ComboFix 09-07-22.05 - James 23/07/2009 15:18.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.1021.241 [GMT 1:00]
Running from: c:\users\James\Desktop\fatboy.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\windows\System32\drivers\ESQULdfqswbhvinndpkoxmsnqopuvigcwrppv.sys
c:\windows\system32\ESQULaupxibbxmepujibsnmbjwtiitmxyssuf.dll
c:\windows\system32\ESQULevskieesifrskppqytkyhlqwthqcttpc.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ESQULserv.sys
-------\Service_ESQULserv.sys
((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 )))))))))))))))))))))))))))))))
.
2009-07-23 14:26 . 2009-07-23 16:00 -------- d-----w- c:\users\James\AppData\Local\temp
2009-07-23 07:59 . 2009-07-23 08:01 -------- d-----w- c:\program files\QuickTime
2009-07-22 09:39 . 2009-07-22 09:39 2338816 ----a-w- c:\users\James\AppData\Roaming\Folding@home-x86\FahCore_78.exe
2009-07-21 23:11 . 2009-07-21 23:12 -------- d-----w- c:\program files\ERUNT
2009-07-21 22:52 . 2009-07-21 22:52 -------- d-----w- c:\program files\Trend Micro
2009-07-21 18:50 . 2009-07-21 18:50 10134 ----a-r- c:\users\James\AppData\Roaming\Microsoft\Installer\{6B755EC3-C709-4F5C-BC58-BC0D3967B6B6}\_D153F602E769D1960CE13B.exe
2009-07-21 18:50 . 2009-07-21 18:50 98477 ----a-r- c:\users\James\AppData\Roaming\Microsoft\Installer\{6B755EC3-C709-4F5C-BC58-BC0D3967B6B6}\_6FEFF9B68218417F98F549.exe
2009-07-21 18:50 . 2009-07-21 18:50 98477 ----a-r- c:\users\James\AppData\Roaming\Microsoft\Installer\{6B755EC3-C709-4F5C-BC58-BC0D3967B6B6}\_2377D972A0372FCB34E3F7.exe
2009-07-21 18:50 . 2009-07-22 09:40 -------- d-----w- c:\users\James\AppData\Roaming\Folding@home-x86
2009-07-21 18:50 . 2009-07-21 18:50 -------- d-----w- c:\program files\Folding@home
2009-07-21 18:19 . 2009-07-21 18:19 -------- d-----w- c:\users\James\AppData\Roaming\AVG8
2009-07-15 22:26 . 2009-07-15 22:26 390664 ----a-w- c:\users\James\AppData\Roaming\Real\RealPlayer\Update\realplayer11gold.exe
2009-07-15 22:26 . 2009-07-15 22:26 390664 ------w- c:\users\James\AppData\Roaming\Real\Update\temp\~Upg4\realplayer11gold.exe
2009-07-14 22:32 . 2009-07-14 22:32 339968 ----a-w- c:\windows\system32\pythoncom25.dll
2009-07-14 22:32 . 2009-07-14 22:32 114688 ----a-w- c:\windows\system32\pywintypes25.dll
2009-07-14 22:32 . 2009-07-14 22:32 2117632 ----a-w- c:\windows\system32\python25.dll
2009-07-14 22:32 . 2008-09-16 16:26 1332197 ----a-w- c:\windows\system32\pythondll.zip
2009-07-14 19:22 . 2009-06-15 15:24 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-14 19:22 . 2009-06-15 15:20 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-14 19:22 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-14 19:22 . 2009-06-15 12:52 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-13 00:52 . 2009-07-21 10:31 -------- d-----w- c:\users\James\AppData\Roaming\vlc
2009-07-13 00:48 . 2009-07-13 00:48 -------- d-----w- c:\program files\VideoLAN
2009-07-03 22:26 . 2009-07-03 22:26 390664 ----a-w- c:\users\James\AppData\Roaming\Real\Update\temp\~Upg3\realplayer11gold.exe
2009-06-24 22:26 . 2009-06-24 22:26 390664 ----a-w- c:\users\James\AppData\Roaming\Real\Update\temp\~Upg2\realplayer11gold.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-23 12:56 . 2008-11-20 01:19 -------- d-----w- c:\progra~2\Google Updater
2009-07-23 08:06 . 2008-11-24 15:09 -------- d-----w- c:\program files\Dl_cats
2009-07-22 23:06 . 2008-09-08 21:21 9052 ----a-w- c:\users\James\AppData\Local\d3d9caps.dat
2009-07-22 10:44 . 2008-12-03 16:22 -------- d-----w- c:\program files\Steam
2009-07-21 22:52 . 2009-04-13 16:30 -------- d-----w- c:\users\James\AppData\Roaming\Azureus
2009-07-21 20:32 . 2009-05-17 18:56 -------- d-----w- c:\users\James\AppData\Roaming\Spotify
2009-07-21 10:12 . 2009-06-03 23:44 -------- d-----w- c:\program files\Safari
2009-07-21 10:00 . 2008-09-10 17:48 -------- d-----w- c:\program files\iTunes
2009-07-21 10:00 . 2008-09-10 17:48 -------- d-----w- c:\program files\iPod
2009-07-21 10:00 . 2008-09-10 17:44 -------- d-----w- c:\program files\Common Files\Apple
2009-07-15 23:35 . 2008-09-19 09:41 -------- d-----w- c:\program files\Google
2009-07-15 00:58 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-07 23:17 . 2009-05-19 15:27 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-07 23:11 . 2008-09-19 20:55 -------- d-----w- c:\program files\DivX
2009-07-03 08:50 . 2008-12-03 16:22 -------- d-----w- c:\program files\Common Files\Steam
2009-07-01 00:17 . 2008-11-28 18:04 -------- d-----w- c:\progra~2\NVIDIA
2009-06-12 22:26 . 2009-06-12 22:26 390664 ----a-w- c:\users\James\AppData\Roaming\Real\Update\temp\~Upg1\realplayer11gold.exe
2009-06-11 09:58 . 2008-09-08 21:22 70176 ----a-w- c:\users\James\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-11 00:57 . 2008-10-08 20:49 -------- d-----w- c:\progra~2\Microsoft Help
2009-06-11 00:53 . 2008-09-18 18:40 -------- d-----w- c:\program files\Microsoft Works
2009-06-01 08:47 . 2009-06-01 08:47 10684866 ----a-w- c:\users\James\AppData\Roaming\Azureus\plugins\azump\mplayer.exe
2009-05-09 05:50 . 2009-06-10 09:21 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-10 09:20 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll
2009-04-30 12:37 . 2009-06-11 00:23 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-04-30 12:37 . 2009-06-11 00:23 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-07-23 11:06 . 2009-07-08 19:21 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2007-02-21 19:49 . 2007-02-21 19:49 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2008-08-01 1103216]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-20 39408]
"Google Update"="c:\users\James\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-05-23 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"DLCFCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCFtime.dll" [2006-10-20 73728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-13 177472]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-07 198160]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-17 4907008]
c:\users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-11-10 50688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{00959EC7-4F1A-46C8-8F1C-835D1A321ECF}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{1FCBE58F-FAAE-4C8B-89B5-CCEB9B23CE17}"= UDP:c:\program files\Kontiki\KService.exe

elivery Manager Service
"{8A5EC9C1-2B83-4EEF-BBD8-340A83A9A9EB}"= TCP:c:\program files\Kontiki\KService.exe

elivery Manager Service
"{100EA001-4DC7-42C5-8C25-E2562960174A}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{A0734E26-240B-47FB-A8A8-CE0BA2410556}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{A7E16BD1-FB93-4C89-BCEB-35197B727D01}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3574BE00-D7EE-4C9E-BE10-8975DF05C358}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{48A64B4E-30B2-4EFD-A172-A0943CFFBA7E}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{10D33C52-660E-4078-9BC8-B84A6381E2A0}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{52211553-D631-4C63-BD60-8B0D035D6773}"= UDP:c:\windows\System32\dlcfcoms.exe:Lexmark Communications System
"{14297CAD-C931-441E-8CFE-84446BBB8AD0}"= TCP:c:\windows\System32\dlcfcoms.exe:Lexmark Communications System
"{81C22815-E219-4726-B91D-C53142B5198F}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\dlcfpswx.exe

rinter Status Window
"{DE4A24E2-D746-485A-9239-B8876795E862}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\dlcfpswx.exe

rinter Status Window
"{8C8D0F2D-4F93-4AF0-AF9E-F7DC6FA3397C}"= UDP:c:\windows\System32\PnkBstrA.exe

nkBstrA
"{96A634F0-3F73-4C2A-90DD-B042B2520D22}"= TCP:c:\windows\System32\PnkBstrA.exe

nkBstrA
"{81BBB98F-5CAC-4438-90D7-4B2036100D46}"= UDP:c:\windows\System32\PnkBstrB.exe

nkBstrB
"{264A7B61-8BE1-4D2C-9F43-093ED3F3227B}"= TCP:c:\windows\System32\PnkBstrB.exe

nkBstrB
"{E79EE1C4-1246-4380-A828-35FAED385786}"= UDP:c:\program files\Steam\steamapps\common\zuma deluxe\Zuma.exe:Zuma Deluxe
"{FFE765E4-A161-4D2B-81B2-D0D23E640E41}"= TCP:c:\program files\Steam\steamapps\common\zuma deluxe\Zuma.exe:Zuma Deluxe
"{129AC2B5-2733-4585-8BEC-993CBD50817C}"= UDP:c:\program files\Steam\steamapps\common\peggle deluxe\Peggle.exe

eggle Deluxe
"{BCCFE4D9-9A6D-4A9E-9A59-19D53E23A3E3}"= TCP:c:\program files\Steam\steamapps\common\peggle deluxe\Peggle.exe

eggle Deluxe
"{5C530BCD-5F54-447A-8B57-2B845A5BC11E}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{319975AC-6D86-4763-A6C2-B16AB8F53F3E}"= UDP:c:\program files\Steam\steamapps\common\gravitron2\Gravitron2.exe:Gravitron 2
"{B95C72E6-539A-42D7-9C05-2EBCABDCCAB1}"= TCP:c:\program files\Steam\steamapps\common\gravitron2\Gravitron2.exe:Gravitron 2
"{B768E137-7E8B-4FBD-8096-F9371D9819D0}"= UDP:c:\program files\Steam\steamapps\common\amazing adventures the lost tomb\AmazingAdventures.exe:Amazing Adventures: The Lost Tomb
"{8DBC5050-87DB-431E-AB43-52A5B95E308B}"= TCP:c:\program files\Steam\steamapps\common\amazing adventures the lost tomb\AmazingAdventures.exe:Amazing Adventures: The Lost Tomb
"{F3529703-A70F-419A-B820-C135C47AA8F2}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{7D3E943B-E742-41DF-A59D-6B031220EC8E}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{E3BD7469-F26B-4DA6-8213-B5C74900B87C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{6B8FEDB0-1858-48FF-A5F3-B14E745CAB65}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{71B9F956-DCE1-41C9-9989-3C2B7D981F3F}c:\\program files\\novalogic\\delta force black hawk down\\update.exe"= UDP:c:\program files\novalogic\delta force black hawk down\update.exe:UPDATE
"UDP Query User{C36D8D4A-A815-418D-A0F6-18A410BFEB68}c:\\program files\\novalogic\\delta force black hawk down\\update.exe"= TCP:c:\program files\novalogic\delta force black hawk down\update.exe:UPDATE
"{E8156A9B-A436-4ABD-BBDD-DC1B84EC324C}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{A62CF99B-8FBF-44A0-8C3B-F57B20FF34BF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{749E1008-B574-4E3C-B814-9FDF945D1DA1}"= UDP:c:\program files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"{9F78C368-213C-44A0-B0A0-70412E35C71D}"= TCP:c:\program files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires III
"TCP Query User{7406BEF0-4F68-4846-A4B4-6BDED48228F7}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{97AD382F-28C8-4FBC-95DD-3862EF9FEBF3}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"TCP Query User{7B829B41-1CA5-4733-932C-9CF2FA8AF657}c:\\program files\\goa\\gunbound\\gunbound.gme"= UDP:c:\program files\goa\gunbound\gunbound.gme:GunBound
"UDP Query User{08C02C24-5909-4637-AD5D-334901606D15}c:\\program files\\goa\\gunbound\\gunbound.gme"= TCP:c:\program files\goa\gunbound\gunbound.gme:GunBound
"TCP Query User{03F7385F-12CE-4374-A68B-0490C669E588}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{5FC9D651-F776-48C0-AA5B-04C4D440F091}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"TCP Query User{C959DBC4-5275-4348-AC19-F43A3A7F3F1F}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
"UDP Query User{1D2233DB-2DF0-4613-B818-0E11889EDE5C}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify
"TCP Query User{E4AD4DC4-4199-4C5E-A908-C520D696F99B}c:\\program files\\steam\\steamapps\\jamster1981\\team fortress 2\\hl2.exe"= UDP:c:\program files\steam\steamapps\jamster1981\team fortress 2\hl2.exe:hl2
"UDP Query User{AA8398EA-959C-48D3-98AC-C03C23518947}c:\\program files\\steam\\steamapps\\jamster1981\\team fortress 2\\hl2.exe"= TCP:c:\program files\steam\steamapps\jamster1981\team fortress 2\hl2.exe:hl2
"{65D262BF-AD48-4814-91EA-A5BEEB125143}"= UDP:c:\program files\Kontiki\KService.exe

elivery Manager Service
"{942100DF-35F6-46E8-B40A-3D02CDA65BF6}"= TCP:c:\program files\Kontiki\KService.exe

elivery Manager Service
"TCP Query User{89765598-5C3A-45F9-AB1F-4700DB743E5F}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{4DCDC5D0-87C1-408A-923C-F550A2D774A0}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"{A07042AD-28F9-4DAE-8057-86005242E815}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{468A21D0-E39B-4DFB-A6BB-415581952D1E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 AERTFilters;Andrea RT Filters Service;c:\windows\System32\AERTSrv.exe [05/12/2007 06:17 77824]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30/03/2009 16:28 1533808]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [16/07/2009 00:11 133104]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [18/02/2009 05:53 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
Notify-GoToAssist - c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} -
http://www.sky.com
TCP: {2043C3A7-1431-4D9E-8EE7-18B9421892D2} = 192.168.0.1
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\users\James\AppData\Roaming\Mozilla\Firefox\Profiles\w7qne9e8.default\
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\James\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-23 17:00
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCFCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\dlcfcoms.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\users\James\AppData\Local\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-07-23 17:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-23 16:06
Pre-Run: 150,523,625,472 bytes free
Post-Run: 150,455,529,472 bytes free
292 --- E O F --- 2009-07-15 00:58