Hope this helps
ComboFix 09-09-20.01 - steven1 09/21/2009 16:41.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1483 [GMT 10:00]
Running from: d:\program files\Mozilla firefox\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\1413d.msi
.
((((((((((((((((((((((((( Files Created from 2009-08-21 to 2009-09-21 )))))))))))))))))))))))))))))))
.
2009-09-20 03:12 . 2009-09-20 03:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Frag great bend logo
2009-09-20 03:12 . 2009-09-20 03:13 -------- d-----w- c:\documents and settings\steven1\Application Data\Open Ooze
2009-09-20 03:12 . 2009-09-20 03:12 -------- d-----w- c:\program files\Open Ooze
2009-09-20 03:12 . 2009-09-20 03:12 -------- d-----w- c:\program files\Circle Develoement
2009-09-20 03:12 . 2009-09-20 03:12 -------- d-----w- c:\program files\Messenger Plus! Live
2009-09-19 06:09 . 2009-09-19 06:20 76580 ----a-w- c:\windows\War3Unin.dat
2009-09-19 06:09 . 2009-09-19 06:17 2829 ----a-w- c:\windows\War3Unin.pif
2009-09-19 06:09 . 2009-09-19 06:17 139264 ----a-w- c:\windows\War3Unin.exe
2009-09-16 06:10 . 2009-09-16 06:10 -------- d-----w- c:\windows\system32\Futuremark
2009-09-16 06:10 . 2008-09-17 05:14 27672 ----a-r- c:\windows\system32\drivers\Entech.sys
2009-09-16 06:10 . 2009-09-16 06:10 -------- d-----w- c:\program files\Common Files\Futuremark Shared
2009-09-14 09:02 . 2009-09-14 09:02 -------- d-----w- c:\documents and settings\steven1\Application Data\DivX
2009-09-09 08:01 . 2009-09-09 08:09 -------- d-----w- c:\program files\RS2Bot
2009-09-09 08:01 . 2009-09-21 06:25 -------- d-----w- c:\program files\Free Offers from Freeze.com
2009-09-06 07:14 . 2009-09-06 07:14 -------- d-----w- c:\program files\NVIDIA Corporation
2009-09-06 07:14 . 2009-09-06 07:14 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-09-06 07:08 . 2009-09-16 06:12 -------- d-----w- c:\program files\SystemRequirementsLab
2009-09-06 07:08 . 2009-09-16 06:12 -------- d-----w- c:\documents and settings\steven1\Application Data\SystemRequirementsLab
2009-09-06 07:01 . 2009-09-20 22:25 253400 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-06 06:37 . 2009-09-06 08:21 -------- d-----w- c:\documents and settings\steven1\Local Settings\Application Data\Rockstar Games
2009-09-06 06:33 . 2009-09-06 06:33 -------- d-----w- c:\windows\ServicePackFiles
2009-09-06 06:23 . 2009-09-06 06:23 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-09-06 06:18 . 2009-09-06 06:18 -------- d-----w- c:\windows\system32\xlive
2009-09-06 06:18 . 2009-09-06 06:50 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-09-06 05:13 . 2009-09-06 05:13 -------- d-----w- c:\program files\MSBuild
2009-09-04 09:11 . 2009-09-04 09:11 -------- d-----w- c:\documents and settings\steven1\Local Settings\Application Data\Oblivion
2009-09-03 06:15 . 2009-09-19 05:30 45 ----a-w- c:\documents and settings\steven1\jagex_runescape_preferences2.dat
2009-08-30 13:16 . 2009-08-30 13:24 -------- d-----w- C:\OutputFolder
2009-08-30 13:15 . 2007-04-12 04:19 129024 ----a-w- c:\windows\system32\AVERM.dll
2009-08-30 13:15 . 2006-09-26 03:57 28672 ----a-w- c:\windows\system32\AVEQT.dll
2009-08-30 13:15 . 2009-08-31 08:47 -------- d-----w- c:\program files\Allok MPEG4 Converter
2009-08-30 10:15 . 2009-08-30 10:15 -------- d-----w- c:\program files\Common Files\xing shared
2009-08-30 10:15 . 2009-08-30 10:15 -------- d-----w- c:\program files\Common Files\Real
2009-08-30 10:15 . 2009-08-30 10:15 -------- d-----w- c:\program files\Real
2009-08-29 10:13 . 2009-08-29 10:13 278984 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-08-29 10:13 . 2009-08-29 10:13 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-21 06:04 . 2008-04-08 13:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-20 12:55 . 2009-08-12 05:54 23 ----a-w- c:\windows\popcinfot.dat
2009-09-19 14:30 . 2009-07-09 07:23 -------- d-----w- c:\documents and settings\steven1\Application Data\uTorrent
2009-09-19 11:13 . 2009-07-09 12:02 -------- d-----w- c:\program files\Garena
2009-09-19 06:03 . 2009-07-24 07:06 37 ----a-w- c:\documents and settings\steven1\jagex_runescape_preferences.dat
2009-09-16 06:10 . 2008-04-08 12:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-06 10:27 . 2009-07-08 05:42 72696 ----a-w- c:\documents and settings\steven1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-05 14:26 . 2009-07-10 10:28 -------- d-----w- c:\documents and settings\steven1\Application Data\LimeWire
2009-09-02 21:56 . 2008-04-08 13:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-02 06:52 . 2008-04-08 13:08 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-26 11:03 . 2009-07-10 10:27 -------- d-----w- c:\program files\LimeWire
2009-08-26 08:20 . 2009-07-24 07:17 -------- d-----w- c:\program files\Java
2009-08-18 12:30 . 2009-08-18 12:30 -------- d-----w- c:\program files\IVT Corporation
2009-08-18 11:56 . 2009-08-18 11:56 28760 ----a-w- c:\windows\system32\BsTrace1.dll
2009-08-18 10:43 . 2009-08-18 10:43 -------- d-----w- c:\program files\DIFX
2009-08-18 10:43 . 2009-08-18 10:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-08-16 17:04 . 2009-08-16 17:04 2173472 ----a-w- c:\windows\system32\nvcplui.exe
2009-08-16 17:04 . 2009-08-16 17:04 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-08-16 17:03 . 2009-08-16 17:03 3170304 ----a-w- c:\windows\system32\nvwss.dll
2009-08-16 17:03 . 2009-08-16 17:03 4026368 ----a-w- c:\windows\system32\nvvitvs.dll
2009-08-16 17:03 . 2009-08-16 17:03 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-08-16 17:03 . 2009-08-16 17:03 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-08-16 17:03 . 2009-08-16 17:03 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-08-16 17:03 . 2009-08-16 17:03 4923392 ----a-w- c:\windows\system32\nvdisps.dll
2009-08-16 17:03 . 2009-08-16 17:03 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-08-16 17:03 . 2009-08-16 17:03 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-08-16 17:03 . 2009-08-16 17:03 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-08-16 17:03 . 2009-08-16 17:03 13877248 ----a-w- c:\windows\system32\nvcpl.dll
2009-08-16 17:02 . 2009-08-16 17:02 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-08-16 14:57 . 2009-06-09 20:03 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-08-16 14:57 . 2009-06-09 20:03 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-08-16 14:57 . 2009-06-09 20:03 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-08-16 14:57 . 2009-06-09 20:03 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-08-16 14:57 . 2008-04-08 12:43 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-08-16 14:57 . 2008-04-08 12:43 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-08-16 14:57 . 2008-04-08 12:43 155648 ----a-w- c:\windows\system32\nvcodins.dll
2009-08-16 14:57 . 2008-04-08 12:43 155648 ----a-w- c:\windows\system32\nvcod.dll
2009-08-16 14:57 . 2008-04-08 12:43 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-08-16 14:57 . 2008-04-08 12:43 7729568 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-08-16 14:57 . 2008-04-08 12:43 5845760 ----a-w- c:\windows\system32\nv4_disp.dll
2009-08-15 11:42 . 2009-08-15 11:42 -------- d-----w- c:\program files\Reference Assemblies
2009-08-15 11:39 . 2009-08-15 11:39 -------- d--h--r- c:\documents and settings\steven1\Application Data\SecuROM
2009-08-13 11:37 . 2009-08-13 11:26 -------- d-----w- c:\documents and settings\steven1\Application Data\TeamViewer
2009-08-13 11:33 . 2009-08-13 11:33 -------- d-----w- c:\program files\TeamViewer
2009-08-13 09:56 . 2009-08-13 09:56 -------- d-----w- c:\documents and settings\steven1\Application Data\com.adobe.ExMan
2009-08-13 06:08 . 2009-08-13 06:08 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-08-13 05:59 . 2009-08-13 05:59 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-08-12 22:23 . 2009-07-31 06:15 -------- d-----w- c:\program files\Common Files\TortoiseOverlays
2009-08-12 22:23 . 2009-07-31 06:15 -------- d-----w- c:\program files\TortoiseSVN
2009-08-11 02:35 . 2009-07-10 12:03 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-08-09 03:41 . 2009-07-11 03:02 -------- d-----w- c:\documents and settings\steven1\Application Data\Auslogics
2009-08-07 09:51 . 2009-08-07 09:51 15308424 ----a-w- c:\windows\system32\xlive.dll
2009-08-07 09:51 . 2009-08-07 09:51 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-08-07 03:08 . 2009-08-07 03:08 -------- d-----w- c:\program files\Windows Media Connect 2
2009-07-31 06:53 . 2009-07-31 06:53 -------- d-----w- c:\documents and settings\steven1\Application Data\TortoiseSVN
2009-07-31 06:31 . 2009-07-31 06:31 -------- d-----w- c:\program files\Sun
2009-07-31 06:27 . 2009-07-31 06:27 -------- d-----w- c:\documents and settings\steven1\Application Data\Subversion
2009-07-24 19:23 . 2009-07-24 07:17 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 07:07 . 2009-07-17 07:07 50 ----a-w- c:\windows\system32\bridf06a.dat
2009-07-12 10:44 . 2009-07-12 10:44 22328 ----a-w- c:\documents and settings\steven1\Application Data\PnkBstrK.sys
2009-07-11 05:05 . 2009-07-11 05:05 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-03 23:13 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-03 23:13 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-03 23:13 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-03 23:13 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-03 23:13 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-03 23:13 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-03 23:13 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-03 23:13 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-03 23:13 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"RGSC"="d:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2009-09-06 306088]
"interidle"="c:\docume~1\steven1\APPLIC~1\OPENOO~1\Tickeggs.exe" [2009-09-20 663552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-06 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-06 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-06 455168]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-27 622592]
"SetDefPrt"="c:\program files\Brother\Brmfl06b\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-06-01 1468296]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-24 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-30 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-12 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-16 13877248]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-16 86016]
"bend logo clock film"="c:\documents and settings\All Users\Application Data\Frag great bend logo\Copy Safe.exe" [2009-09-21 819200]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-03-17 61952]
[HKLM\~\startupfolder\C:^Documents and Settings^steven1^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\steven1\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Symantec AntiVirus"=2 (0x2)
"SPBBCSvc"=3 (0x3)
"SNDSrvc"=3 (0x3)
"DefWatch"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForever.exe"=
"d:\\Program files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForeverLauncher.exe"=
"d:\\Program files\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"d:\\Program files\\Steam\\steamapps\\nigga21\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"d:\\Program files\\Steam\\steamapps\\nigga21\\insurgency\\hl2.exe"=
"d:\\Program files\\Steam\\Steam.exe"=
"d:\\Program files\\Steam\\steamapps\\nigga21\\source dedicated server\\srcds.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"d:\\Program files\\Steam\\steamapps\\nigga21\\source sdk base 2007\\hl2.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
"d:\\Program files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"d:\\Program files\\Steam\\steamapps\\nigga21\\team fortress 2\\hl2.exe"=
"d:\\Program files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\Program files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [1/7/2009 11:39 PM 20744]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [4/8/2008 10:39 PM 1275584]
S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [12/7/2008 12:44 PM 30088]
S3 cpuz130;cpuz130;\??\c:\docume~1\steven1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\steven1\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\steven1\LOCALS~1\Temp\FFR296.tmp --> c:\docume~1\steven1\LOCALS~1\Temp\FFR296.tmp [?]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [7/2/2008 2:58 PM 26248]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" --> c:\program files\Symantec AntiVirus\SavRoam.exe [?]
.
Contents of the 'Scheduled Tasks' folder
2009-09-20 c:\windows\Tasks\A553F99F90A46ECF.job
- c:\docume~1\steven1\applic~1\openoo~1\Book 4 owns.exe [2009-09-20 03:13]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\steven1\Application Data\Mozilla\Firefox\Profiles\aqzow3ck.default\
FF - prefs.js: browser.startup.homepage -
www.google.com
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
AddRemove-LiveUpdate - c:\program files\Symantec\LiveUpdate\LSETUP.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-21 16:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\steven1\LOCALS~1\Temp\FFR296.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1993962763-413027322-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:4f,99,dc,36,83,ec,d4,46,eb,d2,f5,2e,94,de,d8,68,c4,7a,26,82,a7,
57,ba,c3,84,2b,a0,cc,91,71,83,15,f7,3d,25,fa,d0,45,27,2d,dc,0f,6c,fe,ce,24,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-09-21 16:45
ComboFix-quarantined-files.txt 2009-09-21 06:45
Pre-Run: 68,337,336,320 bytes free
Post-Run: 68,375,846,912 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
294 --- E O F --- 2008-04-08 13:44