I think we have a winner.
ComboFix 09-11-27.03 - John 11/27/2009 18:33.2.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3069.1689 [GMT -5:00]
Running from: c:\users\John\Desktop\ComboFix.exe
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
FW: Outpost Firewall Pro *enabled* {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
SP: Outpost Firewall Pro *disabled* (Updated) {8A20CA2A-9E02-4A64-923B-0A38208EB7FD}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
/wow section - STAGE 1
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\VDM2A19.tmp
C:\VDM2A1A.tmp
c:\windows\system32\twain_32.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-10-28 to 2009-11-28 )))))))))))))))))))))))))))))))
.
2009-11-26 20:08 . 2009-11-26 20:08 4045527 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-11-26 20:08 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-26 20:08 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-26 20:08 . 2009-11-27 14:36 4096 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-24 22:38 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-24 22:37 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-24 22:37 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-22 21:26 . 2009-05-07 07:04 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-11-22 20:58 . 2009-11-22 20:59 4096 d-----w- c:\program files\ERUNT
2009-11-22 20:09 . 2009-11-22 20:12 8192 d-----w- c:\program files\Spybot - Search & Destroy
2009-11-22 19:24 . 2009-11-22 19:24 -------- d-----w- c:\windows\system32\Adobe
2009-11-22 19:18 . 2007-07-12 07:50 319984 ------w- c:\programdata\HP\Installer\Temp\difxapi.dll
2009-11-22 19:13 . 2006-09-29 17:09 534528 ------w- c:\programdata\HP\Installer\Temp\dpinst_x32\dpinst.exe
2009-11-21 17:08 . 2009-11-21 17:08 -------- d-----w- c:\users\John\AppData\Local\Microsoft Corporation
2009-11-21 17:07 . 2009-11-21 17:07 4096 d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-11-20 00:29 . 2009-11-20 00:29 -------- d-----w- C:\Diskeeper
2009-11-19 23:15 . 2009-10-21 06:04 45232 ----a-w- c:\windows\system32\drivers\DKRtWrt.sys
2009-11-19 23:15 . 2009-11-19 23:15 -------- d-----w- c:\program files\Common Files\Diskeeper Corporation
2009-11-19 23:15 . 2009-11-19 23:15 -------- d-----w- c:\programdata\Diskeeper Corporation
2009-11-19 23:15 . 2009-11-19 23:15 -------- d-----w- c:\program files\Windows Home Server
2009-11-11 22:29 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
2009-11-11 22:29 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
2009-10-31 13:58 . 2009-10-31 13:58 -------- d-----w- c:\program files\Windows Portable Devices
2009-10-31 13:46 . 2009-09-25 01:31 519680 ----a-w- c:\windows\system32\d3d11.dll
2009-10-31 13:45 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-31 13:45 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-31 13:45 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-31 13:43 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-31 13:43 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-28 00:42 . 2008-11-09 19:17 720 ----a-w- c:\programdata\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll
2009-11-28 00:41 . 2007-12-16 22:24 34257 ----a-w- c:\windows\system32\drivers\stwrte.log
2009-11-27 22:02 . 2007-12-10 22:42 32768 d-----w- c:\users\John\AppData\Roaming\MailWasherPro
2009-11-27 03:02 . 2008-04-20 20:26 4096 d-----w- c:\programdata\Google Updater
2009-11-23 20:46 . 2007-12-10 02:47 165232 ---ha-w- c:\users\John\AppData\Roaming\Microsoft\Virtual PC\VPCKeyboard.dll
2009-11-22 20:50 . 2008-12-26 21:12 4096 d-----w- c:\programdata\Spybot - Search & Destroy
2009-11-22 19:59 . 2006-11-28 05:59 4096 d-----w- c:\program files\Java
2009-11-22 19:09 . 2006-12-02 22:10 -------- d-----w- c:\program files\Common Files\HP
2009-11-22 19:06 . 2006-12-02 22:11 4096 d-----w- c:\programdata\HP
2009-11-22 19:05 . 2006-12-02 21:45 4096 d-----w- c:\program files\HP
2009-11-22 01:38 . 2009-01-24 22:41 12288 d-----w- c:\program files\a-squared Anti-Malware
2009-11-19 23:15 . 2007-01-28 21:38 -------- d-----w- c:\program files\Diskeeper Corporation
2009-11-15 18:26 . 2008-03-30 20:05 3658 ----a-w- c:\programdata\Intuit\QuickBooks 2008\qbbackup.sys
2009-11-11 01:09 . 2007-08-25 14:16 4096 d-----w- c:\program files\Savings Bond Wizard
2009-11-09 10:00 . 2007-07-14 20:47 8192 d-----w- c:\program files\Picasa2
2009-11-03 23:31 . 2007-03-11 21:07 4096 d-----w- c:\program files\1-Click Answers
2009-11-03 01:42 . 2009-10-03 15:05 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-31 13:58 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-31 13:58 . 2009-10-31 13:58 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-19 22:36 . 2007-01-28 19:04 4096 d-----w- c:\program files\Common Files\Adobe
2009-10-14 22:00 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-10-11 09:17 . 2008-11-08 20:51 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-02 07:25 . 2008-03-30 20:03 849184 ----a-w- c:\programdata\Intuit\QuickBooks 2008\Components\DownloadQB18\Patch\qbpatch.exe
2009-10-01 01:02 . 2009-10-31 13:46 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-10-31 13:46 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-10-31 13:46 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-10-31 13:46 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-10-31 13:46 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-10-31 13:46 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-10-31 13:46 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-10-31 13:46 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-10-31 13:46 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-10-31 13:46 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-10-31 13:46 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-10-31 13:46 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-09-25 02:10 . 2009-10-31 13:47 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-10-31 13:47 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-10-31 13:47 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-10-31 13:47 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-10-31 13:47 351232 ----a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-10-31 13:47 847360 ----a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-10-31 13:47 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-10-31 13:47 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-10-31 13:47 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-10-31 13:47 829440 ----a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-10-31 13:47 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-10-31 13:47 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-10-31 13:46 486912 ----a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-10-31 13:46 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-10-31 13:46 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-10-31 13:46 1030144 ----a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-10-31 13:47 828928 ----a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-10-31 13:46 481792 ----a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-10-31 13:46 190464 ----a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-10-31 13:47 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-10-31 13:47 37888 ----a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-10-31 13:46 793088 ----a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-10-31 13:46 1064448 ----a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-10-31 13:47 258048 ----a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-10-31 13:47 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-10-31 13:47 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-14 09:29 . 2009-10-14 21:46 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 20:25 . 2008-03-22 14:31 127640 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-10 16:48 . 2009-10-14 21:46 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 02:01 . 2009-10-31 13:47 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2009-09-10 02:00 . 2009-10-31 13:47 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2009-09-10 02:00 . 2009-10-31 13:47 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2009-09-04 11:41 . 2009-10-14 21:47 60928 ----a-w- c:\windows\system32\msasn1.dll
2007-01-05 20:18 . 2007-01-05 20:18 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
2006-11-02 12:35 . 2006-11-02 12:35 397312 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6000.16386_none_ef216b8c52ca2227\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"SetDefaultMIDI"="MIDIDef.exe" - c:\windows\MIDIDEF.EXE [2006-12-12 28672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe MSRun" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-06-11 178712]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall Pro\feedback.exe" [2008-07-15 435528]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~2\op_mon.exe" [2008-07-15 1153352]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-03-17 570664]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-06-25 1629480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-09-10 420176]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
"CTHelper"="CTHELPER.EXE" - c:\windows\System32\CtHelper.exe [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\System32\CTXFIHLP.EXE [2006-12-12 20480]
"CtxfiReg"="CTXFIREG.EXE" - c:\windows\System32\CTXFIREG.EXE [2006-12-12 44032]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
1-Click Answers.lnk - c:\program files\1-Click Answers\answers.exe [2007-3-11 798720]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-16 972064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Agnitum\OUTPOS~2\wl_hook.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):a6,ca,1a,7b,f4,ea,c9,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1002608937-2175423900-1745845827-1006]
"EnableNotificationsRef"=dword:00000001
R1 afw;Agnitum Firewall Driver;c:\windows\System32\drivers\afw.sys [12/9/2007 1:34 PM 28688]
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [2/6/2009 1:23 PM 106208]
R1 SandBox;SandBox;c:\windows\System32\drivers\SandBox.sys [10/10/2008 4:49 PM 673920]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~2\acs.exe [12/9/2007 1:34 PM 1238344]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2/6/2009 1:23 PM 727720]
R2 epfwwfpr;epfwwfpr;c:\windows\System32\drivers\epfwwfpr.sys [2/6/2009 1:24 PM 92800]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/26/2009 3:08 PM 269648]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [11/22/2009 3:09 PM 1153368]
R3 afwcore;afwcore;c:\windows\System32\drivers\afwcore.sys [10/10/2008 4:49 PM 242704]
R3 cxbu0wdm;CardMan 3x21;c:\windows\System32\drivers\cxbu0wdm.sys [1/15/2008 11:39 AM 97792]
R3 DKRtWrt;DKRtWrt;c:\windows\System32\drivers\DKRtWrt.sys [11/19/2009 6:15 PM 45232]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [11/26/2009 3:08 PM 19160]
R3 VST_DPV;VST_DPV;c:\windows\System32\drivers\VSTDPV3.SYS [11/2/2006 5:25 AM 987648]
R3 VSTHWBS2;VSTHWBS2;c:\windows\System32\drivers\VSTBS23.SYS [11/2/2006 5:25 AM 251904]
S2 NeroRegInCDSrv;Nero Registry InCD Service;c:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe --> c:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe [?]
S3 ASWFilt;ASWFilt;c:\windows\System32\Filt\ASWFilt.dll [10/10/2008 4:49 PM 33408]
S3 Commander Service;Commander Service;c:\program files\Seagull\BarTender\7.74\CmdrSrv.exe --> c:\program files\Seagull\BarTender\7.74\CmdrSrv.exe [?]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [5/25/2008 2:34 PM 21504]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\System32\drivers\motccgp.sys [6/19/2009 3:59 PM 19712]
S3 motccgpfl;MotCcgpFlService;c:\windows\System32\drivers\motccgpfl.sys [1/29/2009 4:18 PM 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\System32\drivers\motodrv.sys [5/8/2009 10:56 AM 42752]
S3 motport;Motorola USB Diagnostic Port;c:\windows\System32\drivers\motport.sys [1/29/2009 4:15 PM 23680]
--- Other Services/Drivers In Memory ---
*Deregistered* - AMON
*Deregistered* - nod32drv
*Deregistered* - NOD32krn
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
WudfServiceGroup REG_MULTI_SZ WUDFSvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-11-28 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]
2009-11-27 c:\windows\Tasks\Malwarebytes' Scheduled Scan for John.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-11-26 19:53]
2009-11-27 c:\windows\Tasks\Malwarebytes' Scheduled Update for John.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-11-26 19:53]
2009-11-28 c:\windows\Tasks\User_Feed_Synchronization-{4FF4E474-DC1F-4154-861C-58E20F0D116F}.job
- c:\windows\system32\msfeedssync.exe [2009-10-14 03:41]
2009-11-28 c:\windows\Tasks\User_Feed_Synchronization-{A1AF7671-31E0-4BED-BBB9-946907EA400B}.job
- c:\windows\system32\msfeedssync.exe [2009-10-14 03:41]
2009-11-28 c:\windows\Tasks\User_Feed_Synchronization-{E143C68F-1647-431E-8400-33CEB4C0595C}.job
- c:\windows\system32\msfeedssync.exe [2009-10-14 03:41]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: {594ECDD4-A991-4208-A7B7-00DDAD9BE328} - hxxp://media.labs.live.com/all/ps/_code_/Photosynth.cab
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-WheresJames Startup Manager - c:\program files\WheresJames\StartupMgr\StartupMgr.exe
HKLM-Run-Vista_upgrade - c:\users\John\Local Settings\Application Data\DellVistaUpgrade\Vista_Upgrade.exe
HKLM-Run-AudioDrvEmulator - c:\program files\Creative\Shared Files\Module Loader\DLLML.exe
AddRemove-Agnitum Outpost Firewall Pro - c:\progra~1\Agnitum\OUTPOS~1\uninst.exe
AddRemove-CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1 - c:\program files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1\HXFSETUP.EXE
AddRemove-Dell Game Console - c:\program files\WildTangent\Apps\Dell Game Console\Uninstall.exe
AddRemove-Monumental Battlefields - c:\windows\ss3unstl.exe Monumental Battlefields
AddRemove-Tweak UI 2.10 - c:\windows\system32\mshta.exe res://c:\windows\system32\TweakUI.exe/uninstall.hta
AddRemove-Windows Live Toolbar - c:\program files\Windows Live Toolbar\UnInstall.exe {D5A145FC-D00C-4F1A-9119-EB4D9D659750}
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-27 19:42
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3520)
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\a-squared Anti-Malware\a2service.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\WUDFHost.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Completion time: 2009-11-27 20:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-28 01:40
Pre-Run: 121,211,273,216 bytes free
Post-Run: 115,939,090,432 bytes free
- - End Of File - - EFD9F506CAA7147EB7A5C2FC9134BABD