computer is faster now.here is combofix
ComboFix 11-01-31.02 - The Sizers 02/05/2011 11:36:36.4.1 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1348 [GMT -6:00]
Running from: c:\users\The Sizers\Downloads\ComboFix.exe
Command switches used :: c:\users\The Sizers\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\f08d2b
c:\programdata\f08d2b\1276eaa2910e83e58bb1136d5d16ef73.ocx
c:\programdata\f08d2b\4160fc86a653a494570e0cc1d00803a8.ocx
c:\programdata\f08d2b\5e7tm9q01u8zkrvov7tm9q01gjvvm9q01u8vop45e7tm9d5e7tm9qw.dll
c:\programdata\f08d2b\f08d2b6f00ed7f828d2c115a033bfe00.ocx
c:\programdata\f08d2b\mozcrt19.dll
c:\programdata\f08d2b\PIS.ico
c:\programdata\f08d2b\sqlite3.dll
c:\programdata\PIRTS
c:\programdata\PIRTS\PIIKDPFVS.cfg
.
((((((((((((((((((((((((( Files Created from 2011-01-05 to 2011-02-05 )))))))))))))))))))))))))))))))
.
2011-02-05 17:43 . 2011-02-05 17:44 -------- d-----w- c:\users\The Sizers\AppData\Local\temp
2011-02-05 17:43 . 2011-02-05 17:43 -------- d-----w- c:\users\Guest\AppData\Local\temp
2011-02-05 17:43 . 2011-02-05 17:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-05 00:53 . 2011-02-05 00:53 -------- d-----w- c:\program files\ESET
2011-02-05 00:46 . 2011-02-05 00:46 -------- d-----w- c:\program files\Common Files\Java
2011-02-05 00:15 . 2011-02-05 00:16 -------- d-----w- c:\program files\Common Files\Adobe
2011-02-04 01:21 . 2011-02-04 01:21 -------- d-----w- c:\users\The Sizers\AppData\Roaming\AVG10
2011-02-04 01:19 . 2011-02-04 01:19 -------- d--h--w- c:\programdata\Common Files
2011-02-04 01:17 . 2011-02-04 23:15 -------- d-----w- c:\programdata\AVG10
2011-02-04 00:52 . 2011-02-04 01:16 -------- d-----w- c:\programdata\MFAData
2011-02-03 01:36 . 2011-02-03 01:36 -------- d-----w- c:\program files\ERUNT
2011-02-02 23:02 . 2011-02-02 23:02 -------- d-----w- c:\windows\Sun
2011-01-27 01:13 . 2011-02-05 00:45 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-27 01:13 . 2011-02-05 00:45 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-01-27 01:09 . 2010-11-01 23:03 1448448 ----a-w- c:\windows\system32\inetcpl.cpl
2011-01-27 01:09 . 2010-11-01 22:59 2381824 ----a-w- c:\windows\system32\mshtml.tlb
2011-01-26 05:56 . 2010-08-17 23:54 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-26 05:56 . 2010-08-17 23:54 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-26 05:56 . 2010-08-17 23:52 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-26 05:56 . 2010-08-17 23:51 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-26 05:56 . 2010-08-17 23:51 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-26 05:56 . 2010-08-17 23:51 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-26 05:56 . 2010-08-17 23:49 1174528 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-26 05:56 . 2010-08-17 23:49 1068032 ----a-w- c:\windows\system32\DWrite.dll
2011-01-26 05:56 . 2010-08-17 23:49 797184 ----a-w- c:\windows\system32\FntCache.dll
2011-01-26 05:56 . 2010-08-17 23:48 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-26 05:56 . 2010-08-17 23:48 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-26 05:56 . 2010-08-17 23:50 680960 ----a-w- c:\windows\system32\d2d1.dll
2011-01-26 05:53 . 2011-01-26 05:53 -------- d-----w- c:\program files\Feedback Tool
2011-01-26 00:08 . 2011-01-20 16:39 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3FB7F439-FCED-4E67-B642-518F0AB4A977}\mpengine.dll
2011-01-25 09:01 . 2011-01-25 09:01 -------- d-----w- c:\program files\Microsoft.NET
2011-01-19 05:12 . 2009-11-08 16:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-01-19 05:12 . 2009-11-08 16:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-01-19 05:12 . 2009-11-08 16:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-01-19 05:12 . 2009-11-08 16:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-01-19 05:12 . 2009-11-08 16:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-01-19 05:05 . 2010-06-16 16:04 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-01-19 05:05 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2011-01-19 05:05 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2011-01-19 05:04 . 2010-10-28 13:20 2048 ----a-w- c:\windows\system32\tzres.dll
2011-01-19 05:02 . 2010-11-04 18:55 601600 ----a-w- c:\windows\system32\schedsvc.dll
2011-01-19 05:01 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-01-19 05:01 . 2010-08-20 16:05 867328 ----a-w- c:\windows\system32\wmpmde.dll
2011-01-19 05:01 . 2010-08-26 16:37 157184 ----a-w- c:\windows\system32\t2embed.dll
2011-01-19 05:01 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2011-01-19 05:01 . 2010-12-14 14:49 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-01-19 04:59 . 2010-05-27 20:08 81920 ----a-w- c:\windows\system32\iccvid.dll
2011-01-19 04:58 . 2010-08-31 15:46 954752 ----a-w- c:\windows\system32\mfc40.dll
2011-01-19 04:58 . 2010-08-31 15:46 954288 ----a-w- c:\windows\system32\mfc40u.dll
2011-01-19 04:58 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2011-01-19 04:58 . 2010-10-18 13:37 81920 ----a-w- c:\windows\system32\consent.exe
2011-01-19 04:58 . 2010-05-04 19:13 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-01-19 04:55 . 2010-08-31 15:44 531968 ----a-w- c:\windows\system32\comctl32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-26 07:06 . 2010-12-26 07:06 749832 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-12-21 00:09 . 2009-01-31 18:20 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 00:08 . 2009-01-31 18:20 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-29 23:38 . 2010-11-29 23:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 23:38 . 2010-11-29 23:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
.
((((((((((((((((((((((((((((( SnapShot@2011-02-04_23.39.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-23 21:53 . 2011-02-05 15:10 72224 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:05 . 2011-02-04 23:19 62264 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2011-02-05 15:10 62264 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-02-27 06:24 . 2011-02-05 15:10 17852 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1200996304-788045959-2936275167-1000_UserData.bin
- 2009-01-31 19:51 . 2011-02-04 03:10 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-31 19:51 . 2011-02-05 06:43 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-31 19:51 . 2011-02-04 03:10 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-31 19:51 . 2011-02-05 06:43 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-31 19:51 . 2011-02-05 06:43 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-31 19:51 . 2011-02-04 03:10 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-02-05 15:08 . 2011-02-05 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-02-04 23:17 . 2011-02-04 23:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-02-04 23:17 . 2011-02-04 23:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-02-05 15:08 . 2011-02-05 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2006-11-02 10:33 . 2011-02-04 23:23 606880 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2011-02-05 15:13 606880 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2011-02-04 23:23 105178 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2011-02-05 15:13 105178 c:\windows\System32\perfc009.dat
+ 2011-02-05 16:52 . 2011-02-05 16:52 233936 c:\windows\System32\Macromed\Flash\FlashUtil10l_Plugin.exe
- 2010-12-27 15:17 . 2010-12-27 15:17 233936 c:\windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.exe
+ 2011-02-05 00:29 . 2011-02-05 00:29 233936 c:\windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.exe
- 2010-12-27 15:17 . 2010-12-27 15:17 311248 c:\windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.dll
+ 2011-02-05 00:29 . 2011-02-05 00:29 311248 c:\windows\System32\Macromed\Flash\FlashUtil10l_ActiveX.dll
+ 2011-02-05 00:45 . 2011-02-05 00:45 157472 c:\windows\System32\javaws.exe
- 2011-01-27 01:13 . 2011-01-27 01:13 145184 c:\windows\System32\javaw.exe
+ 2011-02-05 00:45 . 2011-02-05 00:45 145184 c:\windows\System32\javaw.exe
- 2011-01-27 01:13 . 2011-01-27 01:13 145184 c:\windows\System32\java.exe
+ 2011-02-05 00:45 . 2011-02-05 00:45 145184 c:\windows\System32\java.exe
+ 2011-01-26 06:42 . 2011-02-05 06:45 272812 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2011-01-26 06:42 . 2011-02-04 23:16 272812 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-02-05 00:46 . 2011-02-05 00:46 180224 c:\windows\Installer\45ac5.msi
+ 2011-02-05 00:45 . 2011-02-05 00:45 677376 c:\windows\Installer\45abf.msi
+ 2011-02-05 16:52 . 2011-02-05 16:52 5971408 c:\windows\System32\Macromed\Flash\NPSWF32.dll
+ 2011-02-03 03:55 . 2011-02-05 06:45 5267472 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1200996304-788045959-2936275167-1000-12288.dat
+ 2011-02-05 00:17 . 2011-02-05 00:17 2519552 c:\windows\Installer\1ae20e.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-16 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-16 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-12-14 23:17 47904 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-15 03:17 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2007-10-04 02:02 1783136 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
2007-04-18 15:01 65536 ----a-w- c:\hp\support\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 23:16 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-03-18 23:50 4363504 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
2008-12-12 18:46 9555968 ----a-w- c:\program files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2007-12-26 22:34 8530464 ----a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2007-12-26 22:34 81920 ----a-w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
2007-12-26 22:34 86016 ----a-w- c:\windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
2008-04-01 01:54 507904 ----a-w- c:\program files\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OsdMaestro]
2007-02-15 11:59 118784 ----a-w- c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 23:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
2007-08-20 16:58 701736 ----a-w- c:\program files\Registry Mechanic\RMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-01-15 16:26 4874240 ----a-w- c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2008-02-01 23:22 21898024 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2008-04-01 18:49 36352 ----a-w- c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c8c2207b568970;Google Update Service (gupdate1c8c2207b568970);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-07 133104]
R3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\DRIVERS\NwUsbCdFil.sys [2008-07-07 20480]
R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys [2008-05-09 174336]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [2009-03-21 32408]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2011-02-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-30 17:59]
2011-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-31 05:11]
2011-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-31 05:11]
2011-02-05 c:\windows\Tasks\User_Feed_Synchronization-{A110AB10-5BD3-45B6-861B-1E9924F1496E}.job
- c:\windows\system32\msfeedssync.exe [2011-01-26 06:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath - c:\users\The Sizers\AppData\Roaming\Mozilla\Firefox\Profiles\v4g3d9ua.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-05 11:44
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1200996304-788045959-2936275167-1000\Software\SecuROM\License information*]
"datasecu"=hex:d3,c3,a4,62,70,a1,e0,37,50,38,56,f3,dc,94,16,f0,ae,37,4a,ff,b6,
11,08,42,24,d6,96,6e,7a,4d,dd,2f,f7,71,f0,fa,9e,d4,e2,71,90,36,e9,6c,33,f8,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-02-05 11:46:57
ComboFix-quarantined-files.txt 2011-02-05 17:46
ComboFix2.txt 2011-02-04 23:42
ComboFix3.txt 2011-02-04 00:14
ComboFix4.txt 2009-01-31 21:03
Pre-Run: 59,711,631,360 bytes free
Post-Run: 59,684,106,240 bytes free
- - End Of File - - 76C1201019AE6B477DB73BA51A93AEB2
here is dds
DDS (Ver_10-12-12.02) - NTFSx86
Run by The Sizers at 11:49:18.96 on Sat 02/05/2011
Internet Explorer: 9.0.7930.16406 BrowserJavaVersion: 1.6.0_23
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1167 [GMT -6:00]
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\alg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\unsecapp.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\The Sizers\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe" -delete
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 2 (0x2)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: c:\windows\system32\wpclsp.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\thesiz~1\appdata\roaming\mozilla\firefox\profiles\v4g3d9ua.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Move Media Player: moveplayer@movenetworks.com - %profile%\extensions\moveplayer@movenetworks.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-1-31 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-1-31 55024]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-1-31 1153368]
R3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-2 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1c8c2207b568970;Google Update Service (gupdate1c8c2207b568970);c:\program files\google\update\GoogleUpdate.exe [2009-1-31 133104]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [2008-7-7 20480]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2008-5-9 174336]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-1-31 7408]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\verizo~1\vzacce~1\SMSIVZAM5.SYS [2009-3-20 32408]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2011-02-05 17:47:03 -------- d-sh--w- C:\$RECYCLE.BIN
2011-02-05 17:46:58 -------- d-----w- c:\users\thesiz~1\appdata\local\temp
2011-02-05 00:53:58 -------- d-----w- c:\program files\ESET
2011-02-04 01:21:29 -------- d-----w- c:\users\thesiz~1\appdata\roaming\AVG10
2011-02-04 01:19:26 -------- d--h--w- c:\progra~2\Common Files
2011-02-04 01:17:23 -------- d-----w- c:\progra~2\AVG10
2011-02-04 00:52:38 -------- d-----w- c:\progra~2\MFAData
2011-02-04 00:01:50 89088 ----a-w- c:\windows\MBR.exe
2011-02-04 00:01:50 256512 ----a-w- c:\windows\PEV.exe
2011-01-27 01:13:47 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-27 01:13:47 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-01-27 01:09:12 2381824 ----a-w- c:\windows\system32\mshtml.tlb
2011-01-27 01:09:12 1448448 ----a-w- c:\windows\system32\inetcpl.cpl
2011-01-26 05:56:50 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-26 05:56:50 797184 ----a-w- c:\windows\system32\FntCache.dll
2011-01-26 05:56:50 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-26 05:56:50 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-26 05:56:50 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-26 05:56:50 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-26 05:56:50 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-26 05:56:50 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-26 05:56:50 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-26 05:56:50 1174528 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-26 05:56:50 1068032 ----a-w- c:\windows\system32\DWrite.dll
2011-01-26 05:56:49 680960 ----a-w- c:\windows\system32\d2d1.dll
2011-01-26 05:53:32 -------- d-----w- c:\program files\Feedback Tool
2011-01-26 00:08:37 5890896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{3fb7f439-fced-4e67-b642-518f0ab4a977}\mpengine.dll
2011-01-24 05:34:44 5890896 ------w- c:\progra~2\microsoft\windows defender\definition updates\updates\mpengine.dll
2011-01-19 05:12:39 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-01-19 05:12:38 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-01-19 05:12:38 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-01-19 05:12:38 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-01-19 05:12:38 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-01-19 05:05:24 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-01-19 05:05:05 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2011-01-19 05:05:05 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2011-01-19 05:04:38 2048 ----a-w- c:\windows\system32\tzres.dll
2011-01-19 05:02:55 601600 ----a-w- c:\windows\system32\schedsvc.dll
2011-01-19 05:01:26 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-01-19 05:01:24 867328 ----a-w- c:\windows\system32\wmpmde.dll
2011-01-19 05:01:22 157184 ----a-w- c:\windows\system32\t2embed.dll
2011-01-19 05:01:21 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2011-01-19 05:01:17 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-01-19 04:59:43 81920 ----a-w- c:\windows\system32\iccvid.dll
2011-01-19 04:58:45 954752 ----a-w- c:\windows\system32\mfc40.dll
2011-01-19 04:58:45 954288 ----a-w- c:\windows\system32\mfc40u.dll
2011-01-19 04:58:27 7680 ----a-w- c:\program files\internet explorer\iecompat.dll
2011-01-19 04:58:26 81920 ----a-w- c:\windows\system32\consent.exe
2011-01-19 04:58:01 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-01-19 04:55:04 531968 ----a-w- c:\windows\system32\comctl32.dll
==================== Find3M ====================
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32.dll
2010-11-29 23:38:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 23:38:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
============= FINISH: 11:49:38.57 ===============