ComboFix 12-04-26.01 - Cameron 29/04/2012 8:52.6.2 - x86
Running from: c:\documents and settings\Cameron\Desktop\jgh.exe
Command switches used :: c:\documents and settings\Cameron\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\windows\system32\2wirepcp.dll"
"c:\windows\system32\AdfuUd.dll"
"c:\windows\system32\AdobeActiveFileMonitor6.0.dll"
"c:\windows\system32\adobeversioncue.dll"
"c:\windows\system32\adpu320.dll"
"c:\windows\system32\AmdLLD.dll"
"c:\windows\system32\amfilter.dll"
"c:\windows\system32\AppnApi.dll"
"c:\windows\system32\ARCSOFTVIRTUALCAPTURE.dll"
"c:\windows\system32\asp.net_2.0.50727.dll"
"c:\windows\system32\asusgsb.dll"
"c:\windows\system32\aswrdr.dll"
"c:\windows\system32\atitool.dll"
"c:\windows\system32\ATMsrvc.dll"
"c:\windows\system32\avcgbfl.dll"
"c:\windows\system32\backupexecnamingservice.dll"
"c:\windows\system32\BrScnUsb.dll"
"c:\windows\system32\bt.dll"
"c:\windows\system32\bt3cusb.dll"
"c:\windows\system32\bthusb.dll"
"c:\windows\system32\btserial.dll"
"c:\windows\system32\bvrp_pci.dll"
"c:\windows\system32\bwcsrv.dll"
"c:\windows\system32\cccredmgr.dll"
"c:\windows\system32\ccevtmgr.dll"
"c:\windows\system32\CDRPDACC.dll"
"c:\windows\system32\clipsrv.dll"
"c:\windows\system32\clnt_clientman.dll"
"c:\windows\system32\CoachUsb.dll"
"c:\windows\system32\CoolerXPDriver.dll"
"c:\windows\system32\cpsvc.dll"
"c:\windows\system32\ctxcpubal.dll"
"c:\windows\system32\db2governor.dll"
"c:\windows\system32\DCamUSBSQTECH.dll"
"c:\windows\system32\Defrag32.dll"
"c:\windows\system32\DgiVecp.dll"
"c:\windows\system32\dlcc_device.dll"
"c:\windows\system32\dnetc.dll"
"c:\windows\system32\dns4meclient.dll"
"c:\windows\system32\DSI_SiUSBXp_3_1.dll"
"c:\windows\system32\DSXUSB.dll"
"c:\windows\system32\EagleNT.dll"
"c:\windows\system32\edspport.dll"
"c:\windows\system32\fetnd5bv.dll"
"c:\windows\system32\fsRamDsk.dll"
"c:\windows\system32\ghostsec.dll"
"c:\windows\system32\hap17v2k.dll"
"c:\windows\system32\hdaudbus.dll"
"c:\windows\system32\i8042prt.dll"
"c:\windows\system32\iAimTV5.dll"
"c:\windows\system32\ICAM5USB.dll"
"c:\windows\system32\idsvc.dll"
"c:\windows\system32\ikhlayer.dll"
"c:\windows\system32\intelppm.dll"
"c:\windows\system32\ipodsrv.dll"
"c:\windows\system32\irbus.dll"
"c:\windows\system32\ireike.dll"
"c:\windows\system32\ksthunk.dll"
"c:\windows\system32\lanmanserver.dll"
"c:\windows\system32\LHidUsbK.dll"
"c:\windows\system32\lmimirr.dll"
"c:\windows\system32\LMIRfsClientNP.dll"
"c:\windows\system32\lpx.dll"
"c:\windows\system32\lwwlicenseservice.dll"
"c:\windows\system32\lxdm_device.dll"
"c:\windows\system32\Machnm32.dll"
"c:\windows\system32\messenger.dll"
"c:\windows\system32\MREMP50a64.dll"
"c:\windows\system32\mrpostman.dll"
"c:\windows\system32\msgame.dll"
"c:\windows\system32\msk80service.dll"
"c:\windows\system32\navapel.dll"
"c:\windows\system32\ndasbus.dll"
"c:\windows\system32\NSSvcMgr.dll"
"c:\windows\system32\NTIDrvr.dll"
"c:\windows\system32\NtMtlFax.dll"
"c:\windows\system32\NuidFltr.dll"
"c:\windows\system32\nvata.dll"
"c:\windows\system32\nvedavt.dll"
"c:\windows\system32\nvgts.dll"
"c:\windows\system32\nvmd.dll"
"c:\windows\system32\nvrd64.dll"
"c:\windows\system32\NWDHCP.dll"
"c:\windows\system32\NWSNS.dll"
"c:\windows\system32\NWUSBModem.dll"
"c:\windows\system32\odysseyIM4.dll"
"c:\windows\system32\om518p.dll"
"c:\windows\system32\oracle%oracle_home_service%clientcache80.dll"
"c:\windows\system32\p2pimsvc.dll"
"c:\windows\system32\pctavsvc.dll"
"c:\windows\system32\pdcomp.dll"
"c:\windows\system32\pdiddcci.dll"
"c:\windows\system32\pdlnafac.dll"
"c:\windows\system32\pdlnshay.dll"
"c:\windows\system32\pfmodnt.dll"
"c:\windows\system32\pid_0928.dll"
"c:\windows\system32\ppa3.dll"
"c:\windows\system32\prismxl.dll"
"c:\windows\system32\processor.dll"
"c:\windows\system32\protexislicensing.dll"
"c:\windows\system32\PSDNServ.dll"
"c:\windows\system32\psdvdisk.dll"
"c:\windows\system32\qbposdbservices.dll"
"c:\windows\system32\ql12160.dll"
"c:\windows\system32\rdpdr.dll"
"c:\windows\system32\retroexplauncher.dll"
"c:\windows\system32\rimsptsk.dll"
"c:\windows\system32\RioS30.dll"
"c:\windows\system32\RivaTuner32.dll"
"c:\windows\system32\rksample.dll"
"c:\windows\system32\roxliveshare9.dll"
"c:\windows\system32\rpclocator.dll"
"c:\windows\system32\RR2Ctrl.dll"
"c:\windows\system32\rspndr.dll"
"c:\windows\system32\rt61.dll"
"c:\windows\system32\RTLE8023xp.dll"
"c:\windows\system32\s125mdm.dll"
"c:\windows\system32\se59mgmt.dll"
"c:\windows\system32\sentinelprotectionserver.dll"
"c:\windows\system32\service.dll"
"c:\windows\system32\SetupNT.dll"
"c:\windows\system32\sffdisk.dll"
"c:\windows\system32\SiSRaid.dll"
"c:\windows\system32\slabser.dll"
"c:\windows\system32\smapint.dll"
"c:\windows\system32\SMNDIS5.dll"
"c:\windows\system32\snapman380.dll"
"c:\windows\system32\snareiis.dll"
"c:\windows\system32\SNP2STD.dll"
"c:\windows\system32\spbbcsvc.dll"
"c:\windows\system32\Spsmqvsm.dll"
"c:\windows\system32\sr_service.dll"
"c:\windows\system32\statusagent4.dll"
"c:\windows\system32\sthda.dll"
"c:\windows\system32\stirusb.dll"
"c:\windows\system32\Sunkfiltp.dll"
"c:\windows\system32\sysaidagent.dll"
"c:\windows\system32\TeamViewer.dll"
"c:\windows\system32\tga.dll"
"c:\windows\system32\TPECioCtl.dll"
"c:\windows\system32\TPPWRIF.dll"
"c:\windows\system32\traprcvr.dll"
"c:\windows\system32\tsircsrv.dll"
"c:\windows\system32\twotrack.dll"
"c:\windows\system32\U81xmgmt.dll"
"c:\windows\system32\uagp35.dll"
"c:\windows\system32\ultra.dll"
"c:\windows\system32\UNDPX2A.dll"
"c:\windows\system32\us30service.dll"
"c:\windows\system32\USB_NDIS_51.dll"
"c:\windows\system32\UWProSys.dll"
"c:\windows\system32\VC6SecS.dll"
"c:\windows\system32\viaudio.dll"
"c:\windows\system32\vsbus.dll"
"c:\windows\system32\W55U01.dll"
"c:\windows\system32\Wbutton.dll"
"c:\windows\system32\websenselogserver.dll"
"c:\windows\system32\wencrservice.dll"
"c:\windows\system32\wfxsvc.dll"
"c:\windows\system32\WinFl32.dll"
"c:\windows\system32\WinVd32.dll"
"c:\windows\system32\wlancig.dll"
"c:\windows\system32\wusb54gv2svc.dll"
"c:\windows\system32\WUSB54Gv4SVC.dll"
"c:\windows\system32\x10nets.dll"
"c:\windows\system32\Xyz777s.dll"
"c:\windows\system32\yats32.dll"
"c:\windows\system32\z800mdm.dll"
.
.
((((((((((((((((((((((((( Files Created from 2012-03-28 to 2012-04-29 )))))))))))))))))))))))))))))))
.
.
2012-04-28 01:47 . 2012-04-28 01:47 -------- d-----w- C:\iso
2012-04-28 01:37 . 2012-04-28 01:37 -------- d-----w- c:\documents and settings\Cameron\Application Data\Malwarebytes
2012-04-28 01:37 . 2012-04-28 01:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2012-04-28 01:37 . 2012-04-28 01:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-04-28 01:37 . 2012-04-04 07:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-27 22:05 . 2012-04-27 22:34 -------- d-----w- C:\jgh
2012-04-26 13:57 . 2012-04-26 13:57 -------- d-----w- C:\_OTL
2012-04-26 13:57 . 2011-07-10 17:14 295248 -c--a-w- c:\windows\system32\dllcache\avgtdix.sys
2012-04-25 13:18 . 2012-04-25 22:49 -------- d-----w- C:\TDSSKiller_Quarantine
2012-04-24 05:19 . 2012-04-24 05:20 -------- d-----w- c:\documents and settings\Cameron\Local Settings\Application Data\NPE
2012-04-24 05:19 . 2012-04-24 05:19 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Norton
2012-04-24 05:08 . 2012-04-24 05:08 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\COMODO
2012-04-24 05:08 . 2012-04-24 05:08 -------- d-----w- c:\documents and settings\Cameron\Application Data\Comodo
2012-04-23 17:39 . 2012-04-23 17:39 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Apple Computer
2012-04-22 15:48 . 2012-04-22 15:48 -------- d-----w- c:\documents and settings\Cameron\Local Settings\Application Data\Identities
2012-04-20 00:23 . 2012-04-20 00:38 -------- d-----w- C:\sh4ldr
2012-04-20 00:23 . 2012-04-20 00:23 -------- d-----w- c:\program files\Enigma Software Group
2012-04-20 00:21 . 2012-04-20 00:38 -------- d-----w- c:\windows\4E0C6314A8B84026AC15084E8B63AFB5.TMP
2012-04-20 00:21 . 2012-04-20 00:21 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-04-19 23:48 . 2012-04-24 07:35 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\F4D55F2C000BBBB74E027CC6D151FC4E
2012-04-17 00:41 . 2012-04-17 00:41 -------- d--h--w- c:\documents and settings\All Users.WINDOWS\Application Data\CanonIJFAX
2012-04-17 00:40 . 2010-09-13 06:44 106496 ----a-w- c:\windows\system32\CNC410U.dll
2012-04-17 00:40 . 2010-09-13 06:42 1347584 ----a-w- c:\windows\system32\CNC410C.dll
2012-04-17 00:40 . 2010-09-13 06:42 114688 ----a-w- c:\windows\system32\CNC410I.dll
2012-04-17 00:40 . 2010-09-06 09:03 315392 ----a-w- c:\windows\system32\CNC410L.dll
2012-04-17 00:36 . 2012-04-19 02:05 -------- d-----w- c:\documents and settings\Cameron\Application Data\Canon Easy-WebPrint EX
2012-04-17 00:32 . 2010-10-20 21:00 257024 ----a-w- c:\windows\system32\CNCALAL.DLL
2012-04-17 00:32 . 2012-04-17 00:32 -------- d--h--w- c:\documents and settings\All Users.WINDOWS\Application Data\CanonBJ
2012-04-17 00:31 . 2010-09-19 21:00 74752 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPPAL.DLL
2012-04-17 00:31 . 2010-09-19 21:00 303104 ----a-w- c:\windows\system32\CNMLMAL.DLL
2012-04-17 00:31 . 2010-09-19 21:00 28672 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPDAL.DLL
2012-04-17 00:31 . 2012-04-17 00:31 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2012-04-17 00:31 . 2010-06-03 06:11 94208 ----a-w- c:\windows\system32\CNC410O.dll
2012-04-17 00:31 . 2010-09-07 01:58 180224 ----a-w- c:\windows\system32\CNMIUAL.DLL
2012-04-17 00:31 . 2012-04-17 00:31 -------- d--h--w- c:\program files\CanonBJ
2012-04-07 08:55 . 2012-04-07 08:55 -------- d-----w- C:\found.000
2012-04-07 07:42 . 2012-04-07 07:45 -------- d-----w- C:\big w prints
2012-04-07 07:07 . 2012-04-28 01:46 -------- d-----w- C:\Vuze
2012-04-07 06:48 . 2012-04-07 06:57 -------- d-----w- C:\To Transfer
2012-04-06 00:19 . 2012-04-14 15:02 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-01 03:09 . 2012-04-01 03:09 -------- d-----r- C:\g on Home PC (B03f21ae66bf49c)
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-26 14:10 . 2011-04-04 16:59 295248 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2012-04-25 13:22 . 2008-04-14 12:00 187776 ----a-w- c:\windows\system32\drivers\acpi.sys
2012-04-25 13:22 . 2008-04-14 12:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2012-04-14 15:02 . 2011-06-17 23:36 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-01 11:01 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01 . 2008-04-14 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2008-04-14 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2008-04-14 12:00 148480 ------w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-02-15 03:01 . 2011-12-15 14:13 4547944 ----a-w- c:\windows\system32\usbaaplrc.dll
2012-02-15 03:01 . 2011-12-15 14:13 43520 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2012-02-07 03:02 . 2012-02-07 03:02 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-03 09:22 . 2008-04-14 12:00 1860096 ------w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-27_10.46.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-29 00:51 . 2012-04-29 00:51 16384 c:\windows\Temp\Perflib_Perfdata_70c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-03-29 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"UpdatePDRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-06 222504]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"RTHDCPL"="RTHDCPL.EXE" [2010-04-06 19523104]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-26 421736]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-07-25 2569616]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-09-14 1213848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Cameron\Start Menu\Programs\Startup\
My Program.lnk - c:\program files\FingerPrint\FingerPrint.exe [2012-2-15 924728]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
NETGEAR WG311T Smart Wizard.lnk - c:\program files\NETGEAR\WG311T\wlancfg5.exe [2006-9-15 1503232]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Program Files\\FingerPrint\\FingerPrintService.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Plex\\Plex Media Server\\Plex Media Server.exe"=
"c:\\Program Files\\Plex\\Plex Media Server\\PlexScriptHost.exe"=
"c:\\Program Files\\Plex\\Plex Media Center\\Plex.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Safari\\Safari.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [22/02/2011 8:13 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [16/03/2011 4:03 PM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7/01/2011 6:41 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [5/04/2011 12:59 AM 295248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [12/10/2011 6:25 AM 4433248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/08/2011 6:09 AM 192776]
R2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [23/06/2009 5:40 PM 127352]
R2 FingerPrint;FingerPrint Service;c:\program files\FingerPrint\FingerPrintService.exe -start --> c:\program files\FingerPrint\FingerPrintService.exe -start [?]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [14/04/2011 9:28 PM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [10/02/2011 7:53 AM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10/02/2011 7:53 AM 16720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 1:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [28/03/2012 3:24 PM 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6/04/2012 8:19 AM 253088]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [10/05/2011 7:04 AM 1691480]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [28/03/2012 3:24 PM 116648]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [15/12/2011 10:13 PM 18432]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [6/05/2008 4:06 PM 11520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 1:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-06 15:02]
.
2012-04-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 09:57]
.
2012-04-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-28 07:24]
.
2012-04-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-28 07:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = *.local
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.1.1.1
DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} - hxxps://www.icloud.com/system/iCloud.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-04-29 09:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\05\03\0b\0a;9»"
.
Completion time: 2012-04-29 09:08:52
ComboFix-quarantined-files.txt 2012-04-29 01:08
ComboFix2.txt 2012-04-28 01:19
ComboFix3.txt 2012-04-27 22:34
ComboFix4.txt 2012-04-27 10:48
.
Pre-Run: 35,518,259,200 bytes free
Post-Run: 35,518,197,760 bytes free
.
- - End Of File - - DD853BF5336988CE58D449306C09E703