ComboFix log
ComboFix 09-09-05.02 - Marques Reed 09/07/2009 13:49.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1527.926 [GMT -5:00]
Running from: c:\documents and settings\Marques Reed\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Marques Reed\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FILE ::
"c:\windows\system32\net.net"
.
((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.
2009-09-07 18:44 . 2009-09-07 18:44 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-07 14:03 . 2009-09-07 14:03 -------- d-----w- C:\VundoFix Backups
2009-09-07 12:39 . 2009-09-07 12:39 -------- d-----w- c:\windows\LastGood
2009-09-07 12:16 . 2009-09-07 12:15 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-06 18:51 . 2009-09-06 18:51 -------- d-----w- C:\rsit
2009-09-06 12:40 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-06 12:40 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 04:35 . 2009-09-04 04:35 -------- d-----w- c:\program files\Spy
2009-09-04 02:55 . 2009-09-04 02:55 -------- d-----w- C:\spoolerlogs
2009-08-15 01:01 . 2009-08-15 01:01 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-15 01:00 . 2009-08-15 01:00 -------- d-----w- c:\program files\MSBuild
2009-08-15 01:00 . 2009-08-15 01:00 -------- d-----w- c:\program files\Reference Assemblies
2009-08-15 00:59 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 00:59 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-15 00:59 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 00:59 . 2009-08-15 01:00 -------- d-----w- C:\668a2e47aac041ac6dd0ce8ee5e302
2009-08-15 00:59 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-15 00:59 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 00:59 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-15 00:59 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 00:59 . 2009-09-06 02:34 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-13 23:22 . 2009-08-13 23:22 -------- d-----w- c:\program files\TVAnts
2009-08-12 21:18 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 22:22 . 2009-08-10 22:22 38676 ---ha-w- c:\windows\system32\mlfcache.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-07 18:45 . 2006-04-22 07:50 -------- d-----w- c:\program files\Common Files\Real
2009-09-07 18:44 . 2006-04-22 07:50 -------- d-----w- c:\program files\Real
2009-09-07 15:01 . 2006-04-22 08:00 -------- d-----w- c:\program files\McAfee
2009-09-07 12:18 . 2007-10-16 18:01 -------- d-----w- c:\program files\Orbitdownloader
2009-09-07 12:15 . 2006-04-22 07:39 -------- d-----w- c:\program files\Java
2009-09-07 11:52 . 2006-04-22 07:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-09-07 11:52 . 2006-04-22 07:51 -------- d-----w- c:\program files\Viewpoint
2009-09-06 12:40 . 2008-11-15 15:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-06 12:37 . 2009-07-24 13:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-06 02:12 . 2005-08-16 09:18 56320 ------w- c:\windows\system32\eventlog.dll
2009-09-05 16:45 . 2008-08-24 17:07 -------- d-----w- c:\documents and settings\Marques Reed\Application Data\Move Networks
2009-09-04 04:28 . 2009-07-24 13:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-24 22:38 . 2007-10-16 18:01 -------- d-----w- c:\documents and settings\Marques Reed\Application Data\Orbit
2009-08-15 01:15 . 2006-04-27 01:14 44672 ----a-w- c:\documents and settings\Marques Reed\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-11 00:58 . 2008-07-21 22:31 -------- d-----w- c:\program files\Safari
2009-08-10 22:18 . 2006-06-27 21:25 -------- d-----w- c:\documents and settings\Marques Reed\Application Data\Apple Computer
2009-08-05 09:01 . 2005-08-16 09:18 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 02:55 . 2007-02-22 02:42 -------- d-----w- c:\documents and settings\Marques Reed\Application Data\uTorrent
2009-08-03 01:39 . 2009-08-03 01:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-02 02:05 . 2008-08-16 17:16 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-31 04:37 . 2009-07-31 04:36 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-31 04:37 . 2009-07-31 04:36 -------- d-----w- c:\program files\iTunes
2009-07-31 04:37 . 2009-07-31 04:37 -------- d-----w- c:\program files\iPod
2009-07-31 04:36 . 2007-10-27 15:58 -------- d-----w- c:\program files\Common Files\Apple
2009-07-31 04:35 . 2007-09-29 18:52 -------- d-----w- c:\program files\Bonjour
2009-07-31 04:34 . 2006-04-22 07:51 -------- d-----w- c:\program files\QuickTime
2009-07-30 02:00 . 2009-07-30 01:59 -------- d-----w- c:\program files\Common Files\Remote Control Software Common
2009-07-30 01:59 . 2009-07-30 01:59 -------- d-----w- c:\program files\Logitech
2009-07-30 01:59 . 2006-04-22 07:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-30 01:59 . 2009-07-30 01:59 -------- d-----w- c:\program files\Common Files\Remote Control USB Driver
2009-07-30 01:58 . 2009-07-30 01:58 -------- d-----w- c:\documents and settings\Marques Reed\Application Data\InstallShield
2009-07-23 02:07 . 2009-07-23 02:07 -------- d-----w- c:\program files\Alwil Software
2009-07-17 19:01 . 2005-08-16 09:18 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 15:08 . 2005-08-16 09:19 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 17:16 . 2009-07-31 04:32 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-07-09 17:16 . 2007-10-27 15:59 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-29 16:12 . 2005-08-16 09:18 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2005-08-16 09:18 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2005-08-16 09:18 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2005-08-16 09:18 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2005-08-16 09:18 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2005-08-16 09:18 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2005-08-16 09:18 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2005-08-16 09:18 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2005-08-16 09:18 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2005-08-16 09:18 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-08-16 09:18 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2005-08-16 09:18 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-08-16 09:18 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2005-08-16 09:37 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2005-08-16 09:18 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2005-08-16 09:18 132096 ----a-w- c:\windows\system32\wkssvc.dll
2006-06-22 23:45 . 2006-07-10 00:59 13382656 ----a-w- c:\program files\Setup.msi
2006-06-22 23:44 . 2006-07-10 00:59 247 ----a-w- c:\program files\Setup.Ini
1999-04-29 21:23 . 2007-09-14 00:41 306 ----a-w- c:\program files\Readme.txt
2007-03-10 15:02 . 2006-05-01 01:55 88 --sh--r- c:\windows\system32\4BCAD4245F.sys
2008-01-02 04:23 . 2007-01-23 20:23 56 --sh--r- c:\windows\system32\5F24D4CA4B.sys
2005-07-14 16:31 . 2005-07-14 16:31 27648 --sha-r- c:\windows\system32\AVSredirect.dll
2005-06-26 19:32 . 2005-06-26 19:32 616448 --sha-r- c:\windows\system32\cygwin1.dll
2005-06-22 02:37 . 2005-06-22 02:37 45568 --sha-r- c:\windows\system32\cygz.dll
2008-01-02 04:23 . 2006-08-19 16:28 6580 --sha-w- c:\windows\system32\KGyGaAvL.sys
2005-02-28 17:16 . 2005-02-28 17:16 240128 --sha-r- c:\windows\system32\x.264.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-09-06_02.38.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-07 12:27 . 2009-09-07 12:27 16384 c:\windows\Temp\Perflib_Perfdata_900.dat
- 2006-04-27 00:23 . 2009-09-06 02:08 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-04-27 00:23 . 2009-09-07 14:54 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-04-27 00:23 . 2009-09-06 02:08 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2006-04-27 00:23 . 2009-09-07 14:54 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2006-04-22 07:50 . 2008-10-16 01:47 5632 c:\windows\system32\pndx5032.dll
+ 2009-09-07 18:45 . 2009-09-07 18:45 5632 c:\windows\system32\pndx5032.dll
+ 2009-09-07 18:45 . 2009-09-07 18:45 6656 c:\windows\system32\pndx5016.dll
- 2006-04-22 07:50 . 2008-10-16 01:47 6656 c:\windows\system32\pndx5016.dll
+ 2009-09-07 18:45 . 2009-09-07 18:45 185920 c:\windows\system32\rmoc3260.dll
- 2006-04-22 07:50 . 2008-10-16 01:47 185920 c:\windows\system32\rmoc3260.dll
+ 2006-04-22 07:50 . 2009-09-07 18:44 278528 c:\windows\system32\pncrt.dll
- 2006-04-22 07:50 . 2008-10-16 01:46 278528 c:\windows\system32\pncrt.dll
+ 2009-09-07 12:16 . 2009-09-07 12:15 149280 c:\windows\system32\javaws.exe
+ 2009-09-07 12:16 . 2009-09-07 12:15 145184 c:\windows\system32\javaw.exe
+ 2009-09-07 12:16 . 2009-09-07 12:15 145184 c:\windows\system32\java.exe
+ 2009-09-07 12:15 . 2009-09-07 12:15 1757696 c:\windows\Installer\7abf0.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="1" [X]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-09-26 2356088]
"SpybotSD TeaTimer"="c:\program files\Spy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-04-07 496752]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Motive SmartBridge"="c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"lxdpmon.exe"="c:\program files\Lexmark Z2300 Series\lxdpmon.exe" [2007-12-07 656040]
"EzPrint"="c:\program files\Lexmark Z2300 Series\ezprint.exe" [2007-12-07 107176]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"OpenDNS Update"="c:\program files\OpenDNS Updater\OpenDNS Updater.exe" [2009-02-06 314880]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-07 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-07 198160]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-09-10 393216]
"WD Button Manager"="WDBtnMgr.exe" - c:\windows\system32\WDBtnMgr.exe [2008-06-05 339968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-22 24576]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2006-6-3 315392]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
SBC Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2008-5-27 217088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 21:08 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Marques Reed\\Desktop\\utorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\Marques Reed\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\WINDOWS\\system32\\lxdpcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdppswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdptime.exe"=
"c:\\Program Files\\Lexmark Z2300 Series\\lxdpmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdpjswx.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdpwbgw.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP

HCP Discovery Service
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"16372:TCP"= 16372:TCP:utorrent
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe -service --> c:\windows\system32\lxdpcoms.exe -service [?]
R2 lxdpCATSCustConnectService;lxdpCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdpserv.exe [6/8/2008 2:00 PM 98984]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [12/9/2006 9:22 PM 14976]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 5:19 PM 13592]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [10/18/2007 7:38 PM 17792]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [10/18/2007 7:38 PM 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [10/18/2007 7:38 PM 21504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder
2009-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2008-05-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-08-14 18:32]
2009-05-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-08-14 18:32]
2009-09-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 22:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-CMS_RSChecker - c:\documents and settings\Marques Reed\Desktop\RSFAN.exe
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-WMPNSCFG - c:\program files\Windows Media Player\WMPNSCFG.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-ISUSPM Startup - c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe
HKLM-Run-NapsterShell - c:\program files\Napster\napster.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://att.yahoo.com
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
Trusted Zone: att.net
Trusted Zone: sbcglobal.net
Trusted Zone: yahoo.com\clientapps
Trusted Zone: musicmatch.com\online
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {01E54593-BE14-4D6B-9310-37C0145EFE42} - file:///D:/CDViewer/CdViewer.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\documents and settings\Marques Reed\Application Data\Mozilla\Firefox\Profiles\n3xjydgx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\documents and settings\Marques Reed\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npDimdimControl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdrmv2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdsplay.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwmsdrm.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-07 13:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1056)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
c:\windows\system32\igfxdev.dll
- - - - - - - > 'explorer.exe'(4140)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2009-09-07 14:00
ComboFix-quarantined-files.txt 2009-09-07 18:59
ComboFix2.txt 2009-09-06 02:46
Pre-Run: 10,650,107,904 bytes free
Post-Run: 10,651,897,856 bytes free
310 --- E O F --- 2009-09-03 21:45