ComboFix Log
ComboFix 09-09-09.09 - Rick 09/10/2009 13:17.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.445.259 [GMT -4:00]
Running from: c:\documents and settings\Rick\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\anan.ban
c:\documents and settings\All Users\Documents\duzejyhyd.bin
c:\documents and settings\Rick\Application Data\acahysuxum.dl
c:\documents and settings\Rick\Application Data\yvudopuz.bin
c:\documents and settings\Rick\Cookies\awokewice._dl
c:\documents and settings\Rick\Cookies\odebaxive.scr
c:\documents and settings\Rick\Cookies\zimukewo.dl
c:\documents and settings\Rick\Local Settings\Application Data\ezefaxulen.scr
c:\documents and settings\Rick\Local Settings\Application Data\kivytiw.bin
c:\documents and settings\Rick\Local Settings\Temporary Internet Files\ubobapym._sy
c:\documents and settings\Rick\Local Settings\Temporary Internet Files\vuzybawemi._dl
c:\documents and settings\Rick\My Documents\ZbThumbnail.info
c:\documents and settings\Rick\Uhaul .wps
c:\program files\Windows Police Pro
c:\program files\Windows Police Pro\msvcm80.dll
c:\program files\Windows Police Pro\msvcp80.dll
c:\program files\Windows Police Pro\msvcr80.dll
c:\program files\Windows Police Pro\tmp\dbsinit.exe
c:\program files\Windows Police Pro\tmp\images\i1.gif
c:\program files\Windows Police Pro\tmp\images\i2.gif
c:\program files\Windows Police Pro\tmp\images\i3.gif
c:\program files\Windows Police Pro\tmp\images\j1.gif
c:\program files\Windows Police Pro\tmp\images\j2.gif
c:\program files\Windows Police Pro\tmp\images\j3.gif
c:\program files\Windows Police Pro\tmp\images\jj1.gif
c:\program files\Windows Police Pro\tmp\images\jj2.gif
c:\program files\Windows Police Pro\tmp\images\jj3.gif
c:\program files\Windows Police Pro\tmp\images\l1.gif
c:\program files\Windows Police Pro\tmp\images\l2.gif
c:\program files\Windows Police Pro\tmp\images\l3.gif
c:\program files\Windows Police Pro\tmp\images\pix.gif
c:\program files\Windows Police Pro\tmp\images\t1.gif
c:\program files\Windows Police Pro\tmp\images\t2.gif
c:\program files\Windows Police Pro\tmp\images\up1.gif
c:\program files\Windows Police Pro\tmp\images\up2.gif
c:\program files\Windows Police Pro\tmp\images\w1.gif
c:\program files\Windows Police Pro\tmp\images\w11.gif
c:\program files\Windows Police Pro\tmp\images\w2.gif
c:\program files\Windows Police Pro\tmp\images\w3.gif
c:\program files\Windows Police Pro\tmp\images\w3.jpg
c:\program files\Windows Police Pro\tmp\images\wt1.gif
c:\program files\Windows Police Pro\tmp\images\wt2.gif
c:\program files\Windows Police Pro\tmp\images\wt3.gif
c:\program files\Windows Police Pro\tmp\wispex.html
c:\program files\Windows Police Pro\windows Police Pro.exe
c:\recycler\NPROTECT
c:\windows\asiboqi.exe
c:\windows\epikosuvyv.vbs
c:\windows\huborow.scr
c:\windows\nake.reg
c:\windows\okix.bat
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\system32\auprpbpa.ini
c:\windows\system32\bennuar.old
c:\windows\system32\bincd32.dat
c:\windows\system32\E95THK16.EXE
c:\windows\system32\encapi32.dll
c:\windows\system32\ewiqkywj.ini
c:\windows\SYSTEM32\ieHElpmod.dll
c:\windows\system32\isezit.reg
c:\windows\system32\nizoluw.sys
c:\windows\system32\onhelp.htm
c:\windows\SYSTEM32\qssru.bak1
c:\windows\SYSTEM32\qssru.bak2
c:\windows\SYSTEM32\qssru.ini
c:\windows\system32\rihamudoj.vbs
c:\windows\system32\SKYNETipgvitud.dat
c:\windows\system32\SKYNETirrfuirw.dat
c:\windows\system32\sonhelp.htm
c:\windows\system32\sysnet.dat
c:\windows\system32\wisdstr.exe
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\tygyf.dl
c:\windows\vonozofyto.scr
c:\windows\yvamydu.pif
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ANTIPPRO2009_100
-------\Legacy_SKYNETwruwpuhr
-------\Legacy_UACd.sys
-------\Service_AntipPro2009_100
-------\Service_SKYNETwruwpuhr
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-08-10 to 2009-09-10 )))))))))))))))))))))))))))))))
.
2009-09-10 14:55 . 2009-09-10 14:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-09-10 05:37 . 2009-09-10 05:37 13577 ----a-w- c:\windows\fukaxoki.com
2009-09-10 05:37 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-09-10 05:29 . 2009-09-10 05:39 -------- d-----w- c:\program files\AntivirusPro_2010
2009-09-10 05:19 . 2009-09-10 05:19 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-09-09 19:19 . 2009-09-09 19:19 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AVG Security Toolbar
2009-09-09 18:19 . 2009-09-09 18:19 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-09-09 18:10 . 2009-09-09 18:10 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-09-08 01:11 . 2009-09-08 01:11 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-09-06 03:56 . 2009-09-06 03:56 -------- d-----w- c:\documents and settings\Rick\Application Data\Safer Networking
2009-09-06 03:47 . 2009-09-10 15:17 -------- d-----w- c:\program files\KnightHop
2009-09-06 03:32 . 2009-09-06 03:35 -------- d-----w- c:\program files\Safer Networking
2009-09-04 12:39 . 2009-09-04 12:39 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-09-01 13:45 . 2009-09-01 13:45 -------- d-----w- c:\documents and settings\Rick\Local Settings\Application Data\Downloaded Installations
2009-08-29 01:11 . 2008-07-26 15:26 4658584 ----a-r- c:\windows\system32\drivers\lvuvc.sys
2009-08-29 01:11 . 2008-07-26 15:26 465432 ----a-r- c:\windows\system32\LVUI2RC.dll
2009-08-29 01:11 . 2008-07-26 15:26 41752 ----a-r- c:\windows\system32\drivers\LVUSBSta.sys
2009-08-29 01:11 . 2008-07-26 15:26 490008 ----a-r- c:\windows\system32\LVUI2.dll
2009-08-29 01:11 . 2008-07-26 15:23 195096 ----a-r- c:\windows\system32\lvci11801048.dll
2009-08-29 01:11 . 2008-07-26 15:23 416280 ----a-r- c:\windows\system32\lvcodec2.dll
2009-08-29 01:11 . 2008-04-14 00:12 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-08-29 01:11 . 2008-04-14 00:12 53760 ----a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2009-08-29 01:11 . 2008-07-26 15:26 23832 ----a-r- c:\windows\system32\drivers\lvuvcflt.sys
2009-08-29 00:58 . 2009-09-01 13:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd
2009-08-29 00:58 . 2009-08-29 01:11 -------- d-----w- c:\program files\Common Files\LogiShrd
2009-08-29 00:58 . 2009-08-29 00:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Logitech
2009-08-12 17:11 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-12 02:19 . 2009-08-12 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Borland
2009-08-11 22:33 . 2009-08-11 22:33 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-08-11 22:29 . 2009-08-11 22:29 -------- d-----w- c:\documents and settings\Owner\LOCALS~1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-06 00:34 . 2009-01-25 19:49 -------- d-----w- c:\documents and settings\Rick\Application Data\skypePM
2009-09-05 22:33 . 2009-08-29 01:12 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2009-09-05 22:32 . 2009-08-29 01:11 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2009-09-04 03:04 . 2009-01-25 19:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-09-04 00:24 . 2009-08-11 14:42 -------- d-----w- c:\program files\TSC
2009-09-01 13:45 . 2005-12-12 23:14 -------- d-----w- c:\program files\Common Files\Logitech
2009-08-29 00:58 . 2005-12-12 23:14 -------- d-----w- c:\program files\Logitech
2009-08-16 19:50 . 2008-12-29 04:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-16 19:50 . 2008-12-29 04:56 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-16 19:50 . 2008-12-29 04:56 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-13 15:25 . 2009-06-12 18:53 -------- d-----w- c:\program files\Opera 10 Beta
2009-08-13 14:58 . 2009-01-24 00:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-12 02:55 . 2005-02-09 02:11 66864 ----a-w- c:\documents and settings\Rick\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-11 14:42 . 2009-08-11 14:42 -------- d-----w- c:\program files\Common Files\TSCUninstall
2009-08-05 09:01 . 2004-08-04 10:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 02:09 . 2005-12-26 00:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-24 04:08 . 2004-10-06 03:40 -------- d-----w- c:\program files\MUSICMATCH
2009-07-24 04:08 . 2004-10-06 03:31 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 03:09 . 2009-07-24 03:09 -------- d-----w- c:\documents and settings\Rick\Application Data\Amazon
2009-07-24 03:06 . 2009-07-24 03:06 -------- d-----w- c:\program files\Amazon
2009-07-22 11:58 . 2009-07-22 02:34 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-22 02:34 . 2009-07-22 02:34 -------- d-----w- c:\program files\NOS
2009-07-17 19:01 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-12 16:21 . 2004-08-04 10:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2004-08-04 10:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-04 10:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 10:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 10:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 10:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 10:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 10:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 10:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-17 15:27 . 2009-06-18 23:23 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27 . 2009-06-18 23:23 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-16 14:36 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2005-11-23 01:08 . 2005-10-02 12:58 848 --sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-02-02 155648]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2004-05-12 249856]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2002-09-11 368706]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-16 2007832]
"F5D7050v3"="c:\program files\Belkin\F5D7050v3\Belkinwcui.exe" [2007-10-31 1654784]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-11-19 88363]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-11-07 19968]
c:\documents and settings\Rick\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2005-2-8 233472]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Device Detector 3.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2009-3-20 118784]
Utility Tray.lnk - c:\windows\SYSTEM32\sistray.exe [2004-10-5 335872]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 19:50 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135649015\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135649015\\ee\\aim6.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [12/29/2008 12:56 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [12/29/2008 12:56 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/29/2008 12:55 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/29/2008 12:55 AM 297752]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe --> c:\program files\NOS\bin\getPlus_HelperSvc.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
FF - ProfilePath - c:\documents and settings\Rick\Application Data\Mozilla\Firefox\Profiles\ziv3fga5.default\
FF - prefs.js: browser.startup.homepage - hxxp://us.mc838.mail.yahoo.com/mc/welcome?action=&YY=1714853569&ymv=0&noFlush&mcrumb=Fke9xVmcaVv#_pg=showFolder&fid=Inbox&order=down&tt=7&pSize=25&ymv=0&.rand=1491067721&.jsrand=8429800
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
HKLM-Run-PCMService - c:\program files\Dell\Media Experience\PCMService.exe
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
Notify-urssq - c:\windows\system32\urssq.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-10 13:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(636)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\SYSTEM32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-10 13:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-10 17:37
Pre-Run: 25,879,330,816 bytes free
Post-Run: 26,435,260,416 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30
326 --- E O F --- 2009-09-10 07:09