hi blade, i'm back with the ComboFix Log. =)
ComboFix 09-09-10.03 - mike 09/11/2009 12:00.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1918.995 [GMT -7:00]
Running from: c:\users\mike\Desktop\SnaPPLe.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1427494975-2143899584-4123375682-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2702335933-2054761317-366956104-500
c:\windows\Installer\ab26474.msi
c:\windows\Installer\ebd133.msi
c:\windows\system32\logs
Infected copy of c:\windows\system32\cngaudit.dll was found and disinfected
Restored copy from - c:\windows\system32\logevent.dll
-- Previous Run --
Infected copy of c:\windows\system32\cngaudit.dll was found and disinfected
Restored copy from - c:\windows\system32\logevent.dll
--------
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-08-11 to 2009-09-11 )))))))))))))))))))))))))))))))
.
2009-09-11 19:37 . 2009-09-11 19:46 -------- d-----w- c:\users\mike\AppData\Local\temp
2009-09-11 19:37 . 2009-09-11 19:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-11 18:47 . 2009-09-11 18:48 -------- d-----w- C:\32788R22FWJFW.2.tmp
2009-09-11 14:59 . 2009-09-11 15:01 -------- d-----w- C:\32788R22FWJFW.1.tmp
2009-09-10 06:15 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2009-09-09 18:09 . 2009-09-09 18:16 -------- d-----w- c:\program files\Trend Micro
2009-09-09 06:39 . 2009-09-09 06:39 -------- d-----w- c:\programdata\Sunbelt
2009-09-07 21:54 . 2009-09-08 06:26 -------- d-----w- c:\program files\Sunbelt Software
2009-09-07 02:42 . 2009-09-07 02:42 -------- d-----w- c:\users\mike\AppData\Roaming\Malwarebytes
2009-09-07 02:41 . 2009-08-03 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-07 02:41 . 2009-09-07 02:41 -------- d-----w- c:\programdata\Malwarebytes
2009-09-07 02:41 . 2009-08-03 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-07 02:41 . 2009-09-07 02:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-05 01:49 . 2009-09-09 21:46 -------- d-----w- c:\program files\Panda Security
2009-09-04 20:48 . 2009-09-09 21:41 -------- d-----w- c:\programdata\PC Tools
2009-09-03 00:45 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-03 00:45 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-26 10:02 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-26 00:23 . 2009-08-26 00:23 -------- d-----w- c:\program files\4Musics WAV to MP3 Converter
2009-08-19 18:36 . 2009-08-20 01:30 -------- d-----w- c:\users\mike\AppData\Roaming\Winamp
2009-08-19 18:36 . 2009-08-19 18:37 -------- d-----w- c:\program files\Winamp
2009-08-14 16:59 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-08-14 16:59 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-14 16:59 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-08-14 16:59 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-08-14 16:59 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-08-14 16:59 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-14 16:59 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-08-14 16:59 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 17:59 . 2007-09-09 19:12 -------- d-----w- c:\users\mike\AppData\Roaming\mIRC
2009-09-10 10:09 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-09 19:15 . 2008-03-03 19:13 -------- d-----w- c:\users\mike\AppData\Roaming\uTorrent
2009-09-09 18:29 . 2009-06-16 16:23 0 ----a-w- c:\users\mike\AppData\Local\prvlcl.dat
2009-09-04 21:30 . 2008-04-13 20:19 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-01 23:47 . 2009-09-01 23:47 -------- d-----w- c:\program files\Free Audio Pack
2009-08-26 00:24 . 2008-10-17 22:03 -------- d-----w- c:\program files\Ace MP3 To WAV Converter
2009-08-14 17:07 . 2009-09-10 06:16 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-10 06:16 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-09-10 06:16 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:16 . 2009-09-10 06:16 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-10 06:16 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-10 06:16 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-10 06:16 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-10 06:16 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-10 06:16 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-10 06:16 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:58 . 2009-09-04 21:23 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-08-11 19:30 . 2009-08-11 19:30 -------- d-----w- c:\program files\EarMaster Pro 5
2009-08-11 19:30 . 2009-08-11 19:30 -------- d-----w- c:\users\mike\AppData\Roaming\EarMaster
2009-08-11 19:30 . 2009-08-11 19:30 -------- d-----w- c:\programdata\EarMaster
2009-08-11 05:53 . 2009-08-11 05:53 -------- d-----w- c:\programdata\Downloaded Installations
2009-08-11 05:52 . 2009-05-14 18:23 -------- d-----w- c:\programdata\avg8
2009-08-11 02:16 . 2008-04-13 20:19 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-08-11 02:16 . 2008-04-07 22:11 -------- d-----w- c:\programdata\FLEXnet
2009-08-03 16:19 . 2009-05-14 18:26 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-03 16:19 . 2009-05-14 18:26 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-03 16:19 . 2009-05-14 18:26 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-23 00:23 . 2009-07-23 00:23 74760 ----a-w- c:\windows\system32\drivers\UniversalDD.sys
2009-07-23 00:23 . 2009-07-23 00:23 25608 ----a-w- c:\windows\system32\drivers\AVGIDSErHr.sys
2009-07-21 20:36 . 2009-07-21 20:36 -------- d-----w- c:\program files\Vstplugins
2009-07-18 16:06 . 2009-07-28 23:40 827904 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-07-28 23:40 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-07-28 23:40 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:35 . 2009-08-11 19:36 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:00 . 2009-08-11 19:36 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 12:59 . 2009-08-11 19:36 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 12:58 . 2009-08-11 19:36 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 10:59 . 2009-08-11 19:35 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-13 19:58 . 2008-04-09 06:20 -------- d-----w- c:\program files\Syncrosoft
2009-07-13 19:55 . 2009-07-13 19:55 -------- d-----w- c:\users\mike\AppData\Roaming\Steinberg
2009-07-11 19:32 . 2009-09-10 06:16 302592 ----a-w- c:\windows\system32\wlansec.dll
2009-07-11 19:32 . 2009-09-10 06:16 293376 ----a-w- c:\windows\system32\wlanmsm.dll
2009-07-11 19:32 . 2009-09-10 06:16 513024 ----a-w- c:\windows\system32\wlansvc.dll
2009-07-11 19:29 . 2009-09-10 06:16 127488 ----a-w- c:\windows\system32\L2SecHC.dll
2009-07-01 02:03 . 2009-07-01 02:03 233472 ----a-w- c:\windows\system32\REX Shared Library.dll
2009-06-15 15:24 . 2009-07-15 11:47 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-15 11:47 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-15 11:47 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-15 11:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2008-01-26 22:48 . 2008-01-26 22:48 0 --sha-w- c:\windows\SBC38B530.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-03-13 1773568]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2008-07-03 812952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-19 2153472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"SnapfishMediaDetector"="c:\program files\Snapfish Media Detector\SnapfishMediaDetector.exe" [2007-03-02 1441792]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-11 624248]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-07-07 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-07 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-07 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-12 2007832]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-12-18 307200]
"AVGIDS"="c:\program files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSUI.exe" [2009-07-23 1600008]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-01 4390912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-03-07 44168]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
MFWAKeys.lnk - c:\program files\MOTU\FireWire Audio\MFWAKeys.exe [2007-9-10 126976]
MOTU Pedal Handler.lnk - c:\windows\Installer\{FAAF4F08-107F-42B4-B01C-B5BACB65E7D3}\_B46567FF76B580C507E5B5.exe [2007-12-17 10134]
Snapfish Media Detector.lnk - c:\program files\Snapfish Media Detector\SnapfishMediaDetector.exe [2007-3-2 1441792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B74D4073-4A65-4516-BAA9-C36211272413}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3268F9DE-2BE1-4BA1-8F3A-1BB02C8100D3}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4CC0EE83-F4EF-4719-99E1-490B956C0F5A}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4513983D-0C39-4FAE-90C6-A381B25F63D8}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C52709ED-5492-4C67-AA3D-BDA44F3C77A2}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3CD4529E-5113-41D2-BCAC-DB7911B55C4E}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{9DCBB145-7212-4670-BA5A-1E7FF1382BC4}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{068BAED6-CA03-402A-9E71-2794EBD2C887}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A14168FF-C125-47DE-A405-9FF0B73306DE}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{063497CE-70DD-42AB-9B34-33C87055991F}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{1C001340-DAA4-47E6-B50B-BA230216E23F}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C743F804-8F36-4FFD-A740-4C47EA5768DA}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{BA8EFD64-9614-46FD-B172-42C2530D38DE}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6F48FE21-A898-40B7-B6B1-9B50AD020D25}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{2721363D-8A7C-403D-9745-11663E94956B}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC
"UDP Query User{F6B7ED2B-7F67-4820-A521-8B8478C45518}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC
"TCP Query User{87CFD502-683E-4097-8960-2DB6815907E9}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{4E4AC7AB-D111-43AE-B77F-C45C6D6527F1}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{D3792332-B664-4CE2-9C12-8813271F9D9F}c:\\kav\\kav7\\setup.exe"= UDP:c:\kav\kav7\setup.exe:Kaspersky Anti-Virus 7.0 Setup
"UDP Query User{2A03D6FB-1225-4720-9910-4CA80CD23789}c:\\kav\\kav7\\setup.exe"= TCP:c:\kav\kav7\setup.exe:Kaspersky Anti-Virus 7.0 Setup
"{886A128E-60F3-415C-92CD-7AA722A8AA50}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{AC15DACA-CFA1-4D1D-B672-8240AF2D7012}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{6699F5EA-DAA4-4546-BAFA-7452AB832F66}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{832CFB87-1306-4CF9-B90B-57239E16F75D}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{6E980E6C-8A0C-44E9-8368-F211748849E3}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{9E392FF1-4FFF-4E2E-B8A4-EFFAF4851165}c:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:c:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"TCP Query User{A0A673E7-3B5C-411F-AF5A-0CBA4CA254F8}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{4C0E1E8C-17F4-44EE-AED6-B1629E4B56CF}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{D3F0A7AA-E9A6-4064-AEE3-3C3045435127}c:\\program files\\bittornado\\btdownloadgui.exe"= UDP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"UDP Query User{B0FFC4EE-D8AC-4E8B-8435-CC41C2599459}c:\\program files\\bittornado\\btdownloadgui.exe"= TCP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"TCP Query User{5953E229-30E5-4280-B058-9BDEB3D71A64}c:\\program files\\itunes\\itunes.exe"= UDP:c:\program files\itunes\itunes.exe:iTunes
"UDP Query User{F70EC504-1928-441F-8FB9-67997A3F37C8}c:\\program files\\itunes\\itunes.exe"= TCP:c:\program files\itunes\itunes.exe:iTunes
"TCP Query User{EC435664-8772-4085-8EEC-6AE37572DF2A}c:\\program files\\mirc\\mirc.exe"= UDP:c:\program files\mirc\mirc.exe:mIRC
"UDP Query User{6C759863-6E26-4827-B880-A926CC9BE00B}c:\\program files\\mirc\\mirc.exe"= TCP:c:\program files\mirc\mirc.exe:mIRC
"TCP Query User{ED570B89-E50D-4073-854A-3285FFFF5B34}c:\\program files\\bittornado\\btdownloadgui.exe"= UDP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"UDP Query User{C7DBF1B4-49E9-4093-95E1-2B2FB60E5EBE}c:\\program files\\bittornado\\btdownloadgui.exe"= TCP:c:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"TCP Query User{8EADB55A-E98B-4CF6-BB54-B3326116480F}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{B7ED8531-9224-43E1-B08E-23CED92BB755}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"TCP Query User{5FF4D97E-84F9-4AFB-ABD2-45BF3B5394DF}c:\\program files\\burst\\core-new1.1.3\\btdownloadheadless.exe"= UDP:c:\program files\burst\core-new1.1.3\btdownloadheadless.exe:burst! download engine
"UDP Query User{AC2E0008-8D39-475B-9945-15A0EC16A5E0}c:\\program files\\burst\\core-new1.1.3\\btdownloadheadless.exe"= TCP:c:\program files\burst\core-new1.1.3\btdownloadheadless.exe:burst! download engine
"TCP Query User{FD5759EC-4CFF-453E-8AF2-46E61B4B3097}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{71A4BBC5-BFDA-46E4-8D67-6979959C7F9A}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{2A8FCC79-1900-4247-8B2C-EF036C65CF10}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{55C616E4-7047-4528-920B-0D19F87454B0}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{80C495C5-F775-4BD1-8AA9-BB997939D048}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{98163C55-ED80-4C81-9B1C-2E5D969227AC}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{A30D7A0A-9D14-450F-B7E4-7407AE42B374}c:\\kav\\kav7\\setup.exe"= UDP:c:\kav\kav7\setup.exe:Kaspersky Anti-Virus 7.0 Setup
"UDP Query User{2C622DAD-06D9-4751-8B3A-50B3F11B6B68}c:\\kav\\kav7\\setup.exe"= TCP:c:\kav\kav7\setup.exe:Kaspersky Anti-Virus 7.0 Setup
"{A299CCDE-FF68-4DB6-96B0-1F55EAD8469C}"= c:\program files\AVG\AVG8\avgam.exe:avgam.exe
"{2CDC90EB-1170-4A8D-B2F0-5C47DB5AEE83}"= c:\program files\AVG\AVG8\avgdiag.exe:avgdiag.exe
"{36C82A20-12D6-49DA-8F9F-EE1D07BD96B5}"= c:\program files\AVG\AVG8\avgdiagex.exe:avgdiagex.exe
"{5201E383-A18C-4184-BC07-229C183B5686}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{6BF94A10-9C05-4F98-A6FA-B7D42413B1DE}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{6046AC6C-EB29-4825-819A-4962701C4F73}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R0 AVGIDSErHr;AVGIDSErHr;c:\windows\System32\drivers\AVGIDSErHr.sys [7/22/2009 5:23 PM 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [5/14/2009 11:26 AM 12552]
R1 Avgfwfd;AVG network filter service;c:\windows\System32\drivers\avgfwd6x.sys [5/14/2009 11:04 AM 23832]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [5/14/2009 11:26 AM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [5/14/2009 11:26 AM 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/14/2009 11:25 AM 297752]
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [5/14/2009 11:25 AM 1370488]
R2 AVGIDSWatcher;AVGIDSWatcher;c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe [7/22/2009 5:23 PM 571912]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [3/25/2009 6:44 PM 1153368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/12/2007 12:23 PM 24652]
R3 CLEDX;Team H2O CLEDX service;c:\windows\System32\drivers\cledx.sys [4/8/2008 11:23 PM 33792]
R3 motubus;MOTU Audio MIDI Extension;c:\windows\System32\drivers\motubus.sys [1/4/2007 6:06 PM 23288]
R3 portio32;portio32;c:\windows\System32\drivers\portio32.sys [6/19/2009 3:04 PM 2048]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/14/2009 11:25 AM 908056]
S3 akMPC4kU;AKAI MPC4000 Driver;c:\windows\System32\drivers\akMPC4kU.sys [1/4/2008 3:11 PM 11392]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\drivers\ASPI32.SYS [9/23/2008 12:39 PM 84832]
S3 AVGIDSDriver;AVGIDSDriver;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_VISTA\AVGIDSDriver.sys [7/22/2009 5:23 PM 121352]
S3 AVGIDSFilter;AVGIDSFilter;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_VISTA\AVGIDSFilter.sys [7/22/2009 5:23 PM 30216]
S3 AVGIDSShim;AVGIDSShim;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_VISTA\AVGIDSShim.sys [7/22/2009 5:23 PM 29136]
S3 mfwagsif;MOTU Audio GSIF;c:\windows\System32\drivers\mfwagsif.sys [1/4/2007 7:06 PM 21752]
S3 mfwamidi;MOTU Audio MIDI;c:\windows\System32\drivers\MFWAMIDI.sys [1/4/2007 7:06 PM 25336]
S3 mfwawave;MOTU Audio Wave;c:\windows\System32\drivers\MFWAWave.sys [1/4/2007 7:05 PM 58104]
S3 MotuFWA;MotuFWA;c:\windows\System32\drivers\motufwa.sys [1/4/2007 7:06 PM 233720]
S3 RDID1045;Roland FANTOM-X;c:\windows\System32\drivers\Rdwm1045.sys [3/26/2008 2:37 PM 56832]
S3 YMIDUSBW;Yamaha USB-MIDI Driver (WDM);c:\windows\System32\drivers\ymidusbw.sys [4/19/2008 2:56 PM 33736]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\mike\AppData\Roaming\Mozilla\Firefox\Profiles\ds97wq52.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-11 12:45
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1427494975-2143899584-4123375682-1000\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000013
[HKEY_USERS\S-1-5-21-1427494975-2143899584-4123375682-1000\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:00000003
[HKEY_USERS\S-1-5-21-1427494975-2143899584-4123375682-1000\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:00000003
[HKEY_USERS\S-1-5-21-1427494975-2143899584-4123375682-1000\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:00000003
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3124)
c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
.
**************************************************************************
.
Completion time: 2009-09-11 12:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-11 19:51
Pre-Run: 158,812,659,712 bytes free
Post-Run: 157,387,767,808 bytes free
339 --- E O F --- 2009-09-11 10:00