ComboFix 09-11-27.05 - test 11/28/2009 6:07.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1533.978 [GMT -6:00]
Running from: c:\users\test\Desktop\ComboFix.exe
SP: CA AntiSpyware *enabled* (Updated) {6B98D35F-BB76-41C0-876B-A50645ED099A}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3135756699-365795455-3268573817-500
c:\$recycle.bin\S-1-5-21-3790955515-317854551-3382692383-1001
c:\$recycle.bin\S-1-5-21-3790955515-317854551-3382692383-1002
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-10-28 to 2009-11-28 )))))))))))))))))))))))))))))))
.
2009-11-28 12:15 . 2009-11-28 12:15 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-27 06:19 . 2009-11-24 23:39 1093064 ----a-w- c:\users\test\AppData\Roaming\Mozilla\Firefox\Profiles\vcub4ky9.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
2009-11-26 05:56 . 2009-11-26 05:57 4096 d-----w- c:\program files\Oblivion Savegame Manager V2
2009-11-24 15:59 . 2009-11-24 15:59 4096 d-----w- c:\program files\ERUNT
2009-11-21 20:54 . 2009-11-26 06:52 1 ----a-w- c:\users\test\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-21 20:53 . 2009-11-21 20:53 -------- d-----w- c:\users\test\AppData\Roaming\OpenOffice.org
2009-11-21 20:34 . 2009-11-21 20:34 7424000 ----a-r- c:\users\test\AppData\Roaming\Microsoft\Installer\{E6B87DC4-2B3D-4483-ADFF-E483BF718991}\soffice.exe
2009-11-21 20:32 . 2009-11-21 20:32 -------- d-----w- c:\program files\JRE
2009-11-21 20:32 . 2009-11-21 20:32 4096 d-----w- c:\program files\OpenOffice.org 3
2009-11-18 13:56 . 2009-11-18 13:56 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-18 13:53 . 2009-11-18 13:53 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2009-11-18 13:53 . 2009-11-18 13:53 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2009-11-18 13:53 . 2009-11-18 13:53 502272 ----a-w- c:\windows\system32\wlansvc.dll
2009-11-18 13:53 . 2009-11-18 13:53 47104 ----a-w- c:\windows\system32\wlanapi.dll
2009-11-18 13:53 . 2009-11-18 13:53 297984 ----a-w- c:\windows\system32\wlansec.dll
2009-11-18 13:53 . 2009-11-18 13:53 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2009-11-18 13:51 . 2009-11-18 13:51 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-11-18 13:51 . 2009-11-18 13:51 34304 ----a-w- c:\windows\system32\atmlib.dll
2009-11-18 13:51 . 2009-11-18 13:51 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-11-18 13:51 . 2009-11-18 13:51 24064 ----a-w- c:\windows\system32\lpk.dll
2009-11-18 13:51 . 2009-11-18 13:51 156160 ----a-w- c:\windows\system32\t2embed.dll
2009-11-18 13:51 . 2009-11-18 13:51 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-11-18 13:51 . 2009-11-18 13:51 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-11-18 13:49 . 2009-11-18 13:49 2855424 ----a-w- c:\windows\system32\mf.dll
2009-11-18 13:49 . 2009-11-18 13:49 98816 ----a-w- c:\windows\system32\mfps.dll
2009-11-18 13:49 . 2009-11-18 13:49 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2009-11-18 13:49 . 2009-11-18 13:49 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-11-18 13:49 . 2009-11-18 13:49 2048 ----a-w- c:\windows\system32\mferror.dll
2009-11-18 13:47 . 2009-11-18 13:47 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 13:47 . 2009-11-18 13:47 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-11-18 13:46 . 2009-11-18 13:46 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-11-18 13:46 . 2009-11-18 13:46 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-11-18 13:43 . 2009-11-18 13:43 156160 ----a-w- c:\windows\system32\wkssvc.dll
2009-11-18 13:43 . 2009-11-18 13:43 36352 ----a-w- c:\windows\system32\tsgqec.dll
2009-11-18 13:43 . 2009-11-18 13:43 1871872 ----a-w- c:\windows\system32\mstscax.dll
2009-11-18 13:43 . 2009-11-18 13:43 116736 ----a-w- c:\windows\system32\aaclient.dll
2009-11-18 13:42 . 2009-11-18 13:42 268800 ----a-w- c:\windows\system32\es.dll
2009-11-18 13:42 . 2009-11-03 02:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-18 13:38 . 2009-11-18 13:38 696832 ----a-w- c:\windows\system32\localspl.dll
2009-11-18 13:38 . 2009-11-18 13:38 88576 ----a-w- c:\windows\system32\avifil32.dll
2009-11-18 13:38 . 2009-11-18 13:38 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-11-18 13:38 . 2009-11-18 13:38 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-11-18 13:38 . 2009-11-18 13:38 31232 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-18 13:38 . 2009-11-18 13:38 12800 ----a-w- c:\windows\system32\msrle32.dll
2009-11-18 13:38 . 2009-11-18 13:38 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-11-18 13:37 . 2009-11-18 13:37 2923520 ----a-w- c:\windows\explorer.exe
2009-11-18 13:36 . 2009-11-18 13:36 494592 ----a-w- c:\windows\system32\kerberos.dll
2009-11-18 13:36 . 2009-11-18 13:36 7680 ----a-w- c:\windows\system32\lsass.exe
2009-11-18 13:36 . 2009-11-18 13:36 72704 ----a-w- c:\windows\system32\secur32.dll
2009-11-18 13:36 . 2009-11-18 13:36 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-11-18 13:36 . 2009-11-18 13:36 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-11-18 13:36 . 2009-11-18 13:36 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2009-11-18 13:36 . 2009-11-18 13:36 272384 ----a-w- c:\windows\system32\schannel.dll
2009-11-18 13:35 . 2009-11-18 13:35 24064 ----a-w- c:\windows\system32\netcfg.exe
2009-11-18 13:35 . 2009-11-18 13:35 29184 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2009-11-18 13:35 . 2009-11-18 13:35 220160 ----a-w- c:\windows\system32\drivers\bthport.sys
2009-11-18 13:35 . 2009-11-18 13:35 19456 ----a-w- c:\windows\system32\drivers\bthenum.sys
2009-11-18 13:35 . 2009-11-18 13:35 181760 ----a-w- c:\windows\system32\fsquirt.exe
2009-11-18 13:31 . 2009-11-18 13:31 549888 ----a-w- c:\windows\system32\rpcss.dll
2009-11-18 13:31 . 2009-11-18 13:31 654336 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-11-18 13:31 . 2009-11-18 13:31 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-11-18 13:31 . 2009-11-18 13:31 501760 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2009-11-18 13:31 . 2009-11-18 13:31 247296 ----a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2009-11-18 13:31 . 2009-11-18 13:31 24576 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-11-18 13:31 . 2009-11-18 13:31 130560 ----a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2009-11-18 13:31 . 2009-11-18 13:31 97280 ----a-w- c:\windows\system32\iasrecst.dll
2009-11-18 13:31 . 2009-11-18 13:31 53248 ----a-w- c:\windows\system32\iasads.dll
2009-11-18 13:31 . 2009-11-18 13:31 37888 ----a-w- c:\windows\system32\iasdatastore.dll
2009-11-18 13:31 . 2009-11-18 13:31 158720 ----a-w- c:\windows\system32\sdohlp.dll
2009-11-18 13:30 . 2009-11-18 13:30 2031104 ----a-w- c:\windows\system32\win32k.sys
2009-11-18 13:23 . 2009-11-18 13:23 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-11-18 13:22 . 2009-11-18 13:22 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-11-18 13:22 . 2009-11-18 13:22 321536 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-18 13:21 . 2009-11-18 13:21 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-11-18 12:08 . 2009-11-18 12:08 -------- d-----w- c:\windows\Downloaded Installations
2009-11-18 08:41 . 2009-11-18 10:01 8192 d-----w- c:\program files\Spybot
2009-11-18 08:20 . 2009-11-18 09:58 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-11-18 05:17 . 2009-11-24 16:33 -------- d--h--w- c:\windows\PIF
2009-11-12 14:11 . 2009-11-19 04:10 0 ----a-w- c:\windows\win32k.sys
2009-11-06 02:14 . 2009-11-06 02:14 41872 ----a-w- c:\windows\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-26 05:49 . 2009-07-08 17:55 4096 d-----w- c:\programdata\Xfire
2009-11-26 05:49 . 2009-07-08 17:55 8192 d-----w- c:\program files\Xfire
2009-11-25 17:38 . 2009-07-08 17:55 -------- d-----w- c:\users\test\AppData\Roaming\Xfire
2009-11-24 16:19 . 2007-11-09 00:22 1660 ----a-w- c:\windows\bthservsdp.dat
2009-11-21 20:50 . 2008-09-23 15:47 113632 ----a-w- c:\users\test\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-21 20:32 . 2007-11-09 01:50 -------- d-----w- c:\program files\Java
2009-11-18 14:01 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-18 13:52 . 2007-11-09 01:09 8192 d-----w- c:\programdata\Microsoft Help
2009-11-18 13:48 . 2009-11-18 13:48 72704 ----a-w- c:\windows\system32\admparse.dll
2009-11-18 13:48 . 2009-11-18 13:48 832512 ----a-w- c:\windows\system32\wininet.dll
2009-11-18 13:48 . 2009-11-18 13:48 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-11-18 13:48 . 2009-11-18 13:48 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-11-18 04:19 . 2009-04-28 20:41 12978 ----a-w- c:\users\test\AppData\Roaming\nvModes.dat
2009-11-18 03:45 . 2007-11-09 00:47 4096 d--h--w- c:\program files\InstallShield Installation Information
2009-11-18 02:41 . 2009-06-14 16:53 7484 ----a-w- c:\users\test\AppData\Local\d3d9caps.dat
2009-11-01 07:33 . 2007-11-09 02:05 158735559 ----a-w- c:\windows\DUMP7676.tmp
2009-10-20 09:10 . 2009-10-20 09:10 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-20 09:10 . 2009-10-20 09:10 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-20 09:10 . 2009-10-20 09:10 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-20 09:10 . 2009-10-20 09:10 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-20 09:09 . 2009-10-20 09:09 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-20 09:09 . 2009-10-20 09:09 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-20 09:09 . 2009-10-20 09:09 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-20 09:09 . 2009-10-20 09:09 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-20 09:09 . 2009-10-20 09:09 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-09-25 06:17 . 2009-09-08 05:15 54179488 ----a-w- c:\programdata\Xfire\downloads\Fallout3_1.7_English_US.exe
2009-09-02 21:48 . 2009-09-02 21:48 71680 ----a-w- c:\windows\system32\atl.dll
2009-09-02 21:48 . 2009-09-02 21:48 104448 ----a-w- c:\windows\system32\DWWIN.EXE
2009-09-02 21:44 . 2009-09-02 21:44 9728 ----a-w- c:\windows\system32\LAPRXY.DLL
2009-09-02 21:44 . 2009-09-02 21:44 223232 ----a-w- c:\windows\system32\WMASF.DLL
2009-09-02 21:44 . 2009-09-02 21:44 2048 ----a-w- c:\windows\system32\asferror.dll
2009-09-02 21:44 . 2009-09-02 21:44 25600 ----a-w- c:\windows\system32\amxread.dll
2009-09-02 21:44 . 2009-09-02 21:44 14848 ----a-w- c:\windows\system32\apilogen.dll
2009-09-02 21:44 . 2009-09-02 21:44 441856 ----a-w- c:\windows\system32\win32spl.dll
2009-09-02 21:44 . 2009-09-02 21:44 37376 ----a-w- c:\windows\system32\printcom.dll
2009-09-02 21:44 . 2009-09-02 21:44 14848 ----a-w- c:\windows\system32\wshrm.dll
2009-09-02 21:44 . 2009-09-02 21:44 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2009-09-02 21:43 . 2009-09-02 21:43 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-09-02 21:43 . 2009-09-02 21:43 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-09-02 21:43 . 2009-09-02 21:43 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-09-02 21:43 . 2009-09-02 21:43 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-09-02 21:43 . 2009-09-02 21:43 11776 ----a-w- c:\windows\system32\sbunattend.exe
2009-09-02 21:42 . 2009-09-02 21:42 290304 ----a-w- c:\windows\system32\drivers\srv.sys
2009-09-02 21:42 . 2009-09-02 21:42 83968 ----a-w- c:\windows\system32\dnsrslvr.dll
2009-09-02 21:42 . 2009-09-02 21:42 24576 ----a-w- c:\windows\system32\dnscacheugc.exe
2009-09-02 21:40 . 2009-09-02 21:40 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-09-02 21:40 . 2009-09-02 21:40 11264 ----a-w- c:\windows\system32\icardres.dll
2009-09-02 21:40 . 2009-09-02 21:40 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-09-02 21:39 . 2009-09-02 21:39 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-09-02 21:39 . 2009-09-02 21:39 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-09-02 21:39 . 2009-09-02 21:39 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-09-02 21:39 . 2009-09-02 21:39 326160 ----a-w- c:\windows\system32\PresentationHost.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-16 148888]
c:\users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
HP Connections.lnk - c:\program files\HP Connections\6811507\Program\HP Connections.exe [2007-11-8 34520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy2\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"WirelessAssistant"=c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"NvSvc"=RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
"QlbCtrl"=%ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
"QPService"="c:\program files\HP\QuickPlay\QPService.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3790955515-317854551-3382692383-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [10/18/2006 2:09 AM 73344]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [10/18/2006 2:09 AM 43904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
2009-11-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-26 06:46]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=laptop
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\test\AppData\Roaming\Mozilla\Firefox\Profiles\vcub4ky9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\users\test\AppData\Roaming\Mozilla\Firefox\Profiles\vcub4ky9.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Activation Assistant for the 2007 Microsoft Office suites - c:\programdata\{623D32E9-0C62-4453-AD44-98B31F52A5E1}\Microsoft Office Activation Assistant.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-HijackThis - g:\spybot\HijackThis.exe
AddRemove-NVIDIA Drivers - c:\windows\system32\NVUNINST.EXE UninstallGUI
AddRemove-Steam App 240 - c:\program files\Steam\steam.exe steam://uninstall/240
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-28 06:20
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8448E1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x82670d1f
\Driver\ACPI -> acpi.sys @ 0x804439d6
\Driver\atapi -> 0x8448e1f8
IoDeviceObjectType -> SecurityProcedure -> ntkrnlpa.exe @ 0x81d95467
\Device\Harddisk0\DR0 -> SecurityProcedure -> ntkrnlpa.exe @ 0x81d95467
Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\ehome\ehmsas.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLSched.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-11-28 06:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-28 12:24
Pre-Run: 36,616,740,864 bytes free
Post-Run: 36,550,516,736 bytes free
- - End Of File - - D7EC7C2587D78325631876717B85EAEB