ComboFix ran successfully
Hello again - renaming ComboFix.exe per your instructions allowed it to run, and it detected and removed several files. Following is the C:\ComboFix.log produced by this run - the file log.txt, which was opened in Notepad, is identical to this file. You also requested a file named "New dds.txt log." which doesn't appear to be on my system. Please let me know if I should rerun DDS to create.
ComboFix 09-06-16.05 - Ben 06/17/2009 13:46.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.2274 [GMT -7:00]
Running from: c:\users\Ben\Desktop\blue.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\gxvxcbrntdoqvoqixgbirrtyxtyiuyivwiltf.sys
c:\windows\system32\gxvxccount
c:\windows\system32\gxvxcqlxgpmfeynjdipfmdvsaxumprhihwcit.dll
c:\windows\system32\gxvxcvterhpgrwsrpkmctbddgaleochrpsdsb.dll
D:\Desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_GXVXCSERV.SYS
((((((((((((((((((((((((( Files Created from 2009-05-17 to 2009-06-17 )))))))))))))))))))))))))))))))
.
2009-06-17 20:57 . 2009-06-17 20:57 -------- d-----w- c:\users\Ben\AppData\Local\temp
2009-06-15 17:58 . 2009-06-15 17:58 -------- d-----w- c:\temp\hjt
2009-06-14 02:32 . 2009-06-14 02:32 -------- d-----w- c:\program files\Trend Micro
2009-06-14 02:29 . 2009-06-14 02:29 -------- d-----w- c:\program files\ERUNT
2009-06-13 19:45 . 2009-06-14 03:00 680 ----a-w- c:\users\Ben\AppData\Local\d3d9caps.dat
2009-06-13 19:09 . 2009-06-14 00:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-13 19:09 . 2009-06-14 00:08 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-06-12 17:54 . 2009-06-14 00:20 -------- d-----w- c:\program files\Debugging Tools for Windows (x86)
2009-06-10 20:23 . 2009-06-10 20:23 -------- d-----w- c:\users\Ben\AppData\Roaming\VanDyke
2009-06-10 09:14 . 2009-06-10 09:14 -------- d-----w- c:\program files\VanDyke Software
2009-06-10 09:13 . 2009-06-10 09:13 -------- d-----w- c:\users\Ben\AppData\Local\Downloaded Installations
2009-06-10 06:23 . 2009-06-10 06:23 -------- d-----w- c:\programdata\Citrix
2009-06-10 06:19 . 2009-06-10 06:19 -------- d-----w- c:\program files\Citrix
2009-06-10 06:19 . 2009-06-10 06:19 -------- d-----w- c:\users\Ben\AppData\Local\Citrix
2009-06-04 07:25 . 2009-06-04 07:25 -------- d-----w- c:\program files\PopCap Games
2009-06-02 08:22 . 2009-06-02 08:22 -------- d-----w- c:\programdata\PopCap Games
2009-05-28 09:50 . 2009-05-28 09:50 -------- d-----w- c:\windows\system32\ca-ES
2009-05-28 09:50 . 2009-05-28 09:50 -------- d-----w- c:\windows\system32\eu-ES
2009-05-28 09:50 . 2009-05-28 09:50 -------- d-----w- c:\windows\system32\vi-VN
2009-05-26 19:45 . 2009-05-26 19:45 -------- d-----w- c:\windows\system32\EventProviders
2009-05-26 19:43 . 2009-04-11 06:32 53224 ----a-w- c:\windows\system32\drivers\termdd.sys
2009-05-26 19:42 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-05-22 12:19 . 2009-05-22 19:38 -------- d-----w- C:\sctemp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 18:44 . 2009-05-02 09:01 -------- d-----w- c:\users\Ben\AppData\Roaming\uTorrent
2009-05-28 18:05 . 2008-01-08 01:17 -------- d-----w- c:\programdata\NVIDIA
2009-05-28 09:50 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-05-28 09:50 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-05-28 09:50 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-05-28 09:50 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-28 09:50 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-05-28 09:50 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-05-28 09:50 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-05-28 09:50 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-05-21 21:12 . 2009-05-05 00:54 -------- d-----w- c:\program files\WinMount3
2009-05-13 16:52 . 2009-05-13 16:52 -------- d-----w- c:\program files\Sonic.net Personal Data Backup
2009-05-12 20:30 . 2008-01-07 23:52 -------- d-----w- c:\programdata\Microsoft Help
2009-05-10 03:13 . 2008-01-07 23:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-09 08:16 . 2008-07-05 02:02 -------- d-----w- c:\program files\Bethesda Softworks
2009-05-05 22:07 . 2009-05-05 22:07 -------- d-----w- c:\users\Ben\AppData\Roaming\StarBurn
2009-05-05 21:39 . 2009-05-05 21:39 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-05-05 00:54 . 2009-05-05 00:54 -------- d-----w- c:\users\Ben\AppData\Roaming\Local Settings
2009-05-05 00:54 . 2009-05-05 00:54 37376 ----a-w- c:\windows\system32\drivers\WMDrive.sys
2009-05-03 22:34 . 2008-03-23 23:53 -------- d-----w- c:\program files\Quicken
2009-05-03 22:28 . 2009-05-03 22:28 3616768 ----a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181311-181414.dll
2009-05-03 22:27 . 2009-05-03 22:27 1536000 ----a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181414-18154.dll
2009-05-03 22:27 . 2009-05-03 22:27 1007616 ----a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181129-181212.dll
2009-05-03 22:27 . 2009-05-03 22:27 811008 ----a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\181212-181311.dll
2009-05-03 22:26 . 2009-05-03 22:26 242976 ----a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2009-05-03 22:26 . 2009-05-03 22:26 223584 ----a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\patchw32.dll
2009-05-03 22:26 . 2009-05-03 22:26 997 ----a-w- c:\programdata\Intuit\Quicken\Inet\Common\patch\Update\rebase.cmd
2009-05-03 22:23 . 2009-05-03 22:23 -------- d-----w- c:\program files\Common Files\AnswerWorks 5.0
2009-05-03 09:26 . 2009-05-03 09:25 -------- d-----w- c:\program files\Microsoft
2009-05-03 09:25 . 2009-05-03 09:25 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-05-03 09:23 . 2009-05-03 09:23 -------- d-----w- c:\program files\Common Files\Windows Live
2009-05-02 09:12 . 2009-05-02 09:11 -------- d-----w- c:\program files\Rockstar Games
2009-04-28 21:58 . 2008-03-23 00:51 103128 ----a-w- c:\users\Ben\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-28 21:51 . 2008-01-07 23:50 -------- d-----w- c:\program files\Microsoft Works
2009-04-22 07:20 . 2009-04-22 07:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-22 07:20 . 2009-04-22 07:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-21 05:00 . 2008-07-30 06:27 -------- d-----w- c:\program files\McAfee
2009-04-20 03:54 . 2009-04-20 03:54 -------- d-----w- c:\program files\Lighthouse Interactive
2009-04-11 06:33 . 2009-05-26 19:44 986600 ----a-w- c:\windows\system32\winload.exe
2009-04-11 06:33 . 2009-05-26 19:44 926184 ----a-w- c:\windows\system32\winresume.exe
2009-04-11 06:33 . 2009-05-26 19:43 292840 ----a-w- c:\windows\system32\drivers\volmgrx.sys
2009-04-11 06:33 . 2009-05-26 19:44 897000 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-04-11 06:33 . 2009-05-26 19:44 614376 ----a-w- c:\windows\system32\ci.dll
2009-04-11 06:28 . 2009-05-26 19:44 56320 ----a-w- c:\windows\system32\xmlfilter.dll
2009-04-11 06:27 . 2009-05-26 19:44 441344 ----a-w- c:\windows\system32\SearchIndexer.exe
2009-04-11 06:22 . 2009-05-26 19:43 7168 ----a-w- c:\windows\system32\f3ahvoas.dll
2009-04-11 06:21 . 2009-05-26 19:43 37376 ----a-w- c:\windows\system32\cdd.dll
2009-04-11 05:42 . 2009-05-26 19:43 93696 ----a-w- c:\windows\system32\drivers\bridge.sys
2009-04-11 05:03 . 2009-05-26 19:44 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-04-11 05:03 . 2009-05-26 19:44 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2009-04-11 04:57 . 2009-05-26 19:43 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-04-11 04:54 . 2009-05-26 19:43 2048 ----a-w- c:\windows\system32\mferror.dll
2009-04-11 04:51 . 2009-05-26 19:43 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2009-04-11 04:47 . 2009-05-26 19:43 273920 ----a-w- c:\windows\system32\drivers\afd.sys
2009-04-11 04:46 . 2009-05-26 19:43 69120 ----a-w- c:\windows\system32\drivers\rassstp.sys
2009-04-11 04:46 . 2009-05-26 19:43 121344 ----a-w- c:\windows\system32\drivers\ndiswan.sys
2009-04-11 04:46 . 2009-05-26 19:43 41472 ----a-w- c:\windows\system32\drivers\raspppoe.sys
2009-04-11 04:46 . 2009-05-26 19:43 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2009-04-11 04:46 . 2009-05-26 19:43 33280 ----a-w- c:\windows\system32\drivers\RNDISMP.sys
2009-04-11 04:46 . 2009-05-26 19:43 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-04-11 04:45 . 2009-05-26 19:43 72192 ----a-w- c:\windows\system32\drivers\tdx.sys
2009-04-11 04:45 . 2009-05-26 19:43 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2009-04-11 04:45 . 2009-05-26 19:43 185856 ----a-w- c:\windows\system32\drivers\netbt.sys
2009-04-11 04:45 . 2009-05-26 19:43 401408 ----a-w- c:\windows\system32\drivers\http.sys
2009-04-11 04:45 . 2009-05-26 19:43 113664 ----a-w- c:\windows\system32\drivers\rmcast.sys
2009-04-11 04:45 . 2009-05-26 19:43 66560 ----a-w- c:\windows\system32\drivers\smb.sys
2009-04-11 04:43 . 2009-05-26 19:43 148480 ----a-w- c:\windows\system32\drivers\nwifi.sys
2009-04-11 04:43 . 2009-05-26 19:44 196096 ----a-w- c:\windows\system32\drivers\usbhub.sys
2009-04-11 04:42 . 2009-05-26 19:44 226304 ----a-w- c:\windows\system32\drivers\usbport.sys
2009-04-11 04:42 . 2009-05-26 19:43 25856 ----a-w- c:\windows\system32\drivers\USBCAMD2.sys
2009-04-11 04:42 . 2009-05-26 19:43 25856 ----a-w- c:\windows\system32\drivers\USBCAMD.sys
2009-04-11 04:42 . 2009-05-26 19:43 73216 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-04-11 04:42 . 2009-05-26 19:43 39936 ----a-w- c:\windows\system32\drivers\usbehci.sys
2009-04-11 04:42 . 2009-05-26 19:43 19456 ----a-w- c:\windows\system32\drivers\usbohci.sys
2009-04-11 04:42 . 2009-05-26 19:43 167936 ----a-w- c:\windows\system32\drivers\portcls.sys
2009-04-11 04:42 . 2009-05-26 19:43 12800 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-04-11 04:42 . 2009-05-26 19:43 39424 ----a-w- c:\windows\system32\drivers\hidclass.sys
2009-04-11 04:42 . 2009-05-26 19:43 52992 ----a-w- c:\windows\system32\drivers\stream.sys
2009-04-11 04:42 . 2009-05-26 19:44 561152 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2009-04-11 04:39 . 2009-05-26 19:43 16384 ----a-w- c:\windows\system32\iscsilog.dll
2009-04-11 04:39 . 2009-05-26 19:43 67072 ----a-w- c:\windows\system32\drivers\cdrom.sys
2009-04-11 04:39 . 2009-05-26 19:43 19456 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2009-04-11 04:38 . 2009-05-26 19:43 149504 ----a-w- c:\windows\system32\drivers\ks.sys
2009-04-11 04:38 . 2009-05-26 19:43 17408 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-04-11 04:27 . 2009-05-26 19:43 2560 ----a-w- c:\windows\system32\msimsg.dll
2009-04-11 04:24 . 2009-05-26 19:44 2034688 ----a-w- c:\windows\system32\win32k.sys
2009-04-11 04:23 . 2009-05-26 19:44 626176 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-04-11 04:23 . 2009-05-26 19:43 76288 ----a-w- c:\windows\system32\drivers\dxg.sys
2009-04-11 04:23 . 2009-05-26 19:43 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-04-11 04:22 . 2009-05-26 19:43 33280 ----a-w- c:\windows\system32\drivers\watchdog.sys
2009-04-11 04:15 . 2009-05-26 19:44 288768 ----a-w- c:\windows\system32\drivers\srv.sys
2009-04-11 04:15 . 2009-05-26 19:43 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-04-11 04:15 . 2009-05-26 19:43 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-04-11 04:14 . 2009-05-26 19:44 114688 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2009-04-11 04:14 . 2009-05-26 19:44 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-04-11 04:14 . 2009-05-26 19:44 225280 ----a-w- c:\windows\system32\drivers\rdbss.sys
2009-04-11 04:14 . 2009-05-26 19:43 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2009-04-11 04:14 . 2009-05-26 19:43 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-04-11 04:14 . 2009-05-26 19:43 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2009-04-11 04:14 . 2009-05-26 19:43 35328 ----a-w- c:\windows\system32\drivers\npfs.sys
2008-01-19 07:33 . 2008-03-24 10:41 397312 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fb\WinMail.exe
2008-01-19 07:33 . 2008-03-24 10:41 397312 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6002.18005_none_f343a6944cd6fe47\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnhancedStorageShell]
@="{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}"
[HKEY_CLASSES_ROOT\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}]
2009-04-11 06:28 114176 ----a-w- c:\windows\System32\EhStorShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2007-03-05 1103480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"c:\windows\system32\V0350Ext.ax"="c:\windows\system32\V0350Ext.ax" [X]
"ButtonMonitor"="c:\program files\IOI\ButtonMonitor.exe" [2007-05-11 53248]
"V0350Mon.exe"="c:\windows\V0350Mon.exe" [2007-08-23 28672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"SecureClean4Tray"="c:\program files\WhiteCanyon\SecureClean 4\sctray4.exe" [2007-05-17 1525248]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-04 111936]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-26 13683232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-26 92704]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-01 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-10-31 4702208]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-10-11 1826816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-07-13 40072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"BindDirectlyToPropertySetStorage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b4,c9,a0,ab,7a,df,c9,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{868B1DE4-AE24-40B5-898E-B0401BA607E0}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{1A52C799-8E4A-4A73-92E6-40B1C340A28E}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C5A44B37-455B-4A63-BEF4-BD1C1B71CEFD}"= Disabled:UDP:3724:Blizzard Downloader: 3724
"{DD02E8AE-D3B6-4B50-8A4C-19C22C99AF8D}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{02E03623-A3BC-4A55-8B56-30F2A56C4F03}"= UDP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{EC67DDBA-9A55-4D57-9EDC-4AC7D71CFD16}"= TCP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{A04F1917-82FA-46F3-9620-6CC80C12AB16}"= UDP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"{AC9D4096-C860-4D93-B2AF-B079EE3E99F6}"= TCP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"{3A85660B-70B8-4FBF-8913-2F9B0E18209B}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{8757240A-04BE-4F34-98D8-B24CC70D54FD}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C9BDFC0B-E810-44EB-9CB1-863BC774499C}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{413C08A1-DCE4-4840-A0EA-AE539E020565}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{9A3DF3B8-CFC5-4DE9-AAFC-2E95375883A3}"= UDP:c:\program files\Ubisoft\Lost Via Domus\Yeti_Final_Win32.exe:Lost Via Domus Game
"{EB58312D-6FFC-45A1-920E-764DA7EAEBEC}"= TCP:c:\program files\Ubisoft\Lost Via Domus\Yeti_Final_Win32.exe:Lost Via Domus Game
"{B77A0883-B74D-42C5-96AF-B208308D50E2}"= UDP:c:\program files\Ubisoft\Lost Via Domus\gu.exe:Lost Via Domus Updater
"{E3262F46-216C-4B93-841D-0F9DCAAAC064}"= TCP:c:\program files\Ubisoft\Lost Via Domus\gu.exe:Lost Via Domus Updater
"{2C4BEA35-E428-4CEA-B846-93B4753BCBDA}"= UDP:c:\program files\Ubisoft\Lost Via Domus\detection\Launcher.exe:Lost Via Domus Requirements Tool
"{869F4EF5-970A-492E-9F84-560DC6F0F009}"= TCP:c:\program files\Ubisoft\Lost Via Domus\detection\Launcher.exe:Lost Via Domus Requirements Tool
"{92A6D25E-D63A-436A-98C0-85F24180B3B1}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{624C82D0-6C41-433A-9B50-CF6130EDFAE5}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{1B72D946-4A8F-46BE-B38F-DBC60ED08923}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{5A4D071D-EDC2-40B4-AF56-0851B6BF0996}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{9854779C-8FFA-4470-A07D-1648B59E9EA5}"= UDP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{24B93193-BD1B-43A3-8A0A-44A65B14B40B}"= TCP:c:\program files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"TCP Query User{CE342419-378B-4E03-9E8C-A9FBD55474F5}c:\\program files\\sony\\station\\launchpad\\launchpad.exe"= UDP:c:\program files\sony\station\launchpad\launchpad.exe:LaunchPad
"UDP Query User{0CE88034-57D4-4516-970E-A2263A70FB6D}c:\\program files\\sony\\station\\launchpad\\launchpad.exe"= TCP:c:\program files\sony\station\launchpad\launchpad.exe:LaunchPad
"TCP Query User{52785CAE-41C0-4BAB-9D53-6A37E9CECB1C}c:\\program files\\world of warcraft\\wow-2.3.0-enus-downloader.exe"= Disabled:UDP:c:\program files\world of warcraft\wow-2.3.0-enus-downloader.exe:Blizzard Downloader
"UDP Query User{0A8B078B-68B0-4306-96D8-6DBD8090CEAB}c:\\program files\\world of warcraft\\wow-2.3.0-enus-downloader.exe"= Disabled:TCP:c:\program files\world of warcraft\wow-2.3.0-enus-downloader.exe:Blizzard Downloader
"{E066A09F-A3DB-40AE-9C57-1D4EFFA7B86B}"= Disabled:UDP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{3D6955F6-6726-4C23-8CEC-320CB8B0FBED}"= Disabled:TCP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{6EFCADD6-7C0C-415C-BD90-8BAC177B57FE}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"TCP Query User{94AF89EE-A490-4A77-9A25-9B00ADD5F27E}c:\\program files\\1701 a.d\\1701.exe"= UDP:c:\program files\1701 a.d\1701.exe:Anno 1701
"UDP Query User{9356841E-8BA1-44F2-993B-BD057838BEE4}c:\\program files\\1701 a.d\\1701.exe"= TCP:c:\program files\1701 a.d\1701.exe:Anno 1701
"{AC093992-450C-4494-A45C-B3B38BABA0B3}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A5084631-7D69-4A5D-BDB2-0779A1AF6E4A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{9E03DBB4-3163-447E-9EDE-F4DD9576889C}"= UDP:c:\program files\Valve\Steam\SteamApps\common\mosby's confederacy\MosbysConfederacy.exe:Mosby's Confederacy
"{D7A2FB18-044B-4A6A-9414-5856245A0D01}"= TCP:c:\program files\Valve\Steam\SteamApps\common\mosby's confederacy\MosbysConfederacy.exe:Mosby's Confederacy
"{0C95AEBB-3EB8-4CF6-9F0C-75A6709067D3}"= UDP:c:\program files\Valve\Steam\SteamApps\common\world of goo\WorldOfGoo.exe:World of Goo
"{156B4AC8-0D37-4EC5-9829-2717DA09A93C}"= TCP:c:\program files\Valve\Steam\SteamApps\common\world of goo\WorldOfGoo.exe:World of Goo
"{122CD2DF-28E6-452E-8778-58A843C4CC53}"= UDP:c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club
"{4E7B15F4-EF2D-497E-B18E-287C34C5613B}"= TCP:c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:Rockstar Games Social Club
"{4FC5CB30-328F-47BA-8287-C8AA1E32D6AB}"= UDP:c:\program files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV
"{7FE47F97-92A1-43D2-B9A0-84100CF8D678}"= TCP:c:\program files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:Grand Theft Auto IV
"TCP Query User{671411CD-715A-471C-8EFA-D2DCA5CB211A}c:\\program files\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:c:\program files\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV
"UDP Query User{78EFE075-8349-4467-BAC5-909EA28D65FA}c:\\program files\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:c:\program files\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV
"{1A31631A-1422-41DA-8225-B1DA9327DAED}"= UDP:c:\program files\Valve\Steam\SteamApps\common\left 4 dead\left4dead.exe:Left 4 Dead
"{EA8C257A-1968-4161-A652-5BF6FE4832FC}"= TCP:c:\program files\Valve\Steam\SteamApps\common\left 4 dead\left4dead.exe:Left 4 Dead
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\System32\drivers\StarPortLite.sys [5/5/2009 2:38 PM 95592]
R2 Creative Audio Pack Licensing Service;Creative Audio Pack Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\APLicensing.exe [5/27/2008 12:30 AM 72704]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [9/4/2008 11:34 PM 210216]
R3 AVer88xHD;AVerMedia 23888 AvStream Video Capture;c:\windows\System32\drivers\AVer88xHD.sys [1/7/2008 4:43 PM 401408]
S3 MovRVDrv32;MovRVDrv32;c:\windows\System32\drivers\MovRVDrv32.sys [5/27/2008 1:17 AM 3768]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [11/2/2006 3:25 AM 2589184]
S3 TucbDriverV32;TucbDriverV32;c:\windows\System32\drivers\TucbDriverV32.sys [5/26/2008 1:53 AM 23096]
S3 TucbVideo32;TucbVideo32;c:\windows\System32\drivers\TucbVideo32.sys [5/26/2008 1:53 AM 3768]
S3 VF0350Afx;VF0350 Audio FX;c:\windows\System32\drivers\V0350Afx.sys [3/29/2008 11:19 PM 142656]
S3 VF0350Vfx;VF0350 Video FX;c:\windows\System32\drivers\V0350Vfx.sys [3/29/2008 11:19 PM 7424]
S3 VF0350Vid;Live! Cam Video IM (VF0350);c:\windows\System32\drivers\V0350Vid.sys [3/29/2008 11:19 PM 170368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rsmsvcs REG_MULTI_SZ ntmssvc
.
Contents of the 'Scheduled Tasks' folder
2009-06-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-01 17:53]
2009-06-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-01 17:53]
2009-06-17 c:\windows\Tasks\User_Feed_Synchronization-{CFC35F22-AAF0-4AB6-A948-A00655898034}.job
- c:\windows\system32\msfeedssync.exe [2008-03-24 07:33]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-mfehidk
SafeBoot-mferkdk
SafeBoot-mfetdik
SafeBoot-mfetdik.sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.fark.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=FX7020
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Ben\AppData\Roaming\Mozilla\Firefox\Profiles\tv071v5e.default\
FF - prefs.js: browser.startup.homepage -
www.fark.com
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npff_gdm.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-17 13:57
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2454856603-3589663656-832898514-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b9,12,7e,85,3b,6e,71,58,ad,02,01,8e,60,a3,22,22,88,19,16,1c,ca,0d,90,
02,fe,03,ac,25,46,21,21,b2,0a,68,c2,8a,0a,b2,a5,d5,06,a5,40,88,11,6d,d8,68,\
"??"=hex:69,6f,5c,46,6a,89,f9,ee,2d,48,e0,10,87,42,1e,12
[HKEY_USERS\S-1-5-21-2454856603-3589663656-832898514-1000\Software\SecuROM\License information*]
"datasecu"=hex:7f,d1,35,18,a8,6e,20,6f,21,4d,b3,6b,14,e0,bd,9c,79,ee,4a,b3,e6,
c3,e1,10,c0,c0,39,b9,91,a0,6e,2e,9d,ce,59,02,6b,13,e4,2f,f3,03,2a,31,cf,a4,\
"rkeysecu"=hex:0b,85,ac,26,db,81,ad,86,d1,9c,a8,ec,d7,23,88,2a
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-17 13:58
ComboFix-quarantined-files.txt 2009-06-17 20:58
Pre-Run: 229,377,458,176 bytes free
Post-Run: 229,357,338,624 bytes free
328 --- E O F --- 2009-06-01 22:58
Thanks again for your assistance.