Followed your instructions - round 7
Hi,
The system appears to be running well. The Avira AntiVir software appears to be working although I haven't launched a full scan with it.
I just tried to launch HiJack this but the version that was on the computer was still blocked. I tried uninstalling it using Add or Remove Programs but it told me the application had been deleted and asked if I wanted it removed from the list so I said Yes. I deleted the Folders from C:\Program Files\Trend Micro... and the only file was HiJackThis.exe. Then I launched the installer which was still on the desktop... it opened and I chose "Do a system scan and save a logfile." It finished in around 10 seconds. The log is below. Cool, Hijack This didn't work when we started.
Before I did that I followed your last instructions, logs are also below.
Should I try restoring Mozilla Firefox (and anything else that got blocked) the same way? Uninstall then re-install? Spybot was also blocked but I uninstalled it a while ago and using DOS was able to delete the files by (I think) renaming the folders then deleting them.
Thanks,
Bob
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:40:46 PM, on 10/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\EARTHL~1\PCFINE~1\MXTask.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\EARTHL~1\PCFINE~1\mxtask.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\GAMECO~1\Common\SWTrayV4.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\GAMECO~1\Common\SWTrayV4.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [hcsystray] C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4994/mcfscan.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{C4E8910D-7EEB-43EE-9555-25E9AB197140}: NameServer = 207.217.126.81,207.217.126.82
O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC FineTune Task Manager - Avanquest Publishing USA, Inc. - C:\PROGRA~1\EARTHL~1\PCFINE~1\MXTask.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINDOWS\System32\ZipToA.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
--
End of file - 9658 bytes
ComboFix 09-10-03.01 - bob 10/06/2009 15:40.3.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1024.568
[GMT -7:00]
Running from: c:\documents and settings\bob\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\bob\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
{AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\documents and settings\bob\My Documents\other\exclusivemovie.308.exe"
"c:\documents and settings\Dennis\Application
Data\Sun\Java\Deployment\cache\6.0\23\1c3a7917-48fbe86f"
"c:\documents and settings\Dennis\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-2f2e21ea-3ef49862.zip"
"c:\documents and settings\Dennis\My
Documents\Incomplete\Preview-T-5745425-meaning high mighty.mp3"
"c:\documents and settings\Dennis\My Documents\My eBooks\meaning high
mighty.mp3"
"c:\windows\system32\DHTMLAccess.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions
)))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dennis\Application
Data\Sun\Java\Deployment\cache\6.0\23\1c3a7917-48fbe86f
c:\documents and settings\Dennis\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-2f2e21ea-3ef49862.zip
c:\documents and settings\Dennis\My
Documents\Incomplete\Preview-T-5745425-meaning high mighty.mp3
c:\documents and settings\Dennis\My Documents\My eBooks\meaning high mighty.mp3
c:\windows\Installer\228be5.msi
c:\windows\system32\DHTMLAccess.dll
.
((((((((((((((((((((((((( Files Created from 2009-09-06 to
2009-10-06 )))))))))))))))))))))))))))))))
.
2009-10-05 23:16 . 2009-10-06
13:47 2859040 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-04 17:32 . 2009-10-04 17:32 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-10-04 16:37 . 2001-08-18
12:00 4224 -c--a-w- c:\windows\system32\dllcache\beep.sys
2009-10-04 16:37 . 2001-08-18
12:00 4224 ------w- c:\windows\system32\drivers\beep.sys
2009-09-27 00:02 . 2009-09-27 00:02 -------- d-----w- c:\program
files\Trend Micro
2009-09-26 23:57 . 2009-09-26 23:58 -------- d-----w- c:\program files\ERUNT
2009-09-26 22:47 . 2009-09-26 23:06 -------- d-----w- c:\program
files\Windows Live Safety Center
2009-09-14 02:40 . 2009-09-14 02:41 -------- d-----w- c:\temp\Spybot -
Search & Destroy
2009-09-12 18:20 . 2009-06-21
21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-07 00:54 . 2009-07-28
23:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-07 00:54 . 2009-03-30
17:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-07 00:54 . 2009-02-13
19:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-09-07 00:54 . 2009-02-13
19:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-09-07 00:54 . 2009-09-07 00:54 -------- d-----w- c:\program files\Avira
2009-09-07 00:54 . 2009-09-07 00:54 -------- d-----w- c:\documents and
settings\All Users\Application Data\Avira
2009-09-06 23:24 . 2009-09-06 23:24 -------- d-sh--w- c:\documents and
settings\Administrator\IETldCache
2009-09-06 23:06 . 2009-09-06 23:06 -------- d-----w- c:\documents and
settings\bob\Application Data\Malwarebytes
2009-09-06 23:06 . 2009-09-06 23:06 -------- d-----w- c:\documents and
settings\All Users\Application Data\Malwarebytes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report
))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-06 13:47 . 2009-10-05
23:16 34580 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-04 18:44 . 2002-08-29 21:45 -------- d-----w- c:\program files\Java
2009-10-04 18:21 . 2002-08-16 03:35 -------- d--h--w- c:\program
files\InstallShield Installation Information
2009-10-04 18:02 . 2005-12-25 17:00 -------- d-----w- c:\documents and
settings\bob\Application Data\Apple Computer
2009-10-04 17:25 . 2002-08-19 01:48 -------- d-----w- c:\program
files\Common Files\Adobe
2009-09-14 02:43 . 2004-07-10 01:41 -------- d-----w- c:\documents and
settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-07 23:18 . 2007-03-28 03:53 -------- d-----w- c:\program
files\Common Files\Wise Installation Wizard
2009-08-31 22:43 . 2009-08-31 22:43 -------- d-----w- c:\documents and
settings\Dennis\Application Data\HpUpdate
2009-08-22 18:47 . 2009-08-15 18:26 -------- d-----w- c:\documents and
settings\bob\Application Data\HpUpdate
2009-08-05 09:01 . 2004-02-29
05:54 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 23:03 . 2005-05-24 22:31 43896 ----a-w- c:\documents and
settings\Dennis\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-31 22:23 . 2009-08-08
17:39 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2003-09-10 16:44 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 06:43 . 2004-02-16
18:44 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-12 19:27 . 2002-12-18 23:43 43896 ----a-w- c:\documents and
settings\johanna\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-09 19:16 . 2009-08-02
21:10 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-07-09 19:16 . 2007-10-14
04:16 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2005-09-16 02:26 . 2007-03-08 19:59 44153 ----a-w- c:\program
files\mozilla firefox\components\inspector.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-10-02_23.01.06
)))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-04 18:08 . 2009-10-04 18:08 84661
c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2007-08-19 10:19 . 2009-08-15 18:27 84661
c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-10-04 17:49 . 2009-10-04 17:49 88589
c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-10-04 17:32 . 2009-10-04 17:32 2560 c:\windows\_MSRSTRT.EXE
- 2006-06-05 22:14 . 2006-06-05 22:14 626688
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
+ 2006-06-05 21:14 . 2006-06-05 21:14 626688
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
- 2006-06-05 22:14 . 2006-06-05 22:14 548864
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
+ 2006-06-05 21:14 . 2006-06-05 21:14 548864
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
- 2006-06-05 22:14 . 2006-06-05 22:14 479232
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
+ 2006-06-05 21:14 . 2006-06-05 21:14 479232
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440
c:\windows\system32\Macromed\Flash\FlashUtil10c.exe
+ 2009-10-04 18:45 . 2009-07-31 22:23 149280
c:\windows\system32\javaws.exe
- 2009-08-08 17:39 . 2009-08-08 17:38 149280
c:\windows\system32\javaws.exe
+ 2009-10-04 18:45 . 2009-07-31 22:23 145184
c:\windows\system32\javaw.exe
- 2009-08-08 17:39 . 2009-08-08 17:38 145184
c:\windows\system32\javaw.exe
+ 2009-10-04 18:45 . 2009-07-31 22:23 145184
c:\windows\system32\java.exe
- 2009-08-08 17:39 . 2009-08-08 17:38 145184
c:\windows\system32\java.exe
+ 2009-10-04 17:26 . 2009-10-04 17:28 295606
c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\SC_Reader.exe
+ 2007-01-23 18:39 . 2007-01-23 18:39 443904
c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\JP2KLib.dll
+ 2009-10-04 17:19 . 2009-10-04 17:19 9680384
c:\windows\Installer\1d3b61.msp
+ 2009-10-04 17:26 . 2009-10-04 17:26 4192256
c:\windows\Installer\1d3b46.msi
+ 2008-10-15 07:42 . 2008-10-15 07:42 13219184
c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points
))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="c:\program files\Adaptec\Easy CD Creator
5\DirectCD\DirectCD.exe" [2002-08-17 684032]
"SideWinderTrayV4"="c:\progra~1\GAMECO~1\Common\SWTrayV4.exe" [2000-06-03 24650]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe"
[2001-11-07 196608]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2002-01-24 106496]
"Iomega Startup Options"="c:\program files\Iomega\Common\ImgStart.exe"
[2001-01-17 45056]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe"
[2001-11-20 57344]
"Deskup"="c:\program files\Iomega\DriveIcons\deskup.exe" [2001-10-01 28672]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2001-07-25 57344]
"hcsystray"="c:\program files\Kuma Games\hcsystray\hc_tray.exe"
[2006-11-02 30928]
"HP Software Update"="c:\program files\HP\HP Software
Update\HPWuSchd2.exe" [2007-03-12 49152]
"StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache
Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-17
36864]
"TomcatStartup"="c:\program
files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-04-01 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-16 7110656]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device
Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe"
[2008-06-10 1442888]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe"
[2008-06-10 1406024]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent
Status\StxMenuMgr.exe" [2009-01-16 181544]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader
8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
[2009-07-31 149280]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-07-16 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe
[2008-04-14 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-1-28 113664]
Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe
[2002-8-18 212992]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital
Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Microsoft Office.lnk - c:\program files\Microsoft
Office\Office10\OSA.EXE [2001-2-13 83360]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2002-10-11 106560]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization
4\\Civilization4.exe"=
"c:\\Program Files\\PrintServer Utilities\\WinUtil\\PSAdmin.exe"=
"c:\\Program Files\\Microsoft Games\\Freelancer\\EXE\\Freelancer.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Documents and Settings\\Dennis\\My Documents\\My eBooks\\bittorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Dennis\\My Documents\\BitTorrent\\bittorrent.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 fasttrak;fasttrak;c:\windows\system32\drivers\Fasttrak.sys
[8/15/2002 9:31 PM 70528]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program
files\Avira\AntiVir Desktop\sched.exe [9/6/2009 5:54 PM 108289]
R2 FreeAgentGoNext Service;Seagate Service;c:\program
files\Seagate\SeagateManager\Sync\FreeAgentService.exe [1/16/2009 4:31
PM 161064]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common
Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45
AM 13088]
R2 PC FineTune Task Manager;PC FineTune Task
Manager;c:\progra~1\EARTHL~1\PCFINE~1\MXTask.exe -Service -->
c:\progra~1\EARTHL~1\PCFINE~1\MXTask.exe -Service [?]
S2 ousbehci;%OWC_USBEHCD.DeviceDesc%;c:\windows\system32\drivers\ousbehci.sys
[8/13/2002 10:08 PM 26752]
S3 ousb2hub;OrangeWare USB 2.0 Root Hub
Support;c:\windows\system32\drivers\ousb2hub.sys [8/13/2002 10:08 PM
40704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed
components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe"
"c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: {C4E8910D-7EEB-43EE-9555-25E9AB197140} = 207.217.126.81,207.217.126.82
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\bob\Application
Data\Mozilla\Firefox\Profiles\iama4aq7.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - HiddenExtension: Microsoft .NET Framework Assistant:
{20a82645-c095-46ed-80e3-08825760534b} -
c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation
Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by
Gmer,
http://www.gmer.net
Rootkit scan 2009-10-06 15:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-10-06 15:55
ComboFix-quarantined-files.txt 2009-10-06 22:55
ComboFix2.txt 2009-10-04 17:01
ComboFix3.txt 2009-10-02 23:08
Pre-Run: 4,784,005,120 bytes free
Post-Run: 4,785,315,840 bytes free
221 --- E O F --- 2009-10-02 19:09
DDS (Ver_09-09-29.01) - NTFSx86
Run by bob at 16:03:40.56 on Tue 10/06/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1024.543
[GMT -7:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated)
{AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\EARTHL~1\PCFINE~1\MXTask.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\PROGRA~1\EARTHL~1\PCFINE~1\mxtask.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\svchost.exe -k HPService
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\GAMECO~1\Common\SWTrayV4.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Kuma Games\hcsystray\hc_tray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat
4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\bob\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper:
{06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common
files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper:
{dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class:
{e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program
files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
mRun: [AdaptecDirectCD] c:\program files\adaptec\easy cd creator
5\directcd\DirectCD.exe
mRun: [SideWinderTrayV4] c:\progra~1\gameco~1\common\SWTrayV4.exe
mRun: [HPDJ Taskbar Utility]
c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe
mRun: [ADUserMon] c:\program files\iomega\autodisk\ADUserMon.exe
mRun: [Iomega Startup Options] c:\program files\iomega\common\ImgStart.exe
mRun: [Iomega Drive Icons] c:\program files\iomega\driveicons\ImgIcon.exe
mRun: [Deskup] c:\program files\iomega\driveicons\deskup.exe
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
mRun: [nwiz] nwiz.exe /install
mRun: [hcsystray] c:\program files\kuma games\hcsystray\hc_tray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [StatusClient] c:\program
files\hewlett-packard\toolbox2.0\apache tomcat
4.0\webapps\toolbox\statusclient\StatusClient.exe /auto
mRun: [TomcatStartup] c:\program files\hewlett-packard\toolbox2.0\hpbpsttp.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile
device support\bin\AppleSyncNotifier.exe
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [MaxMenuMgr] "c:\program files\seagate\seagatemanager\freeagent
status\StxMenuMgr.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader
8.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk
- c:\program files\common files\adobe\calibration\Adobe Gamma
Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\exifla~1.lnk
- c:\program files\finepixviewer\QuickDCF.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk
- c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk
- c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk
- c:\program files\winzip\WZQKPICK.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program
files\messenger\msmsgs.exe
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} -
{E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web
printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} -
{A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web
printing\hpswp_extensions.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} -
hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
hxxp://office.microsoft.com/officeupdate/content/opuc.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} -
hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37587.4743634259
DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} -
hxxp://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} -
hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4994/mcfscan.cab
TCP: {C4E8910D-7EEB-43EE-9555-25E9AB197140} = 207.217.126.81,207.217.126.82
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program
files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath -
c:\docume~1\bob\applic~1\mozilla\firefox\profiles\iama4aq7.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - HiddenExtension: Microsoft .NET Framework Assistant:
{20a82645-c095-46ed-80e3-08825760534b} -
c:\windows\microsoft.net\framework\v3.5\windows presentation
foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program
files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program
files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 fasttrak;fasttrak;c:\windows\system32\drivers\Fasttrak.sys [2002-8-15 70528]
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-9-6 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program
files\avira\antivir desktop\sched.exe [2009-9-6 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir
desktop\avguard.exe [2009-9-6 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-6 55656]
R2 FreeAgentGoNext Service;Seagate Service;c:\program
files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-1-16
161064]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\common
files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
R2 PC FineTune Task Manager;PC FineTune Task
Manager;c:\progra~1\earthl~1\pcfine~1\mxtask.exe -service -->
c:\progra~1\earthl~1\pcfine~1\MXTask.exe -Service [?]
S2 ousbehci;%OWC_USBEHCD.DeviceDesc%;c:\windows\system32\drivers\ousbehci.sys
[2002-8-13 26752]
S3 ousb2hub;OrangeWare USB 2.0 Root Hub
Support;c:\windows\system32\drivers\ousb2hub.sys [2002-8-13 40704]
=============== Created Last 30 ================
2009-10-06 15:38 <DIR> --d----- C:\ComboFix
2009-10-05 16:16 2,859,040 a--sh--- c:\windows\system32\drivers\fidbox.dat
2009-10-05 16:16 34,580 a--sh--- c:\windows\system32\drivers\fidbox.idx
2009-10-04 10:32 2,560 a------- c:\windows\_MSRSTRT.EXE
2009-10-04 09:37 4,224 ac------ c:\windows\system32\dllcache\beep.sys
2009-10-04 09:37 4,224 -------- c:\windows\system32\drivers\beep.sys
2009-10-02 15:37 229,888 a------- c:\windows\PEV.exe
2009-10-02 15:37 161,792 a------- c:\windows\SWREG.exe
2009-10-02 15:37 98,816 a------- c:\windows\sed.exe
2009-09-26 17:02 <DIR> --d----- c:\program files\Trend Micro
2009-09-13 19:40 <DIR> --d----- c:\temp\Spybot - Search & Destroy
2009-09-12 11:20 153,088 -c------ c:\windows\system32\dllcache\triedit.dll
2009-09-06 17:54 55,656 a------- c:\windows\system32\drivers\avgntflt.sys
2009-09-06 17:54 <DIR> --d----- c:\program files\Avira
2009-09-06 17:54 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-09-06 16:06 <DIR> --d----- c:\docume~1\bob\applic~1\Malwarebytes
2009-09-06 16:06 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
==================== Find3M ====================
2009-08-05 02:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-31 15:23 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-17 12:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-07-09 12:16 2,060,288 a------- c:\windows\system32\usbaaplrc.dll
2008-03-01 15:00 43,120 a------- c:\docume~1\bob\applic~1\GDIPFONTCACHEV1.DAT
2007-08-13 14:31 92,064 a------- c:\documents and settings\bob\mqdmmdm.sys
2007-08-13 14:31 79,328 a------- c:\documents and settings\bob\mqdmserd.sys
2007-08-13 14:31 66,656 a------- c:\documents and settings\bob\mqdmbus.sys
2007-08-13 14:31 25,600 a------- c:\documents and settings\bob\usbsermptxp.sys
2007-08-13 14:31 22,768 a------- c:\documents and settings\bob\usbsermpt.sys
2007-08-13 14:31 9,232 a------- c:\documents and settings\bob\mqdmmdfl.sys
2007-08-13 14:31 6,208 a------- c:\documents and settings\bob\mqdmcmnt.sys
2007-08-13 14:31 5,936 a------- c:\documents and settings\bob\mqdmwhnt.sys
2007-08-13 14:31 4,048 a------- c:\documents and settings\bob\mqdmcr.sys
2008-11-03 12:37 32,768 a--sh--- c:\windows\system32\config\systemprofile\local
settings\history\history.ie5\mshist012008110320081104\index.dat
============= FINISH: 16:04:09.42 ===============