysguard0.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\sysguard1.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\sysguard2.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\sysguard3.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\top.gif
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\util01.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\util02.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\util03.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\LanguageAct\util04.rtf
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\scanConfig.xml
c:\documents and settings\Guild Wars\Application Data\Spyware Terminator\shields.xml
c:\documents and settings\Timothy\Application Data\Spyware Terminator
c:\documents and settings\Timothy\Application Data\Spyware Terminator\bin_streviews.spt
c:\documents and settings\Timothy\Application Data\Spyware Terminator\BIN_STRSBW.SPT
c:\documents and settings\Timothy\Application Data\Spyware Terminator\info.htm
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\AllowMode.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\appguard0.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\appguard1.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\appguard2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\appguard3.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\appguard4.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\bg01.gif
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\bg02.gif
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\bg07.gif
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\clamguard0.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\clamguard1.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\DenyMode.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\Enhance_security.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\GeneralHips.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\GeneralRtp.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\info.ini
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\InstalDetected.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\Install_wsg.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\intguard0.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\intguard1.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\intguard2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\intguard3.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\intguard4.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\intguard5.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\language.inf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\language.ini
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\li.gif
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\li2.gif
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\ListShield.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\ListSource.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\ListType.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\offlinehelp.html
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\ScanAdvanced2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\scancustom.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\scancustom2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\ScanExtension2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\scanfast.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\scanfast2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\scanfull.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\scanfull2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\Scanfullvirus2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\scansmart2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\Scanvirus2a.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\Scanvirus2b.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\Scanvirus2c.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\SecurityCheck.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\SetHipsReb.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\sysguard0.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\sysguard1.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\sysguard2.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\sysguard3.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\top.gif
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\util01.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\util02.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\util03.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\LanguageAct\util04.rtf
c:\documents and settings\Timothy\Application Data\Spyware Terminator\Reports\reports.dat
c:\documents and settings\Timothy\Application Data\Spyware Terminator\Reports\scan_0001.dat
c:\documents and settings\Timothy\Application Data\Spyware Terminator\Reports\scan_0002.dat
c:\documents and settings\Timothy\Application Data\Spyware Terminator\Reports\scan_0003.dat
c:\documents and settings\Timothy\Application Data\Spyware Terminator\Reports\scan_0004.dat
c:\documents and settings\Timothy\Application Data\Spyware Terminator\Reports\supportReport.txt
c:\documents and settings\Timothy\Application Data\Spyware Terminator\scanConfig.xml
c:\documents and settings\Timothy\Application Data\Spyware Terminator\shields.xml
c:\program files\Spyware Terminator
c:\program files\Spyware Terminator\BIN_RSCSDA.SPF
c:\program files\Spyware Terminator\BIN_STQUEUE.SPT
c:\program files\Spyware Terminator\BIN_STUIUS.SPT
c:\program files\Spyware Terminator\history.txt
c:\program files\Spyware Terminator\languages\ST_BRAZILIANS.cab
c:\program files\Spyware Terminator\languages\ST_CATALAN.cab
c:\program files\Spyware Terminator\languages\ST_CZECH.cab
c:\program files\Spyware Terminator\languages\ST_DUTCH.cab
c:\program files\Spyware Terminator\languages\ST_ENGLISH.cab
c:\program files\Spyware Terminator\languages\ST_FRENCH.cab
c:\program files\Spyware Terminator\languages\ST_GERMAN.cab
c:\program files\Spyware Terminator\languages\ST_HUNGARIAN.cab
c:\program files\Spyware Terminator\languages\ST_ITALIANO.cab
c:\program files\Spyware Terminator\languages\ST_POLISH.cab
c:\program files\Spyware Terminator\languages\ST_PORTUGUESE.cab
c:\program files\Spyware Terminator\languages\ST_RUSSIAN.cab
c:\program files\Spyware Terminator\languages\ST_SERBIAN.cab
c:\program files\Spyware Terminator\languages\ST_SPANISH.cab
c:\program files\Spyware Terminator\languages\ST_VALENCIAN.cab
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\Spyware Terminator\sp_rsser.exe.ulog
c:\program files\Spyware Terminator\sptcontmenu.dll
c:\program files\Spyware Terminator\SpywareTerminator.Exe
c:\program files\Spyware Terminator\SpywareTerminator.Exe.old
c:\program files\Spyware Terminator\SpywareTerminator.exe.ulog
c:\program files\Spyware Terminator\SpywareTerminatorShield.Exe
c:\program files\Spyware Terminator\SpywareTerminatorShield.exe.err
c:\program files\Spyware Terminator\SpywareTerminatorShield.exe.ulog
c:\program files\Spyware Terminator\unins000.dat
c:\program files\Spyware Terminator\unins000.exe
c:\windows\bwUnin-6.1.4.68-8876480L.exe
c:\windows\system32\drivers\sp_rsdrv2.sys
c:\windows\system32\xa207039750.exe
c:\windows\system32\xa207040109.exe
c:\windows\system32\xa251165781.exe
c:\windows\system32\xa251166031.exe
c:\windows\system32\xa251284734.exe
c:\windows\system32\xa251284953.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_SP_RSDRV2
——-\Service_sp_rsdrv2
((((((((((((((((((((((((( Files Created from 2008-12-10 to 2009-01-10 )))))))))))))))))))))))))))))))
.
2009-01-09 18:45 . 2009-01-09 18:45 d——– c:\program files\BillP Studios
2009-01-09 18:45 . 2009-01-09 18:45 d——– c:\documents and settings\Timothy\Application Data\WinPatrol
2009-01-09 17:21 . 2009-01-09 17:21 d——– c:\program files\Common Files\Adobe AIR
2009-01-09 17:21 . 2009-01-09 17:21 d——– c:\program files\Adobe Media Player
2009-01-09 16:00 . 2009-01-09 16:00 d——– c:\documents and settings\All Users\Application Data\Electronic Arts
2009-01-09 01:51 . 2009-01-09 01:51 d——– c:\documents and settings\Timothy\Application Data\DAZ 3D
2009-01-09 01:44 . 2009-01-09 01:44 d——– c:\program files\DAZ
2009-01-06 03:00 . 2009-01-06 03:00 d——– c:\program files\Microsoft CAPICOM 2.1.0.2
2009-01-06 02:09 . 2009-01-06 02:09 d——– c:\program files\Trend Micro
2009-01-05 13:14 . 2009-01-05 13:14 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-05 13:14 . 2009-01-05 13:14 d——– c:\documents and settings\Timothy\Application Data\Malwarebytes
2009-01-05 13:14 . 2009-01-05 13:14 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-05 13:14 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-05 13:14 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-05 12:38 . 2009-01-05 12:38 d——– c:\program files\Enigma Software Group
2008-12-31 12:36 . 2008-12-31 12:36 d——– c:\program files\Babylon
2008-12-31 12:36 . 2008-12-31 19:02 d——– c:\documents and settings\Timothy\Application Data\Babylon
2008-12-31 12:36 . 2009-01-04 23:09 d——– c:\documents and settings\All Users\Application Data\Babylon
2008-12-31 12:11 . 2008-12-31 12:11 d——– c:\program files\Activision
2008-12-29 21:23 . 2008-12-29 21:27 d——– c:\documents and settings\Timothy\Application Data\U3
2008-12-24 03:16 . 2008-12-24 03:16 d——– c:\program files\Games
2008-12-12 19:48 . 2008-12-12 19:48 d——– c:\documents and settings\Guild Wars\Application Data\AVGTOOLBAR
2008-12-12 19:11 . 2008-12-12 19:11 d——– c:\program files\PowerQuest
2008-12-10 11:31 . 2008-10-10 04:52 4,379,984 –a—— c:\windows\system32\D3DX9_40.dll
2008-12-10 11:31 . 2008-10-10 04:52 2,036,576 –a—— c:\windows\system32\D3DCompiler_40.dll
2008-12-10 11:31 . 2008-10-27 10:04 514,384 –a—— c:\windows\system32\XAudio2_3.dll
2008-12-10 11:31 . 2008-10-10 04:52 452,440 –a—— c:\windows\system32\d3dx10_40.dll
2008-12-10 11:31 . 2008-10-27 10:04 235,856 –a—— c:\windows\system32\xactengine3_3.dll
2008-12-10 11:31 . 2008-10-27 10:04 70,992 –a—— c:\windows\system32\XAPOFX1_2.dll
2008-12-10 11:31 . 2008-10-27 10:04 23,376 –a—— c:\windows\system32\X3DAudio1_5.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-09 22:41 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-09 20:47 ——— d—–w c:\program files\Azureus
2009-01-09 20:47 ——— d—–w c:\documents and settings\Timothy\Application Data\Azureus
2009-01-09 06:45 ——— d—–w c:\program files\Common Files\DAZ
2009-01-09 06:42 ——— d—–w c:\program files\GomPlayer
2009-01-06 23:54 ——— d—–w c:\program files\LimeWire
2009-01-06 22:06 ——— d—–w c:\documents and settings\Timothy\Application Data\LimeWire
2009-01-06 07:50 ——— d—–w c:\program files\PokerStars.NET
2009-01-05 04:02 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-12-31 17:11 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-30 17:24 ——— d—–w c:\documents and settings\Timothy\Application Data\Ahead
2008-12-29 08:00 ——— d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-24 22:03 ——— d—–w c:\program files\PKR
2008-12-24 21:45 ——— d—–w c:\program files\Mystery Case Files 4-in-1
2008-12-19 22:10 ——— d—–w c:\program files\Blackberry
2008-12-16 18:37 ——— d—–w c:\documents and settings\Timothy\Application Data\SPORE
2008-12-16 18:23 ——— d—–w c:\program files\SPORE
2008-12-10 20:35 ——— d—–w c:\program files\DefilerPak
2008-12-10 20:34 ——— d—–w c:\program files\TVersity Codec Pack
2008-12-09 23:29 ——— d—–w c:\program files\Quicken
2008-12-09 23:28 ——— d—–w c:\documents and settings\Guild Wars\Application Data\Intuit
2008-12-09 20:48 ——— d—–w c:\documents and settings\Guild Wars\Application Data\Ventrilo
2008-12-04 03:21 ——— d—–w c:\documents and settings\Timothy\Application Data\Ventrilo
2008-12-04 02:59 ——— d—–w c:\program files\Ventrilo
2008-12-04 02:59 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-03 23:07 ——— d—–w c:\program files\Java
2008-12-03 00:17 ——— d—–w c:\program files\Common Files\Logitech
2008-12-02 00:28 ——— d—–w c:\program files\Roxio
2008-12-02 00:28 ——— d—–w c:\program files\Common Files\Sonic Shared
2008-12-02 00:28 ——— d—–w c:\documents and settings\All Users\Application Data\Roxio
2008-12-02 00:21 ——— d—–w c:\program files\Common Files\Roxio Shared
2008-12-01 05:35 ——— d—–w c:\documents and settings\Timothy\Application Data\dvdcss
2008-12-01 01:24 ——— d—–w c:\program files\Logitech
2008-12-01 01:24 ——— d—–w c:\program files\Common Files\FotoWire
2008-12-01 01:24 ——— d—–w c:\documents and settings\Timothy\Application Data\FotoWire
2008-11-27 07:29 ——— d—–w c:\program files\IrfanView
2008-11-23 16:38 ——— d—–w c:\program files\FriendFinder
2008-11-21 18:25 ——— d—–w c:\program files\thriXXX
2008-11-21 18:16 ——— d—–w c:\program files\Red Light District
2008-11-21 16:43 ——— d—–w c:\program files\AllToAVI
2008-11-19 03:44 ——— d—–w c:\program files\NVIDIA
2008-11-19 03:19 ——— d—–w c:\program files\SystemRequirementsLab
2008-11-19 03:19 ——— d—–w c:\documents and settings\Timothy\Application Data\SystemRequirementsLab
2008-11-18 23:16 ——— d—–w c:\program files\Belarc
2008-11-15 03:05 ——— d—–w c:\program files\AGEIA Technologies
2008-11-14 02:19 ——— d–h–r c:\documents and settings\Timothy\Application Data\SecuROM
2008-11-14 01:58 ——— d—–w c:\program files\Electronic Arts
.
((((((((((((((((((((((((((((( snapshot@2009-01-09_16.05.37.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-05 03:16:26 235,936 —-a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
+ 2009-01-09 22:17:56 89,102 —-a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-01-10 01:40:53 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_294.dat
+ 2009-01-10 01:38:48 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_f8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-07-27 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-01-07 3321856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-09-21 9138176]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-03 136600]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xvid"= xvid.dll
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
–a—— 2008-01-11 18:54 623992 c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
–a—— 2008-11-27 09:13 1261336 c:\progra~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
–a—— 2008-09-01 12:59 3563232 c:\program files\Babylon\Babylon-Pro\Babylon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\demoxi identity]
–a—— 2008-08-15 13:56 368722 c:\program files\demoxi\identity\
0.8.1.2658\bin\demoxi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DT ACR]
–a—— 2008-06-06 10:39 81920 c:\program files\Common Files\Portrait Displays\Shared\DT_Startup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMC]
–a—— 2008-01-14 12:14 4053102 c:\program files\FriendFinder\FriendFinder Messenger 4\imc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
–a—— 2007-07-18 16:55 451872 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Name of App]
–a—— 2008-07-07 12:12 675935 c:\program files\SAMSUNG\FW LiveUpdate\FWManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PivotSoftware]
–a—— 2007-02-09 11:17 694008 c:\program files\Portrait Displays\Pivot Software\wpCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
–a—— 2008-06-26 12:22 236016 c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sp_rssrv"=2 (0x2)
"LightScribeService"=2 (0x2)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\mIRC\\mirc.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\World Series of Poker\\WSOPTOC.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero MediaHome\\NeroMediaHome.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero MediaHome\\NMMediaServer.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\demoxi\\identity\\
0.8.1.2658\\bin\\demoxi.exe"=
"c:\\Program Files\\e frontier\\Poser 7\\Poser.exe"=
"c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\SPORE\\Sporebin\\SporeApp.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-10 97928]
R4 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-07-10 76040]
R4 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [2008-09-28 2560]
R4 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2008-08-29 90112]
S4 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-12 875288]
S4 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-12 231704]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0027f67c-c108-11dd-abb9-0019d1a0f0aa}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6072f12c-3bf4-11dd-b902-806d6172696f}]
\Shell\AutoRun\command - F:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7fc64b34-3e09-11dd-919a-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-SpywareTerminator - c:\program files\Spyware Terminator\SpywareTerminatorShield.exe
.
——- Supplementary Scan ——-
.
uStart Page = www.google.com
uInternet Settings,ProxyOverride = *.local;localhost
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
TCP: {8617295F-39C4-4611-BBFA-26DF349310FF} = 68.105.28.11,68.105.29.11,68.105.28.12
FF - ProfilePath - c:\documents and settings\Timothy\Application Data\Mozilla\Firefox\Profiles\1xfzawrn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPBelv32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-09 20:40:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1757981266-1417001333-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:d3,1a,ca,a8,85,de,86,3b,ba,18,28,c8,64,4d,42,d0,b1,ae,ca,c0,b7,
e8,dc,ae,08,fb,a2,30,be,b1,9b,0d,c3,e7,3e,1d,dc,93,3a,bc,5f,ae,e8,c0,d1,89,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \DA9879757777DAE8]
"1"=hex:ed,4b,4a,ed,15,23,49,74,5a,62,6c,ea,06,f6,a6,df
"2"=hex:a9,40,80,f3,45,2c,d5,a1,17,53,11,d7,21,de,a4,9e,70,5f,a0,52,5b,27,ae,
65,1c,9d,59,02,eb,37,2c,7a,87,23,4c,1a,3f,83,53,96
"3"=hex:ed,4b,4a,ed,15,23,49,74,b0,26,52,ff,a0,7d,07,31,e6,5f,d4,da,fb,3f,90,
71,75,14,ea,42,77,9a,7a,ec,d4,b7,cc,3b,f4,0a,33,5b,a4,1e,da,46,25,2d,2a,72,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \DA9879757777DAE8\A4C6DC1D7052183A161573F7BA846387]
"1"=hex:1a,dd,98,10,b1,7c,5d,e1
"2"=hex:67,36,6f,c1,0f,6f,49,c8
"3"=hex:81,20,8f,ab,28,6a,52,9c
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:ed,4b,4a,ed,15,23,49,74,5a,02,d0,c7,f9,dd,f2,e5,3e,e0,99,3d,a8,68,9c,
4f,1f,71,fc,13,23,3b,2c,6b,94,db,ee,08,97,0d,d7,27,bf,b9,1b,eb,26,77,8c,fe,\
"8"=hex:2f,58,fa,50,0e,94,d9,4e,9c,5b,7c,50,84,c6,03,27,ab,3c,9e,bc,1a,ba,04,
35
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:b6,dd,00,4d,9d,38,11,d1
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
[HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\HID\Vid_05fe&Pid_1010&MI_01&Col01\7&62d9050&0&0000\LogConf]
@DACL=(02 0000)
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\TVersity\Media Server\MediaServer.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
c:\program files\Mozilla Firefox\firefox.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2009-01-09 20:44:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-10 01:44:38
ComboFix2.txt 2009-01-10 01:20:59
ComboFix3.txt 2009-01-09 23:24:30
ComboFix4.txt 2009-01-09 21:06:46
Pre-Run: 27,182,985,216 bytes free
Post-Run: 27,078,275,072 bytes free
490 — E O F — 2009-01-06 08:00:22
-Rappy