ComboFix 09-09-10.01 - Arranf_2 10/09/2009 23:57.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2038.988 [GMT 1:00]
Running from: c:\users\Arranf_2\Desktop\cf.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-08-10 to 2009-09-10 )))))))))))))))))))))))))))))))
.
2009-09-10 23:06 . 2009-09-10 23:06 -------- d-----w- c:\users\Arranf_2\AppData\Local\temp
2009-09-10 23:06 . 2009-09-10 23:06 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-10 23:06 . 2009-09-10 23:06 -------- d-----w- c:\users\Noel\AppData\Local\temp
2009-09-10 23:06 . 2009-09-10 23:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-10 22:11 . 2009-09-10 22:11 -------- d-----w- c:\program files\Trend Micro
2009-09-10 22:10 . 2009-09-10 22:10 -------- d-----w- C:\rsit
2009-09-10 21:40 . 2009-09-10 21:40 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\Malwarebytes
2009-09-10 21:40 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:40 . 2009-09-10 21:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-10 21:40 . 2009-09-10 21:40 -------- d-----w- c:\programdata\Malwarebytes
2009-09-10 21:40 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-10 18:18 . 2009-08-27 08:17 97208 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2009-09-10 18:17 . 2009-08-14 11:44 32552 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2009-09-10 18:17 . 2009-08-14 11:44 70280 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2009-09-10 18:17 . 2009-07-29 08:54 46592 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2009-09-09 18:13 . 2009-07-28 15:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-09 18:13 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-09 18:13 . 2009-09-09 18:13 -------- d-----w- c:\programdata\Avira
2009-09-09 17:58 . 2009-09-09 17:58 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\AVG8
2009-09-07 19:56 . 2009-09-07 19:56 32256 ----a-w- c:\windows\system32\fustyisrtl.exe
2009-09-06 08:53 . 2009-09-06 08:53 -------- d-----w- c:\program files\Spotify
2009-09-05 14:01 . 2009-09-05 14:01 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-05 13:00 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-09-05 13:00 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-09-05 13:00 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-09-05 13:00 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-09-05 13:00 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-05 13:00 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-09-05 13:00 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-09-05 13:00 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-09-02 21:29 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 21:29 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 02:02 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-21 22:49 . 2009-08-21 22:57 34 ----a-w- c:\users\Arranf_2\jagex_runescape_preferences.dat
2009-08-21 22:43 . 2009-08-21 22:49 -------- d-----w- C:\.jagex_cache_32
2009-08-20 13:01 . 2009-08-20 13:01 -------- d-----w- c:\programdata\Blizzard Entertainment
2009-08-13 15:08 . 2009-08-13 15:08 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-08-13 15:08 . 2009-08-13 15:08 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-08-13 15:08 . 2009-08-13 15:08 -------- d-----w- c:\program files\OpenAL
2009-08-13 14:36 . 2009-08-13 14:36 -------- d-----w- c:\program files\GameSpy Arcade
2009-08-12 13:44 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-12 13:44 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-12 13:44 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-12 13:44 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-12 13:44 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-12 13:44 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-12 13:43 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-12 13:43 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-12 09:09 . 2009-08-12 09:09 -------- d-----w- c:\program files\ltmoh
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 22:44 . 2009-03-09 18:44 -------- d-----w- c:\programdata\Viewpoint
2009-09-10 22:07 . 2008-11-28 17:58 -------- d-----w- c:\programdata\Kaspersky Lab
2009-09-10 21:14 . 2009-01-31 22:20 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\uTorrent
2009-09-10 18:33 . 2008-03-08 11:04 -------- d-----w- c:\program files\PC Tools Firewall Plus
2009-09-10 18:30 . 2008-11-17 18:03 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\PCToolsFirewallPlus
2009-09-10 17:54 . 2009-03-24 21:08 -------- d-----w- c:\programdata\Google Updater
2009-09-09 18:37 . 2009-03-28 10:22 -------- d-----w- c:\program files\BTopenworld ReInstall
2009-09-05 13:44 . 2009-04-10 12:49 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\U3
2009-09-05 13:35 . 2008-11-28 17:56 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2009-08-28 19:08 . 2008-11-25 22:13 680 ----a-w- c:\users\Arranf_2\AppData\Local\d3d9caps.dat
2009-08-27 22:39 . 2008-11-19 19:02 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\Skype
2009-08-27 08:17 . 2009-01-17 09:47 229176 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-08-24 13:05 . 2009-01-17 09:47 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-08-19 10:01 . 2009-01-17 09:47 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-08-14 11:44 . 2009-01-17 09:46 114832 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2009-08-14 05:58 . 2009-09-10 18:18 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-08-13 14:33 . 2006-11-02 12:37 -------- d-----w- c:\program files\Microsoft Games
2009-08-13 14:16 . 2007-04-13 15:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-13 00:17 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-08-10 18:36 . 2009-08-10 18:34 -------- d-----w- c:\program files\SpeedFan
2009-08-10 15:22 . 2009-02-09 21:55 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-08-08 13:28 . 2009-01-06 22:57 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\vlc
2009-08-08 13:27 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-08-08 13:08 . 2007-04-13 15:22 -------- d-----w- c:\program files\Intel
2009-08-05 21:44 . 2009-08-05 21:43 -------- d-----w- c:\program files\CamStudio
2009-08-05 11:32 . 2009-08-05 11:32 -------- d-----w- c:\programdata\IsolatedStorage
2009-08-05 11:32 . 2009-08-05 11:32 -------- d-----w- c:\program files\Toshiba TEMPRO
2009-08-05 11:31 . 2008-11-16 21:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-05 10:45 . 2009-01-29 23:19 -------- d-----w- c:\program files\SystemRequirementsLab
2009-08-05 10:45 . 2009-01-29 23:19 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\SystemRequirementsLab
2009-08-04 11:06 . 2008-11-17 18:33 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\Azureus
2009-08-02 09:59 . 2008-11-24 20:37 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-29 17:36 . 2009-05-17 16:34 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\Ventrilo
2009-07-26 17:01 . 2009-07-26 17:01 -------- d-----w- c:\program files\iPod
2009-07-26 17:01 . 2008-11-15 20:08 -------- d-----w- c:\program files\Common Files\Apple
2009-07-21 21:52 . 2009-07-29 09:11 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 09:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 09:11 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 09:11 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-06-15 15:24 . 2009-07-15 10:15 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-15 10:15 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-15 10:15 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-15 10:15 289792 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-10_17.52.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-17 18:21 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\gatherWirelessInfo.vbs
+ 2009-08-01 02:12 . 2009-04-11 06:28 68096 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\wlanhlp.dll
+ 2008-11-17 18:21 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\gatherWirelessInfo.vbs
+ 2008-11-17 18:21 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\gatherWirelessInfo.vbs
+ 2008-11-17 18:22 . 2008-01-19 07:36 68096 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\wlanhlp.dll
+ 2008-11-17 18:22 . 2008-01-19 07:36 64512 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\wlanapi.dll
+ 2008-11-17 18:21 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\gatherWirelessInfo.vbs
+ 2006-11-02 12:34 . 2006-11-02 12:34 14827 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\gatherWirelessInfo.vbs
+ 2006-11-02 12:34 . 2006-11-02 12:34 14827 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\gatherWirelessInfo.vbs
+ 2009-08-01 02:12 . 2009-04-11 06:27 53248 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\rrinstaller.exe
+ 2009-08-01 02:12 . 2009-04-11 06:28 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mfps.dll
+ 2009-08-01 02:12 . 2009-04-11 06:27 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mfpmp.exe
+ 2008-11-17 18:22 . 2008-01-19 07:33 53248 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\rrinstaller.exe
+ 2008-11-17 18:22 . 2008-01-19 07:34 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mfps.dll
+ 2008-11-17 18:21 . 2008-01-19 07:33 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mfpmp.exe
+ 2007-04-13 15:52 . 2009-09-10 22:10 62542 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-11-17 18:05 . 2009-09-10 22:10 15124 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1516280849-4020581899-2912383609-1002_UserData.bin
+ 2009-09-10 18:17 . 2009-07-29 08:54 46592 c:\windows\System32\DriverStore\FileRepository\pctndis.inf_d09d4479\pctNdis.sys
+ 2007-10-11 16:23 . 2009-09-10 22:09 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-10-11 16:23 . 2009-09-10 17:22 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-10-11 16:23 . 2009-09-10 22:09 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-11 16:23 . 2009-09-10 17:22 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-11 16:23 . 2009-09-10 17:22 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-10-11 16:23 . 2009-09-10 22:09 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 10:25 . 2009-09-05 13:42 86016 c:\windows\inf\infpub.dat
+ 2006-11-02 10:25 . 2009-09-10 18:18 86016 c:\windows\inf\infpub.dat
+ 2009-08-01 02:12 . 2009-04-11 04:54 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mferror.dll
+ 2006-11-02 12:35 . 2006-11-02 12:35 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mferror.dll
+ 2009-09-10 22:04 . 2009-09-10 22:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-10 17:48 . 2009-09-10 17:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-10 22:04 . 2009-09-10 22:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-09-10 17:48 . 2009-09-10 17:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 13:05 . 2009-09-10 22:10 139732 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-06-19 17:40 . 2009-09-10 18:22 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-06-19 17:40 . 2009-09-10 17:22 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2006-11-02 10:25 . 2009-09-05 13:42 143360 c:\windows\inf\infstrng.dat
+ 2006-11-02 10:25 . 2009-09-10 18:18 143360 c:\windows\inf\infstrng.dat
+ 2006-11-02 10:25 . 2009-09-10 18:18 143360 c:\windows\inf\infstor.dat
- 2006-11-02 10:25 . 2009-09-05 13:42 143360 c:\windows\inf\infstor.dat
- 2006-11-02 10:22 . 2009-09-09 19:25 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-09-10 21:01 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2008-10-10 06:29 . 2009-09-10 22:03 1223896 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2008-10-10 06:29 . 2009-09-10 17:46 1223896 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-06-04 15:33 . 2009-09-10 21:13 212333419 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-08-27 2971608]
"snp2std"="c:\windows\vsnp2std.exe" [2006-12-04 675840]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"avgnt"="e:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-09-03 4702208]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-08-03 1826816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=e:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll e:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Run Registration Tool.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Run Registration Tool.lnk
backup=c:\windows\pss\Run Registration Tool.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Arranf_2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Arranf_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"CollaborationHost"=c:\windows\system32\p2phost.exe -s
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"Persistence"=c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C7E26FB3-618D-4683-817B-E814924CCBE6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4623A832-5A7A-4CF1-9B39-5C975B728009}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{96D781A5-C998-47B1-8922-2F0023B47FD8}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D6A3E005-6EDB-4299-A19A-9F18094B40EA}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{633CCAE7-8124-4AA2-BC03-DBB4C8DA87C0}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{C4E78729-B2F2-4BD1-9B50-6A4ED5F19B97}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A3A4AEB3-E5EF-4E3F-AF76-871E319DDCDF}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{331843F8-E899-4DC8-90F2-FDDC1266A35F}"= UDP:5353:Adobe CSI CS4
"{D8096164-FBCD-46E5-99D6-34CB2D2B6141}"= e:\program files\Skype\Phone\Skype.exe:Skype
"{3F5D1955-0DEB-4BCC-B16E-821608B2EF0B}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{2D3F401C-57D5-4513-94C3-8B2664E835E8}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{B72820F5-0470-467A-91EF-3BED6DC7D9CF}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3A100139-C7CF-4F93-88A8-16D12BCEC70E}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A4BA6C22-B12A-467C-9D16-E1B5E30F514C}"= UDP:e:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{09321481-804F-4783-8438-F38F645F262A}"= TCP:e:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{676AF48F-A499-4DD6-9190-13BA414793BE}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{7BDC8B2F-5960-45E9-9EF6-5247A663974A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{50E6C724-28CB-4856-96FF-63EDCAE95886}"= c:\program files\WiFiConnector\NintendoWFCReg.exe:Nintendo Wi-Fi USB Connector
"{8A2EB9CC-55D6-44B8-9CCF-9B855D17D429}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{89829439-6BC3-4672-B5B8-DD03A6C8F652}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{FB6A0F8C-6993-4820-BE7E-4A522E969C02}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{FD218725-260D-47C0-812D-7EFA1770407C}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{1D69ED13-43AB-49E2-91A0-48353EE99539}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{8ABF9975-3C91-4899-A855-7F262D34CC84}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{1590378C-091D-4605-B684-FEEC23E2FB70}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{76546947-DB5B-4605-9B0A-FA7A94BF886C}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{264F058D-1039-4750-9399-233DF9342D1D}"= UDP:c:\program files\Samsung\Samsung New PC Studio\npsasvr.exe:KTF MUSIC AoD Server
"{37987008-1ECA-4604-A89A-BA888EE4FCBA}"= TCP:c:\program files\Samsung\Samsung New PC Studio\npsasvr.exe:KTF MUSIC AoD Server
"{B44C0B88-70E9-4F45-8541-32F18A9C713B}"= UDP:c:\program files\Samsung\Samsung New PC Studio\npsvsvr.exe:KTF MUSIC VoD Server
"{9FBB6D6A-92BB-4A8F-9F56-7042E764DAC4}"= TCP:c:\program files\Samsung\Samsung New PC Studio\npsvsvr.exe:KTF MUSIC VoD Server
"{E4CC03E1-CD9A-4386-A643-9B4B876AA3CA}"= UDP:e:\program files\iTunes\iTunes.exe:iTunes
"{A63098FE-A5D7-46B0-BBA5-A37DA33A0151}"= TCP:e:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R?2 AeLookupSvcAgereModemAudio;Application Experience AeLookupSvcAgereModemAudio;c:\windows\system32\fustyisrtl.exe service --> c:\windows\system32\fustyisrtl.exe service [?]
R1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [17/01/2009 10:47 229176]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;e:\program files\Avira\AntiVir Desktop\sched.exe [09/09/2009 19:13 108289]
R2 FsUsbExService;FsUsbExService;c:\windows\System32\FsUsbExService.Exe [16/06/2009 16:44 233472]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\System32\drivers\PCTAppEvent.sys [17/01/2009 10:47 86888]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [08/03/2008 12:05 810320]
R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [21/04/2009 17:36 116104]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\System32\FsUsbExDisk.Sys [16/06/2009 16:44 36608]
R3 PCTFW-DNS;PCTools Firewall - DNS driver;c:\windows\System32\drivers\pctNdis-DNS.sys [10/09/2009 19:17 32552]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\System32\drivers\pctNdis-PacketFilter.sys [10/09/2009 19:17 70280]
R3 pctNDIS;PC Tools Driver;c:\windows\System32\drivers\pctNdis.sys [10/09/2009 19:17 46592]
R3 pctplfw;pctplfw;c:\windows\System32\drivers\pctplfw.sys [17/01/2009 10:46 114832]
S2 gupdate1c9acc4d03de291;Google Update Service (gupdate1c9acc4d03de291);c:\program files\Google\Update\GoogleUpdate.exe [24/03/2009 22:09 133104]
S3 iadusb;MT882;c:\windows\System32\drivers\glauiad.sys [08/03/2008 11:30 29696]
S3 S2usbser;S2 USB Device for Legacy Serial Communication;c:\windows\System32\drivers\S2usbser.sys [16/11/2008 15:34 103680]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\System32\drivers\ss_bbus.sys [20/06/2009 12:43 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\System32\drivers\ss_bmdfl.sys [20/06/2009 12:43 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\System32\drivers\ss_bmdm.sys [20/06/2009 12:43 121856]
S4 CplIR;Embedded IR Driver;c:\windows\System32\drivers\CplIR.sys [06/03/2007 15:01 14848]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 21:08]
2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 21:09]
2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 21:09]
2009-09-08 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- e:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-11-15 15:31]
2009-09-10 c:\windows\Tasks\User_Feed_Synchronization-{8CE55126-04F8-452B-846C-193C8187AA96}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redirect-home?tag=Toshibaukbholink-21&site=home
IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\users\Arranf_2\AppData\Roaming\Mozilla\Firefox\Profiles\946dhshw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com
FF - prefs.js: network.proxy.type - 2
FF - component: c:\users\Arranf_2\AppData\Roaming\Mozilla\Firefox\Profiles\946dhshw.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Opera\program\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: e:\program files\DivX\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: e:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-11 00:06
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b4
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5996)
c:\program files\RocketDock\RocketDock.dll
.
Completion time: 2009-09-10 0:10
ComboFix-quarantined-files.txt 2009-09-10 23:10
ComboFix2.txt 2009-09-10 17:58
Pre-Run: 17,215,578,112 bytes free
Post-Run: 17,078,149,120 bytes free
362 --- E O F --- 2009-09-10 21:08
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2038.988 [GMT 1:00]
Running from: c:\users\Arranf_2\Desktop\cf.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-08-10 to 2009-09-10 )))))))))))))))))))))))))))))))
.
2009-09-10 23:06 . 2009-09-10 23:06 -------- d-----w- c:\users\Arranf_2\AppData\Local\temp
2009-09-10 23:06 . 2009-09-10 23:06 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-09-10 23:06 . 2009-09-10 23:06 -------- d-----w- c:\users\Noel\AppData\Local\temp
2009-09-10 23:06 . 2009-09-10 23:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-10 22:11 . 2009-09-10 22:11 -------- d-----w- c:\program files\Trend Micro
2009-09-10 22:10 . 2009-09-10 22:10 -------- d-----w- C:\rsit
2009-09-10 21:40 . 2009-09-10 21:40 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\Malwarebytes
2009-09-10 21:40 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:40 . 2009-09-10 21:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-10 21:40 . 2009-09-10 21:40 -------- d-----w- c:\programdata\Malwarebytes
2009-09-10 21:40 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-10 18:18 . 2009-08-27 08:17 97208 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2009-09-10 18:17 . 2009-08-14 11:44 32552 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2009-09-10 18:17 . 2009-08-14 11:44 70280 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2009-09-10 18:17 . 2009-07-29 08:54 46592 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2009-09-09 18:13 . 2009-07-28 15:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-09 18:13 . 2009-03-30 09:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-09 18:13 . 2009-09-09 18:13 -------- d-----w- c:\programdata\Avira
2009-09-09 17:58 . 2009-09-09 17:58 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\AVG8
2009-09-07 19:56 . 2009-09-07 19:56 32256 ----a-w- c:\windows\system32\fustyisrtl.exe
2009-09-06 08:53 . 2009-09-06 08:53 -------- d-----w- c:\program files\Spotify
2009-09-05 14:01 . 2009-09-05 14:01 355584 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-05 13:00 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-09-05 13:00 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-09-05 13:00 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-09-05 13:00 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-09-05 13:00 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-05 13:00 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-09-05 13:00 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-09-05 13:00 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-09-02 21:29 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 21:29 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 02:02 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-21 22:49 . 2009-08-21 22:57 34 ----a-w- c:\users\Arranf_2\jagex_runescape_preferences.dat
2009-08-21 22:43 . 2009-08-21 22:49 -------- d-----w- C:\.jagex_cache_32
2009-08-20 13:01 . 2009-08-20 13:01 -------- d-----w- c:\programdata\Blizzard Entertainment
2009-08-13 15:08 . 2009-08-13 15:08 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-08-13 15:08 . 2009-08-13 15:08 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-08-13 15:08 . 2009-08-13 15:08 -------- d-----w- c:\program files\OpenAL
2009-08-13 14:36 . 2009-08-13 14:36 -------- d-----w- c:\program files\GameSpy Arcade
2009-08-12 13:44 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-12 13:44 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-12 13:44 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-12 13:44 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-12 13:44 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-12 13:44 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-12 13:43 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-12 13:43 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-12 09:09 . 2009-08-12 09:09 -------- d-----w- c:\program files\ltmoh
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 22:44 . 2009-03-09 18:44 -------- d-----w- c:\programdata\Viewpoint
2009-09-10 22:07 . 2008-11-28 17:58 -------- d-----w- c:\programdata\Kaspersky Lab
2009-09-10 21:14 . 2009-01-31 22:20 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\uTorrent
2009-09-10 18:33 . 2008-03-08 11:04 -------- d-----w- c:\program files\PC Tools Firewall Plus
2009-09-10 18:30 . 2008-11-17 18:03 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\PCToolsFirewallPlus
2009-09-10 17:54 . 2009-03-24 21:08 -------- d-----w- c:\programdata\Google Updater
2009-09-09 18:37 . 2009-03-28 10:22 -------- d-----w- c:\program files\BTopenworld ReInstall
2009-09-05 13:44 . 2009-04-10 12:49 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\U3
2009-09-05 13:35 . 2008-11-28 17:56 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2009-08-28 19:08 . 2008-11-25 22:13 680 ----a-w- c:\users\Arranf_2\AppData\Local\d3d9caps.dat
2009-08-27 22:39 . 2008-11-19 19:02 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\Skype
2009-08-27 08:17 . 2009-01-17 09:47 229176 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-08-24 13:05 . 2009-01-17 09:47 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-08-19 10:01 . 2009-01-17 09:47 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-08-14 11:44 . 2009-01-17 09:46 114832 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2009-08-14 05:58 . 2009-09-10 18:18 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-08-13 14:33 . 2006-11-02 12:37 -------- d-----w- c:\program files\Microsoft Games
2009-08-13 14:16 . 2007-04-13 15:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-13 00:17 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-08-10 18:36 . 2009-08-10 18:34 -------- d-----w- c:\program files\SpeedFan
2009-08-10 15:22 . 2009-02-09 21:55 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-08-08 13:28 . 2009-01-06 22:57 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\vlc
2009-08-08 13:27 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-08-08 13:08 . 2007-04-13 15:22 -------- d-----w- c:\program files\Intel
2009-08-05 21:44 . 2009-08-05 21:43 -------- d-----w- c:\program files\CamStudio
2009-08-05 11:32 . 2009-08-05 11:32 -------- d-----w- c:\programdata\IsolatedStorage
2009-08-05 11:32 . 2009-08-05 11:32 -------- d-----w- c:\program files\Toshiba TEMPRO
2009-08-05 11:31 . 2008-11-16 21:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-05 10:45 . 2009-01-29 23:19 -------- d-----w- c:\program files\SystemRequirementsLab
2009-08-05 10:45 . 2009-01-29 23:19 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\SystemRequirementsLab
2009-08-04 11:06 . 2008-11-17 18:33 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\Azureus
2009-08-02 09:59 . 2008-11-24 20:37 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-29 17:36 . 2009-05-17 16:34 -------- d-----w- c:\users\Arranf_2\AppData\Roaming\Ventrilo
2009-07-26 17:01 . 2009-07-26 17:01 -------- d-----w- c:\program files\iPod
2009-07-26 17:01 . 2008-11-15 20:08 -------- d-----w- c:\program files\Common Files\Apple
2009-07-21 21:52 . 2009-07-29 09:11 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 09:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 09:11 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 09:11 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-06-15 15:24 . 2009-07-15 10:15 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-15 10:15 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-15 10:15 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-15 10:15 289792 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-10_17.52.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-17 18:21 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.22170_none_9e68a7441b62d132\gatherWirelessInfo.vbs
+ 2009-08-01 02:12 . 2009-04-11 06:28 68096 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\wlanhlp.dll
+ 2008-11-17 18:21 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6002.18064_none_9deddb8d02397ad3\gatherWirelessInfo.vbs
+ 2008-11-17 18:21 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.22468_none_9c9507981e2d2ad5\gatherWirelessInfo.vbs
+ 2008-11-17 18:22 . 2008-01-19 07:36 68096 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\wlanhlp.dll
+ 2008-11-17 18:22 . 2008-01-19 07:36 64512 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\wlanapi.dll
+ 2008-11-17 18:21 . 2008-01-05 11:34 15181 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6001.18288_none_9bf5c90f051fc5c6\gatherWirelessInfo.vbs
+ 2006-11-02 12:34 . 2006-11-02 12:34 14827 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.21082_none_9a92fd9a211c6fd7\gatherWirelessInfo.vbs
+ 2006-11-02 12:34 . 2006-11-02 12:34 14827 c:\windows\winsxs\x86_microsoft-windows-wlansvc_31bf3856ad364e35_6.0.6000.16884_none_9a0b894107fccf79\gatherWirelessInfo.vbs
+ 2009-08-01 02:12 . 2009-04-11 06:27 53248 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\rrinstaller.exe
+ 2009-08-01 02:12 . 2009-04-11 06:28 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mfps.dll
+ 2009-08-01 02:12 . 2009-04-11 06:27 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mfpmp.exe
+ 2008-11-17 18:22 . 2008-01-19 07:33 53248 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\rrinstaller.exe
+ 2008-11-17 18:22 . 2008-01-19 07:34 98816 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mfps.dll
+ 2008-11-17 18:21 . 2008-01-19 07:33 24576 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mfpmp.exe
+ 2007-04-13 15:52 . 2009-09-10 22:10 62542 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-11-17 18:05 . 2009-09-10 22:10 15124 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1516280849-4020581899-2912383609-1002_UserData.bin
+ 2009-09-10 18:17 . 2009-07-29 08:54 46592 c:\windows\System32\DriverStore\FileRepository\pctndis.inf_d09d4479\pctNdis.sys
+ 2007-10-11 16:23 . 2009-09-10 22:09 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-10-11 16:23 . 2009-09-10 17:22 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-10-11 16:23 . 2009-09-10 22:09 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-11 16:23 . 2009-09-10 17:22 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-11 16:23 . 2009-09-10 17:22 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-10-11 16:23 . 2009-09-10 22:09 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 10:25 . 2009-09-05 13:42 86016 c:\windows\inf\infpub.dat
+ 2006-11-02 10:25 . 2009-09-10 18:18 86016 c:\windows\inf\infpub.dat
+ 2009-08-01 02:12 . 2009-04-11 04:54 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6002.18049_none_9e2369c00a004aef\mferror.dll
+ 2006-11-02 12:35 . 2006-11-02 12:35 2048 c:\windows\winsxs\x86_microsoft-windows-mediafoundation_31bf3856ad364e35_6.0.6001.18270_none_9c1383940cfa6868\mferror.dll
+ 2009-09-10 22:04 . 2009-09-10 22:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-09-10 17:48 . 2009-09-10 17:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-09-10 22:04 . 2009-09-10 22:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-09-10 17:48 . 2009-09-10 17:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 13:05 . 2009-09-10 22:10 139732 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-06-19 17:40 . 2009-09-10 18:22 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-06-19 17:40 . 2009-09-10 17:22 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2006-11-02 10:25 . 2009-09-05 13:42 143360 c:\windows\inf\infstrng.dat
+ 2006-11-02 10:25 . 2009-09-10 18:18 143360 c:\windows\inf\infstrng.dat
+ 2006-11-02 10:25 . 2009-09-10 18:18 143360 c:\windows\inf\infstor.dat
- 2006-11-02 10:25 . 2009-09-05 13:42 143360 c:\windows\inf\infstor.dat
- 2006-11-02 10:22 . 2009-09-09 19:25 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-09-10 21:01 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2008-10-10 06:29 . 2009-09-10 22:03 1223896 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2008-10-10 06:29 . 2009-09-10 17:46 1223896 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-06-04 15:33 . 2009-09-10 21:13 212333419 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-08-27 2971608]
"snp2std"="c:\windows\vsnp2std.exe" [2006-12-04 675840]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"avgnt"="e:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-09-03 4702208]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-08-03 1826816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=e:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll e:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Run Registration Tool.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Run Registration Tool.lnk
backup=c:\windows\pss\Run Registration Tool.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Arranf_2^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Arranf_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"CollaborationHost"=c:\windows\system32\p2phost.exe -s
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"Persistence"=c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C7E26FB3-618D-4683-817B-E814924CCBE6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4623A832-5A7A-4CF1-9B39-5C975B728009}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{96D781A5-C998-47B1-8922-2F0023B47FD8}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D6A3E005-6EDB-4299-A19A-9F18094B40EA}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{633CCAE7-8124-4AA2-BC03-DBB4C8DA87C0}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{C4E78729-B2F2-4BD1-9B50-6A4ED5F19B97}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A3A4AEB3-E5EF-4E3F-AF76-871E319DDCDF}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{331843F8-E899-4DC8-90F2-FDDC1266A35F}"= UDP:5353:Adobe CSI CS4
"{D8096164-FBCD-46E5-99D6-34CB2D2B6141}"= e:\program files\Skype\Phone\Skype.exe:Skype
"{3F5D1955-0DEB-4BCC-B16E-821608B2EF0B}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{2D3F401C-57D5-4513-94C3-8B2664E835E8}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{B72820F5-0470-467A-91EF-3BED6DC7D9CF}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3A100139-C7CF-4F93-88A8-16D12BCEC70E}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A4BA6C22-B12A-467C-9D16-E1B5E30F514C}"= UDP:e:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{09321481-804F-4783-8438-F38F645F262A}"= TCP:e:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{676AF48F-A499-4DD6-9190-13BA414793BE}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{7BDC8B2F-5960-45E9-9EF6-5247A663974A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{50E6C724-28CB-4856-96FF-63EDCAE95886}"= c:\program files\WiFiConnector\NintendoWFCReg.exe:Nintendo Wi-Fi USB Connector
"{8A2EB9CC-55D6-44B8-9CCF-9B855D17D429}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{89829439-6BC3-4672-B5B8-DD03A6C8F652}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{FB6A0F8C-6993-4820-BE7E-4A522E969C02}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{FD218725-260D-47C0-812D-7EFA1770407C}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{1D69ED13-43AB-49E2-91A0-48353EE99539}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{8ABF9975-3C91-4899-A855-7F262D34CC84}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{1590378C-091D-4605-B684-FEEC23E2FB70}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{76546947-DB5B-4605-9B0A-FA7A94BF886C}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo.exe
"{264F058D-1039-4750-9399-233DF9342D1D}"= UDP:c:\program files\Samsung\Samsung New PC Studio\npsasvr.exe:KTF MUSIC AoD Server
"{37987008-1ECA-4604-A89A-BA888EE4FCBA}"= TCP:c:\program files\Samsung\Samsung New PC Studio\npsasvr.exe:KTF MUSIC AoD Server
"{B44C0B88-70E9-4F45-8541-32F18A9C713B}"= UDP:c:\program files\Samsung\Samsung New PC Studio\npsvsvr.exe:KTF MUSIC VoD Server
"{9FBB6D6A-92BB-4A8F-9F56-7042E764DAC4}"= TCP:c:\program files\Samsung\Samsung New PC Studio\npsvsvr.exe:KTF MUSIC VoD Server
"{E4CC03E1-CD9A-4386-A643-9B4B876AA3CA}"= UDP:e:\program files\iTunes\iTunes.exe:iTunes
"{A63098FE-A5D7-46B0-BBA5-A37DA33A0151}"= TCP:e:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R?2 AeLookupSvcAgereModemAudio;Application Experience AeLookupSvcAgereModemAudio;c:\windows\system32\fustyisrtl.exe service --> c:\windows\system32\fustyisrtl.exe service [?]
R1 pctgntdi;pctgntdi;c:\windows\System32\drivers\pctgntdi.sys [17/01/2009 10:47 229176]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;e:\program files\Avira\AntiVir Desktop\sched.exe [09/09/2009 19:13 108289]
R2 FsUsbExService;FsUsbExService;c:\windows\System32\FsUsbExService.Exe [16/06/2009 16:44 233472]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\System32\drivers\PCTAppEvent.sys [17/01/2009 10:47 86888]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [08/03/2008 12:05 810320]
R2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [21/04/2009 17:36 116104]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\System32\FsUsbExDisk.Sys [16/06/2009 16:44 36608]
R3 PCTFW-DNS;PCTools Firewall - DNS driver;c:\windows\System32\drivers\pctNdis-DNS.sys [10/09/2009 19:17 32552]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\System32\drivers\pctNdis-PacketFilter.sys [10/09/2009 19:17 70280]
R3 pctNDIS;PC Tools Driver;c:\windows\System32\drivers\pctNdis.sys [10/09/2009 19:17 46592]
R3 pctplfw;pctplfw;c:\windows\System32\drivers\pctplfw.sys [17/01/2009 10:46 114832]
S2 gupdate1c9acc4d03de291;Google Update Service (gupdate1c9acc4d03de291);c:\program files\Google\Update\GoogleUpdate.exe [24/03/2009 22:09 133104]
S3 iadusb;MT882;c:\windows\System32\drivers\glauiad.sys [08/03/2008 11:30 29696]
S3 S2usbser;S2 USB Device for Legacy Serial Communication;c:\windows\System32\drivers\S2usbser.sys [16/11/2008 15:34 103680]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\System32\drivers\ss_bbus.sys [20/06/2009 12:43 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\System32\drivers\ss_bmdfl.sys [20/06/2009 12:43 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\System32\drivers\ss_bmdm.sys [20/06/2009 12:43 121856]
S4 CplIR;Embedded IR Driver;c:\windows\System32\drivers\CplIR.sys [06/03/2007 15:01 14848]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 21:08]
2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 21:09]
2009-09-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-24 21:09]
2009-09-08 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- e:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-11-15 15:31]
2009-09-10 c:\windows\Tasks\User_Feed_Synchronization-{8CE55126-04F8-452B-846C-193C8187AA96}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redirect-home?tag=Toshibaukbholink-21&site=home
IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\users\Arranf_2\AppData\Roaming\Mozilla\Firefox\Profiles\946dhshw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com
FF - prefs.js: network.proxy.type - 2
FF - component: c:\users\Arranf_2\AppData\Roaming\Mozilla\Firefox\Profiles\946dhshw.default\extensions\lazarus@interclue.com\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Opera\program\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: e:\program files\DivX\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: e:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-11 00:06
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b4
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5996)
c:\program files\RocketDock\RocketDock.dll
.
Completion time: 2009-09-10 0:10
ComboFix-quarantined-files.txt 2009-09-10 23:10
ComboFix2.txt 2009-09-10 17:58
Pre-Run: 17,215,578,112 bytes free
Post-Run: 17,078,149,120 bytes free
362 --- E O F --- 2009-09-10 21:08